Digital Content Management System

JP2026137417APending Publication Date: 2026-08-27NOMURA RESEARCH INSTITUTE
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
JP2025023507
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2026-08-27

AI Technical Summary

Benefits of technology

【0011】 本願において開示される発明のうち、代表的なものによって得られる効果を簡単に説明すれば、以下のとおりである。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026137417000001_ABST
    Figure 2026137417000001_ABST
Patent Text Reader

Abstract

Even with diversified digital content, the system will more flexibly and dynamically determine usage methods and conditions related to various users. [Solution] The system includes an actor verifiable attribute issuing unit 20 that acquires attribute information relating to actor 2, attaches a first digital signature to it and issues it as a signed actor attribute, a content verifiable attribute issuing unit 40 that acquires attribute information relating to content, attaches a second digital signature to it and issues it as a signed content attribute, an actor identifier management unit 10 that issues an actor identifier, and a content operation management unit 60 that, upon receiving a request to operate content using information with a third digital signature, verifies the third digital signature with a third public key, verifies the first digital signature with a first public key, verifies the second digital signature with a second public key, and determines whether the conditions for using the content are met based on the verified signed actor attribute and signed content attribute.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0006] , ,

[0005] , , ,

[0001] The present invention relates to content management technology, and more particularly to a technology effective for application to a digital content management system that manages various contents including contents that merely represent rights.

Background Art

[0002] With the recent progress of digitalization, the roles of digital contents (hereinafter sometimes simply referred to as "contents") have diversified. In conventional contents, the protection of the contents themselves centered on DRM (Digital Rights Management) (prevention of unauthorized use, copying, alteration, etc.) was the main focus.

[0003] As a technology related to this, for example, Japanese Patent No. 5357292 (Patent Document 1) describes a DRM engine that evaluates a license related to protected content in order to determine whether access or other use of the requested content is authorized, and it is described that the license includes a control program executable by the DRM engine.

Prior Art Documents

[0007] Therefore, the object of the present invention is to provide a digital content management system that can more flexibly and dynamically determine usage methods and conditions related to various users, even for diverse digital content. The aforementioned and other objects and novel features of the present invention will become clear from the description herein and the accompanying drawings. [Means for solving the problem]

[0008] A brief overview of some of the representative inventions disclosed in this application is as follows:

[0009] A digital content management system, a typical embodiment of the present invention, includes: an actor verifiable attribute issuing unit that holds a first public key and private key pair, acquires attribute information relating to the actor, and issues it as a signed actor attribute by attaching a first digital signature with the first private key; a content verifiable attribute issuing unit that holds a second public key and private key pair, acquires attribute information relating to the digital content, and issues it as a signed content attribute by attaching a second digital signature with the second private key; and an actor identifier management unit that issues an actor identifier that identifies the actor, and a third public key and private key pair, and holds the signed actor attribute and the signed content attribute.

[0010] Furthermore, the system includes a content operation management unit that, upon receiving a request from the actor to operate the digital content, which includes information such as the actor identifier, the third public key, the signed actor attribute, and the signed content attribute, to which a third electronic signature is attached using the third private key, verifies the third electronic signature using the third public key, verifies the first electronic signature attached to the signed actor attribute using the first public key obtained from the actor verifiable attribute issuing unit, verifies the second electronic signature attached to the signed content attribute using the second public key obtained from the content verifiable attribute issuing unit, and determines whether the conditions for using the digital content are met based on the verified signed actor attribute and the signed content attribute. [Effects of the Invention]

[0011] The effects obtained by some of the representative inventions disclosed in this application can be briefly explained as follows:

[0012] In other words, according to a typical embodiment of the present invention, it becomes possible to more flexibly and dynamically determine usage methods and conditions related to various users, even for diverse digital content. [Brief explanation of the drawing]

[0013] [Figure 1] This figure outlines an example configuration of a digital content management system, which is one embodiment of the present invention. [Figure 2] This diagram outlines some examples of challenges arising from the diversification of digital content. [Figure 3] This diagram outlines some examples of challenges arising from the diversification of digital content. [Figure 4] This diagram outlines some examples of challenges arising from the diversification of digital content. [Figure 5] This figure outlines an example of the overall processing flow related to the use and manipulation of content in one embodiment of the present invention. [Figure 6] This is a diagram showing an overview of an example of the process of preparing an actor identifier in the preparation stage in one embodiment of the present invention. [Figure 7] This is a diagram showing an overview of an example of the process of acquiring actor attributes in the issuance phase in one embodiment of the present invention. [Figure 8] This is a diagram showing an overview of an example of the process of acquiring content attributes in the issuance phase in one embodiment of the present invention. [Figure 9] This is a diagram showing an overview of another example of the process of acquiring content attributes in the issuance phase in one embodiment of the present invention. [Figure 10] This is a diagram showing an overview of an example of the process of content operation in the operation phase in one embodiment of the present invention. [Figure 11] This is a diagram showing an overview of another example of the process of content operation in the operation phase in one embodiment of the present invention.

Embodiments of the Invention

[0014] Hereinafter, embodiments of the present invention will be described in detail based on the drawings. In all the drawings for explaining the embodiments, the same parts are generally denoted by the same reference numerals, and repeated explanations thereof are omitted. On the other hand, for the parts described with reference numerals in a certain drawing, they will not be shown again in the explanation of other drawings, but may be referred to with the same reference numerals.

[0015] <Overview> As described above, the roles of digital content have diversified. For example, in the case of content such as tickets and coupons, which has no meaning in itself and simply represents rights, various operations are performed by various users, so authority management and establishment of trust with users become complicated.

[0016] Figures 2 to 4 are diagrams showing an overview of examples of problems due to the diversification of digital content. In each figure, the flow of processing and information when a content user uses the content is schematically shown. In the example of Figure 2, an example is shown where, as a condition for a user to use the content, the user belongs to a specific company, school, etc.

[0017] In the example of Figure 2, when a user accesses a service for using (executing) the content (arrow (1) in the figure), the service checks the usage conditions against a mechanism for managing the content and its usage conditions (arrow (2) in the figure). Then, in order to check whether the user satisfies the usage conditions, an authentication request for information acquisition is made to a system that manages the user's attributes (for example, a company or school system) (arrow (3) in the figure). In the system, consent regarding authentication and information provision is requested from the user (arrow (4) in the figure), and when consent is obtained, the user's information (for example, employee number, student ID number, etc.) is responded and linked (arrow (5) in the figure). In the service for using the content, if it can be confirmed based on the acquired user information that the user belongs to a specific company, school, etc., access to the content is permitted to the user (arrow (6) in the figure).

[0018] Thus, when an external system (in the example of Figure 2, a company, school, etc.) has attribute information for determining the usage conditions for a service for using content, access by the user to the service (arrows (1) and (6) in the figure) is premised on Internet access, whereas access by the service to the external system (arrows (3) and (5) in the figure) is premised on intranet access. In such a case, there is a problem that network constraints occur, such as it becoming difficult to simultaneously satisfy the network requirements related to both accesses.

[0019] The example in Figure 3 illustrates a case similar to the example in Figure 2 described above, where multiple external systems possess information for determining the conditions for using the content. For example, this could include a case where, for example, a user has multiple conditions, such as using a specific service and being 18 years of age or older, and each service manages the information needed to determine each of these conditions.

[0020] Similar to the example in Figure 2, when a user accesses a service that uses (executes) content (arrow (1) in the figure), the service checks the terms of use with the mechanism that manages the content and its terms of use (arrow (2) in the figure). Then, in order to confirm whether the user meets the terms of use, it first makes an authentication request to obtain information from a specific service (arrow (3) in the figure). The specific service then requests the user's consent regarding authentication and information provision (arrow (4) in the figure), and if consent is obtained, it responds with information regarding whether the user is subscribed to the specific service (e.g., user ID, etc.) and exchanges information (arrow (5) in the figure).

[0021] Services that utilize content further request authentication from an age verification service to obtain information (arrow (6) in the diagram), and the age verification service obtains consent from the user regarding authentication and information provision (arrow (7) in the diagram) and responds with the user's age (arrow (8) in the diagram). Once it is confirmed that the user has subscribed to a specific service and is 18 years of age or older, services that utilize content grant the user access to the content (arrow (9) in the diagram).

[0022] Thus, when usage conditions become complex and multifaceted, multiple external systems are required to hold the information needed to determine each condition. This presents challenges such as increased overhead for accessing these external systems and increased overhead for user authentication and consent processes (arrows (3) to (8) in the figure).

[0023] Figure 4 illustrates an example where the content does not check who the user is, meaning the content provider does not manage the user, as long as it can input and display identification information such as numbers or barcodes, such as electronic tickets, gift cards, or coupons.

[0024] The content provider provides the user with information such as a ticket or other content identification number, which the user obtains (arrow (1) in the diagram). The user then presents the obtained content number to the content provider (arrow (2) in the diagram) and uses the content. In other words, the user exercises the rights represented by the content. The content provider records to the content provider that the rights represented by the content have been exercised and the content has been used (arrow (3) in the diagram).

[0025] In such cases, the content provider cannot determine whether the content is being properly distributed to users and used correctly, which can lead to problems such as the unauthorized acquisition of content or unintentional resale.

[0026] To address the challenges mentioned above, a mechanism is needed that can more flexibly and dynamically determine usage methods and conditions related to various users (content users, creators, administrators, sellers, etc.).

[0027] In particular, it is necessary to guarantee, while maintaining interoperability, that information such as user attributes and status, which is required to determine the terms of use when allowing manipulation of content, has not been obtained illegally or tampered with. However, such a mechanism goes beyond the scope of conventional DRM, and it is necessary to extend the guarantee of the legitimacy of user attributes and status to an interoperable mechanism. Furthermore, methods for managing ownership of content, such as NFTs (Non-Fungible Tokens), are emerging, and it is anticipated that interoperability with new methods, not just DRMs, and support for free transactions that are not tied to a specific system will be required.

[0028] Therefore, one embodiment of the present invention, a digital content management system, addresses the aforementioned challenges and enables flexible and interoperable content utilization by separately managing verifiable attributes for content and various users (hereinafter sometimes referred to as "actors").

[0029] <System Configuration> Figure 1 is a diagram illustrating an example configuration of a digital content management system 1, which is one embodiment of the present invention. The digital content management system 1 is an information processing system that enables flexible and interoperable use of content by using a CPU (Central Processing Unit) (not shown) to execute middleware such as an OS (Operating System), DBMS (Database Management System), and Web server programs, as well as software running on them, which are deployed from a storage device such as an HDD (Hard Disk Drive) or SSD (Solid State Drive) into memory.

[0030] This digital content management system 1 includes, for example, an actor identifier management unit 10, an actor verifiable attribute issuing unit 20, an actor attribute management unit 30, a content verifiable attribute issuing unit 40, a digital content management unit 50, and a content operation management unit 60, all implemented as software. In the example in Figure 1, these units are shown as a single unit constituting the digital content management system 1, but this is merely a logical configuration. Physically, one or more units may be configured as separate subsystems (which may be external systems) or client-side applications, and may interact with each other via a network (not shown).

[0031] The Actor Identifier Management Unit 10 has the function of an Identity Provider (IdP) that stores and manages information related to identifiers such as IDs (actor identifiers) that can be linked with external services for each actor 2 in a database or the like (not shown). This information includes not only the actor identifier but also a pair of private and public keys (actor private key, actor public key) for electronically signing and verifying the actor identifier. It also has the function of acquiring and storing attribute information of actor 2 and content that is necessary for determining conditions when using and manipulating content.

[0032] For illustrative purposes, in the example in Figure 1, Actor 2 is shown as belonging to the Digital Content Management System 1. However, Actor 2 is a user of the Digital Content Management System 1, and accesses the Digital Content Management System 1 using an information processing terminal such as a PC (Personal Computer), tablet, or smartphone. This information processing terminal is equipped with dedicated applications, wallets, and other software (not shown) for using and manipulating content via the Digital Content Management System 1, as well as a web browser.

[0033] The Actor Verifiable Attribute Issuing Unit 20 has the function of issuing verifiable attribute information (signed actor attributes) by electronically signing the actor identifier and actor public key prepared in advance by actor 2 by the Actor Identifier Management Unit 10, and various attribute information of the actor (e.g., employee number, age, etc.) obtained from the Actor Attribute Management Unit 30 described later. It has a pair of private and public keys (actor issuer private key, actor issuer public key) for electronic signing and verification, which are stored in a database or the like (not shown). Note that the Actor Verifiable Attribute Issuing Unit 20 can be set up for each target actor attribute.

[0034] The Actor Attribute Management Unit 30 holds and manages various attribute information related to actors, and has the function of responding with the target attribute information in response to a request from the Actor Verifiable Attribute Issuance Unit 20. This may be an external system or service, such as a company or school system. The Actor Attribute Management Unit 30 can also be set up for each target actor attribute.

[0035] The Content Verifiable Attribute Issuing Unit 40 has the function of issuing verifiable attribute information (signed content attributes) by electronically signing the actor identifier and actor public key prepared in advance by actor 2 by the actor identifier management unit 10, and the content attribute information (e.g., a ticket number that identifies the content) obtained from the Digital Content Management Unit 50 described later. It has a pair of private and public keys (content issuer private key, content issuer public key) for electronic signing and verification, which are stored in a database or the like (not shown).

[0036] The Digital Content Management Unit 50 has the function of holding and managing digital content such as tickets, and receiving and executing operations on it. This may be an external service or system such as a ticket vendor. The Content Operation Management Unit 60 has the function of receiving requests from actor 2 to use and operate content, verifying actor attributes and content attributes to confirm the reliability of the information, determining the conditions for using the content based on the actor attributes and content attributes whose reliability has been confirmed, and using and operating the content via the Digital Content Management Unit 50 if the conditions are met.

[0037] As shown in the example configuration in Figure 1, by separating processing and functions on the actor side and the content side with actor 2 as the central axis, it is possible to address challenges such as the constraints related to the differences in network requirements when actor 2 accesses both, as shown in the example in Figure 2 above.

[0038] Furthermore, as will be explained in more detail later, the Actor Verifiable Attribute Issuing Unit 20 issues signed actor attributes in advance, eliminating the need to query actor attributes and authenticate each time content is used. This addresses the challenges of increased complexity and load caused by accessing multiple external systems to determine the conditions for using content, as illustrated in the example in Figure 3 above.

[0039] Furthermore, even if actor 2 is untrustworthy, the content operation management unit 60 can verify actor attributes and content attributes to confirm the reliability of the information and verify that actor 2 has the appropriate permissions. This addresses the problem of not being able to determine whether the content is correctly distributed to users and used correctly, as shown in the example in Figure 4 above. Moreover, by configuring the content operation management unit 60 to verify actor attributes and content attributes and to determine the conditions for using the content, it becomes possible to set usage conditions and extend the functionality of the content on the content usage management side without modifying the existing digital content system.

[0040] <Processing flow (overall)> Figure 5 is a diagram illustrating an example of the overall processing flow related to the use and operation of content in one embodiment of the present invention. First, as a preliminary step, the actor identifier is prepared. Here, the actor identifier management unit 10 prepares an actor identifier and a key pair (actor private key, actor public key) for actor 2 that can be linked with external services, etc.

[0041] Next, in the publishing phase, actor attributes and content attributes are retrieved. In retrieving actor attributes, (verifiable) attribute information for actor 2 is obtained based on actor 2's actor identifier. In retrieving content attributes, (verifiable) attribute information for content assigned to or available to actor 2 is obtained based on actor 2's actor identifier. Then, in the operation phase, content is manipulated. Here, the various actor attributes and content attributes obtained by actor 2 in the publishing phase are presented to manipulate the content.

[0042] <Processing Flow (Preparation)> Figure 6 is a diagram illustrating an example of the flow of the actor identifier preparation process in the pre-preparation phase of one embodiment of the present invention. First, Actor 2, who is the operator of the content, makes an authentication request to the Actor Identifier Management Unit 10 using an arbitrary ID that identifies itself via a predetermined application such as a wallet (S01), and the Actor Identifier Management Unit 10 performs a predetermined authentication process (S02). Once authentication is performed, Actor 2 issues an actor identifier and a pair of actor private key and actor public key (S03), requests the Actor Identifier Management Unit 10 to store and back up these (S04), and the Actor Identifier Management Unit 10 stores them (S05).

[0043] The actor identifier management unit 10 acts as an IdP, but only needs to manage the public and private keys for digital signature and verification. Therefore, the actor identifier and actor private / public keys can be any ID and key pair. In this embodiment, a DID (Decentralized Identifier) ​​such as ION (Identity Overlay Network) Long term is used as the actor identifier.

[0044] <Processing flow (Actor attribute acquisition)> Figure 7 is a diagram illustrating an example of the flow of actor attribute acquisition processing in the issuance phase in one embodiment of the present invention. First, actor 2 requests the actor verifiable attribute issuance unit 20 to acquire its own (verifiable) actor attributes (S11). This request includes its actor identifier (DID) and actor public key. The actor identifier itself may also contain the actor public key.

[0045] The Actor Verifiable Attribute Issuing Unit 20 makes an authentication request to the Actor Attribute Management Unit 30 (S12), and the Actor Attribute Management Unit 30 performs authentication processing with Actor 2 (S13, S14). For example, the Actor Attribute Management Unit 30 requests Actor 2 to enter an employee number, and performs authentication based on the employee number entered by Actor 2. Once authentication is performed, the Actor Attribute Management Unit 30 returns predetermined actor attribute information (e.g., employee number, etc.) pertaining to Actor 2 to the Actor Verifiable Attribute Issuing Unit 20 (S15).

[0046] The Actor Verifiable Attribute Issuing Unit 20 digitally signs the Actor Identifier (DID) and Actor Public Key obtained from Actor 2, and the Actor Attribute Information Set obtained from Actor Attribute Management Unit 30, using its own Actor Issuer Private Key (S16), and returns this to Actor 2 as a verifiable signed Actor Attribute (S17). This signed Actor Attribute is created, for example, according to various standards related to VC (Verifiable Credentials). The above series of processes can be understood as, for example, issuing a digital employee ID card in advance if the Actor Attribute is an employee number.

[0047] Actor 2, having obtained the signed actor attribute, requests the actor identifier management unit 10 to save it (S18), and the actor identifier management unit 10 saves the passed signed actor attribute (S19). Note that the process shown in the example in Figure 7 is performed for each actor attribute that is obtained in advance in order to use the content.

[0048] <Processing flow (Content attribute acquisition)> Figure 8 is a diagram illustrating an example of the flow of content attribute acquisition processing in the issuance phase in one embodiment of the present invention. Figure 8 shows an example of the processing flow when content such as tickets is issued to multiple actors 2 in a batch, and content usage permission has been granted in advance, and a list of actors 2 to whom content attributes are to be assigned can be obtained and linked via a file or the like.

[0049] First, the Content Verifiable Attribute Issuing Unit 40 requests content attribute information from the Digital Content Management Unit 50 (S21), and the Digital Content Management Unit 50 sends the content attributes (for example, a list of ticket numbers issued in bulk) (S22). Meanwhile, the Content Verifiable Attribute Issuing Unit 40 works in cooperation with the Actor Identifier Management Unit 10 to obtain information on the actors 2 to whom the content attributes are to be assigned (S23, S24). Here, for example, as described above, the information is obtained in the form of a file or the like listing the actors 2 to whom the content attributes are to be assigned. The information of each actor 2 obtained includes the actor identifier (DID) and actor public key held in the Actor Identifier Management Unit 10.

[0050] Subsequently, the Content Verifiable Attribute Issuance Unit 40 digitally signs the information set of each actor identifier (DID) and actor public key obtained from the Actor Identifier Management Unit 10, and each content attribute (ticket number, etc.) obtained from the Digital Content Management Unit 50, using its own Content Issuer private key, and lists them as verifiable signed content attributes (S25). Then, it requests the Actor Identifier Management Unit 10 to save the signed content attributes (S26), and the Actor Identifier Management Unit 10 saves the provided signed content attributes (S27). In the example in Figure 8, the Actor Identifier Management Unit 10 is configured to be located on a server or the like, rather than on the terminal used by Actor 2.

[0051] Through the above process, each actor 2 can reference and retrieve the content attributes assigned to it. That is, actor 2 requests the actor identifier management unit 10 to reference and retrieve the content attributes assigned to it (S28), and the actor identifier management unit 10 sends this request to actor 2 (S29), allowing actor 2 to retrieve the content attributes (S30).

[0052] Figure 9 is a diagram illustrating another example of the content attribute acquisition process flow in the publishing phase of one embodiment of the present invention. Unlike the example in Figure 8 described above, this shows an example of the process flow when actor 2 acquires content attributes in real time when using the content.

[0053] First, when Actor 2 uses the content, it accesses the Content Verifiable Attribute Issuing Unit 40 through some channel (S31). The Content Verifiable Attribute Issuing Unit 40 determines whether the conditions for issuing content attributes are met (S32) and confirms that the conditions are met by some action by Actor 2 (S33, S34). The actions here may be, for example, payment or information presentation, but the processing related to such actions does not necessarily have to be provided in the Content Verifiable Attribute Issuing Unit 40, and may be performed in an external system or service with which it is linked.

[0054] When the conditions for issuing content attributes are met, Actor 2 requests the Content Verifiable Attribute Issuance Unit 40 to obtain the content attributes (S35). This request includes the Actor Identifier (DID) and the Actor Public Key. Subsequently, the Content Verifiable Attribute Issuance Unit 40 requests the Digital Content Management Unit 50 to obtain the content attributes (S36), and the Digital Content Management Unit 50 sends the content attributes (e.g., ticket number) (S37). Note that the request for content attributes from the Digital Content Management Unit 50 may be made each time Actor 2 uses the content, as in the example in Figure 9, or it may be requested and obtained in advance.

[0055] Subsequently, the Content Verifiable Attribute Issuing Unit 40 digitally signs the Actor Identifier (DID) and Actor Public Key provided by Actor 2, along with the set of content attribute information (ticket number, etc.) obtained from the Digital Content Management Unit 50, using its own Content Issuer Private Key (S38), and returns it to Actor 2 as a verifiable signed content attribute (S39). Actor 2 requests the Actor Identifier Management Unit 10 to save the acquired signed content attribute (S40), and the Actor Identifier Management Unit 10 saves it (S41).

[0056] <Processing flow (content manipulation)> Figure 10 is a diagram illustrating an example of the content manipulation process flow in the operation phase of one embodiment of the present invention. First, actor 2 accesses the content manipulation management unit 60 to request the use and manipulation of content (S51). Upon receiving the request, the content manipulation management unit 60 presents the actor attributes and content attributes necessary for manipulating the content (S52).

[0057] If Actor 2 does not possess any of the presented attributes on its terminal, it requests the Actor Identifier Management Unit 10 to acquire them (S53). The Actor Identifier Management Unit 10 retrieves the attribute information already acquired and stored in the issuance phase and sends it to Actor 2 (S54). If the necessary actor attributes have not been acquired and are not stored in the Actor Identifier Management Unit 10, the actor attributes may be acquired separately by the process shown in the example in Figure 7 above.

[0058] When actor 2 obtains the necessary attribute information, it digitally signs the information containing the actor identifier (DID), actor public key, necessary actor attribute information set, and necessary content attribute information set using its own actor private key (S55), and sends it to content operation management unit 60 (S56).

[0059] The content operation management unit 60 first verifies the reliability of the acquired attribute information (S57). Specifically, for example, it first verifies the digital signature of the entire attribute information sent from actor 2 using the actor's public key contained therein. If verification is successful, it further checks whether the values ​​of the actor identifier and actor's public key contained in the attribute information match those of the actor identifier and actor's public key contained in the actor attribute information set, and those of the actor identifier and actor's public key contained in the content attribute information set. This confirms that the acquired attribute information was acquired and correctly sent by a legitimate actor 2.

[0060] Furthermore, the digital signature of the actor attribute information set is verified using the actor issuer public key, and if verification is successful, it is confirmed, if possible, that the expiration date set for the actor attribute has not expired. The actor issuer public key used for verifying the digital signature is obtained from the actor verifiable attribute issuing unit 20 related to the actor attribute (it may be obtained in advance). Similarly, the digital signature of the content attribute information set is verified using the content issuer public key, and if verification is successful, it is confirmed, if possible, that the expiration date set for the content attribute has not expired. The content issuer public key used for verifying the digital signature is obtained from the content verifiable attribute issuing unit 40 (it may be obtained in advance).

[0061] Once the reliability of the attribute information is confirmed, it is determined whether the content usage conditions are met based on the content of the actor attributes and content attributes (S58). Note that other optional processes may be incorporated and executed when determining the usage conditions. If the actor attributes and content attributes meet the usage conditions, a request is made to the digital content management unit 50 to perform an operation on the content related to the content attribute (e.g., content number) (S59), and the digital content management unit 50 performs the operation on the target content (S60).

[0062] When content is manipulated, the content manipulation management unit 60 requests the actor identifier management unit 10 to record as a history that actor attributes and content attribute information have been used (S61), and the actor identifier management unit 10 may record the usage history of attribute information in a database or the like. The content manipulation management unit 60 then notifies actor 2 that the content manipulation is complete (S63), and actor 2 completes the use and manipulation of the content upon receiving this notification (S64).

[0063] Figure 11 is a diagram illustrating another example of the content manipulation processing flow in the operation phase of one embodiment of the present invention. In the example of Figure 11, in a processing flow similar to the example of Figure 10 described above (only steps S57 to S60 of the example of Figure 10 are shown in the figure), after the content manipulation management unit 60 confirms the reliability of the attribute information (S57), it shows an example in which, before determining whether the obtained actor attributes and content attributes satisfy the content usage conditions (S58), the validity of the acquired actor attributes and content attributes is reconfirmed by querying the publisher each time.

[0064] In the process of re-verifying the validity of actor attributes and content attributes, for the actor attributes and content attributes whose reliability was confirmed in step S57, a re-verification of validity is requested from the target actor verifiable attribute issuing unit 20 and content verifiable attribute issuing unit 40, respectively, based on the query URL (Uniform Resource Locator) contained in each and the key information that identifies the respective attribute information (S61).

[0065] The actor verifiable attribute issuing unit 20 and the content verifiable attribute issuing unit 40 reconfirm whether the actor attributes and content attributes are valid (S62, S63). For example, by linking with the actor attribute management unit 30 and the digital content management unit 50 via API (Application Programming Interface), the validity of actor attributes and content attributes can be confirmed at the latest point in time. This allows for appropriate restriction of content use even in cases where, for example, the target actor 2 has left the company and their employee number is no longer valid immediately before the content is manipulated, meaning that actor attributes and content attributes acquired in advance were valid at the time but are no longer valid at the time of content manipulation.

[0066] As described above, according to the digital content management system 1, which is one embodiment of the present invention, by separately managing verifiable attributes for actors and content, it is possible to realize flexible and interoperable content utilization.

[0067] In other words, by separating processing and functions between the actor side and the content side, with actor 2 as the central point, it is possible to address challenges such as constraints related to differences in network requirements when actor 2 accesses both. Furthermore, by issuing signed actor attributes in advance using the actor verifiable attribute issuing unit 20, it eliminates the need to query actor attributes and authenticate each time content is used. This addresses the challenges of increased complexity and load caused by accessing multiple external systems to determine the conditions for using content. In addition, even if actor 2 is not trusted, the content operation management unit 60 verifies actor attributes and content attributes to confirm the reliability of the information and to confirm that actor 2 has appropriate permissions. This addresses the challenge of not being able to determine whether content is being correctly distributed to users and used correctly.

[0068] The present inventors have described the invention in detail based on embodiments above, but it goes without saying that the present invention is not limited to the above embodiments and can be modified in various ways without departing from its essence. Furthermore, the above embodiments are described in detail for the purpose of explaining the present invention in an easy-to-understand manner and are not necessarily limited to those having all the configurations described. In addition, it is possible to add, delete, or replace some of the configurations of the above embodiments with other configurations.

[0069] Furthermore, each of the above configurations, functions, processing units, and processing means may be implemented in hardware, in whole or in part, for example, by designing them as integrated circuits. Alternatively, each of the above configurations, functions, and means may be implemented in software by having the processor interpret and execute programs that implement each function. Information such as programs, tables, and files that implement each function can be stored in memory, hard disks, SSDs, or other recording devices, or in recording media such as IC cards, SD cards, or DVDs.

[0070] Furthermore, in the diagrams above, the control lines and information lines shown are those deemed necessary for explanation and do not necessarily represent all control lines and information lines that would be present in the actual implementation. In reality, it can be assumed that almost all components are interconnected. [Industrial applicability]

[0071] This invention can be used in a digital content management system that manages a variety of content, including content that merely represents rights. [Explanation of Symbols]

[0072] 1…Digital content management system, 2…Actor, 10...Actor Identifier Management Unit, 20...Actor Verifiable Attribute Issuance Unit, 30...Actor Attribute Management Unit, 40...Content Verifiable Attribute Issuance Unit, 50...Digital Content Management Unit, 60...Content Operation Management Unit

Claims

1. A digital content management system that controls the manipulation of digital content by actors, An actor verifiable attribute issuing unit that holds a first public key and private key pair, obtains attribute information relating to the actor, and issues it as a signed actor attribute by attaching a first digital signature with the first private key, A content verifiable attribute issuing unit that holds a second public key and private key pair, obtains attribute information relating to the digital content, and issues it as a signed content attribute by attaching a second digital signature using the second private key, An actor identifier management unit issues an actor identifier that identifies the actor, and a third public key and private key pair, and holds the signed actor attributes and the signed content attributes, A digital content management system comprising: a content operation management unit that, upon receiving a request from the actor to operate the digital content, which includes information including the actor identifier, the third public key, the signed actor attribute, and the signed content attribute, to which a third electronic signature is attached using the third private key, verifies the third electronic signature using the third public key, verifies the first electronic signature attached to the signed actor attribute using the first public key obtained from the actor verifiable attribute issuing unit, verifies the second electronic signature attached to the signed content attribute using the second public key obtained from the content verifiable attribute issuing unit, and determines whether the conditions for using the digital content are met based on the verified signed actor attribute and the signed content attribute.

2. In the digital content management system described in claim 1, The signed actor attribute and the signed content attribute each include the actor identifier and the third public key, respectively. A digital content management system in which the content operation management unit confirms that the actor identifier and the third public key included in the information match the values ​​of the actor identifier and the third public key included in the signed actor attribute and the signed content attribute, respectively.

3. In the digital content management system described in claim 1, The Content Operation Management Unit is a digital content management system that verifies that the verified signed actor attribute and the signed content attribute have not expired.

4. In the digital content management system described in claim 1, The Content Operation Management Unit is a digital content management system that reconfirms that the attribute information is valid for the verified signed actor attribute and the signed content attribute.

Citation Information

Patent Citations

  • Unsaturated polyester resin composition

    JP1978057292A