Digital Content Key Management via Trusted Third Party Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In digital content management, independent content providers and DRM service entities often lack trust, making it difficult to manage digital rights effectively, as they have conflicting interests and require secure, reliable methods for content key distribution and decryption.

Innovation Solution

The system involves the content provider encrypting the content key, sending it to the DRM service entity, which then releases license data including the encrypted key to the user, while the content provider decrypts the key and sends it to the user upon authorization, using a commutative encryption method to ensure secure decryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the content provider and DRM service entity are independent entities, then the content provider can maintain independence and control over their content, but trust and reliable key management become difficult to establish

Engineering Contradiction:
Improveindependence of content providerVSAvoidtrust between entities
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a trusted third party (TTP) as an intermediary that generates key pairs and manages cryptographic operations. The TTP acts as a neutral mediator between the content provider and DRM service entity, enabling them to trust each other through the TTP's cryptographic guarantees without needing to trust each other directly. This resolves the contradiction by maintaining entity independence while establishing reliable trust through the intermediary.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/social concept of trust between independent entities with a cryptographic system based on mathematical proofs. Instead of relying on interpersonal or inter-organizational trust, the system uses public key cryptography, digital signatures, and zero-knowledge proofs to provide deterministic, verifiable security guarantees. This substitution transforms trust from a subjective social construct into an objective mathematical property.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If the content key is shared between content provider and DRM service entity, then decryption capability is enabled, but security and control over content access are compromised

Engineering Contradiction:
Improvedecryption capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the content key into multiple shares using secret sharing schemes. Instead of a single shared key, the original key is divided into multiple parts that are distributed to different entities. No single entity possesses the complete key, and only a threshold number of shares can reconstruct it. This enables decryption capability while distributing security risk and preventing any single point of failure or compromise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted third party serves as an intermediary that holds and manages the content key securely. Rather than sharing the key directly between the content provider and DRM service entity, the TTP intermediates key distribution and access control. The TTP can release key shares or authorize decryption only when proper credentials and permissions are verified, maintaining security while enabling necessary decryption operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the DRM service entity controls the content key, then access control and licensing are improved, but the content provider loses control over their own content

Engineering Contradiction:
Improveaccess controlVSAvoidcontent provider control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments control authority by dividing key management responsibilities. The content provider holds some key shares and control rights, while the DRM service entity holds others. Access control decisions require collaboration between multiple parties, ensuring that no single entity has complete control. This segmentation enables reliable access control through multi-party authorization while preserving content provider control through their retained key shares and rights.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted third party performs preliminary actions by pre-generating key pairs and establishing cryptographic bindings between content, licenses, and access rights before distribution. Content providers can embed cryptographic identifiers and access policies in advance, and the TTP pre-configures key material that enforces these policies. This preliminary setup enables automated access control execution while maintaining content provider control through the embedded policies and identifiers they specified in advance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2359291B1Method and device for managing digital content
Publication Date: 2016.08.17 KONINKLIJKE PHILIPS NV
  • EP2359291B1 patent drawingFigure 1~2
  • EP2359291B1 patent drawingFigure 3A~3D
  • EP2359291B1 patent drawingFigure 4~6

AI summary

The invention provides a method and devices for managing digital content, the method comprising the steps of sending, by a first device (21), an encrypted content key (202) to a second device (22); sending, by said second device (22) to a third device (23), a license data describing the rights to use said digital content by said third device (23) in response to a request from said third device (23) to use said digital content, wherein said license data includes said encrypted content key (202); and receiving, by said third device (23) from said first device (21), data for decrypting said encrypted content key (202).