Security and Business Models for Virtual Goods Uwe Muster Hamburg ACM Multimedia Security Workshop 6 December 2002 Juan le Pin, France Prof. Dr. Rüdiger Grimm TU Ilmenau R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 1 Content Virtual goods Cost of digital goods Busines models for virtual goods IPMP / Lightweight model Alternative Potato model Applications, challenges References R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 2 Seite 1 1
Life cycle of goods Creation Production Reproduction Distribution Consumption Satisfaction Product value Usage value Cheaper for digital goods R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 3 e.g., Music in the Internet: digital good Digital: one form of virtuality Special properties: Lossless separation from medium Re-binding to other media Repeatable by free choice of user R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 4 Seite 2 2
Production / Communication / Consumption of digital goods code (reduction) interpretation (enrichment 011101000100101001 111010010000100110 transfer/storage (lossless) 011101000100101001 111010010000100110 R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 5 Cost Production of media is expensive Sales of products is expensive Investing into end-user devices is expensive Infrastructure of end-user devices is available Infrastructure of communication is available Consumption of products is cheap Communication of products is cheap Reproduction of products is cheap R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 6 Seite 3 3
Cost per-piece= Product value/euro Degression of costperpiece for virtual goods 10.000 Cost for total production 1000 100 10 1 0,1 0,01 1 10 100 1.000 10.000 100.000 1 Mio. 10 Mio. Final cost of additional piece almost zero Number of pieces sold R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 7 Busines models for virtual goods IntellectualProperty Management & Protection (IPMP) Central control of usage by provider Policy of rights Restriction of users through policies Technical basis (full IPMP): IPMP-Tools (control of users) Technical basis (light-weight): signatures (traces) Friendly File-Sharing ( Potato ) Decentralizes sales model Policy of provisions Users are free to use, but they earn provision only if they pay Technical basis: sales receipt (TAN in file name) R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 8 Seite 4 4
IPMP: CP-centric model Content Provider Specifies rights Sells content Controls usage User executes rights of usage User executes rights of usage User executes rights of usage User executes rights of usage R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 9 Critical comments on IPMP/DRM 1. Conflict between interest and enforcement 2. CP-centric view of policies 3. Burden of enforcement on the user equipment 4. Enforcement vs. identification of rights 5. Interoperability 6. Scalability 7. Privacy 8. Negotiation of policies R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 10 Seite 5 5
LWDRM light-weight model Re 4: enforcement vs. identification : There is no unsigned content in clear in the network By consuming a file, its origin is verified By distributing a file, it is signed Method: signcryption (recoverable signature) R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 11 Role of content provider (BMG, Sony,...) Files CDs Provider Transfer specify / sell / control R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 12 Seite 6 6
Role of content provider (II) Napster Provider Files R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 13 Role of content provider (III) Napster controls Provider Gnutella Files R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 14 Seite 7 7
Conflict of interests Users are interested in re-distribution Users have power to re-distribute Providers are interested in re-distribution Providers want money Solution???: Providers prevent users from re-distribution - Pursue of users - Criminalization of users R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 15 Cooperation of interests Users are interested in re-distribution Users havepower to re-distribute Providers are interested in re-distribution Providers want money Solution: Providers support users to re-distribute Users earn share of income (provision) R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 16 Seite 8 8
Fred creates content and Ginnie buys content Fred Music Provider 3 Ginny likes to listen to Fred s music MySong4fo21.mp3 MySong.mp3 2 Fred adds TAN=21 to file name Fred registers MySong 1 TAN=21 Fred offers his music to many users Ginny presents TAN=21 and pays for the music TAN=53 4 MySong4fo21.mp3 MySong4fo53.mp3 Ginny adds TAN=53 to file name 5 Fred receives share as author Accounting Server R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 17 Content files are registered in (distributed) accounting centers Fred (composer, author) creates content file (1) Fred registers content file at Accounting Service of Bill und recieves TAN (add to file name) (2) Fred distributes his file in the Internet (3)Ginnie receives file from anywhere (e.g., from Fred) R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 18 Seite 9 9
Payment = right to receive a provision (3)Ginnie receives file from anywhere (e.g., from Fred) (4) Ginnie pays for the file at Bill s and recieves a receipt (her own TAN to be added to file name) (5) Bill pays Fred (6) Ginnie distributes the file in the Internet R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 19 Ginnie copies content to Harry Ginny loves Fred s music Fred Music Provider MySong4fo53.mp3 Ginny receives provision 9 Fred receives share as author 6 Ginny copies Fred s music to Harry and toother friends Harry presents TAN=53 and pays for the file Harry shares Ginnies enthusiam for Fred s music TAN=71 7 MySong4fo53.mp3 MySong4fo71.mp3 Harry adds TAN=71 To file name 8 Accounting Server R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 20 Seite 10 10
Payment= right to receive aprovision (6) Ginnie copies file to Harry (Harry is free to pay or not) (7) In caseharry pays, then he receives his own TAN (to be added to file name, (8) then Fred receives his share as an author (9) and then Ginny receives her share as provision (6) Harry re-distributes his file... R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 21 Pretty Good Distribution Users can earn more money than they pay Users who do not pay, are free to consume and redistribute Re-distribution without payment supports former payer Re-distribution supports marketing Alternative structure of distribution bottom-up For friends only (name of an Ilmenau spin-off) Open source in www.4fo.de R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 22 Seite 11 11
Applications Music marketing Music of young groups / composers Radio / TV broadcast Conference papers (authors want to keep right of distribution) Levels in games of different authors Community and re-distribution services (Ginnie has the best pieces, so we look for products at Ginnie s server) R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 23 Challenges Accounting protocol Central names and file register vs. de-central receipts Electronic payment (e.g., Paybest) Integrity of origin (Audio-Id, water marks?) Models of provision Models of receipts Roll of a PKI (needed anyway?) Establishment of accounting services R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 24 Seite 12 12
References [1] Angelo Sotira: Step 1 What is Gnutella? In: http://www.gnutella.com, 3 Dec 2001. Adam T. Lindsay, Jürgen Herre: MPEG-7 and MPEG -7 Audio An Overview. Journal of the AES, June/July 2001. [2] Allamanche, E.; Herre, J.; Hellmuth, O.; Fröba, B.; Cremer, M.: AudioID: Towards Content-Based Identification of Audio Material. In 110th AES-Convention, Amsterdam, 2001. Convention Paper 5380 [3] IPMP Ad-hoc Group, ISO/IEC JTC 1/SC 29/WG11: Coding of Moving Pictures and Audio. Study of Text of PDAM ISO/IEC 14496-1:2001, Dec 2001. [4] G. Spenger, C.C. Bürgel: MPEG-21: Der Schlüssel zu Multimedia. DuD 5/2002. [5] Grimm, R.; Nützel, J.: Geschäftsmodelle für virtuelle Waren. DuD 5/2002. [6] 3GPP TS 22.242 V6.0.0 (2002-06). Digital Rights Management (DRM) Stage 1, Release 6, June 2002. [7] Neubauer, Ch.; Pickel, J.; Brandenburg, K.; Siebenhaar, F.: Aspekte des Rechtemanagements für digitale Güter, 22. Tonmeistertagung, Hannover, November 2002, VDT. [8] Nützel J.; Grimm R.; Puchta S.: Musik im Internet Wie kann man eine Ware verkaufen, die alle schon haben? 22. Tonmeistertagung, Hannover, November 2002, VDT. http://www.4fo.de http://www.4friendsonly.com R. Grimm, TU Ilmenau, Dec 2002 Virtual Goods 25 Seite 13 13