Authentication Evidence for Secure Content Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current conditional access systems (CAS) face challenges in securely authorizing content access across diverse devices and networks, particularly with the rise of mobile computing and changing consumer behaviors, as they lack effective mechanisms for dynamic subscriber-device binding, robust authentication, and protection against piracy and unauthorized access.
Innovation Solution
A method and system for authentication and authorization that separates device and subscriber authentication processes, using secure channels and cryptographic evidence to ensure only authorized devices access content, with a centralized server managing authentication and authorization to provide scalable and secure content delivery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional static device-subscriber binding is used, then authorization management is simple, but the system cannot support mobile computing and content access from multiple devices
Solution Approach 1:
The patent segments the authentication process into two independent parts: device authentication (verifying device identity and capabilities) and subscriber authentication (verifying user credentials). This allows the system to support multiple device types without complicating the overall authorization framework, as each device is evaluated independently against capability criteria.
Solution Approach 2:
The patent implements dynamic device-subscriber binding where the association is not static but established temporarily for each content access session. The binding duration is limited to the content consumption period, allowing flexible reassignment and revocation of access rights across different devices and subscribers based on real-time authorization decisions.
2Reliability
If cryptographic weak methods like passwords and PINs are used for authentication, then ease of operation is improved, but security against piracy and unauthorized access deteriorates
Solution Approach 1:
The patent introduces an intermediary authentication mechanism using device certificates and cryptographic proof of possession. Instead of relying solely on weak user credentials, the system uses the device's cryptographic key pair as an intermediary that provides strong security verification. The device proves its identity through cryptographic challenges without exposing weak passwords or PINs.
Solution Approach 2:
The patent performs preliminary device authentication and capability assessment before allowing content access. The device must present its certificate and prove possession of the corresponding private key before any content decryption keys are distributed. This preliminary cryptographic verification establishes a secure foundation that protects against piracy regardless of the strength of subsequent subscriber authentication.
3Adaptability or versatility
If device identity and credentials are distributed through retail channels, then device availability is improved, but the service provider loses a priori knowledge of device fitness for content rendering
Solution Approach 1:
The patent performs preliminary device capability assessment through cryptographic challenge-response mechanisms and capability advertisement protocols. Before a device can access content, it must demonstrate its rendering capabilities and robustness properties through cryptographic proofs. This allows the service provider to evaluate device fitness remotely without prior knowledge from retail channels.
Solution Approach 2:
The patent implements a feedback mechanism where devices advertise their capabilities and the service provider responds with authorization decisions. The device sends capability information and cryptographic credentials, the service provider evaluates this information against content protection requirements, and provides feedback in the form of authorization grants or denials. This continuous feedback loop enables dynamic adaptation to diverse device types acquired through various channels.
4Ease of operation
If content decryption keys are distributed to multiple devices, then content accessibility is improved, but the risk of passive eavesdropping and key redirection increases
Solution Approach 1:
The patent implements dynamic key distribution where content decryption keys are provided temporarily for the duration of content consumption only. The keys are bound to specific device-subscriber pairs and automatically revoked after the authorized viewing period expires. This dynamic approach allows content accessibility across multiple devices while minimizing the window of opportunity for eavesdropping and key redirection attacks.
Solution Approach 2:
The patent performs preliminary authorization verification before distributing content decryption keys. The service provider verifies device identity, subscriber credentials, and content access rights through cryptographic authentication protocols. Only after successful verification are decryption keys distributed, ensuring that keys are provided only to authorized device-subscriber pairs and reducing the risk of unauthorized key acquisition through eavesdropping or redirection.
Data Source
Figure 1
Figure 2~3
Figure 4~5
AI summary
A method of authentication and authorization over a communications system is provided. Disclosed herein are systems and methods for creating a cryptographic evidence, called authentication/ authorization evidence, AE, when a successful authentication/ authorization between a client and an authentication server is complete. There are a variety of methods for generating AE. For instance, the AE can be data that is exchanged during the authentication signaling or data that results from it. A distinctive point being that AE results from the authentication process and is used as prior state for the following TLS exchange. An example for creation of AE, is as follows: EAP authentications typically result in an Extended Master Session Key (EMSK). The EMSK can be used to create an Evidence Master Key (EMK) that can then be used to create AE for a variety of servers.