Decentralized DRM Key Management via Public Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional digital rights management (DRM) systems rely on centralized key and policy stores, which introduce network latency, create single points of failure, and leave packaging systems vulnerable to security attacks, failing to meet the needs of content owners who want to keep content isolated and secure.

Innovation Solution

A decentralized management system that uses public key encryption to protect content encryption keys (CEKs) by including them within the content and license requests, eliminating the need for centralized key stores and allowing for secure distribution of content without direct connection to the key store, and also employs symmetric key encryption for efficient key provisioning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If centralized key stores are used in DRM systems, then key management is simplified, but network latency increases and single points of failure are created

Engineering Contradiction:
Improvekey management simplicityVSAvoidnetwork latency
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent segments the centralized key store into distributed key provisioning capabilities across multiple packaging entities. Each packaging entity can independently provision content encryption keys to authorized recipients without requiring communication with a centralized key store, thereby eliminating network latency while maintaining key management functionality through decentralized autonomous operation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the key provisioning functionality from the centralized key store and embeds it directly within packaging entities. This allows packaging entities to autonomously generate and distribute content encryption keys using their private keys, removing the dependency on centralized key management infrastructure and eliminating the associated network latency

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If centralized key stores are used in DRM systems, then key distribution is centralized, but single points of failure are created

Engineering Contradiction:
Improvekey distribution controlVSAvoidsystem availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the centralized key distribution authority into multiple independent packaging entities, each capable of autonomously provisioning keys. This distribution of authority eliminates single points of failure, as the system can continue to function even if some packaging entities are unavailable, thereby improving system reliability while maintaining controlled key distribution

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent enables each packaging entity to operate independently with local key provisioning capabilities. Each entity maintains its own private key and can autonomously provision content encryption keys to authorized recipients, ensuring that the failure of one entity does not affect the operational reliability of other entities in the system

Inventive Principle:
Principle #3Local quality

3Ease of manufacture

If packaging systems connect to centralized key stores, then key provisioning is simplified, but vulnerability to security attacks increases

Engineering Contradiction:
Improvekey provisioning processVSAvoidsecurity attack vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the key provisioning process from the centralized key store connection and enables packaging entities to autonomously generate and distribute content encryption keys using their private keys. This eliminates the need for packaging systems to connect to centralized key stores, removing the security vulnerability associated with such connections while maintaining simplified key provisioning through local autonomous operation

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses public key cryptography as an intermediary mechanism, where packaging entities use their private keys to encrypt content encryption keys and transmit them securely to authorized recipients. This cryptographic intermediary eliminates the need for direct connections to centralized key stores, thereby removing security vulnerabilities while maintaining secure key provisioning

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If content is packaged with content encryption keys, then content security is improved, but content isolation during packaging is compromised

Engineering Contradiction:
Improvecontent securityVSAvoidcontent exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the content encryption key from the packaging process and replaces it with a content identifier. The actual content encryption key is provisioned separately and securely to the recipient through public key cryptography, allowing the content to be packaged without exposing sensitive encryption keys while maintaining content security through the use of the content identifier for key retrieval

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20140289525A1System and method for decentralized management of keys and policies
Publication Date: 2014.09.25 ADOBE INC
  • US20140289525A1 patent drawing
  • US20140289525A1 patent drawing
  • US20140289525A1 patent drawing

AI summary

Various embodiments of a system and method for decentralized management of keys and policies are described. Various embodiments may include a computer system configured to receive a request from a remote computer system associated with a recipient of content. Such request may include an encrypted content encryption key that is encrypted with a packaging key utilized by a packaging entity. The request may also include an identifier identifying the packaging entity. In some embodiments, the request may also include policy information specifying one or more usage rights of the content. The computer system may be configured to, in response to determining the recipient is authorized to access the content, generate the packaging key based on the identifier and a secret root seed, utilize the generated packaging key to decrypt the encrypted content encryption key, and provide the decrypted content encryption key to the remote computer system.