Content Use System with Protected Storage Area for Flash Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current content protection standards, such as AACS, inadequately address unauthorized use of content when transferred between media, particularly from hard disks to flash memory cards like USB memories, lacking sufficient specifications for controlling use on these devices, which can lead to unregulated copying and compromised copyright protection.
Innovation Solution
A content use system that divides storage into protected and general-purpose areas, with access permissions determined by device certificates, where encryption keys are stored in the protected area and output to authorized reproduction devices, using a domain key provided by a management server, ensuring secure content reproduction by verifying media ID verification values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If content is copied from a hard disk to a flash memory card, then content portability and accessibility are improved, but copyright protection and use control are weakened due to insufficient specifications for flash memory devices
Solution Approach 1:
The storage medium is divided into a protected area where encryption keys are stored with restricted access, and a general purpose area for content storage. This segmentation allows portable content storage while maintaining security through differentiated access control mechanisms for different regions of the same medium.
Solution Approach 2:
A management server acts as an intermediary between the content source and the flash memory card, providing use control information and encryption keys. This intermediary ensures that even when content is portably transferred to flash memory, copyright protection is maintained through centralized control mechanisms.
2Reliability
If encryption keys are stored in a protected area with certificate verification, then unauthorized access is prevented, but device complexity and access control overhead increase
Solution Approach 1:
Device certificates and encryption keys are pre-configured in the flash memory card during manufacturing or initialization. This preliminary setup eliminates the need for complex runtime key distribution and certificate management, reducing operational complexity while maintaining security.
Solution Approach 2:
Instead of implementing complex real-time cryptographic verification for every access operation, the system uses pre-verified device certificates that are copied and stored in the protected area. This allows simplified access checks that verify device identity without repeated complex cryptographic operations.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
To realize a configuration to output content to a medium and to use the content stored in the medium under control of the use of content. A content-output-device outputs an encrypted content and an encryption key to be applied to the using process to the medium, and a management server generates a media ID verification value based on a media ID that is an identifier of the medium and transmits the value to the medium. The medium stores the encrypted content, the encryption key, and the media ID verification value in a storage unit. A reproduction device loads the medium and calculates a verification value based on the media ID acquired from the medium, and executes a reproducing process of the encrypted content stored in the medium by data processing to which the encryption key is applied on condition that a matching process performed between the verification value and the media ID verification value stored in the medium is established.