1460720845-77e63717-7752-4ad2-b15a-17c3e5ee2755

1-91. (canceled)
92. An encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the apparatus comprising:
a digital work storage unit operable to store a digital work;
a first secret key storage unit operable to store a first secret key to be used for encrypting a digital work;
a second secret key storage unit operable to store a second secret key associated with a decryption apparatus that decrypts an encrypted digital work;
a certificate revocation list (CRL) storage unit operable to store a CRL that is a list of information for specifying revoked public key certificates;
an attribute value calculation unit operable to calculate an attribute value that depends on the information in the CRL, based on the CRL stored in the CRL storage unit;
a modification unit operable to modify the second secret key stored in the second secret key storage unit, using the attribute value calculated by the attribute value calculation unit;
a first encryption unit operable to encrypt the first secret key stored in the first secret key storage unit, using the second secret key modified by the modification unit;
a second encryption unit operable to encrypt the digital work stored in the digital work storage unit, using the first secret key stored in the first secret key storage unit; and
an output unit operable to output, to the storage medium or the transmission medium, the attribute value calculated by the attribute value calculation unit, the first secret key encrypted by the first encryption unit and the digital work encrypted by the second encryption unit.
93. The encryption apparatus according to claim 92, further comprising
a verification data output unit operable to output, to the storage medium or the transmission medium, verification data to be a criterion for checking whether or not the first secret key decrypted by the decryption apparatus is correct.
94. The encryption apparatus according to claim 93,
wherein the verification data output unit outputs, to the storage medium or the transmission medium, data obtained by encrypting predetermined fixed-pattern data using the first secret key stored in the first secret key storage unit, as the verification data.
95. The encryption apparatus according to claim 93,
wherein the verification data output unit outputs, to the storage medium or the transmission medium, data obtained by encrypting the first secret key stored in the first secret key storage unit, using said first secret key, as the verification data.
96. The encryption apparatus according to claim 92,
wherein the attribute value calculation unit calculates a hash value of the CRL as the attribute value, and
the modification unit modifies the second secret key by obtaining an exclusive OR value between the second secret key and the hash value.
97. The encryption apparatus according to claim 92,
wherein the output unit outputs the CRL stored in the CRL storage unit to the storage medium or the transmission medium.
98. An encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the apparatus comprising:
a digital work storage unit operable to store a digital work;
a first secret key storage unit operable to store a first secret key to be used for encrypting a digital work;
a second secret key storage unit operable to store a second secret key associated with a decryption apparatus that decrypts an encrypted digital work;
a CRL storage unit operable to store a CRL that is a list of information for specifying revoked public key certificates;
a first encryption unit operable to encrypt the first secret key stored in the first secret key storage unit, using the second secret key stored in the second secret key storage unit;
an attribute value calculation unit operable to calculate an attribute value that depends on the information in the CRL, based on the CRL stored in the CRL storage unit;
a modification unit operable to modify the first secret key stored in the first secret key storage unit, using the attribute value calculated by the attribute value calculation unit;
a second encryption unit operable to encrypt the digital work stored in the digital work storage unit, using the first secret key modified by the modification unit; and
an output unit operable to output, to a storage medium or a transmission medium, the attribute value calculated by the attribute value calculation unit, the first secret key encrypted by the first encryption unit and the digital work encrypted by the second encryption unit.
99. The encryption apparatus according to claim 98, further comprising
a verification data output unit operable to output, to the storage medium or the transmission medium, verification data to be a criterion for checking whether or not the first secret key decrypted by the decryption apparatus is correct.
100. The encryption apparatus according to claim 99,
wherein the verification data output unit outputs, to the storage medium or the transmission medium, data obtained by encrypting predetermined fixed-pattern data using the first secret key modified by the modification unit, as the verification data.
101. The encryption apparatus according to claim 99,
wherein the verification data output unit outputs the verification data to the storage medium or the transmission medium, the verification data being data obtained by encrypting the first secret key modified by the modification unit, using said first secret key.
102. An encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the apparatus comprising:
a digital work storage unit operable to store a digital work;
a medium identification information storage unit operable to store medium identification information to be used for encrypting a digital work;
a first secret key storage unit operable to store a first secret key associated with a decryption apparatus that decrypts an encrypted digital work;
a certificate revocation list (CRL) storage unit operable to store a CRL that is a list of information for specifying revoked public key certificates;
an attribute value calculation unit operable to calculate an attribute value that depends on the information in the CRL, based on the CRL stored in the CRL storage unit;
a modification unit operable to modify the first secret key stored in the first secret key storage unit, using the attribute value calculated by the attribute value calculation unit;
a function conversion unit operable to convert the medium identification information stored in the medium identification information storage unit and the first secret key modified by the modification unit, by entering said information and key into a one-way function;
a second encryption unit operable to encrypt the digital work stored in the digital work storage unit, using a function value obtained by the function conversion unit; and
an output unit operable to output, to the storage medium or the transmission medium, the attribute value calculated by the attribute value calculation unit, the medium identification information stored in the medium identification information unit and the digital work encrypted by the second encryption unit.
103. An encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the apparatus comprising:
a digital work storage unit operable to store a digital work;
a medium identification information storage unit operable to store medium identification information to be used for encrypting a digital work;
a first secrete key storage unit operable to store a first secret key associated with a decryption apparatus that decrypts an encrypted digital work;
a certificate revocation list (CRL) storage unit operable to store a CRL that is a list of information for specifying revoked public key certificates;
a function conversion unit operable to convert the medium identification information stored in the medium identification information storage unit and the first secrete key stored in the first secret key storage unit, by entering said information and key into a one-way function;
an attribute value calculation unit operable to calculate an attribute value that depends on the information in the CRL, based on the CRL stored in the CRL storage unit;
a modification unit operable to modify a function value obtained by the function conversion unit, using the attribute value calculated by the attribute value calculation unit;
a first encryption unit operable to encrypt the digital work stored in the digital work storage unit, using the attribute value modified by the modification unit; and
an output unit operable to output, to the storage medium or the transmission medium, the attribute value calculated by the attribute value calculation unit, the medium identification information stored in the medium identification information storage unit and the digital work encrypted by the first encryption unit.
104. An encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the apparatus comprising:
a digital work storage unit operable to store a digital work;
a first secret key storage unit operable to store a first secret key to be used for encrypting a digital work;
a second secret key storage unit operable to store a second secret key associated with a decryption apparatus that decrypts an encrypted digital work;
a third secret key storage unit operable to store a third secret key to be used for encrypting the first secret key;
a certificate revocation list (CRL) storage unit operable to store a CRL that is a list of information for identifying revoked public key certificates;
an attribute value calculation unit operable to calculate an attribute that depends on the information in the CRL, based on the CRL stored in the CRL storage unit;
a modification unit operable to modify the second secret key stored in the CRL storage unit, using the attribute value calculated by the attribute value calculation unit;
a first encryption unit operable to encrypt the third secret key stored in the third secret key storage unit, using the second secret key modified by the modification unit;
a second encryption unit operable to encrypt the first secret key stored in the first secret key storage unit, using the third secret key stored in the third secret key storage unit;
a third encryption unit operable to encrypt the digital work stored in the digital work storage unit, using the first secret key stored in the first secret key storage unit; and
an output unit operable to output, to the storage medium or the transmission medium, the attribute value calculated by the attribute value calculation unit, the third secret key encrypted by the first encryption unit, the first secret key encrypted by the second encryption unit and the digital work encrypted by the third encryption unit.
105. The encryption apparatus according to claim 104, further comprising
a verification data output unit operable to output, to the storage medium or the transmission medium, verification data to be a criterion for checking whether or not the third secret key decrypted by the decryption apparatus is correct.
106. The encryption apparatus according to claim 105,
wherein the verification data output unit outputs, to the storage medium or the transmission medium, data obtained by encrypting predetermined fixed-pattern data using the third secret key stored in the third secret key storage unit, as the verification data.
107. The encryption apparatus according to claim 105,
wherein the verification data output unit outputs, to the storage medium or the transmission medium, data obtained by encrypting the third secret key stored in the third secret key storage unit, using said third secret key, as the verification data.
108. An encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the apparatus comprising:
a digital work storage unit operable to store a digital work;
a first secret key storage unit operable to store a first secret key to be used for encrypting a digital work,
a second secret key storage unit operable to store a second secret key associated with a decryption apparatus that decrypts an encrypted digital work:
a third secret key storage unit operable to store a third secret key to be used for encrypting the first secret key;
a certificate revocation list (CRL) storage unit operable to store a CRL that is a list of information for specifying revoked public key certificates;
a first encryption unit operable to encrypt the third secret key stored in the third secret key storage unit, using the second secret key stored in the second secret key storage unit;
an attribute value calculation unit operable to calculate an attribute value that depends on the information in the CRL, based on the CRL stored in the CRL storage unit;
a modification unit operable to modify the third secret key stored in the third secret key storage unit, using the attribute value calculated by the attribute value calculation unit;
a second encryption unit operable to encrypt the first secret key stored in the first secret key storage unit, using the attribute value modified by the modification unit;
a third encryption unit operable to encrypt the digital work stored in the digital work storage unit, using the first secret key stored in the first secret key storage unit; and
an output unit operable to output, to the storage medium or the transmission medium, the attribute value calculated by the attribute value calculation unit, the third secret key encrypted by the first encryption unit, the first secret key encrypted by the second encryption unit and the digital work encrypted by the third encryption unit.
109. An encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the apparatus comprising:
a digital work storage unit operable to store a digital work;
a first secret key storage unit operable to store a first secret key to be used for encrypting a digital work;
a second secret key storage unit operable to store a second secret key associated with a decryption apparatus that decrypts an encrypted digital work;
a third secret key storage unit operable to store a third secret key to be used for encrypting the first secret key;
a certificate revocation list (CRL) storage unit operable to store a CRL that is a list of information for specifying revoked public key certificates;
a first encryption unit operable to encrypt the third secret key stored in the third secret key storage unit, using the second secret key stored in the second secret key storage unit;
a second encryption unit operable to encrypt the first secret key stored in the first secret key storage unit, using the third secret key encrypted by the first encryption unit;
an attribute value calculation unit operable to calculate an attribute value that depends on the information in the CRL, based on the CRL stored in the CRL storage unit;
a modification unit operable to modify the first secret key stored in the first secret key storage unit, using the attribute value calculated by the attribute value calculation unit;
a third encryption unit operable to encrypt the digital work stored in the digital work storage unit, using the first secret key modified by the modification unit; and
an output unit operable to output, to the storage medium or the transmission medium, the attribute value calculated by the attribute value calculation unit, the third secret key encrypted by the first encryption unit, the first secret key encrypted by the second encryption unit and the digital work encrypted by the third encryption unit.
110. An encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the apparatus comprising:
a digital work storage unit operable to store a digital work;
a first secret key storage unit operable to store a first secret key to be used for encrypting a digital work;
a second secret key storage unit operable to store a second secret key associated with a decryption apparatus that decrypts an encrypted digital work;
a fourth secret key storage unit operable to store a fourth secret key to be used for encrypting the first secret key;
a certificate revocation list (CRL) storage unit operable to store a CRL that is a list of information for specifying revoked public key certificates;
a first encryption unit operable to encrypt the fourth secret key stored in the fourth secret key storage unit, using the second secret key stored in the second secret key storage unit;
a second encryption unit operable to encrypt the first secret key stored in the first secret key storage unit, using the fourth secret key stored in the fourth secret key storage unit;
an attribute value calculation unit operable to calculate an attribute value that depends on the information in the CRL, based on the CRL stored in the CRL storage unit;
a secret key generation unit operable to generate a fifth secret key for encrypting a content based on the first secret key stored in the first secret key storage unit and the attribute value calculated by the attribute value calculation unit;
a third encryption unit operable to encrypt the digital work stored in the digital work storage unit, using the fifth secret key generated by the secret key generation unit; and
an output unit operable to output, to the storage medium or the transmission medium, the attribute value calculated by the attribute value calculation unit, the fourth secret key encrypted by the first encryption unit, the first secret key encrypted by the second encryption unit and the digital work encrypted by the third encryption unit.
111. The encryption apparatus according to claim 110, further comprising
an information storage unit operable to store information for specifying at least one of the storage medium or the transmission medium, and the content,
wherein the secret key generation unit generates the fifth secret key based on the information stored in the information storage unit.
112. An encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the apparatus comprising:
a digital work storage unit operable to store a digital work;
a medium identification information storage unit operable to store medium identification information to be used for encrypting a digital work;
a first secret key storage unit operable to store a first secret key associated with a decryption apparatus that decrypt an encrypted digital work;
a second secret key storage unit operable to store a second secret key to be used for encrypting the medium identification information;
a certificate revocation list (CRL) storage unit operable to store a CRL that is a list of information for specifying revoked public key certificates;
an attribute value calculation unit operable to calculate an attribute value that depends on the information in the CRL, based on the CRL stored in the CRL storage unit;
a modification unit operable to modify the first secret key stored in the first secret key storage unit, using the attribute value calculated by the attribute value calculation unit;
a first encryption unit operable to encrypt the second secret key stored in the second secret key storage unit, using the first secret key modified by the modification unit;
a function conversion unit operable to convert the medium identification information stored in the medium identification information storage unit and the second secret key stored in the second secret key storage unit, by entering said information and key into a one-way function;
a second encryption unit operable to encrypt the digital work stored in the digital work storage unit, using a function value obtained by the function conversion unit; and
an output unit operable to output, to the storage medium or the transmission medium, the attribute value stored in the digital work storage unit, the second secret key encrypted by the first encryption unit, the medium identification information stored in the medium identification information storage unit and the digital work encrypted by the third encryption unit.
113. The encryption apparatus according to claim 112, further comprising
a verification data output unit operable to output, to the storage medium or the transmission medium, verification data to be a criterion for checking whether or not the second secret key decrypted by the decryption apparatus is correct.
114. The encryption apparatus according to claim 113,
wherein the verification data output unit outputs, to the storage medium or the transmission medium, data obtained by encrypting predetermined fixed-pattern data using the second secret key stored in the second secret key storage unit, as the verification data.
115. The encryption apparatus according to claim 113,
wherein the verification data output unit operable to output, to the storage medium or the transmission medium, data obtained by encrypting the second secret key stored in the second secret key storage unit, using said second secret key, as the verification data.
116. An encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the apparatus comprising:
a digital work storage unit operable to store a digital work;
a medium identification information storage unit operable to store medium identification information to be used for encrypting a digital work;
a first secret key storage unit operable to store a first secret key associated with a decryption apparatus that decrypts an encrypted digital work;
a second secret key storage unit operable to store a second secret key to be used for encrypting the medium identification information;
a certificate revocation list (CRL) storage unit operable to store a CRL that is a list of information for specifying revoked public key certificates;
a first encryption unit operable to encrypt the second secret key stored in the second secret key storage unit, using the first secret key stored in the first secret key storage unit;
an attribute value calculation unit operable to calculate an attribute value that depends on the information in the CRL ,based on the CRL stored in the CRL storage unit;
a modification unit operable to modify the second secret key stored in the second secret key storage unit, using the attribute value calculated by the attribute value calculation unit;
a function conversion unit operable to convert the medium identification information stored in the medium identification information storage unit and the second secret key modified by the modification unit, by entering said information and key into a one-way function;
a second encryption unit operable encrypt the digital work stored in the digital work storage unit, using a function value obtained by the function conversion unit; and
an output unit operable to output, to the storage medium or the transmission medium, the attribute value calculated by the attribute value calculation unit, the second secret key encrypted by the first encryption unit, the medium identification information stored in the medium identification information storage unit and the digital work encrypted by the third encryption unit.
117. An encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the apparatus comprising:
a digital work storage unit operable to store a digital work;
a medium identification information storage unit operable to store medium identification information to be used for encrypting a digital work;
a first secret key storage unit operable to store a first secret key associated with a decryption apparatus that decrypts an encrypted digital work;
a second secret key storage unit operable to store a second secret key to be used for encrypting the medium identification information;
a certificate revocation list (CRL) storage unit operable to store a CRL that is a list of information for specifying revoked public key certificates;
a first encryption unit operable to encrypt the second secret key stored in the second secret key storage unit, using the first secret key stored in the first secret key storage unit;
a function conversion unit operable to convert the medium identification information stored in the medium identification information storage unit and the second secret key stored in the second secret key storage unit, by entering said information and key into a one-way function;
an attribute value calculation unit operable to calculate an attribute value that depends on the information in the CRL, based on the CRL stored in the CRL storage unit;
a modification unit operable to modify a function value obtained by the function conversion unit, using the attribute value calculated by the attribute calculation unit;
a second encryption unit operable to encrypt the digital work stored in the digital work storage unit, using a function value modified by the modification unit; and
an output unit operable to output, to the storage medium or the transmission medium, the attribute value calculated by the attribute value calculation unit, the second secret key encrypted by the first encryption unit, the medium identification information stored in the medium identification information storage unit, and the digital work encrypted by the second encryption unit.
118. A decryption apparatus that obtains an encrypted digital work via a storage medium or a transmission medium and decrypts the encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, and an encrypted first secret key generated by encrypting a first secret key used for the encryption of the digital work;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a modification unit operable to modify the second secret key stored in the second secret key storage unit, using the attribute value obtained by the obtainment unit;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment, using the second secret key modified by the modification unit; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the first secret key decrypted by the first decryption unit.
119. The decryption apparatus according to claim 118,
wherein the obtainment unit obtains a hash value of the CRL as the attribute value, and
the modification unit modifies the second secret key by obtaining an exclusive OR value between the second secret key and the hash value.
120. A decryption apparatus that obtains an encrypted digital work via a storage medium or a transmission medium and decrypts the encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, and an encrypted first secret key generated by encrypting a first secret key used for encrypting a digital work;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
an attribute value calculation unit operable to calculate an attribute value that depends on the information in the CRL, based on the CRL obtained by the obtainment unit;
a modification unit operable to modify the first secret key decrypted by the first decryption unit, using the attribute value obtained by the obtainment unit; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the first secret key modified by the modification unit.
121. A decryption apparatus that obtains an encrypted digital work via a storage medium or a transmission medium and decrypts the encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, and medium identification information used for encrypting a digital work;
a first secret key storage unit operable to store a first secret key specific to the decryption apparatus;
a modification unit operable to modify the first secret key stored in the first secret key storage unit, using the attribute value obtained by the obtainment unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the first secret key modified by the modification unit, by entering said information and key into a one-way function; and
a first decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using a function value obtained by the function conversion unit.
122. A decryption apparatus that obtains an encrypted digital work via a storage medium and a transmission medium and decrypts the encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, and medium identification information used for encrypting a digital work;
a first secret key storage unit operable to store a first secret key specific to the decryption apparatus;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the first secret key stored in the first secret key storage unit, by entering said information and key into a one-way function;
a modification unit operable to modify a function value obtained by the function conversion unit, using the attribute value modified by the modification unit; and
a first decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the attribute value modified by the modification unit.
123. A decryption apparatus that obtains an encrypted digital work via a storage medium or a transmission medium and decrypts the encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, an encrypted first secret key generated by encrypting a first secret key used for encrypting a digital work, and an encrypted third secret key generated by encrypting a third secret key used for the encryption of the first secret key;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a modification unit operable to modify the third secret key stored in the third secret key storage unit, using the attribute value obtained by the obtainment unit;
a first decryption unit operable to decrypt the encrypted third secret key obtained by the obtainment unit, using the second secret key modified by the modification unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the third secret key decrypted by the first decryption unit; and
a third decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the first secret key decrypted by the second decryption unit.
124. A decryption apparatus that obtains an encrypted digital work via a storage medium or a transmission medium and decrypts the encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, an encrypted first secret key generated by encrypting a first secret key used for the encryption of the digital work, an encrypted third secret key generated by encrypting a third secret key used for the encryption of the first secret key;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted third secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
a modification unit operable to modify the third secret key decrypted by the first decryption unit, using the attribute value obtained by the obtainment unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the third secret key modified by the modification unit; and
a third decryption unit operable to decrypt the encrypted digital work obtained by the obtainment, using the first secret key decrypted by the second decryption unit.
125. A decryption apparatus that obtains an encrypted digital work via a storage medium or a transmission medium and decrypts the encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, an encrypted first secret key generated by encrypting a first secret key used for encrypting a digital work, an encrypted third secret key generated by encrypting a third secret key used for the encryption of the first secret key;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted third secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the third secret key decrypted by the first decryption unit;
a modification unit operable to modify the first secret key decrypted by the second decryption unit, using the attribute value obtained by the obtainment unit; and
a third decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the first secret key modified by the modification unit.
126. A decryption apparatus that obtains an encrypted digital work via a storage medium or a transmission medium and decrypts the encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, an encrypted first secret key generated by encrypting a first secret key used for encrypting a digital work, and an encrypted fourth secret key generated by encrypting a fourth secret key used for the encryption of the first secret key;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted fourth secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the fourth secret key decrypted by the first decryption unit;
a secret key generation unit operable to generate a fifth secret key for decrypting the encrypted digital work, based on the first secret key decrypted by the second decryption unit and the attribute value obtained by the obtainment unit; and
a third decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the fifth secret key generated by the secret key generation unit.
127. The decryption apparatus according to claim 126,
wherein the obtainment unit obtains information for specifying at least one of the storage medium or the transmission medium, and the content, and
the secret key generation unit generates the fifth secret key based on the information obtained by the obtainment unit.
128. A decryption apparatus that obtains an encrypted digital work via a storage medium or a transmission medium and decrypts the encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, an attribute which depends on the information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, medium identification information used for encrypting a digital work, and an encrypted second secret key generated by encrypting a second secret key used for encrypting the medium identification information;
a first secret key storage unit operable to store a first secret key specific to the decryption apparatus;
a modification unit operable to modify the first secret key stored in the first secret key storage unit, using the attribute value obtained by the obtainment unit;
a first decryption unit operable to decrypt the encrypted second secret key obtained by the obtainment unit, using the first secret key modified by the modification unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the second secret key decrypted by the first decryption unit, by entering said information and key into a one-way function; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit using a function value obtained by the function conversion unit.
129. A decryption apparatus that obtains an encrypted digital work via a storage medium or a transmission medium and decrypts the encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, medium identification information used for encrypting a digital work, and an encrypted second secret key generated by encrypting a second secret key used for encrypting the medium identification information;
a first secret key storage unit operable to store a first secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted second secret key obtained by the obtainment unit, using the first secret key stored in the first secret key storage unit;
a modification unit operable to modify the second secret key decrypted by the first decryption unit, using the attribute value obtained by the obtainment unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the attribute value modified by the modification unit, by entering said information and value to a one-way function; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using a function value obtained by the function conversion unit.
130. A decryption apparatus that obtains an encrypted digital work via a storage medium or a transmission medium and decrypts the encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, medium identification information used for encrypting a digital work, and an encrypted second secret key generated by encrypting a second secret key used for encrypting the medium identification information;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the second secret key decrypted by the first decryption unit, by entering said information and key into a one-way function;
a modification unit operable to modify a function value obtained by the function conversion unit, using the attribute value obtained by the obtainment unit; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the function value modified by the modification unit.
131. A decryption apparatus comprising: an obtainment apparatus for obtaining an encrypted digital work via a storage medium or a transmission medium; and an application program to be used for decrypting the encrypted digital work,
wherein the obtainment apparatus includes:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, and an encrypted first secret key generated by encrypting a first secret key used for encrypting a digital work; and
a first encrypted communication unit operable to judge a validity of a public key held by the application program with reference to the CRL, and transmit, to the application program, at least the encrypted first secret key in encrypted form using the public key, in the case of judging that said public key is valid, and
the application program includes:
a second encrypted communication unit operable to judge a validity of a public key held by the obtainment apparatus with reference to the CRL, and transmits, to the obtainment apparatus, at least the encrypted first secret key in encrypted form using the public key;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
an attribute value calculation unit operable to calculate an attribute value which depends on the information in the CRL, based on the obtained CRL;
a modification unit operable to modify the second secret key stored in the second secret key storage unit, using the attribute value calculated by the attribute value calculation unit;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key modified by the modification unit; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the first secret key decrypted by the first decryption unit.
132. A decryption apparatus comprising: an obtainment apparatus for obtaining an encrypted digital work via a storage medium or a transmission medium; and an application program to be used for decrypting the encrypted digital work,
wherein the obtainment apparatus includes:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, and an encrypted first secret key generated by encrypting a first secret key used for the encryption of the digital work; and
a first encryption communication unit operable to judge a validity of a public key held by the application program with reference to the CRL, and transmit to the application program, at least the CRL in encrypted form using the public key, in the case of judging that said public key is valid, and
the application program includes:
a second encrypted communication unit operable to judge a validity of a public key held by the obtainment apparatus with reference to the CRL, and transmit, to the obtainment apparatus, at least the encrypted first secret key in encrypted form using said public key, in the case of judging that said public key is valid; and
an attribute value calculation unit operable to calculate an attribute value which depends on the information in the CRL, based on the CRL obtained in the encrypted communication, and the obtainment apparatus further includes:
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a modification unit operable to modify the second secret key stored in the second secret key storage unit, using the attribute value calculated by the attribute value calculation unit;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key modified by the modification unit; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the first secret key decrypted by the first decryption unit.
133. A secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the secret key generation apparatus comprising:
an obtainment unit operable to obtain, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, and an encrypted first secret key generated by encrypting a first secret key used for encrypting a digital work;
a second secret key storage unit operable to store a second secret key specific to the secret key generation apparatus;
a modification unit operable to modify the second secret key stored in the second secret key storage unit, using the attribute value obtained by the obtainment unit;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key modified by the modification unit; and
an output unit operable to output, to the decryption apparatus, the first secret key decrypted by the first decryption unit as the secret key for decrypting the digital work.
134. The secret key generation apparatus according to claim 133, further comprising
a judgment unit operable to judge whether or not the first secret key decrypted by the first decryption unit is a correct first secret key used for the encryption of the digital work.
135. The secret key generation apparatus according to claim 134,
wherein the judgment unit includes:
a verification data obtainment unit operable to obtain, from the storage medium or the transmission medium, verification data to be a criterion for the judgment;
a verification data decryption unit operable to decrypt the obtained verification data using the first secret key decrypted by the first decryption unit; and
a subunit operable to judge whether or not the data obtained in the decryption performed by the verification data decryption unit corresponds to a predetermined fixed-pattern, and judge that said first secret key is correct in the case where said data corresponds to said fixed-pattern.
136. The secret key generation apparatus according to claim 134,
wherein the judgment unit includes:
a verification data obtainment unit operable to obtain, from the storage medium or the transmission medium, verification data to be a criterion for the judgment;
a first secret key encryption unit operable to encrypt the first secret key decrypted by the first decryption unit using said first secret key; and
a subunit operable to judge whether or not the first secret key encrypted by the first secret key encryption unit corresponds to the verification data obtained by the verification data obtainment unit, and judge that said first secret key is correct in the case where said first secret key corresponds to said verification data.
137. The secret key generation apparatus according to claim 134,
wherein the judgment unit includes:
a verification data obtainment unit operable to obtain, from the storage medium or the transmission medium, verification data to be a criterion for the judgment;
a verification data decryption unit operable to decrypt the verification data obtained by the verification data obtainment unit using the first secret key decrypted by the first decryption unit; and
a subunit operable to judge whether or not a value decrypted by the verification data decryption unit corresponds to the first secret key decrypted by the first decryption unit, and judge that said first secret key is correct in the case where the value corresponds to said first secret key.
138. The secret key generation apparatus according to claim 133,
wherein the obtainment unit obtains a hash value of the CRL as the attribute value, and
the modification unit modifies the second secret key by obtaining an exclusive OR value between the second secret key and the hash value.
139. A secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, and an encrypted first secret key generated by encrypting a first secret key used for encrypting a digital work;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
a modification unit operable to modify the first secret key decrypted by the first decryption unit, using the attribute value obtained by the obtainment unit; and
an output unit operable to output the first secret key modified by the modification unit as the secret key for decrypting the digital work.
140. The secret key generation apparatus according to claim 139, further comprising
a judgment unit operable to judge whether or not the first secret key modified by the modification unit is a correct first secret key used for encrypting the digital work.
141. The secret key generation apparatus according to claim 140,
wherein the judgment unit includes:
a verification data obtainment unit operable to obtain, from the storage medium or the transmission medium, verification data to be a criterion for the judgment;
a verification data decryption unit operable to decrypt the obtained verification data using the first secret key modified by the modification unit; and
a subunit operable to judge whether or not the data obtained in the decryption performed by the verification data decryption unit corresponds to a predetermined fixed-pattern, and judge that said first secret key is correct in the case where said data corresponds to said fixed-pattern.
142. The secret key generation apparatus according to claim 140,
wherein the judgment unit includes:
a verification data obtainment unit operable to obtain, from the storage medium or the transmission medium, verification data to be a criterion for the judgment;
a first secret key encryption unit operable to encrypt the first secret key modified by the modification unit, using said first secret key; and
a subunit operable to judge whether or not the first secret key encrypted by the first secret key encryption unit corresponds to the verification data obtained by the verification data obtainment unit, and judge that said first secret key is correct in the case where said first secret key corresponds to said verification data.
143. The secret key generation apparatus according to claim 140,
wherein the judgment unit includes:
a verification data obtainment unit operable to obtain, from the storage medium or the transmission medium, verification data to be a criterion for the judgment;
a verification data decryption unit operable to decrypt the verification data obtained by the verification data obtainment unit, using the first secret key modified by the modification unit; and
a judgment unit operable to judge whether or not a value decrypted by the verification data decryption unit corresponds to the first secret key modified by the modification unit, and judge that said first secret key is correct in the case where the value corresponds to said first secret key.
144. A secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via a storage medium or a transmission medium, an attribute which depends on the information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, and medium identification information used for the encryption of the digital work;
a first secret key storage unit operable to store a first secret key specific to the decryption apparatus;
a modification unit operable to modify the first secret key stored in the first secret key storage unit, using the attribute value obtained by the obtainment unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the first secret key modified by the modification unit, by entering said information and key into a one-way function; and
an output unit operable to output a function value obtained by the function conversion unit as the secret key for decrypting the digital work.
145. A secret key generation apparatus that outputs a secret key for decryption to-a decryption apparatus that decrypts an encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, and medium identification information used for the encryption of the digital work;
a first secret key storage unit operable to store a first secret key specific to the decryption apparatus;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the first secret key stored in the first secret key storage unit, by entering said information and key into a one-way function;
a modification unit operable to modify a function value modified by the modification unit, using the attribute value obtained by the obtainment unit; and
an output unit operable to output the attribute value modified by the modification unit as the secret key for decrypting the digital work.
146. A secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted first secret key generated by encrypting a first secret key used for the encryption of the digital work, and an encrypted second secret key generated by encrypting a second secret key used for the encryption of the first secret key;
a third secret key storage unit operable to store a third secret key specific to the secret key generation apparatus;
a modification unit operable to modify the third secret key stored in the third secret key storage unit, using the attribute value obtained by the obtainment unit;
a first decryption unit operable to decrypt the encrypted second secret key obtained by the obtainment unit, using the third secret key modified by the modification unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key decrypted by the first decryption unit; and
an output unit operable to output, to the decryption apparatus, the first secret key decrypted by the second decryption unit, as the secret key for decrypting the digital work.
147. The secret key generation apparatus according to claim 146, further comprising
a judgment unit operable to judge whether or not the second secret key decrypted by the first decryption unit is a correct second secret key used for encrypting the first secret key.
148. The secret key generation apparatus according to claim 147,
wherein the judgment unit includes:
a verification data obtainment unit operable to obtain, from the storage medium or the transmission medium, verification data to be a criterion for the judgment;
a verification data decryption unit operable to decrypt the obtained verification data using the second secret key decrypted by the first decryption unit; and
a subunit operable to judge whether or not the data obtained in the decryption performed by the verification data decryption unit corresponds to a predetermined fixed-pattern, and judge that said second secret key is correct in the case where said data corresponds to said fixed-pattern.
149. The secret key generation apparatus according to claim 147,
wherein the judgment includes:
a verification data obtainment unit operable to obtain, from the storage medium or the transmission medium, verification data to be a criterion for the judgment;
a second secret key encryption unit operable to encrypt the second secret key decrypted by the first decryption unit, using said second secret key; and
a subunit operable to judge whether or not the second secret key encrypted by the second secret key encryption unit corresponds to the verification data obtained by the verification data obtainment unit, and judge that said second secret key is correct in the case where the second secret key corresponds to the verification data.
150. The secret key generation apparatus according to claim 147,
wherein the judgment unit includes:
a verification data obtainment unit operable to obtain, from a storage medium or a transmission medium, verification data to be a criteria for the judgment;
a verification data decryption unit operable to decrypt the verification data obtained by the verification data obtainment unit, using the second secret key decrypted by the first decryption unit; and
a judgment unit operable to judge whether or not a value decrypted by the verification data decryption unit corresponds to the second secret key decrypted by the first decryption unit, and judge that said second secret key is correct in the case where the value corresponds to said second secret key.
151. A secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted first secret key generated by encrypting a first secret key used for the encryption of the digital work, and an encrypted second secret key generated by encrypting a second secret key used for the encryption of the first secret key;
a third secret key storage unit operable to store a third secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted second secret key obtained by the obtainment unit, using the third secret key stored in the third secret key storage unit;
a modification unit operable to modify the second secret key decrypted by the first decryption unit, using the attribute value obtained by the obtainment unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key modified by the modification unit; and
an output unit operable to output, to the decryption apparatus, the first secret key decrypted by the second decryption unit, as the secret key for decrypting the digital work.
152. A secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted first secret key generated by encrypting a first secret key used for the encryption of the digital work, and an encrypted second secret key generated by encrypting a second secret key used for the encryption of the first secret key;
a third secret key storage unit operable to store a third secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted second secret key obtained by the obtainment unit, using a third secret key stored in the third secret key storage unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key decrypted by the first decryption unit;
a modification unit operable to modify the first secret key decrypted by the second decryption unit, using the attribute value obtained by the obtainment unit; and
an output unit operable to output, to the decryption apparatus, the first secret key decrypted by the second decryption unit as the secret key for decrypting the digital work.
153. A secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, an encrypted secret key generated by encrypting a first secret key used for the encryption of the digital work, and an encrypted fourth secret key generated by encrypting a fourth secret key used for the encryption of the first secret key;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted fourth secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the fourth secret key decrypted by the first decryption unit;
a secret key generation unit operable to generate a fifth secret key for decrypting the encrypted digital work based on the first secret key decrypted by the second decryption unit and the attribute value obtained by the obtainment unit; and
an output unit operable to output, to the decryption apparatus, the fifth secret key generated by the secret key generation unit, as the secret key for decryption.
154. The secret key generation apparatus according to claim 153,
wherein the obtainment unit obtains information for specifying at least one of the storage medium or the transmission medium, and the content, and
the secret key generation unit generates the fifth secret key based on the information obtained by the obtainment unit.
155. A secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, medium identification information used for the encryption of the digital work, and an encrypted first secret key generated by encrypting a first secret key used for encrypting the medium identification information;
a second secret key storage unit operable to store a second secret key specific to the secret key generation apparatus;
a modification unit operable to modify the second secret key stored in the second secret key storage unit, using the attribute value obtained by the obtainment unit;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key modified by the modification unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the first secret key decrypted by the first decryption unit, by entering said information and key into a one-way function; and
an output unit operable to output, to the decryption apparatus, a function value obtained by the function conversion unit, as the secret key for decrypting the digital work.
156. The secret key generation apparatus according to claim 155, further comprising
a judgment unit operable to judge whether or not the first secret key decrypted by the first decryption unit is a correct first secret key used for the encryption of the medium identification information.
157. The secret key generation apparatus according to claim 156,
wherein the judgment unit includes:
a verification data obtainment unit operable to obtain, from the storage medium or the transmission medium, verification data to be a criterion for the judgment;
a verification data decryption unit operable to decrypt the obtained verification data using the first secret key decrypted by the first decryption unit; and
a subunit operable to judge whether or not the data obtained in the decryption performed by the verification data decryption unit corresponds to a predetermined fixed-pattern, and judge that said first secret key is correct in the case where said data corresponds to said fixed-pattern.
158. The secret key generation apparatus according to claim 156,
wherein the judgment unit includes:
a verification data obtainment unit operable to obtain, from the storage medium or the transmission medium, verification data to be a criterion for the judgment;
a first secret key encryption unit operable to encrypt the first secret key decrypted by the first decryption unit, using said first secret key; and
a subunit operable to judge whether or not the first secret key encrypted by the first secret key encryption unit corresponds to the verification data obtained by the verification data obtainment unit, and judge that said first secret key is correct in the case where said first secret key corresponds to said verification data.
159. The secret key generation apparatus according to claim 156,
wherein the judgment unit includes:
a verification data obtainment unit operable to obtain, from the storage medium or the transmission medium, verification data to be a criterion for the judgment;
a verification data decryption unit operable to decrypt the verification data obtained by the verification data obtainment unit, using the first secret key decrypted by the first decryption unit; and
a subunit operable to judge whether or not a value decrypted by the verification data decryption unit corresponds to the first secret key decrypted by the first decryption unit, and judge that said first secret key is correct in the case where the value corresponds to said first secret key.
160. A secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the apparatus comprising:
an obtainment unit operable to obtain, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, medium identification information used for the encryption of the digital work, and an encrypted first secret key generated by encrypting a first secret key used for encrypting the medium identification information;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
a modification unit operable to modify the first secret key decrypted by the first decryption unit, using the attribute value obtained by the obtainment unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the attribute value modified by the modification unit, by entering said information and key into a one-way function; and
an output unit operable to output, to the decryption apparatus, a function value obtained by the function conversion unit, as the secret key for decrypting the digital work.
161. A secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, said apparatus comprising:
an obtainment unit operable to obtain, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, medium identification information used for the encrypting of the digital work, and an encrypted first secret key generated by encrypting a first secret key used for encrypting the medium identification information;
a second secret key storage unit operable to store a second secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the first secret key decrypted by the first decryption unit, by entering said information and key into a one-way function;
a modification unit operable to modify a function value obtained by the function conversion unit, using the attribute value obtained by the obtainment unit; and
an output unit operable to output, to the decryption apparatus, the function value modified by the modification unit, as the secret key for decrypting the digital work.
162. A copyright protection system for securely transmitting a digital work via a storage medium or a transmission medium, comprising:
the encryption apparatus according to claim 92; and
a decryption apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, the attribute value, the encrypted digital work, and an encrypted first secret key generated by encrypting the first secret key;
a second secret key storage unit operable to store the second secret key;
a modification unit operable to modify the second secret key stored in the second secret key storage unit, using the attribute value obtained by the obtainment unit;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key modified by the modification unit; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the first secret key decrypted by the first decryption unit.
163. A copyright protection system for securely transmitting a digital work via a storage medium or a transmission medium, comprising:
the encryption apparatus according to claim 98; and
a decryption apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, the attribute value, the encrypted digital work, and an encrypted first secret key generated by encrypting the first secret key;
a second secret key storage unit operable to store the second secret key;
a first decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
an attribute value calculation unit operable to calculate the attribute value, based on the CRL obtained by the obtainment unit;
a modification unit operable to modify the first secret key decrypted by the first decryption unit, using the attribute value obtained by the obtainment unit; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the first secret key modified by the modification unit.
164. A copyright protection system for securely transmitting a digital work via a storage medium or a transmission medium, comprising:
the encryption apparatus according to claim 102; and
a decryption apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, the attribute value, the encrypted digital work, and the medium identification information;
a first secret key storage unit operable to store the first secret key;
a modification unit operable to modify the first secret key stored in the first secret key storage unit, using the attribute value obtained by the obtainment unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the first secret key modified by the modification unit, by entering said information and key into a one-way function; and
a first decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using a function value obtained by the function conversion unit.
165. A copyright protection system for securely transmitting a digital work via a storage medium or a transmission medium, comprising:
the encryption apparatus according to claim 103; and
a decryption apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, the attribute value, the encrypted digital work, and the medium identification information;
a first secret key storage unit operable to store the first secret key;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the first secret key stored in the first secret key storage unit, by entering said information and key into a one-way function;
a modification unit operable to modify a function value obtained by the function conversion unit, using the attribute value modified by the modification unit; and
a first decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the attribute value modified by the modification unit.
166. A copyright protection system for securely transmitting a digital work via a storage medium or a transmission medium, comprising:
the encryption apparatus according to claim 104; and
a decryption apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, the attribute value, the encrypted digital work, an encrypted first secret key generated by encrypting the first secret key, and an encrypted third secret key generated by encrypting the third secret key;
a second secret key storage unit operable to store a second secret key;
a modification unit operable to modify the second secret key stored in the second secret key storage unit, using the attribute value obtained by the obtainment unit;
a first decryption unit operable to decrypt the encrypted third secret key obtained by the obtainment unit, using the second secret key modified by the modification unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the third secret key decrypted by the first decryption unit; and
a third decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the first secret key decrypted by the second decryption unit.
167. A copyright protection system for securely transmitting a digital work via a storage medium or a transmission medium, comprising:
the encryption apparatus according to claim 108; and
a decryption apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, the attribute value, the encrypted digital work, an encrypted first secret key generated by encrypting the first secret key, an encrypted third secret key generated by encrypting the third secret key;
a second secret key storage unit operable to store the second secret key;
a first decryption unit operable to decrypt the encrypted third secret key obtained by the obtainment unit, using the second secret key stored in the third secret key storage unit;
a modification unit operable to modify the third secret key decrypted by the first decryption unit, using the attribute value obtained by the obtainment unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the second secret key modified by the modification unit; and
a third decryption unit operable to decrypt the encrypted digital work obtained by the obtainment, using the first secret key decrypted by the second decryption unit.
168. A copyright protection system for securely transmitting a digital work via a storage medium or a transmission medium, comprising:
the encryption apparatus according to claim 109; and
a decryption apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, the attribute value, the encrypted digital work, an encrypted first secret key generated by encrypting the first secret key, an encrypted third secret key generated by encrypting the third secret key used for the encryption of the first secret key;
a second secret key storage unit operable to store the second secret key;
a first decryption unit operable to decrypt the encrypted third secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the third secret key decrypted by the first decryption unit;
a modification unit operable to modify the first secret key decrypted by the second decryption unit, using the attribute value obtained by the obtainment unit; and
a third decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the first secret key modified by the modification unit.
169. A copyright protection system for securely transmitting a digital work via a storage medium or a transmission medium, comprising:
the encryption apparatus according to claim 110; and
a decryption apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, the attribute value, the encrypted digital work, an encrypted first secret key generated by encrypting the first secret key, and an encrypted fourth secret key generated by encrypting the fourth secret key;
a second secret key storage unit operable to store the second secret key;
a first decryption unit operable to decrypt the encrypted fourth secret key obtained by the obtainment unit, using the second secret key stored in the second secret key storage unit;
a second decryption unit operable to decrypt the encrypted first secret key obtained by the obtainment unit, using the fourth secret key decrypted by the first decryption unit;
a secret key generation unit operable to generate a fifth secret key for decrypting the encrypted digital work, based on the first secret key decrypted by the second decryption unit and the attribute value obtained by the obtainment unit; and
a third decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the fifth secret key generated by the secret key generation unit.
170. A copyright protection system for securely transmitting a digital work via a storage medium or a transmission medium, comprising:
the encryption apparatus according to claim 112; and
a decryption apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, the attribute value, the encrypted digital work, the medium identification information, and an encrypted second secret key generated by encrypting the second secret key;
a first secret key storage unit operable to store the first secret key;
a modification unit operable to modify the first secret key stored in the first secret key storage unit, using the attribute value obtained by the obtainment unit;
a first decryption unit operable to decrypt the encrypted second secret key obtained by the obtainment unit, using the first secret key modified by the modification unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the second secret key decrypted by the first decryption unit, by entering said information and key into a one-way function; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit using a function value obtained by the function conversion unit.
171. A copyright protection system for securely transmitting a digital work via a storage medium or a transmission medium, comprising:
the encryption apparatus according to claim 116; and
a decryption apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, the attribute value, the encrypted digital work, the medium identification information, and an encrypted second secret key generated by encrypting the second secret key;
a first secret key storage unit operable to store the first secret key specific to the decryption apparatus;
a first decryption unit operable to decrypt the encrypted second secret key obtained by the obtainment unit, using the first secret key stored in the first secret key storage unit;
a modification unit operable to modify the second secret key decrypted by the first decryption unit, using the attribute value obtained by the obtainment unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the attribute value modified by the modification unit, by entering said information and value to a one-way function; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using a function value obtained by the function conversion unit.
172. A copyright protection system for securely transmitting a digital work via a storage medium or a transmission medium, comprising:
the encryption apparatus according to claim 117; and
a decryption apparatus comprising:
an obtainment unit operable to obtain, via the storage medium or the transmission medium, the attribute value, the encrypted digital work, the medium identification information used for encrypting a digital work, and an encrypted second secret key generated by encrypting the second secret key;
a first secret key storage unit operable to store the first secret key;
a first decryption unit operable to decrypt the encrypted second secret key obtained by the obtainment unit, using the first secret key stored in the first secret key storage unit;
a function conversion unit operable to convert the medium identification information obtained by the obtainment unit and the second secret key decrypted by the first decryption unit, by entering said information and key into a one-way function;
a modification unit operable to modify a function value obtained by the function conversion unit, using the attribute value obtained by the obtainment unit; and
a second decryption unit operable to decrypt the encrypted digital work obtained by the obtainment unit, using the function value modified by the modification unit.
173. An encryption method for an encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the method comprising:
repeating, for a first through (n-1)th (n is 2 or greater) secret keys, a sequence of encrypting a digital work using a first secret key out of n secret keys, and encrypting an (i-1)th (2\u2266i\u2266n) secret key using an i th secret key;
outputting the encrypted first through (n-1)th secret keys to either of the mediums;
modifying a secret key, prior to encryption, using an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, in the case where at least one of the first through (n-1)th secret keys is used in the encryption; and
outputting the attribute value to the medium.
174. An encryption method for an encryption apparatus that encrypts a digital work and outputs the encrypted digital work to a storage medium or a transmission medium, the method comprising:
repeating, for a first through an (n-1)th (n is 1 or greater) secret keys, a sequence of encrypting a digital work using the converted medium identification information after converting medium identification information by one-way function using the first secret key out of n secret keys, and encrypting an (i-1)th (2\u2266i\u2266n) secret key using an i th secret key, in the case where n is 2 or greater;
outputting the encrypted first through (n-1)th secret keys to the either of the mediums;
modifying, prior to encryption or conversion, (i) a secret key, using an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, or (ii) the medium identification information obtained in the conversion, using the attribute value, in the case where at least one of the first through n th secret keys is used in the encryption or the conversion; and
outputting the attribute value to the medium.
175. A decryption method for a decryption apparatus that decrypts an encrypted digital work, the method comprising:
repeating, for n (n is 2 or greater) encrypted secret keys, a sequence of decrypting, using a pre-hold secret key, a first encrypted secret key out of said n encrypted secret keys, after obtaining, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, an encrypted digital work, and said n encrypted secret keys, and decrypting a second encrypted secret key using the first encrypted secret key obtained as a result of the decryption;
decrypting a digital work using the n th secret key obtained in the last decryption; and
modifying, prior to decryption, a secret key to be used for the decryption, using the attribute value, for at least one of the decryptions performed on the first through n th encrypted secret keys.
176. A decryption method for a decryption apparatus that decrypts an encrypted digital work, the method comprising:
repeating, for n (n is 1 or greater) encrypted secret keys, a sequence of decrypting, using a pre-hold secret key, a first encrypted secret key out of said n encrypted secret keys, after obtaining, via a storage medium or a transmission medium, the following: an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates; an encrypted digital work; medium identification information; and said n encrypted secret keys, and decrypting a second encrypted secret key using a first secret key obtained in the decryption, in the case where said n is 2 or greater, converting the medium identification information by one-way function using the n th secret key obtained in the last decryption;
decrypting a digital work using the converted medium identification information; and
modifying, prior to decryption or conversion, (i) a secret key to be used for the decryption or the conversion, using the attribute value, or ii) the medium identification information obtained in the conversion, using the attribute value, in at least one of the following cases: a decryption performed on the first through n th encrypted secret keys; or a conversion performed on the medium identification information.
177. A secret key generation method for a secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the method comprising:
repeating, for n (n is 2 or greater) encrypted secret keys, a sequence of decrypting, using a pre-hold secret key, a first encrypted secret key out of said n encrypted secret keys, after obtaining, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates and said n encrypted secret keys, and decrypting a second encrypted secret key using the first secret key obtained in the decryption;
outputting the n th secret key obtained in the last decryption to the decryption apparatus; and
modifying, prior to decryption, a secret key to be used for the decryption, using the attribute value, for at least one of the decryptions performed on the first through n th encrypted secret keys.
178. A secret key generation method for a secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the method comprising:
repeating, for n (n is 1 or greater) encrypted secret keys, a sequence of decrypting, using a pre-hold secret key, a first encrypted secret key out of said n encrypted secret keys, after obtaining, via a storage medium or a transmission medium, an attribute value which depends on information in a certificate revocation list (CRL) that is a list of information for specifying revoked public key certificates, medium identification information, and said n encrypted secret keys and decrypting a second encrypted secret key using the first secret key obtained in the decryption, in the case where n is 2 or greater;
converting the medium identification information by one-way function using the n th secret key obtained in the last decryption;
outputting the converted medium identification information to the decryption apparatus; and
modifying, prior to decryption or conversion, (i) a secret key to be used for the decryption or the conversion, using the attribute value; or ii) the medium identification information obtained in the conversion, using the attribute value, in at least one of the following cases: a decryption performed on the first through n th encrypted secret keys; or a conversion performed on the medium identification information.
179. A program for an encryption apparatus that encrypts a digital work and outputs the encrypted digital work via a storage medium or a transmission medium, the program causing a computer to execute the steps in the encryption method according to claim 173.
180. A program for a decryption apparatus that obtains an encrypted digital work via a storage medium or a transmission medium, and decrypts the encrypted digital work, the program causing a computer to execute the step in the decryption method according to claim 175.
181. A program for a secret key generation apparatus that outputs a secret key for decryption to a decryption apparatus that decrypts an encrypted digital work, the program causing a computer to execute the step in the secret key generation method according to claim 177.
182. A storage medium for storing an encrypted digital work encrypted by an encryption apparatus that encrypts a digital work,
wherein the encryption apparatus includes:
a digital work storage unit operable to store a digital work;
a first secret key storage unit operable to store a first secret key used for the encryption of the digital work;
a second secret key storage unit operable to store a second secret key associated with a decryption apparatus that decrypts an encrypted digital work;
a certificate revocation list (CRL) storage unit operable to store a CRL that is a list of information for specifying revoked public key certificates;
an attribute value calculation unit operable to calculate an attribute value which depends on the information in the CRL, based on the CRL stored in the CRL storage unit;
a modification unit operable to modify the second secret key stored in the second secret key storage unit, using the attribute value calculated by the attribute value calculation unit;
a first encryption unit operable to encrypt the first secret key stored in the first secret key storage unit, using the second secret key modified by the modification unit;
a second encryption unit operable to encrypt the digital work stored in the digital work storage unit, using the first secret key stored in the first secret key storage unit; and
an output unit operable to output, to the storage medium, the CRL stored in the CRL storage unit, the attribute value calculated by the attribute value calculation unit, the first secret key encrypted by the first encryption unit, and the digital work encrypted by the second encryption unit, and
the CRL stored in the CRL storage unit, the attribute value calculated by the attribute value calculation unit, the first secret key encrypted by the first encryption unit, and the digital work encrypted by the second encryption unit are stored.
The claims below are in addition to those above.
All refrences to claim(s) which appear below refer to the numbering after this setence.

1. A baseboard for covering a flooring border, said baseboard having a longitudinally extending axis of symmetry, a first side with a first contour and a second oppositely situated side with a second contour, said first contour having a first edge region and a second edge region, said second contour having a first edge region and a second edge region, wherein said first edge region of said first contour, corresponds in shape to said second edge region of said second contour, and said first edge region of said second contour axis corresponds in shape to said second edge region of said first contour, such that said baseboard can be rotated 180\xb0 about said axis of symmetry so as to reverse position.
2. The baseboard as claimed in claim 1, wherein said first and second contour in said first edge region are curved to the same side.
3. The baseboard as claimed in claim 1, wherein said first and second contour in said first edge region are angled off to the same side.
4. The baseboard as claimed in claim 1, wherein at least one of said first and second contours has at least one slot for receiving an ornamental strip.
5. A connecting piece for a baseboard of the type having edge regions, said connecting piece having at least one side on which it, for connection to said baseboard, comprises a connecting region, said connecting region having a projection adapted to overlap a portion of said baseboard when the baseboard is received in said connecting region, further comprising holding pins situated opposite said projection, said baseboard being able to be held, solely in its edge regions, in clamping engagement between said projection and said holding pins.
6. The connecting piece as claimed in claim 5, wherein said holding pins are disposed one above the other.
7. The connecting piece as claimed in claim 5, wherein at least one stop face is provided between said projection and said holding pins.
8. The connecting piece as claimed in claim 5, wherein said projection can fully overlap said baseboard.
9. The connecting piece as claimed in claim 5, wherein said connecting piece has two stop regions, which are oriented in mutual alignment.
10. The connecting piece as claimed in claim 5, wherein said connecting piece has two stop regions, which are oriented at right angles to each other.
11. A connecting piece for a baseboard of the type having edge regions which respectively have recesses, said connecting piece having a axis of symmetry and at least one side on which it, for connection to said baseboard, comprises an upper and lower connecting region, wherein said connecting piece is configured in the form of a clip rail which can be fixed to a wall, the recessess of said baseboard being configured to fit said connecting regions of the connecting piece, and each of said connecting regions, rotated through 180\xb0 about said axis of symmetry, corresponding to said respectively other connecting region.