Digital Content Key Management via Trusted Third Party Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In digital content management, independent content providers and DRM service entities often lack trust, making it difficult to manage digital rights effectively, as they have conflicting interests and require secure, reliable methods for content key distribution and decryption.
Innovation Solution
The system involves the content provider encrypting the content key, sending it to the DRM service entity, which then releases license data including the encrypted key to the user, while the content provider decrypts the key and sends it to the user upon authorization, using a commutative encryption method to ensure secure decryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the content provider and DRM service entity are independent entities, then the content provider can maintain independence and control over their content, but trust and reliable key management become difficult to establish
Solution Approach 1:
The patent introduces a trusted third party (TTP) as an intermediary that generates key pairs and manages cryptographic operations. The TTP acts as a neutral mediator between the content provider and DRM service entity, enabling them to trust each other through the TTP's cryptographic guarantees without needing to trust each other directly. This resolves the contradiction by maintaining entity independence while establishing reliable trust through the intermediary.
Solution Approach 2:
The patent replaces the mechanical/social concept of trust between independent entities with a cryptographic system based on mathematical proofs. Instead of relying on interpersonal or inter-organizational trust, the system uses public key cryptography, digital signatures, and zero-knowledge proofs to provide deterministic, verifiable security guarantees. This substitution transforms trust from a subjective social construct into an objective mathematical property.
2Ease of operation
If the content key is shared between content provider and DRM service entity, then decryption capability is enabled, but security and control over content access are compromised
Solution Approach 1:
The patent segments the content key into multiple shares using secret sharing schemes. Instead of a single shared key, the original key is divided into multiple parts that are distributed to different entities. No single entity possesses the complete key, and only a threshold number of shares can reconstruct it. This enables decryption capability while distributing security risk and preventing any single point of failure or compromise.
Solution Approach 2:
The trusted third party serves as an intermediary that holds and manages the content key securely. Rather than sharing the key directly between the content provider and DRM service entity, the TTP intermediates key distribution and access control. The TTP can release key shares or authorize decryption only when proper credentials and permissions are verified, maintaining security while enabling necessary decryption operations.
3Reliability
If the DRM service entity controls the content key, then access control and licensing are improved, but the content provider loses control over their own content
Solution Approach 1:
The patent segments control authority by dividing key management responsibilities. The content provider holds some key shares and control rights, while the DRM service entity holds others. Access control decisions require collaboration between multiple parties, ensuring that no single entity has complete control. This segmentation enables reliable access control through multi-party authorization while preserving content provider control through their retained key shares and rights.
Solution Approach 2:
The trusted third party performs preliminary actions by pre-generating key pairs and establishing cryptographic bindings between content, licenses, and access rights before distribution. Content providers can embed cryptographic identifiers and access policies in advance, and the TTP pre-configures key material that enforces these policies. This preliminary setup enables automated access control execution while maintaining content provider control through the embedded policies and identifiers they specified in advance.
Data Source
Figure 1~2
Figure 3A~3D
Figure 4~6
AI summary
The invention provides a method and devices for managing digital content, the method comprising the steps of sending, by a first device (21), an encrypted content key (202) to a second device (22); sending, by said second device (22) to a third device (23), a license data describing the rights to use said digital content by said third device (23) in response to a request from said third device (23) to use said digital content, wherein said license data includes said encrypted content key (202); and receiving, by said third device (23) from said first device (21), data for decrypting said encrypted content key (202).