WO2010081267A1 - E-book for protecting copyright - Google Patents

E-book for protecting copyright Download PDF

Info

Publication number
WO2010081267A1
WO2010081267A1 PCT/CN2009/000655 CN2009000655W WO2010081267A1 WO 2010081267 A1 WO2010081267 A1 WO 2010081267A1 CN 2009000655 W CN2009000655 W CN 2009000655W WO 2010081267 A1 WO2010081267 A1 WO 2010081267A1
Authority
WO
WIPO (PCT)
Prior art keywords
book
dynamic password
module
electronic
server
Prior art date
Application number
PCT/CN2009/000655
Other languages
French (fr)
Chinese (zh)
Inventor
严正华
赵海萍
Original Assignee
盛大计算机(上海)有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 盛大计算机(上海)有限公司 filed Critical 盛大计算机(上海)有限公司
Publication of WO2010081267A1 publication Critical patent/WO2010081267A1/en

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/10Protecting distributed programs or content, e.g. vending or licensing of copyrighted material ; Digital rights management [DRM]

Landscapes

  • Engineering & Computer Science (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Multimedia (AREA)
  • Technology Law (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Storage Device Security (AREA)

Abstract

An e-book for protecting copyright, the e-book is an electric data reading apparatus, which includes a processor, an internal memory module, and a memory module, display screen, network connecting module, a bus and a dynamic code generating module. The dynamic code generating module has a serial number and a dynamic code generating algorithm set inside it, and the dynamic code generating algorithm is a computing rule between the input and the output of the dynamic code generating module. The different dynamic code generating module has a different serial number, but has the same dynamic code generating algorithm. The input of the different dynamic code generating module at least includes the serial number of the dynamic code generating module.

Description

保护版权的电子书  Copyright protection e-book
技术领域 Technical field
本发明涉及一种电子资料阅读装置,特别是涉及一种能够实现版权保 护的电子资料阅读装置。  The present invention relates to an electronic material reading apparatus, and more particularly to an electronic material reading apparatus capable of realizing copyright protection.
背景技术 Background technique
随着网络及电子产品的发展,传统纸质书本的阅读方式已不能满足 e 时代人们的需求。 电子书(电子资料阅读装置) 以其小巧、 便于携带、 存 储量大、存储和删除快捷方便、可以根据需求添加或删除电子资料的特点, 而越来越受到年轻人的青睐。 电子书已日益成为纸质书籍的替代品。  With the development of networks and electronic products, the way traditional paper books are read can no longer meet the needs of people in the e-age. E-books (electronic data reading devices) are increasingly favored by young people because of their small size, portability, large storage capacity, fast and convenient storage and deletion, and the ability to add or delete electronic materials according to their needs. E-books have increasingly become an alternative to paper books.
当前市场上的电子书, 多为可以直接连接网络下载电子资料的方式。 网络上的电子资料只要满足电子书的阅读格式要求,就可以进行下载和阅 读, 这给电子资料的版权保护带来很多问题。  The current e-books on the market are mostly ways to directly connect to the Internet to download electronic materials. The electronic data on the network can be downloaded and read as long as it meets the reading format requirements of the e-book, which brings many problems to the copyright protection of electronic materials.
中国发明专利说明书 CN1231852C (公告日: 2005年 12月 14日) 公 开了一种带 SIM卡的电子书。该电子书包括 SIM卡插座和 SIM卡,其中的 SIM卡包括 ID信息和部分操作系统信息。 使用时, 只有 SIM卡在 SIM卡 插座上, SIM卡中的部分操作系统与电子书中的部分操作系统才能结合形 成完整的操作系统, SIM卡中的 ID信息用于解密电子资料的内容。 该方 案可以实现电子资料的版权保护,但在操作系统的设计上比较烦琐。同时 若 ID信息被盗取, 则电子资料的加密很容易被破解。  Chinese invention patent specification CN1231852C (Announcement Date: December 14, 2005) An electronic book with a SIM card is opened. The e-book includes a SIM card socket and a SIM card, wherein the SIM card includes ID information and part of operating system information. In use, only the SIM card is on the SIM card socket, part of the operating system in the SIM card and some operating systems in the e-book can be combined to form a complete operating system, and the ID information in the SIM card is used to decrypt the content of the electronic data. This scheme can realize the copyright protection of electronic materials, but it is cumbersome in the design of the operating system. At the same time, if the ID information is stolen, the encryption of the electronic data can be easily cracked.
中国发明专利说明书 CN1200355C (公告日: 2005年 5月 4日) 公开 了一种电子书的加密方法。该电子书的密钥包括固定部分和随机部分。随 机部分的密钥在电子资料文件的某一位置,该位置信息在电子资料文件的 头信息之中确定。使用时,只有将密钥的固定部分和随机部分结合形成完 整密钥,才能对电子资料进行解密和阅读。该方案也可以实现电子资料的 版权保护,但仅在电子资料的阅读时进行解密验证,在电子资料的下载时 不进行解密验证。这便使得电子资料文件的传输过程中存在密码的随机部 分被破解的可能性。 而一旦密码的随机部分被破解, 整个密码就暴露了, 因此该方案仍不具有较高的可靠性、 安全性。 发明内容 China Invention Patent Specification CN1200355C (Announcement Date: May 4, 2005) Public An encryption method for an e-book. The key of the e-book includes a fixed portion and a random portion. The key of the random part is at a certain position of the electronic data file, and the location information is determined in the header information of the electronic data file. When used, the electronic data can be decrypted and read only by combining the fixed part and the random part of the key to form a complete key. The scheme can also realize the copyright protection of electronic materials, but only decrypts the electronic data when it is read, and does not perform decryption verification when the electronic data is downloaded. This makes it possible for the random portion of the password to be cracked during the transmission of the electronic data file. Once the random part of the password is cracked, the entire password is exposed, so the solution still does not have high reliability and security. Summary of the invention
本发明所要解决的技术问题是提供一种保护版权的电子书,可以对电 子资料的版权进行有效保护。  The technical problem to be solved by the present invention is to provide an electronic book for protecting copyright, which can effectively protect the copyright of electronic materials.
为解决上述技术问题, 本发明保护版权的电子书为电子资料阅读装 置, 包括处理器、 内存模块、 存储模块、 显示屏、 网络连接模块和总线, 所述电子书还包括动态密码生成模块,所述动态密码生成模块具有序列号 并内置动态密码生成算法,所述动态密码生成算法为动态密码生成模块的 输入与输出之间的计算规则。  In order to solve the above technical problem, the copyright protected electronic book is an electronic data reading device, which comprises a processor, a memory module, a storage module, a display screen, a network connection module and a bus, and the electronic book further comprises a dynamic password generating module. The dynamic password generating module has a serial number and a built-in dynamic password generating algorithm, and the dynamic password generating algorithm is a calculation rule between input and output of the dynamic password generating module.
本发明可以在电子资料的下载过程中进行动态密码验证,访问过程中 进行两次解密, 从而有效地保证电子书用户的身份唯一, 且不易被破解, 最终实现了对电子资料的版权保护。 附图说明 图 1是本发明保护版权的电子书的硬件模块示意图; The invention can perform dynamic password verification in the process of downloading electronic materials, and decrypts twice during the access process, thereby effectively ensuring that the identity of the e-book user is unique and difficult to be cracked, and finally realizes copyright protection of the electronic material. DRAWINGS 1 is a schematic diagram of a hardware module of an electronic book for protecting copyrights according to the present invention;
图 2是本发明保护版权的电子书向服务器注册的流程图;  2 is a flow chart of registering a copyright protected e-book to a server according to the present invention;
图 3是本发明保护版权的电子书从服务器下载电子资料的流程图; 图 4是本发明保护版权的电子书访问电子资料的流程图。  3 is a flow chart of downloading electronic materials from a server for protecting copyrighted electronic books according to the present invention; and FIG. 4 is a flow chart of accessing electronic materials of copyright protected electronic books according to the present invention.
图中附图标记为: 1-处理器; 2-内存模块; 3-存储模块; 4-显示器; 5-网络连接模块; 6-动态密码生成模块; 7-总线。  The reference numerals in the figure are: 1-processor; 2-memory module; 3-memory module; 4-display; 5-network connection module; 6-dynamic password generation module;
本发明的实施方式 Embodiments of the invention
下面结合附图及具体实施方式对本发明作进一步详细说明。  The present invention will be further described in detail below in conjunction with the drawings and specific embodiments.
请参阅图 1, 本发明电子书为电子资料阅读装置, 包括:  Please refer to FIG. 1. The electronic book of the present invention is an electronic data reading device, including:
-处理器 1, 可采用微处理器、 单片机、 PLC等, 用于管理和控制所述 电子书的所有硬件模块和软件系统。  - Processor 1, which can be used to manage and control all hardware modules and software systems of the e-book, such as a microprocessor, a single chip microcomputer, a PLC, or the like.
-内存模块 2, 可采用 SRAM、 ROM等。 内存模块 2中的数据通常在断 电后消失, 但也可以在断电后仍保留。在内存模块 2中, 不同进程之间无 法访问其他进程的内存, 因此可以认为正在使用的内存是安全可靠的。  - Memory module 2, SRAM, ROM, etc. can be used. The data in memory module 2 usually disappears after a power failure, but it can also be retained after a power failure. In memory module 2, the memory of other processes cannot be accessed between different processes, so the memory being used can be considered safe and reliable.
-存储模块 3, 可采用 SD卡、 Flash等。 存储模块 3中的数据在断电 后仍保留。存储模块 3包括允许用户访问的公共存储区和禁止用户访问的 限制存储区, 公共存储区和限制存储区的划分可由所述电子书的固件实 现, 或者由所述电子书的软件系统实现。所述限制存储区是指, 电子书的 固件或软件系统既不向用户提供按文件 /文件夹访问的手段, 也不向用户 提供免密码的登录 /调试手段。  - Memory module 3, SD card, Flash, etc. can be used. The data in enclosure 3 remains after power down. The storage module 3 includes a common storage area that allows the user to access and a restricted storage area that prohibits user access, and the division of the common storage area and the restricted storage area can be implemented by the firmware of the electronic book or by the software system of the electronic book. The restricted storage area means that the firmware or software system of the e-book neither provides a means for accessing the file/folder to the user, nor provides the user with a password-free login/debug means.
-显示屏 4, 可采用 "电子纸"。 所述 "电子纸"是指轻薄的、 具备记 忆功能 (即在断电后仍能保持原显示内容)、 采用反射式显示方式的显示 系统。 所述 "电子纸"技术包括双稳态向列液晶显示技术 (Bi TNLCD)、 胆固醇液晶显示技术(Ch-LCD)、 电子粉流体显示技术(QR-LPD)和 /或电 泳显示技术 (EPD)。 - Display 4, "electronic paper" can be used. The "electronic paper" refers to a thin and light, with a record Recalling the function (that is, the original display content can be maintained after the power is turned off), and the display system adopting the reflective display mode. The "electronic paper" technology includes bistable nematic liquid crystal display technology (Bi TNLCD), cholesteric liquid crystal display technology (Ch-LCD), electronic powder fluid display technology (QR-LPD), and/or electrophoretic display technology (EPD). .
-网络连接模块 5, 使所述电子书与外界的有线或无线网络相连接, 并进行数据的双向传输。  - a network connection module 5, connecting the e-book to an external wired or wireless network, and performing bidirectional transmission of data.
-动态密码生成模块 6, 具有序列号并内置动态密码生成算法, 所述 动态密码生成算法为动态密码生成模块的输入与输出之间的计算规则。不 同的动态密码生成模块具有不同的序列号,但具有相同的动态密码生成算 法。动态密码生成模块的输入至少包括该动态密码生成模块的序列号和服 务器发给所述电子书的挑战码。  - Dynamic password generation module 6, having a serial number and a built-in dynamic password generation algorithm, the dynamic password generation algorithm being a calculation rule between the input and output of the dynamic password generation module. Different dynamic password generation modules have different serial numbers but have the same dynamic password generation algorithm. The input of the dynamic password generating module includes at least the serial number of the dynamic password generating module and the challenge code sent by the server to the e-book.
-总线 7,所述电子书的各硬件模块均连接到总线 7,任意硬件模块之 间的数据通讯都通过总线 7进行。  - Bus 7, each hardware module of the e-book is connected to the bus 7, and data communication between any hardware modules is performed via the bus 7.
所述电子书还可以包括输入模块,供用户操作电子书及其中的电子资 料。输入模块可以是按钮、 键盘, 也可以是触摸屏(此时触摸屏既是显示 屏, 也是输入模块)。  The e-book can also include an input module for the user to operate the e-book and the electronic information therein. The input module can be a button, a keyboard, or a touch screen (the touch screen is both a display screen and an input module).
所述电子书还包括有软件系统,例如可采用类 Linux的嵌入式操作系 统, 该软件系统负责电子书各方面使用、 操作。  The e-book also includes a software system, for example, an embedded operating system like Linux, which is responsible for all aspects of the use and operation of the e-book.
所述电子书的使用包括如下三方面:一是电子书向服务器注册,二是 电子书从服务器下载电子资料, 三是电子书访问已下载的电子资料。  The use of the e-book includes the following three aspects: one is that the e-book is registered with the server, the other is that the e-book downloads the electronic material from the server, and the third is that the e-book accesses the downloaded electronic material.
所述服务器内置或连接数据库,所述数据库包括多个电子资料,所述 电子资料包括电子形式的书籍、 图片、 动画、 音频和 /或视频, 每个电子 资料具有各不相同的编号。所述数据库还包括所有动态密码生成模块的序 列号。所述服务器中具有所述动态密码生成算法和至少一种非对称加密算 法。 The server includes or connects to a database, the database including a plurality of electronic materials, including electronic books, pictures, animations, audio, and/or video, each electronic The data has different numbers. The database also includes the serial number of all dynamic password generation modules. The server has the dynamic password generation algorithm and at least one asymmetric encryption algorithm.
所述电子书只有在服务器注册之后,才能从服务器下载电子资料。所 述电子书只有从服务器下载电子资料之后,才能在电子书本地访问己下载 的电子资料。  The e-book can download electronic materials from the server only after the server registers. The e-book can access the downloaded electronic material locally in the e-book only after downloading the electronic material from the server.
请参阅图 2, 所述电子书在服务器注册包括如下步骤- 第 1步, 电子书向服务器发出注册请求,所述注册请求中包括该电子 书的动态密码生成模块的序列号。 所述序列号为一串数字的组合。 例如, 该序列号可采用 9位十进制数。  Referring to FIG. 2, the e-book registration in the server includes the following steps: Step 1: The e-book issues a registration request to the server, where the registration request includes a serial number of the dynamic password generation module of the e-book. The serial number is a combination of a series of numbers. For example, the serial number can take a 9-digit decimal number.
第 2步,服务器接收所述注册请求,并在所述数据库中査询所述注册 请求中的序列号。  In the second step, the server receives the registration request and queries the database for the serial number in the registration request.
如数据库中有该序列号,服务器随机产生一挑战码,并向该电子书发 送该挑战码。  If the serial number is in the database, the server randomly generates a challenge code and sends the challenge code to the e-book.
所述挑战码是服务器随机生成的一串数字、 字母和 /或符号的组合。 例如, 挑战码可采用 64位的二进制数。  The challenge code is a combination of a string of numbers, letters, and/or symbols randomly generated by the server. For example, the challenge code can use a 64-bit binary number.
如数据库中无该序列号, 服务器停止操作。  If the serial number is not available in the database, the server stops operating.
第 3步,该电子书接收该挑战码,该电子书的动态密码生成模块将该 挑战码和 /或该动态密码生成模块的序列号作为输入经计算后输出密码, 该电子书向服务器发送该密码。  In step 3, the e-book receives the challenge code, and the dynamic password generation module of the e-book takes the challenge code and/or the serial number of the dynamic password generation module as an input, and outputs the password, and the e-book sends the password to the server. password.
所述密码是动态密码生成模块计算生成的一串数字的组合。例如,密 码可采用 64位的二进制数。 不同的动态密码生成模块的序列号不同,而序列号是动态密码生成算 法的输入项之一,因此不同的动态密码生成模块经计算输出的密码总是不 同的。对同一个动态密码生成模块而言, 由于服务器产生的挑战码是随机 的,而挑战码也是动态密码生成算法的输入项之一, 因此同一个动态密码 生成模块经计算输出的密码也总是不同的。 The password is a combination of a series of numbers calculated by the dynamic password generation module. For example, the password can use a 64-bit binary number. Different dynamic password generation modules have different serial numbers, and the serial number is one of the input items of the dynamic password generation algorithm. Therefore, the passwords calculated by different dynamic password generation modules are always different. For the same dynamic password generation module, since the challenge code generated by the server is random, and the challenge code is also one of the inputs of the dynamic password generation algorithm, the password generated by the same dynamic password generation module is always different. of.
第 4步,服务器接收该密码,并与服务器自身根据所述动态密码生成 算法将所述挑战码和 /或序列号作为输入进行计算的结果相比较。  In step 4, the server receives the password and compares it with the results of the server itself calculating the challenge code and/or serial number as input based on the dynamic password generation algorithm.
如该密码和服务器的计算结果相同,服务器采用非对称加密算法生成 一对非对称密钥,所述非对称密钥包括一个私钥和一个公钥。服务器将私 钥存储于所述数据库, 将公钥发给该电子书。  If the password and the server are the same, the server generates a pair of asymmetric keys using an asymmetric encryption algorithm, and the asymmetric key includes a private key and a public key. The server stores the private key in the database and sends the public key to the e-book.
如该密码和服务器的计算结果不同, 服务器停止操作。  If the password and server result are different, the server stops operating.
第 5步, 该电子书接收所述公钥, 并将所述公钥存储在限制存储区。 上述电子书在服务器注册的过程中, 具体可采用如下方式: 一、 电子 书通过 https协议连接服务器,并与服务器进行通讯。二、所述注册请求、 挑战码、密码、 公钥均以 XML格式在电子书和服务器之间传输。三、 所述 非对称加密算法采用 RSA算法。  In step 5, the e-book receives the public key and stores the public key in a restricted storage area. In the process of registering the above e-book, the following methods can be used: 1. The e-book connects to the server through the https protocol and communicates with the server. 2. The registration request, challenge code, password, and public key are transmitted in an XML format between the e-book and the server. 3. The asymmetric encryption algorithm uses an RSA algorithm.
请参阅图 3, 所述电子书从服务器下载电子资料包括如下步骤: 第 1步, 电子书向服务器发出下载请求,所述下载请求中包括该电子 书的动态密码生成模块的序列号。  Referring to FIG. 3, the downloading the electronic data from the server by the electronic book includes the following steps: Step 1: The electronic book sends a download request to the server, where the download request includes a serial number of the dynamic password generating module of the electronic book.
第 2步,服务器接收所述下载请求,并在所述数据库中查询所述下载 请求中的序列号。  In the second step, the server receives the download request and queries the database for the serial number in the download request.
如数据库中有该序列号,服务器随机产生一挑战码,并向该电子书发 送该挑战码。 If the serial number is in the database, the server randomly generates a challenge code and sends the challenge code to the e-book. Send the challenge code.
如数据库中无该序列号, 服务器停止操作。  If the serial number is not available in the database, the server stops operating.
第 3步,该电子书接收该挑战码,该电子书的动态密码生成模块将该 挑战码和 /或该动态密码生成模块的序列号作为输入经计算后输出密码, 该电子书向服务器发送该密码和请求下载的电子资料的编号。  In step 3, the e-book receives the challenge code, and the dynamic password generation module of the e-book takes the challenge code and/or the serial number of the dynamic password generation module as an input, and outputs the password, and the e-book sends the password to the server. The password and the number of the electronic material that requested the download.
第 4步,服务器接收该密码和请求下载的电子资料的编号,并将该密 码与服务器自身根据所述动态密码生成算法将所述挑战码作为输入进行 计算的结果相比较。  In step 4, the server receives the password and the number of the electronic material requested for download, and compares the password with the result of the server itself calculating the challenge code as an input according to the dynamic password generation algorithm.
如两者相同,服务器根据所述请求下载的电子资料的编号在数据库中 査询所述请求下载的电子资料。当服务器根据所述请求下载的电子资料的 编号在数据库中査询不到所述请求下载的电子资料时,服务器向该电子书 返回错误信息。  If the two are the same, the server queries the database for the downloaded electronic data according to the number of the electronic data downloaded in the request. When the server cannot find the electronic material requested to be downloaded in the database according to the number of the electronic data downloaded by the request, the server returns an error message to the electronic book.
服务器还根据该电子书的动态密码生成模块的序列号在数据库中査 询该电子书对应的私钥。当服务器根据该电子书的动态密码生成模块的序 列号在数据库中査询不到该电子书对应的私钥时,服务器向该电子书返回 "提示注册"或 "更新证书" 的信息。  The server also queries the database for the private key corresponding to the e-book based on the serial number of the dynamic password generating module of the e-book. When the server cannot find the private key corresponding to the e-book in the database according to the serial number of the dynamic password generating module of the e-book, the server returns information of "prompt registration" or "update certificate" to the e-book.
然后服务器将所述请求下载的电子资料压缩和加密 (可以是先压縮再 加密, 也可以是压縮和加密同时进行)。 压缩时, 服务器随机产生一访问 证书。所述访问证书是服务器随机生成的一串数字的组合。例如, 访问证 书可采用 2080个字节的二进制数。  The server then compresses and encrypts the electronic data requested for download (either by compressing and then encrypting, or by compressing and encrypting simultaneously). When compressed, the server randomly generates an access certificate. The access certificate is a combination of a string of numbers randomly generated by the server. For example, an access certificate can use a binary number of 2080 bytes.
所述加密包括以访问证书为密钥对所述请求下载的电子资料加密,还 包括以该电子书对应的私钥为密钥对所述访问证书加密。服务器将加密后 的电子资料和访问证书发给该电子书。 The encrypting includes encrypting the electronic data downloaded by the request with the access certificate as a key, and further encrypting the access certificate by using a private key corresponding to the electronic book as a key. The server will be encrypted The electronic data and access certificate are sent to the e-book.
如两者不同, 服务器停止操作。  If the two are different, the server stops operating.
第 5步,该电子书接收加密后的电子资料和访 ¾证书,并将加密后的 访问证书存储在限制存储区,加密后的电子资料可以存储在公共存储区和 /或限制存储区。  In the fifth step, the e-book receives the encrypted electronic data and the access certificate, and stores the encrypted access certificate in the restricted storage area, and the encrypted electronic data can be stored in the common storage area and/or the restricted storage area.
上述电子书从服务器下载电子资料的过程中, 具体可采用如下方式: 一、电子书通过 https协议与服务器进行连接和通讯。二、所述下载请求、 挑战码、 密码和请求下载的电子资料的编号、 错误信息、 "提示注册"或 "更新证书"的信息、加密后的电子资料和访问证书均以 XML格式在电子 书和服务器之间传输。三、 电子资料通常为一个文件或目录, 如果服务器 为 Linux/Unix或类似系统,对电子资料的压縮和压缩可以先用 mkcramfs 命令将电子资料压缩为 cramfs文件系统, 再用 loop_aes块设备 (block device, 是一种软件) 对该 cramfs文件系统加密, 从而得到压縮和加密 后的电子资料。 ioop- aes块设备可采用 AES128、 multikey- v3方式加密, loop-aes块设备使用的加密密钥 (encryption key ) 就是所述访问证书。 接着服务器再用 RSA算法中的私钥对所述访问证书加密。  In the process of downloading the electronic data from the server, the above-mentioned e-book can adopt the following methods: 1. The e-book connects and communicates with the server through the https protocol. 2. The download request, the challenge code, the password, the number of the electronic data requesting to download, the error message, the information of the "prompt registration" or "update certificate", the encrypted electronic data and the access certificate are all in the XML format in the e-book. Transfer between the server and the server. Third, the electronic data is usually a file or directory. If the server is a Linux/Unix or similar system, the compression and compression of the electronic data can be first compressed into the cramfs file system using the mkcramfs command, and then the loop_aes block device (block) Device, is a software) that encrypts the cramfs file system to obtain compressed and encrypted electronic data. The ioop-aes block device can be encrypted by AES128 or multikey-v3, and the encryption key used by the loop-aes block device is the access certificate. The server then encrypts the access certificate with the private key in the RSA algorithm.
请参阅图 4, 所述电子书访问己下载的电子资料包括如下步骤: 第 1步, 电子书根据用户请求访问的电子资料,在该电子书的限制存 储区中寻找该电子资料对应的访问证书。当电子书在限制存储区中寻找不 到该请求访问的电子资料对应的访问证书时,该电子书向用户显示错误信 息。  Referring to FIG. 4, the e-book accessing the downloaded electronic material includes the following steps: Step 1: The e-book searches for an access certificate corresponding to the electronic data in the restricted storage area of the e-book according to the electronic material accessed by the user request. . When the e-book searches for an access certificate corresponding to the electronic material that is not requested to be accessed in the restricted storage area, the e-book displays an error message to the user.
第 2步,该电子书使用限制存储区中的公钥对所述访问证书解密。解 密后的访问证书仅在内存,使用完毕后电子书将解密后的访问证书从内存 中抹除。 In step 2, the e-book decrypts the access certificate using a public key in the restricted storage area. Solution The secret access certificate is only in memory. After the use, the e-book erases the decrypted access certificate from the memory.
第 3步,该电子书以解密后的访问证书为密钥加载所述请求访问的电 子资料,加载点在限制存储区中, 电子书自动对所述请求访问的电子资料 进行解密和解压缩, 解密和解压縮后的电子资料明文仅挂载在内存区。  In the third step, the e-book loads the electronic data requested to be accessed by using the decrypted access certificate as a key, and the loading point is in the restricted storage area, and the electronic book automatically decrypts and decompresses the electronic data requested to be accessed, and decrypts The decompressed electronic data is only mounted in the memory area.
所述加载, 是将设备、文件或文件夹作为一个文件系统, 并将该文件 系统挂在某目录下,加载后该目录的内容就是该文件系统的内容。加载点 在限制存储区, 就是指该文件系统所挂的目录是在限制存储区的目录。  The loading is to use a device, a file or a folder as a file system, and the file system is hung in a directory. After loading, the content of the directory is the content of the file system. Load point In the limit storage area, it means that the directory where the file system is mounted is the directory that restricts the storage area.
第 4步, 用户使用该电子书访问解密和解压縮后的电子资料明文。 第 5步,用户退出访问电子资料,该电子书将解密后的电子资料明文 从内存区中抹除, 并从限制存储区中卸载所述请求访问的电子资料。  In step 4, the user uses the e-book to access the decrypted and decompressed electronic material clear text. In the fifth step, the user quits accessing the electronic material, and the electronic book erases the decrypted electronic data plaintext from the memory area, and unloads the electronic material requested to be accessed from the restricted storage area.
所述卸载,是将某文件系统从某目录下去除,卸载后该目录的内容不 包括该文件系统的内容。  The uninstallation removes a file system from a directory. The content of the directory does not include the contents of the file system after uninstallation.
上述电子书访问已下载的电子资料的过程中, 具体可采用如下方式: 一、 电子资料和对应的访问证书之间以校验和的方式相关联, 例如采用 SHA1 校验和。 电子书中可能存储有多个电子资料和多个访问证书。 在接 收解密后的电子资料和加密后的访问证书时,电子书先对每个加密后的电 子资料计算校验和,并将该校验和与该加密后的电子资料的加密后的访问 证书相对应,并一起存储在限制存储区中。当电子书需要根据电子资料寻 找对应的访问证书时, 先计算该请求访问的电子资料(加密状态)的校验 和, 再从限制存储区中根据校验和寻找相应的访问证书。二、如果加密后 的电子资料是 Linux/Unix 或类似系统中以 loop-aes 块设备加密的 cramfs文件系统,那么只需要一个 mount命令将该 cramf s文件系统加载, 该 Linux/Unix 或类似系统会自动对加载后的文件系统进行解密和解压 缩。 三、 如果电子书为 Linux/Unix或类似系统, 解密和解压缩后的电子 资料明文仅挂载在电子书的 mfs (内存文件系统) 文件系统中。 工业实用性 In the process of accessing the downloaded electronic material by the above e-book, the following manner may be adopted: 1. The electronic data and the corresponding access certificate are associated with each other in a checksum manner, for example, using a SHA1 checksum. Multiple electronic materials and multiple access certificates may be stored in the e-book. After receiving the decrypted electronic data and the encrypted access certificate, the electronic book first calculates a checksum for each encrypted electronic data, and encrypts the checksum with the encrypted electronic data. Corresponding and stored together in the restricted storage area. When the e-book needs to find a corresponding access certificate according to the electronic data, the checksum of the electronic data (encrypted state) requested to be accessed is first calculated, and then the corresponding access certificate is searched according to the checksum from the restricted storage area. Second, if the encrypted electronic data is encrypted by a loop-aes block device in Linux/Unix or similar systems. Cramfs file system, then only need a mount command to load the cramf s file system, the Linux / Unix or similar system will automatically decrypt and decompress the loaded file system. 3. If the e-book is a Linux/Unix or similar system, the decrypted and decompressed electronic data plaintext is only mounted in the efs mfs (memory file system) file system. Industrial applicability
与现有技术相比,本发明保护版权的电子书在硬件上增加了动态密码 生成模块,该动态密码生成模块可将服务器发来的挑战码和自身的序列号 为输入,输出不断变化的动态密码。所述电子书在向服务器注册和从服务 器下载电子资料的过程中,服务器都需要验证电子书的动态密码;所述电 子书在访问电子资料时, 需要由非对称密钥中的公钥先对访问证书解密, 再用访问证书对电子资料的内容解密,从而确保了电子资料的版权始终处 于受保护的状态。  Compared with the prior art, the copyright protection e-book of the present invention adds a dynamic password generation module to the hardware, and the dynamic password generation module can input the challenge code sent by the server and its serial number as input, and output the changing dynamics. password. In the process of registering the electronic book with the server and downloading the electronic data from the server, the server needs to verify the dynamic password of the electronic book; when the electronic book accesses the electronic data, the public key in the asymmetric key needs to be first Access to the certificate decryption, and then use the access certificate to decrypt the content of the electronic data, thus ensuring that the copyright of the electronic data is always protected.

Claims

权利要求书 Claim
1、 一种保护版权的电子书, 所述电子书为电子资料阅读装置, 其特征 是: 所述电子书包括处理器、 内存模块、 存储模块、 显示屏、 网络连接模 块、 总线和动态密码生成模块, 所述动态密码生成模块具有序列号并内置 动态密码生成算法, 所述动态密码生成算法为动态密码生成模块的输入与 输出之间的计算规则。  1. An electronic book for protecting copyright, the electronic book being an electronic data reading device, characterized in that: the electronic book comprises a processor, a memory module, a storage module, a display screen, a network connection module, a bus and a dynamic password generation The module, the dynamic password generating module has a serial number and a built-in dynamic password generating algorithm, and the dynamic password generating algorithm is a calculation rule between input and output of the dynamic password generating module.
2、 根据权利要求 1所述的保护版权的电子书, 其特征是: 不同的动态 密码生成模块具有不同的序列号, 但具有相同的动态密码生成算法。  2. The copyright protected e-book according to claim 1, wherein: the different dynamic password generating modules have different serial numbers but have the same dynamic password generating algorithm.
3、 根据权利要求 1所述的保护版权的电子书, 其特征是: 所述动态密 码生成模块的输入至少包括该动态密码生成模块的序列号和服务器发给所 述电子书的挑战码。  3. The copyright-protected electronic book according to claim 1, wherein: the input of the dynamic password generating module includes at least a serial number of the dynamic password generating module and a challenge code sent by the server to the electronic book.
4、 根据权利要求 3所述的保护版权的电子书, 其特征是: 不同动态密 码生成模块的输出总是不同的;  4. The copyright-protected electronic book according to claim 3, wherein: the output of the different dynamic password generating modules is always different;
同一个动态密码生成模块对服务器发给所述电子书的不同挑战码的输 出也总是不同的。  The output of the different challenge codes sent by the same dynamic password generation module to the e-book by the server is also always different.
5、 根据权利要求 1所述的保护版权的电子书, 其特征是: 所述存储模 块包括允许用户访问的公共存储区和禁止用户访问的限制存储区, 由所述 电子书的固件或软件系统划分。  5. The copyright-protected electronic book according to claim 1, wherein: said storage module comprises a common storage area for allowing a user to access and a restricted storage area for prohibiting user access, by said firmware or software system of said electronic book. Division.
PCT/CN2009/000655 2009-01-15 2009-06-15 E-book for protecting copyright WO2010081267A1 (en)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN200910056847.0A CN101782949A (en) 2009-01-15 2009-01-15 Electronic book with protection copyright
CN200910056847.0 2009-01-15

Publications (1)

Publication Number Publication Date
WO2010081267A1 true WO2010081267A1 (en) 2010-07-22

Family

ID=42339388

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2009/000655 WO2010081267A1 (en) 2009-01-15 2009-06-15 E-book for protecting copyright

Country Status (2)

Country Link
CN (1) CN101782949A (en)
WO (1) WO2010081267A1 (en)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102223364B (en) * 2011-05-09 2014-06-04 飞天诚信科技股份有限公司 Method and system for accessing e-book data
CN108537009B (en) * 2017-03-03 2022-03-04 绍兴读图网络科技有限公司 Method and system for downloading picture and verifying original edition
CN109034775A (en) * 2018-06-27 2018-12-18 深圳市必发达科技有限公司 A kind of antitheft chapter method, apparatus of the network novel, memory and processor

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1356636A (en) * 2001-12-29 2002-07-03 徐翔 Method for creating electronic book with intellectual property right protection and its reader
CN1485752A (en) * 2002-09-25 2004-03-31 天津津科电子系统工程有限公司 Electronic book with SIM card
CN1992590A (en) * 2005-12-29 2007-07-04 盛大计算机(上海)有限公司 Identity authentication system of network user and method

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1356636A (en) * 2001-12-29 2002-07-03 徐翔 Method for creating electronic book with intellectual property right protection and its reader
CN1485752A (en) * 2002-09-25 2004-03-31 天津津科电子系统工程有限公司 Electronic book with SIM card
CN1992590A (en) * 2005-12-29 2007-07-04 盛大计算机(上海)有限公司 Identity authentication system of network user and method

Also Published As

Publication number Publication date
CN101782949A (en) 2010-07-21

Similar Documents

Publication Publication Date Title
US10491379B2 (en) System, device, and method of secure entry and handling of passwords
CN109862041B (en) Digital identity authentication method, equipment, device, system and storage medium
CN109951489B (en) Digital identity authentication method, equipment, device, system and storage medium
JP5852265B2 (en) COMPUTER DEVICE, COMPUTER PROGRAM, AND ACCESS Permission Judgment Method
US9148415B2 (en) Method and system for accessing e-book data
US8191129B2 (en) Apparatus and method for processing digital rights object
WO2010072041A1 (en) Management system of digital copyright and achieving method thereof
US7263608B2 (en) System and method for providing endorsement certificate
TW201009637A (en) Backing up digital content that is stored in a secured storage device
US20080022099A1 (en) Information transfer
TWI424321B (en) Cloud storage system and method
WO2015043323A1 (en) Management method and device for privacy data of browser, and client
KR20100096090A (en) Mobile smartcard based authentication
WO2018166163A1 (en) Pos terminal control method, pos terminal, server and storage medium
CN114629639A (en) Key management method and device based on trusted execution environment and electronic equipment
CA2891610C (en) Agent for providing security cloud service and security token device for security cloud service
WO2010081267A1 (en) E-book for protecting copyright
TWI428752B (en) Electronic file delivering system, portable communication apparatus with decryption functionality, and related computer program product
AU2005263103B2 (en) Apparatus and method for processing digital rights object
WO2016165662A1 (en) Mobile phone quasi-digital certificate subsystem, and system and method thereof
TWI273492B (en) Encryption/decryption method incorporated with local server software
ES2782329T3 (en) Process to ensure the communication of a digital file through a communication network
KR101828425B1 (en) Electronic book protection system and method for private copy
TW202347354A (en) Application sharing method, file sharing method and device based on blockchain
CN117131522A (en) File processing method and device and electronic equipment

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 09838054

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 09838054

Country of ref document: EP

Kind code of ref document: A1