Authentication Evidence for Secure Content Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current conditional access systems (CAS) face challenges in securely authorizing content access across diverse devices and networks, particularly with the rise of mobile computing and changing consumer behaviors, as they lack effective mechanisms for dynamic subscriber-device binding, robust authentication, and protection against piracy and unauthorized access.

Innovation Solution

A method and system for authentication and authorization that separates device and subscriber authentication processes, using secure channels and cryptographic evidence to ensure only authorized devices access content, with a centralized server managing authentication and authorization to provide scalable and secure content delivery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional static device-subscriber binding is used, then authorization management is simple, but the system cannot support mobile computing and content access from multiple devices

Engineering Contradiction:
Improvedevice compatibilityVSAvoidauthorization mechanism
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into two independent parts: device authentication (verifying device identity and capabilities) and subscriber authentication (verifying user credentials). This allows the system to support multiple device types without complicating the overall authorization framework, as each device is evaluated independently against capability criteria.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic device-subscriber binding where the association is not static but established temporarily for each content access session. The binding duration is limited to the content consumption period, allowing flexible reassignment and revocation of access rights across different devices and subscribers based on real-time authorization decisions.

Inventive Principle:
Principle #15Dynamics

2Reliability

If cryptographic weak methods like passwords and PINs are used for authentication, then ease of operation is improved, but security against piracy and unauthorized access deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary authentication mechanism using device certificates and cryptographic proof of possession. Instead of relying solely on weak user credentials, the system uses the device's cryptographic key pair as an intermediary that provides strong security verification. The device proves its identity through cryptographic challenges without exposing weak passwords or PINs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary device authentication and capability assessment before allowing content access. The device must present its certificate and prove possession of the corresponding private key before any content decryption keys are distributed. This preliminary cryptographic verification establishes a secure foundation that protects against piracy regardless of the strength of subsequent subscriber authentication.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If device identity and credentials are distributed through retail channels, then device availability is improved, but the service provider loses a priori knowledge of device fitness for content rendering

Engineering Contradiction:
Improvedevice acquisition flexibilityVSAvoiddevice capability assessment
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent performs preliminary device capability assessment through cryptographic challenge-response mechanisms and capability advertisement protocols. Before a device can access content, it must demonstrate its rendering capabilities and robustness properties through cryptographic proofs. This allows the service provider to evaluate device fitness remotely without prior knowledge from retail channels.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where devices advertise their capabilities and the service provider responds with authorization decisions. The device sends capability information and cryptographic credentials, the service provider evaluates this information against content protection requirements, and provides feedback in the form of authorization grants or denials. This continuous feedback loop enables dynamic adaptation to diverse device types acquired through various channels.

Inventive Principle:
Principle #23Feedback

4Ease of operation

If content decryption keys are distributed to multiple devices, then content accessibility is improved, but the risk of passive eavesdropping and key redirection increases

Engineering Contradiction:
Improvecontent accessibilityVSAvoidsecurity threats
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements dynamic key distribution where content decryption keys are provided temporarily for the duration of content consumption only. The keys are bound to specific device-subscriber pairs and automatically revoked after the authorized viewing period expires. This dynamic approach allows content accessibility across multiple devices while minimizing the window of opportunity for eavesdropping and key redirection attacks.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary authorization verification before distributing content decryption keys. The service provider verifies device identity, subscriber credentials, and content access rights through cryptographic authentication protocols. Only after successful verification are decryption keys distributed, ensuring that keys are provided only to authorized device-subscriber pairs and reducing the risk of unauthorized key acquisition through eavesdropping or redirection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2604017B1System and method for cognizant transport layer security
Publication Date: 2017.10.04 GOOGLE TECHNOLOGY HOLDINGS LLC
  • EP2604017B1 patent drawingFigure 1
  • EP2604017B1 patent drawingFigure 2~3
  • EP2604017B1 patent drawingFigure 4~5

AI summary

A method of authentication and authorization over a communications system is provided. Disclosed herein are systems and methods for creating a cryptographic evidence, called authentication/ authorization evidence, AE, when a successful authentication/ authorization between a client and an authentication server is complete. There are a variety of methods for generating AE. For instance, the AE can be data that is exchanged during the authentication signaling or data that results from it. A distinctive point being that AE results from the authentication process and is used as prior state for the following TLS exchange. An example for creation of AE, is as follows: EAP authentications typically result in an Extended Master Session Key (EMSK). The EMSK can be used to create an Evidence Master Key (EMK) that can then be used to create AE for a variety of servers.