Deterministic Content Encryption Key Generation Across Distinct Units
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital rights management (DRM) systems face challenges in efficiently generating and managing common content encryption keys across distinct encryption units, leading to complexities in encrypting and decrypting content items representing different portions of a media object, such as varying bit rates or temporal segments, without a centralized key store.
Innovation Solution
A system and method for deterministic generation of a common content encryption key on distinct encryption units, where each unit uses a shared base secret and a media object identifier to generate equivalent encryption keys for content items, ensuring that all encrypted items require the same decryption key, thus eliminating the need for a centralized key store and facilitating seamless playback.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a centralized content encryption key store is used, then key management is simplified, but system complexity and single point of failure risk increase
Solution Approach 1:
The patent extracts the centralized key store from the system and replaces it with distributed key generation. Each encryption unit independently generates its own key pair, eliminating the need for a centralized authority to manage keys. This removes the single point of failure while distributing key management responsibility across multiple independent units.
Solution Approach 2:
Each encryption unit performs self-key generation and self-certificate creation without requiring intervention from a centralized key store. The units autonomously manage their own cryptographic credentials, generating keys and certificates locally based on shared secrets and media object identifiers, thereby eliminating dependency on centralized key management infrastructure.
2Adaptability or versatility
If distinct encryption units generate independent keys for different content items, then encryption flexibility is improved, but decryption complexity increases
Solution Approach 1:
The patent merges the decryption process by ensuring all encryption units generate equivalent keys for the same media object. Different encryption units produce different key pairs, but when encrypting the same content item, they all use keys that can be decrypted by the corresponding decryption unit, creating a unified decryption experience across distributed units.
Solution Approach 2:
The system changes the key generation parameters dynamically based on the media object identifier and shared secret. Each encryption unit uses the same deterministic parameters (shared secret + media object ID) to generate equivalent keys, ensuring consistency across units while maintaining the ability to handle different content items with different identifiers.
3Ease of operation
If a centralized key store is implemented, then key distribution is simplified, but security vulnerability increases
Solution Approach 1:
The patent removes the centralized key store that creates security vulnerabilities from the system. By extracting this single point of weakness and replacing it with distributed key generation, the system eliminates the attack surface associated with centralized key storage while maintaining secure key distribution through cryptographic protocols between encryption units and content delivery networks.
Data Source
AI summary
Various embodiments of a system and method for deterministic generation of a common content encryption key on distinct encryption units are described. Embodiments may include, for each given content item of multiple content items that represent one or more portions of a common media object, controlling a different encryption unit of multiple distinct encryption units to i) generate a content encryption key for the given content item based on: a common base secret shared by the multiple distinct encryption units, and an identifier specific to the media object, and ii) encrypt the given content item with the respective content encryption key generated for that content item in order to generate a respective encrypted content item. Each content encryption key generated for a given content item may be equivalent to each other content encryption key such that decryption of each encrypted content item requires a common decryption key.


