Device, control method for device, and content distribution system

A cost-effective content distribution system using a content management unit and memory management unit in a general-purpose microcontroller addresses the challenge of securing content distribution, enabling efficient protection and high-speed content loading across diverse devices.

WO2025225364A1PCT designated stage Publication Date: 2025-10-30SONY SEMICON SOLUTIONS CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/JP2025/014020
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-04-25
Filing Date
2025-04-08
Publication Date
2025-10-30

AI Technical Summary

Technical Problem

Existing content distribution systems face challenges in protecting digital content from misuse and unauthorized access, particularly in systems using System on a Chip (SoC) due to the high cost of SoCs, and there is a need for an affordable mechanism to secure content distribution.

Method used

A device and system that includes a content management unit, a memory unit, and a memory management unit to protect content information, using a general-purpose microcontroller to manage and decrypt encrypted content while preventing misuse, without requiring expensive SoCs.

Benefits of technology

The solution effectively protects content from unauthorized access and misuse, allowing for high-speed booting and content loading, while being cost-effective and applicable to various devices, including IoT devices and smart cameras.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025014020_30102025_PF_FP_ABST
    Figure JP2025014020_30102025_PF_FP_ABST
Patent Text Reader

Abstract

Provided is a device comprising: a content management unit that operates in a memory space and decodes content distributed in an encrypted state; a storage unit that stores information for enabling the content management unit to operate; and a memory management unit that protects information stored in the storage unit and / or information used by the content management unit.
Need to check novelty before this filing date? Find Prior Art

Description

Device, control method for device and content distribution system

[0001] The present technology relates to a device, a control method for the device, and a content distribution system.

[0002] There is an application providing system that can realize a distribution system that distributes applications developed by developers, manufacturers, companies, individuals, and other developers to users over the Internet (Patent Document 1).

[0003] In systems that distribute such content, it is common to use DRM (Digital Rights Management) to protect the copyright of the content. DRM is a mechanism that restricts the method and period of use of content in order to prevent the unjust infringement of the copyrights and other rights held by the copyright holders of digital content.

[0004] When distributing content to devices with restrictions on usage periods using DRM, a mechanism is needed to protect information that may be misused to attack other content or devices, etc. Attacks include, for example, decrypting content or removing or changing restrictions on content usage periods.

[0005] U.S. Patent Publication US2013 / 0212160

[0006] For example, in a System on a Chip (SoC) running Linux (registered trademark), such information can be protected by using a Memory Management Unit, but the problem is that SoCs are more expensive than microcomputers.

[0007] The present technology has been developed in consideration of such problems, and aims to provide a device, a control method for the device, and a content distribution system that can inexpensively implement a mechanism for protecting information that may be misused during content distribution.

[0008] In order to solve the above-mentioned problems, the first technology is a device that includes a content management unit that operates in memory space and decrypts content that has been distributed in encrypted form, a memory unit that stores information to enable the content management unit to operate, and a memory management unit that protects at least one of the information stored in the memory unit and the information used by the content management unit.

[0009] The second technology is a control method in a device in which a content management unit, which is enabled to operate in memory space using information stored in a storage unit, decrypts content that has been distributed in an encrypted state, and protects at least one of the information stored in the storage unit and the information used by the content management unit.

[0010] The third technology is a content distribution system comprising a device that includes a content distribution device that distributes content in an encrypted state, a content management unit that is enabled to operate in memory space and decrypts the content that has been distributed in an encrypted state, a memory unit that stores information to enable the content management unit to operate, and a memory management unit that protects at least one of the information stored in the memory unit and the information used by the content management unit.

[0011] 1 is a block diagram showing a configuration of a content distribution system 10. FIG. 2 is a block diagram showing a hardware configuration of a content distribution device 100. FIG. 3 is a diagram showing processing blocks of the content distribution device 100. FIG. 4 is a flowchart showing processing of the content distribution device 100. FIG. 5 is a block diagram showing a hardware configuration of a device 200. FIG. 6 is a diagram showing processing blocks of the device 200. FIG. 7 is a flowchart showing processing of the device 200. FIG. 8 is a block diagram showing a configuration of a microcomputer 220. FIG. 9 is a diagram showing processing in the microcomputer 220.

[0012] Hereinafter, embodiments of the present technology will be described with reference to the drawings. The description will be made in the following order: <Embodiment> [Configuration of content distribution system 10] [Configuration and processing of content distribution device 100] [Configuration and processing of device 200] <Modification>

[0013] <Embodiment> [Configuration of Content Distribution System 10] The configuration of the content distribution system 10 will be described with reference to Fig. 1. The content distribution system 10 is configured with a content distribution device 100 that distributes content and a device 200 on which the distributed content operates.

[0014] In the present technology, content refers to executable content that operates on device 200 when executed, such as an AI (Artificial Intelligence) application, an application, an AI model, a game, a program, software, etc. In addition, content in the present technology also includes video data, audio data, image data, document data, etc. that are accompanied by menus or mini-games that can be operated by a person via a controller or the like.

[0015] The content distribution device 100 is used by a person who distributes content (hereinafter referred to as a distributor). The content distribution device 100 registers content uploaded by a person who provides content (hereinafter referred to as a provider) and stores the content in a database, and distributes content requested by a person who uses content (hereinafter referred to as a user) to a device 200 specified by the user. The provider may be an individual, a corporation, a developer, a manufacturer, a company, etc. The user is also not limited to an individual, and may be a manufacturer, a company, etc.

[0016] The content distribution device 100 distributes content protected by DRM. When distributing content using DRM, multiple licenses with different usage conditions may exist for a single piece of content. A license is a contract for content distribution, which has become more flexible with the shift from physical distribution to digitalization. The usage conditions limit the use of content (execution, viewing, saving, copying, etc.) to a specific period, specific device, specific user, etc.

[0017] By using the content distribution device 100, it is possible to realize a so-called online marketplace that distributes content online in response to requests from users. Note that the content may be distributed on a paid basis based on purchases that require payment by the user, or may be distributed free of charge without requiring payment.

[0018] A provider who creates and provides content uploads and registers content to the content distribution device 100 using a terminal device 300 connected to the content distribution device 100 via a network. The terminal device 300 may be a personal computer, a smartphone, a tablet device, a server device, or the like, but any device capable of uploading content may be used. Note that although one terminal device 300 is shown in FIG. 1 , typically, multiple terminal devices 300 are connected to the content distribution device 100 via a network, and multiple providers upload content to the content distribution device 100 for distribution.

[0019] The device 200 is connected to the content distribution device 100 via a network. The device 200 is a variety of devices capable of running content distributed from the content distribution device 100. Examples of the device 200 include Internet of Things (IoT) devices, personal computers, server devices, tablet terminals, smartphones, smart watches, smart cameras, wearable devices, home game consoles, portable game consoles, media players, home appliances, and mobile objects such as automobiles and drones. However, the device 200 is not limited to these and may be any device capable of running content. The device 200 that uses DRM uses the content within the scope of the usage conditions of the license if the license distributed along with the content is valid.

[0020] Although one device 200 is shown in FIG. 1 , in reality, multiple devices 200 are connected to the content distribution device 100 via a network. The multiple devices 200 may belong to one user or multiple users. For example, if the device 200 is a camera and multiple cameras are connected to the content distribution device 100 in advance, the use case for each camera may be different, such as using a specific camera to detect people and other cameras to detect objects. In such a case, it is possible to select a camera application (content) and a camera to run the application, and distribute different applications to each of the multiple cameras.

[0021] Note that the user may make a content distribution request to the content distribution device 100 using the device 200, or may make the content distribution request using a device other than the device 200. When making a content distribution request using a device other than the device 200 on which the content runs, the other device needs to transmit device identification information, which is information specifying the device 200 on which the content runs, to the content distribution device 100 when making the distribution request. Examples of other devices include a personal computer, a smartphone, a tablet terminal, a wearable device, a stationary game console, a portable game console, and a media player.

[0022] Before content distribution, the content distribution apparatus 100 and the device 200 need to perform mutual authentication (device authentication, server authentication), establish secure communication, and so on.

[0023] The content distribution system 10 is configured as described above. Since many parties are involved in such a content distribution system 10, including providers, distributors, designers of the devices 200, and users, there are various concerns regarding copyrights of the content.

[0024] Security on the Internet and Wi-Fi targets attacks from malicious third parties. In contrast, security for content must address not only malicious third parties, but also content providers, device 200 designers, and content users, as these may also be potential attackers. It is also necessary to consider the physical security of the device 200 used to use the content and the misuse of content production technology.

[0025] For example, content providers may wish to receive compensation for distributing their content, but may risk using other people's content or know-how without permission, regardless of whether this was malicious or not, resulting in plagiarism, etc. Furthermore, content that was distributed with terms of use, such as a usage period, may be used by users who invalidate those terms, resulting in disadvantages.

[0026] The content distributor bears responsibility for imposing obligations on the designer of the device 200 to properly distribute the content received from the content provider.

[0027] The designer of the device 200 may be concerned about ignoring the restrictions that accompany the distribution of content and using the content, but this is addressed through a contract with the content distributor.

[0028] A content user may physically access the device 200 and modify or analyze it to extend the usage period of the content, or may invalidate the usage conditions and make malicious use of the content, such as copying the content.

[0029] Therefore, the use of DRM is essential for content distribution. Examples of DRM implementation for executable content include the following:

[0030] Content recorded on a Blu-ray disc is encrypted so that it can be decrypted using an authentication key in the Blu-ray player's Advanced Access Content System (AACS). Additionally, interactive content and menus are created in Java, separate from the main video and audio, and run within the Blu-ray player's JAVA Sandbox. This prevents attacks on the Blu-ray player's system and the video and audio recorded on the Blu-ray disc. Furthermore, the security is reset when the Blu-ray disc is replaced, preventing interference with interactive content on other Blu-ray discs.

[0031] In addition, in the case of home video game consoles, the system side has the game's DRM and service network authentication infrastructure. The game manages the user, device, usage period, etc. according to the license. The user can operate the game by switching between the system menu and the in-game experience. In home video game consoles, DRM is implemented using a Memory Management Unit, etc.

[0032] [Configuration and Processing of Content Distribution Device 100] The hardware configuration of the content distribution device 100 will be described with reference to FIG.

[0033] The control unit 101 is composed of a CPU (Central Processing Unit), RAM (Random Access Memory), ROM (Read Only Memory), etc. The CPU executes various processes and issues commands according to programs stored in the ROM, thereby controlling the entire content distribution device 100 and each of its components.

[0034] The storage unit 102 is a large-capacity storage medium configured, for example, by a hard disk, a solid-state drive (SSD), etc. The storage unit 102 stores programs for operating the content distribution device 100 and the content distribution system 10, as well as other data.

[0035] The communication unit 103 is a communication interface between the device 200, the terminal device 300, a network, etc. The communication method may be either wired or wireless. Communication methods include cellular communication, 4G, 5G, Wi-Fi, Bluetooth (registered trademark), NFC (Near Field Communication), Ethernet (registered trademark), HDMI (High-Definition Multimedia Interface), USB (Universal Serial Bus), etc. It is desirable to encrypt communication using TLS (Transport Layer Security) or SSL (Secure Sockets Layer).

[0036] Next, the configuration and processing of the processing blocks of the content distribution device 100 will be described with reference to FIGS.

[0037] A predetermined DRM authentication key for the distributor is embedded in the system firmware of the content distribution device 100. The DRM authentication key does not differ for each provider, but is unique to the distributor.

[0038] First, in the content storage stage shown in FIG. 4A, in step S11, the receiving unit 111 receives the content uploaded from the terminal device 300 of the provider before distribution.

[0039] Next, in step S12, the encryption processing unit 112 encrypts the content with the randomly generated content decryption key. Note that the encryption processing unit 112 may have a function for generating the content decryption key, or a key generation unit separate from the encryption processing unit 112 may generate the content decryption key. The encryption processing unit 112 outputs the encrypted content to the content database 113. As a result, the content is stored in the content database 113 in step S13.

[0040] The content database 113 is a database that stores content uploaded by one or more providers. The content stored in the content database 113 may be in a platform-dependent format or a platform-independent format. Examples of platform-independent formats include WASM (WebAssembly) bytecode, source code in C++, Java (registered trademark), JavaScript (registered trademark), and object code targeted at a virtual machine.

[0041] In this manner, the content distribution device 100 performs the process at the content storage stage.

[0042] 4B , when a content distribution request is received from the user, in step S14 the user / device management unit 114 sets a usage period based on the purchase conditions and request details sent by the user, and identifies the device 200 to which the content should be distributed by referring to the user / device information database 115 based on the device identification information. The user / device management unit 114 then outputs usage condition information including the content usage period and the device identification information of the device to which the content will be distributed to the DRM processing unit 116.

[0043] Furthermore, the user / device management unit 114 outputs content identification information indicating the content requested by the user to the content selection unit 117. Furthermore, the user / device management unit 114 outputs device identification information specifying the device 200 to which the content is to be distributed to the transmission unit 118.

[0044] Furthermore, the user / device management unit 114 may register device information sent from users, register user information, manage transactions related to application distribution requests, etc., or other processing units may perform these processes. User information is information about users, such as the user's name, login information, ID, and password. Device information is, for example, information such as device type, device serial number and other device identification information, device certificate, device configuration, and device platform architecture.

[0045] The user / device information database 115 is a database that stores information about users and their devices 200. Before requesting content distribution, the user transmits and registers user information and device information to the content distribution device 100.

[0046] Next, in step S15, the DRM processing unit 116 encrypts the content decryption key using the DRM authentication key. Next, in step S16, the DRM processing unit 116 concatenates the encrypted content decryption key with the plaintext usage condition information to generate license information, and ensures the integrity of the license information using the DRM authentication key. This makes the license information usable only in devices 200 that have a DRM authentication key that corresponds to the DRM authentication key held by the content distribution device 100.

[0047] The following methods can be used to ensure integrity. The first method is to use a common AES (Advanced Encryption Standard) symmetric key as a DRM authentication key in the content distribution system 10 to add a MAC and perform verification. The second method is to use a common RSA asymmetric key pair as a DRM authentication key in the content distribution system 10, with the content distribution device 100 on the distribution side signing using a private key and the device 200 on the receiving side verifying using a public key. The third method is to have each device 200 on the receiving side individually hold a key such as an AES symmetric key or an RSA asymmetric key pair, and the content distribution device 100 on the distribution side manages a database of AES keys or RSA private keys corresponding to all devices 200, and searches for and utilizes them based on device identification information.

[0048] The confidentiality of the content decryption key is ensured by a DRM authentication key. There are the following methods for ensuring confidentiality. In the first method, the content distribution device 100 on the distribution side encrypts the content decryption key using a common AES symmetric key in the content distribution system 10, and the device 200 on the receiving side decrypts the content decryption key. In the second method, the content distribution device 100 on the distribution side encrypts the content decryption key using a public key using a common RSA asymmetric key pair in the content distribution system 10, and the device 200 on the receiving side decrypts the content decryption key using a private key. In the third method, each device 200 on the receiving side individually holds a key such as an AES symmetric key or an RSA asymmetric key pair, and the content distribution device 100 on the distribution side manages an AES key or RSA public key database corresponding to all devices 200, and searches for and utilizes the key based on device identification information.

[0049] The DRM processing unit 116 may add a signature or MAC to the license information itself so that the usage condition information can be verified by the device 200 having the DRM authentication key. In this case, the device 200 decrypts the license information with the DRM authentication key and verifies the signature or MAC.

[0050] Next, in step S17, the content selection unit 117 selects and acquires the content requested by the user from the content database 113 based on the content identification information. The content selection unit 117 outputs the acquired content to the transmission unit 118.

[0051] Next, in step S18, the transmitting unit 118 distributes the encrypted content and the license information associated with the content to the device 200 identified by the device identification information.

[0052] The processing of the content distribution device 100 according to the present technology is performed in the above manner.

[0053] The encryption processing unit 112, user / device management unit 114, DRM processing unit 116, and content selection unit 117 are realized by processing in the control unit 101. Each of these processing units may be realized by hardware having a dedicated function. The content database 113 and user / device information database 115 are configured by the storage unit 102.

[0054] The content distribution device 100 may be realized by various devices (such as a server, a personal computer, a tablet terminal, or a smartphone) having computer functions executing a program. The program may be pre-installed in the various devices, or may be distributed by download or storage medium and installed by the content distributor. The content distribution device 100 may also be configured as a stand-alone device. The content distribution device 100 may also be a system including multiple servers interconnected via a network.

[0055] [Configuration and Processing of Device 200] Next, the hardware configuration of the device 200 will be described with reference to Fig. 5. The device 200 includes at least a control unit 201, a storage unit 202, a communication unit 203, and a user management unit 204.

[0056] The control unit 201 is composed of a CPU, RAM, ROM, etc. The CPU executes various processes in the memory space of the RAM in accordance with a program stored in the ROM and issues commands, thereby controlling the entire device 200 and each of its components.

[0057] The storage unit 202 is a large-capacity storage medium configured, for example, by a hard disk, an SSD, etc. The storage unit 202 stores programs for operating the device 200 and using the content distribution system 10, as well as other data.

[0058] The communication unit 203 is a communication interface between the content distribution device 100, a network, etc. The communication method may be either wired or wireless. Communication methods include cellular communication, 4G, 5G, Wi-Fi, Bluetooth (registered trademark), NFC, Ethernet (registered trademark), HDMI (registered trademark), USB, etc. It is desirable to encrypt communication using TLS or SSL.

[0059] The user management unit 204 performs processes such as requesting content and transmitting device information to the content distribution device 100 based on input operations by the user, and also manages transactions with the content distribution device 100. The user management unit 204 may be configured as a dedicated processing unit, may be realized by processing in the control unit 201, may be realized by hardware with dedicated functions, or may be provided in a terminal device different from the device 200.

[0060] In addition, although not shown in the figure, device 200 may also include an input unit such as a mouse, keyboard, or touch panel that a user uses to input a content delivery request, a GUI processing unit that performs processing related to a GUI (Graphical User Interface) for content delivery requests, and a display unit such as a display that displays a GUI, etc.

[0061] Next, the configuration and processing of the processing blocks of device 200 will be described with reference to Figures 6 and 7. The receiving unit 211, authentication processing unit 212, confirmation processing unit 213, and key decryption unit 214 are realized by processing in the control unit 201. Furthermore, each of these processing units may be realized by device 200 executing a program. The program may be installed in device 200 in advance, or may be distributed by download or storage medium, etc., and installed by the user. Furthermore, each processing unit may be realized by a processing block of hardware having a dedicated function.

[0062] The system firmware of the device 200 stores a receiving-side DRM authentication key that pairs with the distributor's DRM authentication key during the manufacturing process, firmware update, etc. The device 200 may be shipped with the DRM authentication key stored. Note that if the microcomputer storage unit 221 (described later) has sufficient storage capacity, the DRM authentication key may be stored in the microcomputer storage unit 221.

[0063] First, in step S21, the receiving unit 211 receives the content and license information transmitted from the content distribution device 100.

[0064] Next, in step S22, the authentication processing unit 212 verifies the integrity of the license information using the DRM authentication key.

[0065] Next, in step S23, the confirmation processing unit 213 refers to the usage condition information included in the license information and confirms whether the usage period limit of the content and the device identification information in the license are appropriate.

[0066] Next, in step S24, the key decryption unit 214 decrypts the content decryption key included in the license information using the DRM authentication key. This content decryption key is information used by the content management unit 232 (described later) to decrypt the encrypted content and make it operable. If the information used by the content management unit 232 is obtained by content operating in the memory space of the microcomputer 220, it could be misused by the content provider to attack other providers or the device 200.

[0067] Next, in step S25, the content decryption unit 215 decrypts the content to make it operable.

[0068] The process in step S25 will now be described in detail. This process is performed in the memory space of the microcomputer 220 included in the device 200. First, the configuration of the microcomputer 220 will be described with reference to FIG.

[0069] If a general-purpose microcomputer, which is cheaper than an SoC, has functions for authenticated firmware startup, firmware encryption, and firmware encryption key access prohibition, this technology can be realized by using the general-purpose microcomputer as the microcomputer 220.

[0070] The microcomputer storage unit 221 includes, for example, a boot ROM and E-Fuse. A public signature key or a symmetric MAC key serving as a system firmware authentication key is stored in the microcomputer storage unit 221 in advance, for example, during the manufacture of the device 200. Although the terms "public signature key" and "symmetric MAC key" are used, both the public signature key and the symmetric MAC key may be stored in the microcomputer storage unit 221. These keys govern authentication for loading specific system firmware. The microcomputer storage unit 221 also stores a symmetric encryption key (system firmware encryption symmetric key) for encrypting the contents of the system firmware. If these keys are obtained by content running in the microcomputer 220's memory space, they could be misused by the content provider to attack other providers or the device 200. The microcomputer storage unit 221 corresponds to a storage unit in the claims.

[0071] The SRAM (Static Random Access Memory) 222 constitutes a memory space for the operation of each processing unit that executes processing in the microcomputer 220 and content. However, the memory space may be constituted using a RAM other than an SRAM.

[0072] In this embodiment, the authenticated encryption system firmware is stored in an external flash memory 400 serving as an external storage medium. However, the authenticated encryption system firmware may also be stored in the microcomputer 220. Storing the authenticated encryption system firmware in the flash memory 400 can reduce the manufacturing cost of the device 200.

[0073] The boot ROM serving as the microcomputer storage unit 221 loads and starts the authenticated encryption system firmware from the flash memory 400. The authenticated encryption system firmware is authenticated by verifying the signature using a signature public key serving as the system firmware authentication key, or by verifying the MAC using a MAC-added symmetric key.

[0074] In the explanation of Fig. 9, the content is referred to as content 500. As shown in Fig. 9A, in the memory space in the initial state, neither the processing units nor the content 500 are in an operable state.

[0075] 9B , when a user starts up device 200 using secure boot, device 200 authenticates and decrypts memory management unit 231, content management unit 232, and usage period management unit 233 using the signature public key or MAC-added symmetric key and the system firmware encryption symmetric key stored in microcomputer storage unit 221. This enables memory management unit 231, content management unit 232, and usage period management unit 233 to operate in the memory space.

[0076] The memory management unit 231 manages each processing unit operating in the memory space and performs processing to transition the state of the memory space, etc. For example, NuttX, which is a real-time operating system (RTOS), can be used as the memory management unit 231.

[0077] The content management unit 232 authenticates and decrypts the content 500 using the content decryption key, and converts the encrypted content 500 into plain text.

[0078] The usage period management unit 233 manages the usage period of the content based on the usage condition information included in the license information. For example, if the usage condition information sets the usage period as "from May 1, 2024 to May 31, 2024," the usage period management unit 233 performs processing such as stopping the operation of the content 500 or deleting the content 500 from the memory space at the end of May 31, 2024.

[0079] When the device 200 loads the content 500, the content 500 is launched in the memory space as shown in Fig. 9C. At this stage, the content 500 is in an encrypted state and is not in an operable state.

[0080] Next, the content management unit 232 authenticates and decrypts the content 500 using the content decryption key, and puts the content 500 into a plaintext state as shown in Fig. 9D, thereby enabling the executable content 500 to operate.

[0081] Once the content 500 is operable in the memory space, it can access the entire memory space. This may allow the content 500 to obtain information in the memory space, which could be used by the provider of the content 500 to attack other providers or the device 200.

[0082] Therefore, in this technology, when the content management unit 232 becomes operable, the memory management unit 231 restricts the reading of information from the microcomputer storage unit 221, as shown in FIG. 9C . This prevents content from obtaining the system firmware authentication key and the system firmware encryption symmetric key stored in the microcomputer storage unit 221 and the content provider from misusing this information. This protects information that may be subject to misuse. Note that, since key confidentiality is not required in the asymmetric public key signature verification method, there is no need to prohibit or erase the reading of the signature public key. Therefore, when only the signature public key is used as the system firmware authentication key, there is no need to restrict the reading of information from the microcomputer storage unit 221. On the other hand, since the MAC addition symmetric key can also be used to add a MAC during MAC verification, reading of the MAC addition symmetric key must be restricted or erased. Therefore, when only the MAC addition symmetric key is used as the system firmware authentication key, there is a need to restrict the reading of information from the microcomputer storage unit 221. However, even when only the signature public key is used as the system firmware authentication key, other information may be stored in the microcomputer memory unit 221, so reading of information from the microcomputer memory unit 221 may be restricted.

[0083] When the microcomputer storage unit 221 is composed of a boot ROM and an E-Fuse, it is the E-Fuse that needs to be restricted from reading, and restricting reading from the E-Fuse can be achieved, for example, by setting a control register. The control register can be set by a program in the boot ROM, or by the memory management unit 231. Furthermore, restricting reading can be achieved by cutting off the connection to the microcomputer storage unit 221 in hardware, or by a hardware circuit configuration such as returning an invalid value in response to a read request.

[0084] Furthermore, once the content 500 becomes operable in the memory space, the content management unit 232 becomes unnecessary, and the memory management unit 231 deletes the content management unit 232 from the memory space. This prevents the content from acquiring the content decryption key used by the content management unit 232 and misusing the content decryption key by the content provider. This makes it possible to protect information that may be misused.

[0085] Information that is unlikely to be misused and processing units necessary for the operation of the content 500 can be co-located with the content 500 in the memory space of the microcomputer 220. The usage period management unit 233 manages the usage period of the content based on the usage condition information included in the license information, and therefore co-locates and operates with the content 500 in the memory space.

[0086] For the sake of explanation, it is assumed that there is a provider A who provides content A and a provider B who provides content B. The usage period management unit 233 that manages the usage period of content A is referred to as usage period management unit A, and the usage period management unit 233 that manages the usage period of content B is referred to as usage period management unit B.

[0087] The usage period management unit A is necessary to manage the usage period of the content A, and therefore resides together with the content A in the memory space as long as the content A operates in the memory space.

[0088] However, usage period management unit B for content B provided by provider B should not coexist with content A provided by provider A. This is because if usage period management unit B for content B could arbitrarily change the usage period of content A, it would be disadvantageous to provider A and the content distributor. For example, if the usage period of content A, which is originally 30 days, is changed to 100 days by usage period management unit B, content A will be used by users for a longer period than intended by provider A or the content distributor, causing damage to provider A and the content distributor.

[0089] Furthermore, content B should not be run in the memory space where content A and usage period management unit A are running. If content B coexists in the memory space where content A and usage period management unit A are running, usage period management unit A may change the usage period of content B, causing damage to provider B and the content distributor.

[0090] Therefore, it is desirable to operate the content 500 provided by one provider and one usage period management unit 233 that manages the usage period of the content 500 in the memory space.

[0091] However, multiple contents provided by one provider can be made to coexist and operate in the same memory space. As mentioned above, if multiple contents provided by different providers coexist in the same memory space, there is a risk that the usage period of the content may be changed arbitrarily by the usage period management unit 233, but if multiple contents are provided by one provider, such a problem does not arise.

[0092] When device 200 is turned off by a user input or the like, memory management unit 231 resets the memory space to the initial state shown in Fig. 9A. This allows device 200 to run content provided by providers other than the provider of the content that had been running in the memory space until then.

[0093] As described above, the device 200 of the present technology is configured, and the control method is executed in the device 200. According to the present technology, while maintaining content protection by DRM, it is possible to prevent the content provider from acquiring information that could be used to attack the content provider or the device 200, and prevent the content provider from misusing the information. This makes it possible to protect information that could be misused.

[0094] Furthermore, the mechanism for protecting this information can be realized using a general-purpose microcontroller, which is less expensive than an SoC that uses a Memory Management Unit. Because it can be realized using a general-purpose microcontroller, the mechanism of this technology can be incorporated into inexpensive devices such as image sensors and smart cameras.

[0095] In the past, when distributing content with a usage period limited by DRM, a mechanism such as a Memory Management Unit or WASM was required to separate and protect the system code including the DRM from the content code. However, with this technology, since the process of separating the system code including the DRM from the content code is not required, the process of booting the device 200 and loading and launching the content can be performed at high speed. Specifically, the process of booting the device 200 and loading and launching the executable content can be performed at high speed compared to when sandbox technology is used for a microcomputer 220 running an RTOS for the same purpose.

[0096] When designing dedicated hardware or ROM code to separate potentially exploitable information, the versatility and updatable nature of the components employed becomes an issue, but with this technology, such issues do not arise because it can be achieved through processing on a general-purpose microcontroller.Furthermore, with this technology, it is easier to provide, expand, and update firmware-side system code and DRM implementation compared to separation hardware or ROM code.

[0097] With this technology, the native code of executable content can fully utilize the entire CPU of the device 200. Furthermore, developing executable content does not require online invocation of a development tool. Furthermore, online signing of plaintext executable content is also not required.

[0098] By using this technology, executable content can be encrypted and delivered to the user's device 200, and DRM license management such as device binding and usage period restrictions can be performed.

[0099] In the above-described embodiment, the system firmware authentication key and the system firmware encryption symmetric key, which are information stored in the microcomputer storage unit 221, are protected, and the content decryption key, which is information used by the content management unit 232, is also protected. The present technology can further protect any information stored in the microcomputer storage unit 221 or information used by processing units operating in memory space. For example, it is possible to protect content-related know-how, important information in the content distribution system 10 (e.g., Wi-Fi passwords), DRM content decryption keys and authentication keys, firmware encryption keys, firmware secure boot signature keys, and the like, which can be used for content provided by other content providers.

[0100] Also, for example, if device 200 is a smart camera, the information that can be protected includes confidential information of the smart camera installer and user, know-how and integrity regarding content distribution system 10 and content distribution device 100, know-how regarding other companies' applications, and hardware assets and software implementations for system privilege separation and application restriction management.

[0101] A smart camera is a device that combines the functions of a camera and a computer, and is capable of not only taking pictures but also performing advanced image processing and AI processing. In addition, because smart cameras have network connectivity, they can also download applications and updates from the internet.

[0102] Confidential information of the smart camera installer and user includes, for example, the Wi-Fi password at the installation location, authentication information for the cloud service used, client authentication information for the smart camera and sensing-related services using it, DRM authentication keys for smart camera-related services, etc. Situations that should be avoided in this case include the transfer of authentication information by a malicious app, or the unintentional inclusion of the Wi-Fi password in the image memory buffer and being treated as an image file.

[0103] The know-how and integrity related to the content distribution system 10 and the content distribution device 100 include the OS (Operating System), sensor access driver, image processing library, etc. In this case, situations that should be avoided include the reading of library know-how, tampering with the OS and embedding malware, etc.

[0104] The know-how related to content includes the selection of an AI model to solve a specific problem, the weighting of the AI ​​model tuned to the environment, etc. In this case, situations that should be avoided include the theft of the AI ​​model's output and its use for someone else's business.

[0105] Hardware assets and software implementations for system privilege separation and application restriction management include information related to secure boot, Memory Management Unit, Interpreter implementation, etc. Situations to be avoided in this case include situations where the technology for asset protection has vulnerabilities that cannot be addressed, and problems with commercial asset management arise when technology for development purposes is repurposed.

[0106] 2. Modifications Although the embodiments of the present technology have been specifically described above, the present technology is not limited to the above-described embodiments, and various modifications based on the technical ideas of the present technology are possible.

[0107] In the embodiment, the usage period management unit 233 manages the usage period of the content in the memory space of the microcontroller 220, but for example, a processing unit that manages other usage conditions such as how to use the content, a processing unit that controls the enable / disable of multiple additional functions, and a processing unit that controls the enable / disable of output terminals and output formats may also be operated in the memory space in the same manner as the usage period management unit 233.

[0108] In the embodiment, content is distributed from the content distribution device 100 to the device 200 via communication over a network, but content can also be distributed offline. In this case, the content distribution device 100 writes the content and license information to a storage medium such as a flash memory, and the device 200 acquires the content and license information from the storage medium. The subsequent processing is the same as in the embodiment.

[0109] In the content distribution device 100, the content database 113 and the user / device information database 115 may be configured in an external storage device rather than being provided in the content distribution device 100. In this case, the content selection unit 117 and the user / device management unit 114 access the external storage device to acquire the content and device information.

[0110] In the embodiment, it has been described that the device 200 to which the content is to be delivered is selected by the user, but the content delivery apparatus 100 may automatically select the device 200 to which the content is to be delivered, instead of the user selecting the device 200. For example, an AI may determine that a specific type of content should be delivered to a specific type of device 200 based on accumulated information on the relationship between past content and the device 200.

[0111] The present technology may also be configured as follows. (1) A device comprising: a content management unit that operates in a memory space and decrypts content distributed in an encrypted state; a storage unit that stores information for enabling the content management unit; and a memory management unit that protects at least one of the information stored in the storage unit and information used by the content management unit. (2) The device described in (1), in which the memory management unit protects the information stored in the storage unit by restricting reading from the storage unit. (3) The device described in (2), in which the memory management unit restricts reading from the storage unit when the content management unit becomes operable. (4) The device described in any of (1) to (3), in which the memory management unit protects the information used by the content management unit by deleting the content management unit from the memory space. (5) The device described in (4), in which the memory management unit deletes the content management unit from the memory space when the content becomes operable. (6) The device described in any of (1) to (5), in which the memory management unit resets the memory space when the device is turned off. (7) The device according to any one of (1) to (6), wherein the memory management unit is made operable in the memory space using information stored in the storage unit. (8) The device according to any one of (1) to (7), comprising a usage period management unit that manages the usage period of the content based on distributed license information associated with the content. (9) The device according to (8), wherein the usage period management unit is made operable in the memory space using information stored in the storage unit. (10) The device according to any one of (1) to (9), wherein the information used by the content management unit is a content decryption key that is distributed together with the license information of the content. (11) The device according to any one of (1) to (10), comprising a microcomputer, wherein the storage unit is provided in the microcomputer, and wherein the content management unit and the memory management unit operate in the memory space of the microcomputer.(12) The device according to any one of (1) to (11), in which the content is distributed in an encrypted state. (13) The device according to any one of (1) to (12), in which the content is content operable in the memory space. (14) The device according to (13), in which the content is an AI application. (15) A control method in a device, in which a content management unit operable in a memory space using information stored in a storage unit decrypts content distributed in an encrypted state, and protects at least one of the information stored in the storage unit and information used by the content management unit. (16) A content distribution system comprising: a content distribution apparatus that distributes content in an encrypted state; a content management unit operable in a memory space and decrypts content distributed in an encrypted state; a storage unit that stores information for enabling the content management unit to operate; and a memory management unit that protects at least one of the information stored in the storage unit and information used by the content management unit.

[0112] 10... Content distribution system 100... Content distribution device 200... Device 220... Microcomputer 221... Storage unit in microcomputer 231... Memory management unit 232... Content management unit 233... Usage period management unit

Claims

1. A device comprising: a content management unit that operates in memory space and decrypts content distributed in encrypted form; a storage unit that stores information to enable the content management unit to operate; and a memory management unit that protects at least one of the information stored in the storage unit and the information used by the content management unit.

2. The device according to claim 1, wherein the memory management unit protects information stored in the storage unit by restricting reading from the storage unit.

3. The device according to claim 2, wherein the memory management unit restricts reading from the storage unit when the content management unit becomes operational.

4. The device according to claim 1, wherein the memory management unit protects information used by the content management unit by deleting the content management unit from the memory space.

5. The device according to claim 4, wherein the memory management unit deletes the content management unit from the memory space when the content becomes operable.

6. The device according to claim 1, wherein the memory management unit resets the memory space when the device is turned off.

7. The device of claim 1, wherein the memory manager is enabled to operate in the memory space using information stored in the storage unit.

8. The device according to claim 1, further comprising a usage period management unit that manages the usage period of the content based on distributed license information associated with the content.

9. The device according to claim 8, wherein the usage period management unit is enabled to operate in the memory space using information stored in the storage unit.

10. The device according to claim 1, wherein the information used by the content management unit is a content decryption key that is distributed together with the license information of the content.

11. The device according to claim 1, comprising a microcomputer, wherein the storage unit is provided in the microcomputer, and the content management unit and the memory management unit operate in the memory space of the microcomputer.

12. The device of claim 1, wherein the content is delivered in an encrypted state.

13. The device of claim 1, wherein the content is operable in the memory space.

14. The device of claim 13, wherein the content is an AI application.

15. A control method for a device in which a content management unit that is enabled to operate in memory space using information stored in a storage unit decrypts content that has been distributed in an encrypted state, and protects at least one of the information stored in the storage unit and the information used by the content management unit.

16. A content distribution system comprising a device including: a content distribution device that distributes content in an encrypted state; a content management unit that is enabled to operate in memory space and decrypts content distributed in an encrypted state; a memory unit that stores information to enable the content management unit to operate; and a memory management unit that protects at least one of the information stored in the memory unit and the information used by the content management unit.

Citation Information

Patent Citations

  • Semiconductor integrated circuit device

    JP1996185361A

  • Data memory device and data writing device

    JP2001212350A

  • License information generating device and program therefor, distributed content generating device and program therefor, content decoding device and program therefor, and content decoding method

    JP2006121359A

  • Microcomputer

    JP2008003774A