Digital Rights Management Evaluation Device for Smart Terminals

The DRM evaluation device simulates and monitors smart terminal operations to assess DRM security risks, ensuring secure playback of high-quality content by evaluating compliance with hardware trust execution environments, addressing the limitations of existing software-based DRM technologies.

CN114168907BActive Publication Date: 2025-07-15ACADEMY OF BROADCASTING SCI STATE ADMINISTATION OF PRESS PUBLICATION RADIO FILM & TELEVISION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202010949666.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-09-10
Publication Date
2025-07-15
Estimated Expiration
2040-09-10

AI Technical Summary

Technical Problem

The existing digital copyright management technology of smart terminals cannot ensure the full process of digital media content in a trusted hardware execution environment, and cannot effectively evaluate the copyright protection measures of smart terminals.

Method used

A digital copyright management evaluation device is provided. Through a simulation module, the operating system of the smart terminal to be evaluated is run in the operating system of the evaluation device. The monitoring module obtains monitoring data during operation, and the security evaluation module evaluates whether there is a digital copyright management security risk based on the monitoring data.

Benefits of technology

It realizes an effective evaluation of the digital copyright management technology of smart terminals, ensuring that only smart terminals that meet security requirements can play high-quality media content, reducing the dependence on the technical reserves and experience of detectors, and improving the accuracy of evaluation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114168907B_ABST
    Figure CN114168907B_ABST
Patent Text Reader

Abstract

The present invention discloses a digital rights management evaluation device for intelligent terminals, which device comprises: a simulation module, configured to, in response to a first instruction, run a second operating system of the intelligent terminal to be evaluated in a first operating system of the evaluation device itself; the simulation module is further configured to, in response to a second instruction input by a user through a system interface of the second operating system, run a media content playback program in the second operating system; a monitoring module, configured to obtain monitoring data of the second operating system during the running of the media content playback program; a data sending module, configured to send the monitoring data to a security evaluation module; and a security evaluation module, configured to receive the monitoring data and evaluate whether there is a digital rights management security risk in the intelligent terminal to be evaluated according to the monitoring data, and obtain an analysis result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital rights management (DRM), and more particularly, to a digital rights management evaluation device for smart terminals. Background Art

[0002] With the continuous advancement of media convergence, radio and television broadband, etc., smart terminals have begun to support the operation of 4K / HDR (High-Dynamic Range) content. On the one hand, the rapid update and iteration of smart terminals have brought more threats and challenges to content protection. On the other hand, due to its high production cost and other characteristics, 4K ultra-high-definition content has higher and higher requirements for content protection. Moreover, with the development and operation of 4K ultra-high-definition content and services by content providers, content providers, especially large film companies, have put forward higher requirements for copyright protection, especially copyright protection on smart terminals.

[0003] Existing digital rights management technologies (DRM, Digital Rights Management) for smart terminals are usually software-based security protection mechanisms, which cannot ensure that digital media content is implemented under the protection of a hardware trusted execution environment from decryption, decoding, buffering, display or output in the entire process on smart terminals, and effectively protect the security during content playback. However, content providers, especially large film companies and domestic mainstream content providers, are urgently hoping to effectively evaluate the digital rights management technology on smart terminals to ensure that only smart terminals that meet security requirements can play high-quality content.

[0004] Therefore, it is necessary to propose a digital rights management evaluation device for smart terminals to effectively evaluate the digital rights management technology on smart terminals. Summary of the Invention

[0005] An object of the present invention is to provide a technical solution for effectively evaluating the digital rights management technology on smart terminals.

[0006] According to a first aspect of the present invention, there is provided a digital rights management evaluation device for smart terminals, including:

[0007] An emulation module, configured to, in response to a first instruction, run a second operating system of a smart terminal to be evaluated in a first operating system of the evaluation device itself;

[0008] The emulation module is further configured to, in response to a second instruction input by a user through a system interface of the second operating system, run a media content playback program in the second operating system;

[0009] A monitoring module, configured to obtain monitoring data of the second operating system during the running of the media content playback program;

[0010] A data sending module, configured to send the monitoring data to a security assessment module;

[0011] A security assessment module, configured to receive the monitoring data and evaluate whether there is a digital rights management security risk for the intelligent terminal to be evaluated according to the monitoring data, so as to obtain an analysis result.

[0012] Optionally, the monitoring module at least includes a stored data monitoring unit, a memory data monitoring unit, and a communication data monitoring unit;

[0013] The stored data monitoring unit is configured to obtain the stored data of the second operating system during the process of running a media content playing program;

[0014] The memory data monitoring unit is configured to obtain the memory data of the second operating system during the process of running a media content playing program;

[0015] The communication data monitoring unit is configured to obtain the communication data of the second operating system during the process of running a media content playing program.

[0016] Optionally, the security assessment module includes a security assessment policy analysis unit, a DRM information analysis unit, and an analysis result generation unit;

[0017] The security assessment policy analysis unit is configured to analyze the monitoring data by invoking a pre-stored security assessment policy to generate a first analysis result;

[0018] The DRM information analysis unit is configured to analyze the monitoring data by invoking DRM information to generate a second analysis result, where the DRM information at least includes a DRM communication protocol, a DRM license, and a media content format;

[0019] The analysis result generation unit is configured to evaluate whether there is a digital rights management security risk for the intelligent terminal to be evaluated according to the first analysis result and the second analysis result, and output an evaluation result.

[0020] Optionally, the security assessment module further includes a security assessment policy management unit;

[0021] The security assessment policy management unit is configured to set a security assessment policy, where the security assessment policy at least includes a stored data analysis policy, a memory data analysis policy, and a communication data analysis policy.

[0022] Optionally, the device further includes: a data management module, and the data management module includes a data receiving unit, a data storage unit, and a data query unit;

[0023] The data receiving unit is configured to receive the monitoring data sent by the data sending module;

[0024] The data storage unit is configured to structurally store the monitoring data;

[0025] The data query unit is configured to receive a data query request, obtain the corresponding monitoring data according to the data query request and send it.

[0026] Optionally, the data storage unit is specifically configured to obtain the feature information of the monitoring data, and the feature information at least includes the type of the monitoring data and the acquisition time corresponding to the monitoring data;

[0027] The data storage unit is specifically further configured to search a preset index table and obtain index information matching the feature information;

[0028] The data storage unit is specifically further configured to write the monitoring data into a storage file corresponding to the index information;

[0029] The data query unit is specifically configured to obtain the monitoring data matching the index information according to the index information in the data query request.

[0030] Optionally, the data management module further includes a data preprocessing unit;

[0031] The data preprocessing unit is configured to preprocess the monitoring data.

[0032] Optionally, the security assessment module is further configured to send a data query request to the data query unit;

[0033] The security assessment module is further configured to evaluate whether there is a digital rights management security risk in the intelligent terminal to be evaluated according to the monitoring data obtained by the data query request, and obtain an analysis result.

[0034] Optionally, the simulation module includes a security assessment container;

[0035] The security assessment container runs the second operating system of the intelligent terminal to be evaluated in the first operating system of the evaluation device itself.

[0036] Optionally, the simulation module includes a virtual machine;

[0037] The virtual machine runs the second operating system of the intelligent terminal to be evaluated in the first operating system of the evaluation device itself.

[0038] According to an embodiment of the present disclosure, by simulating a second operating system of an intelligent terminal and obtaining monitoring data generated during the operation of a media content playback program in the second operating system, it is determined whether there is a digital rights management security risk in the intelligent terminal to be evaluated based on the monitoring data. The embodiment of the present disclosure provides an evaluation device for digital rights security technology based on a hardware trusted execution environment, which can effectively evaluate the digital rights management technology on the intelligent terminal, so as to ensure that only intelligent terminals meeting certain security requirements can play their high-quality media content.

[0039] Other features and advantages of the present invention will become clear from the following detailed description of exemplary embodiments of the present invention with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] The drawings incorporated in and constituting a part of this specification illustrate embodiments of the present invention and, together with the description, serve to explain the principles of the present invention.

[0041] Figure 1 A block diagram of a digital rights management evaluation device for an intelligent terminal provided by an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0042] Now, various exemplary embodiments of the present invention will be described in detail with reference to the accompanying drawings. It should be noted that: Unless otherwise specifically stated, the relative arrangements of components and steps, numerical expressions and values set forth in these embodiments do not limit the scope of the present invention.

[0043] The following description of at least one exemplary embodiment is merely illustrative in nature and in no way serves as a limitation on the present invention or its application or use.

[0044] Techniques, methods, and devices known to those of ordinary skill in the relevant art may not be discussed in detail, but where appropriate, the techniques, methods, and devices should be considered as part of the specification.

[0045] In all the examples shown and discussed here, any specific value should be construed as merely exemplary and not as a limitation. Therefore, other examples of the exemplary embodiments may have different values.

[0046] It should be noted that: Similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further discussed in subsequent drawings.

[0047] Existing digital rights management technologies (DRM) for smart terminals are usually software-based security protection mechanisms. Generally, there are document evaluation, decompilation, penetration testing, etc. The document evaluation method is based on the trust in the smart terminal manufacturer or DRM technology provider, and evaluates its copyright protection-related solutions. Theoretically, it analyzes whether it meets the security requirements. However, the disadvantage of this solution is that it cannot confirm whether the smart terminal is implemented strictly according to the provided security technology solution. The decompilation method mainly targets the copyright protection solution at the software level security. The way is to use a decompilation tool to decompile the copyright protection software on the smart terminal and try to find relevant vulnerabilities to judge whether the solution is secure. However, more and more current solutions rely on chip-level security solutions such as hardware trusted execution environments to implement, and decompilation cannot comprehensively reflect relevant security issues. The penetration testing method mainly conducts trial attacks on the smart terminal based on many attack means, makes various attempts to attack the smart terminal from different angles, and tries to find vulnerabilities in it. This method is highly dependent on the technical ability of the test evaluation personnel. A system that cannot be attacked does not mean that it reaches a certain security level. Therefore, to ensure that digital media content is implemented under the protection of the hardware trusted execution environment throughout the entire process from decryption, decoding, buffering, display, or output on the smart terminal and effectively protect the security during content playback, a digital rights management evaluation device for smart terminals is proposed.

[0048] Figure 1 FIG. is a block schematic diagram of a digital rights management evaluation device 10 for a smart terminal according to an embodiment of the present disclosure.

[0049] See Figure 1 As shown, the evaluation device 10 includes a simulation module 11, a monitoring module 12, a data sending module 13, and a security evaluation module 14. The simulation module 11 is communicatively connected to the monitoring module 12, the monitoring module 12 is communicatively connected to the data sending module 13, and the data sending module 13 is communicatively connected to the security evaluation module 14.

[0050] The simulation module 11 is configured to run a second operating system of the smart terminal to be evaluated in a first operating system of the evaluation device itself in response to a first instruction.

[0051] The smart terminal may be a terminal device with media content playback function, or a terminal device installed with a media content playback program. The smart terminal is, for example, a mobile phone, a portable computer, a tablet computer, a personal digital assistant, etc. The second operating system of the smart terminal may be, for example, an IOS operating system, an Android operating system, a Windows operating system, etc.

[0052] In one embodiment, the simulation module 11 may be a security assessment container. The security assessment container is used to run the second operating system of the intelligent terminal to be evaluated in the first operating system of the evaluation device itself.

[0053] In one embodiment, the simulation module 11 may be a virtual machine. The virtual machine is used to run the second operating system of the intelligent terminal to be evaluated in the first operating system of the evaluation device itself.

[0054] The simulation module 11 is further configured to run a media content playback program in the second operating system in response to a second instruction input by the user through the system interface of the second operating system;

[0055] After running the second operating system of the intelligent terminal to be evaluated in the first operating system of the evaluation device itself, the system interface of the second operating system of the intelligent terminal is displayed on the interaction interface of the evaluation device. The system interface includes a plurality of interaction controls, and different operations can be implemented through the interaction controls. For example, a media content playback program can be run in the second operating system.

[0056] The monitoring module 11 is configured to obtain monitoring data of the second operating system during the running of the media content playback program;

[0057] In one embodiment, the monitoring module 11 at least includes a stored data monitoring unit 111, a memory data monitoring unit 112, and a communication data monitoring unit 113.

[0058] The stored data monitoring unit 111 is configured to obtain the stored data of the second operating system during the running of the media content playback program.

[0059] The stored data may be the data stored in the second operating system during the running of the media content playback program. The stored data includes stored data information and the acquisition time corresponding to the stored data information. According to the stored data, it can be determined whether there is a digital rights management security risk in the storage of media content data by the intelligent terminal.

[0060] The memory data monitoring unit 112 is configured to obtain the memory data of the second operating system during the running of the media content playback program.

[0061] The memory data may be the data in the memory of the second operating system during the running of the media content playback program. The memory data includes memory data information and the acquisition time corresponding to the memory data information. According to the memory data, the process of media content data flow can be determined to analyze whether there is a digital rights management security risk in the memory of the intelligent terminal.

[0062] The communication data monitoring unit 113 is configured to obtain the communication data of the second operating system during the running of the media content playing program.

[0063] In one embodiment, the communication data may include interface data, interrupt data, and interrupt semaphores. According to the change information of the interface data, interrupt data, and interrupt semaphores during the running of the media content playing program, it can be determined whether the process jumps to other programs during the running of the media content playing program, so that the digital rights management security risk of the intelligent terminal can be analyzed.

[0064] The data sending module 13 is configured to send the monitoring data to the security evaluation module.

[0065] The security evaluation module 14 is configured to receive the monitoring data and evaluate whether the intelligent terminal to be evaluated has a digital rights management security risk according to the monitoring data, and obtain an analysis result.

[0066] According to the embodiments of the present disclosure, by simulating the second operating system of the intelligent terminal and obtaining the monitoring data generated during the running of the media content playing program in the second operating system, and evaluating whether the intelligent terminal to be evaluated has a digital rights management security risk according to the monitoring data, the embodiments of the present disclosure provide an evaluation device for digital rights security technology based on a hardware trusted execution environment, which can effectively evaluate the digital rights management technology on the intelligent terminal, so as to ensure that only intelligent terminals that meet certain security requirements can play their high-quality media content.

[0067] In one embodiment, the security evaluation module 14 includes a security evaluation policy analysis unit 141, a DRM information analysis unit 142, and an analysis result generation unit 143.

[0068] The security evaluation policy analysis unit 141 is configured to analyze the monitoring data by invoking the pre-stored security evaluation policy and generate a first analysis result.

[0069] The security evaluation policy can be obtained in advance according to actual needs.

[0070] In a more specific example, the security evaluation module 14 further includes a security evaluation policy management unit 144.

[0071] The security evaluation policy management unit 144 is configured to set the security evaluation policy.

[0072] Specifically, the security evaluation policy management unit 144 can add or delete security evaluation policies according to actual needs. Among them, for the digital rights management security evaluation of the intelligent terminal, the security evaluation policy at least includes storage data analysis policy, memory data analysis policy, and communication data analysis policy.

[0073] According to an embodiment of the present disclosure, according to the differences of the programs to be evaluated, corresponding security evaluation policies can be added to implement security evaluation for the processes of running different programs on the operating system of the intelligent terminal.

[0074] The DRM information analysis unit 142 is used to analyze the monitoring data by invoking DRM information and generate a second analysis result.

[0075] The DRM information at least includes a DRM communication protocol, a DRM license, and a media content format. According to the DRM communication protocol, the DRM license, and the media content format, it can be evaluated whether the media content format of the media content playing program running on the intelligent terminal is correct, whether the license format is correct, and whether it meets the requirements of the DRM communication protocol, so as to implement the security evaluation of the digital rights management technology of the intelligent terminal.

[0076] The analysis result generation unit 143 is used to evaluate whether there is a digital rights management security risk in the intelligent terminal according to the first analysis result and the second analysis result, and output an evaluation result.

[0077] The digital rights management security risk can be, for example, a memory risk, a storage risk, an encryption process risk, etc.

[0078] According to an embodiment of the present disclosure, according to the first analysis result and the second analysis result, it can be evaluated whether there is a digital rights management security risk in the intelligent terminal to be evaluated. If so, a reminder is sent to the user. Moreover, by performing security evaluation on the intelligent terminal according to the preset security evaluation policy and DRM information, the dependence on the technical reserve, technical experience, and technical ability of the detection personnel can be greatly reduced, the influence of subjective detection and evaluation factors can be reduced, and the accuracy of the evaluation can be improved.

[0079] In one embodiment, as shown in Figure 1 the evaluation device further includes: a data management module 15. The data management module 15 is used to structurally store the acquired monitoring data to facilitate the query of the monitoring data, thereby improving the evaluation efficiency.

[0080] The data management module 15 includes a data receiving unit 151, a data storage unit 152, and a data query unit 153.

[0081] The data receiving unit 151 is used to receive the monitoring data sent by the data sending module 13.

[0082] The data storage unit 152 is used to structurally store the monitoring data.

[0083] In a more specific example, the data storage unit 152 is specifically configured to obtain the characteristic information of the monitoring data, where the characteristic information at least includes the type of the monitoring data and the acquisition time corresponding to the monitoring data.

[0084] The data storage unit 152 is further specifically configured to search a preset index table to obtain index information that matches the characteristic information.

[0085] The index information may be, for example, the type of the monitoring data or the acquisition time corresponding to the monitoring data.

[0086] The data storage unit 152 is further specifically configured to write the monitoring data into a storage file corresponding to the index information.

[0087] The data query unit 153 is configured to receive a data query request, obtain corresponding monitoring data according to the data query request, and send it.

[0088] In a more specific example, the data query unit 153 is specifically configured to obtain monitoring data that matches the index information according to the index information in the data query request.

[0089] In one embodiment, the data management module 15 further includes a data preprocessing unit 154.

[0090] The data preprocessing unit 154 is configured to preprocess the monitoring data. For example, it converts the format of the monitoring data so that the security evaluation module 14 can read the monitoring data.

[0091] In one embodiment, the security evaluation module 14 can receive the monitoring data sent by the data sending module 13, and evaluate whether there is a digital rights management security risk in the smart terminal to be evaluated according to the monitoring data, and obtain an analysis result.

[0092] In one embodiment, the security evaluation module 14 can also send a data query request to the data query unit 153, and evaluate whether there is a digital rights management security risk in the smart terminal to be evaluated according to the monitoring data returned by the data query unit 153, and obtain an analysis result.

[0093] The following uses a specific example to illustrate the process of evaluating the digital rights management technology of a smart terminal based on this evaluation device. This process includes steps S101 - S10.

[0094] S101. In response to a first instruction, the evaluation device starts a security evaluation container and imports the second operating system of the smart terminal to be evaluated into the security evaluation container for running.

[0095] S102. In response to a second instruction input by a user through a system interface of a second operating system, run a media content playback program in the second operating system.

[0096] S103. During the process of running the media content playback program, a storage data monitoring unit monitors the storage data of the second operating system in real time, a memory data monitoring unit monitors the memory data of the second operating system in real time, and a communication data monitoring unit monitors the communication data of the second operating system in real time.

[0097] S104. A data sending module sends the monitored storage data, memory data, and communication data to a data receiving unit.

[0098] S105. The data receiving unit receives the storage data, memory data, and communication data sent by the data sending module, and sends the received data to a data preprocessing unit.

[0099] S106. The data preprocessing unit preprocesses the received storage data, memory data, and communication data, and then sends them to a data storage unit.

[0100] S107. The data storage unit receives the storage data, memory data, and communication data, obtains the feature information of the storage data, memory data, and communication data, obtains the index information matching the feature information by looking up a preset index table, and writes the storage data, memory data, and communication data into a storage file corresponding to the matching index information.

[0101] S108. A data query unit receives a data query request sent by a security evaluation module, obtains the storage data, memory data, and communication data matching the index information according to the index information in the data query request, and sends them to the security evaluation module.

[0102] S109. The security evaluation module receives the storage data, memory data, and communication data, calls a pre-stored security evaluation policy and DRM information to analyze the storage data, memory data, and communication data, so as to evaluate whether there is a digital rights management security risk in the intelligent terminal to be evaluated, and outputs an evaluation result.

[0103] According to the embodiments of the present disclosure, by simulating the second operating system of the intelligent terminal and obtaining the monitoring data generated during the process of running the media content playback program in the second operating system, and evaluating whether there is a digital rights management security risk in the intelligent terminal to be evaluated according to the monitoring data, the embodiments of the present disclosure provide an evaluation device for digital rights security technology based on a hardware trusted execution environment, which can effectively evaluate the digital rights management technology on the intelligent terminal, so as to ensure that only intelligent terminals meeting certain security requirements can play their high-quality media content.

[0104] According to an embodiment of the present disclosure, based on the first analysis result and the second analysis result, it is possible to evaluate whether there is a digital rights management security risk in the intelligent terminal to be evaluated, and if so, a reminder is sent to the user. Moreover, by performing a security assessment on the intelligent terminal according to a preset security assessment policy and DRM information, the dependence on the technical reserves, technical experience, and technical capabilities of the detection personnel can be greatly reduced, the influence of subjective detection and evaluation factors can be reduced, and the accuracy of the evaluation can be improved.

[0105] The above embodiments mainly focus on the differences from other embodiments. However, those skilled in the art should clearly understand that the above embodiments can be used alone or in combination as needed.

[0106] Each embodiment in this specification is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. However, those skilled in the art should clearly understand that the above embodiments can be used alone or in combination as needed. Additionally, for the device embodiments, since they correspond to the method embodiments, they are described relatively simply. For the relevant parts, reference can be made to the corresponding parts of the method embodiments. The system embodiments described above are merely illustrative.

[0107] The present invention can be a system, a method, and / or a computer program product. The computer program product may include a computer-readable storage medium having thereon computer-readable program instructions for causing a processor to implement various aspects of the present invention.

[0108] The computer-readable storage medium can be a tangible device that can hold and store instructions used by an instruction execution device. The computer-readable storage medium can be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanical encoding device, such as a punched card or raised structures in grooves storing instructions thereon, and any suitable combination of the above. The computer-readable storage medium used herein is not construed as an instantaneous signal itself, such as radio waves or other freely propagating electromagnetic waves, electromagnetic waves propagating through a waveguide or other transmission medium (e.g., optical pulses through an optical fiber cable), or electrical signals transmitted through wires.

[0109] The computer-readable program instructions described herein can be downloaded to various computing / processing devices from a computer-readable storage medium or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in each computing / processing device.

[0110] The computer program instructions for performing the operations of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state-setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, by using the state information of the computer-readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit can execute the computer-readable program instructions to implement various aspects of the present invention.

[0111] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0112] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that the instructions, when executed by the processor of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions may also be stored in a computer-readable storage medium that causes a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer-readable medium storing the instructions comprises a manufacture including instructions for implementing various aspects of the functions / acts specified in one or more blocks of the flowchart and / or block diagram.

[0113] The computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process such that the instructions executed on the computer, other programmable data processing apparatus, or other device implement the functions / acts specified in one or more blocks of the flowchart and / or block diagram.

[0114] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a segment of code, or a portion of an instruction, which comprises one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two consecutive blocks may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functionality involved. It should also be noted that each block of the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by special-purpose hardware-based systems that perform the specified functions or acts, or by combinations of special-purpose hardware and computer instructions. It is well known to those skilled in the art that implementation by hardware, implementation by software, and implementation by a combination of software and hardware are equivalent.

[0115] The embodiments of the present invention have been described above. The above description is exemplary and not exhaustive, and is also not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The choice of terms used herein is intended to best explain the principles of the embodiments, practical applications, or improvements to the technology in the market, or to enable other ordinary skill in the art to understand the embodiments disclosed herein. The scope of the present invention is defined by the appended claims.

Claims

1. A digital rights management (DRM) evaluation device for smart terminals, characterized in that, Comprising: A simulation module, configured to, in response to a first instruction, run a second operating system of a smart terminal to be evaluated in a first operating system of the evaluation device itself; The simulation module is further configured to, in response to a second instruction input by a user through a system interface of the second operating system, run a media content playback program in the second operating system; A monitoring module, configured to obtain monitoring data of the second operating system during the running of the media content playback program; A data sending module, configured to send the monitoring data to a security evaluation module; A security evaluation module, configured to receive the monitoring data and evaluate whether there is a digital rights management security risk in the smart terminal to be evaluated according to the monitoring data, and obtain an analysis result; Wherein, the monitoring module at least includes a storage data monitoring unit, a memory data monitoring unit, and a communication data monitoring unit; The storage data monitoring unit is configured to obtain storage data of the second operating system during the running of the media content playback program; The memory data monitoring unit is configured to obtain memory data of the second operating system during the running of the media content playback program; The communication data monitoring unit is configured to obtain communication data of the second operating system during the running of the media content playback program.

2. The device according to claim 1, wherein The security evaluation module includes a security evaluation policy analysis unit, a DRM information analysis unit, and an analysis result generation unit; The security evaluation policy analysis unit is configured to analyze the monitoring data by invoking a pre-stored security evaluation policy to generate a first analysis result; The DRM information analysis unit is configured to analyze the monitoring data by invoking DRM information, where the DRM information at least includes a DRM communication protocol, a DRM license, and a media content format, to generate a second analysis result; The analysis result generation unit is configured to evaluate whether there is a digital rights management security risk in the smart terminal to be evaluated according to the first analysis result and the second analysis result, and output an evaluation result.

3. The device according to claim 1, wherein The security evaluation module further includes a security evaluation policy management unit; The security evaluation policy management unit is configured to set a security evaluation policy, where the security evaluation policy at least includes a storage data analysis policy, a memory data analysis policy, and a communication data analysis policy.

4. The device according to claim 1, wherein, The device further includes: a data management module, and the data management module includes a data receiving unit, a data storage unit, and a data query unit; The data receiving unit is configured to receive the monitoring data sent by the data sending module; The data storage unit is configured to structurally store the monitoring data; The data query unit is configured to receive a data query request, obtain corresponding monitoring data according to the data query request, and send it.

5. The device according to claim 4, wherein, The data storage unit is specifically configured to obtain characteristic information of the monitoring data, where the characteristic information at least includes the type of the monitoring data and the acquisition time corresponding to the monitoring data; The data storage unit is specifically further configured to search a preset index table to obtain index information matching the characteristic information; The data storage unit is specifically further configured to write the monitoring data into a storage file corresponding to the index information; The data query unit is specifically configured to obtain the monitoring data matching the index information according to the index information in the data query request.

6. The apparatus according to claim 4, wherein The data management module further includes a data preprocessing unit; The data preprocessing unit is configured to preprocess the monitoring data.

7. The device according to claim 4, wherein, The security evaluation module is further configured to send a data query request to the data query unit; The security evaluation module is further configured to evaluate whether there is a digital rights management security risk in the smart terminal to be evaluated according to the monitoring data obtained by the data query request, and obtain an analysis result.

8. The apparatus according to claim 1, wherein The simulation module includes a security evaluation container; The security evaluation container runs the second operating system of the smart terminal to be evaluated in the first operating system of the evaluation device itself.

9. The device according to claim 1, wherein, The simulation module includes a virtual machine; The virtual machine runs the second operating system of the smart terminal to be evaluated in the first operating system of the evaluation device itself.

Citation Information

Patent Citations

  • Using a custom media library to secure digital media content

    CN102449638A

  • Method and system for providing digital rights management contents

    KR100770245B1