Terminal Identification via Content Decryption Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The challenge in identifying user terminals accessing protected multimedia content on open networks, such as the Internet, is exacerbated by the limitations of HTML5 applications not having access to hardware resources, making it difficult to uniquely and permanently identify terminals, which is crucial for anti-piracy control and access management.

Innovation Solution

A method and system that determine a unique identifier for the user terminal by integrating with the content decryption module (CDM) of the DRM system, involving a terminal identification process that includes requesting a DRM system identifier, generating an authentication content request, and using a license challenge to obtain a terminal identifier through cryptographic processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If HTML5 applications are used for streaming protected multimedia content, then content accessibility and compatibility across devices are improved, but terminal identification capability deteriorates due to lack of hardware resource access

Engineering Contradiction:
Improvecontent accessibilityVSAvoidterminal identification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an intermediary approach by using the CDM's unique identifier as a mediator between the HTML5 application and the terminal hardware. Instead of directly accessing hardware resources, the application obtains terminal identification information through the CDM identifier, which serves as an indirect but reliable link to the terminal's unique identity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the traditional mechanical approach of direct hardware resource access with a cryptographic substitution. Instead of using JavaScript to query hardware identifiers, the system uses cryptographic challenges and responses through the CDM to obtain terminal identification, substituting a security-based mechanism for a direct hardware access mechanism.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional hardware-based identification methods are used, then terminal identification reliability is improved, but compatibility with HTML5 applications and cross-device access deteriorates

Engineering Contradiction:
Improveterminal identification reliabilityVSAvoidcross-device access
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the CDM identifier serve multiple functions: it acts as both a security credential for content protection and as a terminal identification marker for access control. This multi-functionality allows the same identifier to support both reliable terminal identification and cross-device access management within the HTML5 ecosystem.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the identification parameter from hardware-based identifiers (which are device-specific and incompatible across devices) to CDM-based identifiers (which can be consistently associated with user accounts across multiple devices). This parameter change enables both reliable identification and cross-device compatibility.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If no terminal identification is implemented, then system complexity is reduced and ease of operation is improved, but access control security and anti-piracy capability deteriorate

Engineering Contradiction:
Improvesystem simplicityVSAvoidaccess control security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements a self-service mechanism where the CDM automatically provides its unique identifier in response to a license challenge request. The terminal identification process requires minimal intervention from the application developer, as the CDM handles the identification provision automatically during the license acquisition flow.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs terminal identification as a preliminary action during the license challenge phase, before content delivery begins. By obtaining the CDM identifier early in the authentication process, the system establishes terminal identification without adding complexity to the content playback operation.

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution enables the unique identification of user terminals, enhancing access control and countermeasures against illegitimate access by providing a persistent and authentic terminal identifier, thereby improving content protection mechanisms.

Implementation Method 1

generating a challenge response, which is unique to the terminal, using an identifier of the terminal

Methodology Applied
Scientific EffectCryptographic process:

Data Source

PatentEP3732849B1Method and system for identifying a user terminal in order to receive streaming protected multimedia content
Publication Date: 2023.07.26 VIACCESS SA
  • EP3732849B1 patent drawingFigure 1
  • EP3732849B1 patent drawingFigure 2
  • EP3732849B1 patent drawingFigure 3

AI summary

The invention relates to a method and a system for identifying a user terminal. It is implemented in a system for supplying protected multimedia content comprising a licence server (8, 8b) and a content server, the user terminal (12) being used for receiving multimedia content protected by a digital right management (DRM) system and streamed, in encrypted form, via an open communication network, and for being reproduced on said user terminal (12) by a browser (10) implementing a multimedia content player (14) and a content decryption module (18) suitable for decrypting multimedia content encrypted according to said DRM. The method includes steps, implemented by the licence server (8) modified to integrate an authentication server (8a) suitable for implementing an authentication function, of obtaining an identifier of the content decryption module, and of generating a terminal identifier as a function of the identifier of the content decryption module.