I think that the report has not fully informed itself in the area of RELs, particularly with regard to the activities within MPEG-21 (Moving Pictures Experts Group Multimedia Framework initiative). In para 5.6.4, the concluding remarks of the chapter on technical aspects (Helberger et al. 2004, p. 92f) there is a significant factual error, which leads the reader to assume that XrML (eXtensible rights Markup Language) and the activity in MPEG are not connected. In fact they are, as XrML provided the baseline for the MPEG REL. Furthermore you refer to IPMP (Intellectual Property Management and Protection) as though it were a REL. It is not. IPMP covers all the activities that can be brought together generally under the DRM acronym.

MPEG went out of its way to avoid using the DRM tag, simply because it didn't want to be saddled with legacy thinking. The current MPEG-21, part 4 is now called "IPMP Components" and at present it provides tools to enable different proprietary DRM systems to talk to each other. Currently there is no intention within MPEG to specify any kind of security algorithm that could be used for encryption. The specification, at heart, is about messaging.

This brings me on to a wider point, which is the whole issue of your coverage of MPEG-21, which is not really very adequate. Over the five years since its beginning, MPEG-21 has specified a whole bunch of tools that could be used in combination to create an environment for the secure delivery of content. While a lot of these specifications have, apparently, nothing to do with DRM, they are all focussed ensuring that all users in the system can have access to standard technologies. For instance, "Digital Item Adaptation" provides tools to ensure that content can be rendered on different platforms, an essential part of interoperability. "Event Reporting" is being specified so that both rights holders and consumers can have an audit trail. While I don't expect anyone to have the extensive knowledge of MPEG-21 possessed by those intimately involved in the standard, I think that it would have been possible to see that the MPEG-21 initiative is an honest attempt to work on many of the issues covered by the INDICARE report.

Finally, I would like to bring to your attention MPEG-21, Part 6, the "Rights Data Dictionary", in which I was closely involved. This is an attempt to provide a platform for interoperable metadata for rights, so that content from different metadata environments can be integrated. That said, there is some other work we are doing connected with the RDD that I'd like to mention. This is in the area of rights statements, which we believe can be used to create offers. At the moment, RELs are all about permissions rights holders give to consumers. It is a one way business. The issue of symmetric RELs (Niels Rump and I wrote about this for INDICARE, see Rump and Barlas 2005, and rejected the term) is that they maintain the "permission" modality and do not embrace the negotiation modality. Rights statements would be part of an agent based negotiation process. Certainly, without the rights statement (here's my offer, you can do this, this and this, but not this and if you do this, we will do that), you cannot move on to any kind of automated negotiation based on personal profiles. That is, I think, where we need to get to.

The INDICARE report addresses the right topics, however picking up one technical aspect, namely Rights Expression Languages (REL) and the work of MPEG-21 there is room for improvement.

