EP1961188A2 - Systeme de distribution controlee de contenus - Google Patents
Systeme de distribution controlee de contenusInfo
- Publication number
- EP1961188A2 EP1961188A2 EP06842133A EP06842133A EP1961188A2 EP 1961188 A2 EP1961188 A2 EP 1961188A2 EP 06842133 A EP06842133 A EP 06842133A EP 06842133 A EP06842133 A EP 06842133A EP 1961188 A2 EP1961188 A2 EP 1961188A2
- Authority
- EP
- European Patent Office
- Prior art keywords
- content
- provider
- user
- access
- rights
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/10—Protecting distributed programs or content, e.g. vending or licensing of copyrighted material ; Digital rights management [DRM]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/08—Access security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2463/00—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00
- H04L2463/101—Additional details relating to network architectures or network communication protocols for network security covered by H04L63/00 applying security measures for digital rights management
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W28/00—Network traffic management; Network resource management
- H04W28/02—Traffic management, e.g. flow control or congestion control
- H04W28/10—Flow control between communication endpoints
- H04W28/14—Flow control between communication endpoints using intermediate storage
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W4/00—Services specially adapted for wireless communication networks; Facilities therefor
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W8/00—Network data management
- H04W8/18—Processing of user or subscriber data, e.g. subscribed services, user preferences or user profiles; Transfer of user or subscriber data
- H04W8/20—Transfer of user or subscriber data
Definitions
- the present invention relates to a controlled distribution system of content acquired by a user from a content provider and accessible through at least one access provider.
- the invention finds a particularly advantageous application in the field of controlling access to multimedia content and its dissemination to users that can be simultaneously connected to several types of networks, especially when they are in a mobility situation. and nomadism.
- the invention therefore aims to guarantee the suppliers of multimedia content that their content will not be misused on a telecommunications network. It also allows end users to control access to their surroundings, for example, to unwanted content.
- the system according to the invention is designed so that the user enjoys the flexibility of telecommunications networks. It can thus use different network access, such as the mobile network, including GPRS, a local area network WLAN, or a fixed broadband network of the xDSL type, to access its contents and / or to broadcast them in accordance with the rights it will have subscribed with the supplier of multimedia content.
- the system according to the invention allows the user to dispose of its contents and to disseminate them, even if it is in a situation of mobility or nomadism and therefore does not access the telecommunications network by its nominal line.
- OMA Open Mobile Alliance
- DRM Digital Right Management
- a personalization of the contents by marking with a watermark specific to a given acquisition, gathering data relating to the acquired content, to the acquisition itself, and to the user, in particular his rights on the acquired content,
- the OMA imposes strong constraints on the equipment and in particular on the mobile terminal which processes the DRM message. Therefore, the reuse of data is difficult to envisage by the intrinsic architecture, so that the portability of this solution to other terminals remains problematic in particular in a fixed network environment.
- the system does not have the capacity to integrate heterogeneous marking technologies: only the marking technology proposed by the DRM service provider is admissible.
- the system is centralized around the content control provider's database. Its sizing is critical as regards the relationship between, on the one hand, the abundance of flows between the analysis devices, or probes, and the DRM service provider and, on the other hand, the strong constraint of keeping a time limit of short answer to a request from a probe.
- the system can detect watermarks only at the user, on a specific equipment, forcing the end user to be equipped with a dedicated hardware for reading.
- the system does not detect or interrupt the illegal exchange of content during its transfer.
- the system does not discriminate the rights of the user depending on the network access used. - The system does not detect or notify a content provider the detection of an illegal exchange of content, as long as the content is not read in the installation of the end user.
- each participant (distributor, operator, seller, end user) manages a database that contains the rights of use of the user for the contents of this participant.
- the problem to be solved by the object of the present invention is to propose a controlled distribution system of a content acquired by a user from a content provider and accessible through at least one access provider, said system comprising a content control provider adapted to receive from said content provider and store in a centralized database at least data relating to the rights of the user on the acquired content, which would include the integration of constraints of a multi-network environment in which the user would like to have the acquired content regardless of the access network used, and to optimize the exchanges between the flow analysis probes and the content control provider so as to reduce the response time to a request from a probe about the rights of the user.
- the solution to the technical problem posed consists, according to the present invention, in that said access provider comprises a local database able to receive from said content control provider said data relating to the rights of the user, and a data protection device. decision-making able to analyze flows issued by said user and to decide whether said transmitted streams are in accordance with the rights of the user registered in said local database.
- the controlled distribution system conforms to the The invention provides a decentralized architecture obtained by associating a local database with each access provider. It is understood that, in this way, the response time to a query of a decision-making device with respect to the rights of the user is fast since the response to the request emanates in this case from the local database of the provider. access and not the central database of the content control provider.
- the invention provides that said access provider is able to provide an aggregated presence function of the content control provider with information. the presence of the user on an access point, and in that the content control provider is able to supply the local database of the access provider with the data relating to the rights of said user present on said access point. 'access.
- This particularly advantageous arrangement makes it possible to provide the local database only the data relating to the only users connected to the access provider with which said local database is associated.
- said centralized database is able to receive access control data to said content. These data are defined by the user with a service provider according to a profile allowing him for example to exercise a parental control on the acquired contents.
- said access control data is provided to the local database of the access provider concerned so that the decision-making device, or probe, can check whether the access to the content by said third party user is allowed or not.
- said centralized database is adapted to receive broadcast control data of said content.
- said broadcast control data are marking characteristics of said acquired content.
- the invention also relates to a content control provider in a controlled distribution system of content acquired by a user from a content provider, which is remarkable in that said content control provider is able to provide a database data provider's local data provider user rights data on the acquired content.
- said content control provider is able to receive from said access provider a user's presence information on an access point and to supply the local database of said access provider the data. relating to the rights of the said user present on the said access point.
- said content control provider is able to receive and store in a centralized database access control data to said content.
- said content control provider is able to receive and store in a centralized database broadcast control data of said content.
- the invention also relates to an access provider in a controlled distribution system for a content acquired by a user from a content provider, which is remarkable in that said access provider includes a local database capable of storing data relating to the rights of the user on the acquired content, and a decision-making device able to analyze flows sent by said user and to decide whether said transmitted streams comply with said rights of use of the user.
- said access provider is able to provide an aggregated presence function of a content control provider with information on the presence of the user on an access point.
- Figure 1 is a general diagram of a controlled distribution system according to the invention.
- Figure 2 is a diagram illustrating the provisioning of the local database of an ISP.
- Figure 3 is a diagram illustrating the provisioning of the content control provider for content access control.
- Figure 4 is an implementation schema for content access control.
- Fig. 5 is a content tagging scheme for content broadcast control.
- Fig. 6 is an implementation scheme for content broadcast control.
- FIG. 7 is a diagram of an application of the system according to the invention to a user in situation of mobility or nomadism.
- FIG. 1 shows a system for the controlled distribution of a content, for example a multimedia file that a user has acquired from a content provider. This content is accessible by the user through at least one access provider, the invention being of particular interest when the user can access the content acquired through several access providers, as will be seen later about mobility and nomadism.
- the access technologies that can be considered here are the mobile network, including GPRS, local area networks WLAN, and fixed broadband network such as ADSL.
- the controlled distribution system, object of the invention comprises a content control provider which itself comprises a control system responsible for exchanging useful data with the content provider and the provider. access.
- These data are stored in a centralized database and concern, on the one hand, information provided by the content provider such as data relating to the acquired content, data relating to the acquirer, in particular an identification of the network of data.
- the access provider comprises a local database in which information provided by the content control provider, including the rights data of the user, as well as the data provider can be stored.
- the user's network identity and the user's network identifier which can be the IP address of the user on an IP network.
- the access provider comprises a decision-making device able to analyze by means of a probe the flows sent by the user so as to decide whether the transmitted streams comply with the rights of the user such as they have been registered in the local database.
- An advantage of the local database is that it may contain only the information about the users who are actually connected to the considered network.
- the sequence of steps is as follows: 1 -
- the network under consideration proposes a procedure called "network attachment function" that allows the user to connect.
- the network attachment function informs the local database that a new user has logged on.
- This database is responsible for matching the network information provided by the network attachment function with the information that will be provided in step 5 by the control system of the content control provider.
- the network data to be entered in the local database at this point are:
- the network identifier which is the interrogation key of the decision-making system during the processing of the flows sent by the user
- the function of attachment to the network informs a function, called presence, the presence of the identified user from its network identity.
- the exchanged data is the network identity of the user.
- the presence function notifies a function, called aggregate presence, of the content control provider, the attachment of the user using the user's network identity and the identification of the network, or point d network access, which is extracted from the network identifier.
- the data exchanged are: - the network identity of the user,
- the network access point as network identification.
- the aggregated presence function aggregates, for a given user, all of its network identities and its network locations, and notifies the control system of the content control provider of the presence of the user on the network of the user. access considered.
- the data exchanged are:
- control system retrieves from the centralized database all the useful data relating to the characteristics of the content acquired by the user, whose associated rights for the access point in question and the access rights of the user in the case of controlling access to content. 5- The control system sends all of these useful data to the local database.
- the sequence of steps is as follows: 1 -
- the emitted streams to be processed are directed by a probe to a PDP decision point ("Policy Decision Point"),
- the PDP checks with the local database if the network identifier corresponds to a controlled distribution service relating to a user, with the possibility of keeping in memory this result to overcome future verifications that relate to the same identifier network.
- the PDP queries the local database from the network identifier and the characteristics of the stream to be processed.
- the local database then provides service rights.
- the PDP can recover all the rights, regardless of the characteristics of the stream to be processed.
- the information is then stored in memory and then avoid the repetition of step 2 at each flow processing for this network identifier.
- this last variant requires the implementation of an update mechanism by the local database as soon as the information (characteristics of the flow to be processed and corresponding rights) associated with this identifier are modified.
- the PDP informs a PEP ("Policy Enforcement Point") execution point of the policy to apply for the user-issued stream.
- PEP Policy Enforcement Point
- the PDP informs the control system about the event and its processing relative to the user based on the user's network identity.
- the user's network identity belongs to the data of the local database (step 1a of the database supply). local data) and was retrieved by consulting the local database in Step 2.
- the content control provider is then responsible for notifying the processing of the users for which the content providers have subscribed to the distribution control services. It retrieves the additional information necessary for the notification by consultation of the centralized database, the interrogation key of this centralized database being the network identity of the user.
- the content controlled distribution system that has just been generically described with reference to FIGS. 1 and 2 can be applied to various instantiations, such as the access control to the contents and the distribution of the contents, which will be presented successively. below.
- An example of access control is parental control when accessing web pages.
- the goal is to control the websites visited by a third-party user identified during his attachment to the network.
- the control can be done during the request of the page, in the upstream direction of the request, or during the descent of the data to the terminal of the user.
- the user provides the characteristics of the control that he wishes to carry out to the access control service provider.
- the control characteristics will relate to the identity of the third party user (s) to which the control applies.
- the control characteristics as well as the network identity of the user or third-party users are provided by the service provider to the content control provider.
- the access control service provider when subscribing to the service, the access control service provider must provide the identity of the user to the content control provider. This then matches the identity of the user with his network identity.
- Step (0) corresponds to the supply phase that has just been described in relation to FIG. 3, in which the user indicates the characteristics of the control that he wishes to see performed.
- the user may be a parent and the third-party user is a child who connects to web pages.
- the decision-making device is positioned between the user and the content provider at the ISP. This device analyzes the flows coming from the user as well as the downstream flows coming from the Web servers. The decision-making can thus be carried out either on the requests of the user (1) or on the responses of the web servers (2).
- the decision-making device may, according to the customer's request, block the flow and / or warn the user.
- the access provider sends (3) the information to the content control provider that relays (4) to the service provider, which sends it (5) to the user.
- FIGS. 5 and 6 An application of the controlled distribution system according to the invention to the diffusion of contents is illustrated in FIGS. 5 and 6.
- the purpose of this application is to provide a content provider that the file it provides to a user will be broadcast according to the rights to which the user has subscribed.
- the control of the diffusion of contents is carried out thanks to a mechanism known as marking of the contents.
- the marking relates in particular to data which makes it possible to discriminate the contents and on the associated rights, in particular the persons authorized to receive these contents.
- the content provider may mark (1b) the content itself or have it tagged (1a) by the content control provider or by a third party entity, this is done at the level of the content provider. "Marking of content” shown in Figure 5. In the event that the marking is not carried out by the content control provider, the third party performing the marking must have knowledge of the identity of the user in order to customize the marking. The marked content will then be sent to the content provider for distribution to the user.
- the user's ISP Before the file is sent by the content provider, the user's ISP must first provide (3) the user's network identity to the content control provider. It can thus match the service identity of the user and his network identity.
- the following information is provisioned (4) and associated with the service identity of the user:
- the actual broadcast control is then performed in accordance with FIG. 6.
- the decision-making device is positioned between the users A and B at the access provider.
- the decision-making device goes back (2) the information to the content control provider that relays it (3) to the content provider.
- the latter can inform (4) the purchaser of the content of the anomaly detected.
- the content provider notifies (5) the content control provider of the changes on the profiles of the users.
- FIG. 7 illustrates how the controlled distribution system which has just been described advantageously applies to the mobility or nomadic situation of the user.
- the consideration of mobility and nomadism is made possible by the implementation of network mechanisms exploiting the advantages of presence functions that make it possible to determine the location of the user.
- the initial descent of the information in local database, corresponding to the network A operated by the access provider A, is carried out as described with reference to FIG.
- the user information contained in the initial local database of access provider A is only cleared after a timeout has been exhausted
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Signal Processing (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- Computer Networks & Wireless Communication (AREA)
- General Engineering & Computer Science (AREA)
- Technology Law (AREA)
- General Physics & Mathematics (AREA)
- Computing Systems (AREA)
- Physics & Mathematics (AREA)
- Multimedia (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR0553859 | 2005-12-13 | ||
| PCT/FR2006/051322 WO2007068848A2 (fr) | 2005-12-13 | 2006-12-08 | Systeme de distribution controlee de contenus |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP1961188A2 true EP1961188A2 (fr) | 2008-08-27 |
Family
ID=36250744
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP06842133A Withdrawn EP1961188A2 (fr) | 2005-12-13 | 2006-12-08 | Systeme de distribution controlee de contenus |
Country Status (3)
| Country | Link |
|---|---|
| US (1) | US20090234857A1 (fr) |
| EP (1) | EP1961188A2 (fr) |
| WO (1) | WO2007068848A2 (fr) |
Families Citing this family (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20110004915A1 (en) * | 2009-07-02 | 2011-01-06 | Nokia Corporation | Method and apparatus for managing access to identity information |
| US9883446B2 (en) | 2010-12-27 | 2018-01-30 | Google Technology Holdings LLC | Method and apparatus for mobile media optimization |
| US8874687B2 (en) * | 2011-04-07 | 2014-10-28 | Infosys Technologies, Ltd. | System and method for dynamically modifying content based on user expectations |
| US9756395B1 (en) | 2012-03-19 | 2017-09-05 | Google Inc. | Content rating and control |
| US9749813B2 (en) * | 2012-12-17 | 2017-08-29 | Radius Networks, Inc. | System and method for associating a MAC address of a wireless station with personal identifying information of a user of the wireless station |
| GB2536067B (en) * | 2015-03-17 | 2017-02-22 | Openwave Mobility Inc | Identity management |
| US10469997B2 (en) | 2016-02-26 | 2019-11-05 | Microsoft Technology Licensing, Llc | Detecting a wireless signal based on context |
| US10475144B2 (en) | 2016-02-26 | 2019-11-12 | Microsoft Technology Licensing, Llc | Presenting context-based guidance using electronic signs |
| US10452835B2 (en) | 2016-06-30 | 2019-10-22 | Microsoft Technology Licensing, Llc | User-management of third-party user information |
Family Cites Families (6)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6850252B1 (en) * | 1999-10-05 | 2005-02-01 | Steven M. Hoffberg | Intelligent electronic appliance system and method |
| US6571282B1 (en) * | 1999-08-31 | 2003-05-27 | Accenture Llp | Block-based communication in a communication services patterns environment |
| US7630986B1 (en) * | 1999-10-27 | 2009-12-08 | Pinpoint, Incorporated | Secure data interchange |
| US7266704B2 (en) * | 2000-12-18 | 2007-09-04 | Digimarc Corporation | User-friendly rights management systems and methods |
| US7260555B2 (en) * | 2001-12-12 | 2007-08-21 | Guardian Data Storage, Llc | Method and architecture for providing pervasive security to digital assets |
| SE0202451D0 (sv) * | 2002-08-15 | 2002-08-15 | Ericsson Telefon Ab L M | Flexible Sim-Based DRM agent and architecture |
-
2006
- 2006-12-08 EP EP06842133A patent/EP1961188A2/fr not_active Withdrawn
- 2006-12-08 US US12/086,268 patent/US20090234857A1/en not_active Abandoned
- 2006-12-08 WO PCT/FR2006/051322 patent/WO2007068848A2/fr not_active Ceased
Non-Patent Citations (1)
| Title |
|---|
| See references of WO2007068848A3 * |
Also Published As
| Publication number | Publication date |
|---|---|
| WO2007068848A2 (fr) | 2007-06-21 |
| US20090234857A1 (en) | 2009-09-17 |
| WO2007068848A3 (fr) | 2007-12-21 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US10693839B2 (en) | Digital media content distribution blocking | |
| FR3072802A1 (fr) | Verification d'identite preservant la confidentialite | |
| KR20090111821A (ko) | 퍼시스턴트/익명의 식별자를 사용 네트워크 작업과 정보 처리 시스템 및 방법 | |
| WO2006134310A2 (fr) | Procede et systeme de reperage et de filtrage d'informations multimedia sur un reseau | |
| EP2294761A1 (fr) | Procède de traçabilité et de résurgence de flux pseudonymises sur des réseaux de communication, et procède d'émission de flux informatif apte a sécuriser le trafic de données et ses destinataires | |
| EP2797010A2 (fr) | Système et procédé de stockage et de récupération de support d'interaction distribué | |
| EP1961188A2 (fr) | Systeme de distribution controlee de contenus | |
| FR3103990A1 (fr) | Procédés et applications de contrôle d’accès distribué à un réseau de télécommunications | |
| EP1787475A1 (fr) | Protection et controle de diffusion de contenus sur reseaux de telecommunications | |
| FR2852753A1 (fr) | Systeme de transmission de donnees client/serveur securise | |
| EP1704700B1 (fr) | Procede et systeme pour l' exploitation d'un reseau informatique destine a la publication de contenu | |
| WO2023203291A1 (fr) | Procedes, terminal et serveur de gestion de donnees personnelles | |
| EP2630765B1 (fr) | Procede d'optimisation du transfert de flux de donnees securises via un reseau autonomique | |
| FR3019427A1 (fr) | Procede de mise en cache d'un contenu dans un reseau de distribution de contenus | |
| EP2464068B1 (fr) | Système de gestion globale de filtrage personnalisé basé sur un circuit d'échange d'informations sécurisé et procédé associé | |
| WO2014016478A1 (fr) | Dispositif informatique de stockage de données privées totalement distribué en environnement hostile | |
| EP1510904B1 (fr) | Procédé et système d'évaluation du niveau de sécurité de fonctionnement d'un équipement électronique et d'accès conditionnel à des ressources | |
| FR3131492A1 (fr) | Authentification d’un evenement par certification et verification de fichiers multimedia | |
| EP1648143B1 (fr) | Procédé de mise en relation sans fil, sélective et spontanée d'au moins deux entités et équipement mettant en oeuvre ce procédé | |
| FR2862170A1 (fr) | Procede de transfert de donnees confidentielles en coeur de reseaux | |
| EP3110109A1 (fr) | Procédé et dispositif de mise à jour des capacités d'un objet connecté à un réseau de communications | |
| FR3162335A1 (fr) | Méthode de distribution de contenu multimédia et système associé | |
| WO2004004294A1 (fr) | Procede d'individualisation d'un terminal relie a au moins un serveur a travers un reseau | |
| FR2835331A1 (fr) | Procede de controle de l'exploitation de contenus numeriques par un module de securite ou une carte a puce comprenant ledit module | |
| Trabelsi | Services spontanés sécurisés pour l'informatique diffuse |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20080520 |
|
| AK | Designated contracting states |
Kind code of ref document: A2 Designated state(s): AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HU IE IS IT LI LT LU LV MC NL PL PT RO SE SI SK TR |
|
| RIN1 | Information on inventor provided before grant (corrected) |
Inventor name: BARAULT, ERIC Inventor name: VANDENBUSSCHE, ARMAND Inventor name: BIHANNIC, NICOLAS |
|
| 17Q | First examination report despatched |
Effective date: 20101210 |
|
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20120703 |