Rights Management and Security in the Electronic Library

Laura Challman Anderson, Jeffrey B. Lotspiech · Bulletin of the American Society for Information Science and Technology · 1995

Developing a technical solution to manage intellectual property rights is a cornerstone in the Electronic Library Project, a collaborative effort between the Institute for Scientific Information (ISI) and the IBM Digital Library group at the Almaden Research Center. Our system incorporates mechanisms that protect the information content owners (e.g., publishers), as well as the end-users of the system. Techniques to ensure information integrity, assurances of the authenticity of journal articles, confidentiality of usage data and management of copyright are detailed. General security features are also presented. The term rights management refers to the process of honoring those copyright provisions, license terms and usage agreements established by the owners of intellectual property (in this case, publishers of scholarly journals). The term security refers to the controls that determine who can access information in the system, how the information is stored and who can perform operations on the information, such as modifying it. Rights management and security mechanisms are critical components of any digital library containing copyrighted or proprietary information. The challenge is to embed these controls in the system in an artful way. Our goal is a system that enforces policies established by the content owners (for example, limits access only to authorized use) without apparent and heavy-handed security. Researchers at the IBM Almaden Research Center in San Jose, along with the technical personnel at the Institute for Scientific Information in Philadelphia, are working together to deploy a responsive system, implemented on a variety of client platforms, which effectively manages a subset of copyrighted scientific literature. In the print publishing world, the limitations of the medium largely dictate the enforcement of copyright. The intellectual property controls cannot be "tuned" or adjusted. The most effective inhibitors are pragmatic issues, such as loss of quality during reproduction (for example, photocopying) and the time, expense and inconvenience involved. Copyright law and personal ethics are additional inhibiting factors that span both print and electronic media. Clearly the print context does not provide absolute enforcement of rights by the owners of content. However, it is at least a familiar environment where the risks are known, and the scope of federal protection is clear. The test of the electronic media is to be no less secure at a minimum. Providing access to copyrighted material in an electronic environment might be viewed with alarm. Certainly, if no security measures are put in place, the situation in essence enables a convenient, limitless, perfect copier on every user's desktop, with potential access to many terabytes of data. However, one can also see in the digital context the chance to leapfrog the limitations of paper and to improve the management of copyrights. Ideally, the best technical approach would be to design a system that can enforce owner policies on a level of fine granularity. This is the approach adopted for this system. ISI's Electronic Library Project is based on an economic model that makes subscription-based pricing a significant component. After publishers set the fees for electronic versions of their print journals and for the number of copies that can be printed from each issue, each library selects a set of electronic journal subscriptions. The options available for printing illustrate the granularity and flexibility that is available. The system allows specification of one of the following options for journal articles: no printing at all; printing only on a secured printer which is attached to the local library server; or printing on any printer device to which the end-user has access. Another dimension of improvement in the electronic realm is in addressing the manual and labor-intensive task of copyright management in libraries. This system enforces copyright and licensing terms established by the participating publishers. We know that traditional security mechanisms alone are not granular enough for the transaction-based object model of an electronic library. For example, traditional access control dictates what sort of access a user has against a database, but does not dynamically count the number of times users have printed a particular article. A digital system provides the capability of managing attributes of the user dimension as entities. Examples of this are user authentication, providing access control by user against an object store and providing different levels of authority against objects by user. In the same way, objects have unique properties ranging from how they are stored, what access users have against them and the types of operations that can be performed on them. Audit spans both of the dimensions, providing detailed transaction information about entities in both the user and object worlds. Taken together, these give the electronic environment much greater functional control than exists today in the print world. 1 Security Dimensions In the ISI Electronic Library Project, we are hoping to explore the dynamics of security mechanisms in the context of usability of the system. As illustrated in the accompanying graph, if security is very low, the flow of information can also be low because the information providers do not trust the channel; they may not be able to recover the costs of producing the information due to illegal copying. On the other hand, if security functions are heavy, pervasive, and unwieldy, they can also negatively inhibit the flow of information by affecting system usability. For example, the requirement for multiple entry of a password disrupts and interrupts the thought process and workflow of a user. Security vs. Information Flow Let's apply that balance to the problem of printing documents from a digital library. The most convenient printer for a user is probably the printer or printers used for normal computer printing. The concern of the content owner, however, might be that the "printer" that the user chooses to print on may not be a printer at all, but a device that is capturing the stream of bits. Thus, we see the interests of these two parties (at least potentially) at odds with one another. Somewhere along this curve, there is the "right" balance, and by piloting the system with real users, we will be able to measure the impact of various security mechanismson usability. Before a detailed description is given of how the security and rights management controls are implemented, a discussion of the technical context of these mechanisms is necessary. The IBMASI Electronic Library Project Team has implemented a two server hierarchy, where the central "source" server is located at ISI in Philadelphia. This server communicates with a local library server—installed by ISI—at each pilot site location. The local library server is an OS/2 server located in a secure physical environment, and is running only the OS/2 operating system, Lotus Notes server and ISI's Electronic Library system code. The central server and library servers constitute a trusted server environment, with key exchange at system boot time used for encryption in transmissions between them. Clients are on Windows, Macintosh, AIX and OS/2 platforms. Clients run a Lotus Notes client and application, as well as a custom viewer. There is session encryption between each client and the library server. User authentication is accomplished through Lotus Notes. Bibliographic data in the system is stored in Lotus Notes databases, and the article pages of the journals are stored as image files that are encrypted until they are prepared for viewing in the memory of the client workstation. 3 System Architecture The security and rights management capabilities of the system are enabled by one or more of the system components described above (client, local server, central server). Secure viewing is enabled by both user authentication and session encryption. A user must enter a valid Lotus Notes password at the beginning of a session to open the ISI Electronic Library database. The additional control of session encryption between the client and the local server guarantees that the transmission is secure. Secure printing is enabled by the custom viewer, tiered server architecture, and hidden and visible watermarking. The viewer enforces the policy set by the content owner. If printing is not allowed at all, the print button is disabled on the client display. If only server printing is allowed, that is reflected as an available option on the client menu. The tiered server architecture provides the option of a printer that is driven directly by the local library server that is harder to subvert due to the secure physical environment. Additionally, a visible watermark is placed on the first page of each article printed, encoding 1000 bits of information (such as user, server name, date) in a two-dimensional bar-code. If a document does not contain this barcode, we know it has not been printed through approved channels in the system. An example of this barcode and the accompanying copyright statement for a journal published by S. Karger Ag is illustrated on this page. Copyright Statement and Visible Watermark Authenticity of documents is guaranteed by a digitally signed fingerprint. This is a two-part test: first, the fingerprint must match the source document, and then it must be correctly signed. If both of these tests are not passed successfully,the viewer will not display the article. This mechanism is a powerful protection for the end user of the information and data in the journal literature. Unauthorized duplication is discouraged by placement of a hidden watermark in the image file of each page of a journal article. An electronic copy of a journal article page can be compared to the original watermark to determine its point of origination. Copyright management is implemented by recognizing electronic subscriptions. Users can only view journal article pages for the journals to which their library subscribes. Additionally, a copyright notice is placed on the first page of each journal article, serving to raise end-user awareness about their responsibilities in this area. Protecting the confidentiality of individual user usage records is an important feature of this system. Implementing session encryption to prevent knowledge gained by eavesdropping on the network is fundamental in accomplishing this. The system also provides the capability to remove user identity from usage records to prevent us or anyone else from learning about what any individual is reading. No record is kept anywhere of who read what article. This is a critical issue in personal privacy, as well as corporate and academic research. We are "taking the high road" in managing the user's data in this system, and our expectation is that the users of the system will reciprocate and respect copyright laws and licensing guidelines. The system implemented for the ISI Electronic Library Project has control mechanisms built into every major system component. Scheduled to be tested at eight sites in North America and Europe, the aggregate usage statistics collected during the pilot will provide the opportunity to learn about the relationship between these controls and system usability and usage. Special thanks go to the extended technical team working on the Electronic Library Project at the IBM Almaden Research Center: Alan Bell, Steve Boyer, David Choy, Dick Dievendorff, Tom Griffin, Bruce Hoenig, Ray Holland, Mark Jackson, Waziri Kaka, Vi Ma, Jim McCrossin, Alex Miller, Robert Morris, Steve Newell, Norm Pass, Florian Pestom and Deidra Picciano; at ISI: Sina Adibi, Helen Atkins, Isabel Czech, Michael Fishkow, Blaine Johnston, Frank Licata, Keith MacGregor, Dave Pedrick, Jacqueline Trolley and Bernadette Williams; and at IBM Digital Library: Willy Chin and Jonathan Prial.

Read the paper · More papers on PaperTik