Blu-ray Client Authentication via AACS Cryptographic Permissions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Advanced Access Content System (AACS) does not provide explicit mechanisms for content providers to reliably authenticate client applications executing on AACS-compliant devices, making it difficult to distinguish between authorized and unauthorized clients, especially in networked environments, which can lead to unauthorized access to protected content.

Innovation Solution

The implementation of cryptographic authentication techniques using AACS elements, such as the AACS Layer API, to validate client applications by generating and verifying AACS Permissions, ensuring that only non-revoked AACS-compliant devices can access encrypted content, and using a mechanism like bogus authentication permissions to authenticate clients.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If AACS content protection system is implemented to protect against unauthorized access to copyrighted content, then content security is improved, but the system lacks explicit mechanisms for client authentication, making it difficult to distinguish between authorized and unauthorized clients

Engineering Contradiction:
Improvecontent securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that mediates between the AACS content protection system and the client application. This intermediary layer uses cryptographic permissions and proofs to verify client authenticity without requiring fundamental changes to the AACS protocol, thus resolving the contradiction between maintaining content security and implementing authentication without increasing system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic authentication mechanisms are added to authenticate clients in networked environments, then client authentication reliability is improved, but the system complexity and implementation difficulty increase

Engineering Contradiction:
Improveclient authentication reliabilityVSAvoidsystem implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-generating cryptographic permissions and proofs that can be verified without complex real-time authentication infrastructure. The client application creates cryptographic proofs beforehand using the AACS permission, allowing the server to authenticate clients through simple verification of these pre-computed credentials, thus improving authentication reliability while minimizing system complexity

Inventive Principle:
Principle #10Preliminary action

3Reliability

If AACS permission validation is used to authenticate client applications, then unauthorized access prevention is improved, but the difficulty of detecting and measuring client authenticity increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidclient authenticity verification difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent replaces mechanical or procedural authentication methods with cryptographic verification. Instead of relying on complex validation procedures to detect client authenticity, the system uses cryptographic proofs and permissions that can be automatically verified through mathematical validation, thus improving unauthorized access prevention while reducing the difficulty of detecting client authenticity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8234715B2Activating streaming video in a blu-ray disc player
Publication Date: 2012.07.31 NETFLIX INC
  • US8234715B2 patent drawing
  • US8234715B2 patent drawing
  • US8234715B2 patent drawing

AI summary

Techniques are described herein for using cryptographic elements of the Advanced Access Content System (AACS) in a client-server environment to cryptographically authenticate client applications that are executing on non-revoked AACS-compliant playback devices. The techniques described herein may be used to protect a server application from providing information to client applications executing in non-AACS-compliant or revoked environments. In one embodiment, the techniques are used to authenticate a Blu-ray Disc Java Application executing on a non-revoked AACS-compliant Blu-ray Disc Player.