The invention relates to a device for recording data on a track of a record carrier, which record carrier comprises a first keylocker which holds information about the data and a second keylocker which holds the same information, which two keylockers are positioned adjacent to each other on the track, the device comprising invalidating means for invalidating the keylockers.
The invention further relates to a record carrier having a track for recording data, the record carrier comprising a first keylocker which holds information about the data and a second keylocker which holds the same information, the two keylockers being positioned adjacent to each other on the track.
The invention also relates to a method of recording data on a track of a record carrier, which record carrier comprises a first keylocker which holds information about the data and a second keylocker which holds the same information, the two keylockers being positioned adjacent to each other on the track, the method comprising a step of invalidating the keylockers.
As copying of data in the form of copyrighted material from one record carrier to an other becomes more and more easy, the need for proper protection of that data becomes greater. An example of a scheme to protect data uses a so-called keylocker. In a keylocker all secrets, for example usage rights, keys, counters, a unique identification of the disc or any information are stored in the keylocker in a tamper-free way. Usage rights may be, for example, the rights to play or copy the data on the record carrier. A keylocker is encrypted with a so-called keylocker key. It is common to have two or more identical copies of the keylocker on the record carrier. If one keylocker is damaged, the other keylocker can be used. The keylockers are commonly placed adjacent to each other.
An example of data that can be protected is music. The keylocker may contain the right to copy the music once. After a copy has been made, the keylocker is updated indicating that no more copy can be made. If the record carrier is a write once record carrier, or if the data is written on the record carrier in a similar way as with a write once record carrier, the updating of the keylocker is done by writing new keylockers and invalidating the old ones. On a write once record carrier, invalidating can be done by damaging the keylockers with a laser pulse having a sufficiently high power level. A problem with this invalidation is that also the data directly adjacent to the keylockers will be damaged or will be inaccessible. The directly adjacent data can be damaged when the data is written interleaved on the record carrier. Interleaved writing means that the data is not written continuously but in blocks, which blocks are written with a spacing between them. That spacing may be, for example, two or three blocks of other data. When data is invalidated, units of data are invalidated that do not coincide with the interleave blocks. Therefore also data adjacent to the keylocker is invalidated. The data directly adjacent to the keylocker may also become inaccessible when the keylocker is invalidated because of the following reason. When a device such as an optical recorder wants to access certain target data on the record carrier, it does not jump directly to the target address of that data, but to a previous address before the target address. This is done because the optical recorder then has time to settle before the target data is read. If the data on the previous address is invalidated, however, the target data is inaccessible.
It is an object of the invention to provide a device and method for recording data which is able to invalidate the keylockers without making the neighboring data inaccessible.
It is also an object of the invention to provide a record carrier which contains keylockers that can be invalidated without making the neighboring data inaccessible.
For this purpose, the device as described in the opening paragraph is characterized in that the invalidating means are able to invalidate the keylockers by invalidating an identical part of the information of the first keylocker and of the second keylocker, the information of the first keylocker being arranged differently from the information of the second keylocker in that the information that is to be invalidated of at least one keylocker is positioned closer to the other keylocker than in a situation in which the information of the keylockers is arranged identically. The record carrier described in the opening paragraph is characterized in that the keylockers can be invalidated by invalidating an identical part of the information of the first keylocker and of the second keylocker, the information of the first keylocker being arranged differently from the information of the second keylocker in that the information that is to be invalidated of at least one keylocker is positioned closer to the other keylocker than in a situation in which the information of the keylockers is arranged identically. The method described in the opening paragraph is characterized in that the step of invalidating the keylockers invalidates the keylockers by invalidating an identical part of the information of the first keylocker and of the second keylocker, the information of the first keylocker being arranged differently from the information of the second keylocker in that the information that is to be invalidated of at least one keylocker is positioned closer to the other keylocker than in a situation in which the information of the keylockers is arranged identically.
It is sufficient to invalidate only a part of the keylocker in order to disable the use of the keylocker. If the same part of all the keylockers is disabled, it is not possible to retrieve the whole keylocker. However, disabling of, for example, the first part of both keylockers will also disable the data preceding the first keylocker. Disabling the first part of the keylockers is preferable, because in practice the space reserved for the keylocker could be greater than the keylocker needs, resulting in the last part of the space reserved for the keylocker being unused. Disabling the last part would have the result that the information of the whole keylocker is still retrievable. If the first part of the first keylocker is arranged closer to the other, adjacent keylocker, then that first part is further away from the preceding data and the preceding data will not be damaged. This ensures a better integrity of the preceding data after invalidation. In an embodiment, the keylocker contains usage rights of the data. These rights may be, for example, the right to copy the data once.
In an embodiment of the recording device, the information that is to be deleted of the first keylocker is directly adjacent to the information that is to be deleted of the second keylocker. This has the advantage that the information that is to be deleted is as far as possible away from the data directly neighboring the keylockers, thereby minimizing the risk of making the neighboring data inaccessible.
In another embodiment, the information contained in the keylockers is divided into sectors. The part of the information that is to be invalidated preferably comprises the last sectors of the first keylocker and the first sectors of the second keylocker.
In a further embodiment, the record carrier comprises more than two keylockers which are adjacent to each other, and the first keylocker and the second keylocker are the two outermost keylockers. Here again the part of the information that is invalidated is further away from the neighboring data. The arrangement of the information of the keylockers between the first and second keylocker is not important in this connection.
These and other aspects of the invention will be apparent from and elucidated further with reference to the embodiments described by way of example in the following description and with reference to the accompanying drawings, in which
a shows an example of two identical keylockers,
b shows another example of two identical keylockers,
In
a and 3b show two examples of the keylockers 7 and 8 on a record carrier 1 according to the invention. In
Although the invention has been explained mainly with reference to embodiments of an optical recording device, similar embodiments of recording devices are suitable which have the characteristic that invalidation of data on the record carrier also damages data adjacent to the invalidated data. Also, an optical disc may be used for the record carrier, or other media such as a magnetic disc or tape may be used. It is noted that in this document the verb ‘comprise’ and its derived forms do not exclude the presence of other elements or steps than those listed, and the word ‘a’ or ‘an’ preceding an element does not exclude the presence of a plurality of such elements, that any reference signs do not limit the scope of the claims, that the invention may be implemented by means of both hardware and software, and that several ‘means’ may be represented by the same item of hardware. Further, the scope of the invention is not limited to the embodiments, and the invention lies in each and every novel feature or combination of features described above.
Number | Date | Country | Kind |
---|---|---|---|
02076644.0 | Apr 2002 | EP | regional |
Filing Document | Filing Date | Country | Kind | 371c Date |
---|---|---|---|---|
PCT/IB03/01381 | 4/4/2003 | WO | 10/20/2004 |