TWI227846B - Method and apparatus managing the transfer of rights - Google Patents
Method and apparatus managing the transfer of rights Download PDFInfo
- Publication number
- TWI227846B TWI227846B TW91124583A TW91124583A TWI227846B TW I227846 B TWI227846 B TW I227846B TW 91124583 A TW91124583 A TW 91124583A TW 91124583 A TW91124583 A TW 91124583A TW I227846 B TWI227846 B TW I227846B
- Authority
- TW
- Taiwan
- Prior art keywords
- rights
- license
- consumer
- item
- scope
- Prior art date
Links
Landscapes
- Storage Device Security (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
Description
12278461227846
著作權告示: 本專利申請文件的部分 在專利商標局的專利樓案或 不反對專利文件或揭露的複 則保留於其上之所有著作權 揭露受到著作權的保護,當其 紀錄中顯示時,著作權所有者 本重衣,但除此以外的情形, 之權利。 一、 【發明所屬之技術領域】 本發明係關於一種權利移轉的方法與裝置。 二、 【先前技術】 阻礙藉由電子方法,特別是網際網路,傳播之數位作 品(digital work)(就是以電腦可讀之形式的文件或其他 内容)的最重要爭端之一,在於現今於數位作品使用與傳 播期間,缺乏執行内容所有者之智慧財產權的能力。解決 這類問題的工作,已稱為π智慧財產權管理 "(Intellectual Property Rights Management, IPRM) ^ ’’數位財產權管理"(Digital Property Rights Management,DPRM)、n 智慧財產管理”(intei iectual Property Management, IPM)、丨丨權利管理,丨(Ri ghts Management,RM)、以及ff 電子著作權管理"(Electronic Copyright Management, ECM),在此集合起來通稱為丨丨數 位權利管理’’(Digital Rights Management, DRM)。在實 現DRM系統上,需考量許多問題。舉例來說,應該要提出 認證(authentication)、授權(authorization)、帳單Copyright notice: Part of this patent application document is in the Patent Office of the Patent and Trademark Office or no objection to patent documents or disclosure. All copyright disclosures retained on it are protected by copyright. When shown in their records, copyright owners This heavy clothing, but in other cases, the right. 1. [Technical Field to which the Invention belongs] The present invention relates to a method and device for transferring rights. 2. [Prior art] One of the most important disputes that hinder the dissemination of digital work (that is, documents or other content in computer-readable form) through electronic methods, especially the Internet, is now in During the use and dissemination of digital works, the ability to enforce the intellectual property rights of the content owner is lacking. The work to solve such problems has been called π Intellectual Property Rights Management (IPRM) ^ "Digital Property Rights Management (DPRM), n Intellectual Property Management" (intei iectual Property Management, IPM), 丨 丨 Rights Management, (Rights Management, RM), and ff Electronic Copyright Management " (Electronic Copyright Management, ECM), collectively referred to herein as 丨 丨 Digital Rights Management '' (Digital Rights Management) Management, DRM). There are many issues to consider when implementing a DRM system. For example, you should propose authentication, authorization, and billing.
illill
I __ 第5頁 1227846 五、發明說明(2) (accounting)、付款(pay men t)與財務清算(f i nanc i a 1 clearing)、權禾J 說明(r i gh t s specification)、權利確 認(rights verification)、權利執行(rights enforcement),以及文件保護課題等。參考美國專利號5, 530,235、5,634,0 1 2、5,71 5,403、5,638,443,以及 5, 6 29, 98〇,揭露了解決此些爭端的DRM系統。 已經使用的兩大基本DRM設計是安全容器(secure container)與信託系統(trusted system)。"安全容器 π(或簡單的加密文件(encrypted document)),提供一種 在符合一組授權情況與准予若干著作權條件(如使用者付 費)之前,保持文件内容為加密的方法。在文件提供者確 認各種情況與條件之後,文件會以不加密的形式(c丨ear f orm)發送給使用者。如商用產品crypt〇l〇PEStM與 D I G I B0XESTM,皆屬於此範疇。顯然地,安全容器的技術, 在非安全通道上,提供了保護文件的解決方法,但其無法 提供任何的機制,來避免合法使用者取得不加密文件後, 使用並再傳播此文件造成侵犯内容所有者之智慧財產權。 在”信託系統’’技術中,整個系統負責避免未授權的使 用與文件的傳播。建構信託系統通常需要新的硬體,例如 女全處理 $ (secure processor)、安全儲存(secure storage) ’ 與安全翻譯設備(secure rendering devices)。因此,在信託系統上執行的軟體應用也需要被I __ Page 5 1227846 V. Description of the invention (2) (accounting), payment (pay men t) and financial liquidation (fi nanc ia 1 clearing), Quanhe J specification (ri gh ts specification), rights verification (rights verification ), Rights enforcement, and file protection issues. References to U.S. Patent Nos. 5,530,235, 5,634,0 1 2, 5,71 5,403, 5,638,443, and 5, 6 29, 98, disclose DRM systems that resolve these disputes. The two basic DRM designs that have been used are secure containers and trusted systems. " Secure Container π (or simply an encrypted document) provides a way to keep the content of a file encrypted until it meets a set of licensing conditions and grants certain copyright conditions (such as user fees). After the file provider confirms the various conditions and conditions, the file will be sent to the user in an unencrypted form (cearear). Commercial products such as crypt〇l〇 PEStM and D I G I B0XESTM fall into this category. Obviously, the technology of secure containers provides solutions to protect files on non-secure channels, but it cannot provide any mechanism to prevent legitimate users from using and re-propagating this file after obtaining an unencrypted file to cause infringement. Intellectual property rights of the owner. In the "trust system" technology, the entire system is responsible for avoiding unauthorized use and the spread of documents. Building trust systems usually requires new hardware, such as women's full processing $ (secure processor), secure storage ('secure storage') and Secure rendering devices. Therefore, software applications running on the trust system also need to be
第6頁 1227846 五、發明說明(3) 認證為可信賴的。當對於既存技術而言,建構一防止竄改 (tamper-proof)之信託系統是一大挑戰時。現今市場^勢 建議,諸如使用瀏覽器通往網頁的個人電腦(pc)與工作站 等之開放且不可靠的系統,將是用來通往數位作品的首要 · 系統(dominant system)。這樣的認知下,既存的電腦環 · · i兄’諸如搭配普通操作系統(例如W i n d 〇 W STM、[ i n u χΤΜ,與 UN I X)的個人電腦與工作站,以及例如瀏覽器之翻譯應 - 用’在沒有重大更動它們架構的情形下,不會是信託系 統,也不會是可靠的。當然,架構的更動,削弱了網頁之 諸如靈活度與相容性的原本目的。 舉例來說’參考美國專利5,63 4,0 1 2的揭露,揭示一 種用以控制數位文件傳播的系統。每個翻譯裝置具有一配 合的儲存庫(repository)。預設一組使用交易(usage ‘ transaction)步驟,定義一執行使用權(usage rights)的, 儲存庫所使用的協議(Protocol)。使用權定義了一或多個 使用相關文件内容與存留文件内容的方式。使用權允許各 種使用方式,例如只能觀看、使用一次、傳播等諸如此 類使用權也可在付款或其他情形下附加上去。再者,一 團體能將使用權授予此團體所擁有之次級使用權(a ❶ subset 〇f usage rights)給其他團體。 DRM系統藉由允許内容使用者可控制其内容的使用, 疋進了電子内容的傳播。然而,以㈣、傳播、以及使用Page 6 1227846 V. Description of the invention (3) Authentication is trustworthy. When building a tamper-proof trust system is a challenge for existing technologies. The market today suggests that open and unreliable systems, such as personal computers (pcs) and workstations that use browsers to access web pages, will be the primary system for accessing digital works. Under this recognition, existing computer rings, such as personal computers and workstations with common operating systems (such as Windows STM, [inu χΤ, and UN IX), and translation applications such as browsers- 'Without major changes to their architecture, it will not be a trust system or reliable. Of course, changes to the architecture have weakened the original purpose of the web page, such as flexibility and compatibility. By way of example, reference is made to the disclosure of U.S. Patent 5,63 4,0 12 to disclose a system for controlling the spread of digital files. Each translation device has a matching repository. A preset set of usage transaction steps defines a protocol used by the repository to execute usage rights. The right to use defines one or more ways to use the content of the relevant file and keep it. The right of use allows various ways of use, such as viewing, use only, dissemination, etc. Such right of use can also be added in payment or other circumstances. Furthermore, a group can grant usage rights (a ❶ subset 〇f usage rights) owned by this group to other groups. The DRM system advances the dissemination of electronic content by allowing content users to control the use of their content. However, to spread, spread, and use
1227846 五、發明說明(4) 電子内容與其他項目為目的的已知商業模式,牽涉了許多 的團體。舉例來說,内容創作者可將内容販售給出版商, 然後出版商授權給配銷商在線上店面(〇n—丨ine storefront)傳播内容,然後線上店面販售内容給終端用 戶(end-user)。再者,終端用戶可能會試圖分享或進一步 傳播此内容。在如此的商業模式中,可根據每個團體在傳 播鍵上的角色’給予其使用權。然而,除非團體以某些方 式’參與或瞭解下游團體的交易協議,否則他們無法控制 其下游的團體。舉例來說,一旦出版商提供内容給配銷 商’出版商不容易控制那些已授予下游團體的權利,例如 第一或隨後的使用者,除非出版商保留一團體至下游交易 協義。結合了日盈複雜傳播鏈的控制之喪失,造成了阻礙 電子内容或其他項目傳播的情形。再者,出版商也許是要 禁止配銷商及/或店面觀看或列印内容,而允許從店面接 受一許可證的終端使用者觀看或列印。根據上述,簡化權 利給屬於次級所有權的觀念並不適用於多團體,也就是多 層級(multi-tier)傳播模式。 【發明内容 本發明之一方面是,從一權利供應者到一權利消費 者’移轉適宜關聯項目的權利的一種方法。此方法包含獲 得一組關聯一項目的權利,此組權利包含後設權利 (m e t a - r i gh t s) ’其詳細指明可由權利消費者取得之可衍 生的權利(derivable rights),以及決定是否給予權利消1227846 V. Description of Invention (4) Many known groups involve electronic content and other known business models. For example, content creators can sell content to publishers, and then publishers authorize distributors to distribute content on the online storefront (〇n— 丨 ine storefront), and then sell content to online users (end- user). Furthermore, end users may attempt to share or further disseminate this content. In such a business model, each group can be given the right to use it based on its role on the distribution key. However, unless a group ’s participation in or understanding of a downstream group ’s transaction agreement in some way, they cannot control their downstream group. For example, once a publisher provides content to a distributor, a publisher's cannot easily control the rights that have been granted to downstream groups, such as first or subsequent users, unless the publisher retains a group to downstream transaction agreement. The loss of control combined with Riying's complex communications chain has created situations that hinder the dissemination of electronic content or other items. Furthermore, publishers may want to prohibit distributors and / or stores from viewing or printing content, but allow end users who receive a license from the store to view or print. According to the above, the idea of simplifying the granting of rights to sub-ownership does not apply to multi-group, that is, multi-tier transmission models. [Summary of the Invention] One aspect of the present invention is a method of transferring the right of an associated item from a rights supplier to a rights consumer '. This method involves obtaining a set of rights associated with a project, this set of rights including meta-ri gh ts' which specifies the derivable rights that can be obtained by the rights consumer, and decides whether to grant rights Eliminate
第8頁 1227846Page 8 1227846
費者取得由後設權利所指明之可衍生的權利,與所取得之 該複數個可衍生的權利之至少其_,以及假如給予權利 費者取得由後設權利所定之可衍生的權利時,產生一咛可 證(license),其包含指明權利消費者為一主體的被衍生 權利(p r i n c i p a 1 ) 0 本發明之另-方面是,一種關聯一項目的許可證 宜在一糸統中使用’此系移Ρ r- -I- κ 亍、、、死用以攸一榷利供應者到一權利 泊費者,處理權利移轉$卜μ s η ^ ^ ^ 得至此項目。許可證包含一組權利, 其包含一後設權利,詳細沪日士以立丨、上祖+ 惟〜 的榷利、一主體標明至.一 丁王 . λα τ 榣利消費者,其被授權取得可The fee acquirer obtains the derivable rights specified by the subordinated rights, and at least one of the plurality of derivable rights acquired, and if the grantee is granted the right, the feederable rights stipulated by the subordinated rights, Generate a license that contains derived rights (principa 1) specifying the right consumer as a subject. Another aspect of the invention is that a license associated with a project should be used in a unified system. The system transfers ρ r- -I- κ 、,,,, and dying to the benefit of the supplier to a right to pay the fee, to deal with the transfer of rights $ oo μ s ^ ^ ^ ^ to this project. The license contains a set of rights, which includes a post-decision right, detailing the Japanese and Japanese priests, the ancestor + Wei ~, the subject, and the subject is marked to. 一 丁 王. Λα τ 榣 Li consumers, who are authorized Obtainable
何生的榷利、以及一撼生丨丨m w J ^ 制用以k供關聯此組權利之項目的He Sheng's doubts, and a shocking life 丨 m w J ^
本潑^明之又一方而H 項目的權利的方法。心、二種從後設權利取得適宜關聯 利,此組權利包含後包含獲得一組關聯一項目的權 得之可衍生的權;/=’其詳細指明由權利消費者取 一許可證。 產生關聯項目與包含衍生權利的This splash is another way of knowing the H project right. Two types of rights are obtained from meta-rights. This group of rights includes the derivable rights that include the right to obtain a set of related rights; / = ’, which specifies that the right consumer obtains a license. Generate associated projects and
四、【實施方式】 可利用一數位權刹总m 行特定内容、服務、σ、&里DRM )系統,以詳細指明與執 使用於連接之較佳勒^ 他項目的使用權。圖1說明一可 土汽知例的—數位權利管理(DRM)系統4. [Implementation] A digital rights brake system can be used to specify the content, service, σ, & DRM) system, in order to specify and execute the right to use the better alternative project for connection. Figure 1 illustrates a known example of a digital rights management (DRM) system.
1227846 五、發明說明(6) - 10。DRM系統10包含一以啟動伺服器20(activati〇n server)為形式之使用者啟動組件(user activatbn component),如已知的,其在一保護形式下核發(issue) 共有與私有餘對(key pair)給内容使用者。在啟動過程 中,若干資訊在啟動伺服器20與客戶環境3〇(cHent environment)之間交換,其中客戶環境3〇是一關聯一内容 接文者((:〇1^6111: recipient)的電腦或其他設備,以及下 載客戶組件60 (cl ient component),並安裝於客戶環境3〇 中。客戶組件60最好是可防竄改的,並且包含由啟動伺服 器20核發的一組共有與私有鑰對,以及其他要件,例如需 要用以翻譯内容4 2的任何組件。 而 權利標記40(rights label)與内容42關聯,且詳細指 明使用權,以及可由一内容接受者選擇之可能對應的條曰 件。許可證伺服器50(license 361^61〇處理加密鑰匙、 (encryption keys)以及核發受保護内容的許可證。此些 許可證收錄(embody)給終端使用者之使用權的實際授予。 舉例來說,權利標記40可包含一使用權,其允許三接受者 付費5 το觀看内容,以及付費丨〇元觀看與列印内容。舉例 來說,當已付費5元時,對於觀看權核發許可證52。客戶 + 組件60可瞭解並執行這些於許可證52中指定的權利。 圖6為根據一較佳實施例之一權利標記4 〇。權利標記 4〇包含若干權利提供者44(rights offers),每個權利提1227846 V. Description of Invention (6)-10. The DRM system 10 includes a user activatbn component in the form of an activation server 20 (activation server). As is known, it issues issues of public and private pairs in a protected form ( key pair) to content users. During the startup process, certain information is exchanged between the startup server 20 and the client environment 3 (cHent environment), where the client environment 30 is a computer associated with a content receiver ((: 〇1 ^ 6111: recipient) Or other devices, and download the client component 60 (cl ient component) and install it in the client environment 30. The client component 60 is preferably tamper-resistant and contains a set of shared and private keys issued by the startup server 20 Yes, and other requirements, such as any components needed to translate the content 42. The rights label 40 (rights label) is associated with the content 42 and specifies the right of use and a possible corresponding clause that can be selected by a content recipient. License server 50 (license 361 ^ 61〇 processing encryption keys, (encryption keys), and issuance of licenses for protected content. These licenses embody the actual grant of use rights to end users. Examples For example, the rights mark 40 may include a right of use, which allows three recipients to pay 5 το to watch the content, and pay 丨 0 yuan to view and print the content. For example, when When 5 yuan has been paid, the license 52 is issued for the viewing right. The customer + component 60 can understand and enforce these rights specified in the license 52. Figure 6 shows a rights mark 4 0 according to a preferred embodiment. Rights mark 4〇 Includes several rights providers 44 (rights offers)
第10頁 1227846 五、發明說明(7) 供者4 4包含使用權4 4 a、情況4 4 b、以及内容說明 44c(content specification) ° 内容說明44c 可以包含用 以呼叫、委託、定位、連結、或除此之外關聯提供者4 4之 特定内容4 2的任何機制。關聯内容出版商、内容配銷商、 内容服務提供者、或其他團體的一電腦7〇,在其上安裝的 ion application) 的準備包含詳細指明 權利標記40與内容 利用如XrMLTM的權利 用任何方式說明。權 式’或是僅關聯内容 權利的過程參照關聯 之權利標記4 0與用來 ’可以被傳遞至許可 權利4 4 a可包含說明 他的權利的後設權Page 10 1227846 V. Description of the invention (7) The supplier 4 4 includes the right to use 4 4 a, case 4 4 b, and content specification 44c (content specification) ° Content specification 44c may include for calling, commissioning, positioning, and linking , Or any mechanism other than a specific content 4 2 of the provider 44. Preparation of a computer 70 associated with a content publisher, content distributor, content service provider, or other group, on which the ion application is installed) includes specifying the rights mark 40 and the rights to use the content such as XrMLTM in any way Instructions. Rights ’or only the content. The process of rights is referred to the associated rights mark 40 and used to’ can be passed to the license. Right 4 4a may include a post-right to explain his rights.
文件準備應用72 (document preparat 準備未加密(未受保護)的内容。内容 内容42可使用下的權利與條件、關聯 42、以及以加密演算保護内容42。可 语言指明權利與條件。然而,權利可 利也可以是一預先定義好的說明書形 的樣本(temp late)。根據上述,指明 格利與内容的任何過程。關聯内容4 2 ,為碼内谷的加密餘(encrypt i on key ) 證飼服器50。如下要詳細討論的是, 使用方式的使用權,以及允許取得盆 利。 〃 需滿子中,許可證52包含為了行使-特定權利所 而士足的條件。舉例來說,條件可以是, 所 之别的付費、提交個人資料 仃 行為 可以是"存取條件"(ac='0=其他所需的要求。條件 樂部的會員等。換句n 干的孥生、或是登記俱 換句3舌§兄,條件可以是,使用者是一特定Document preparation application 72 (document preparat prepares unencrypted (unprotected) content. Rights and conditions under which content content 42 can be used, associations 42, and content protection with encryption algorithms 42. Rights and conditions can be specified in language. However, rights Koli can also be a pre-defined sample (temp late). According to the above, specify any process of Gree and the content. The associated content 4 2 is the encrypted i on key certificate of the code valley. Feeder 50. As discussed in more detail below, the right to use the method of use, and the allowance to obtain a profit. 中 In the case of a man, the license 52 contains conditions required to exercise-specific rights. For example, The condition can be that the other payment and submission of personal data can be " access conditions " (ac = '0 = other required requirements. Members of the condition club, etc. In other words n dry health Or register in another sentence 3 §Brother, provided that the user is a specific
12278461227846
族群的會員之一或是特定的一個人 離存在行使,或是結合一起亦可。 權利與條件可以以分 標記、提供者、使用權、與條件,皆可和内容 是=容說明44c或其他機制之除此之外的 ,或 一起储存。可利用如XrMLTM的權利語言說明權利血=42 無淪如何,可用任何方式指明權利。權利也可以是—。 定義好的說明書形式’或是僅關聯内容42的樣本。預先 DRM系統1 〇的典型工作流程詳述如。 二環作的一接受者,以接受啟動词服4動‘ 已知方式下,造成一共有—私有輪 一One of the members of the ethnic group can be exercised separately or combined. Rights and conditions can be divided into tags, providers, usage rights, and conditions, which can be stored with the content or other content except 44c or other mechanisms. The rights language such as XrMLTM can be used to explain the rights and blood = 42. No rights can be specified in any way. Rights can also be-. A well-defined description form 'or a sample of only the associated content 42. The typical workflow of the pre-DRM system 10 is detailed as follows. A recipient of the second ring, accepting the activation verb to act 4 ‘Known method, resulting in a total — private round
使用者/機器特有資訊),以客戶軟體要件60的形弋—、了些 環境3 0。啟動過程可在核發一許可證之前;任:J 當一接X者欲得到一特定的内容4 2時,可 — 作出一請求(request)。舉例來說,作為接受者—^ 者,可以使用在客戶環境3〇中安裝的劉覽器使用 伺服器(Web ”〇6〇8〇上的網站,以及請求内^在=頁 過程中,使用者可能經過一連串可能包含費用 :在此 販售内容時)或其他交易(例如資料收集)的步驟。^ = f 了若干適宜的條件與其他必要前提,例如收取費田" 使用者已被啟動時,網頁伺服器8 〇會透過安全诵=^ 5忍 、机通道User / machine-specific information), in the form of customer software element 60-some environment 30. The initiation process can be before a license is issued; any: J When the person receiving X wants to get a specific content 4 2 can-make a request. For example, as the recipient—the recipient, you can use the website of the server (Web) server (Web) 0608 installed in the client environment 30, and use the request in the process of = pages. The user may go through a series of steps that may include fees: when the content is sold) or other transactions (such as data collection). ^ = F A number of suitable conditions and other necessary prerequisites, such as fee collection " user has been activated At the time, the web server 8 〇 will pass the secure recitation = ^ 5 tolerance, machine channel
12278461227846
五、發明說明(9) (secure communication channel),例如使用網路資料安 全傳輸協定(Secure Sockets Layer, SSL)的通道,聯繫 a午可證伺服器5 〇。稍後許可證伺服器5 〇為内容4 2產生一許 可證5 2 ’以及網頁伺服器8 〇引起内容與許可證5 2的下載。 5午可證5 2包含適當的權利,例如使用權與/或後設權利, 並從許可證伺服器5 〇或關聯設備下載下來。内容4 2可從關 聯買主、配銷商、或其他團體的電腦7 〇中下載。V. Explanation of the invention (9) (secure communication channel), for example, a channel using a network data security transmission protocol (Secure Sockets Layer, SSL), contact a certificate server 50. Later, the license server 50 generates a license 5 2 'for the content 4 2 and the web server 80 causes downloading of the content and the license 52. The 5K certificate 5 2 contains the appropriate rights, such as the right to use and / or subsequent rights, and is downloaded from the license server 50 or associated equipment. Content 4 2 can be downloaded from a computer 7 0 of an associated buyer, distributor, or other group.
在客戶環境30中的客戶要件6〇,稍後將進行翻譯 (interpret)許可證52,並且基於使用權與在許可證52中 指明的條件,允許内容42的使用。使用權的翻譯與執行為 已知之技藝,舉例來說,可參照上述的專利。上述之步驟 可以依序或幾乎同時進行,或是有不同的順序亦可。 ^ DRM系統10應付(address)内容42的安全性方面。特別 疋DR Μ系統1 〇可認證由許可證伺服器5 〇核發的許可證 52。為應用程式6〇完成如此認證的一種方法,是去決定是 否此許可證52是可信賴的。換句話說,應用程式6〇有能力 去核對(verify)與證實(validate)用密碼寫的簽名 (CryPt〇graphic signature),或是許可證52之其他可識 別的特性。當然,上述例子只是實現DRM系統的一種方 式。t例來說,可以從不同的實體傳播許可證52與内容 42。報交換機構90(clearingh〇use)可用來進行付款交 易與在核發一許可證之前核對付款。The customer requirement 60 in the customer environment 30 will be interpreted later with a license 52, and the use of the content 42 is permitted based on the right of use and the conditions specified in the license 52. The translation and enforcement of the right of use are known techniques, for example, refer to the patents mentioned above. The above steps can be performed sequentially or almost simultaneously, or in a different order. ^ The DRM system 10 addresses the security aspects of content 42. In particular, the DR Μ system 10 can certify a license 52 issued by a license server 50. One way to accomplish such authentication for the application 60 is to decide whether this license 52 is trustworthy. In other words, the application 60 has the ability to verify and validate a cryptographic signature (CryPtgraphic graphic signature), or other identifiable features of the license 52. Of course, the above example is just one way to implement a DRM system. For example, licenses 52 and content 42 can be disseminated from different entities. The clearing house 90 (clearing server) can be used to conduct payment transactions and verify payments before issuing a permit.
第13頁 1227846 五、發明說明(10) 上述要 含若干團體 者。在一傳 給予下游的 念,例如美 5, 638, 443 與相關的系 後設權利是 衍生其他權 其他後設權 非常清楚。 注意的是,傳播數位内容之典型的商業模式包 ,例如所有者、出版商、配銷商、以及使用 播鏈中,每個團體皆可作為一供應者,將權_ 一消費者。此較佳實施例延伸使用權的已知觀 國專利號5, 62 9, 980、5, 634, 0 1 2、 k 5, 715, 403,以及5, 630, 235所揭露之使用權 統,加上(incorporate )π後設權利”的觀念。 一個體必須產生、操縱、修正、處置或除此外 利的權利。後設權利可被認為是對使用權(或 利)的使用權。這樣的觀念基於如下的描述將 後設權利能包含 轉讓權利(negotiate 權、暴露權利、權利 (compile rights)、 r ights)、交換權利' 從其他方面。後設權 的任何條件。舉例來 縮小一特別權利的範 或縮小一權利的有效 (hierarchical),以 配銷商可擁有後設權 可衍生權利以提供權利、給予權利、 rights)、得到權利、移轉權利、姨 存檔(archive rights)、編譯權利 追縱權利、讓渡權利(s u r r e n d e r 以及撤銷權利(revoke rights)到/ 利能包含權利,可修正關聯其他權利 說’後設權利是一種權利,可擴大或 圍。後設權利是一種權利,也可擴大 期限。後設權利能是分級體系的 建構為物件中的物件。舉例來說,一 利’允許配銷商將一後設權利給予一Page 13 1227846 V. Description of the invention (10) The above should include several groups. In the first pass, the downstream ideas are given, such as the US 5, 638, 443 and related systems. Subsequent rights are derived from other rights. Other post rights are very clear. Note that the typical business model package for disseminating digital content, such as owners, publishers, distributors, and users of broadcast chains, each group can act as a supplier and a consumer_a consumer. This preferred embodiment extends the usage rights disclosed in the well-known Guanguo Patent Nos. 5, 62 9, 980, 5, 634, 0 1 2, k 5, 715, 403, and 5, 630, 235, Add the concept of (incorporate) π meta-rights ". An entity must create, manipulate, amend, dispose of, or otherwise benefit from rights. Meta-rights can be considered as the right to use (or benefit). Such The idea is based on the following description that the meta-rights can include transfer rights (negotiate rights, exposure rights, compile rights, rights), exchange rights' from other aspects. Any conditions of meta-rights. For example to narrow down a special right Or reduce the effectiveness of a right, so that the distributor can have subsequent rights and can derive rights to provide rights, grant rights, obtain rights, transfer rights, archive rights, compile rights Pursuing rights, surrender rights, and revoke rights include rights, which can be amended in relation to other rights and say 'the post-right is a right that can be expanded or encircled. Li is a right, the period may be expanded after the claim could be provided for construction of an object in the hierarchy of objects. For example, a benefit 'will allow a Dealers claim administration a meta
第14頁 1227846 五、發明說明(11) 零售商,其允許零售商給予使用者觀看内容的權利。如同 權利有若干條件,後設權利也能有若干條件。後設權利也 能關聯其他後設權利。 後設權利的概念能特別有用,因為傳播模式可包含若· 干不是數位内容的創作者或擁有者的實體,但其存在於關 聯内容之運用權利的交易中。舉例來說,如上述要注意的 是,在多層級内容傳播模式中,中間實體(intermedia;e e n t i t i e s )(例如配銷商)一般將無法創造或使用内容,但 被給予權利去對其所傳播之内容核發權利。換句話說,配+ 銷商或轉售商需要得到權利(後設權利)才可核發權利。為 清楚起見’給予使用權或後設權利的團體被歸類於”供應 者”’且接受與/或行使此權利的團體在此被歸類於”消費 者”。非常清楚的,任何團體能是一供應者或一消費者, 端視其在一傳播鏈中,與相鄰團體之間的關係為何。注意 一消費者消費’’,也就是行使權利,並且未必消費,也就 是使用關聯的内容。 圖2示意地說明一多層級傳播模式2 〇 〇的例子。舉例, 出版商2 1 0為了配銷商2 2 〇的傳播,出版内容。配銷商2 2 0 傳播内容給零售者,例如零售商23〇,零售商230販售内容 給使用者,例如使用者2 4 〇。在模式2 〇 〇中,出版商21 〇能 與配銷商220轉讓商業關係,而配銷商22〇能與零售商230 轉讓商業關係。同時,零售商2 3 0可要求除了給予配銷商Page 14 1227846 V. Description of Invention (11) Retailer, which allows the retailer to give users the right to view content. Just as a right has several conditions, a subsequent right can also have several conditions. Meta-rights can also be linked to other meta-rights. The concept of meta-rights can be particularly useful, as the mode of transmission can include entities that are not creators or owners of digital content, but that exist in transactions involving the use of rights in related content. For example, as mentioned above, it should be noted that in multi-level content distribution models, intermediate entities (e.g., distributors) will generally not be able to create or use content, but are given the right to distribute it. Content release rights. In other words, distribution + resellers or resellers need rights (subsequent rights) to issue rights. For the sake of clarity, the group that grants the right of use or subordinate right is classified as a “supplier” and the group that accepts and / or exercises this right is classified here as a “consumer”. It is very clear that any group can be a supplier or a consumer, depending on its relationship with neighboring groups in a transmission chain. Note that a consumer consumes', that is, exercising rights, and does not necessarily consume, that is, using associated content. FIG. 2 schematically illustrates an example of a multi-level propagation mode 2000. For example, the publisher 2 10 publishes content for the dissemination of the distributor 220. Distributor 2 2 0 disseminates content to a retailer, such as retailer 23, and retailer 230 sells content to a user, such as user 2 4 0. In model 2000, publisher 21 can transfer business relationships with distributor 220, and distributor 220 can transfer business relationships with retailer 230. At the same time, retailers 2 30 may require
第15頁 1227846 1、發明說明(12) " ' —- 2 2 0之使用權的使用權。然而,要記住的是,在利用一用 以控制内容或其他項目的使用與傳播之DRM系統的一傳播 鏈中’内容可透過任何數位通訊通道,例如一網路或實際 中介傳送,從出版商210行進至使用者240。當使用者24〇 希立使用此内各日t,可得到如上述之方式的一許可證。根 據上述’被轉讓關係如果不是不可能,就是會變得非常困 難。‘ 圖2的模式2 0 0 ’零售商2 3 0僅能將已經預設的權利給 予使用者240,亦即由配銷商220、出版商210、以及潛在 + 的其他處理之上游團體’例如内容創作者或擁有者,所預 設的權利。權利是預設過的,並且從配銷商2 2 0給予零售 商2 3 0之後設權利所衍生出來。當然,在傳播鏈中可具有 任何數量的團體。舉例來說,在不需零售商230的條件 下,配銷商2 2 0可直接販售給大眾。也能有額外附加的團 體,例如使用者2 4 0可傳播給其他使用者。 模式2 0 0中,出版商給予配銷商2 2 0使用權2 1 2,允許 内容的傳播與後設權利214。後設權利214允許配銷商220 g 給予零售商230使用權21 4’(從後設權利214衍生而來),以〇 用來配銷或可能販售内容與後設權利2 1 6。後設權利2 1 6允 許零售商230給予使用者240權利去使用内容。舉例來說, 出版商2 1 0可透過後設權利2 1 4指明,給予零售商2 3 0的後 設權利2 1 6,允許零售商2 3 0去給予只有5 0 0份許可證與使Page 15 1227846 1. Description of the invention (12) " '--- 2 2 0 The right to use the right. However, it is important to keep in mind that in a distribution chain utilizing a DRM system that controls the use and dissemination of content or other items, 'content can be transmitted through any digital communication channel, such as a network or physical intermediary, from publishing The quotient 210 travels to the user 240. When the user uses the days t here, he can get a license as described above. According to the 'assignment relationship', if it is not impossible, it becomes very difficult. 'Mode 2 of Figure 2 0 0' Retailers 2 3 0 can only give users 240 pre-set rights, that is, upstream groups handled by distributor 220, publisher 210, and other potential + ' Content creator or owner, preset rights. Entitlements are pre-set and derived from the rights placed by the distributor 220 to the retailer 230. Of course, there can be any number of parties in the propagation chain. For example, the distributor 230 can be sold directly to the public without the need for the retailer 230. There can also be additional groups, such as user 2 40 can be transmitted to other users. In model 2 0 0, the publisher grants the distributor 2 2 2 the right to use 2 2 2 and allows the dissemination and subsequent rights of the content 214. Meta-rights 214 allow distributors 220 g to give retailers 230 use rights 21 4 ′ (derived from Meta-rights 214), which are used to distribute or possibly sell content and meta-rights 2 1 6. Subsequent rights 2 1 6 allow the retailer 230 to give the user 240 rights to use the content. For example, publisher 2 1 0 may specify through meta rights 2 1 4 that meta rights 2 3 6 are granted to retailers 2 3 6 and retailers 2 30 are allowed to grant only 500 licenses and licenses.
第16頁 1227846 五、發明說明(13) 用權21 6’ ,使得零售商230能給予一使用者只能π觀看"與” 列印一次π的使用權2 1 6 ’ 。換句話說,配銷商2 2 0將後設權 利給予零售商2 3 0。類似地,出版商21 0核發後設權利2 1 4 給配銷商,其將決定配銷商2 2 0能給予零售商2 3 0何種形式 · 與多少數量的權利。注意這些實體可以是部門、單位、或 · · 是較大企業之部分的個人,其也可以具有其他角色。舉例 來說,公司可創造、傳播、與販售内容,以及在公司内使 用不同的員工或不同交易單位完成這樣的活動。後設權利 的原則能應用至一公司,以在公司内決定内容使用。零售 商230能將後設權利218給予使用者240,允許使用者240去$ 分享或給予使用權以達到超級傳播模式。可見在一傳播鏈 中,一團體的後設權利衍生自上游團體所給予的後設權 利0 舉例來說,個人醫療紀錄可以是數位形式,由一如零 售商2 3 0之第一醫院管理。在此局面中,個人如同供應 者,將使用權給予如同消費者的醫院,以進入並更新醫療 紀錄。假設個人在一第二醫院要求治療,並且欲傳送其紀 錄至第二醫院時,個人可給予第一醫院權利,用以透過後 設權利,傳送存取權利至新的醫院。換句話說,個人已經 指定後设權利以及將後設權利給予第一醫院。後設權利允 許如同供應者的第一醫院,將權利給予如同消費者的第二 醫院。另一例子是,個人的遺言與遺囑可以是數位形式, 並且由一如同出版商2 1 0的法律事務所管理。假設個人欲Page 16 1227846 V. Description of the invention (13) The right of use 21 6 'enables the retailer 230 to give a user only π to view " and print π the right to use 2 1 6'. In other words, The distributor 2 2 0 gives the retailer 2 3 0. Similarly, the publisher 21 0 issues the distributor 2 2 4 to the distributor, which will decide that the distributor 2 2 0 can give the retailer 2 30 What form and how many rights. Note that these entities can be departments, units, or individuals who are part of a larger business and can also have other roles. For example, a company can create, disseminate, And selling content, and using different employees or different transaction units in the company to complete such activities. The principle of meta-rights can be applied to a company to determine the use of content within the company. Retailers 230 can post meta-rights 218 Give the user 240, allow the user 240 to share or give the right to use to achieve the super propagation mode. It can be seen that in a communication chain, the post-rights of a group are derived from the post-rights given by the upstream group Personal medical Records can be in digital form and managed by the first hospital like a retailer 230. In this situation, individuals are like suppliers, giving usage rights to hospitals like consumers to access and update medical records. Assume an individual is in When a second hospital requests treatment and wants to transfer its records to the second hospital, the individual can give the first hospital the right to transfer the access right to the new hospital through the post-establishment rights. In other words, after the individual has designated Establishing rights and granting subsequent rights to the first hospital. Subsequent rights allow the first hospital like a supplier to give a second hospital like a consumer. Another example is that personal wills and wills can be in digital form. And is managed by a law firm like the publisher 2 0. Assume personal desire
第17頁 1227846 五、發明說明(14) 允許第三者檢視此遺言時,個人可將後設權利給予法律事 務所’允許法律事務所去將存取權利給予第三者。 執行與行使後設權利的高階過程如同使用權。然而, 使用權與後設權利之間的差異源於行使權利的結果。當行 使使用權時,發生針對内容的行為。舉例來說,使用權係 用以觀看、列印、或複製數位内容。當行使後設權利時, 從後設權利創造出新權利,或是由於行使後設權利的結 果’處置既存權利。新權利的接受者,可以是行使後設權 利的相同主體(同一人、實體、或機器等)。此外,後設權 利的接受者,也可以是一新主體。接受衍生權利的主體, 在接受/儲存衍生權利之前,也許是被認證及授權的。如 此,執行與行使後設權利的機制可以和使用權的機制相 同。舉例來說,使用到美國專利5, 634, 0 1 2中所揭露的機 制。 藉由使用文法或權利語言表現後設權利,包含資料結 構、符號、要素、或多組規則。舉例來說,可使用XrMLTM 權利語言。如圖3所示,許可證5 2的結構能由一或多個給 予(grants) 30 0以及一或多個數位簽名310所組成。每個給 予3 0 〇包含特定被給予後設權利3 0 2,例如提供使用權的權 利、給予使用權、得到使用權、轉讓使用權、交換使用 權、傳送使用權、讓渡使用權、撤銷使用權、再使用使用 權、或是處理後設權利,例如備份權利的權利、恢復權、Page 17 1227846 V. Description of the invention (14) When a third party is allowed to view the last words, the individual may give the subsequent rights to the legal office 'to allow the law firm to grant the access right to the third party. The high-level process of enforcing and exercising subsequent rights is like the right of use. However, the difference between the right of use and the subordinate right stems from the result of exercising the right. Content-specific behavior occurs when usage rights are exercised. For example, usage rights are used to view, print, or copy digital content. When the meta-rights are exercised, new rights are created from the meta-rights or the existing rights are disposed of as a result of exercising the meta-rights. The recipient of the new right can be the same subject (the same person, entity, or machine, etc.) as the post-established right. In addition, the recipient of a post-establishment right can also be a new subject. Subjects receiving derivative rights may be authenticated and authorized before receiving / storing derivative rights. In this way, the mechanism for enforcing and exercising subsequent rights may be the same as the mechanism for using rights. For example, the mechanism disclosed in U.S. Patent No. 5,634,012 is used. Subsequent rights are expressed through the use of grammar or rights language, including data structures, symbols, elements, or sets of rules. For example, XrMLTM rights language can be used. As shown in FIG. 3, the structure of the license 52 can be composed of one or more grants 300 and one or more digital signatures 310. Each grant of 300 includes specific grant rights of 302, such as the right to provide the right to use, to grant the right to use, to obtain the right to use, to transfer the right to use, to exchange the right to use, to transmit the right to use, to transfer the right to use, to revoke Use rights, reuse rights, or post-processing rights, such as the right to back up, the right to restore,
第18頁 1227846 五、發明說明(15) 再核發權利 此類。Page 18 1227846 V. Description of the invention (15) Re-issue rights This category.
或是對後設權利的處理附帶委付權利等諸如 給予3 0 0也能指定一或多個主體304給特定被給予之後 設權利。給予30 0也包含條件306與狀態變數308。如同使 用權,被給予之後設權利的存取與行使,由任何相關的條 件306與狀態變數308所控制。藉由使用數位簽名31〇或其 他認證機制來確保許可證5 2的完整性。簽名3 1 〇能包含一 加密演算、一鑰匙、或以已知方式提供存取内容42的其他 機制。數位簽名3 1 〇的結構包含簽名本身、如何計算密碼 的方法、需要核對密碼的鑰匙資訊、以及核發者證明。 狀態變數追蹤潛在動態狀態條件。狀態變數是一種變 數’其具有代表權利狀態或其他動態條件的數值。基於在 許可1^52中的認證機制,狀態變數可被情報交換機構9〇或 其他裝置追蹤。再者,狀態變數的數值能在一條件中使 用°舉例來說’使用權可以是列印内容42的權利,以及條 件可以是行使三次使用權。每次行使使用權時,狀態變數 的Ϊ值就會遞增。在此例中,當狀態變數的數值為三時, 狀怨不再被滿足,並且不能列印内容4 2。狀態變數的另一 個I列子是時間。許可證5 2的一種條件可以是要求在3 0天中 =印内容42。狀態變數則能用來追蹤30天的期限。再者, =以收集狀態變數來追蹤一權利的狀態。收集使用權的狀 〜的改受代表此權利的使用歷史。Or the processing of subsequent rights can be accompanied by a delegating right, such as giving 3 0 0. One or more subjects 304 can also be assigned to certain given subsequent rights. Giving 300 also includes condition 306 and state variable 308. As with the right of use, the access and exercise of the right after it is granted is controlled by any relevant conditions 306 and state variables 308. The integrity of the license 52 is ensured by using a digital signature 31 or other authentication mechanism. The signature 3 1 0 can include a cryptographic algorithm, a key, or other mechanism that provides access to the content 42 in a known manner. The structure of the digital signature 3 1 0 includes the signature itself, how to calculate the password, key information that needs to be checked against the password, and the issuer's certificate. State variables track potential dynamic state conditions. A state variable is a variable ' that has a value representing the status of a right or other dynamic condition. Based on the authentication mechanism in license 1 ^ 52, state variables can be tracked by the intelligence exchange agency 90 or other devices. Furthermore, the value of the state variable can be used in a condition. For example, the 'use right may be the right to print the content 42, and the condition may be the exercise of the right to use three times. Each time the usage right is exercised, the threshold of the state variable is incremented. In this example, when the value of the state variable is three, the complaint is no longer satisfied, and the content 4 2 cannot be printed. Another I column of state variables is time. A condition of the permit 52 can be a requirement to print the content 42 in 30 days. State variables can be used to track 30-day periods. Furthermore, = track the status of a right by collecting status variables. Collect the status of the right to use ~ The change represents the history of use of this right.
第19頁 1227846 五、發明說明(16) — 圖4疋被澤在XrMLTM中之許可證5 2的一個例子。供應商 給予配銷商一後設權利以核發一使用權(例如放映),將内 容(例如書籍)給予任一終端使用者。有此後設權利,配銷 商可以在美國境内核發一放映書籍的權利,並且受制於一 些配銷商可以強加於使用者的附加條件。只要配銷商每次 付一元給供應商,配銷商就可核發一許可證給終端使用 者。XrMLTM說明書是公開且廣為人知的。 圖5為根據一較佳實施例之許可證伺服器5 〇的原始模 式。許可證翻譯模組502證實並翻譯許可證52,並且具有 功能可詢問許可證的所有範圍,例如後設權利3 〇 2。條件 30 6、狀悲變數308、主體304、以及/或數位簽名310。許 可證處理模組503處理用以儲存許可證52的所有許可證儲 存庫,並且也提供功能,對於衍生權利、驗證許可證、儲 存許可證、取出許可證、以及傳送許可證等創造許可證 52。權利模組504的地位是處理權利與後設權利的狀態與 歷史連同條件之狀態變數的現值與歷史,操控了對於一 已認證主體’允許其以行使所給予的後設權利。條件驗證 者5 0 6驗證關聯後設權利的條件。連同狀態變數,關聯後 没權利之條件定義變數,其數值在後設權利的生命週期中 可以改變。使用於條件中之狀態變數的數值,可在當時, 以及在行使權利期間影響後設權利。Page 19 1227846 V. Description of the Invention (16)-Figure 4 shows an example of the license 5 2 in XrMLTM. The supplier grants distributors a subsequent right to issue a right of use (such as a screening) and gives content (such as a book) to any end user. With the subsequent rights, distributors can issue a right to show a book within the United States, subject to additional conditions that some distributors can impose on users. As long as the distributor pays the supplier one yuan at a time, the distributor can issue a license to the end user. XrMLTM specifications are public and well known. FIG. 5 is an original mode of the license server 50 according to a preferred embodiment. The license translation module 502 verifies and translates the license 52, and has a function to query all the scopes of the license, such as a post-right 302. Condition 30 6. State tragic number 308, subject 304, and / or digital signature 310. The license processing module 503 processes all license repositories for storing licenses 52, and also provides functions for creating licenses 52 for derivative rights, verifying licenses, storing licenses, removing licenses, and transferring licenses. . The status of the rights module 504 is to deal with the status and history of rights and meta-rights together with the present value and history of conditional variables of the conditions, and manipulate the authorized body 'to allow it to exercise the meta-rights granted. The condition verifier 5 0 6 sets the condition of the right after verifying the association. Together with the state variables, the condition-defining variables that have no rights after the association, their values can change during the life cycle of the underlying rights. The value of the state variable used in the condition can affect subsequent rights at the time and during the exercise of the rights.
第20頁 1227846 五、發明說明(17) 授權模組508授權請求,以行使後設權利,以及儲存 最近之被創造的權利,或由於行使後設權利之衍生的權 利。杈權模組5 08存取權利模組5〇4與條件驗證者5〇6的狀 態。授權模組508與許可證處理模組5〇3、狀態變數與條件 列表互動,然後傳遞對權利處理模組5 〇 4之狀態的狀態變 數’以及傳遞對用以授權之條件驗證者5〇6的條件列表。 用以行使後δ又權利之請求被傳遞至後設權利處理模組 510。假設已認證請求裝置,後設權利處理模組510請求許 y也處理模組5 〇 4去驗證用以行使被請求後設權利的許可 證。許可證處理模組5〇4驗證許可證的數位簽名與簽名者 的鑰t如果簽名者的鑰匙是可靠的,並且驗證了數位簽 名二稍後許可證處理模組5〇4會回覆"驗證”給後設權利處 理模組5 1 0。否則是擲回”不被驗證”。 ,權模組508指示許可證處理模組5〇3去取得許可證52 ^狀恶變數308與條件306。稍後授權模組5〇8決定強制執 二斗可證52所需之狀態變數。權利處理模組5〇4稍後提供 母個所需之狀態變數的現值給授權模組508。稍後授權模 ^08傳遞條件306與所需之狀態變數給條件驗證者506。 ^ ί足所有的條件306,授權模組508回覆,,授權,,給後設 榷利處理模組51〇。 後认權利處理模組5丨〇驗證於其中的許可證Η及後設Page 20 1227846 V. Description of the invention (17) Authorization module 508 authorizes the request to exercise the subsequent rights, and to store the recently created rights, or the rights derived from the exercise of the subsequent rights. The power module 5 08 accesses the status of the power module 504 and the condition verifier 506. The authorization module 508 interacts with the license processing module 503, the status variables and the condition list, and then passes the status variables of the status of the rights processing module 504 'and the condition verifier 506 for authorization List of conditions. The request for exercising the post-δ rights is passed to the post-right processing module 510. Assuming that the requesting device has been authenticated, the post-rights processing module 510 requests Xu to also process module 504 to verify the license used to exercise the requested post-rights. The license processing module 504 verifies the digital signature of the license and the signer's key. If the signer's key is reliable and the digital signature is verified, the license processing module 504 will reply later. Set the right processing module 5 1 0. Otherwise, it will be thrown back "not verified". The right module 508 instructs the license processing module 503 to obtain the license 52 ^ evil variables 308 and conditions 306. Later, the authorization module 508 decides the state variables required to enforce the enforcement of the second leg license 52. The rights processing module 504 provides the present value of the required state variables to the authorization module 508 later. Later The authorization module ^ 08 passes the condition 306 and the required state variables to the condition verifier 506. ^ Enabling all the conditions 306, the authorization module 508 responds, authorizes, and assigns a post-mortem processing module 51. Entitlement processing module 5 丨 〇 Licenses and subsequent verifications
1227846 五、發明說明(18) 杻利3 02,用以授權行使後設權利3〇2的請求 另一方面,權利處理模組5 1 2,處理被創造的新權利,以 及由於行使後設權利所得之被衍生權利。權利處理模組 512利 '授權模組5〇8,以驗證被創造的新權利或被衍生權 利的接受者係預期之主體3〇4。假使接受者已被授權,稍 後權利處理模組512指示許可證處理模組5〇4,在關聯消費 者的一儲存庫中,儲存被創造的新權利。更進一步的P討論 參照圖7。 〇 i述之授權過程並未限定是依序的或是階段性的。舉 例來說,可編程一系統,在數位簽名驗證之前,允許授權 模組508請求來自許可證處理模組5〇4的狀態條件。在^種 例子中,可能會在一已驗證之許可證的受限下進行。再 者,若干模組未必要駐在許可證伺服器或相關裝置中。透 過硬體與/或系統之部分軟體,可以任何方式結合或分 離,使得模組作用。 —一旦已經授權行使後設權利的請求,則後設權利能被 行使。後設權利處理模組5 1 〇通知權利處理模組5 〇 4去開始 行使所請求的後設權利。稍後權利處理模組5 〇 4紀錄使用 歷史,並更改狀悲變數的現值。後設權利處理模組51 〇係 以類似於行使使用權的程序,行使後設權利。如果取得新 權利,稍後後設權利處理模組5 1〇喚起許可證處理模組5〇4 ! 第22頁 1227846 五、發明說明(19) -- 去創造由於行使後設權利所得之新權利。每個新權利稱後 送至對應的消費者的權利處理模組512,並且儲存於關聯 消費者的一儲存庫中。在接受與儲存最近創造的權利之y 前’消費者的權利處理模組5 1 2將認證與授權消費者。根 據一組規則或其他邏輯,從後設權利取得新權利。舉例來 說,一規則能規定,去提供使用的許可證之一被消費的權 利’將造成具有權利的消費者去提供一使用權,以及將此 使用權的一許可證給予另一消費者。1227846 V. Description of the invention (18) 杻 利 3 02, which is used to authorize the request for the exercise of the post-rights 3 02. On the other hand, the rights processing module 5 1 2 deals with the new rights created and the post-rights The resulting derived rights. The rights processing module 512 benefits the authorization module 508 to verify that the recipient of the new rights created or the rights derived is the intended subject 304. If the recipient has been authorized, later the rights processing module 512 instructs the license processing module 504 to store the created new rights in a repository of the associated consumer. Further discussion of P Refer to FIG. 7. 〇 The authorization process described above is not limited to sequential or phased. For example, a system can be programmed to allow the authorization module 508 to request status conditions from the license processing module 504 before digital signature verification. In some cases, this may be done under the restriction of a validated license. Furthermore, several modules do not need to reside in the license server or related devices. Through the hardware and / or part of the software, the module can be combined or separated in any way. -Once a request for a subordinate right has been authorized, the subordinate right can be exercised. The post-rights processing module 5 1 0 notifies the right-handling module 5 04 to start exercising the requested post-rights. Later, the rights processing module 504 records the usage history and changes the present value of the tragic state. The post-rights processing module 51 〇 implements the post-rights in a procedure similar to the exercise of the right to use. If a new right is obtained, the right processing module 5 will be set up later. 10 The license processing module 504 will be called up! Page 22 1227846 V. Description of the invention (19)-to create a new right obtained by exercising the post-set rights . Each new entitlement is sent to the entitlement processing module 512 of the corresponding consumer and stored in a repository of the associated consumer. Before accepting and storing the recently created rights, the consumer's rights processing module 5 1 2 will authenticate and authorize the consumer. New rights are derived from the underlying rights based on a set of rules or other logic. For example, a rule can provide that the right to consume one of the licenses for use 'will cause a consumer with rights to provide a right to use and a license to this right to another consumer.
圖7為根據一較佳實施例之一過程的流程圖,用以移 轉後设權利以及從後設權利取得新權利。位於圖7左半側 的所有步驟關係到權利的供應者,位於右半側的 關係到權利的消費者。在步驟7 〇 2,在一已知方的式斤二 二: 許可證5 2的主體3 0 4。換句話說,決定是否行使後設權利 302的團體有適宜的許可證可這樣做。假如主體未被認 證’程序於步驟704終止。假如主體已被認證,程序前進 至步驟7 0 6,在其中行使後設權利3 〇 2,並以具有上述方式 之被衍生權利的許可證52的形式,傳送至消費者處。在步 驟7 〇 8,主體已被認證。換句話說,決定是否行使被衍生 權利的團體有適宜的許可證可這樣做。假如主體未被認 證’程序於步驟7 1 〇終止。假如主體已被認證,程序前進 至步驟7 1 2,在其中儲存被衍生權利。對於在許可證中的 每個附加權利,程序稍後回到步驟7〇8,當所有權利處理 過後,程序於步驟714終止。Fig. 7 is a flowchart of a process according to a preferred embodiment for transferring and acquiring new rights from the latter. All steps on the left side of Figure 7 are related to the supplier of rights, and on the right side are the consumers of rights. At step 702, the weight of a known party is two: the subject of permit 5 2 3 0 4. In other words, the group that decides whether to exercise the subordinate right 302 has the appropriate license to do so. If the subject is not authenticated 'the procedure terminates at step 704. If the subject has been authenticated, the process proceeds to step 706 where the exercised right is set to 302 and transmitted to the consumer in the form of a license 52 with derivative rights in the manner described above. In step 708, the subject has been authenticated. In other words, the group that decides whether to exercise the derived right has the appropriate license to do so. If the subject is not certified, the procedure is terminated at step 7 10. If the subject has been authenticated, the process proceeds to step 7 12 where the derived rights are stored. For each additional right in the license, the program later returns to step 708, and when all rights have been processed, the program terminates at step 714.
第23頁 1227846 五、發明說明(20) 杈佳實施例並未被在何處利用轉售者、配銷商、或其 他中間商所受限。舉例來說,可在企業或其他組織中應用 此較佳實施例,其創造與/或傳播數位内容或其他項目, 以在企業或其他組織中控制内容的使用。當一權利的給予 關係到另一權利時,也可將後設權利核發給終端使用者。 舉例來說,在交易選項與期貨交易的條件下,去買得或販 售澄券(securities)的權利。後設權利能被指派或關聯產 品服務、來源、或其他項目。 本發明 統。較佳實 在單一電腦 (dumb term 等,或透過 模Μ已被分 士應有的認 精神及範疇 替換。較佳 存在。各種 用網際網路 媒體中傳送 置可以包含 等。 藉由各種型態的裝置完成,例如電腦或電腦系 施例是在一主從環境中完成。然而,本發明可 或其他裝置中完成。在一使用無智型終端機 lnal)、精簡型客戶端(thin client)或其他等 任何配置之裝置的網路上。較佳實施例的各種 離與以功旎清楚描述。然而,習知此領域的人 知,若干一般的替換無疑地亦不脫離本發明的 。例如,各種軟硬體可以以其他可選用的方式 =分離的實體’可以以明確的個體 通、道此在本發明中使用。舉例來說,可使 或其他網路。於裝置之間,資料也可 ’例如CD、DVD、±隹疊記憶體等諸 移。動式 個人電腦、工作站、精簡型客戶端、pda^Page 23 1227846 V. Description of the Invention (20) The preferred embodiment is not restricted by where to use resellers, distributors, or other intermediaries. For example, this preferred embodiment may be applied in a business or other organization that creates and / or disseminates digital content or other items to control the use of content in the business or other organization. When the grant of one right is related to another right, subsequent rights can also be issued to the end user. For example, under the conditions of trading options and futures trading, the right to buy or sell securities. Subsequent rights can be assigned or linked to products, services, sources, or other items. This invention is uniform. It is better to be in a single computer (dumb term, etc., or has been replaced by the recognition spirit and scope of the division. It is better to exist. Various transmission devices can be included in the Internet media. By various types of Device completion, such as a computer or computer system, is implemented in a master-slave environment. However, the present invention can be performed in other devices. In a smart terminal, thin client, or thin client, On any other configured device. The various functions and functions of the preferred embodiment are clearly described. However, as is known in the art, several general substitutions undoubtedly do not depart from the present invention. For example, various hardware and software can be used in other alternative ways = separate entities' can be used in the present invention as a clear individual. For example, you can make or other networks. Data can also be moved from device to device such as CD, DVD, ± stacked memory, and so on. Mobile PC, Workstation, Thin Client, pda ^
1227846 五、發明說明(21) 本發明藉由參考不同的實施例描述如上,然而,若干 一般的替換無疑地亦不脫離本發明的精神及範疇。即大凡 依本發明所揭示之精神所作之均等變化或修飾,仍應涵蓋 在本發明之專利範圍内。 參1227846 V. Description of the invention (21) The present invention is described above by referring to different embodiments. However, some general substitutions undoubtedly do not depart from the spirit and scope of the present invention. That is to say, all equal changes or modifications made according to the spirit disclosed by the present invention should still be covered by the patent scope of the present invention. Participate
第25頁 1227846 圖式簡單說明 五、【圖式簡單說明】 本發明將透過一較佳實施例,並配合所附圖示加以說 明: 圖1為根據本發明實施例之一權利管理系統的示意說 明。 圖2為一舉例傳播鏈之方塊示意圖,顯示從後設權利 取得權利。 圖3為根據一較佳實施例之許可證的示意說明。 圖4為根據一較佳實施例之一基於XML的權利語言表示 的許可證例子。 圖5為圖1系統之許可證伺服器的方塊示意圖。 圖6為根據一較佳實施例之一權利標記的方塊示意 圖。 圖7為根據一較佳實施例之一移轉與取得權利過程的 流程圖。 圖式元件符號說明 10 數位權利管理系統 20 啟動伺服器 30 客戶環境 40 權利標記 42 内容 44 提供者 44a 使用權 44b 情況 44c 内容說明 50 許可證伺服器 52 許可證 60 客戶要件 70 電腦 72 文件準備應用Page 27 1227846 Brief description of the drawings V. [Simplified description of the drawings] The present invention will be described through a preferred embodiment and the accompanying drawings: FIG. 1 is a schematic diagram of a rights management system according to an embodiment of the present invention Instructions. Fig. 2 is a block diagram of an example propagation chain, showing that rights are obtained from meta-rights. FIG. 3 is a schematic illustration of a license according to a preferred embodiment. Figure 4 is an example of a license expressed in an XML-based rights language according to one of the preferred embodiments. FIG. 5 is a block diagram of the license server of the system of FIG. 1. Figure 6 is a schematic block diagram of a rights label according to a preferred embodiment. FIG. 7 is a flowchart of a process of transferring and acquiring rights according to a preferred embodiment. Graphical component symbol description 10 Digital rights management system 20 Start server 30 Customer environment 40 Rights mark 42 Content 44 Provider 44a Use right 44b Situation 44c Content description 50 License server 52 License 60 Customer requirements 70 Computer 72 Document preparation application
第26頁 1227846 圖式簡單說明 80 網頁伺服器 2 0 0模式 2 1 2使用權 214’使用權 2 1 6 ’使用權 2 2 0 配銷商 240使用者 3 0 2 後設權利 3 0 6 條件 310簽名 5 0 3 許可證處理模組 5 0 6 條件驗證者 5 1 0 後設權利處理模組 90 情報交換機構 2 1 0 出版商 2 1 4 後設權利 2 1 6 後設權利 2 1 8 後設權利 230 零售商 3 0 0 給予 304 主體 3 0 8 狀態變數 5 0 2 許可證翻譯模組 504 權利模組 5 0 8 授權模組 5 1 2 權利處理模組 〇 〇Page 26 1227846 Schematic description 80 Web server 2 0 0 Mode 2 1 2 Right to use 214 'Right to use 2 1 6' Right to use 2 2 0 Distributor 240 users 3 0 2 Post-rights 3 0 6 Conditions 310 signature 5 0 3 license processing module 5 0 6 condition verifier 5 1 0 post-rights processing module 90 information exchange agency 2 1 0 publisher 2 1 4 post-rights 2 1 6 post-rights 2 1 8 post Set rights 230 Retailer 3 0 0 Give 304 Subject 3 0 8 State variable 5 0 2 License translation module 504 Rights module 5 0 8 Authorization module 5 1 2 Rights processing module 〇〇
第27頁Page 27
Claims (1)
Applications Claiming Priority (4)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US33162101P | 2001-11-20 | 2001-11-20 | |
US33162501P | 2001-11-20 | 2001-11-20 | |
US33162401P | 2001-11-20 | 2001-11-20 | |
US10/162,701 US20030140003A1 (en) | 2001-06-07 | 2002-06-06 | Method and apparatus managing the transfer of rights |
Publications (1)
Publication Number | Publication Date |
---|---|
TWI227846B true TWI227846B (en) | 2005-02-11 |
Family
ID=35667160
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
TW91124583A TWI227846B (en) | 2001-11-20 | 2002-10-23 | Method and apparatus managing the transfer of rights |
Country Status (2)
Country | Link |
---|---|
AR (1) | AR037569A1 (en) |
TW (1) | TWI227846B (en) |
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
TWI427501B (en) * | 2006-09-12 | 2014-02-21 | Ibm | System and method for digital content player with secure processing vault |
-
2002
- 2002-10-23 TW TW91124583A patent/TWI227846B/en not_active IP Right Cessation
- 2002-11-20 AR ARP020104456 patent/AR037569A1/en not_active Application Discontinuation
Cited By (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
TWI427501B (en) * | 2006-09-12 | 2014-02-21 | Ibm | System and method for digital content player with secure processing vault |
Also Published As
Publication number | Publication date |
---|---|
AR037569A1 (en) | 2004-11-17 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
AU2002312351B2 (en) | Method and apparatus managing the transfer of rights | |
US8078542B2 (en) | System and method for managing transfer of rights using shared state variables | |
US8001053B2 (en) | System and method for rights offering and granting using shared state variables | |
Bonatti et al. | A uniform framework for regulating service access and information release on the web | |
RU2348073C2 (en) | Digital rights management (drm) server registration/subregistration in drm architecture | |
EP1465040B1 (en) | Issuing a publisher use licence off-line in a digital rights management (DRM) System | |
US7774279B2 (en) | Rights offering and granting | |
KR100755631B1 (en) | System and method for specifying and processing legality expressions | |
US7386513B2 (en) | Networked services licensing system and method | |
KR100621747B1 (en) | Method and System for Subscription Digital Rights Management | |
AU2002312351A1 (en) | Method and apparatus managing the transfer of rights | |
JP2004046833A (en) | Publishing of contents related to digital copyright management (drm) system | |
JP2004062890A (en) | System and method of offering digital rights management service | |
Michiels et al. | Towards a software architecture for DRM | |
KR20200099041A (en) | Apparatus and method for managing content access rights based on blockchain | |
KR20070061605A (en) | The p2p system which can prevent the transmission and reproduction of the illegal contents and support the legal network marketing of the contents | |
AU2003219907B2 (en) | Networked services licensing system and method | |
Fan et al. | A new usage control protocol for data protection of cloud environment | |
TWI227846B (en) | Method and apparatus managing the transfer of rights | |
Chhabra et al. | Blockchain, AI, and Data Protection in Healthcare: A Comparative Analysis of Two Blockchain Data Marketplaces in Relation to Fair Data Processing and the ‘Data Double-Spending’Problem | |
WO2006041462A2 (en) | System and method for rights offering and granting using shared state variables | |
KR20030096255A (en) | Rights offering and granting | |
JP4932058B2 (en) | Method and apparatus for transferring rights associated with content | |
JP4898966B2 (en) | Method for offering and granting rights using shared state variables | |
Arnab et al. | Specifications for a Componetised Digital Rights Management (DRM) Framework |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
MK4A | Expiration of patent term of an invention patent |