WO2018024061A1 - Method, device and system for licensing shared digital content - Google Patents

Method, device and system for licensing shared digital content Download PDF

Info

Publication number
WO2018024061A1
WO2018024061A1 PCT/CN2017/091220 CN2017091220W WO2018024061A1 WO 2018024061 A1 WO2018024061 A1 WO 2018024061A1 CN 2017091220 W CN2017091220 W CN 2017091220W WO 2018024061 A1 WO2018024061 A1 WO 2018024061A1
Authority
WO
WIPO (PCT)
Prior art keywords
domain
digital content
license
terminal device
copyright management
Prior art date
Application number
PCT/CN2017/091220
Other languages
French (fr)
Chinese (zh)
Inventor
陈懿新
文均荣
张蒲
刘德钱
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Publication of WO2018024061A1 publication Critical patent/WO2018024061A1/en

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F16/00Information retrieval; Database structures therefor; File system structures therefor
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/10Protecting distributed programs or content, e.g. vending or licensing of copyrighted material ; Digital rights management [DRM]
    • G06F21/105Arrangements for software license management or administration, e.g. for managing licenses at corporate level

Landscapes

  • Engineering & Computer Science (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Technology Law (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Multimedia (AREA)
  • Data Mining & Analysis (AREA)
  • Databases & Information Systems (AREA)
  • Storage Device Security (AREA)

Abstract

The present invention relates to the technical field of digital copyright management. A method, device and system for licensing shared digital content is disclosed for resolving a lack of security and auditability in the process of sharing a license in existing terminal equipment. The method comprises: a domain gateway copyright management device receiving a digital content license request sent by terminal equipment (201), the license request comprising an identification (ID) of the digital content; the domain gateway copyright management device acquiring a domain permission according to the ID of the digital content (202), the domain permission comprising a decryption key for digital content encrypted using a public key of the domain gateway copyright management device; the domain gateway copyright management device generating a license for the terminal equipment according to the domain permission (203); sending the license to the terminal equipment (204); and the domain gateway copyright management device sending a license issuing transaction request to a block chain device (205), the license issuing transaction request comprising a domain license transaction ID, a signature of a private key of the domain gateway copyright management device, an address of the terminal equipment and permission information.

Description

一种共享数字内容的许可证的方法、装置及系统Method, device and system for sharing license of digital content
本申请要求于2016年8月2日提交中国专利局、申请号为201610624448.X,发明名称为“一种共享数字内容的许可证的方法、装置及系统”的中国专利申请的优先权,其全部内容通过引用结合在本申请中。This application claims priority to Chinese Patent Application No. 201610624448.X, filed on August 2, 2016, entitled "A Method, Apparatus, and System for Sharing Licenses for Digital Content", The entire contents are incorporated herein by reference.
技术领域Technical field
本发明涉及数字版权管理技术领域,尤其涉及一种共享数字内容的许可证的方法、装置及系统。The present invention relates to the field of digital rights management technologies, and in particular, to a method, device and system for sharing a license for digital content.
背景技术Background technique
数字内容许可权共享,是指将购买的一个数字内容的许可证在多个终端设备之间共享,实现多个终端设备共同访问该数字内容,以提高数字内容的利用效率。The sharing of the digital content permission means that the license of one digital content purchased is shared among the plurality of terminal devices, and the plurality of terminal devices share the digital content to improve the utilization efficiency of the digital content.
目前,常见的实现数字内容许可权共享的两种方法包括:(1)在中心化版权管理系统中增加域的概念,终端设备加入域,与中心化版权管理系统进行交互,域内的终端设备之间可以共享许可证;(2)在终端侧放置本地域管理服务器,负责本地域的创建、终端设备加入域以及许可证的发放,实现域内的终端设备之间的许可证共享。在上述方法中,终端设备共享许可证的过程虽然会被记录,但是由于该记录只存储了一份,很容易被篡改,因此并不是完全可信的,从而使得终端设备共享许可证的过程缺乏安全性且无法被审计。At present, two common methods for realizing the sharing of digital content permission rights include: (1) adding a concept of a domain in a centralized copyright management system, a terminal device joining a domain, interacting with a centralized copyright management system, and terminal devices in the domain (2) The local domain management server is placed on the terminal side, responsible for the creation of the local domain, the joining of the terminal device to the domain, and the issuance of licenses, thereby realizing license sharing between terminal devices in the domain. In the above method, although the process of sharing the license by the terminal device is recorded, since the record is only stored one copy, it is easily falsified, and thus is not completely trusted, so that the process of sharing the license by the terminal device is lacking. Security and cannot be audited.
发明内容Summary of the invention
本发明的实施例提供一种共享数字内容的许可证的方法、装置及系统,用以解决现有的终端设备共享许可证的过程缺乏安全性且无法被审计的问题。Embodiments of the present invention provide a method, apparatus, and system for sharing a license for digital content to solve the problem that the existing terminal device sharing license lacks security and cannot be audited.
为达到上述目的,本发明的实施例采用如下技术方案:In order to achieve the above object, embodiments of the present invention adopt the following technical solutions:
第一方面,提供了一种共享数字内容的许可证的方法,包括:域网关版权管理装置接收终端设备发送的数字内容的许可证请求,许可证请求中包括数字内容的标识ID;域网关版权管理装置根据数字内容的ID获取域许可,域许可包括采用域网关版权管理装置的公钥加密后的数字内容的解密密钥;域网关版权管理装置根据域许可生成终端设备的许可证,并发送给终端设备;域网关版权管理装置向区块链装置发送许可证分发事务请求,许可证分发事务请求包括域许可证事务ID,域网关版权管理装置的私钥的签名,终端设备的地址以及许可信息,以使得区块链装置校验域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造许可证分发事务并将许可证分发事务存储在区块链中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。A first aspect provides a method for sharing a license for digital content, comprising: a domain gateway copyright management device receiving a license request for digital content transmitted by a terminal device, the license request including an identification ID of the digital content; and a domain gateway copyright The management device acquires the domain license according to the ID of the digital content, the domain license includes a decryption key of the digital content encrypted by the public key of the domain gateway copyright management device; the domain gateway copyright management device generates a license of the terminal device according to the domain license, and sends the license To the terminal device; the domain gateway copyright management device transmits a license distribution transaction request to the blockchain device, the license distribution transaction request including the domain license transaction ID, the signature of the private key of the domain gateway copyright management device, the address of the terminal device, and the license Information, so that the blockchain device checks whether the domain license transaction ID exists, whether the signature of the private key of the domain gateway copyright management device is correct, and after the verification is successful, constructs a license distribution transaction and stores the license distribution transaction at In the blockchain, the input to the license distribution transaction includes the domain license transaction ID And the signature of the private key of the domain gateway copyright management device, the output content including the address and license information of the terminal device.
第一方面提供的方法,终端设备在域内共享数字内容的许可证的过程中,会将许可证分发事务在区块链中进行存储,在区块链装置中的每个节点上都会存储有该事务,若其中一个节点需要篡改数据时,需要得到区块链装置中的大多数节点的同意,因此,一般情况下,一旦事务添加到区块链后,就无法更改,并且,由于每个节点上都存储有区块链,一个节点瘫 痪,不会导致区块链数据的丢失,这样区块链数据就具有很强的安全性,保证了数字内容许可证共享过程数据的高安全性,并且每个许可证共享的过程都可以被审计。The first aspect provides a method in which a terminal device stores a license distribution transaction in a blockchain during a process of sharing a license for digital content in a domain, and the node distribution device stores the license distribution transaction at each node in the blockchain device. Transaction, if one of the nodes needs to tamper with the data, it needs to get the consent of most nodes in the blockchain device. Therefore, in general, once the transaction is added to the blockchain, it cannot be changed, and, because each node There are blockchains stored on the top, one node瘫 痪, will not lead to the loss of blockchain data, so blockchain data has a strong security, ensuring high security of digital content license sharing process data, and each license sharing process can be audit.
结合第一方面,在第一种可能的实现方式中,许可证请求中还包括终端设备的地址,在域网关版权管理装置根据数字内容的ID获取域许可之前,方法还包括:域网关版权管理装置根据终端设备的地址确定终端设备为域网关版权管理装置创建的域中的设备。With reference to the first aspect, in a first possible implementation manner, the license request further includes an address of the terminal device, and before the domain gateway copyright management device acquires the domain license according to the ID of the digital content, the method further includes: domain gateway copyright management The device determines, according to the address of the terminal device, the device in the domain created by the terminal device as the domain gateway copyright management device.
结合第一方面的第一种可能的实现方式,在第二种可能的实现方式中,在域网关版权管理装置根据终端设备的地址确定终端设备为域网关版权管理装置创建的域中的设备之后,方法还包括:域网关版权管理装置确定域是否购买过数字内容;若是,域网关版权管理装置根据数字内容的ID获取本地的域许可;若否,域网关版权管理装置向数字内容提供装置发送域许可证颁发请求,域许可证颁发请求包括数字内容的ID、域网关版权管理装置的地址、域标识以及许可信息,以使得数字内容提供装置校验数字内容的ID在数据库中是否存在,在校验成功后,确定域网关版权管理装置的地址对应的帐号并对该帐号进行扣费处理,构造域许可证事务并将域许可证事务向区块链装置发送,从而使得区块链装置将域许可证事务存储在区块链中,数字内容提供装置生成域许可并向域网关版权管理装置发送,域许可证事务的输入内容包括数字内容提供装置的许可证事务ID、数字内容的许可证在数字内容提供装置的许可证事务中的索引以及数字内容提供装置的私钥的签名,域许可证事务的输出内容包括域网关版权管理装置的地址和许可信息。With reference to the first possible implementation manner of the first aspect, in a second possible implementation manner, after the domain gateway copyright management device determines, according to the address of the terminal device, the device in the domain created by the domain gateway copyright management device The method further includes: the domain gateway copyright management device determining whether the domain has purchased the digital content; if so, the domain gateway copyright management device acquires the local domain license based on the ID of the digital content; if not, the domain gateway copyright management device transmits the digital content providing device to the digital content providing device a domain license issuance request, the domain license issuance request includes an ID of the digital content, an address of the domain gateway copyright management device, a domain identifier, and license information to cause the digital content providing device to check whether the ID of the digital content exists in the database, After the verification succeeds, the account corresponding to the address of the domain gateway copyright management device is determined and the account is deducted, the domain license transaction is constructed, and the domain license transaction is sent to the blockchain device, so that the blockchain device will The domain license transaction is stored in the blockchain, and the digital content providing device generates the domain license And transmitting to the domain gateway copyright management device, the input content of the domain license transaction includes a license transaction ID of the digital content providing device, an index of the license of the digital content in the license transaction of the digital content providing device, and the digital content providing device The signature of the private key, the output of the domain license transaction includes the address and license information of the domain gateway copyright management device.
结合第一方面的第二种可能的实现方式,在第三种可能的实现方式中,在域网关版权管理装置根据域许可生成终端设备的许可证之前,方法还包括:域网关版权管理装置判断已使用的数字内容的许可证数目未超过域许可中的许可信息中限制的许可证个数。With reference to the second possible implementation manner of the first aspect, in a third possible implementation manner, before the domain gateway copyright management device generates the license of the terminal device according to the domain license, the method further includes: the domain gateway copyright management device determining The number of licenses for used digital content does not exceed the number of licenses restricted in the license information in the domain license.
结合第一方面,第一方面的第一种可能的实现方式至第三种可能的实现方式中的任一种,在第四种可能的实现方式中,域网关版权管理装置根据域许可生成终端设备的许可证,包括:域网关版权管理装置采用域网关版权管理装置的私钥对域许可中包含的加密后的数字内容的解密密钥进行解密,得到数字内容的解密密钥;域网关版权管理装置采用终端设备的公钥对数字内容的解密密钥进行加密;域网关版权管理装置根据采用终端设备的公钥加密后的数字内容的解密密钥、终端设备的地址、数字内容的ID和许可信息生成终端设备的许可证。With reference to the first aspect, the first possible implementation of the first aspect to any one of the third possible implementation manners, in the fourth possible implementation manner, the domain gateway copyright management apparatus generates the terminal according to the domain license The license of the device includes: the domain gateway copyright management device decrypts the decryption key of the encrypted digital content included in the domain license by using the private key of the domain gateway copyright management device, and obtains the decryption key of the digital content; the domain gateway copyright The management device encrypts the decryption key of the digital content by using the public key of the terminal device; the domain gateway copyright management device decrypts the digital content based on the public key of the terminal device, the address of the terminal device, the ID of the digital content, and The license information generates a license for the terminal device.
结合第一方面,第一方面的第一种可能的实现方式至第四种可能的实现方式中的任一种,在第五种可能的实现方式中,在域网关版权管理装置根据域许可生成终端设备的许可证,并发送给终端设备之后,方法还包括:域网关版权管理装置接收终端设备发送的下发加密数字内容的请求,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;若域购买过数字内容,域网关版权管理装置根据下发加密数字内容的请求向终端设备发送本地保存的加密数字内容;若域未购买过数字内容,域网关版权管理装置根据下发加密数字内容的请求向数字内容提供装置请求下发加密数字内容;域网关版权管理装置将数字内容提供装置下发的加密数字内容在本地进行保存并向终端设备发送。With reference to the first aspect, the first possible implementation manner of the first aspect to any one of the fourth possible implementation manners, in the fifth possible implementation manner, the domain gateway copyright management apparatus generates the domain license according to the domain license After the license of the terminal device is sent to the terminal device, the method further includes: the domain gateway copyright management device receiving the request for sending the encrypted digital content sent by the terminal device, and the encrypted digital content can be decrypted by using the digital content decryption key to obtain the The digital content; if the domain purchases the digital content, the domain gateway copyright management device sends the locally stored encrypted digital content to the terminal device according to the request for sending the encrypted digital content; if the domain has not purchased the digital content, the domain gateway copyright management device issues the digital content The request for encrypting the digital content requests the digital content providing device to deliver the encrypted digital content; the domain gateway copyright management device saves the encrypted digital content delivered by the digital content providing device locally and transmits it to the terminal device.
结合第一方面,第一方面的第一种可能的实现方式至第五种可能的实现方式中的任一种,在第六种可能的实现方式中,在域网关版权管理装置接收终端设备发送的数字内容的许可证请求之前,方法还包括:域网关版权管理装置接收终端设备发送的加入域请求并向区块链装置发送加入域请求,加入域请求包括终端设备的地址、域网关版权管理装置的私钥的签 名、域标识、域网关版权管理装置的地址以及创建域事务ID,以使得区块链装置校验创建域事务的事务ID是否存在、域网关版权管理装置的私钥的签名是否正确、创建域事务的输出内容中的域标识和加入域请求中的域标识是否相同以及终端设备的地址是否符合生成规范,在校验成功后,构造加入域事务并将加入域事务存储在区块链中,加入域事务的输入内容为创建域事务ID和域网关版权管理装置的私钥的签名,输出内容为域网关版权管理装置的地址、终端设备的地址和域标识。With reference to the first aspect, the first possible implementation manner of the first aspect to any one of the fifth possible implementation manners, in the sixth possible implementation manner, the domain gateway copyright management device receives the terminal device to send Before the license request of the digital content, the method further comprises: the domain gateway copyright management device receiving the join domain request sent by the terminal device and sending the join domain request to the blockchain device, the join domain request including the address of the terminal device, the domain gateway copyright management Signing of the device's private key Name, domain identifier, address of the domain gateway copyright management device, and creation of the domain transaction ID, so that the blockchain device verifies whether the transaction ID of the domain transaction is created, whether the signature of the private key of the domain gateway copyright management device is correct, and the domain is created. Whether the domain identifier in the output content of the transaction is the same as the domain identifier in the join domain request and whether the address of the terminal device conforms to the generation specification. After the verification succeeds, constructing the join domain transaction and storing the join domain transaction in the blockchain, The input to the domain transaction is the signature of the domain transaction ID and the private key of the domain gateway copyright management device. The output is the address of the domain gateway copyright management device, the address of the terminal device, and the domain identifier.
该种可能的实现方式,将终端设备加入域的加入域事务存储在区块链中,确保了终端设备加入域的过程数据的高安全性和可审计性。In this possible implementation, the joining domain transaction of the terminal device joining the domain is stored in the blockchain, which ensures high security and auditability of the process data of the terminal device joining the domain.
结合第一方面的第六种可能的实现方式,在第七种可能的实现方式中,在域网关版权管理装置接收终端设备发送的加入域请求并向区块链装置发送加入域请求之前,方法还包括:域网关版权管理装置向区块链装置发送创建域请求,创建域请求包括域网关版权管理装置的地址和域网关版权管理装置的私钥的签名,以使得区块链装置在校验域网关版权管理装置的地址符合生成规范且域网关版权管理装置的私钥的签名正确后,构造创建域事务并将创建域事务存储在区块链中,创建域事务的输入内容为空,输出内容为域网关版权管理装置的私钥的签名、域网关版权管理装置的地址和域标识。With reference to the sixth possible implementation manner of the first aspect, in a seventh possible implementation manner, before the domain gateway copyright management device receives the join domain request sent by the terminal device and sends the join domain request to the blockchain device, the method The method further includes: the domain gateway copyright management device transmitting a create domain request to the blockchain device, the create domain request including the address of the domain gateway copyright management device and the signature of the private key of the domain gateway copyright management device, so that the blockchain device is in the check After the address of the domain gateway copyright management device conforms to the generation specification and the signature of the private key of the domain gateway copyright management device is correct, the domain transaction is created and the domain transaction is created in the blockchain, and the input content of the created domain transaction is empty, and the output is empty. The content is the signature of the private key of the domain gateway copyright management device, the address of the domain gateway copyright management device, and the domain identifier.
该种可能的实现方式,将域网关版权管理装置创建域的创建域事务存储在区块链中,确保了域网关版权管理装置创建域的过程数据的高安全性和可审计性。In this possible implementation, the domain creation transaction of the domain gateway copyright management device creation domain is stored in the blockchain, which ensures the high security and auditability of the process data of the domain gateway copyright management device creation domain.
结合第一方面,第一方面的第一种可能的实现方式至第七种可能的实现方式中的任一种,在第八种可能的实现方式中,该方法还包括:域网关版权管理装置接收退出域请求并向区块链装置发送退出域请求,退出域请求包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,以使得区块链装置校验加入域事务的事务ID是否存在以及域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造退出域事务并将退出域事务存储在区块链中,退出域事务的输入内容包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,输出内容为空。With reference to the first aspect, the first possible implementation manner of the first aspect to any one of the seventh possible implementation manners, in the eighth possible implementation manner, the method further includes: a domain gateway copyright management device Receiving an exit domain request and sending an exit domain request to the blockchain device, the exit domain request including the terminal device joining the domain transaction ID and the signature of the private key of the domain gateway copyright management device, so that the blockchain device verifies the transaction joining the domain transaction Whether the ID exists and the signature of the private key of the domain gateway copyright management device is correct. After the verification succeeds, the exit domain transaction is constructed and the exit domain transaction is stored in the blockchain. The input content of the exit domain transaction includes the terminal device joining the domain. The transaction ID and the signature of the private key of the domain gateway copyright management device, the output content is empty.
该种可能的实现方式,将终端设备退出域的退出域事务存储在区块链中,确保了终端设备退出域的过程数据的高安全性和可审计性。In this possible implementation, the exit domain transaction of the terminal device exiting the domain is stored in the blockchain, which ensures high security and auditability of the process data of the terminal device exiting the domain.
第二方面,提供了一种共享数字内容的许可证的方法,包括:终端设备接收消费者输入的在线使用数字内容的请求;终端设备根据消费者输入的在线使用数字内容的请求向域网关版权管理装置发送许可证请求,以使得域网关版权管理装置获取域许可,根据域许可生成终端设备的许可证,并向终端设备发送;终端设备接收域网关版权管理装置发送的终端设备的许可证,并根据终端设备的许可证获取数字内容。In a second aspect, a method for sharing a license for digital content is provided, comprising: receiving, by a terminal device, a request for online use of digital content input by a consumer; and authenticating the content to the domain gateway according to a request by the consumer for online use of the digital content The management device sends a license request, so that the domain gateway copyright management device acquires the domain license, generates a license of the terminal device according to the domain license, and transmits the license to the terminal device; the terminal device receives the license of the terminal device sent by the domain gateway copyright management device, And obtain digital content according to the license of the terminal device.
第三方面,提供了一种共享数字内容的许可证的方法,包括:区块链装置接收域网关版权管理装置发送的许可证分发事务请求,许可证分发事务请求包括域许可证事务ID,域网关版权管理装置的私钥的签名,终端设备的地址以及许可信息;区块链装置校验域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造许可证分发事务并将许可证分发事务存储在区块链中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。 In a third aspect, a method for sharing a license for digital content is provided, comprising: a blockchain device receiving a license distribution transaction request sent by a domain gateway copyright management device, the license distribution transaction request including a domain license transaction ID, a domain The signature of the private key of the gateway copyright management device, the address of the terminal device and the license information; whether the blockchain device checks whether the domain license transaction ID exists, and whether the signature of the private key of the domain gateway copyright management device is correct, after the verification is successful Constructing a license distribution transaction and storing the license distribution transaction in the blockchain, the input of the license distribution transaction includes the domain license transaction ID and the signature of the private key of the domain gateway copyright management device, and the output includes the terminal device Address and license information.
第四方面,提供了一种共享数字内容的许可证的方法,包括:终端设备向数字内容提供装置发送数字内容的许可证请求,数字内容的许可证请求中包括数字内容的ID、终端设备的地址和终端设备所属的域的域标识,以使得数字内容提供装置校验终端设备所属的域存在、终端设备为该域中的设备以及终端设备的地址符合生成规范,在验证成功后向区块链装置发送许可证分发事务,从而使得区块链装置将许可证分发事务存储在区块链中,数字内容提供装置生成并向终端设备分发数字内容的许可证;终端设备接收数字内容提供装置分发的许可证,许可证包括被终端设备公钥加密后的数字内容解密密钥。A fourth aspect provides a method for sharing a license for digital content, comprising: a terminal device transmitting a license request for digital content to a digital content providing device, wherein the license request for the digital content includes an ID of the digital content, and the terminal device The address and the domain identifier of the domain to which the terminal device belongs, so that the digital content providing device verifies that the domain to which the terminal device belongs, the terminal device is the device in the domain, and the address of the terminal device conforms to the generation specification, and after the verification succeeds, the domain is identified. The chain device transmits a license distribution transaction such that the blockchain device stores the license distribution transaction in the blockchain, the digital content providing device generates and distributes the license of the digital content to the terminal device; the terminal device receives the digital content providing device for distribution The license includes a digital content decryption key encrypted by the terminal device public key.
第四方面提供的方法,当终端设备为域中的设备但是离开域了之后,仍然可以共享数字内容的许可证,满足了终端设备离线共享许可证的需求,并且在共享数字内容的许可证的过程中,会将许可证分发事务在区块链中进行存储,在区块链装置中的每个节点上都会存储有该事务,若其中一个节点需要篡改数据时,需要得到区块链装置中的大多数节点的同意,因此,一般情况下,一旦事务添加到区块链后,就无法更改,并且,由于每个节点上都存储有区块链,一个节点瘫痪,不会导致区块链数据的丢失,这样区块链数据就具有很强的安全性,保证了数字内容许可证共享过程数据的高安全性,并且每个许可证共享的过程都可以被审计。The method provided by the fourth aspect, after the terminal device is a device in the domain but leaves the domain, can still share the license of the digital content, meets the requirement of the terminal device to share the license offline, and is in the license for sharing the digital content. During the process, the license distribution transaction is stored in the blockchain, and the transaction is stored on each node in the blockchain device. If one of the nodes needs to tamper with the data, the blockchain device needs to be obtained. Most nodes agree, so in general, once a transaction is added to the blockchain, it cannot be changed, and since each node has a blockchain stored, one node does not cause a blockchain. The loss of data makes the blockchain data highly secure, ensuring high security of the digital content license sharing process data, and the process of sharing each license can be audited.
结合第四方面,在第一种可能的实现方式中,在终端设备接收数字内容提供装置分发的许可证之后,方法还包括:终端设备根据数字内容的ID向数字内容提供装置请求下发加密数字内容,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;终端设备接收数字内容提供装置下发的加密数字内容;终端设备使用终端设备的私钥对许可证中包括的数字内容的解密密钥进行解密,得到数字内容的解密密钥,再采用数字内容的解密密钥对加密数字内容进行解密,得到数字内容。With reference to the fourth aspect, in a first possible implementation, after the terminal device receives the license distributed by the digital content providing apparatus, the method further includes: the terminal device requests the digital content providing apparatus to send the encrypted digit according to the ID of the digital content. Content, the encrypted digital content can be decrypted by using a digital content decryption key to obtain digital content; the terminal device receives the encrypted digital content delivered by the digital content providing device; and the terminal device uses the private key of the terminal device to the digital content included in the license The decryption key is decrypted to obtain a decryption key for the digital content, and the encrypted digital content is decrypted using the decryption key of the digital content to obtain digital content.
第五方面,提供了一种共享数字内容的许可证的方法,包括:数字内容提供装置接收终端设备发送的数字内容的许可证请求,数字内容的许可证请求包括数字内容的ID、终端设备的地址和终端设备所属的域的域标识;数字内容提供装置校验终端设备所属的域存在、终端设备为该域中的设备以及终端设备的地址符合生成规范;数字内容提供装置向区块链装置发送许可证分发事务,从而使得区块链装置将许可证分发事务存储在区块链中;数字内容提供装置根据数字内容的ID生成并向终端设备分发数字内容的许可证;许可证包括被终端设备公钥加密后的数字内容解密密钥。A fifth aspect provides a method for sharing a license for digital content, comprising: a digital content providing device receiving a license request for digital content transmitted by a terminal device, the license request of the digital content including an ID of the digital content, and a terminal device The address and the domain identifier of the domain to which the terminal device belongs; the digital content providing device verifies that the domain to which the terminal device belongs, the terminal device is the device in the domain, and the address of the terminal device conforms to the generation specification; the digital content providing device to the blockchain device Transmitting a license distribution transaction such that the blockchain device stores the license distribution transaction in the blockchain; the digital content providing device generates and distributes the license of the digital content to the terminal device according to the ID of the digital content; the license includes the terminal The digital content decryption key after the device public key is encrypted.
结合第五方面,在第一种可能的实现方式中,数字内容提供装置根据数字内容的ID生成并向终端设备分发数字内容的许可证,包括:数字内容提供装置根据数字内容的ID获取数字内容的解密密钥;数字内容提供装置采用终端设备的公钥对数字内容的解密密钥进行加密;数字内容提供装置根据加密后的数字内容的解密密钥、终端设备的地址、数字内容的ID和许可信息生成许可证。With reference to the fifth aspect, in a first possible implementation, the digital content providing apparatus generates and distributes the license of the digital content according to the ID of the digital content, including: the digital content providing apparatus acquires the digital content according to the ID of the digital content. a decryption key; the digital content providing device encrypts the decryption key of the digital content by using the public key of the terminal device; the digital content providing device is based on the decrypted key of the encrypted digital content, the address of the terminal device, the ID of the digital content, and The license information generates a license.
结合第五方面或第五方面的第一种可能的实现方式,在数字内容提供装置生成并向终端设备分发数字内容的许可证之后,方法还包括:数字内容提供装置接收终端设备发送的下发加密数字内容的请求,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;数字内容提供装置根据下发加密数字内容的请求向终端设备下发加密数字内容,以使得终端设备获取数字内容。 With the fifth aspect or the first possible implementation manner of the fifth aspect, after the digital content providing apparatus generates and distributes the license of the digital content to the terminal device, the method further includes: the digital content providing apparatus receives the sending by the terminal apparatus The request for encrypting the digital content, the encrypted digital content can be decrypted by using the digital content decryption key to obtain the digital content; the digital content providing device sends the encrypted digital content to the terminal device according to the request for sending the encrypted digital content, so that the terminal device obtains Digital content.
第六方面,提供了一种域网关版权管理装置,包括:接收单元,用于接收终端设备发送的数字内容的许可证请求,许可证请求中包括数字内容的标识ID;获取单元,用于根据数字内容的ID获取域许可,域许可包括采用域网关版权管理装置的公钥加密后的数字内容的解密密钥;生成单元,用于根据域许可生成终端设备的许可证;发送单元,用于将终端设备的许可证发送给终端设备;发送单元,还用于向区块链装置发送许可证分发事务请求,许可证分发事务请求包括域许可证事务ID,域网关版权管理装置的私钥的签名,终端设备的地址以及许可信息,以使得区块链装置校验域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造许可证分发事务并将许可证分发事务存储在区块链中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。The sixth aspect provides a domain gateway copyright management apparatus, including: a receiving unit, configured to receive a license request for digital content sent by a terminal device, where the license request includes an identifier ID of the digital content; and an acquiring unit, configured to The ID of the digital content acquires a domain license, the domain license includes a decryption key of the digital content encrypted by the public key of the domain gateway copyright management device; a generating unit for generating a license of the terminal device according to the domain license; and a transmitting unit for Transmitting a license of the terminal device to the terminal device; the sending unit is further configured to send a license distribution transaction request to the blockchain device, where the license distribution transaction request includes a domain license transaction ID, and a private key of the domain gateway copyright management device The signature, the address of the terminal device, and the license information, so that the blockchain device checks whether the domain license transaction ID exists, whether the signature of the private key of the domain gateway copyright management device is correct, and after the verification succeeds, constructs a license distribution transaction. And store the license distribution transaction in the blockchain. The input of the license distribution transaction includes the domain license. Private key signature card transaction ID and Domain Rights-managed gateway device, the output includes the address of the terminal equipment and licensing information.
该装置中的各个单元用于实现上述方法,因此,该装置的有益效果可以参见上述方法的有益效果,在此不再赘述。The various units in the device are used to implement the above method. Therefore, the beneficial effects of the device can be seen in the beneficial effects of the above method, and details are not described herein again.
结合第六方面,在第一种可能的实现方式中,许可证请求中还包括终端设备的地址,该装置还包括:确定单元,用于根据终端设备的地址确定终端设备为域网关版权管理装置创建的域中的设备。With reference to the sixth aspect, in a first possible implementation, the license request further includes an address of the terminal device, the device further includes: a determining unit, configured to determine, according to the address of the terminal device, the terminal device as a domain gateway copyright management device The device in the created domain.
结合第六方面的第一种可能的实现方式,在第二种可能的实现方式中,所述确定单元,还用于确定域是否购买过数字内容;若是,所述获取单元,具体用于根据数字内容的ID获取本地的域许可;若否,所述发送单元,还用于向数字内容提供装置发送域许可证颁发请求,域许可证颁发请求包括数字内容的ID、域网关版权管理装置的地址、域标识以及许可信息,以使得数字内容提供装置校验数字内容的ID在数据库中是否存在,在校验成功后,确定域网关版权管理装置的地址对应的帐号并对该帐号进行扣费处理,构造域许可证事务并将域许可证事务向区块链装置发送,从而使得区块链装置将域许可证事务存储在区块链中,数字内容提供装置生成域许可并向域网关版权管理装置发送,域许可证事务的输入内容包括数字内容提供装置的许可证事务ID、数字内容的许可证在数字内容提供装置的许可证事务中的索引以及数字内容提供装置的私钥的签名,域许可证事务的输出内容包括域网关版权管理装置的地址和许可信息。In conjunction with the first possible implementation of the sixth aspect, in a second possible implementation, the determining unit is further configured to determine whether the domain has purchased digital content; if yes, the acquiring unit is specifically configured to The ID of the digital content acquires a local domain license; if not, the sending unit is further configured to send a domain license issuance request to the digital content providing device, where the domain license issuance request includes the ID of the digital content, and the domain gateway copyright management device The address, the domain identifier, and the license information, so that the digital content providing device checks whether the ID of the digital content exists in the database. After the verification succeeds, the account corresponding to the address of the domain gateway copyright management device is determined and the account is charged. Processing, constructing a domain license transaction and transmitting the domain license transaction to the blockchain device such that the blockchain device stores the domain license transaction in the blockchain, the digital content providing device generates the domain license and applies the domain license to the domain gateway The management device sends, the input of the domain license transaction includes the license transaction ID of the digital content providing device, and the digital content. License Services license providing device in the digital content indexing and digital signature private key content providing device, output content domain license transaction information, including addresses and domain gateway license Rights-managed device.
结合第六方面的第二种可能的实现方式,在第三种可能的实现方式中,该装置还包括:判断单元,用于判断已使用的数字内容的许可证数目未超过域许可中的许可信息中限制的许可证个数。In conjunction with the second possible implementation of the sixth aspect, in a third possible implementation, the apparatus further includes: a determining unit, configured to determine that the number of licenses of the used digital content does not exceed the license in the domain license The number of licenses restricted in the message.
结合第六方面,第六方面的第一种可能的实现方式至第三种可能的实现方式中的任一种,在第四种可能的实现方式中,生成单元具体用于:采用域网关版权管理装置的私钥对域许可中包含的加密后的数字内容的解密密钥进行解密,得到数字内容的解密密钥;采用终端设备的公钥对数字内容的解密密钥进行加密;根据采用终端设备的公钥加密后的数字内容的解密密钥、终端设备的地址、数字内容的ID和许可信息生成终端设备的许可证。With reference to the sixth aspect, the first possible implementation manner of the sixth aspect to any one of the third possible implementation manners, in the fourth possible implementation manner, the generating unit is specifically configured to: adopt the domain gateway copyright The private key of the management device decrypts the decryption key of the encrypted digital content contained in the domain license to obtain a decryption key of the digital content; and encrypts the decryption key of the digital content by using the public key of the terminal device; The decryption key of the digital content encrypted by the public key of the device, the address of the terminal device, the ID of the digital content, and the license information generate a license of the terminal device.
结合第六方面,第六方面的第一种可能的实现方式至第四种可能的实现方式中的任一种,在第五种可能的实现方式中:接收单元,还用于接收终端设备发送的下发加密数字内容的请求,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;若域购买过数字内容,发送单元还用于根据下发加密数字内容的请求向终端设备发送本地保存的加 密数字内容;若域未购买过数字内容,该装置还包括请求单元,用于根据下发加密数字内容的请求向数字内容提供装置请求下发加密数字内容;该装置还包括存储单元,用于将数字内容提供装置下发的加密数字内容在本地进行保存,发送单元还用于将加密数字内容向终端设备发送。With reference to the sixth aspect, the first possible implementation manner of the sixth aspect, the fourth possible implementation manner, in the fifth possible implementation manner, the receiving unit is further configured to send, by the receiving terminal device The request for encrypting the digital content is performed, and the encrypted digital content can be decrypted by using the digital content decryption key to obtain the digital content; if the domain purchases the digital content, the sending unit is further configured to send the encrypted digital content to the terminal device according to the request Send locally saved plus The digital content; if the domain has not purchased the digital content, the device further includes a requesting unit, configured to request the digital content providing device to deliver the encrypted digital content according to the request for sending the encrypted digital content; the device further includes a storage unit, configured to: The encrypted digital content delivered by the digital content providing device is saved locally, and the sending unit is further configured to send the encrypted digital content to the terminal device.
结合第六方面,第六方面的第一种可能的实现方式至第五种可能的实现方式中的任一种,在第六种可能的实现方式中,发送单元,还用于将接收到的终端设备发送的加入域请求向区块链装置发送,加入域请求包括终端设备的地址、域网关版权管理装置的私钥的签名、域标识、域网关版权管理装置的地址以及创建域事务ID,以使得区块链装置校验创建域事务的事务ID是否存在、域网关版权管理装置的私钥的签名是否正确、创建域事务的输出内容中的域标识和加入域请求中的域标识是否相同以及终端设备的地址是否符合生成规范,在校验成功后,构造加入域事务并将加入域事务存储在区块链中,加入域事务的输入内容为创建域事务ID和域网关版权管理装置的私钥的签名,输出内容为域网关版权管理装置的地址、终端设备的地址和域标识。With reference to the sixth aspect, the first possible implementation manner of the sixth aspect to any one of the fifth possible implementation manners, in the sixth possible implementation manner, the sending unit is further configured to receive the received The joining domain request sent by the terminal device is sent to the blockchain device, and the joining domain request includes the address of the terminal device, the signature of the private key of the domain gateway copyright management device, the domain identifier, the address of the domain gateway copyright management device, and the creation of the domain transaction ID. In order for the blockchain device to verify whether the transaction ID of the domain transaction is created, whether the signature of the private key of the domain gateway copyright management device is correct, whether the domain identifier in the output content of the created domain transaction, and the domain identifier in the join domain request are the same. And whether the address of the terminal device conforms to the generation specification. After the verification succeeds, constructing the join domain transaction and storing the join domain transaction in the blockchain, and inputting the domain transaction input content is creating the domain transaction ID and the domain gateway copyright management device. The signature of the private key, the output content is the address of the domain gateway copyright management device, the address of the terminal device, and the domain identifier.
该种可能的实现方式,将终端设备加入域的加入域事务存储在区块链中,确保了终端设备加入域的过程数据的高安全性和可审计性。In this possible implementation, the joining domain transaction of the terminal device joining the domain is stored in the blockchain, which ensures high security and auditability of the process data of the terminal device joining the domain.
结合第六方面的第六种可能的实现方式,在第七种可能的实现方式中,发送单元,还用于向区块链装置发送创建域请求,创建域请求包括域网关版权管理装置的地址和域网关版权管理装置的私钥的签名,以使得区块链装置在校验域网关版权管理装置的地址符合生成规范且域网关版权管理装置的私钥的签名正确后,构造创建域事务并将创建域事务存储在区块链中,创建域事务的输入内容为空,输出内容为域网关版权管理装置的私钥的签名、域网关版权管理装置的地址和域标识。With reference to the sixth possible implementation manner of the sixth aspect, in a seventh possible implementation, the sending unit is further configured to send a create domain request to the blockchain device, where the domain request includes the address of the domain gateway copyright management device And the signature of the private key of the domain gateway copyright management device, so that the blockchain device constructs the domain transaction after the address of the verification domain gateway copyright management device conforms to the generation specification and the signature of the private key of the domain gateway copyright management device is correct. The created domain transaction is stored in the blockchain, and the input of the created domain transaction is empty, and the output content is the signature of the private key of the domain gateway copyright management device, the address of the domain gateway copyright management device, and the domain identifier.
该种可能的实现方式,将域网关版权管理装置创建域的创建域事务存储在区块链中,确保了域网关版权管理装置创建域的过程数据的高安全性和可审计性。In this possible implementation, the domain creation transaction of the domain gateway copyright management device creation domain is stored in the blockchain, which ensures the high security and auditability of the process data of the domain gateway copyright management device creation domain.
结合第六方面,第六方面的第一种可能的实现方式至第七种可能的实现方式中的任一种,在第八种可能的实现方式中,接收单元,还用于接收退出域请求;发送单元,还用于向区块链装置发送退出域请求,退出域请求包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,以使得区块链装置校验加入域事务的事务ID是否存在以及域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造退出域事务并将退出域事务存储在区块链中,退出域事务的输入内容包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,输出内容为空。With reference to the sixth aspect, the first possible implementation manner of the sixth aspect, the seventh possible implementation manner, in the eighth possible implementation manner, the receiving unit is further configured to receive the exit domain request The sending unit is further configured to send an exit domain request to the blockchain device, where the exit domain request includes the terminal device joining the domain transaction ID and the signature of the private key of the domain gateway copyright management device, so that the blockchain device checks the join domain transaction. Whether the transaction ID exists and the signature of the private key of the domain gateway copyright management device is correct. After the verification is successful, the exit domain transaction is constructed and the exit domain transaction is stored in the blockchain, and the input content of the exit domain transaction includes the terminal device. The domain transaction ID and the signature of the private key of the domain gateway copyright management device are added, and the output content is empty.
该种可能的实现方式,将终端设备退出域的退出域事务存储在区块链中,确保了终端设备退出域的过程数据的高安全性和可审计性。In this possible implementation, the exit domain transaction of the terminal device exiting the domain is stored in the blockchain, which ensures high security and auditability of the process data of the terminal device exiting the domain.
第七方面,提供了一种终端设备,包括:接收单元,用于接收消费者输入的在线使用数字内容的请求;发送单元,用于根据消费者输入的在线使用数字内容的请求向域网关版权管理装置发送许可证请求,以使得域网关版权管理装置获取域许可,根据域许可生成终端设备的许可证,并向终端设备发送;接收单元,还用于接收域网关版权管理装置发送的终端设备的许可证;获取单元,用于根据终端设备的许可证获取数字内容。 A seventh aspect provides a terminal device, comprising: a receiving unit, configured to receive a request for online use of digital content input by a consumer; and a sending unit, configured to apply to the domain gateway according to a request of the online input of the digital content input by the consumer The management device sends a license request, so that the domain gateway copyright management device acquires the domain license, generates a license of the terminal device according to the domain license, and sends the license to the terminal device; and the receiving unit is further configured to receive the terminal device sent by the domain gateway copyright management device. License; an acquisition unit for obtaining digital content based on a license of the terminal device.
第八方面,提供了一种区块链装置,包括:接收单元,用于接收域网关版权管理装置发送的许可证分发事务请求,许可证分发事务请求包括域许可证事务ID,域网关版权管理装置的私钥的签名,终端设备的地址以及许可信息;校验单元,用于校验域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确;构造存储单元,用于在校验成功后,构造许可证分发事务并将许可证分发事务存储在区块链中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。In an eighth aspect, a blockchain device is provided, comprising: a receiving unit, configured to receive a license distribution transaction request sent by a domain gateway copyright management device, the license distribution transaction request includes a domain license transaction ID, and a domain gateway copyright management The signature of the private key of the device, the address of the terminal device and the license information; a verification unit for verifying whether the domain license transaction ID exists, whether the signature of the private key of the domain gateway copyright management device is correct; constructing a storage unit for After the verification is successful, the license distribution transaction is constructed and the license distribution transaction is stored in the blockchain, and the input of the license distribution transaction includes the domain license transaction ID and the signature of the private key of the domain gateway copyright management device, and the output The content includes the address and license information of the terminal device.
第九方面,提供了一种终端设备,包括:发送单元,用于向数字内容提供装置发送数字内容的许可证请求,数字内容的许可证请求中包括数字内容的ID、终端设备的地址和终端设备所属的域的域标识,以使得数字内容提供装置校验终端设备所属的域存在、终端设备为该域中的设备以及终端设备的地址符合生成规范,在验证成功后向区块链装置发送许可证分发事务,从而使得区块链装置将许可证分发事务存储在区块链中,数字内容提供装置生成并向终端设备分发数字内容的许可证;接收单元,用于接收数字内容提供装置分发的许可证,许可证包括被终端设备公钥加密后的数字内容解密密钥。A ninth aspect provides a terminal device, comprising: a transmitting unit, configured to send a license request for digital content to a digital content providing apparatus, wherein the license request of the digital content includes an ID of the digital content, an address of the terminal device, and a terminal The domain identifier of the domain to which the device belongs, so that the digital content providing device verifies that the domain to which the terminal device belongs, the terminal device is the device in the domain, and the address of the terminal device conforms to the generation specification, and sends the packet to the blockchain device after the verification succeeds. The license distributes the transaction such that the blockchain device stores the license distribution transaction in the blockchain, the digital content providing device generates and distributes the license for the digital content to the terminal device, and the receiving unit is configured to receive the digital content providing device for distribution The license includes a digital content decryption key encrypted by the terminal device public key.
该终端设备用于执行上述方法,因此,该终端设备的有益效果可以参见方法部分的有益效果,在此不再赘述。The terminal device is used to perform the foregoing method. Therefore, the beneficial effects of the terminal device can be referred to the beneficial effects of the method part, and details are not described herein again.
结合第九方面,在第一种可能的实现方式中,该装置还包括:请求单元,用于根据数字内容的ID向数字内容提供装置请求下发加密数字内容,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;所述接收单元,还用于接收数字内容提供装置下发的加密数字内容;获取单元,用于使用终端设备的私钥对许可证中包括的数字内容的解密密钥进行解密,得到数字内容的解密密钥,再采用数字内容的解密密钥对加密数字内容进行解密,得到数字内容。In conjunction with the ninth aspect, in a first possible implementation, the apparatus further includes: a requesting unit, configured to request, according to the ID of the digital content, the digital content providing device to deliver the encrypted digital content, and the encrypted digital content can be decrypted by using the digital content Decrypting the key to obtain the digital content; the receiving unit is further configured to receive the encrypted digital content delivered by the digital content providing device; and the acquiring unit is configured to use the private key of the terminal device to the digital content included in the license The decryption key is decrypted to obtain a decryption key of the digital content, and the encrypted digital content is decrypted by using the decryption key of the digital content to obtain digital content.
第十方面,提供了一种数字内容提供装置,包括:接收单元,用于接收终端设备发送的数字内容的许可证请求,数字内容的许可证请求包括数字内容的ID、终端设备的地址和终端设备所属的域的域标识;校验单元,用于校验终端设备所属的域存在、终端设备为该域中的设备以及终端设备的地址符合生成规范;发送单元,用于向区块链装置发送许可证分发事务,从而使得区块链装置将许可证分发事务存储在区块链中;执行单元,用于根据数字内容的ID生成并向终端设备分发数字内容的许可证;许可证包括被终端设备公钥加密后的数字内容解密密钥。According to a tenth aspect, a digital content providing apparatus includes: a receiving unit, configured to receive a license request for digital content transmitted by the terminal device, where the license request of the digital content includes an ID of the digital content, an address of the terminal device, and a terminal The domain identifier of the domain to which the device belongs; the verification unit is configured to verify that the domain to which the terminal device belongs, the terminal device is the device in the domain, and the address of the terminal device conforms to the generation specification; the sending unit is configured to the blockchain device Transmitting a license distribution transaction such that the blockchain device stores the license distribution transaction in the blockchain; an execution unit for generating and distributing a license for the digital content according to the ID of the digital content; the license includes The digital content decryption key after the terminal device public key is encrypted.
结合第十方面,在第一种可能的实现方式中,执行单元,具体用于根据数字内容的ID获取数字内容的解密密钥;采用终端设备的公钥对数字内容的解密密钥进行加密;根据加密后的数字内容的解密密钥、终端设备的地址、数字内容的ID和许可信息生成许可证。With reference to the tenth aspect, in a first possible implementation, the executing unit is specifically configured to acquire a decryption key of the digital content according to the ID of the digital content; and encrypt the decryption key of the digital content by using the public key of the terminal device; A license is generated based on the decrypted key of the encrypted digital content, the address of the terminal device, the ID of the digital content, and the license information.
结合第十方面或第十方面的第一种可能的实现方式,在第二种可能的实现方式中,所述接收单元,还用于接收终端设备发送的下发加密数字内容的请求,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;所述发送单元,还用于根据下发加密数字内容的请求向终端设备下发加密数字内容,以使得终端设备获取数字内容。With reference to the tenth aspect or the first possible implementation manner of the tenth aspect, in a second possible implementation, the receiving unit is further configured to receive a request for sending the encrypted digital content sent by the terminal device, and encrypt the digital The content can be decrypted by using a digital content decryption key to obtain digital content. The sending unit is further configured to send the encrypted digital content to the terminal device according to the request for sending the encrypted digital content, so that the terminal device acquires the digital content.
第十一方面,提供了一种域网关版权管理装置,包括:接收器、存储器、处理器和发送器,接收器,用于接收终端设备发送的数字内容的许可证请求,许可证请求中包括数字内容 的标识ID;存储器用于存储一组代码,处理器根据该代码执行相应的动作,处理器,用于根据数字内容的ID获取域许可,域许可包括采用域网关版权管理装置的公钥加密后的数字内容的解密密钥;根据域许可生成终端设备的许可证;发送器,用于将终端设备的许可证发送给终端设备;向区块链装置发送许可证分发事务请求,许可证分发事务请求包括域许可证事务ID,域网关版权管理装置的私钥的签名,终端设备的地址以及许可信息,以使得区块链装置校验域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造许可证分发事务并将许可证分发事务存储在区块链中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。An eleventh aspect provides a domain gateway copyright management apparatus, including: a receiver, a memory, a processor, and a transmitter, and a receiver, configured to receive a license request for digital content sent by the terminal device, where the license request includes Digital content The identifier ID; the memory is used to store a set of codes, the processor performs a corresponding action according to the code, and the processor is configured to obtain the domain license according to the ID of the digital content, and the domain license includes encrypting the public key by using the domain gateway copyright management device a decryption key of the digital content; generating a license of the terminal device according to the domain license; a sender for transmitting the license of the terminal device to the terminal device; transmitting a license distribution transaction request to the blockchain device, the license distribution transaction The request includes a domain license transaction ID, a signature of the private key of the domain gateway copyright management device, an address of the terminal device, and license information, so that the blockchain device checks whether the domain license transaction ID exists, and the private authority of the domain gateway copyright management device Whether the signature of the key is correct. After the verification is successful, the license distribution transaction is constructed and the license distribution transaction is stored in the blockchain. The input of the license distribution transaction includes the domain license transaction ID and the domain gateway copyright management device. The signature of the private key, the output includes the address and license information of the terminal device.
该装置中的各个器件用于实现上述方法,因此,该装置的有益效果可以参见上述方法的有益效果,在此不再赘述。Each device in the device is used to implement the above method. Therefore, the beneficial effects of the device can be seen in the beneficial effects of the above method, and details are not described herein again.
结合第十一方面,在第一种可能的实现方式中,许可证请求中还包括终端设备的地址,处理器,还用于根据终端设备的地址确定终端设备为域网关版权管理装置创建的域中的设备。With reference to the eleventh aspect, in a first possible implementation, the license request further includes an address of the terminal device, and the processor is further configured to determine, according to the address of the terminal device, the domain created by the terminal device as the domain gateway copyright management device. In the device.
结合第十一方面的第一种可能的实现方式,在第二种可能的实现方式中,处理器,还用于确定域是否购买过数字内容;若是,处理器,具体用于根据数字内容的ID获取本地的域许可;若否,发送器,还用于向数字内容提供装置发送域许可证颁发请求,域许可证颁发请求包括数字内容的ID、域网关版权管理装置的地址、域标识以及许可信息,以使得数字内容提供装置校验数字内容的ID在数据库中是否存在,在校验成功后,确定域网关版权管理装置的地址对应的帐号并对该帐号进行扣费处理,构造域许可证事务并将域许可证事务向区块链装置发送,从而使得区块链装置将域许可证事务存储在区块链中,数字内容提供装置生成域许可并向域网关版权管理装置发送,域许可证事务的输入内容包括数字内容提供装置的许可证事务ID、数字内容的许可证在数字内容提供装置的许可证事务中的索引以及数字内容提供装置的私钥的签名,域许可证事务的输出内容包括域网关版权管理装置的地址和许可信息。In conjunction with the first possible implementation of the eleventh aspect, in a second possible implementation, the processor is further configured to determine whether the domain has purchased the digital content; if yes, the processor is specifically configured to be based on the digital content The ID obtains the local domain license; if not, the sender is further configured to send a domain license issuance request to the digital content providing device, where the domain license issuance request includes the ID of the digital content, the address of the domain gateway copyright management device, the domain identifier, and The license information is such that the digital content providing device checks whether the ID of the digital content exists in the database. After the verification succeeds, the account corresponding to the address of the domain gateway copyright management device is determined and the account is deducted, and the domain license is constructed. And the domain license transaction is sent to the blockchain device, so that the blockchain device stores the domain license transaction in the blockchain, and the digital content providing device generates the domain license and sends the domain license to the domain gateway copyright management device. The input of the license transaction includes the license transaction ID of the digital content providing device, and the license of the digital content is within the number License Rights to provide the device in the index, and digital signatures provide content private means, an output content domain license transaction information, including addresses and domain gateway license Rights-managed device.
结合第十一方面的第二种可能的实现方式,在第三种可能的实现方式中,处理器,还用于判断已使用的数字内容的许可证数目未超过域许可中的许可信息中限制的许可证个数。In conjunction with the second possible implementation of the eleventh aspect, in a third possible implementation, the processor is further configured to determine that the number of licenses of the used digital content does not exceed the limit in the license information in the domain license. The number of licenses.
结合第十一方面,第十一方面的第一种可能的实现方式至第三种可能的实现方式中的任一种,在第四种可能的实现方式中,处理器具体用于:采用域网关版权管理装置的私钥对域许可中包含的加密后的数字内容的解密密钥进行解密,得到数字内容的解密密钥;采用终端设备的公钥对数字内容的解密密钥进行加密;根据采用终端设备的公钥加密后的数字内容的解密密钥、终端设备的地址、数字内容的ID和许可信息生成终端设备的许可证。With reference to the eleventh aspect, the first possible implementation manner of the eleventh aspect to any one of the third possible implementation manners, in the fourth possible implementation manner, the processor is specifically configured to: adopt a domain The private key of the gateway copyright management device decrypts the decryption key of the encrypted digital content contained in the domain license to obtain a decryption key of the digital content; and encrypts the decryption key of the digital content by using the public key of the terminal device; The license of the terminal device is generated using the decryption key of the digital content encrypted by the public key of the terminal device, the address of the terminal device, the ID of the digital content, and the license information.
结合第十一方面,第十一方面的第一种可能的实现方式至第四种可能的实现方式中的任一种,在第五种可能的实现方式中:接收器,还用于接收终端设备发送的下发加密数字内容的请求,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;若域购买过数字内容,发送器还用于根据下发加密数字内容的请求向终端设备发送本地保存的加密数字内容;若域未购买过数字内容,处理器,还用于根据下发加密数字内容的请求向数字 内容提供装置请求下发加密数字内容;将数字内容提供装置下发的加密数字内容在本地进行保存,发送器还用于将加密数字内容向终端设备发送。With reference to the eleventh aspect, the first possible implementation manner of the eleventh aspect to any one of the fourth possible implementation manners, in a fifth possible implementation manner, the receiver is further configured to receive the terminal The device sends a request for transmitting the encrypted digital content, and the encrypted digital content can be decrypted by using the digital content decryption key to obtain the digital content; if the domain purchases the digital content, the sender is further used to send the encrypted digital content according to the request The terminal device sends the locally stored encrypted digital content; if the domain has not purchased the digital content, the processor is also used to send the digital image according to the request for the encrypted digital content. The content providing device requests to send the encrypted digital content; the encrypted digital content delivered by the digital content providing device is locally saved, and the transmitter is further configured to send the encrypted digital content to the terminal device.
结合第十一方面,第十一方面的第一种可能的实现方式至第五种可能的实现方式中的任一种,在第六种可能的实现方式中,发送器,还用于将接收到的终端设备发送的加入域请求向区块链装置发送,加入域请求包括终端设备的地址、域网关版权管理装置的私钥的签名、域标识、域网关版权管理装置的地址以及创建域事务ID,以使得区块链装置校验创建域事务的事务ID是否存在、域网关版权管理装置的私钥的签名是否正确、创建域事务的输出内容中的域标识和加入域请求中的域标识是否相同以及终端设备的地址是否符合生成规范,在校验成功后,构造加入域事务并将加入域事务存储在区块链中,加入域事务的输入内容为创建域事务ID和域网关版权管理装置的私钥的签名,输出内容为域网关版权管理装置的地址、终端设备的地址和域标识。With reference to the eleventh aspect, the first possible implementation manner of the eleventh aspect to any one of the fifth possible implementation manners, in the sixth possible implementation manner, the transmitter is further configured to receive The joining domain request sent by the terminal device is sent to the blockchain device, and the domain request includes the address of the terminal device, the signature of the private key of the domain gateway copyright management device, the domain identifier, the address of the domain gateway copyright management device, and the creation of the domain transaction. ID, such that the blockchain device verifies whether the transaction ID of the created domain transaction exists, whether the signature of the private key of the domain gateway copyright management device is correct, the domain identifier in the output content of the created domain transaction, and the domain identifier in the join domain request Whether the same and the address of the terminal device meet the generation specification. After the verification succeeds, construct the join domain transaction and store the join domain transaction in the blockchain. The input of the join domain transaction is to create the domain transaction ID and the domain gateway copyright management. The signature of the private key of the device, and the output content is the address of the domain gateway copyright management device, the address of the terminal device, and the domain identifier.
该种可能的实现方式,将终端设备加入域的加入域事务存储在区块链中,确保了终端设备加入域的过程数据的高安全性和可审计性。In this possible implementation, the joining domain transaction of the terminal device joining the domain is stored in the blockchain, which ensures high security and auditability of the process data of the terminal device joining the domain.
结合第十一方面的第六种可能的实现方式,在第七种可能的实现方式中,发送器,还用于向区块链装置发送创建域请求,创建域请求包括域网关版权管理装置的地址和域网关版权管理装置的私钥的签名,以使得区块链装置在校验域网关版权管理装置的地址符合生成规范且域网关版权管理装置的私钥的签名正确后,构造创建域事务并将创建域事务存储在区块链中,创建域事务的输入内容为空,输出内容为域网关版权管理装置的私钥的签名、域网关版权管理装置的地址和域标识。With reference to the sixth possible implementation manner of the eleventh aspect, in a seventh possible implementation, the transmitter is further configured to send a create domain request to the blockchain device, where the domain request includes a domain gateway copyright management device The address and the signature of the private key of the domain gateway copyright management device, so that the blockchain device constructs the domain transaction after the address of the verification domain gateway copyright management device conforms to the generation specification and the signature of the private key of the domain gateway copyright management device is correct. The created domain transaction is stored in the blockchain, and the input of the created domain transaction is empty, and the output content is the signature of the private key of the domain gateway copyright management device, the address of the domain gateway copyright management device, and the domain identifier.
该种可能的实现方式,将域网关版权管理装置创建域的创建域事务存储在区块链中,确保了域网关版权管理装置创建域的过程数据的高安全性和可审计性。In this possible implementation, the domain creation transaction of the domain gateway copyright management device creation domain is stored in the blockchain, which ensures the high security and auditability of the process data of the domain gateway copyright management device creation domain.
结合第十一方面,第十一方面的第一种可能的实现方式至第七种可能的实现方式中的任一种,在第八种可能的实现方式中,接收器,还用于接收退出域请求;发送器,还用于向区块链装置发送退出域请求,退出域请求包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,以使得区块链装置校验加入域事务的事务ID是否存在以及域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造退出域事务并将退出域事务存储在区块链中,退出域事务的输入内容包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,输出内容为空。With reference to the eleventh aspect, the first possible implementation manner of the eleventh aspect, the seventh possible implementation manner, in the eighth possible implementation manner, the receiver is further configured to receive the exit The domain request; the sender is further configured to send an exit domain request to the blockchain device, where the exit domain request includes the terminal device joining the domain transaction ID and the signature of the private key of the domain gateway copyright management device, so that the blockchain device checks to join Whether the transaction ID of the domain transaction exists and the signature of the private key of the domain gateway copyright management device is correct. After the verification succeeds, the exit domain transaction is constructed and the exit domain transaction is stored in the blockchain, and the input of the exit domain transaction includes The terminal device joins the domain transaction ID and the signature of the private key of the domain gateway copyright management device, and the output content is empty.
该种可能的实现方式,将终端设备退出域的退出域事务存储在区块链中,确保了终端设备退出域的过程数据的高安全性和可审计性。In this possible implementation, the exit domain transaction of the terminal device exiting the domain is stored in the blockchain, which ensures high security and auditability of the process data of the terminal device exiting the domain.
第十二方面,提供了一种终端设备,包括:接收器、发送器、存储器和处理器,接收器,用于接收消费者输入的在线使用数字内容的请求;发送器,用于根据消费者输入的在线使用数字内容的请求向域网关版权管理装置发送许可证请求,以使得域网关版权管理装置获取域许可,根据域许可生成终端设备的许可证,并向终端设备发送;接收器,还用于接收域网关版权管理装置发送的终端设备的许可证;存储器用于存储一组代码,处理器根据该代码执行以下动作:根据终端设备的许可证获取数字内容。According to a twelfth aspect, a terminal device includes: a receiver, a transmitter, a memory, and a processor, a receiver for receiving a request for online use of digital content input by a consumer, and a transmitter for The input request for using the digital content online sends a license request to the domain gateway copyright management device, so that the domain gateway copyright management device acquires the domain license, generates a license of the terminal device according to the domain license, and transmits the license to the terminal device; And a memory for storing a license of the terminal device sent by the domain gateway copyright management device; the memory is configured to store a set of codes, and the processor performs the following actions according to the code: acquiring the digital content according to the license of the terminal device.
第十三方面,提供了一种区块链装置,包括:接收器、存储器和处理器,接收器,用于 接收域网关版权管理装置发送的许可证分发事务请求,许可证分发事务请求包括域许可证事务ID,域网关版权管理装置的私钥的签名,终端设备的地址以及许可信息;存储器用于存储一组代码,处理器根据该代码执行以下动作:校验域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确;在校验成功后,构造许可证分发事务并将许可证分发事务存储在区块链中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。A thirteenth aspect, a blockchain device comprising: a receiver, a memory and a processor, and a receiver for Receiving a license distribution transaction request sent by the domain gateway copyright management device, the license distribution transaction request includes a domain license transaction ID, a signature of a private key of the domain gateway copyright management device, an address of the terminal device, and license information; and the memory is used to store one The group code according to which the processor performs the following actions: verifying whether the domain license transaction ID exists, whether the signature of the private key of the domain gateway copyright management device is correct; after the verification is successful, constructing a license distribution transaction and the license The distribution transaction is stored in the blockchain, and the input of the license distribution transaction includes the domain license transaction ID and the signature of the private key of the domain gateway copyright management device, and the output includes the address of the terminal device and the license information.
第十四方面,提供了一种终端设备,包括:发送器和接收器,发送器,用于向数字内容提供装置发送数字内容的许可证请求,数字内容的许可证请求中包括数字内容的ID、终端设备的地址和终端设备所属的域的域标识,以使得数字内容提供装置校验终端设备所属的域存在、终端设备为该域中的设备以及终端设备的地址符合生成规范,在验证成功后向区块链装置发送许可证分发事务,从而使得区块链装置将许可证分发事务存储在区块链中,数字内容提供装置生成并向终端设备分发数字内容的许可证;接收器,用于接收数字内容提供装置分发的许可证,许可证包括被终端设备公钥加密后的数字内容解密密钥。According to a fourteenth aspect, a terminal device includes: a transmitter and a receiver, a transmitter, a license request for transmitting digital content to a digital content providing device, and a license request for the digital content includes an ID of the digital content The address of the terminal device and the domain identifier of the domain to which the terminal device belongs, so that the digital content providing device verifies that the domain to which the terminal device belongs, the terminal device is the device in the domain, and the address of the terminal device conforms to the generation specification, and the verification succeeds. The backward blockchain device transmits a license distribution transaction such that the blockchain device stores the license distribution transaction in the blockchain, and the digital content providing device generates and distributes the license for the digital content to the terminal device; the receiver uses Receiving a license distributed by the digital content providing device, the license includes a digital content decryption key encrypted by the terminal device public key.
该终端设备用于执行上述方法,因此,该终端设备的有益效果可以参见方法部分的有益效果,在此不再赘述。The terminal device is used to perform the foregoing method. Therefore, the beneficial effects of the terminal device can be referred to the beneficial effects of the method part, and details are not described herein again.
结合第十四方面,在第一种可能的实现方式中,该装置还包括:存储器和处理器,存储器用于存储一组代码,处理器根据该代码执行以下动作:根据数字内容的ID向数字内容提供装置请求下发加密数字内容,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;接收器,还用于接收数字内容提供装置下发的加密数字内容;处理器,还用于使用终端设备的私钥对许可证中包括的数字内容的解密密钥进行解密,得到数字内容的解密密钥,再采用数字内容的解密密钥对加密数字内容进行解密,得到数字内容。In conjunction with the fourteenth aspect, in a first possible implementation, the apparatus further includes: a memory and a processor, the memory is configured to store a set of codes, and the processor performs the following actions according to the code: the digital number according to the ID of the digital content The content providing device requests to deliver the encrypted digital content, and the encrypted digital content can be decrypted by using the digital content decryption key to obtain the digital content; the receiver is further configured to receive the encrypted digital content delivered by the digital content providing device; the processor further The decryption key of the digital content included in the license is decrypted by using the private key of the terminal device to obtain a decryption key of the digital content, and the encrypted digital content is decrypted by using the decryption key of the digital content to obtain digital content.
第十五方面,提供了一种数字内容提供装置,包括:接收器、存储器、处理器和发送器,接收器,用于接收终端设备发送的数字内容的许可证请求,数字内容的许可证请求包括数字内容的ID、终端设备的地址和终端设备所属的域的域标识;存储器用于存储一组代码,处理器根据该代码执行以下动作:校验终端设备所属的域存在、终端设备为该域中的设备以及终端设备的地址符合生成规范;发送器,用于向区块链装置发送许可证分发事务,从而使得区块链装置将许可证分发事务存储在区块链中;处理器,还用于根据数字内容的ID生成并向终端设备分发数字内容的许可证;许可证包括被终端设备公钥加密后的数字内容解密密钥。According to a fifteenth aspect, a digital content providing apparatus includes: a receiver, a memory, a processor, and a transmitter, a receiver, a license request for receiving digital content sent by the terminal device, and a license request for the digital content. The ID of the digital content, the address of the terminal device, and the domain identifier of the domain to which the terminal device belongs; the memory is configured to store a set of codes, and the processor performs the following actions according to the code: verifying that the domain to which the terminal device belongs, and the terminal device is the The device in the domain and the address of the terminal device conform to the generation specification; the sender is configured to send a license distribution transaction to the blockchain device, so that the blockchain device stores the license distribution transaction in the blockchain; the processor, A license for generating and distributing digital content to the terminal device based on the ID of the digital content; the license includes a digital content decryption key encrypted by the terminal device public key.
结合第十五方面,在第一种可能的实现方式中,处理器,具体用于根据数字内容的ID获取数字内容的解密密钥;采用终端设备的公钥对数字内容的解密密钥进行加密;根据加密后的数字内容的解密密钥、终端设备的地址、数字内容的ID和许可信息生成许可证。With reference to the fifteenth aspect, in a first possible implementation, the processor is specifically configured to acquire a decryption key of the digital content according to the ID of the digital content; and encrypt the decryption key of the digital content by using the public key of the terminal device The license is generated based on the decrypted key of the encrypted digital content, the address of the terminal device, the ID of the digital content, and the license information.
结合第十五方面或第十五方面的第一种可能的实现方式,在第二种可能的实现方式中,所述接收器,还用于接收终端设备发送的下发加密数字内容的请求,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;所述发送器,还用于根据下发加密数字内容的请求向终端设备下发加密数字内容,以使得终端设备获取数字内容。With reference to the fifteenth aspect or the first possible implementation manner of the fifteenth aspect, in a second possible implementation, the receiver is further configured to receive a request for sending the encrypted digital content sent by the terminal device, The encrypted digital content can be decrypted by using a digital content decryption key to obtain digital content. The transmitter is further configured to send the encrypted digital content to the terminal device according to the request for sending the encrypted digital content, so that the terminal device acquires the digital content. .
第十六方面,提供了一种共享数字内容的许可证的系统,包括:域网关版权管理装置和区块链装置,其中,域网关版权管理装置用于执行第一方面提供的任一种方法,区块链装置用于:校验许可证分发事务请求中的域许可证事务ID是否存在,域网关版权管理装置的私钥 的签名是否正确,在校验成功后,构造许可证分发事务并将许可证分发事务存储在区块链中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。A sixteenth aspect, a system for sharing a license for digital content, comprising: a domain gateway copyright management device and a blockchain device, wherein the domain gateway copyright management device is configured to perform any of the methods provided by the first aspect The blockchain device is configured to: verify whether the domain license transaction ID in the license distribution transaction request exists, and the private key of the domain gateway copyright management device The signature is correct. After the verification is successful, the license distribution transaction is constructed and the license distribution transaction is stored in the blockchain. The input of the license distribution transaction includes the domain license transaction ID and the private content of the domain gateway copyright management device. The signature of the key, the output content including the address and license information of the terminal device.
该系统中的装置用于实现上述方法,因此,该系统的有益效果可以参见上述方法部分的有益效果,在此不再赘述。The device in the system is used to implement the above method. Therefore, the beneficial effects of the system can be seen in the beneficial effects of the above method, and details are not described herein again.
结合第十六方面,在第一种可能的实现方式中,区块链装置还用于:接收域网关版权管理装置发送的加入域请求,加入域请求包括终端设备的地址、域网关版权管理装置的私钥的签名、域标识、域网关版权管理装置的地址以及创建域事务ID;校验创建域事务的事务ID是否存在、域网关版权管理装置的私钥的签名是否正确、创建域事务的输出内容中的域标识和加入域请求中的域标识是否相同以及终端设备的地址是否符合生成规范,在校验成功后,构造加入域事务并将加入域事务存储在区块链中,加入域事务的输入内容为创建域事务ID和域网关版权管理装置的私钥的签名,输出内容为域网关版权管理装置的地址、终端设备的地址和域标识。With reference to the sixteenth aspect, in a first possible implementation, the blockchain device is further configured to: receive a join domain request sent by the domain gateway copyright management device, where the join domain request includes the address of the terminal device, and the domain gateway copyright management device The signature of the private key, the domain identifier, the address of the domain gateway copyright management device, and the creation of the domain transaction ID; verify whether the transaction ID of the domain transaction is created, whether the signature of the private key of the domain gateway copyright management device is correct, and the creation of the domain transaction Whether the domain identifier in the output content and the domain identifier in the join domain request are the same and whether the address of the terminal device conforms to the generation specification. After the verification succeeds, constructing the join domain transaction and storing the join domain transaction in the blockchain, joining the domain The input of the transaction is the signature of the domain transaction ID and the private key of the domain gateway copyright management device, and the output content is the address of the domain gateway copyright management device, the address of the terminal device, and the domain identifier.
结合第十六方面或第十六方面的第一种可能的实现方式,在第二种可能的实现方式中,区块链装置还用于:接收域网关版权管理装置发送的创建域请求,创建域请求包括域网关版权管理装置的地址和域网关版权管理装置的私钥的签名;校验域网关版权管理装置的地址是否符合生成规范且域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造创建域事务并将创建域事务存储在区块链中,创建域事务的输入内容为空,输出内容为域网关版权管理装置的私钥的签名、域网关版权管理装置的地址和域标识。In conjunction with the sixteenth aspect or the first possible implementation manner of the sixteenth aspect, in a second possible implementation, the blockchain device is further configured to: receive a create domain request sent by the domain gateway copyright management device, and create The domain request includes the address of the domain gateway copyright management device and the signature of the private key of the domain gateway copyright management device; whether the address of the domain gateway copyright management device conforms to the generation specification and the signature of the private key of the domain gateway copyright management device is correct, After the verification is successful, the domain transaction is created and the domain transaction is stored in the blockchain. The input of the domain transaction is empty, and the output is the signature of the private key of the domain gateway copyright management device, and the domain gateway copyright management device Address and domain ID.
结合第十六方面、第十六方面的第一种可能的实现方式或第二种可能的实现方式,在第三种可能的实现方式中,区块链装置还用于:接收域网关版权管理装置发送的退出域请求,退出域请求包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名;校验加入域事务的事务ID是否存在以及域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造退出域事务并将退出域事务存储在区块链中,退出域事务的输入内容包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,输出内容为空。In conjunction with the sixteenth aspect, the first possible implementation manner of the sixteenth aspect, or the second possible implementation manner, in a third possible implementation manner, the blockchain apparatus is further configured to: receive domain gateway copyright management The exit domain request sent by the device, the exit domain request includes the signature of the terminal device joining the domain transaction ID and the private key of the domain gateway copyright management device; verifying whether the transaction ID of the domain transaction is present and the signature of the private key of the domain gateway copyright management device Is it correct, after the verification is successful, construct the exit domain transaction and store the exit domain transaction in the blockchain, the input content of the exit domain transaction includes the signature of the terminal device joining the domain transaction ID and the private key of the domain gateway copyright management device, The output is empty.
附图说明DRAWINGS
为了更清楚地说明本发明实施例或现有技术中的技术方案,下面将对实施例或现有技术描述中所需要使用的附图作简单地介绍,显而易见地,下面描述中的附图仅仅是本发明的一些实施例,对于本领域普通技术人员来讲,在不付出创造性劳动的前提下,还可以根据这些附图获得其他的附图。In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings used in the embodiments or the description of the prior art will be briefly described below. Obviously, the drawings in the following description are only It is a certain embodiment of the present invention, and other drawings can be obtained from those skilled in the art without any creative work.
图1为本发明实施例提供的一种系统架构组成示意图;FIG. 1 is a schematic structural diagram of a system architecture according to an embodiment of the present invention;
图2为本发明实施例提供的一种共享数字内容的许可证的方法的交互流程图;2 is an interaction flowchart of a method for sharing a license for digital content according to an embodiment of the present invention;
图3为本发明实施例提供的又一种共享数字内容的许可证的方法的交互流程图;3 is an interaction flowchart of still another method for sharing a license for digital content according to an embodiment of the present invention;
图4为本发明实施例提供的又一种共享数字内容的许可证的方法的交互流程图;4 is an interaction flowchart of still another method for sharing a license for digital content according to an embodiment of the present invention;
图5为本发明实施例提供的又一种共享数字内容的许可证的方法的交互流程图; 5 is an interaction flowchart of still another method for sharing a license for digital content according to an embodiment of the present invention;
图6为本发明实施例提供的一种域网关版权管理装置创建域的方法的交互流程图;FIG. 6 is an interaction flowchart of a method for creating a domain by a domain gateway copyright management apparatus according to an embodiment of the present invention;
图7为本发明实施例提供的一种终端设备加入域的方法的交互流程图;FIG. 7 is an interaction flowchart of a method for a terminal device to join a domain according to an embodiment of the present disclosure;
图8为本发明实施例提供的一种终端设备退出域的方法的交互流程图;FIG. 8 is an interaction flowchart of a method for a terminal device to exit a domain according to an embodiment of the present disclosure;
图9为本发明实施例提供的一种域网关版权管理装置的组成示意图;FIG. 9 is a schematic structural diagram of a domain gateway copyright management apparatus according to an embodiment of the present invention;
图10为本发明实施例提供的又一种域网关版权管理装置的组成示意图;FIG. 10 is a schematic structural diagram of another domain gateway copyright management apparatus according to an embodiment of the present disclosure;
图11为本发明实施例提供的又一种域网关版权管理装置的组成示意图;FIG. 11 is a schematic structural diagram of another domain gateway copyright management apparatus according to an embodiment of the present disclosure;
图12为本发明实施例提供的一种区块链装置的组成示意图;FIG. 12 is a schematic structural diagram of a blockchain device according to an embodiment of the present invention;
图13为本发明实施例提供的又一种区块链装置的组成示意图;FIG. 13 is a schematic structural diagram of still another blockchain device according to an embodiment of the present invention;
图14为本发明实施例提供的一种终端设备的组成示意图;FIG. 14 is a schematic structural diagram of a terminal device according to an embodiment of the present disclosure;
图15为本发明实施例提供的又一种终端设备的组成示意图;FIG. 15 is a schematic structural diagram of still another terminal device according to an embodiment of the present disclosure;
图16为本发明实施例提供的又一种终端设备的组成示意图;FIG. 16 is a schematic structural diagram of still another terminal device according to an embodiment of the present disclosure;
图17为本发明实施例提供的一种数字内容提供装置的组成示意图;FIG. 17 is a schematic structural diagram of a digital content providing apparatus according to an embodiment of the present invention;
图18为本发明实施例提供的又一种数字内容提供装置的组成示意图;FIG. 18 is a schematic structural diagram of still another digital content providing apparatus according to an embodiment of the present invention;
图19为本发明实施例提供的一种共享数字内容的许可证的系统的组成示意图。FIG. 19 is a schematic structural diagram of a system for sharing a license for digital content according to an embodiment of the present invention.
具体实施方式detailed description
下面将结合本发明实施例中的附图,对本发明实施例中的技术方案进行清楚、完整地描述,显然,所描述的实施例仅仅是本发明一部分实施例,而不是全部的实施例。基于本发明中的实施例,本领域普通技术人员在没有做出创造性劳动前提下所获得的所有其他实施例,都属于本发明保护的范围。The technical solutions in the embodiments of the present invention are clearly and completely described in the following with reference to the accompanying drawings in the embodiments of the present invention. It is obvious that the described embodiments are only a part of the embodiments of the present invention, but not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts are within the scope of the present invention.
本发明实施例提供的方法主要用于实现局域网中的终端设备之间的数字内容许可证的共享。如图1所示,为本发明实施例提供的一种用于实现本发明实施例提供的方法的系统架构图,包括:终端设备、域网关管理客户端、域网关、区块链装置以及数字内容提供装置,其中,终端设备、域网关管理客户端和域网关置于局域网中,区块链装置以及数字内容提供装置置于外部网络中,数字内容提供装置可以由内容分发商、数字内容的创作者或版权所有人提供,内容分发商是为消费者(即终端设备服务的用户)提供数字内容服务的组织,可以将数字内容分发到最终消费者,通常来说,内容分发商是经营数字内容的商业机构。例如:视频传播机构,文学作品传播机构或者音乐传播机构。数字内容提供装置用于提供数字内容。The method provided by the embodiment of the present invention is mainly used to implement sharing of digital content licenses between terminal devices in a local area network. As shown in FIG. 1 , a system architecture diagram for implementing the method provided by the embodiment of the present invention includes: a terminal device, a domain gateway management client, a domain gateway, a blockchain device, and a digital device. a content providing device, wherein the terminal device, the domain gateway management client and the domain gateway are placed in the local area network, the blockchain device and the digital content providing device are placed in the external network, and the digital content providing device can be provided by the content distributor, the digital content Provided by the creator or copyright owner, the content distributor is an organization that provides digital content services to consumers (ie, users of terminal devices) that can distribute digital content to the final consumer. Typically, content distributors are operating figures. Content of the business organization. For example: video communication agencies, literary communication agencies or music communication agencies. The digital content providing device is for providing digital content.
具体的,终端设备上可以安装版权管理客户端,终端设备具体可以为智能电视、智能手机、平板电脑、机顶盒以及其他智能终端等,版权管理客户端中可以存储数字内容的ID(Ident ity,标识),数字内容的ID是根据某个hash(哈希)算法,对数字内容与版权所有人(版权所有人为拥有数字内容版权的自然人、法人或者社会机构)的地址进行hash运算得到的hash值,数字内容的ID用于标识数字内容的唯一性。Specifically, the copyright management client may be installed on the terminal device, and the terminal device may specifically be a smart TV, a smart phone, a tablet computer, a set top box, and other smart terminals, and the ID (Identity) of the digital content may be stored in the copyright management client. The ID of the digital content is a hash value obtained by hashing the address of the digital content and the copyright holder (the copyright owner is a natural person, a legal person or a social institution having the copyright of the digital content) according to a hash algorithm. The ID of the digital content is used to identify the uniqueness of the digital content.
域网关是使家庭、办公室或学校内部多种智能设备之间实现联网,以及从家庭、办公室 或学校内部到外部网络实现联网的设备。域网关包括版权区块链处理安全芯片和数据存储服务模块。版权区块链处理安全芯片具体包括基于域的许可证管理控制和区块链基础能力模块,基于域的许可证管理控制用于负责域的创建、终端设备加入域和退出域的处理及域策略的控制、域许可证管理控制,区块链基础能力模块可以与区块链装置进行网络通信。数据存储服务模块包括:数字内容下载客户端和数字内容存储模块,数字内容下载客户端负责从数字内容提供装置处下载数字内容,数字内容存储模块负责存储下载下来的数字内容。在本发明提供的实施例中将版权区块链处理安全芯片和数据存储服务模块统称为域网关版权管理装置。Domain gateways enable networking between multiple smart devices in a home, office or school, as well as from homes and offices. Or devices that are networked internally to the school. The domain gateway includes a copyright blockchain processing security chip and a data storage service module. The copyright blockchain processing security chip specifically includes a domain-based license management control and a blockchain basic capability module, and the domain-based license management control is used for responsible domain creation, terminal device joining domain and exit domain processing, and domain policy. The control, domain license management control, blockchain basic capability module can communicate with the blockchain device. The data storage service module comprises: a digital content download client and a digital content storage module, the digital content download client is responsible for downloading the digital content from the digital content providing device, and the digital content storage module is responsible for storing the downloaded digital content. In the embodiment provided by the present invention, the copyright blockchain processing security chip and the data storage service module are collectively referred to as a domain gateway copyright management device.
区块链装置包含多个节点,每个节点中均存储有区块链(Block Chain),区块链包含多个区块(Block),每个区块都包含区块链数据中链接的前一个区块标识、生成Block时间和事务,每个区块用于存储若干个事务,在本发明实施例中,事务包括域网关版权管理装置创建域的事务,终端设备加入域的事务,终端设备退出域的事务、域许可证事务以及许可证分发事务(或者也可以称为终端设备使用许可证的事务)等。The blockchain device includes a plurality of nodes, each of which stores a blockchain (Block Chain), and the blockchain includes a plurality of blocks, each of which contains a link in the blockchain data. A block identifier, a block time and a transaction are generated, and each block is used to store a plurality of transactions. In the embodiment of the present invention, the transaction includes a domain gateway copyright management device to create a domain transaction, the terminal device joins the domain transaction, and the terminal device Exit domain transactions, domain license transactions, and license distribution transactions (or transactions that can also be referred to as end device licenses).
事务包括版本号、事务类型、输入内容和输出内容等。其中,版本号表示承载该事务的数据结构的版本,输入内容包括了表示事务所承载的资产输入来源,输出内容包含输出对象地址和资产数据,事务ID可以是根据某一hash算法对事务中的包含所有数据hash后得到的hash值,hash算法可以有多种,例如:安全哈希算法(Secure Hash Algorithm,简称,SHA1)和信息-摘要算法5(Message-Digest Algorithm 5,简称,MD5)。Transactions include version number, transaction type, input content, and output content. The version number indicates the version of the data structure carrying the transaction, the input content includes the source of the asset input represented by the transaction, the output content includes the output object address and the asset data, and the transaction ID may be based on a hash algorithm in the transaction. The hash value obtained by all the data hashes can be various, such as the Secure Hash Algorithm (SHA1) and the Message-Digest Algorithm 5 (MD5).
具体的,在本发明实施例中,区块链装置可以包括区块链域管理装置和区块链处理装置,其中,区块链域管理装置用于对事务或域网关版权管理装置的设备证书以及设备证书中的安全芯片序列号进行校验,区块链处理装置用于对事务进行存储。具体的,区块链域管理装置和区块链处理装置可以置于同一物理节点中。Specifically, in the embodiment of the present invention, the blockchain device may include a blockchain domain management device and a blockchain processing device, wherein the blockchain domain management device is used for a device certificate of a transaction or domain gateway copyright management device. And the security chip serial number in the device certificate is verified, and the blockchain processing device is used to store the transaction. Specifically, the blockchain domain management device and the blockchain processing device may be placed in the same physical node.
本发明实施例提供了一种共享数字内容的许可证的方法,如图2所示,包括:An embodiment of the present invention provides a method for sharing a license for digital content, as shown in FIG. 2, including:
201、终端设备接收消费者输入的在线使用数字内容的请求后,向域网关版权管理装置发送数字内容的许可证请求。201. After receiving the request for online use of the digital content input by the consumer, the terminal device sends a license request for the digital content to the domain gateway copyright management device.
其中,当消费者需要在线使用数字内容时,在终端设备输入在线使用数字内容的请求。Wherein, when the consumer needs to use the digital content online, the terminal device inputs a request to use the digital content online.
数字内容的许可证请求用于向域网关版权管理装置请求数字内容的许可证。数字内容可以包括文学作品、文本、视频、音频、动漫、图片或flash等,这里只是列举了几类常见数字内容作品形式,并不是限制本发明中的数字内容只可以为这几类作品形式。A license request for digital content is used to request a license for digital content from a domain gateway copyright management device. The digital content may include literary works, text, video, audio, animation, pictures or flash, etc. Here, only a few types of common digital content works are listed, and the digital content in the present invention is not limited to these types of works.
数字内容的许可证请求中可以包含数字内容的ID,数字内容的ID可以是版权登记流程中的数字内容的ID,也可以是版权转移后的数字内容的ID。The license request of the digital content may include the ID of the digital content, and the ID of the digital content may be the ID of the digital content in the copyright registration process, or may be the ID of the digital content after the copyright transfer.
在图2所述的实施例中,终端设备为域网关版权管理装置创建的域中的设备。In the embodiment depicted in Figure 2, the terminal device is a device in the domain created by the domain gateway rights management device.
202、域网关版权管理装置接收终端设备发送的数字内容的许可证请求,并根据数字内容的ID获取域许可。202. The domain gateway copyright management device receives the license request of the digital content sent by the terminal device, and acquires the domain license according to the ID of the digital content.
其中,域许可中包括采用域网关版权管理装置的公钥加密后的数字内容的解密密钥。The domain license includes a decryption key of the digital content encrypted by the public key of the domain gateway copyright management device.
203、域网关版权管理装置根据域许可生成终端设备的许可证。 203. The domain gateway copyright management device generates a license of the terminal device according to the domain license.
终端设备的许可证中包括数字内容的ID、终端设备的地址、被终端设备的公钥加密的数字内容的解密密钥以及许可信息等,具体来说,许可信息可以包含许可证允许执行的操作,许可证对操作的约束和许可证分发约束。许可信息具体可以包括如下内容:A.允许对数字内容执行的操作类型,例如播放、显示、运行、打印或者导出等。B.对数字内容操作的约束,例如允许操作数字内容的次数、允许操作数字内容的时间或者允许操作数字内容的地理位置等。C.许可证分发约束,其规定了本许可证是否允许分发给其他人(消费者/其他内容分发商),可以包括如下分发约束:分发次数、分发开始结束时间或分发时长等。分发给终端设备的许可证,一般设置为不可分发(例如把分发次数设置为0)。The license of the terminal device includes an ID of the digital content, an address of the terminal device, a decryption key of the digital content encrypted by the public key of the terminal device, license information, and the like, and specifically, the license information may include an operation permitted by the license. , licenses for operational constraints and license distribution constraints. The license information may specifically include the following contents: A. Types of operations that are allowed to be performed on the digital content, such as playing, displaying, running, printing, or exporting. B. Constraints on digital content operations, such as the number of times a digital content is allowed to be manipulated, the time at which digital content is allowed to be manipulated, or the geographic location at which digital content is allowed to operate. C. License Distribution Constraints, which stipulate whether this license is allowed to be distributed to others (consumer/other content distributors), and may include distribution restrictions such as the number of distributions, the end of distribution start time, or the length of distribution. The licenses distributed to the terminal device are generally set to be non-distributable (for example, setting the number of distributions to 0).
步骤203在具体实现时可以包括:域网关版权管理装置采用域网关版权管理装置的私钥对域许可中包含的加密后的数字内容的解密密钥进行解密,得到数字内容的解密密钥;再采用终端设备的公钥对数字内容的解密密钥进行加密;域网关版权管理装置根据采用终端设备的公钥加密后的数字内容的解密密钥、终端设备的地址、数字内容的ID和许可信息生成终端设备的许可证。The step 203 may include: the domain gateway copyright management device decrypts the decryption key of the encrypted digital content included in the domain license by using the private key of the domain gateway copyright management device to obtain a decryption key of the digital content; The decryption key of the digital content is encrypted by using the public key of the terminal device; the decryption key of the digital content encrypted by the domain gateway copyright management device according to the public key of the terminal device, the address of the terminal device, the ID of the digital content, and the license information Generate a license for the terminal device.
204、域网关版权管理装置向终端设备发送终端设备的许可证。204. The domain gateway copyright management device sends a license of the terminal device to the terminal device.
205、域网关版权管理装置向区块链装置发送许可证分发事务请求。205. The domain gateway copyright management device sends a license distribution transaction request to the blockchain device.
其中,许可证分发事务请求包括域许可证事务ID,域网关版权管理装置的私钥的签名,终端设备的地址以及许可信息。The license distribution transaction request includes a domain license transaction ID, a signature of a private key of the domain gateway copyright management device, an address of the terminal device, and license information.
其中,域许可证事务ID具体是指域许可证事务的事务ID,关于域许可证事务的内容可以参见下文中的相关描述。The domain license transaction ID specifically refers to the transaction ID of the domain license transaction. For the content of the domain license transaction, refer to the related description below.
在本发明实施例中,签名是用私钥对一段任意数字(例如:数字、数字内容ID、许可证等等)进行加密运算的结果。通过公钥可以对签名进行验证,验证通过,则说明被签名的数字内容是由公钥所有者发布的和可信的;否则表示被签名的数据是伪造的和不可信的。则域网关版权管理装置的私钥的签名是指采用域网关版权管理装置的私钥对数字内容的ID进行加密运算的结果。In an embodiment of the invention, the signature is the result of encrypting an arbitrary number (eg, number, digital content ID, license, etc.) with a private key. The signature can be verified by the public key. If the verification is passed, the signed digital content is issued and trusted by the public key owner; otherwise, the signed data is forged and untrusted. The signature of the private key of the domain gateway copyright management device refers to the result of encrypting the ID of the digital content by using the private key of the domain gateway copyright management device.
206、区块链装置接收域网关版权管理装置发送的许可证分发事务请求,并对该请求中的信息进行校验。206. The blockchain device receives a license distribution transaction request sent by the domain gateway copyright management device, and checks the information in the request.
具体的,区块链装置对许可证分发事务请求中的信息进行校验具体包括:校验域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确。Specifically, the blockchain device performs verification on the information in the license distribution transaction request, specifically: whether the verification domain license transaction ID exists, and whether the signature of the private key of the domain gateway copyright management device is correct.
具体的校验方法为:1)在区块链装置中查询域许可证事务的事务ID是否存在。The specific verification method is as follows: 1) Query whether the transaction ID of the domain license transaction exists in the blockchain device.
2)根据域许可证事务的事务ID到区块链装置中查询该事务的输出内容,采用域网关版权管理装置的公钥对域网关版权管理装置的私钥的签名进行解密,若解密成功、且解密结果与该输出内容包含的域网关版权管理装置的地址一致,则域网关版权管理装置的私钥的签名正确,否则,域网关版权管理装置的私钥的签名不正确。2) according to the transaction ID of the domain license transaction to query the output content of the transaction in the blockchain device, decrypt the signature of the private key of the domain gateway copyright management device by using the public key of the domain gateway copyright management device, and if the decryption is successful, And the decryption result is consistent with the address of the domain gateway copyright management device included in the output content, and the signature of the private key of the domain gateway copyright management device is correct; otherwise, the signature of the private key of the domain gateway copyright management device is incorrect.
207、在校验成功后,构造许可证分发事务并将许可证分发事务存储在区块链中。207. After the verification is successful, construct a license distribution transaction and store the license distribution transaction in the blockchain.
其中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。另外,许可证分发事务还包括版本号和 事务类型,版本号表示承载该事务的数据结构的版本。The input content of the license distribution transaction includes a domain license transaction ID and a signature of a private key of the domain gateway copyright management device, and the output content includes an address of the terminal device and license information. In addition, the license distribution transaction also includes the version number and The transaction type, the version number indicates the version of the data structure hosting the transaction.
上述方法在具体实现时,域网关版权管理装置可以向区块链装置中的区块链域管理装置发送许可证分发事务请求,区块链域管理装置对该请求中的信息进行校验,并在校验成功后,构造许可证分发事务,并将该事务向区块链处理装置发送,区块链处理装置将该事务存储在区块链中。When the foregoing method is specifically implemented, the domain gateway copyright management apparatus may send a license distribution transaction request to the blockchain domain management apparatus in the blockchain apparatus, and the blockchain domain management apparatus checks the information in the request, and After the verification is successful, a license distribution transaction is constructed and sent to the blockchain processing device, and the blockchain processing device stores the transaction in the blockchain.
本发明实施例提供的方法,终端设备在域内共享数字内容的许可证的过程中,会将许可证分发事务在区块链中进行存储,在区块链装置中的每个节点上都会存储有该事务,若其中一个节点需要篡改数据时,需要得到区块链装置中的大多数节点的同意,因此,一般情况下,一旦事务添加到区块链后,就无法更改,并且,由于每个节点上都存储有区块链,一个节点瘫痪,不会导致区块链数据的丢失,这样区块链数据就具有很强的安全性,保证了数字内容许可证共享过程数据的高安全性,并且每个许可证共享的过程都可以被审计。According to the method provided by the embodiment of the present invention, in the process of sharing the license of the digital content in the domain, the terminal device stores the license distribution transaction in the blockchain, and each node in the blockchain device stores The transaction, if one of the nodes needs to tamper with the data, needs to get the consent of most nodes in the blockchain device, so in general, once the transaction is added to the blockchain, it cannot be changed, and, because each The block chain is stored on the node, and one node does not cause the loss of the blockchain data, so the blockchain data has strong security, which ensures the high security of the digital content license sharing process data. And each license sharing process can be audited.
以下图3和图4所述的实施例为对图2所述的实施例的更为具体的示例性说明,其中,上述方法具体包括:The embodiment shown in FIG. 3 and FIG. 4 is a more specific exemplary description of the embodiment described in FIG. 2, wherein the above method specifically includes:
301、终端设备接收消费者输入的在线使用数字内容的请求后,向域网关版权管理装置发送数字内容的许可证请求。301. After receiving the request for online use of digital content input by the consumer, the terminal device sends a license request for the digital content to the domain gateway copyright management device.
其中,数字内容的许可证请求可以包括数字内容的ID、终端设备的地址。Wherein, the license request of the digital content may include an ID of the digital content and an address of the terminal device.
302、域网关版权管理装置接收终端设备发送的数字内容的许可证请求,并根据终端设备的地址确定终端设备是否为域网关版权管理装置创建的域中的设备。302. The domain gateway copyright management device receives the license request of the digital content sent by the terminal device, and determines, according to the address of the terminal device, whether the terminal device is a device in a domain created by the domain gateway copyright management device.
域网关版权管理装置可以根据本地存储的事务或者区块链中的事务确定终端设备是否为域网关版权管理装置创建的域中的设备,具体的,若存在该终端设备加入域的事务且不存在该终端设备退出域的事务,则表明该终端设备为域网关版权管理装置创建的域中的设备,具体可以通过事务的输入内容和/或输出内容确定。若事务的输出内容为域网关版权管理装置的地址、终端设备的地址和域标识,则表明该终端设备加入了域网关版权管理装置创建的域标识为该输出内容中包含的域标识的域中。若事务的输入内容为终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,输出内容为空,则表明该终端设备退出了域。The domain gateway copyright management device may determine, according to the locally stored transaction or the transaction in the blockchain, whether the terminal device is a device in a domain created by the domain gateway copyright management device, and specifically, if the terminal device joins the domain transaction and does not exist The terminal device exits the domain transaction, indicating that the terminal device is a device in the domain created by the domain gateway copyright management device, and may be determined by the input content and/or the output content of the transaction. If the output content of the transaction is the address of the domain gateway copyright management device, the address of the terminal device, and the domain identifier, it indicates that the terminal device joins the domain identifier created by the domain gateway copyright management device as the domain identifier included in the output content. . If the input content of the transaction is the signature of the terminal device joining the domain transaction ID and the private key of the domain gateway copyright management device, if the output content is empty, it indicates that the terminal device has exited the domain.
需要说明的是,在本发明实施例中,区块链装置构造事务并将事务存储在区块链的过程中,一般是构造好多个事务之后,将多个事务构造成一个区块,当一个事务为与域网关版权管理装置(或数字内容提供装置)相关的事务,则区块链装置中的构造区块的节点在构造好包含该事务的区块之后会向区块链装置中的其他节点和域网关版权管理装置(或数字内容提供装置)广播该区块,域网关版权管理装置(或数字内容提供装置)将该区块中的与自身相关的事务提取出来并进行存储,因此,域网关版权管理装置(或数字内容提供装置)中会存储与自身相关的事务。It should be noted that, in the embodiment of the present invention, the blockchain device constructs a transaction and stores the transaction in the process of the blockchain, generally after constructing multiple transactions, constructing multiple transactions into one block, when one The transaction is a transaction related to the domain gateway copyright management device (or digital content providing device), and the node of the building block in the blockchain device will be the other in the blockchain device after constructing the block containing the transaction. The node and domain gateway copyright management device (or digital content providing device) broadcasts the block, and the domain gateway copyright management device (or digital content providing device) extracts and stores the transaction related to itself in the block, and therefore, A transaction related to itself is stored in the domain gateway copyright management device (or digital content providing device).
若不是,直接向终端设备返回处理失败的消息,若是,继续执行以下步骤。If not, return a message that the processing failed directly to the terminal device. If yes, continue with the following steps.
303、域网关版权管理装置确定域是否购买过数字内容。303. The domain gateway copyright management device determines whether the domain has purchased the digital content.
具体的,域网关版权管理装置可以根据本地存储的事务或者区块链中的事务确定域是否购买过数字内容,若存在域购买数字内容的事务,则表明域购买过数字内容,具体可以通过 事务的输入内容和/或输出内容确定。若事务的输出内容包括域网关版权管理装置的地址和该数字内容的ID,则表明域购买过数字内容。Specifically, the domain gateway copyright management device may determine whether the domain has purchased the digital content according to the locally stored transaction or the transaction in the blockchain. If there is a transaction in the domain to purchase the digital content, the domain purchases the digital content, specifically The input and/or output of the transaction is determined. If the output of the transaction includes the address of the domain gateway copyright management device and the ID of the digital content, it indicates that the domain has purchased the digital content.
若是,如图3所示,执行步骤304a-313a,若否,如图4所示,执行步骤304b-320b。If so, as shown in FIG. 3, steps 304a-313a are performed, and if not, as shown in FIG. 4, steps 304b-320b are performed.
304a、域网关版权管理装置根据数字内容的ID获取本地的域许可。304a. The domain gateway copyright management device acquires the local domain license according to the ID of the digital content.
305a、域网关版权管理装置判断已使用的数字内容的许可证数目是否未超过域许可中的许可信息中限制的许可证个数。305a. The domain gateway copyright management device determines whether the number of licenses of the used digital content does not exceed the number of licenses restricted in the license information in the domain license.
具体的,域网关版权管理装置可以根据域许可中的许可信息和自己分发过程中记录的分发的许可证数目确定已使用的数字内容的许可证数目是否未超过域许可中的许可信息中限制的许可证个数。Specifically, the domain gateway copyright management apparatus may determine, according to the license information in the domain license and the number of distributed licenses recorded in the self-distribution process, whether the number of licenses of the used digital content does not exceed the limit in the license information in the domain license. The number of licenses.
若是,执行以下步骤,若否,直接向终端设备返回处理失败的消息。If yes, perform the following steps. If no, return the message that the processing failed directly to the terminal device.
306a、域网关版权管理装置根据域许可生成终端设备的许可证。306a. The domain gateway copyright management device generates a license of the terminal device according to the domain license.
步骤306a的具体实现可参见上文,在此不再赘述。For the specific implementation of step 306a, reference may be made to the above, and details are not described herein again.
307a、域网关版权管理装置向终端设备发送终端设备的许可证。307a. The domain gateway copyright management device sends a license of the terminal device to the terminal device.
308a、域网关版权管理装置向区块链装置发送许可证分发事务请求。308a. The domain gateway copyright management device sends a license distribution transaction request to the blockchain device.
其中,许可证分发事务请求包括域许可证事务ID,域网关版权管理装置的私钥的签名,终端设备的地址以及许可信息。The license distribution transaction request includes a domain license transaction ID, a signature of a private key of the domain gateway copyright management device, an address of the terminal device, and license information.
309a、区块链装置接收域网关版权管理装置发送的许可证分发事务请求,并对该请求中的信息进行校验。309a. The blockchain device receives the license distribution transaction request sent by the domain gateway copyright management device, and checks the information in the request.
具体的,区块链装置对许可证分发事务请求中的信息进行校验具体包括:校验域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确。Specifically, the blockchain device performs verification on the information in the license distribution transaction request, specifically: whether the verification domain license transaction ID exists, and whether the signature of the private key of the domain gateway copyright management device is correct.
310a、在校验成功后,区块链装置构造许可证分发事务并将许可证分发事务存储在区块链中。310a. After the verification is successful, the blockchain device constructs a license distribution transaction and stores the license distribution transaction in the blockchain.
其中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。另外,许可证分发事务还包括版本号和事务类型,版本号表示承载该事务的数据结构的版本。The input content of the license distribution transaction includes a domain license transaction ID and a signature of a private key of the domain gateway copyright management device, and the output content includes an address of the terminal device and license information. In addition, the license distribution transaction also includes a version number and a transaction type, and the version number indicates the version of the data structure that hosts the transaction.
311a、终端设备接收域网关版权管理装置发送的许可证,向域网关版权管理装置请求下发加密数字内容。311a. The terminal device receives the license sent by the domain gateway copyright management device, and requests the domain gateway copyright management device to deliver the encrypted digital content.
其中,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容。Wherein, the encrypted digital content can be decrypted by using a digital content decryption key to obtain digital content.
312a、域网关版权管理装置向终端设备发送本地保存的加密数字内容。312a. The domain gateway copyright management device sends the locally stored encrypted digital content to the terminal device.
313a、终端设备接收域网关版权管理装置发送的加密数字内容,并根据终端设备的私钥以及许可证获取数字内容。313a. The terminal device receives the encrypted digital content sent by the domain gateway copyright management device, and acquires the digital content according to the private key of the terminal device and the license.
具体的,终端设备使用终端设备的私钥对许可证中包括的数字内容的解密密钥进行解密,得到数字内容的解密密钥,再采用数字内容的解密密钥对加密数字内容进行解密,得到数字内容。 Specifically, the terminal device decrypts the decryption key of the digital content included in the license by using the private key of the terminal device to obtain a decryption key of the digital content, and then decrypts the encrypted digital content by using a decryption key of the digital content to obtain a decryption key. Digital content.
图3所述的实施例描述了域购买过数字内容的场景下,数字内容的许可证的共享过程。The embodiment illustrated in Figure 3 describes the sharing process of licenses for digital content in the context of a domain purchased digital content.
304b、域网关版权管理装置向数字内容提供装置发送域许可证颁发请求。304b. The domain gateway copyright management device sends a domain license issuance request to the digital content providing device.
其中,域许可证颁发请求包括数字内容的ID、域网关版权管理装置的地址、域标识以及许可信息。The domain license issuance request includes an ID of the digital content, an address of the domain gateway copyright management device, a domain identifier, and license information.
305b、数字内容提供装置接收域网关版权管理装置发送的域许可证颁发请求,并确定数字内容的ID在数据库中是否存在。305b. The digital content providing apparatus receives the domain license issuance request sent by the domain gateway copyright management apparatus, and determines whether the ID of the digital content exists in the database.
若是,继续执行以下步骤,若否,向域网关版权管理装置返回处理失败的消息。If yes, continue with the following steps, and if not, return a message indicating that the processing failed to the domain gateway copyright management device.
306b、数字内容提供装置确定域网关版权管理装置的地址对应的帐号并对该帐号进行扣费处理。306b. The digital content providing device determines an account corresponding to the address of the domain gateway copyright management device, and performs deduction processing on the account.
307b、数字内容提供装置构造域许可证事务并将域许可证事务向区块链装置发送。307b. The digital content providing device constructs a domain license transaction and transmits the domain license transaction to the blockchain device.
域许可证事务的输入内容包括所述数字内容提供装置的许可证事务ID、所述数字内容的许可证在所述数字内容提供装置的许可证事务中的索引以及所述数字内容提供装置的私钥的签名,所述域许可证事务的输出内容包括所述域网关版权管理装置的地址和许可信息。域许可证事务还包括版本号和事务类型。The input content of the domain license transaction includes a license transaction ID of the digital content providing device, an index of the license of the digital content in a license transaction of the digital content providing device, and a private content of the digital content providing device The signature of the key, the output content of the domain license transaction includes the address and license information of the domain gateway copyright management device. Domain license transactions also include version numbers and transaction types.
数字内容提供装置的许可证事务ID是指数字内容提供装置获取数字内容的许可证的事务的事务ID。The license transaction ID of the digital content providing device refers to the transaction ID of the transaction in which the digital content providing device acquires the license of the digital content.
308b、区块链装置接收数字内容提供装置发送的域许可证事务并将该事务存储在区块链中。308b. The blockchain device receives the domain license transaction sent by the digital content providing device and stores the transaction in the blockchain.
309b、数字内容提供装置生成域许可并向域网关版权管理装置发送。309b. The digital content providing device generates a domain license and sends the domain license to the domain gateway copyright management device.
数字内容提供装置生成域网关版权管理装置的域许可的过程包括:数字内容提供装置根据数字内容的ID确定该数字内容的解密密钥,采用域网关版权管理装置的公钥对数字内容的解密密钥进行加密,根据加密后的数字内容的解密密钥、域标识以及许可信息生成域许可。其中,数字内容的ID与数字内容的解密密钥存在对应关系。The process of generating the domain license of the domain gateway copyright management apparatus by the digital content providing apparatus includes: the digital content providing apparatus determines the decryption key of the digital content according to the ID of the digital content, and decrypts the digital content by using the public key of the domain gateway copyright management apparatus The key is encrypted, and a domain license is generated based on the decrypted key of the encrypted digital content, the domain identifier, and the license information. The ID of the digital content has a correspondence relationship with the decryption key of the digital content.
310b、域网关版权管理装置根据域许可生成终端设备的许可证。310b. The domain gateway copyright management device generates a license of the terminal device according to the domain license.
步骤310b的具体实现可参见上文,在此不再赘述。For the specific implementation of step 310b, reference may be made to the above, and details are not described herein again.
311b、域网关版权管理装置向终端设备发送终端设备的许可证。311b. The domain gateway copyright management device sends a license of the terminal device to the terminal device.
312b、域网关版权管理装置向区块链装置发送许可证分发事务请求。312b. The domain gateway copyright management device sends a license distribution transaction request to the blockchain device.
其中,许可证分发事务请求包括域许可证事务ID,域网关版权管理装置的私钥的签名,终端设备的地址以及许可信息。The license distribution transaction request includes a domain license transaction ID, a signature of a private key of the domain gateway copyright management device, an address of the terminal device, and license information.
313b、区块链装置接收域网关版权管理装置发送的许可证分发事务请求,并对该请求中的信息进行校验。313b. The blockchain device receives the license distribution transaction request sent by the domain gateway copyright management device, and checks the information in the request.
具体的,区块链装置对许可证分发事务请求中的信息进行校验具体包括:校验域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确。Specifically, the blockchain device performs verification on the information in the license distribution transaction request, specifically: whether the verification domain license transaction ID exists, and whether the signature of the private key of the domain gateway copyright management device is correct.
314b、在校验成功后,区块链装置构造许可证分发事务并将许可证分发事务存储在区块 链中。314b. After the verification is successful, the blockchain device constructs a license distribution transaction and stores the license distribution transaction in the block. In the chain.
其中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。另外,许可证分发事务还包括版本号和事务类型,版本号表示承载该事务的数据结构的版本。The input content of the license distribution transaction includes a domain license transaction ID and a signature of a private key of the domain gateway copyright management device, and the output content includes an address of the terminal device and license information. In addition, the license distribution transaction also includes a version number and a transaction type, and the version number indicates the version of the data structure that hosts the transaction.
315b、终端设备接收域网关版权管理装置发送的许可证,向域网关版权管理装置请求下发加密数字内容。315b. The terminal device receives the license sent by the domain gateway copyright management device, and requests the domain gateway copyright management device to deliver the encrypted digital content.
其中,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容。Wherein, the encrypted digital content can be decrypted by using a digital content decryption key to obtain digital content.
316b、域网关版权管理装置向数字内容提供装置请求下发加密数字内容。316b. The domain gateway copyright management device requests the digital content providing device to deliver the encrypted digital content.
317b、数字内容提供装置向域网关版权管理装置下发加密数字内容。317b. The digital content providing device sends the encrypted digital content to the domain gateway copyright management device.
318b、域网关版权管理装置接收数字内容提供装置下发的加密数字内容,并在本地进行保存。318b. The domain gateway copyright management device receives the encrypted digital content delivered by the digital content providing device, and saves it locally.
319b、域网关版权管理装置向终端设备发送加密数字内容。319b. The domain gateway copyright management device sends the encrypted digital content to the terminal device.
320b、终端设备接收域网关版权管理装置发送的加密数字内容,并根据终端设备的私钥以及许可证获取数字内容。320b. The terminal device receives the encrypted digital content sent by the domain gateway copyright management device, and acquires the digital content according to the private key of the terminal device and the license.
具体的,终端设备使用终端设备的私钥对许可证中包括的数字内容的解密密钥进行解密,得到数字内容的解密密钥,再采用数字内容的解密密钥对加密数字内容进行解密,得到数字内容。Specifically, the terminal device decrypts the decryption key of the digital content included in the license by using the private key of the terminal device to obtain a decryption key of the digital content, and then decrypts the encrypted digital content by using a decryption key of the digital content to obtain a decryption key. Digital content.
图4所述的实施例描述了域未购买过数字内容的场景下,数字内容的许可证的共享过程。The embodiment illustrated in Figure 4 describes the sharing process of licenses for digital content in the context of a domain having not purchased digital content.
在上述方法中,域网关版权管理装置根据域许可中包含的许可信息对数字内容的许可证的使用进行控制。在终端设备申请数字内容的许可证时,判断分发的许可证数目是否已经超过限制,当分发的许可证数目已经超过限制,本地的域许可变为无效。具体的,控制方法可以为:为每个终端设备只颁发一个一次性使用的许可证,终端设备每次访问数字内容都需要重新向域网关版权管理装置申请许可证,从而域网关版权管理装置可知道许可证的总使用次数。In the above method, the domain gateway copyright management apparatus controls the use of the license of the digital content in accordance with the license information contained in the domain license. When the terminal device applies for a license for digital content, it is judged whether the number of distributed licenses has exceeded the limit, and when the number of distributed licenses has exceeded the limit, the local domain license becomes invalid. Specifically, the control method may be: issuing only one single-use license for each terminal device, and each time the terminal device accesses the digital content, it is required to apply for a license to the domain gateway copyright management device again, so that the domain gateway copyright management device can Know the total number of licenses used.
上述实施例所述的方法适用的场景为:终端设备为域中的设备且位于局域网中,在另一种场景下,终端设备虽为域中的设备但却离开了局域网,该情况下,如图5所示,共享数字内容的许可证的方法具体包括:The scenario described in the foregoing embodiment is applicable to the following steps: the terminal device is a device in the domain and is located in the local area network. In another scenario, the terminal device is a device in the domain but leaves the local area network. In this case, As shown in FIG. 5, the method for sharing a license for digital content specifically includes:
501、终端设备接收消费者输入的在线使用数字内容的请求后,向数字内容提供装置发送数字内容的许可证请求。501. After receiving the request for online use of the digital content input by the consumer, the terminal device sends a license request for the digital content to the digital content providing device.
其中,数字内容的许可证请求包括数字内容的ID、终端设备的地址和终端设备所属的域的域标识。The license request of the digital content includes an ID of the digital content, an address of the terminal device, and a domain identifier of a domain to which the terminal device belongs.
502、数字内容提供装置接收终端设备发送的数字内容的许可证请求后,对该许可证请求中包括的信息进行校验。502. After receiving the license request for the digital content sent by the terminal device, the digital content providing device checks the information included in the license request.
其中,对数字内容的许可证请求中包括的信息进行校验具体包括校验终端设备所属的域是否存在、终端设备是否为该域中的设备以及终端设备的地址是否符合生成规范,若均是, 则校验成功。The verification of the information included in the license request of the digital content includes verifying whether the domain to which the terminal device belongs, whether the terminal device is a device in the domain, and whether the address of the terminal device meets the generation specification, if both are , The verification is successful.
503、若校验成功,数字内容提供装置向区块链装置发送许可证分发事务。503. If the verification is successful, the digital content providing device sends a license distribution transaction to the blockchain device.
504、区块链装置接收数字内容提供装置发送的许可证分发事务,并将许可证分发事务存储在区块链中。504. The blockchain device receives a license distribution transaction sent by the digital content providing device, and stores the license distribution transaction in a blockchain.
区块链装置将许可证分发事务存储在区块链中后,可以向数字内容提供装置返回存储成功的响应。After the blockchain device stores the license distribution transaction in the blockchain, it can return a successful response to the digital content providing device.
505、数字内容提供装置根据数字内容的ID生成并向终端设备分发数字内容的许可证。505. The digital content providing device generates and distributes a license of the digital content to the terminal device according to the ID of the digital content.
许可证中包括被终端设备公钥加密后的数字内容解密密钥以及许可信息等。The license includes a digital content decryption key encrypted by the terminal device public key, license information, and the like.
步骤505在具体实现时包括:数字内容提供装置根据数字内容的ID获取数字内容的解密密钥;采用所述终端设备的公钥对数字内容的解密密钥进行加密;根据加密后的数字内容的解密密钥、终端设备的地址、数字内容的ID和许可信息生成许可证。The step 505 includes: the digital content providing device acquires a decryption key of the digital content according to the ID of the digital content; and encrypts the decryption key of the digital content by using the public key of the terminal device; according to the encrypted digital content The decryption key, the address of the terminal device, the ID of the digital content, and the license information generate a license.
506、终端设备接收数字内容提供装置分发的许可证,并根据数字内容的ID向数字内容提供装置请求下发加密数字内容。506. The terminal device receives the license distributed by the digital content providing device, and requests the digital content providing device to deliver the encrypted digital content according to the ID of the digital content.
其中,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容。Wherein, the encrypted digital content can be decrypted by using a digital content decryption key to obtain digital content.
507、数字内容提供装置接收终端设备的下发加密数字内容的请求,并向终端设备下发加密数字内容。507. The digital content providing apparatus receives a request for sending the encrypted digital content by the terminal device, and sends the encrypted digital content to the terminal device.
508、终端设备根据终端设备的私钥以及许可证获取数字内容。508. The terminal device acquires digital content according to the private key of the terminal device and the license.
具体的,终端设备可以使用终端设备的私钥对许可证中包括的数字内容的解密密钥进行解密,得到数字内容的解密密钥,再采用数字内容的解密密钥对加密数字内容进行解密,得到数字内容。Specifically, the terminal device may decrypt the decryption key of the digital content included in the license by using the private key of the terminal device to obtain a decryption key of the digital content, and then decrypt the encrypted digital content by using the decryption key of the digital content. Get digital content.
该方法支持终端设备离线时的数字内容的许可证的共享。基于图5所述的实施例中,数字内容提供装置可以将分发的许可证记录在区块链上,域网关版权管理装置定时从区块链同步相关记录,当发现许可证的使用次数超过限制,则向区块链装置提交域许可证废弃事务。The method supports sharing of licenses for digital content when the terminal device is offline. In the embodiment described based on FIG. 5, the digital content providing apparatus may record the distributed license on the blockchain, and the domain gateway copyright management apparatus periodically synchronizes the related records from the blockchain, and when the number of used licenses is found to exceed the limit , submit the domain license obsolete transaction to the blockchain device.
本发明实施例提供的方法,当终端设备为域中的设备但是离开域了之后,仍然可以共享数字内容的许可证,满足了终端设备离线共享许可证的需求,并且在共享数字内容的许可证的过程中,会将许可证分发事务在区块链中进行存储,在区块链装置中的每个节点上都会存储有该事务,若其中一个节点需要篡改数据时,需要得到区块链装置中的大多数节点的同意,因此,一般情况下,一旦事务添加到区块链后,就无法更改,并且,由于每个节点上都存储有区块链,一个节点瘫痪,不会导致区块链数据的丢失,这样区块链数据就具有很强的安全性,保证了数字内容许可证共享过程数据的高安全性,并且每个许可证共享的过程都可以被审计。The method provided by the embodiment of the present invention can still share the license of the digital content after the terminal device is the device in the domain but leaves the domain, satisfies the requirement for the terminal device to share the license offline, and the license for sharing the digital content. During the process, the license distribution transaction is stored in the blockchain, and the transaction is stored on each node in the blockchain device. If one of the nodes needs to tamper with the data, the blockchain device needs to be obtained. Most nodes in the agreement agree, so in general, once the transaction is added to the blockchain, it cannot be changed, and since each node has a blockchain stored, one node will not cause the block. The loss of chain data makes the blockchain data highly secure, ensuring high security of digital content license sharing process data, and the process of sharing each license can be audited.
在上述实施例的方法执行之前,域网关版权管理装置首先需要创建域,从而使得终端设备加入域,具体的,如图6所示,域网关版权管理装置创建域的过程具体包括:Before the method of the foregoing embodiment is executed, the domain gateway copyright management device first needs to create a domain, so that the terminal device joins the domain. Specifically, as shown in FIG. 6, the process of the domain gateway copyright management device creating the domain specifically includes:
601、域网关版权管理装置接收域网关管理客户端发送的创建域请求。601. The domain gateway copyright management device receives the create domain request sent by the domain gateway management client.
602、域网关版权管理装置查询本地记录确定该域是否已经创建。 602. The domain gateway copyright management device queries the local record to determine whether the domain has been created.
具体的,消费者可以通过域网关管理客户端应用创建一个创建域的界面,在该界面输入域帐号和口令,请求创建域,域网关版权管理装置可以根据本地存储的域帐号和口令的记录确定域的域帐号和口令与该界面中输入的域帐号和口令相同的域是否已经创建。Specifically, the consumer can create a domain creation interface through the domain gateway management client application, input a domain account and password in the interface, request to create a domain, and the domain gateway copyright management device can determine according to the record of the locally stored domain account and password. Whether the domain's domain account and password are the same as the domain account and password entered in the interface.
具体的,域帐号和口令可以是消费者自己设定的,域中的设备可以是提前确定好,也可以是创建域之后确定的,域帐号和口令可以用于终端设备加入域时使用。Specifically, the domain account and the password may be set by the consumer. The device in the domain may be determined in advance, or may be determined after the domain is created. The domain account and password may be used when the terminal device joins the domain.
若是,则直接返回创建成功响应,响应中包含域标识,若否,执行以下步骤。If yes, directly return to create a successful response, the response contains the domain identifier, and if not, perform the following steps.
603、域网关版权管理装置记录域帐号和口令,并向区块链装置发送创建域请求。603. The domain gateway copyright management device records the domain account and password, and sends a create domain request to the blockchain device.
创建域请求包括域网关版权管理装置的地址和域网关版权管理装置的私钥的签名。The create domain request includes the address of the domain gateway rights management device and the signature of the private key of the domain gateway rights management device.
具体的,在本发明实施例中,各个设备的公私钥对可以在设备启动的时候生成,也可以在一定的触发条件下生成,本发明实施例对此不作具体限定。Specifically, in the embodiment of the present invention, the public-private key pair of each device may be generated when the device is started, or may be generated under a certain triggering condition, which is not specifically limited in the embodiment of the present invention.
604、区块链装置根据创建域请求中的信息确定域是否已经创建。604. The blockchain device determines, according to information in the create domain request, whether the domain has been created.
其中,创建域请求包括域网关版权管理装置的地址和所述域网关版权管理装置的私钥的签名。The create domain request includes an address of the domain gateway copyright management device and a signature of the private key of the domain gateway copyright management device.
具体的,区块链装置可以通过查询区块链中的事务确定域是否已经创建,具体的,若存在事务的输出内容为域网关版权管理装置的私钥的签名、域网关版权管理装置的地址和域标识的事务,则表示域已经创建。Specifically, the blockchain device may determine whether the domain has been created by querying a transaction in the blockchain. Specifically, if the output content of the transaction is the signature of the private key of the domain gateway copyright management device, the address of the domain gateway copyright management device A transaction with a domain ID indicates that the domain has been created.
若是,向域网关版权管理装置返回创建成功响应,该响应中包括域标识。若否,执行以下步骤。If yes, a successful creation response is returned to the domain gateway copyright management device, and the response includes the domain identifier. If no, perform the following steps.
605、区块链装置对创建域请求中的信息进行校验。605. The blockchain device verifies the information in the create domain request.
对创建域请求中的信息进行校验具体包括:校验域网关版权管理装置的地址是否符合生成规范且域网关版权管理装置的私钥的签名是否正确,若均是,则校验成功。The verification of the information in the creation of the domain request includes: checking whether the address of the domain gateway copyright management device conforms to the generation specification and whether the signature of the private key of the domain gateway copyright management device is correct, and if yes, the verification is successful.
具体的校验方法为:1)判断域网关版权管理装置的地址是否符合生成规范。The specific verification method is: 1) judging whether the address of the domain gateway copyright management device conforms to the generation specification.
2)采用域网关版权管理装置的公钥对域网关版权管理装置的私钥的签名进行解密,若解密成功、且解密结果与域网关版权管理装置的地址一致,则域网关版权管理装置的私钥的签名正确,否则,域网关版权管理装置的私钥的签名不正确。2) decrypting the signature of the private key of the domain gateway copyright management device by using the public key of the domain gateway copyright management device. If the decryption is successful and the decryption result is consistent with the address of the domain gateway copyright management device, the private key of the domain gateway copyright management device The signature of the key is correct. Otherwise, the signature of the private key of the domain gateway copyright management device is incorrect.
606、在校验成功后,区块链装置构造创建域事务并将创建域事务存储在区块链中。606. After the verification succeeds, the blockchain device construct creates a domain transaction and stores the created domain transaction in the blockchain.
其中,创建域事务的输入内容为空,输出内容为域网关版权管理装置的私钥的签名、域网关版权管理装置的地址和域标识。The input content of the creation domain transaction is empty, and the output content is the signature of the private key of the domain gateway copyright management device, the address of the domain gateway copyright management device, and the domain identifier.
607、区块链装置向域网关版权管理装置返回创建域响应,创建域响应中包括域标识。607. The blockchain device returns a create domain response to the domain gateway copyright management device, where the domain response includes a domain identifier.
608、域网关版权管理装置向域网关管理客户端返回创建域响应。608. The domain gateway copyright management device returns a create domain response to the domain gateway management client.
域网关管理客户端收到创建域响应则确定域标识为域响应中的域标识的域创建成功。The domain gateway management client receives the Create Domain Response and determines that the domain ID is successfully created for the domain ID in the domain response.
上述方法在具体实现时,域网关版权管理装置可以向区块链装置中的区块链域管理装置发送创建域请求,由区块链域管理装置完成对创建域请求中的信息的校验后,将构造的创建域事务向区块链处理装置发送,由区块链处理装置将该事务存储在区块链中。 When the foregoing method is specifically implemented, the domain gateway copyright management apparatus may send a create domain request to the blockchain domain management apparatus in the blockchain apparatus, and the blockchain domain management apparatus completes verification of the information in the create domain request. The constructed create domain transaction is sent to the blockchain processing device, and the transaction is stored in the blockchain by the blockchain processing device.
通过上述过程,将域网关版权管理装置创建域的创建域事务存储在区块链中,确保了域网关版权管理装置创建域的过程数据的高安全性和可审计性。Through the above process, the domain creation transaction of the domain gateway copyright management device creation domain is stored in the blockchain, which ensures the high security and auditability of the process data of the domain gateway copyright management device creation domain.
如图7所示,终端设备加入域的过程具体包括:As shown in Figure 7, the process of joining a terminal device to a domain specifically includes:
701、终端设备向域网关版权管理装置请求获取域标识,请求消息中携带域帐号和口令。701. The terminal device requests the domain gateway copyright management device to obtain the domain identifier, where the request message carries the domain account and the password.
其中,域帐号和口令为消费者启动版权管理客户端后,在加入域的界面中输入的域帐号和口令。The domain account and password are the domain account and password entered in the domain joining interface after the consumer starts the copyright management client.
702、域网关版权管理装置验证请求消息中包含的域帐号和口令是否与已经创建的域的域帐号和口令匹配。702. Whether the domain account and password included in the domain gateway copyright management device verification request message match the domain account and password of the domain that has been created.
若是,则执行后续步骤,若否,则返回失败。If yes, the next step is performed, and if not, the return fails.
703、域网关版权管理装置向终端设备返回域标识。703. The domain gateway copyright management device returns a domain identifier to the terminal device.
704、终端设备接收到域标识之后,向域网关版权管理装置发送加入域请求。704. After receiving the domain identifier, the terminal device sends a join domain request to the domain gateway copyright management device.
其中,该加入域请求中包含终端设备的地址、域网关版权管理装置的私钥的签名、域标识、域网关版权管理装置的地址以及创建域事务ID。The join domain request includes an address of the terminal device, a signature of the private key of the domain gateway copyright management device, a domain identifier, an address of the domain gateway copyright management device, and a domain transaction ID.
705、域网关版权管理装置验证终端设备的地址是否符合生成规范,域网关版权管理装置的私钥的签名是否正确。705. The domain gateway copyright management device verifies whether the address of the terminal device conforms to the generation specification, and whether the signature of the private key of the domain gateway copyright management device is correct.
若是,执行后续步骤,若否,返回处理失败的消息。If yes, perform the next step, if not, return a message that the processing failed.
706、域网关版权管理装置向区块链装置发送加入域请求。706. The domain gateway copyright management device sends a join domain request to the blockchain device.
需要说明的是,如果此时局域网与外网断连,则域网关版权管理装置对终端设备的地址和域网关版权管理装置的私钥的签名校验成功的话,先批准终端设备的加入域。并本地缓存终端设备的加入域请求,等网络连接恢复后,再自动提交到区块链装置上。It should be noted that, if the local area network is disconnected from the external network at this time, if the domain gateway copyright management device successfully verifies the signature of the address of the terminal device and the private key of the domain gateway copyright management device, the joining domain of the terminal device is approved first. And the local domain cache device joins the domain request, and after the network connection is restored, it is automatically submitted to the blockchain device.
707、区块链装置接收域网关版权管理装置发送的加入域请求,并对该请求中的信息进行校验。707. The blockchain device receives the join domain request sent by the domain gateway copyright management device, and checks the information in the request.
对该请求中的信息进行校验具体包括:校验创建域事务的事务ID是否存在、域网关版权管理装置的私钥的签名是否正确、创建域事务的输出内容中的域标识和加入域请求中的域标识是否相同以及终端设备的地址是否符合生成规范,若均是,则校验成功。The verification of the information in the request specifically includes: verifying whether the transaction ID of the domain creation transaction exists, whether the signature of the private key of the domain gateway copyright management device is correct, the domain identifier in the output content of the creation domain transaction, and the joining domain request Whether the domain identifiers in the domain are the same and whether the address of the terminal device meets the generation specifications. If yes, the verification succeeds.
具体的校验方法为:1)在区块链装置中查询创建域事务的事务ID是否存在。The specific verification method is as follows: 1) Query whether the transaction ID of the domain transaction is present in the blockchain device.
2)根据创建域事务的事务ID到区块链处理装置中查询该事务的输出内容,采用域网关版权管理装置的公钥对域网关版权管理装置的私钥的签名进行解密,若解密成功、且解密结果与该输出内容包含的域网关版权管理装置的地址一致,则域网关版权管理装置的私钥的签名正确,否则,域网关版权管理装置的私钥的签名不正确。2) according to the transaction ID of the creation domain transaction to the block chain processing device to query the output content of the transaction, and use the public key of the domain gateway copyright management device to decrypt the signature of the private key of the domain gateway copyright management device, if the decryption is successful, And the decryption result is consistent with the address of the domain gateway copyright management device included in the output content, and the signature of the private key of the domain gateway copyright management device is correct; otherwise, the signature of the private key of the domain gateway copyright management device is incorrect.
3)创建域事务的输出内容中的域标识和加入域请求中的域标识是否相同。3) The domain identifier in the output content of the created domain transaction is the same as the domain identifier in the join domain request.
4)判断终端设备的地址是否符合生成规范。4) Determine whether the address of the terminal device conforms to the generation specification.
需要说明的是,在步骤705处域网关版权管理装置也可以不对终端设备的地址和域网关版权管理装置的私钥的签名进行校验,该情况下,域网关版权管理装置可以直接将终端设备 发送的加入域请求转发到区块链装置。It should be noted that, in step 705, the domain gateway copyright management device may not verify the address of the terminal device and the signature of the private key of the domain gateway copyright management device. In this case, the domain gateway copyright management device may directly connect the terminal device. The sent join domain request is forwarded to the blockchain device.
708、区块链装置构造加入域事务并将加入域事务存储在区块链中。708. The blockchain device construct joins the domain transaction and stores the joined domain transaction in the blockchain.
加入域事务的输入内容为创建域事务ID和域网关版权管理装置的私钥的签名,输出内容为域网关版权管理装置的地址、终端设备的地址和域标识。The input to the domain transaction is the signature of the domain transaction ID and the private key of the domain gateway copyright management device. The output is the address of the domain gateway copyright management device, the address of the terminal device, and the domain identifier.
709、区块链装置向域网关版权管理装置返回加入域响应。709. The blockchain device returns a join domain response to the domain gateway copyright management device.
710、域网关版权管理装置向终端设备返回加入域响应。710. The domain gateway copyright management device returns a join domain response to the terminal device.
具体的,终端设备接收到加入域响应则确定自身已经加入域。Specifically, the terminal device determines that it has joined the domain after receiving the join domain response.
上述方法在具体实现时,域网关版权管理装置可以向区块链装置中的区块链域管理装置发送创建域请求,由区块链域管理装置完成对创建域请求中的信息的校验后,将构造的加入域事务向区块链处理装置发送,由区块链处理装置将该事务存储在区块链中。When the foregoing method is specifically implemented, the domain gateway copyright management apparatus may send a create domain request to the blockchain domain management apparatus in the blockchain apparatus, and the blockchain domain management apparatus completes verification of the information in the create domain request. The constructed join domain transaction is sent to the blockchain processing device, and the transaction is stored in the blockchain by the blockchain processing device.
通过上述过程,将终端设备加入域的加入域事务存储在区块链中,确保了终端设备加入域的过程数据的高安全性和可审计性。Through the above process, the join domain transaction of the terminal device joining the domain is stored in the blockchain, which ensures the high security and auditability of the process data of the terminal device joining the domain.
另外,在一些场景下,域中的终端设备需要退出域,例如,临时客人作客期间加入域,需要离开时,该客人使用的终端设备需要退出域;或者,终端设备坏掉后,域网关管理客户端需要让该终端设备退出域。如图8所示,终端设备退出域的过程具体可以为:In addition, in some scenarios, the terminal device in the domain needs to log out of the domain. For example, when the temporary guest joins the domain during the guest, when the user needs to leave, the terminal device used by the guest needs to exit the domain; or, after the terminal device is broken, the domain gateway manages The client needs to let the terminal device exit the domain. As shown in Figure 8, the process of the terminal device exiting the domain may be as follows:
801、域网关版权管理装置接收退出域请求并向区块链装置发送退出域请求。801. The domain gateway copyright management device receives the exit domain request and sends an exit domain request to the blockchain device.
其中,退出域请求可以为终端设备(或域网关管理客户端)发送的。The exit domain request can be sent for the terminal device (or the domain gateway management client).
其中,退出域请求包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名。The exit domain request includes a signature of the terminal device joining the domain transaction ID and the private key of the domain gateway copyright management device.
802、区块链装置接收域网关版权管理装置发送的退出域请求,并对该请求中的信息进行校验。802. The blockchain device receives an exit domain request sent by the domain gateway copyright management device, and checks the information in the request.
对该请求中的信息进行校验具体包括:加入域事务的事务ID是否存在以及域网关版权管理装置的私钥的签名是否正确,若均是,则校验成功。The verification of the information in the request specifically includes whether the transaction ID of the domain transaction is present and the signature of the private key of the domain gateway copyright management device is correct. If yes, the verification is successful.
具体的校验方法为:1)在区块链装置中查询终端设备加入域事务的事务ID是否存在。The specific verification method is as follows: 1) Query whether the transaction ID of the terminal device joining the domain transaction exists in the blockchain device.
2)根据终端设备加入域事务的事务ID到区块链装置中查询该事务的输出内容,采用域网关版权管理装置的公钥对域网关版权管理装置的私钥的签名进行解密,若解密成功、且解密结果与该输出内容包含的域网关版权管理装置的地址一致,则域网关版权管理装置的私钥的签名正确,否则,域网关版权管理装置的私钥的签名不正确。2) according to the transaction ID of the terminal device joining the domain transaction to the block chain device to query the output content of the transaction, and using the public key of the domain gateway copyright management device to decrypt the signature of the private key of the domain gateway copyright management device, if the decryption is successful And the decryption result is consistent with the address of the domain gateway copyright management device included in the output content, and the signature of the private key of the domain gateway copyright management device is correct; otherwise, the signature of the private key of the domain gateway copyright management device is incorrect.
803、在校验成功后,区块链装置构造退出域事务并将退出域事务存储在区块链中。803. After the verification succeeds, the blockchain device constructs the exit domain transaction and stores the exit domain transaction in the blockchain.
其中,退出域事务的输入内容包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,输出内容为空。The input content of the exit domain transaction includes the signature of the terminal device joining the domain transaction ID and the private key of the domain gateway copyright management device, and the output content is empty.
804、区块链装置向域网关版权管理装置返回退出域响应。804. The blockchain device returns an exit domain response to the domain gateway copyright management device.
在步骤804之后,域网关版权管理装置还可以向终端设备(或域网关管理客户端)返回退出域响应。 After step 804, the domain gateway rights management device may also return an exit domain response to the terminal device (or domain gateway management client).
上述方法在具体实现时,域网关版权管理装置可以向区块链装置中的区块链域管理装置发送退出域请求,由区块链域管理装置完成对退出域请求中的信息的校验后,将构造的退出域事务向区块链处理装置发送,由区块链处理装置将该事务存储在区块链中。When the foregoing method is specifically implemented, the domain gateway copyright management apparatus may send an exit domain request to the blockchain domain management apparatus in the blockchain apparatus, and the blockchain domain management apparatus completes verification of the information in the exit domain request. The constructed exit domain transaction is sent to the blockchain processing device, and the transaction is stored in the blockchain by the blockchain processing device.
通过上述过程,将终端设备退出域的退出域事务存储在区块链中,确保了终端设备退出域的过程数据的高安全性和可审计性。Through the above process, the exit domain transaction of the terminal device exiting the domain is stored in the blockchain, which ensures high security and auditability of the process data of the terminal device exiting the domain.
本发明实施例还提供了一种域网关版权管理装置90,如图9所示,包括:The embodiment of the present invention further provides a domain gateway copyright management device 90, as shown in FIG. 9, comprising:
接收单元901,用于接收终端设备发送的数字内容的许可证请求,许可证请求中包括数字内容的标识ID;The receiving unit 901 is configured to receive a license request for the digital content sent by the terminal device, where the license request includes an identifier ID of the digital content;
获取单元902,用于根据数字内容的ID获取域许可,域许可包括采用域网关版权管理装置的公钥加密后的数字内容的解密密钥;An obtaining unit 902, configured to acquire a domain license according to an ID of the digital content, where the domain license includes a decryption key of the digital content encrypted by using a public key of the domain gateway copyright management device;
生成单元903,用于根据域许可生成终端设备的许可证;a generating unit 903, configured to generate a license of the terminal device according to the domain license;
发送单元904,用于将终端设备的许可证发送给终端设备;a sending unit 904, configured to send a license of the terminal device to the terminal device;
发送单元904,还用于向区块链装置发送许可证分发事务请求,许可证分发事务请求包括域许可证事务ID,域网关版权管理装置的私钥的签名,终端设备的地址以及许可信息,以使得区块链装置校验域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造许可证分发事务并将许可证分发事务存储在区块链中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。The sending unit 904 is further configured to send a license distribution transaction request to the blockchain device, where the license distribution transaction request includes a domain license transaction ID, a signature of a private key of the domain gateway copyright management device, an address of the terminal device, and license information, In order for the blockchain device to verify the domain license transaction ID, whether the signature of the private key of the domain gateway copyright management device is correct, after the verification is successful, construct a license distribution transaction and store the license distribution transaction in the block. In the chain, the input of the license distribution transaction includes the domain license transaction ID and the signature of the private key of the domain gateway copyright management device, and the output includes the address of the terminal device and the license information.
可选的,许可证请求中还包括终端设备的地址,如图10所示,该装置90还包括:确定单元905,用于根据终端设备的地址确定终端设备为域网关版权管理装置创建的域中的设备。Optionally, the license request further includes an address of the terminal device. As shown in FIG. 10, the apparatus 90 further includes: a determining unit 905, configured to determine, according to an address of the terminal device, a domain created by the terminal device as a domain gateway copyright management device. In the device.
可选的,所述确定单元905,还用于确定域是否购买过数字内容;Optionally, the determining unit 905 is further configured to determine whether the domain has purchased digital content;
若是,所述获取单元902,具体用于根据数字内容的ID获取本地的域许可;If yes, the obtaining unit 902 is specifically configured to acquire a local domain license according to the ID of the digital content;
若否,所述发送单元904,还用于向数字内容提供装置发送域许可证颁发请求,域许可证颁发请求包括数字内容的ID、域网关版权管理装置的地址、域标识以及许可信息,以使得数字内容提供装置校验数字内容的ID在数据库中是否存在,在校验成功后,确定域网关版权管理装置的地址对应的帐号并对该帐号进行扣费处理,构造域许可证事务并将域许可证事务向区块链装置发送,从而使得区块链装置将域许可证事务存储在区块链中,数字内容提供装置生成域许可并向域网关版权管理装置发送,域许可证事务的输入内容包括数字内容提供装置的许可证事务ID、数字内容的许可证在数字内容提供装置的许可证事务中的索引以及数字内容提供装置的私钥的签名,域许可证事务的输出内容包括域网关版权管理装置的地址和许可信息。If not, the sending unit 904 is further configured to send a domain license issuance request to the digital content providing apparatus, where the domain license issuance request includes an ID of the digital content, an address of the domain gateway copyright management device, a domain identifier, and license information, to And causing the digital content providing device to check whether the ID of the digital content exists in the database, after the verification succeeds, determining an account corresponding to the address of the domain gateway copyright management device, and deducting the account for the account, constructing a domain license transaction and The domain license transaction is sent to the blockchain device such that the blockchain device stores the domain license transaction in the blockchain, and the digital content providing device generates the domain license and sends it to the domain gateway copyright management device, the domain license transaction The input content includes a license transaction ID of the digital content providing device, an index of the license of the digital content in the license transaction of the digital content providing device, and a signature of the private key of the digital content providing device, and the output content of the domain license transaction includes the domain The address and license information of the gateway copyright management device.
可选的,如图10所示,该装置90还包括:判断单元906,用于判断已使用的数字内容的许可证数目未超过域许可中的许可信息中限制的许可证个数。 Optionally, as shown in FIG. 10, the apparatus 90 further includes: a determining unit 906, configured to determine that the number of licenses of the used digital content does not exceed the number of licenses restricted in the license information in the domain license.
可选的,生成单元903具体用于:采用域网关版权管理装置的私钥对域许可中包含的加密后的数字内容的解密密钥进行解密,得到数字内容的解密密钥;采用终端设备的公钥对数字内容的解密密钥进行加密;根据采用终端设备的公钥加密后的数字内容的解密密钥、终端设备的地址、数字内容的ID和许可信息生成终端设备的许可证。Optionally, the generating unit 903 is specifically configured to: decrypt the decryption key of the encrypted digital content included in the domain license by using a private key of the domain gateway copyright management device, to obtain a decryption key of the digital content; and adopt a terminal device The public key encrypts the decryption key of the digital content; the license of the terminal device is generated according to the decryption key of the digital content encrypted with the public key of the terminal device, the address of the terminal device, the ID of the digital content, and the license information.
可选的,接收单元901,还用于接收终端设备发送的下发加密数字内容的请求,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;Optionally, the receiving unit 901 is further configured to receive a request for sending the encrypted digital content sent by the terminal device, where the encrypted digital content can be decrypted by using the digital content decryption key to obtain the digital content;
若域购买过数字内容,发送单元904还用于根据下发加密数字内容的请求向终端设备发送本地保存的加密数字内容;If the domain has purchased the digital content, the sending unit 904 is further configured to send the locally saved encrypted digital content to the terminal device according to the request for sending the encrypted digital content;
若域未购买过数字内容,如图10所示,该装置90还包括请求单元907,用于根据下发加密数字内容的请求向数字内容提供装置请求下发加密数字内容;该装置90还包括存储单元908,用于将数字内容提供装置下发的加密数字内容在本地进行保存,发送单元904还用于将加密数字内容向终端设备发送。If the domain has not purchased the digital content, as shown in FIG. 10, the device 90 further includes a requesting unit 907 for requesting the digital content providing device to deliver the encrypted digital content according to the request for sending the encrypted digital content; the device 90 further includes The storage unit 908 is configured to save the encrypted digital content delivered by the digital content providing device locally, and the sending unit 904 is further configured to send the encrypted digital content to the terminal device.
可选的,发送单元904,还用于将接收到的终端设备发送的加入域请求向区块链装置发送,加入域请求包括终端设备的地址、域网关版权管理装置的私钥的签名、域标识、域网关版权管理装置的地址以及创建域事务ID,以使得区块链装置校验创建域事务的事务ID是否存在、域网关版权管理装置的私钥的签名是否正确、创建域事务的输出内容中的域标识和加入域请求中的域标识是否相同以及终端设备的地址是否符合生成规范,在校验成功后,构造加入域事务并将加入域事务存储在区块链中,加入域事务的输入内容为创建域事务ID和域网关版权管理装置的私钥的签名,输出内容为域网关版权管理装置的地址、终端设备的地址和域标识。Optionally, the sending unit 904 is further configured to send the join domain request sent by the received terminal device to the blockchain device, where the domain request includes the address of the terminal device, the signature of the private key of the domain gateway copyright management device, and the domain. Identifying, the address of the domain gateway copyright management device, and creating a domain transaction ID to cause the blockchain device to verify whether the transaction ID of the created domain transaction exists, whether the signature of the private key of the domain gateway copyright management device is correct, and the output of the domain transaction is created. Whether the domain identifier in the content and the domain identifier in the join domain request are the same and the address of the terminal device conforms to the generation specification. After the verification succeeds, construct the join domain transaction and store the join domain transaction in the blockchain, and join the domain transaction. The input content is the signature of the domain transaction ID and the private key of the domain gateway copyright management device, and the output content is the address of the domain gateway copyright management device, the address of the terminal device, and the domain identifier.
可选的,发送单元904,还用于向区块链装置发送创建域请求,创建域请求包括域网关版权管理装置的地址和域网关版权管理装置的私钥的签名,以使得区块链装置在校验域网关版权管理装置的地址符合生成规范且域网关版权管理装置的私钥的签名正确后,构造创建域事务并将创建域事务存储在区块链中,创建域事务的输入内容为空,输出内容为域网关版权管理装置的私钥的签名、域网关版权管理装置的地址和域标识。Optionally, the sending unit 904 is further configured to send a create domain request to the blockchain device, where the domain request includes the address of the domain gateway copyright management device and the signature of the private key of the domain gateway copyright management device, so that the blockchain device After the address of the verification domain gateway copyright management device conforms to the generation specification and the signature of the private key of the domain gateway copyright management device is correct, the domain transaction is created and the domain transaction is created in the blockchain, and the input of the domain transaction is created. Empty, the output content is the signature of the private key of the domain gateway copyright management device, the address of the domain gateway copyright management device, and the domain identifier.
可选的,接收单元901,还用于接收退出域请求;Optionally, the receiving unit 901 is further configured to receive an exit domain request.
发送单元904,还用于向区块链装置发送退出域请求,退出域请求包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,以使得区块链装置校验加入域事务的事务ID是否存在以及域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造退出域事务并将退出域事务存储在区块链中,退出域事务的输入内容包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,输出内容为空。The sending unit 904 is further configured to send an exit domain request to the blockchain device, where the exit domain request includes the terminal device joining the domain transaction ID and the signature of the private key of the domain gateway copyright management device, so that the blockchain device checks the join domain transaction. Whether the transaction ID exists and the signature of the private key of the domain gateway copyright management device is correct. After the verification is successful, the exit domain transaction is constructed and the exit domain transaction is stored in the blockchain, and the input content of the exit domain transaction includes the terminal device. The domain transaction ID and the signature of the private key of the domain gateway copyright management device are added, and the output content is empty.
本发明实施例提供的装置90中包括的各个单元用于执行上述方法,因此,装置90的有益效果可以参见上述方法,在此不再赘述。The various units included in the device 90 provided by the embodiment of the present invention are used to perform the foregoing method. Therefore, the beneficial effects of the device 90 can be referred to the foregoing method, and details are not described herein again.
本发明实施例还提供了一种域网关版权管理装置110,如图11所示,包括:接收器1101、存储器1102、处理器1103和发送器1104。 The embodiment of the present invention further provides a domain gateway copyright management apparatus 110, as shown in FIG. 11, comprising: a receiver 1101, a memory 1102, a processor 1103, and a transmitter 1104.
其中,接收器1101、存储器1102、处理器1103和发送器1104之间是通过总线系统1105耦合在一起的,其中存储器1102可能包含随机存取存储器,也可能还包括非易失性存储器,例如至少一个磁盘存储器。总线系统1105可以是工业标准体系结构(Industry Standard Architecture,简称ISA)总线、外部设备互连(Peripheral Component,简称PCI)总线或扩展工业标准体系结构(Extended Industry Standard Architecture,简称EISA)总线等。该总线系统1105可以分为地址总线、数据总线、控制总线等。为便于表示,图11中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。The receiver 1101, the memory 1102, the processor 1103, and the transmitter 1104 are coupled together by a bus system 1105. The memory 1102 may include a random access memory, and may also include a non-volatile memory, such as at least A disk storage. The bus system 1105 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. The bus system 1105 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 11, but it does not mean that there is only one bus or one type of bus.
需要说明的是,接收器1101、存储器1102、处理器1103和发送器1104具体执行上述方法,具体过程可参见上文。It should be noted that the receiver 1101, the memory 1102, the processor 1103, and the transmitter 1104 specifically perform the foregoing methods, and the specific process can be referred to above.
其中,图9和图10中的接收单元901可以为接收器1101,发送单元904可以为发送器1104,其余单元可以为处理器1103,其余单元可以以硬件形式内嵌于或独立于装置110的处理器1103中,也可以以软件形式存储于装置110的存储器1102中,以便于处理器1103调用执行以上各个单元对应的操作,该处理器可以为中央处理器(Central Processing Unit,简称CPU)、特定集成电路(Application Specific Integrated Circuit,简称ASIC)或者是被配置成实施本发明实施例的一个或多个集成电路。The receiving unit 901 in FIG. 9 and FIG. 10 may be the receiver 1101, the sending unit 904 may be the transmitter 1104, and the remaining units may be the processor 1103. The remaining units may be embedded in hardware or independent of the device 110. The processor 1103 can also be stored in the memory 1102 of the device 110 in the form of software, so that the processor 1103 can call the operation corresponding to each unit, and the processor can be a central processing unit (CPU). An Application Specific Integrated Circuit (ASIC) is one or more integrated circuits configured to implement the embodiments of the present invention.
本发明实施例提供的装置110中包括的各个器件用于执行上述方法,因此,装置110的有益效果可以参见上述方法,在此不再赘述。The various devices included in the device 110 provided by the embodiment of the present invention are used to perform the foregoing method. Therefore, the beneficial effects of the device 110 can be referred to the foregoing method, and details are not described herein again.
本发明实施例还提供了一种区块链装置120,如图12所示,包括:The embodiment of the present invention further provides a blockchain device 120, as shown in FIG. 12, comprising:
接收单元1201,用于接收域网关版权管理装置发送的许可证分发事务请求,许可证分发事务请求包括域许可证事务ID,域网关版权管理装置的私钥的签名,终端设备的地址以及许可信息;The receiving unit 1201 is configured to receive a license distribution transaction request sent by the domain gateway copyright management device, where the license distribution transaction request includes a domain license transaction ID, a signature of a private key of the domain gateway copyright management device, an address of the terminal device, and a license information. ;
校验单元1202,用于校验域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确;The verification unit 1202 is configured to check whether the domain license transaction ID exists, and whether the signature of the private key of the domain gateway copyright management device is correct;
构造存储单元1203,用于在校验成功后,构造许可证分发事务并将许可证分发事务存储在区块链中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。The storage unit 1203 is configured to construct a license distribution transaction and store the license distribution transaction in the blockchain after the verification succeeds, and the input content of the license distribution transaction includes the domain license transaction ID and the domain gateway copyright management device. The signature of the private key, the output includes the address and license information of the terminal device.
该装置可以将许可证分发事务存储在区块链中,确保了许可证分发事务的过程数据的高安全性和可审计性。The appliance stores license distribution transactions in a blockchain, ensuring high security and auditability of process data for license distribution transactions.
本发明实施例还提供了一种区块链装置130,如图13所示,包括:接收器1301、存储器1302和处理器1303。The embodiment of the present invention further provides a blockchain device 130, as shown in FIG. 13, comprising: a receiver 1301, a memory 1302, and a processor 1303.
其中,接收器1301、存储器1302和处理器1303之间是通过总线系统1304耦合在一起的,其中存储器1302可能包含随机存取存储器,也可能还包括非易失性存储器,例如至少一个磁盘存储器。总线系统1304可以是ISA、PCI或EISA总线等。该总线系统1304可以分为地址总线、数据总线、控制总线等。为便于表示,图13中仅用一条粗线表示,但并不表 示仅有一根总线或一种类型的总线。The receiver 1301, the memory 1302 and the processor 1303 are coupled together by a bus system 1304, wherein the memory 1302 may include a random access memory, and may also include a non-volatile memory, such as at least one disk storage. Bus system 1304 can be an ISA, PCI or EISA bus or the like. The bus system 1304 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 13, but it is not Show only one bus or one type of bus.
需要说明的是,接收器1301、存储器1302和处理器1303具体执行上述方法,具体过程可参见上文。It should be noted that the receiver 1301, the memory 1302, and the processor 1303 specifically perform the foregoing methods, and the specific process can be referred to above.
其中,图12中的接收单元1201可以为接收器1301,其余单元可以为处理器1303,其余单元可以以硬件形式内嵌于或独立于装置130的处理器1303中,也可以以软件形式存储于装置130的处理器1303中,以便于处理器1303调用执行以上各个单元对应的操作,该处理器可以为CPU、ASIC或者是被配置成实施本发明实施例的一个或多个集成电路。The receiving unit 1201 in FIG. 12 may be the receiver 1301, and the remaining units may be the processor 1303. The remaining units may be embedded in or independent of the processor 1303 of the device 130 in hardware, or may be stored in software. In processor 1303 of device 130, in order for processor 1303 to invoke operations corresponding to the various units above, the processor may be a CPU, an ASIC, or one or more integrated circuits configured to implement embodiments of the present invention.
本发明实施例提供的装置130为与装置120对应的装置,因此,装置130的有益效果可以参见装置120的有益效果,在此不再赘述。The device 130 provided by the embodiment of the present invention is a device corresponding to the device 120. Therefore, the beneficial effects of the device 130 can be seen in the beneficial effects of the device 120, and details are not described herein again.
本发明实施例还提供了一种终端设备140,如图14所示,包括:The embodiment of the present invention further provides a terminal device 140, as shown in FIG. 14, comprising:
发送单元1401,用于向数字内容提供装置发送数字内容的许可证请求,数字内容的许可证请求中包括数字内容的ID、终端设备的地址和终端设备所属的域的域标识,以使得数字内容提供装置校验终端设备所属的域存在、终端设备为该域中的设备以及终端设备的地址符合生成规范,在验证成功后向区块链装置发送许可证分发事务,从而使得区块链装置将许可证分发事务存储在区块链中,数字内容提供装置生成并向终端设备分发数字内容的许可证;The sending unit 1401 is configured to send a license request for the digital content to the digital content providing apparatus, where the license request of the digital content includes an ID of the digital content, an address of the terminal device, and a domain identifier of a domain to which the terminal device belongs, so that the digital content Providing the device to verify that the domain to which the terminal device belongs, the terminal device being the device in the domain, and the address of the terminal device comply with the generation specification, and after the verification succeeds, sending a license distribution transaction to the blockchain device, so that the blockchain device will The license distribution transaction is stored in the blockchain, and the digital content providing device generates and distributes a license for the digital content to the terminal device;
接收单元1402,用于接收数字内容提供装置分发的许可证,许可证包括被终端设备公钥加密后的数字内容解密密钥。The receiving unit 1402 is configured to receive a license distributed by the digital content providing device, where the license includes a digital content decryption key encrypted by the terminal device public key.
可选的,如图15所示,该装置140还包括:Optionally, as shown in FIG. 15, the device 140 further includes:
请求单元1403,用于根据数字内容的ID向数字内容提供装置请求下发加密数字内容,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;The requesting unit 1403 is configured to request the digital content providing device to deliver the encrypted digital content according to the ID of the digital content, and the encrypted digital content can be decrypted by using the digital content decryption key to obtain the digital content;
所述接收单元1402,还用于接收数字内容提供装置下发的加密数字内容;The receiving unit 1402 is further configured to receive the encrypted digital content delivered by the digital content providing device;
获取单元1404,用于使用终端设备的私钥对许可证中包括的数字内容的解密密钥进行解密,得到数字内容的解密密钥,再采用数字内容的解密密钥对加密数字内容进行解密,得到数字内容。The obtaining unit 1404 is configured to decrypt the decryption key of the digital content included in the license by using the private key of the terminal device, obtain a decryption key of the digital content, and decrypt the encrypted digital content by using the decryption key of the digital content. Get digital content.
本发明实施例提供的终端设备140中包括的各个单元用于执行上述方法,因此,终端设备140的有益效果可以参见上述方法,在此不再赘述。The various units included in the terminal device 140 provided by the embodiment of the present invention are used to perform the foregoing method. Therefore, the beneficial effects of the terminal device 140 can be referred to the foregoing method, and details are not described herein again.
本发明实施例还提供了一种终端设备160,如图16所示,包括:发送器1601和接收器1602。其中,发送器1601用于执行发送单元1401的动作,接收器1602用于执行接收单元1402的动作,The embodiment of the present invention further provides a terminal device 160, as shown in FIG. 16, comprising: a transmitter 1601 and a receiver 1602. The transmitter 1601 is configured to perform an action of the sending unit 1401, and the receiver 1602 is configured to perform an action of the receiving unit 1402.
本发明实施例提供的终端设备160中包括的各个器件用于执行上述方法,因此,终端设备160的有益效果可以参见上述方法,在此不再赘述。 Each device included in the terminal device 160 provided by the embodiment of the present invention is used to perform the foregoing method. Therefore, the beneficial effects of the terminal device 160 can be referred to the foregoing method, and details are not described herein again.
本发明实施例还提供了一种数字内容提供装置170,如图17所示,包括:The embodiment of the present invention further provides a digital content providing apparatus 170, as shown in FIG. 17, comprising:
接收单元1701,用于接收终端设备发送的数字内容的许可证请求,数字内容的许可证请求包括数字内容的ID、终端设备的地址和终端设备所属的域的域标识;The receiving unit 1701 is configured to receive a license request for the digital content sent by the terminal device, where the license request of the digital content includes an ID of the digital content, an address of the terminal device, and a domain identifier of a domain to which the terminal device belongs;
校验单元1702,用于校验终端设备所属的域存在、终端设备为该域中的设备以及终端设备的地址符合生成规范;a verification unit 1702, configured to verify that a domain to which the terminal device belongs, the terminal device is a device in the domain, and an address of the terminal device conforms to a generation specification;
发送单元1703,用于向区块链装置发送许可证分发事务,从而使得区块链装置将许可证分发事务存储在区块链中;a sending unit 1703, configured to send a license distribution transaction to the blockchain device, so that the blockchain device stores the license distribution transaction in the blockchain;
执行单元1704,用于根据数字内容的ID生成并向终端设备分发数字内容的许可证;许可证包括被终端设备公钥加密后的数字内容解密密钥。The executing unit 1704 is configured to generate and distribute a license of the digital content according to the ID of the digital content; the license includes a digital content decryption key encrypted by the terminal device public key.
可选的,执行单元1704,具体用于根据数字内容的ID获取数字内容的解密密钥;采用终端设备的公钥对数字内容的解密密钥进行加密;根据加密后的数字内容的解密密钥、终端设备的地址、数字内容的ID和许可信息生成许可证。Optionally, the executing unit 1704 is configured to acquire a decryption key of the digital content according to the ID of the digital content; encrypt the decryption key of the digital content by using the public key of the terminal device; and decrypt the key according to the encrypted digital content. A license is generated by the address of the terminal device, the ID of the digital content, and the license information.
可选的,所述接收单元1701,还用于接收终端设备发送的下发加密数字内容的请求,加密数字内容能够采用数字内容解密密钥进行解密从而获取到数字内容;所述发送单元Optionally, the receiving unit 1701 is further configured to receive a request for sending the encrypted digital content sent by the terminal device, where the encrypted digital content can be decrypted by using a digital content decryption key to obtain digital content;
1703,还用于根据下发加密数字内容的请求向终端设备下发加密数字内容,以使得终端设备获取数字内容。1703. The method is further configured to send the encrypted digital content to the terminal device according to the request for sending the encrypted digital content, so that the terminal device acquires the digital content.
本发明实施例提供的装置170中包括的各个单元用于执行上述方法,因此,装置170的有益效果可以参见上述方法,在此不再赘述。The various units included in the apparatus 170 provided by the embodiment of the present invention are used to perform the foregoing method. Therefore, the beneficial effects of the apparatus 170 can be referred to the foregoing method, and details are not described herein again.
本发明实施例还提供了一种数字内容提供装置180,如图18所示,包括:接收器1801、存储器1802、处理器1803和发送器1804。The embodiment of the present invention further provides a digital content providing apparatus 180, as shown in FIG. 18, comprising: a receiver 1801, a memory 1802, a processor 1803, and a transmitter 1804.
其中,接收器1801、存储器1802、处理器1803和发送器1804之间是通过总线系统1805耦合在一起的,其中存储器1802可能包含随机存取存储器,也可能还包括非易失性存储器,例如至少一个磁盘存储器。总线系统1805可以是ISA、PCI或EISA总线等。该总线系统1805可以分为地址总线、数据总线、控制总线等。为便于表示,图18中仅用一条粗线表示,但并不表示仅有一根总线或一种类型的总线。The receiver 1801, the memory 1802, the processor 1803, and the transmitter 1804 are coupled together by a bus system 1805. The memory 1802 may include a random access memory, and may also include a non-volatile memory, such as at least A disk storage. The bus system 1805 can be an ISA, PCI or EISA bus or the like. The bus system 1805 can be divided into an address bus, a data bus, a control bus, and the like. For ease of representation, only one thick line is shown in Figure 18, but it does not mean that there is only one bus or one type of bus.
需要说明的是,接收器1801、存储器1802、处理器1803和发送器1804具体执行上述方法,具体过程可参见上文。It should be noted that the receiver 1801, the memory 1802, the processor 1803, and the transmitter 1804 specifically perform the foregoing methods, and the specific process can be referred to above.
其中,图17中的接收单元1701可以为接收器1801,发送单元可以为发送器1804,其余单元可以为处理器1803,其余单元可以以硬件形式内嵌于或独立于装置180的处理器1803中,也可以以软件形式存储于装置180的处理器1803中,以便于处理器1803调用执行以上各个单元对应的操作,该处理器可以为CPU、ASIC或者是被配置成实施本发明实施例的一个或多个集成电路。The receiving unit 1701 in FIG. 17 may be the receiver 1801, the sending unit may be the transmitter 1804, and the remaining units may be the processor 1803. The remaining units may be embedded in the hardware or in the processor 1803 of the device 180. It may also be stored in the form of software in the processor 1803 of the device 180, so that the processor 1803 calls for performing operations corresponding to the above respective units, and the processor may be a CPU, an ASIC or a one configured to implement an embodiment of the present invention. Or multiple integrated circuits.
本发明实施例提供的装置180中包括的各个器件用于执行上述方法,因此,装置180的有益效果可以参见上述方法,在此不再赘述。 The various devices included in the device 180 provided by the embodiment of the present invention are used to perform the foregoing method. Therefore, the beneficial effects of the device 180 can be referred to the foregoing method, and details are not described herein again.
本发明实施例还提供了一种共享数字内容的许可证的系统190,如图19所示,包括:域网关版权管理装置1901和区块链装置1902,其中,域网关版权管理装置1901用于执行上述方法,区块链装置1902用于:校验许可证分发事务请求中的域许可证事务ID是否存在,域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造许可证分发事务并将许可证分发事务存储在区块链中,许可证分发事务的输入内容包括域许可证事务ID和域网关版权管理装置的私钥的签名,输出内容包括终端设备的地址和许可信息。The embodiment of the present invention further provides a system 190 for sharing licenses for digital content. As shown in FIG. 19, the system includes: a domain gateway copyright management device 1901 and a blockchain device 1902, wherein the domain gateway copyright management device 1901 is used. Executing the above method, the blockchain device 1902 is configured to: verify whether the domain license transaction ID in the license distribution transaction request exists, whether the signature of the private key of the domain gateway copyright management device is correct, and after the verification succeeds, construct the license The license distribution transaction stores the license distribution transaction in the blockchain, and the input of the license distribution transaction includes the domain license transaction ID and the signature of the private key of the domain gateway copyright management device, and the output includes the address and license of the terminal device. information.
可选的,区块链装置1902还用于:接收域网关版权管理装置发送的加入域请求,加入域请求包括终端设备的地址、域网关版权管理装置的私钥的签名、域标识、域网关版权管理装置的地址以及创建域事务ID;校验创建域事务的事务ID是否存在、域网关版权管理装置的私钥的签名是否正确、创建域事务的输出内容中的域标识和加入域请求中的域标识是否相同以及终端设备的地址是否符合生成规范,在校验成功后,构造加入域事务并将加入域事务存储在区块链中,加入域事务的输入内容为创建域事务ID和域网关版权管理装置的私钥的签名,输出内容为域网关版权管理装置的地址、终端设备的地址和域标识。Optionally, the blockchain device 1902 is further configured to: receive a join domain request sent by the domain gateway copyright management device, where the join domain request includes an address of the terminal device, a signature of the private key of the domain gateway copyright management device, a domain identifier, and a domain gateway. The address of the copyright management device and the creation of the domain transaction ID; verifying whether the transaction ID of the creation domain transaction exists, whether the signature of the private key of the domain gateway copyright management device is correct, the domain identification in the output content of the creation domain transaction, and the joining domain request Whether the domain identifier is the same and whether the address of the terminal device conforms to the generation specification. After the verification succeeds, construct the join domain transaction and store the join domain transaction in the blockchain. The input content of the join domain transaction is to create the domain transaction ID and domain. The signature of the private key of the gateway copyright management device, and the output content is the address of the domain gateway copyright management device, the address of the terminal device, and the domain identifier.
可选的,区块链装置1902还用于:接收域网关版权管理装置发送的创建域请求,创建域请求包括域网关版权管理装置的地址和域网关版权管理装置的私钥的签名;校验域网关版权管理装置的地址是否符合生成规范且域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造创建域事务并将创建域事务存储在区块链中,创建域事务的输入内容为空,输出内容为域网关版权管理装置的私钥的签名、域网关版权管理装置的地址和域标识。Optionally, the blockchain device 1902 is further configured to: receive a create domain request sent by the domain gateway copyright management device, where the domain request includes the address of the domain gateway copyright management device and the signature of the private key of the domain gateway copyright management device; Whether the address of the domain gateway copyright management device conforms to the generation specification and the signature of the private key of the domain gateway copyright management device is correct. After the verification succeeds, construct the domain transaction and store the created domain transaction in the blockchain to create a domain transaction. The input content is empty, and the output content is the signature of the private key of the domain gateway copyright management device, the address of the domain gateway copyright management device, and the domain identifier.
可选的,区块链装置1902还用于:接收域网关版权管理装置发送的退出域请求,退出域请求包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名;校验加入域事务的事务ID是否存在以及域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造退出域事务并将退出域事务存储在区块链中,退出域事务的输入内容包括终端设备加入域事务ID以及域网关版权管理装置的私钥的签名,输出内容为空。Optionally, the blockchain device 1902 is further configured to: receive an exit domain request sent by the domain gateway copyright management device, and the exit domain request includes a signature of the terminal device joining the domain transaction ID and the private key of the domain gateway copyright management device; Whether the transaction ID of the domain transaction exists and the signature of the private key of the domain gateway copyright management device is correct. After the verification succeeds, the exit domain transaction is constructed and the exit domain transaction is stored in the blockchain, and the input of the exit domain transaction includes The terminal device joins the domain transaction ID and the signature of the private key of the domain gateway copyright management device, and the output content is empty.
该系统中的装置用于实现上述方法,因此,该系统的有益效果可以参见上述方法的有益效果,在此不再赘述。The device in the system is used to implement the above method. Therefore, the beneficial effects of the system can be seen in the beneficial effects of the above method, and details are not described herein again.
在本申请所提供的几个实施例中,应该理解到,所揭露的装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施例仅仅是示意性的,例如,所述模块的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个模块或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。In the several embodiments provided by the present application, it should be understood that the disclosed apparatus and method may be implemented in other manners. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be another division manner, for example, multiple modules or components may be combined or Can be integrated into another system, or some features can be ignored or not executed.
所述作为分离部件说明的模块可以是或者也可以不是物理上分开的,作为模块显示的部件可以是或者也可以不是物理模块,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施例方案的目的。The modules described as separate components may or may not be physically separated. The components displayed as modules may or may not be physical modules, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the embodiment.
另外,在本发明各个实施例中的各功能模块可以集成在一个处理模块中,也可以两个或两个以上模块集成在一个模块中。上述集成的模块既可以采用硬件的形式实现,也可以采用硬件加软件功能模块的形式实现。In addition, each functional module in each embodiment of the present invention may be integrated into one processing module, or two or more modules may be integrated into one module. The above integrated modules can be implemented in the form of hardware or in the form of hardware plus software function modules.
上述以软件功能模块的形式实现的集成的模块,可以存储在一个计算机可读取存储介质 中。上述软件功能模块存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)执行本发明各个实施例所述方法的部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(Read-Only Memory,简称ROM)、随机存取存储器(Random Access Memory,简称RAM)、磁碟或者光盘等各种可以存储程序代码的介质。 The above integrated module implemented in the form of a software function module can be stored in a computer readable storage medium in. The software functional modules described above are stored in a storage medium and include instructions for causing a computer device (which may be a personal computer, server, or network device, etc.) to perform some of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, and the like, and the program code can be stored. Medium.

Claims (29)

  1. 一种共享数字内容的许可证的方法,其特征在于,包括:A method of sharing a license for digital content, comprising:
    域网关版权管理装置接收终端设备发送的数字内容的许可证请求,所述许可证请求中包括所述数字内容的标识ID;The domain gateway copyright management device receives a license request for the digital content sent by the terminal device, where the license request includes an identifier ID of the digital content;
    所述域网关版权管理装置根据所述数字内容的ID获取域许可,所述域许可包括采用所述域网关版权管理装置的公钥加密后的数字内容的解密密钥;The domain gateway copyright management apparatus acquires a domain license according to an ID of the digital content, the domain license including a decryption key of the digital content encrypted by using a public key of the domain gateway copyright management apparatus;
    所述域网关版权管理装置根据所述域许可生成所述终端设备的许可证,并发送给所述终端设备;The domain gateway copyright management device generates a license of the terminal device according to the domain license, and sends the license to the terminal device;
    所述域网关版权管理装置向区块链装置发送许可证分发事务请求,所述许可证分发事务请求包括域许可证事务ID,所述域网关版权管理装置的私钥的签名,所述终端设备的地址以及许可信息。The domain gateway copyright management device transmits a license distribution transaction request to the blockchain device, the license distribution transaction request including a domain license transaction ID, a signature of a private key of the domain gateway copyright management device, the terminal device Address and license information.
  2. 根据权利要求1所述的方法,其特征在于,所述许可证请求中还包括所述终端设备的地址,在所述域网关版权管理装置根据所述数字内容的ID获取域许可之前,所述方法还包括:The method according to claim 1, wherein the license request further includes an address of the terminal device, before the domain gateway copyright management device acquires a domain license according to an ID of the digital content, The method also includes:
    所述域网关版权管理装置根据所述终端设备的地址确定所述终端设备为所述域网关版权管理装置创建的域中的设备。The domain gateway copyright management device determines, according to the address of the terminal device, the device in the domain created by the terminal device for the domain gateway copyright management device.
  3. 根据权利要求2所述的方法,其特征在于,在所述域网关版权管理装置根据所述终端设备的地址确定所述终端设备为所述域网关版权管理装置创建的域中的设备之后,所述方法还包括:The method according to claim 2, wherein after the domain gateway copyright management device determines, according to the address of the terminal device, the device in the domain created by the terminal device for the domain gateway copyright management device, The method also includes:
    所述域网关版权管理装置确定所述域是否购买过所述数字内容;The domain gateway copyright management device determines whether the domain has purchased the digital content;
    若是,所述域网关版权管理装置根据所述数字内容的ID获取本地的域许可;If yes, the domain gateway copyright management device acquires a local domain license according to the ID of the digital content;
    若否,所述域网关版权管理装置向数字内容提供装置发送域许可证颁发请求,所述域许可证颁发请求包括所述数字内容的ID、所述域网关版权管理装置的地址、域标识以及许可信息。If not, the domain gateway copyright management device sends a domain license issuance request to the digital content providing device, the domain license issuance request including an ID of the digital content, an address of the domain gateway copyright management device, a domain identifier, and License information.
  4. 根据权利要求3所述的方法,其特征在于,在所述域网关版权管理装置根据所述域许可生成所述终端设备的许可证之前,所述方法还包括:The method according to claim 3, wherein before the domain gateway copyright management device generates the license of the terminal device according to the domain license, the method further includes:
    所述域网关版权管理装置判断已使用的所述数字内容的许可证数目未超过域许可中的许可信息中限制的许可证个数。The domain gateway copyright management apparatus judges that the number of licenses of the digital content that has been used does not exceed the number of licenses restricted in the license information in the domain license.
  5. 根据权利要求1-4任一项所述的方法,其特征在于,所述域网关版权管理装置根据所述域许可生成所述终端设备的许可证,包括:The method according to any one of claims 1-4, wherein the domain gateway copyright management device generates a license of the terminal device according to the domain license, including:
    所述域网关版权管理装置采用所述域网关版权管理装置的私钥对所述域许可中包含的加密后的数字内容的解密密钥进行解密,得到所述数字内容的解密密钥;The domain gateway copyright management device decrypts the decryption key of the encrypted digital content included in the domain license by using the private key of the domain gateway copyright management device to obtain a decryption key of the digital content;
    所述域网关版权管理装置采用所述终端设备的公钥对所述数字内容的解密密钥进行加密;The domain gateway copyright management device encrypts a decryption key of the digital content by using a public key of the terminal device;
    所述域网关版权管理装置根据采用所述终端设备的公钥加密后的数字内容的解密密钥、所述终端设备的地址、所述数字内容的ID和许可信息生成所述终端设备的许可证。The domain gateway copyright management apparatus generates a license of the terminal device according to a decryption key of the digital content encrypted by the public key of the terminal device, an address of the terminal device, an ID of the digital content, and license information. .
  6. 根据权利要求1-5任一项所述的方法,其特征在于,在所述域网关版权管理装置根据所述域许可生成所述终端设备的许可证,并发送给所述终端设备之后,所述方法还包括:The method according to any one of claims 1 to 5, wherein after the domain gateway copyright management apparatus generates a license of the terminal device according to the domain license and transmits the license to the terminal device, The method also includes:
    所述域网关版权管理装置接收所述终端设备发送的下发加密数字内容的请求,所述加密 数字内容能够采用所述数字内容解密密钥进行解密从而获取到所述数字内容;Receiving, by the terminal device, a request for sending encrypted digital content sent by the terminal device, the encryption The digital content can be decrypted using the digital content decryption key to obtain the digital content;
    若所述域购买过所述数字内容,所述域网关版权管理装置根据所述下发加密数字内容的请求向所述终端设备发送本地保存的加密数字内容;And if the domain purchases the digital content, the domain gateway copyright management device sends the locally stored encrypted digital content to the terminal device according to the request for sending the encrypted digital content;
    若所述域未购买过所述数字内容,所述域网关版权管理装置根据所述下发加密数字内容的请求向所述数字内容提供装置请求下发加密数字内容;所述域网关版权管理装置将所述数字内容提供装置下发的加密数字内容在本地进行保存并向所述终端设备发送。If the domain has not purchased the digital content, the domain gateway copyright management device requests the digital content providing device to deliver the encrypted digital content according to the request for sending the encrypted digital content; the domain gateway copyright management device The encrypted digital content delivered by the digital content providing device is locally saved and transmitted to the terminal device.
  7. 根据权利要求1-6任一项所述的方法,其特征在于,在域网关版权管理装置接收终端设备发送的数字内容的许可证请求之前,所述方法还包括:The method according to any one of claims 1-6, wherein before the domain gateway copyright management device receives the license request for the digital content sent by the terminal device, the method further includes:
    所述域网关版权管理装置接收所述终端设备发送的加入域请求并向所述区块链装置发送加入域请求,所述加入域请求包括所述终端设备的地址、所述域网关版权管理装置的私钥的签名、域标识、所述域网关版权管理装置的地址以及创建域事务ID。Receiving, by the domain gateway copyright management device, a join domain request sent by the terminal device, and sending a join domain request to the blockchain device, where the join domain request includes an address of the terminal device, and the domain gateway copyright management device The signature of the private key, the domain identifier, the address of the domain gateway rights management device, and the creation of the domain transaction ID.
  8. 根据权利要求7所述的方法,其特征在于,在所述域网关版权管理装置接收所述终端设备发送的加入域请求并向所述区块链装置发送加入域请求之前,所述方法还包括:The method according to claim 7, wherein before the domain gateway copyright management device receives the join domain request sent by the terminal device and sends a join domain request to the blockchain device, the method further includes :
    所述域网关版权管理装置向所述区块链装置发送创建域请求,所述创建域请求包括所述域网关版权管理装置的地址和所述域网关版权管理装置的私钥的签名。The domain gateway copyright management device transmits a create domain request to the blockchain device, the create domain request including an address of the domain gateway copyright management device and a signature of a private key of the domain gateway copyright management device.
  9. 根据权利要求1-8任一项所述的方法,其特征在于,所述方法还包括:The method of any of claims 1-8, wherein the method further comprises:
    所述域网关版权管理装置接收退出域请求并向所述区块链装置发送所述退出域请求,所述退出域请求包括所述终端设备加入域事务ID以及所述域网关版权管理装置的私钥的签名。Receiving, by the domain gateway copyright management device, an exit domain request and sending the exit domain request to the blockchain device, the exit domain request including the terminal device joining a domain transaction ID and a private of the domain gateway copyright management device The signature of the key.
  10. 一种共享数字内容的许可证的方法,其特征在于,包括:A method of sharing a license for digital content, comprising:
    终端设备向数字内容提供装置发送数字内容的许可证请求,所述数字内容的许可证请求中包括所述数字内容的ID、所述终端设备的地址和所述终端设备所属的域的域标识;The terminal device sends a license request for the digital content to the digital content providing device, where the license request of the digital content includes an ID of the digital content, an address of the terminal device, and a domain identifier of a domain to which the terminal device belongs;
    所述终端设备接收所述数字内容提供装置分发的许可证,所述许可证包括被所述终端设备公钥加密后的数字内容解密密钥。The terminal device receives a license distributed by the digital content providing device, the license including a digital content decryption key encrypted by the terminal device public key.
  11. 根据权利要求10所述的方法,其特征在于,在所述终端设备接收所述数字内容提供装置分发的许可证之后,所述方法还包括:The method according to claim 10, wherein after the terminal device receives the license distributed by the digital content providing device, the method further comprises:
    所述终端设备根据数字内容的ID向所述数字内容提供装置请求下发加密数字内容,所述加密数字内容能够采用所述数字内容解密密钥进行解密从而获取到所述数字内容;The terminal device requests the digital content providing device to deliver the encrypted digital content according to the ID of the digital content, and the encrypted digital content can be decrypted by using the digital content decryption key to obtain the digital content;
    所述终端设备接收所述数字内容提供装置下发的所述加密数字内容;Receiving, by the terminal device, the encrypted digital content delivered by the digital content providing device;
    所述终端设备使用所述终端设备的私钥对所述许可证中包括的所述数字内容的解密密钥进行解密,得到所述数字内容的解密密钥,再采用所述数字内容的解密密钥对所述加密数字内容进行解密,得到所述数字内容。Decrypting the decryption key of the digital content included in the license by using a private key of the terminal device to obtain a decryption key of the digital content, and then using the decryption key of the digital content The key decrypts the encrypted digital content to obtain the digital content.
  12. 一种共享数字内容的许可证的方法,其特征在于,包括:A method of sharing a license for digital content, comprising:
    数字内容提供装置接收终端设备发送的数字内容的许可证请求,所述数字内容的许可证请求包括所述数字内容的ID、所述终端设备的地址和所述终端设备所属的域的域标识;The digital content providing apparatus receives a license request of the digital content sent by the terminal device, where the license request of the digital content includes an ID of the digital content, an address of the terminal device, and a domain identifier of a domain to which the terminal device belongs;
    所述数字内容提供装置校验所述终端设备所属的域存在、所述终端设备为该域中的设备以及所述终端设备的地址符合生成规范;The digital content providing apparatus verifies that the domain to which the terminal device belongs, the terminal device is a device in the domain, and an address of the terminal device conforms to a generation specification;
    所述数字内容提供装置向区块链装置发送许可证分发事务;The digital content providing device transmits a license distribution transaction to the blockchain device;
    所述数字内容提供装置根据所述数字内容的ID生成并向所述终端设备分发所述数字内容的许可证;所述许可证包括被所述终端设备公钥加密后的数字内容解密密钥。The digital content providing device generates and distributes a license of the digital content to the terminal device according to an ID of the digital content; the license includes a digital content decryption key encrypted by the terminal device public key.
  13. 根据权利要求12所述的方法,其特征在于,所述数字内容提供装置根据所述数字 内容的ID生成并向所述终端设备分发所述数字内容的许可证,包括:The method according to claim 12, wherein said digital content providing means is based on said number The ID of the content generates and distributes the license of the digital content to the terminal device, including:
    所述数字内容提供装置根据所述数字内容的ID获取所述数字内容的解密密钥;The digital content providing device acquires a decryption key of the digital content according to an ID of the digital content;
    所述数字内容提供装置采用所述终端设备的公钥对所述数字内容的解密密钥进行加密;The digital content providing device encrypts a decryption key of the digital content by using a public key of the terminal device;
    所述数字内容提供装置根据加密后的数字内容的解密密钥、所述终端设备的地址、所述数字内容的ID和许可信息生成所述许可证。The digital content providing device generates the license based on a decryption key of the encrypted digital content, an address of the terminal device, an ID of the digital content, and license information.
  14. 根据权利要求12或13所述的方法,其特征在于,在所述数字内容提供装置生成并向所述终端设备分发数字内容的许可证之后,所述方法还包括:The method according to claim 12 or 13, wherein after the digital content providing device generates and distributes a license for the digital content to the terminal device, the method further comprises:
    所述数字内容提供装置接收所述终端设备发送的下发加密数字内容的请求,所述加密数字内容能够采用所述数字内容解密密钥进行解密从而获取到所述数字内容;The digital content providing device receives a request for sending the encrypted digital content sent by the terminal device, and the encrypted digital content can be decrypted by using the digital content decryption key to obtain the digital content;
    所述数字内容提供装置根据所述下发加密数字内容的请求向所述终端设备下发所述加密数字内容。The digital content providing device delivers the encrypted digital content to the terminal device according to the request for sending the encrypted digital content.
  15. 一种域网关版权管理装置,其特征在于,包括:A domain gateway copyright management device, comprising:
    接收单元,用于接收终端设备发送的数字内容的许可证请求,所述许可证请求中包括所述数字内容的标识ID;a receiving unit, configured to receive a license request for the digital content sent by the terminal device, where the license request includes an identifier ID of the digital content;
    获取单元,用于根据所述数字内容的ID获取域许可,所述域许可包括采用所述域网关版权管理装置的公钥加密后的数字内容的解密密钥;An obtaining unit, configured to acquire a domain license according to an ID of the digital content, where the domain license includes a decryption key of the digital content encrypted by using a public key of the domain gateway copyright management device;
    生成单元,用于根据所述域许可生成所述终端设备的许可证;a generating unit, configured to generate a license of the terminal device according to the domain license;
    发送单元,用于将所述终端设备的许可证发送给所述终端设备;a sending unit, configured to send a license of the terminal device to the terminal device;
    所述发送单元,还用于向区块链装置发送许可证分发事务请求,所述许可证分发事务请求包括域许可证事务ID,所述域网关版权管理装置的私钥的签名,所述终端设备的地址以及许可信息。The sending unit is further configured to send a license distribution transaction request to the blockchain device, where the license distribution transaction request includes a domain license transaction ID, a signature of a private key of the domain gateway copyright management device, and the terminal The address of the device and the license information.
  16. 根据权利要求15所述的装置,其特征在于,所述许可证请求中还包括所述终端设备的地址,所述装置还包括:The device according to claim 15, wherein the license request further includes an address of the terminal device, and the device further includes:
    确定单元,用于根据所述终端设备的地址确定所述终端设备为所述域网关版权管理装置创建的域中的设备。a determining unit, configured to determine, according to an address of the terminal device, a device in a domain that the terminal device creates for the domain gateway copyright management device.
  17. 根据权利要求16所述的装置,其特征在于,The device of claim 16 wherein:
    所述确定单元,还用于确定所述域是否购买过所述数字内容;The determining unit is further configured to determine whether the domain has purchased the digital content;
    若是,所述获取单元,具体用于根据所述数字内容的ID获取本地的域许可;If yes, the obtaining unit is specifically configured to obtain a local domain license according to the ID of the digital content;
    若否,所述发送单元,还用于向数字内容提供装置发送域许可证颁发请求,所述域许可证颁发请求包括所述数字内容的ID、所述域网关版权管理装置的地址、域标识以及许可信息。If not, the sending unit is further configured to send a domain license issuance request to the digital content providing apparatus, where the domain license issuance request includes an ID of the digital content, an address of the domain gateway copyright management device, and a domain identifier. And licensing information.
  18. 根据权利要求17所述的装置,其特征在于,所述装置还包括:The device according to claim 17, wherein the device further comprises:
    判断单元,用于判断已使用的所述数字内容的许可证数目未超过域许可中的许可信息中限制的许可证个数。The judging unit is configured to judge that the number of licenses of the digital content that has been used does not exceed the number of licenses restricted in the license information in the domain license.
  19. 根据权利要求15-18任一项所述的装置,其特征在于,所述生成单元具体用于:The device according to any one of claims 15 to 18, wherein the generating unit is specifically configured to:
    采用所述域网关版权管理装置的私钥对所述域许可中包含的加密后的数字内容的解密密钥进行解密,得到所述数字内容的解密密钥;Decrypting the decryption key of the encrypted digital content included in the domain license by using a private key of the domain gateway copyright management device to obtain a decryption key of the digital content;
    采用所述终端设备的公钥对所述数字内容的解密密钥进行加密;Encrypting the decryption key of the digital content by using a public key of the terminal device;
    根据采用所述终端设备的公钥加密后的数字内容的解密密钥、所述终端设备的地址、所述数字内容的ID和许可信息生成所述终端设备的许可证。The license of the terminal device is generated according to a decryption key of the digital content encrypted by the public key of the terminal device, an address of the terminal device, an ID of the digital content, and license information.
  20. 根据权利要求15-19任一项所述的装置,其特征在于, Apparatus according to any of claims 15-19, wherein
    所述接收单元,还用于接收所述终端设备发送的下发加密数字内容的请求,所述加密数字内容能够采用所述数字内容解密密钥进行解密从而获取到所述数字内容;The receiving unit is further configured to receive a request for sending the encrypted digital content sent by the terminal device, where the encrypted digital content can be decrypted by using the digital content decryption key to obtain the digital content;
    若所述域购买过所述数字内容,所述发送单元还用于根据所述下发加密数字内容的请求向所述终端设备发送本地保存的加密数字内容;If the domain purchases the digital content, the sending unit is further configured to send the locally stored encrypted digital content to the terminal device according to the request for sending the encrypted digital content;
    若所述域未购买过所述数字内容,所述装置还包括请求单元,用于根据所述下发加密数字内容的请求向所述数字内容提供装置请求下发加密数字内容;所述装置还包括存储单元,用于将所述数字内容提供装置下发的加密数字内容在本地进行保存,所述发送单元,还用于将加密数字内容向所述终端设备发送。If the domain has not purchased the digital content, the device further includes a requesting unit, configured to request the digital content providing device to deliver the encrypted digital content according to the request for sending the encrypted digital content; the device further The storage unit is configured to save the encrypted digital content delivered by the digital content providing device locally, and the sending unit is further configured to send the encrypted digital content to the terminal device.
  21. 根据权利要求15-20任一项所述的装置,其特征在于,所述发送单元还用于:The device according to any one of claims 15 to 20, wherein the sending unit is further configured to:
    将接收到的所述终端设备发送的加入域请求向所述区块链装置发送,所述加入域请求包括所述终端设备的地址、所述域网关版权管理装置的私钥的签名、域标识、所述域网关版权管理装置的地址以及创建域事务ID。And sending the received domain request sent by the terminal device to the blockchain device, where the join domain request includes an address of the terminal device, a signature of a private key of the domain gateway copyright management device, and a domain identifier. The address of the domain gateway copyright management device and the creation of a domain transaction ID.
  22. 根据权利要求21所述的装置,其特征在于,所述发送单元还用于:The device according to claim 21, wherein the sending unit is further configured to:
    向所述区块链装置发送创建域请求,所述创建域请求包括所述域网关版权管理装置的地址和所述域网关版权管理装置的私钥的签名。A create domain request is sent to the blockchain device, the create domain request including an address of the domain gateway rights management device and a signature of a private key of the domain gateway rights management device.
  23. 根据权利要求15-22任一项所述的装置,其特征在于,Apparatus according to any of claims 15-22, wherein
    所述接收单元,还用于接收退出域请求;The receiving unit is further configured to receive an exit domain request;
    所述发送单元,还用于向所述区块链装置发送所述退出域请求,所述退出域请求包括所述终端设备加入域事务ID以及所述域网关版权管理装置的私钥的签名。The sending unit is further configured to send the exit domain request to the blockchain device, where the exit domain request includes a signature of the terminal device joining a domain transaction ID and a private key of the domain gateway copyright management device.
  24. 一种终端设备,其特征在于,包括:A terminal device, comprising:
    发送单元,用于向数字内容提供装置发送数字内容的许可证请求,所述数字内容的许可证请求中包括所述数字内容的ID、所述终端设备的地址和所述终端设备所属的域的域标识;a sending unit, configured to send a license request for the digital content to the digital content providing device, where the license request of the digital content includes an ID of the digital content, an address of the terminal device, and a domain to which the terminal device belongs Domain identifier
    接收单元,用于接收所述数字内容提供装置分发的许可证,所述许可证包括被所述终端设备公钥加密后的数字内容解密密钥。And a receiving unit, configured to receive a license distributed by the digital content providing apparatus, where the license includes a digital content decryption key encrypted by the terminal device public key.
  25. 根据权利要求24所述的终端设备,其特征在于,所述装置还包括:The terminal device according to claim 24, wherein the device further comprises:
    请求单元,用于根据数字内容的ID向所述数字内容提供装置请求下发加密数字内容,所述加密数字内容能够采用所述数字内容解密密钥进行解密从而获取到所述数字内容;a requesting unit, configured to request, according to the ID of the digital content, the encrypted digital content to be sent to the digital content providing device, where the encrypted digital content can be decrypted by using the digital content decryption key to obtain the digital content;
    所述接收单元,还用于接收所述数字内容提供装置下发的所述加密数字内容;The receiving unit is further configured to receive the encrypted digital content delivered by the digital content providing device;
    获取单元,用于使用所述终端设备的私钥对所述许可证中包括的所述数字内容的解密密钥进行解密,得到所述数字内容的解密密钥,再采用所述数字内容的解密密钥对所述加密数字内容进行解密,得到所述数字内容。An obtaining unit, configured to decrypt, by using a private key of the terminal device, a decryption key of the digital content included in the license, to obtain a decryption key of the digital content, and then use the decryption of the digital content The key decrypts the encrypted digital content to obtain the digital content.
  26. 一种数字内容提供装置,其特征在于,包括:A digital content providing apparatus, comprising:
    接收单元,用于接收终端设备发送的数字内容的许可证请求,所述数字内容的许可证请求包括所述数字内容的ID、所述终端设备的地址和所述终端设备所属的域的域标识;a receiving unit, configured to receive a license request of the digital content sent by the terminal device, where the license request of the digital content includes an ID of the digital content, an address of the terminal device, and a domain identifier of a domain to which the terminal device belongs ;
    校验单元,用于校验所述终端设备所属的域存在、所述终端设备为该域中的设备以及所述终端设备的地址符合生成规范;a verification unit, configured to verify that a domain to which the terminal device belongs, the terminal device being a device in the domain, and an address of the terminal device comply with a generation specification;
    发送单元,用于所述数字内容提供装置向区块链装置发送许可证分发事务;a sending unit, configured to send, by the digital content providing device, a license distribution transaction to the blockchain device;
    执行单元,用于根据所述数字内容的ID生成并向所述终端设备分发所述数字内容的许可证;所述许可证包括被所述终端设备公钥加密后的数字内容解密密钥。And an execution unit, configured to generate and distribute the license of the digital content according to the ID of the digital content to the terminal device; the license includes a digital content decryption key encrypted by the terminal device public key.
  27. 根据权利要求26所述的装置,其特征在于,所述执行单元,具体用于: The device according to claim 26, wherein the execution unit is specifically configured to:
    根据所述数字内容的ID获取所述数字内容的解密密钥;Obtaining a decryption key of the digital content according to the ID of the digital content;
    采用所述终端设备的公钥对所述数字内容的解密密钥进行加密;Encrypting the decryption key of the digital content by using a public key of the terminal device;
    根据加密后的数字内容的解密密钥、所述终端设备的地址、所述数字内容的ID和许可信息生成所述许可证。The license is generated based on the decrypted key of the encrypted digital content, the address of the terminal device, the ID of the digital content, and the license information.
  28. 根据权利要求26或27所述的装置,其特征在于,Device according to claim 26 or 27, characterized in that
    所述接收单元,还用于接收所述终端设备发送的下发加密数字内容的请求,所述加密数字内容能够采用所述数字内容解密密钥进行解密从而获取到所述数字内容;The receiving unit is further configured to receive a request for sending the encrypted digital content sent by the terminal device, where the encrypted digital content can be decrypted by using the digital content decryption key to obtain the digital content;
    所述发送单元,还用于根据所述下发加密数字内容的请求向所述终端设备下发所述加密数字内容。The sending unit is further configured to send the encrypted digital content to the terminal device according to the request for sending the encrypted digital content.
  29. 一种共享数字内容的许可证的系统,其特征在于,包括:域网关版权管理装置和区块链装置,其中,所述域网关版权管理装置用于执行权利要求1-9任一项所述的方法,所述区块链装置用于:校验许可证分发事务请求中的域许可证事务ID是否存在,所述域网关版权管理装置的私钥的签名是否正确,在校验成功后,构造许可证分发事务并将所述许可证分发事务存储在区块链中,所述许可证分发事务的输入内容包括所述域许可证事务ID和所述域网关版权管理装置的私钥的签名,输出内容包括所述终端设备的地址和许可信息。 A system for sharing a license for digital content, comprising: a domain gateway copyright management device and a blockchain device, wherein the domain gateway copyright management device is configured to perform any one of claims 1-9 The method of the blockchain device is configured to: verify whether a domain license transaction ID in the license distribution transaction request exists, and whether the signature of the private key of the domain gateway copyright management device is correct, after the verification succeeds, Constructing a license distribution transaction and storing the license distribution transaction in a blockchain, the input content of the license distribution transaction including the domain license transaction ID and a signature of a private key of the domain gateway copyright management device The output content includes an address and license information of the terminal device.
PCT/CN2017/091220 2016-08-02 2017-06-30 Method, device and system for licensing shared digital content WO2018024061A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610624448.X 2016-08-02
CN201610624448.XA CN107679369A (en) 2016-08-02 2016-08-02 A kind of method, apparatus and system of the licensing of shared digital content

Publications (1)

Publication Number Publication Date
WO2018024061A1 true WO2018024061A1 (en) 2018-02-08

Family

ID=61072497

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/091220 WO2018024061A1 (en) 2016-08-02 2017-06-30 Method, device and system for licensing shared digital content

Country Status (2)

Country Link
CN (1) CN107679369A (en)
WO (1) WO2018024061A1 (en)

Cited By (11)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108600262A (en) * 2018-05-09 2018-09-28 合肥达朴汇联科技有限公司 A kind of includes the device of the block chain node as recipient
CN108632018A (en) * 2018-05-09 2018-10-09 合肥达朴汇联科技有限公司 A kind of includes the device of the block chain node as sender
CN108632019A (en) * 2018-05-09 2018-10-09 合肥达朴汇联科技有限公司 A method of the block chain node as recipient
CN108712282A (en) * 2018-05-09 2018-10-26 合肥达朴汇联科技有限公司 A method of the block chain node as sender
CN108737108A (en) * 2018-05-09 2018-11-02 合肥达朴汇联科技有限公司 A kind of computer-readable medium including block chain node
CN108737107A (en) * 2018-05-09 2018-11-02 合肥达朴汇联科技有限公司 A kind of computer equipment including block chain node
CN109412793A (en) * 2018-02-13 2019-03-01 李茗 A kind of rights issuer method, device and equipment based on block chain
WO2019157810A1 (en) * 2018-02-13 2019-08-22 华为技术有限公司 Data transmission method and device and network node
CN110390183A (en) * 2019-07-28 2019-10-29 西南石油大学 Digital publishing rights transaction deposit system based on block chain
WO2020082614A1 (en) * 2018-10-25 2020-04-30 深圳壹账通智能科技有限公司 Blockchain information sharing method and apparatus, and computer device
US11301452B2 (en) 2018-10-09 2022-04-12 Ebay, Inc. Storing and verification of derivative work data on blockchain with original work data

Families Citing this family (10)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108563788B (en) * 2018-04-27 2023-05-23 腾讯科技(深圳)有限公司 Block chain-based data query method, device, server and storage medium
CN108769750B (en) * 2018-05-02 2020-11-17 中广热点云科技有限公司 Digital content bank system based on block chain technology
CN108769751B (en) * 2018-05-02 2020-09-08 中广热点云科技有限公司 Network audio-visual management support system based on intelligent contract
CN108875316A (en) * 2018-05-31 2018-11-23 中链科技有限公司 Licensing generation and verification method and server based on block chain
TWI685767B (en) * 2018-06-07 2020-02-21 艾維克科技股份有限公司 Decentralized software information creation system and method
CN108989019A (en) * 2018-06-27 2018-12-11 天闻数媒科技(湖南)有限公司 Content resource safety system based on block chain technology
CN109118220A (en) * 2018-08-03 2019-01-01 上海点融信息科技有限责任公司 For handling the method, apparatus and storage medium of affairs in distributed network
TWI691857B (en) 2018-11-30 2020-04-21 財團法人工業技術研究院 Digital rights management system and digital rights protection method
CN111818000B (en) * 2019-04-11 2021-08-03 北京子辰飞马科技有限公司 Block chain-based distributed Digital Rights Management (DRM) system
CN112114739A (en) * 2019-06-21 2020-12-22 伊姆西Ip控股有限责任公司 Method, apparatus and computer program product for managing data objects

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100111298A1 (en) * 2008-10-27 2010-05-06 Advanced Micro Devices, Inc. Block cipher decryption apparatus and method
CN103927397A (en) * 2014-05-05 2014-07-16 湖北文理学院 Recognition method for Web page link blocks based on block tree
CN105790954A (en) * 2016-03-02 2016-07-20 布比(北京)网络技术有限公司 Method and system for constructing electronic evidence

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101315654B (en) * 2007-06-01 2013-02-27 华为技术有限公司 Method and system for validating permission
CN101639916A (en) * 2008-07-28 2010-02-03 北京邮电大学 Digital media resource registering transaction management system and realizing method thereof
CN102142067A (en) * 2011-03-09 2011-08-03 中山大学 Digital family network-based digital rights management system
US9063721B2 (en) * 2012-09-14 2015-06-23 The Research Foundation For The State University Of New York Continuous run-time validation of program execution: a practical approach

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20100111298A1 (en) * 2008-10-27 2010-05-06 Advanced Micro Devices, Inc. Block cipher decryption apparatus and method
CN103927397A (en) * 2014-05-05 2014-07-16 湖北文理学院 Recognition method for Web page link blocks based on block tree
CN105790954A (en) * 2016-03-02 2016-07-20 布比(北京)网络技术有限公司 Method and system for constructing electronic evidence

Non-Patent Citations (2)

* Cited by examiner, † Cited by third party
Title
WU, JIAN ET AL.,: "Digital Copyright Protection Based on Blockchain Technology", RADIO & TELEVISION INFORMATION, no. 291, 31 July 2016 (2016-07-31) *
ZHANG, JUNHUA: "Study on Digital Copyright Management (DRM) Protocols and Application thereof", ELECTRONIC TECHNOLOGY & INFORMATION SCIENCE, CHINA MASTER`S THESES FULL-TEXT DATABASE, no. 3, 15 March 2014 (2014-03-15) *

Cited By (12)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109412793A (en) * 2018-02-13 2019-03-01 李茗 A kind of rights issuer method, device and equipment based on block chain
WO2019157810A1 (en) * 2018-02-13 2019-08-22 华为技术有限公司 Data transmission method and device and network node
CN108600262A (en) * 2018-05-09 2018-09-28 合肥达朴汇联科技有限公司 A kind of includes the device of the block chain node as recipient
CN108632018A (en) * 2018-05-09 2018-10-09 合肥达朴汇联科技有限公司 A kind of includes the device of the block chain node as sender
CN108632019A (en) * 2018-05-09 2018-10-09 合肥达朴汇联科技有限公司 A method of the block chain node as recipient
CN108712282A (en) * 2018-05-09 2018-10-26 合肥达朴汇联科技有限公司 A method of the block chain node as sender
CN108737108A (en) * 2018-05-09 2018-11-02 合肥达朴汇联科技有限公司 A kind of computer-readable medium including block chain node
CN108737107A (en) * 2018-05-09 2018-11-02 合肥达朴汇联科技有限公司 A kind of computer equipment including block chain node
US11301452B2 (en) 2018-10-09 2022-04-12 Ebay, Inc. Storing and verification of derivative work data on blockchain with original work data
US11880352B2 (en) 2018-10-09 2024-01-23 Ebay, Inc. Storing and verification of derivative work data on blockchain with original work data
WO2020082614A1 (en) * 2018-10-25 2020-04-30 深圳壹账通智能科技有限公司 Blockchain information sharing method and apparatus, and computer device
CN110390183A (en) * 2019-07-28 2019-10-29 西南石油大学 Digital publishing rights transaction deposit system based on block chain

Also Published As

Publication number Publication date
CN107679369A (en) 2018-02-09

Similar Documents

Publication Publication Date Title
WO2018024061A1 (en) Method, device and system for licensing shared digital content
TWI748387B (en) System and method for verifying verifiable claims
US11651109B2 (en) Permission management method, permission verification method, and related apparatus
US11025435B2 (en) System and method for blockchain-based cross-entity authentication
US11038670B2 (en) System and method for blockchain-based cross-entity authentication
WO2022042301A1 (en) Data processing method and apparatus, smart device and storage medium
JP6873270B2 (en) Handling of transaction activities based on smart contracts in the blockchain Caution Methods and devices for protecting data
EP3404891B1 (en) Method and system for distributing digital content in peer-to-peer network
CN109067801B (en) Identity authentication method, identity authentication device and computer readable medium
CN109845220B (en) Method and apparatus for providing blockchain participant identity binding
CN107231351B (en) Electronic certificate management method and related equipment
US8196186B2 (en) Security architecture for peer-to-peer storage system
TW202103029A (en) System and method for mapping decentralized identifiers to real-world entities
US20090193526A1 (en) Posted move in anchor point-based digital rights management
JP2007511810A (en) Proof of execution using random number functions
JP2003296281A (en) Method and system for access control
JP4525609B2 (en) Authority management server, authority management method, authority management program
US20140157368A1 (en) Software authentication
CN109492424B (en) Data asset management method, data asset management device, and computer-readable medium
JP6742558B2 (en) Certification system and certification program
JP7280517B2 (en) Right holder terminal, user terminal, right holder program, user program, content usage system and content usage method
CN111241492A (en) Product multi-tenant secure credit granting method, system and electronic equipment
JP6742557B2 (en) Authentication system
KR100989371B1 (en) DRM security mechanism for the personal home domain
TW202347354A (en) Application sharing method, file sharing method and device based on blockchain

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17836243

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17836243

Country of ref document: EP

Kind code of ref document: A1