EP2973321A1 - Verfahren und vorrichtung zur steuerung des zugriffs auf digitale inhalte - Google Patents
Verfahren und vorrichtung zur steuerung des zugriffs auf digitale inhalteInfo
- Publication number
- EP2973321A1 EP2973321A1 EP14708904.9A EP14708904A EP2973321A1 EP 2973321 A1 EP2973321 A1 EP 2973321A1 EP 14708904 A EP14708904 A EP 14708904A EP 2973321 A1 EP2973321 A1 EP 2973321A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- access
- application
- data
- network segment
- mobile terminal
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/083—Network architectures or network communication protocols for network security for authentication of entities using passwords
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06Q—INFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
- G06Q30/00—Commerce
- G06Q30/06—Buying, selling or leasing transactions
- G06Q30/0601—Electronic shopping [e-shopping]
- G06Q30/0621—Electronic shopping [e-shopping] by configuring or customising goods or services
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/101—Access control lists [ACL]
Definitions
- the invention relates to a method for controlling the access to digital data, comprising a mobile terminal with a
- Network interface and a spatially limited
- Previous DRM digital rights management
- Location-aware access control systems link DRM and access control to specific locations / locations - the owner of the rights is himself mobile.
- the invention describes a solution for location-based DRM that allows temporary, location-dependent access to protected electronic multimedia content using mobile devices (generally smartphones, tablets, laptops) independent of a particular content provider.
- the invention includes a system and method for controlling access to digital data.
- digital data may not only be classical music data, video data, games or information data in written form, but may also mean active content created on the site (eg blogs or discussion forums) that provides access for only Allow a limited amount of people.
- the invention also relates not only to the retrieval, but also to the creation of digital content - eg reports.
- the term data is thus not limited to downloadable content, but may also include dialog-oriented forums that are not characterized by pure data in static form.
- the invention comprises a mobile terminal with a network interface that can be assigned to a spatially limited network segment, which can be unambiguously assigned to a rights holder in the digital data provided in the network segment.
- these are WLAN networks, but other networks such as Bluetooth, GSM networks or LTTE or UMTS networks may be meant, which have a cell structure, and are thus localized.
- These network segments have a unique identification, which is usually provided by a gateway of this network segment. The unique identification of the network segment is used to control the access to the digital data.
- the method comprises the steps:
- Range of the network segment is left, but at least after expiry of the temporary reading rights
- the unique identification of the network segment is secured by a signature relative to the usage server, so that misuse of the identification is avoided.
- the identification of the network segment is provided with a signature that the
- the usage server issues a token that is passed to the application after the unique identification is obtained, the token determining which data the application has access to, the
- the token is usually a SAML assertion or equivalent
- the token determines which network segment gets access to which data.
- the token is thus specifically assembled for the network segment and maps the identification of the network segment and the rights of the rights holder in the location area of the network segment to the data that may be accessed from the network segment.
- the application runs as one
- APP Application on a mobile device.
- Such an application can be retrieved, for example, by known central stores such as Market Store, AppStore or Playstore. It is also conceivable that the application is already designed as an integral part of the firmware of a mobile terminal. In this case, the application accesses the network segment gateway and the application requests the token from the usage server.
- the application usually has a secure storage area (SandBox) in which the downloaded data is stored, if necessary. Of course, preference is given to data that is not local must be saved or which must be obtained only by streaming, wherein the reproduced is then discarded by the device. If, however, the data also needs to be stored locally, this is done in a secure area to which only the application has access. This memory area is no longer accessible or deleted by the application after leaving the network segment.
- the application thus also monitors the entry and exit into the network segment. Furthermore, the application also manages the request for the token and the transmission of the token to the
- the application thus provides an interface to the components of the invention. In this way, the application procures from the gateway the identification of the network segment in which this is contacted.
- the application may also run on a server and the mobile terminal is merely a display device.
- the application runs on a server, on which the mobile terminal accesses with a browser, wherein the representation takes place only on the mobile terminal, but access to the data is done by the server.
- the server accesses with a browser
- the representation takes place only on the mobile terminal, but access to the data is done by the server.
- only presentation data is transmitted and not content-related data.
- the content data remains on the application server, which has the same function as described above.
- A local network segment
- A controls the access via a mobile device to certain protected electronic contents (e-books, music, documents) locally and temporally limited and combines the following characteristics:
- a mobile device with standardized network technology e.g., WIFI
- WIFI wireless fidelity
- a location-based electronic content DRM is attached to the network
- the location based DRM is independent of the various suppliers of electronic content
- An application is installed on the mobile device that communicates with the network and backs up the DRM on the reader.
- the network assigns a temporary, local network address to a mobile terminal, this is preferably done by known mechanisms as in the case of WIFI by DHCP.
- the DHCP can also communicate the address of the gateway, which takes over the corresponding ID management.
- information about the access server can be provided, which provides the token accordingly.
- the app / application gets an access permission to the contents by means of a location-specific token, which is valid only for the defined area.
- the application on the mobile device may access the content of the network segment according to the contractual rules (binding to the DRM of the specific content) at the location of the network segment.
- the location-specific token including any cached content, is deleted from the app, preventing further access to the content
- a mechanism that invalidates the token if certain local information is missing eg MAC address, gateway
- IP address the app contains mechanisms that allow for the acquisition of personal rights to the content on request.
- the user can take the content with him by acquiring it accordingly or giving other explanations or consent.
- protected E-contents can be temporarily released in locations / areas with wireless network reception (i.e. WiFi) protected.
- the owner of a mobile device esp.
- Smartphones, Tablets & Notebooks can fully access the e-content without authentication as soon as - and as long as - it stays in the location. If he leaves the location, the access also expires - unless the user has acquired the content.
- the Digital Rights Management is to the
- Figure 1 shows a method with an application on a mobile terminal receiving a token
- FIG. 2 shows a method in which the information flow is described with regard to the functions used
- FIG. 3 shows the process steps on the application and their
- Figure 4 shows a flow chart of the application.
- FIG. 1 shows the possible sequence of the method. The following steps are to be observed.
- the app sends a usage request to the central usage control.
- the address for the central usage control can also be obtained from the DHCP information. Because the
- Rights of use of the protected content held via the local rights owner is a local
- the central usage control determines rights and accesses for the location's access to the content server and generates a location specific. Token passed to the APP.
- the app ensures that after expiration of the read authorization (iR after leaving the local network) the token expires and access to the content is prevented by the local usage control.
- An overview of the content is also provided by the app, for example, in categories and lists
- Thick client or as a web application.
- the interaction with the central usage control must be adequately secured so that compliance with the digital rights can be guaranteed
- Usage control mapping s the identifiers of the locations to the respective accesses of the rights holders (authentication), evaluates the rights to the contents (authorization) and returns to the client a corresponding token for accessing the contents.
- access can be made directly from the client or via the gateway.
- Encryption mechanisms such as SSL are used in synchronous or asynchronous methods.
- Directory service managed as part of an identity management. Since different types of content are used, there are also different ones
- Gateway The technical component that ensures the assignment of a location-specific ID.
- the ID can be arbitrarily composed (eg a network range which is unique for the location or a
- This ID identifying the local network is provided to the client upon request in the response
- Content Server / Digital Content Content is provided by the Content Provider.
- the central usage control provides according to the
- Access is either to appropriately pre-processed content directly to a repository or via a
- the usage control at the location can be realized either as a web solution with the core functionality in the gateway or as an app (thick client) with the core functionality in the app. In any case, the distribution of the components of the lokationssspez.
- Usage control (for example, via the App Store or Gateway as an appliance) is the responsibility of the platform provider and forms a self-contained system.
- One of the possible distributions is shown in the diagram.
- the content of the token essentially contains the information of a SAML Assertion (Security Assertion Markup Language), a standard for the exchange of authentication and authentication
- a binding to the gateway is meant here logically.
- the gateway can also be used outside the
- the gateway is nothing more than a local "gateway" to the mobile device, but the "location” has to be identified by the network.
- the gateway provides the app with the so-called “Location ID.” The determination of the ID must be secured, only if the app has a secure location ID, it gets from the central
- the gateway hereby designates a network-technical solution which assures that the Localization of the mobile terminal takes place and the location can be clearly identified.
- the app only shows the content available at the location
- FIG. 2 shows the sequential flow under
- the app After the user has entered the local network area with their mobile device, the app requests a unique identifier for the location at the gateway.
- the app sends the network ID to the central usage control via an encrypted connection.
- the temporary token will be returned to the app.
- FIG. 3 shows how the technology can be used within an app that provides fixed electronic books, newspapers or audiobooks. Fig. 3 shows the following: After opening the application, the user gets either
- Fig. 4 shows that in the case of authorization, the user can fully view and use the contents.
- Tokens checks. If the token is still valid, the content can continue to be used. If the token is no longer valid, a warning message appears. At the same time, the time without a valid token is added up to a specified limit. If the time without a valid token is above the limit ("Time delay without valid
Landscapes
- Engineering & Computer Science (AREA)
- Business, Economics & Management (AREA)
- Accounting & Taxation (AREA)
- Finance (AREA)
- General Engineering & Computer Science (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computing Systems (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Economics (AREA)
- Theoretical Computer Science (AREA)
- General Physics & Mathematics (AREA)
- General Business, Economics & Management (AREA)
- Physics & Mathematics (AREA)
- Development Economics (AREA)
- Strategic Management (AREA)
- Marketing (AREA)
- Storage Device Security (AREA)
- Information Transfer Between Computers (AREA)
- Telephonic Communication Services (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| DE102013102487.4A DE102013102487A1 (de) | 2013-03-12 | 2013-03-12 | Verfahren und Vorrichtung zur Steuerung des Zugriffs auf digitale Inhalte |
| PCT/EP2014/054676 WO2014139998A1 (de) | 2013-03-12 | 2014-03-11 | Verfahren und vorrichtung zur steuerung des zugriffs auf digitale inhalte |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP2973321A1 true EP2973321A1 (de) | 2016-01-20 |
Family
ID=50239654
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP14708904.9A Ceased EP2973321A1 (de) | 2013-03-12 | 2014-03-11 | Verfahren und vorrichtung zur steuerung des zugriffs auf digitale inhalte |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20160028717A1 (de) |
| EP (1) | EP2973321A1 (de) |
| DE (1) | DE102013102487A1 (de) |
| WO (1) | WO2014139998A1 (de) |
Families Citing this family (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| DE102014116183A1 (de) * | 2014-11-06 | 2016-05-12 | Bundesdruckerei Gmbh | Verfahren zum Bereitstellen eines Zugangscodes auf einem portablen Gerät und portables Gerät |
| US10505850B2 (en) | 2015-02-24 | 2019-12-10 | Qualcomm Incorporated | Efficient policy enforcement using network tokens for services—user-plane approach |
| DE102015115386B4 (de) * | 2015-09-11 | 2018-01-04 | Deutsche Telekom Ag | Ortsgebundene Bereitstellung eines Dienstes in einem Netzwerk |
| US20170339100A1 (en) * | 2016-05-18 | 2017-11-23 | Empire Technology Development Llc | Device address update based on event occurrences |
| US10342445B2 (en) * | 2016-11-03 | 2019-07-09 | Medtronic Monitoring, Inc. | Method and apparatus for detecting electrocardiographic abnormalities based on monitored high frequency QRS potentials |
| JP7189159B2 (ja) | 2017-06-23 | 2022-12-13 | スミス アンド ネフュー ピーエルシー | センサを有効化した創傷モニタリングまたは治療のためのセンサの配置 |
| EP3819798A1 (de) | 2019-11-05 | 2021-05-12 | Service Layers GmbH | Verfahren und system zur ausführung eines identity und access management systems |
| DE202019106136U1 (de) | 2019-11-05 | 2019-12-05 | Service Layers GmbH | System zur Ausführung eines Identity und Access Managements |
| DE102019129762B3 (de) * | 2019-11-05 | 2020-10-15 | Service Layers GmbH | Verfahren und System zur Ausführung eines Identity und Access Ma-nagement Systems |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2011041916A1 (en) * | 2009-10-09 | 2011-04-14 | Quickplay Media Inc. | Digital rights management in a mobile environment |
Family Cites Families (9)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP0127464A3 (de) | 1983-05-30 | 1986-04-16 | Daniel Benjamin Moolman | Abort |
| US6798358B2 (en) | 2001-07-03 | 2004-09-28 | Nortel Networks Limited | Location-based content delivery |
| US7103351B2 (en) * | 2003-06-23 | 2006-09-05 | July Systems Inc. | Policy service system and methodology |
| US8086536B2 (en) * | 2004-09-16 | 2011-12-27 | Microsoft Corporation | Location based licensing |
| US20060173782A1 (en) * | 2005-02-03 | 2006-08-03 | Ullas Gargi | Data access methods, media repository systems, media systems and articles of manufacture |
| US20070116288A1 (en) * | 2005-11-18 | 2007-05-24 | Oktay Rasizade | System for managing keys and/or rights objects |
| AU2007206046A1 (en) | 2006-01-19 | 2007-07-26 | Safelite Group, Inc. | Method and device for providing location based content delivery |
| EP2074836A2 (de) * | 2006-08-17 | 2009-07-01 | Core Mobility, Inc. | Präsenzbasierte kommunikation zwischen zugangspunkten eines lokalen drahtlosen netzwerkes und mobilen vorrichtungen |
| US9330275B1 (en) * | 2013-03-28 | 2016-05-03 | Amazon Technologies, Inc. | Location based decryption |
-
2013
- 2013-03-12 DE DE102013102487.4A patent/DE102013102487A1/de not_active Withdrawn
-
2014
- 2014-03-11 US US14/774,737 patent/US20160028717A1/en not_active Abandoned
- 2014-03-11 WO PCT/EP2014/054676 patent/WO2014139998A1/de not_active Ceased
- 2014-03-11 EP EP14708904.9A patent/EP2973321A1/de not_active Ceased
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| WO2011041916A1 (en) * | 2009-10-09 | 2011-04-14 | Quickplay Media Inc. | Digital rights management in a mobile environment |
Also Published As
| Publication number | Publication date |
|---|---|
| DE102013102487A1 (de) | 2014-09-18 |
| US20160028717A1 (en) | 2016-01-28 |
| WO2014139998A1 (de) | 2014-09-18 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP2973321A1 (de) | Verfahren und vorrichtung zur steuerung des zugriffs auf digitale inhalte | |
| KR102462894B1 (ko) | 통제된 액세스 자원들에 대한 위치―기반 액세스 | |
| US9225704B1 (en) | Unified management of third-party accounts | |
| DE112018004390B4 (de) | Sichere zugriffsverwaltung für werkzeuge innerhalb einer sicheren umgebung | |
| DE102010053651B3 (de) | Verfahren und Verwendung eines Systems zur ortsbeschränkten Anzeige lesbarer Inhalte auf einem mobilen Lesegerät | |
| DE102016012835B4 (de) | Automatisches Identifizieren einer verringerten Verfügbarkeit von Vielkanalmedienverteilern zur Authentisierung oder Autorisierung | |
| DE102015101240A1 (de) | Drahtlosleistungssendeeinrichtungen, verfahren zum signalisieren von zugangsinformationen für ein drahtloskommunikationsnetz und verfahren zum autorisieren einer drahtlosleistungsempfangseinrichtung | |
| DE112013006286B4 (de) | Verfahren und System zur Authentifizierung und zum Betreiben persönlicher Kommunikationsgeräte über Netzwerke der öffentlichen Sicherheit | |
| DE112010005387T5 (de) | Instore Lese-System | |
| GB2500597A (en) | An integrated server and access point | |
| DE112017002794T5 (de) | Verfahren und vorrichtung zum ausstellen eines berechtigungsnachweises für ein incident area network | |
| DE102013203101A1 (de) | Erweitern der Attribute einer Credentialanforderung | |
| CN103209107B (zh) | 一种实现用户访问控制的方法 | |
| EP1604490A1 (de) | Verfahren und anordnung zum externen steuern und verwalten wenigstens eines einem lokalen funknetz zugeordneten wlan-teilnehmers | |
| DE102019005737A1 (de) | Verfahren zur Erst-lnbetriebnahme eines Datenerfassungsgeräts | |
| DE112012006751T5 (de) | Bereitstellen von Vertragsdaten zum Ermöglichen des Zugangs eines Kundengeräts zu einer ausgewählten Einrichung aus einer Vielzahl von Einrichtungen | |
| EP3857405A1 (de) | Datenbanksystem für ein soziales netzwerk mit verwendung von blockchain-technologie | |
| EP2041923A2 (de) | Verfahren und anordnung zur realisierung von zugangsnetzwerken zu einem öffentlichen netzwerk | |
| EP3142338B1 (de) | Ortsgebundene bereitstellung eines dienstes in einem netzwerk | |
| EP1845689B1 (de) | Verfahren und kommunikationssystem zum bereitstellen eines personalisierbaren zugangs zu einer gruppe von einrichtungen | |
| EP2068530B1 (de) | Verfahren und Kommunikationssystem zum Steuern des Zugangs zu Medieninhalten in Abhängigkeit des Alters eines Nutzers | |
| EP3089499B1 (de) | Nutzeridentifikation mit infrarotsignalen | |
| DE102005027219A1 (de) | Verfahren zur Funktionsüberwachung bei einer medizinischen Großanlage | |
| AT13290U1 (de) | Verfahren und System zum Bereitstellen von Daten auf einem Endgerät | |
| DE112013002121B4 (de) | Managen von sich wiederholenden Zahlungen von mobilen Endstellen |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| 17P | Request for examination filed |
Effective date: 20151012 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| DAX | Request for extension of the european patent (deleted) | ||
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: EXAMINATION IS IN PROGRESS |
|
| 17Q | First examination report despatched |
Effective date: 20170510 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R003 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN REFUSED |
|
| 18R | Application refused |
Effective date: 20190513 |