Content Use System with Protected Storage Area for Flash Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current content protection standards, such as AACS, inadequately address unauthorized use of content when transferred between media, particularly from hard disks to flash memory cards like USB memories, lacking sufficient specifications for controlling use on these devices, which can lead to unregulated copying and compromised copyright protection.

Innovation Solution

A content use system that divides storage into protected and general-purpose areas, with access permissions determined by device certificates, where encryption keys are stored in the protected area and output to authorized reproduction devices, using a domain key provided by a management server, ensuring secure content reproduction by verifying media ID verification values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If content is copied from a hard disk to a flash memory card, then content portability and accessibility are improved, but copyright protection and use control are weakened due to insufficient specifications for flash memory devices

Engineering Contradiction:
Improvecontent portabilityVSAvoidcopyright protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The storage medium is divided into a protected area where encryption keys are stored with restricted access, and a general purpose area for content storage. This segmentation allows portable content storage while maintaining security through differentiated access control mechanisms for different regions of the same medium.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A management server acts as an intermediary between the content source and the flash memory card, providing use control information and encryption keys. This intermediary ensures that even when content is portably transferred to flash memory, copyright protection is maintained through centralized control mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption keys are stored in a protected area with certificate verification, then unauthorized access is prevented, but device complexity and access control overhead increase

Engineering Contradiction:
Improveaccess securityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Device certificates and encryption keys are pre-configured in the flash memory card during manufacturing or initialization. This preliminary setup eliminates the need for complex runtime key distribution and certificate management, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Instead of implementing complex real-time cryptographic verification for every access operation, the system uses pre-verified device certificates that are copied and stored in the protected area. This allows simplified access checks that verify device identity without repeated complex cryptographic operations.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP2717185B1Information processing device, information processing method, and program
Publication Date: 2019.09.04 SONY GROUP CORP
  • EP2717185B1 patent drawingFigure 1
  • EP2717185B1 patent drawingFigure 2
  • EP2717185B1 patent drawingFigure 3

AI summary

To realize a configuration to output content to a medium and to use the content stored in the medium under control of the use of content. A content-output-device outputs an encrypted content and an encryption key to be applied to the using process to the medium, and a management server generates a media ID verification value based on a media ID that is an identifier of the medium and transmits the value to the medium. The medium stores the encrypted content, the encryption key, and the media ID verification value in a storage unit. A reproduction device loads the medium and calculates a verification value based on the media ID acquired from the medium, and executes a reproducing process of the encrypted content stored in the medium by data processing to which the encryption key is applied on condition that a matching process performed between the verification value and the media ID verification value stored in the medium is established.