Browser-Based DRM via User-Specific Obfuscated Code
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital rights management systems are ineffective in preventing unauthorized redistribution of digital content viewed within web browsers, as they require hardware and operating system-specific code and local software installation, and lack mechanisms to prevent automated duplication of content.
Innovation Solution
A method that encrypts content and provides user-specific, obfuscated browser-executable code, which changes periodically, to prevent unauthorized redistribution, by generating encrypted content and obfuscated code based on user identity and pre-computing user-specific code versions for improved security and performance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional digital rights management is used, then content protection is provided, but the system requires hardware and operating system-specific code and local software installation, reducing portability and ease of operation
Solution Approach 1:
The patent replaces traditional hardware-based DRM mechanisms with browser-based JavaScript code that runs in the client's web browser. This substitution eliminates the need for hardware-specific implementations and local software installation, allowing content protection to work across different devices and operating systems through the universal browser environment.
Solution Approach 2:
The patent creates a universal content protection system that works across multiple platforms by utilizing the web browser as a common execution environment. The same JavaScript-based DRM solution can protect content on Windows, macOS, Linux, mobile devices, and other platforms that support web browsers, eliminating the need for platform-specific implementations.
2Ease of operation
If web-based viewing is implemented, then accessibility and ease of operation are improved, but the content can be easily duplicated and downloaded using automated tools, worsening content security
Solution Approach 1:
The patent applies preliminary obfuscation and encryption to the content and browser-executable code before delivery to the client. By pre-processing the content with encryption and the code with obfuscation techniques, the system creates barriers that prevent automated downloading tools from easily copying and distributing the content, while still allowing legitimate users to access it through their browsers.
3Reliability
If content is provided in encrypted form with browser-executable code, then unauthorized redistribution is prevented, but the system complexity increases due to encryption and code obfuscation mechanisms
Solution Approach 1:
The patent introduces an intermediary encryption/decryption layer that operates within the browser environment. This intermediary mechanism handles the complex encryption and decryption operations transparently, protecting content without requiring complex client-side software. The browser acts as an intermediary that manages the security operations, simplifying the overall system architecture.
4Reliability
If user-specific encryption is implemented, then content protection against automated duplication is improved, but the time required for content delivery increases due to individual encryption processes
Solution Approach 1:
The patent changes the encryption parameter from dynamic per-user encryption to a more efficient model where the same encrypted content and obfuscated code are delivered to all users. The user-specific protection is achieved through browser-specific identifiers and runtime environment verification rather than individualized encryption processes, significantly reducing content delivery time while maintaining security.
Data Source
AI summary
A content server provides a browser of a client with encrypted content and with obfuscated browser-executable code for decrypting and displaying the content within the browser. Both the encrypted content and the obfuscated browser-executable code are generated based at least in part on an identity of the user requesting the content, and thus are different from encrypted content and obfuscated browser-executable code provided to other users. Further, in one embodiment the browser-executable code provided by the server changes periodically, such as weekly, thereby rendering ineffective any malicious software tools that obtain decrypted content by calling expected functions of the code. In one embodiment, the obfuscated browser-executable code for a user is pre-computed before that user makes a request for content.


