详细信息    本馆镜像全文|  推荐本文 |  |   获取CNKI官网全文
     首先,针对现有数字版权管理体系框架多局限于对己授权用户权利的使用控制,缺乏对版权证明和侵权认定等机制描述的问题,基于学习资源生命周期的概念,提出一个学习资源数字权利管理(LRDRM)体系框架。与现有的如OpenDRM、OMA DRM、Imprimatur等体系框架相比,LRDRM框架能够有效覆盖数字化学习资源生命周期全过程,并涵盖了版权证明和侵权认定等必要功能。
     第三,针对现有学习资源访问控制机制中授权多基于传统访问控制策略,存在无法进行细粒度授权、使用控制过程缺乏可持续性等问题,参考Ravi Sandhu等人提出的UCONABC使用控制模型,提出一个基于属性和策略的使用控制模型AP-UCON及相应的执行机制。其创新性体现如下:(1)与传统的访问控制和UCONABC使用控制模型相比,AP-UCON模型增加了权利属性要素,并在条件决策因子中加入了例外(Exception)要素,用于描述合理使用、例外授权等在公共知识领域不可避免的版权获取方式。(2)针对可重用的学习资源在创建阶段的嵌套式封装可能带来的安全策略冲突问题,提出了适用的冲突检测方法和一致性策略创建算法。(3)基于AP-UCON模型,参考引用监控机的思想,提出了AP-UCON引擎机制。该机制采用模块化设计,基于属性和安全策略进行授权决策,能够实现细粒度的动态授权和数字权利的可持续使用控制。
With the further development of education informationization, the copyright protection issues of digital learning resources have become an urgent problem to be solved. Rights management for learning resources is an innovative application of digital rights management technology. With the help of technological tools, we can put intellectual property laws and various copyright protocols into effect, and also provide much more effective and reasonable protection for quality learning resources. All those could help the copyright holders and the legal users to protect their lawful rights and interests.
     Due to the limitations of the digital rights management technology, along with the new challenges brought by the domain characteristics of education reality, new digital rights management mechanisms for education application area are need to be studied.
     Based on our project research work and amounts of research literature references, this dissertation takes an in-depth research on digital rights management key mechanisms for learning resources, which include:(1) research on learning resources digital rights management architecture framework and functional structure;(2) research on rights management-enabled content information model and secure packaging mechanism for learning resources;(3) research on digital rights usage control mechanism for learning resources;(4) research on copyright identification and usage tracing protocols for learning resources;(5) design and implementation of digital rights management system for learning resources. The research focuses of this dissertation are digital rights usage control mechanism and copyrights identification and usage tracing protocols.
     This dissertation conducts a series of research and has obtained the following innovative achievements:
     First of all, since most of existing digital rights management architecture frameworks focus on the usage control of authorized user's rights, which makes them lack of description and coverage of copyright identification functions. A novel concept of learning resource lifecycle was presented. And based on the concept, the learning resources digital rights management architecture framework and functional structure which can cover the whole learning resource lifecycle are proposed.
     Secondly, since the existing content packaging method barely support nested protection for learning resources, on the basis of learning object metadata (LOM) and content packaging (CP) standards, the rights management-enabled learning resources information model and secure packaging mechanism is studied. Unlike existing content packaging technique, the proposed mechanism can separately provide protection for each content item in a learning resource file. It is much more suitable for compounded, heterogeneous reusable learning resources, and could provide a secure foundation for flexible authorization of digital rights.
     Thirdly, since most of existing learning resources access control mechanisms are based on traditional access control policy which can't provide fine-grained authorization and the usage processes are lack of persistent control, Based on Ravi Sandhu's UCONABC model, an attribute-policy based usage control (AP-UCON) model and its enforcement mechanism is proposed. The innovative achievement are as follows:(1) The "oBligation" factor is combined into the "Condition" decision factor, and the "Exception" factor is introduced into the model to describe the "fair use" use case, which is quite common in education research field;(2) The security policy confliction problems brought by the nested packaging of learning resources in the content creation stage are analyzed, and a consistent policy creation algorithm is presented;(3) Based on the concept of reference monitor, an AP-UCON client engine mechanism is proposed, which is proved to be very useful to perform the authorization decision and digital rights usage control enforcement.
     Then, to resolve the piracy and illegal usage issues of learning resources, a series of learning resource copyright ownership identification (CIOP) and usage tracing (UTP) protocols are proposed. Beyond the basic security objectives of security protocol, the proposed protocol mechanism has the following innovative achievement:(1) In the CIOP protocol, a trusted third party embeds robust copyright watermark into learning resources work in the creation/publishing stage with the help of timestamp scheme, to make sure that even the watermark is removed, the copyright ownership can still be identified and proved;(2) In the UTP protocol, user's digital fingerprint is added to a copy of learning resources work in the distribution stage. To ensure honest user's anonymity and traitor's traceability, a new anonymous public-private key pair is presented and the performance is improved.
     Finally, several digital rights management system tools are designed and implemented based on the researches mentioned above, and the secure mechanisms of those system tools and discussed.
     The research achievements can be used in e-Learning, digital libraries, knowledge management, e-commerce and other information content services areas, and is conducive to the establishment of lifelong education services platform with digital rights management services.
    [12]Creative Commons项目主页[EB/OL]. http://creativecommons.org/.
    [14]Danny Bradbury. Decoding digital rights management[J]. Computers & Security,2007 (1): 31-33.
    [15]Wenjun Zeng, Ching-Yung Lin, Heather Yu. Multimedia Security Technologies for Digital Rights Management[M]. Elsevier.2006.
    [16]Windows Media Rights Manager 10 SDK[EB/OL]. http://msdn.microsoft.com/en-us/library/ ms986509.aspx.
    [17]Jan De Clercq. Windows Server 2003 Security Infrastructures[J]. Digital Press.2006.
    [18]Olin Sibert, David Bernstein, David Van Wie. DigiBox:a self-protecting container for information commerce[C]. Proceedings of the 1st conference on USENIX Workshop on Electronic Commerce.1995 (7):1-15.
    [19]IBM'EMMS[CP/OL]. http://www.almaden.ibm.com/cs/madison.html.
    [20]Adobe digital rights management (DRM) solutions [EB/OL]. http://www.adobe.com/manufacturing/resources/drm/.
    [22]Undergraduate Students' Perception of Copyright Infringement:A Case Study of the University of Ibadan, Oyo State, Nigeria. Library Philosophy and Practice 2012, http://www.webpages.uidaho.edu/-mbolin/isiakpona.htm.
    [24]Heeyoul Kim, Younho Lee, Yongsu Park. A robust and flexible digital rights management system for home networks [J]. Journal of Systems and Software,2010 (12):2431-2440.
    [27]John S. Erickson. OpenDRM:A standards framework for digital rights expression, messaging and enforcement[EB/OL]. http://personal.hpl.hp.com/joheri/opendrm_project.htm.
    [28]Nicholas P. Sheppard. On Implementing MPEG-21 Intellectual Property Management and Protection[C]. ACM workshop on Digital Rights Management.2007:10-22.
    [29]OpenIPMP project[EB/OL]. http://sourceforge.net/projects/openipmp/.
    [30]Microsoft PlayReady[EB/OL]. http://www.microsoft.com/playready/.2010.
    [31]OMA Digital Rights Management Specification V2.2[S]. http://www.openmobilealliance.org.2011.
    [32]魏景芝,杨义先,钮心忻OMA DRM技术体系研究综述[J].电子与信息学报,2008(3):746-751.
    [33]X.M. Zhang, Q. Liu, H.Q. Wang, Ontologies for intellectual property rights protection, Expert Systems with Applications, Volume 39, Issue 1, January 2012, Pages 1388-1400
    [34]Chia-Chi Wu, Chia-Chen Lin, Chin-Chen Chang. Digital rights management for multimedia content over 3G mobile networks[J]. Expert Systems with Applications,2010 (10):6787-6797.
    [35]Adobe LiveCycle Rights Management ES2 technology[EB/OL]. http://www.adobe.com/.
    [37]Microsoft Digital Rights Management License Protocol Specification[S]. http://msdn.microsoft.com.2008.
    [38]Anil Jain, Umut Uludag. Multimedia Security Technologies for Digital Rights Management[M]. Academic Press.2006.
    [39]Florian Kelbert, Alexander Pretschner. Towards a policy enforcement infrastructure for distributed usage control[C]. The 17th ACM symposium on Access Control Models and Technologies,2012:119-122.
    [40]Prachi Kumari, Alexander Pretschner. Deriving implementation-level policies for usage control enforcement[C]. The 2nd ACM conference on Data and Application Security and Privacy,2012: 83-94.
    [41]Zhiyong Zhang, Qingqi Pei, Jianfeng Ma et al. Security and trust in digital rights management: A survey [J]. International Journal of Network Security,2009 (3):247-263.
    [42]Pramod A. Jamkhedkar, Gregory L. Heileman. A formal conceptual model for rights[C]. The 8th ACM workshop on Digital rights management (DRM'08),2008:29-38.
    [43]Nicholas P. Sheppard, Reihaneh Safavi-Naini. On the operational semantics of rights expression languages[C]. The 9th ACM workshop on Digital rights management,2009:09-10.
    [44]Kunihiko Fujita, Yasuyuki Tsukada. An analysis of interoperability between licenses[C]. the 10th annual ACM workshop on Digital rights management (DRM'10),2010:61-72.
    [45]eXtensible rights Markup Language (XrML) 2.0 Specification[S]. ContentGuard Inc.
    [46]M.Usama, M. Sobh. Software Copy Protection and Licensing based on XrML and PKCS#11[J]. Communications, Computers and Signal Processing,2011 (05):856-861.
    [47]Open Digital Rights Language (ODRL) version 2.0 [EB/OL], http://www.w3.org/community/odrl/.
    [48]Dongyang Xu, Zhi Tang; Yinyan Yu. An extended rights expression model supporting dynamic digital rights management[C]. The 7th International Conference on Information Assurance and Security,2011:186-191.
    [49]Xin Wang, T.DeMartini, B.Wragg. The MPEG-21 Rights Expression Language and Rights Data Dictionary[J]. IEEE Transactions on Multimedia,2005 (3):408-417.
    [50]Xin Wang. MPEG-21 Rights Expression Language:enabling interoperable digital rights management[J]. IEEE Multimedia,2004 (4):84-87.
    [51]Jaime Delgado, Victor Torres, Silvia Llorente et al. Rights Management in Architectures for Distributed Multimedia Content Applications[M]. TRUSTWORTHY INTERNET. Springer Verlag.2011:335-347.
    [52]Alapan Arnab, Andrew Hutchison. Persistent access control:a formal model for drm[C]. The ACM workshop on Digital Rights Management (DRM'07),2007:41-53.
    [53]Pramod A. Jamkhedkar, Gregory L. Heileman. A Formal Conceptual Model for Rights[C]. The 8th ACM Digital Rights Management Workshop.2008:29-38.
    [54]Christopher C. Lamb, Pramod A. Jamkhedkar, Mathew P. Bohnsack et al. A domain specific language for usage management[C]. the 11th annual ACM workshop on Digital rights management,2011:51-62.
    [55]Roberto Garcia, Rosa Gil, Jaime Delgado. A web ontologies framework for digital rights management[J]. Artificial Intelligence and Law,2007 (06):137-154.
    [56]Cheun Ngen Chong, Ricardo Corin, Jeroen Doumen et al. LicenseScript:a logical language for digital rights management[J]. Annals of Telecommunications,2006 (4):284-331.
    [57]Pramod A. Jamkhedkar, Gregory L. Heileman, Christopher C. Lamb. An interoperable usage management framework[C]. The 10th ACM workshop on Digital rights management,2010: 73-88.
    [58]Pramod A. Jamkhedkar, Gregory L. Heileman. Digital rights management architectures[J]. Computers & Electrical Engineering,2009 (2):376-394.
    [59]Nicholas Paul Sheppard, Reihaneh Safavi-Naini. On the operational semantics of rights expression languages[C]. The 9th ACM workshop on Digital rights management,2009:17-28.
    [60]Jaehong Park, Ravi S. Sandhu. The UCONABC usage control model. ACM Transaction on Information System Security[J],2004 (1):128-174.
    [61]Ravi S. Sandhu, Jaehong Park. Usage Control:A Vision for Next Generation Access Control[J]. Computer Network Security,2003:17-31.
    [62]Srijith K.Nair, Andrew S. Tanenbaum, Gabriela Gheorghe et al. Enforcing DRM policies across applications[C]. The 8th ACM workshop on Digital rights management,2008:87-94.
    [63]Alexander Pretschner, Manuel Hilty, Florian Schiitz et al. Usage Control Enforcement:Present and Future[J]. IEEE Security & Privacy,2008 (4):44-53.
    [66]Adam Muhlbauer, Reihaneh Safavi-Naini, Farzad Salim et al. Location constraints in digital rights management[J]. Computer Communications,2008 (04):1173-1180.
    [67]Pramod A. Jamkhedkar, Gregory L. Heileman. Digital rights management architectures[J]. Computers & Electrical Engineering,2009 (2):376-394.
    [69]Hao-hua Chu, Lintian Qiao, Klara Nahrstedt et al. A secure multicast protocol with copyright protection[J]. ACM SIGCOMM Computer Communication Review,2002 (2):42-60.
    [70]Yacine Gasmi, Ahmad-Reza Sadeghi et al. Flexible and secure enterprise rights management based on trusted virtual domains[C]. The 3rd ACM workshop on Scalable trusted computing, 2008 (10):71-80.
    [71]Chin Ling Chen. A secure and traceable E-DRM system based on mobile device[J]. Expert Systems with Applications,2008 (3):878-886.
    [72]Chung-Ming Ou, C.R. Ou. Adaptation of agent-based non-repudiation protocol to mobile digital right management (DRM)[J]. Expert Systems with Applications,2011 (9):11048-11054.
    [74]V. D.To, R.Safavi-Naini, F.Zhang. New traitor tracing schemes using bilinear map[C]. The 3rd ACM workshop on Digital rights management,2003:67-76.
    [78]J. Zhang, W. Kou, K. Fan. Secure buyer-seller watermarking protocol[C]. IEEE Proceedings of Information Security,2006 (1):15-18.
    [79]Raphael C. W. Phan, B. M. Goi, G. S. Poh. Analysis of a Buyer-Seller Watermarking Protocol for Trustworthy Purchasing of Digital Contents[J]. Wireless Personal Communictions,2011 (1): 73-83.
    [80]Tzung Her Chena, Gwoboa Horngb. A lightweight and anonymous copyright-protection protocol[J]. Computer Standards & Interfaces,2007 (02):229-237.
    [81]M. H. Shao. A Privacy-Preserving Buyer-Seller Watermarking Protocol with Semi-trust Third Party [J]. Trust, Privacy and Security in Digital Business.2007:44-53.
    [82]Kun Jiang, Xiaoming Wang. Anonymous and Traceable Copyright Protection Protocol based on Mobile Devices[J]. Computer Science,2012 (04):71-74.
    [83]N. Memon, P. W. Wong. A buyer-seller watermarking protocol[J]. IEEE Transactions on Image Processing,2001 (10):643-649.
    [84]H. S. Ju, H.Kim, D. H. Lee et al. An Anonymous Buyer-Seller Watermarking Protocol with Anonymity Control[J]. Information security and cryptology'02,2002:421-432.
    [85]C. L. Lei, P. L. Yu, P. L. Tsai et al. An efficient and anonymous buyer-seller watermarking protocol[J]. IEEE Transactions on Image Processing,2004 (13):1618-1626.
    [86]C. N. Fan, M. T. Chen, W. Z. Sun. Buyer-seller watermarking protocols with off-line trusted third parties[J]. International Journal of Ad Hoc and Ubiquitous Computing,2008 (1):36-43.
    [87]Renato Iannella. Digital rights management architectures[J]. D-Lib Magazine,2001 (06):1-6.
    [88]Eric Diehl. A Four-Layer Model for Security of Digital Rights Management [C]. The 8th ACM Workshop on Digital Rights Management (DRM'08),2008 (10):19-27.
    [89]Open Mobile Alliance DRM Architecture Version2.2 [EB/OL]. http://www.openmobilealliance.org/Technical/release_program/docs/DRM/V2_2-20110419-C/O MA-AD-DRM-V2_2-20110419-C.pdf
    [90]Imprimatur Business Model Version 2.1 [EB/OL]. http://www.imprimatur.net/.
    [91]Seong Oun Hwang, Ki Song Yoon, Kyung Pyo Jun et al. Modeling and implementation of digital rights[J]. The Journal of Systems and Software,2004 (3):533-549.
    [95]Wenjun Zeng, Shawmin Lei. Efficient frequency domain selective scrambling of digital video[J]. IEEE Transactions on Multimedia,2003 (1):118-129.
    [96]Chung-Ping Wu, C.-C. Jay Kuo. Design of Integrated Multimedia Compression and Encryption Systems[J]. IEEE Transactions on multimedia,2005 (10):828-839.
    [97]Susie J. Wee, John G. Apostolopoulos. Secure scalable streaming enabling transcoding without decryption[C]. International Conference on Image Processing'01,2001:437-440.
    [99]Dublin Core Metadata Element Set (Version 1.1) [S]. http://dublincore.org/documents/dces/.
    [100]Learning Resource Meta-data Specification Version 1.3[S]. http://www. imsproj ect.org/metadata/.
    [101]Microsoft Object Linking and Embedding (OLE) Data Structures[CB/OL]. http://msdn.microsoft.com/en-us/library/dd942265(v=prot.l0).aspx (2012.07).
    [102][RFC 2557]MIME Encapsulation of Aggregate Documents, such as HTML (MHTML)[EB/OL]. http://tools.ietf.org/html/rfc2557/.
    [103]IMS Content Packaging v1.2 Public Draft v2.0 specification[J]. http://www. imsglobal. org/content/packaging/.
    [104]Peter M. Benton. Packing Information for Superdistribution[EB/OL]. http://www.ibm.com/
    [106]ADL Sharable Content Object Reference Model (SCORM 2004)[S]. http://www.adlnet.org/.
    [107]OASIS eXtensible Access Control Markup Language Specification v2.0. http://xml.coverpages.org/xacml.html.
    [108]Information Technology-Multimedia Framework-Part 5:Rights Expression Language. ISO/IEC FDIS 21000-5:2003(E)[S]. http://mpeg.chiariglione.org/standards/mpeg-21/mpeg-21.htm.
    [109]Xerox Digital Property Rights Language[S]. http://xml.coverpages.org/dprl.html.
    [110]Norm Friesen, Magda Mourad, Robby Robson. Towards a Digital Rights Expression Language Standard for Learning Technology[R]. http://ltsc.ieee.org/wg4/.
    [111]Open Digital Rights Language Specification Version 2.0[S]. http://www.w3.org/community/odrl/.
    [113]Prados Jose, Rodriguez Eva, Delgado Jaime. Interoperability between different rights expression languages and protection mechanisms[C]. First International Conference on Automated Production of Cross Media Content for Multi-channel Distribution,2005,:145-152.
    [115]Xiaolei Qian, Teresa F. Lunt. A MAC Policy Framework for Multilevel Relational Databases[J]. IEEE Transactions on Knowledge and Data Engineering,1996 (1):3-15.
    [117]Catherine Jensen McCollum, Judith R. Messing, LouAnna Notargiacomo. Beyond the Pale of MAC and DAC--Defining New Forms of Access Control[C]. IEEE Symposium on Security and Privacy,1990:190-200.
    [118]David F.C. Brewer. Michael J. Nash. The Chinese Wall security policy[C]. IEEE Symposium on Security and Privacy,1989:206-214.
    [120]David F. Ferraiolo, Ravi Sandhu, Serban Gavrila et al. Proposed NIST standard for role-based access control[J]. ACM Transactions on Information System Security,2001 (3):224-274.
    [121]Liang Chen. Analyzing and Developing Role-Based Access Control Models[D]. University of London.2011.
    [123]Hung-Chang Lee, Shih-Hsin Chang. RBAC-Matrix-Based EMR Right Management System to Improve HIPAA Compliance[J]. Journal of Medical Systems,2012 (5):2981-2992.
    [125]Hanbing Yao, Heping Hu, Baohua Huang et al. Dynamic Role and Context-Based Access Control for Grid Applications[C]. The 6th International Conference on Parallel and Distributed Computing Applications and Technologies (PDCAT'05),2005:404-406.
    [126]E Bertino, AC Squicciarini, I Paloscia et al. Ws-AC:A fine grained access control system for web services[J]. World Wide Web,2006 (2):143-171.
    [127]R.K.Thomas, Ravi Sandhu. Task-based Authorization Controls (TBAC):A Family of Models for Active and Enterprise-oriented Authorization Management[C]. The IFIP WG11.3 Workshop on Database Security,1997:11-13.
    [129]Mohammad A.Al-Kahtani, R.Sandhu. Rule-Based RBAC with Negative Authorization[C].20th Annual Computer Security Applications Conference,2004:405-415.
    [130]Jaehong Park, Xinwen Zhang, Ravi Sandhu. Attribute Mutability in Usage Control[C]. IFIP International Federation for Information Processing,2004:15-29.
    [131]D.Basin, M.Harvan, F.Klaedtke et al. Monitoring Usage-Control Policies in Distributed Systems[C]. The 18th International Symposium on Temporal Representation and Reasoning, 2011:88-95.
    [132]G. R. Gangadharan, Vincenzo D'Andrea. Managing Copyrights and Moral Rights of Service-Based Software[J]. IEEE Software.2011(2):48-55.
    [133]Huijia Xie. Protecting fair use from digital rights management in china[C]. the 2007 ACM workshop on Digital Rights Management,2007:33-38.

© 2004-2018 中国地质图书馆版权所有 京ICP备05064691号 京公网安备11010802017129号

地址:北京市海淀区学院路29号 邮编:100083

电话:办公室:(+86 10)66554848;文献借阅、咨询服务、科技查新:66554700