Distributed Security Management for Home Network Media Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital rights management (DRM) systems for home networks rely on centralized servers, which are cumbersome and prone to failure, and require complex configurations, while also compromising user privacy and not supporting mobile devices or group management, especially in home networking scenarios.

Innovation Solution

A distributed security management framework that uses media devices as logical servers for key management and authentication, eliminating the need for a centralized server and allowing for mobile operation without user intervention, while maintaining provider control and user privacy through public/private key encryption and a Proxy Network Access Translator module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized server is used for key management and authentication, then security control is improved, but device complexity and configuration difficulty increase

Engineering Contradiction:
Improvesecurity controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the centralized server functionality into distributed components across multiple media devices. Each device maintains its own security credentials and can independently authenticate with rights issuers, eliminating the need for a single centralized server while maintaining security control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Media devices are empowered to perform self-authentication and self-key-management without requiring a centralized server. Each device can independently create security associations with rights issuers and manage its own cryptographic credentials, reducing configuration complexity.

Inventive Principle:
Principle #25Self-service

2Reliability

If a centralized server is deployed, then security management is improved, but system reliability deteriorates due to single point of failure

Engineering Contradiction:
Improvesecurity managementVSAvoidsystem reliability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security management function from a single centralized server and distributes it across multiple media devices. This creates redundancy where if one device fails, others can continue to provide security management services, eliminating the single point of failure.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If each device creates separate security associations with media providers, then device autonomy is improved, but communication overhead increases

Engineering Contradiction:
Improvedevice autonomyVSAvoidcommunication overhead
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent merges the security association management for multiple media providers into a single unified security association at the gateway device. This allows the gateway to handle authentication and key management for all providers on behalf of the home network, reducing the communication overhead while maintaining device autonomy.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If smart cards are used for DRM interworking, then device compatibility is improved, but device complexity and cost increase

Engineering Contradiction:
ImproveDRM compatibilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the smart card functionality from individual media devices and consolidates it into a separate gateway device. This allows media devices to achieve DRM compatibility through the gateway's smart card capabilities without requiring each device to have its own smart card interface, reducing device complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8893302B2Method for managing security keys utilized by media devices in a local area network
Publication Date: 2014.11.18 GOOGLE TECHNOLOGY HOLDINGS LLC
  • US8893302B2 patent drawing
  • US8893302B2 patent drawing
  • US8893302B2 patent drawing

AI summary

A controller (900) for transferring media content rights between media devices comprising a memory (906), a user interface (910) and a transceiver (902). The memory (906) stores a list of media devices (914) capable of receiving the permissions associated with the media content from an originating device and an encryption key (920) that may be used to encrypt the permissions. The user interface (910) detects a user selection of a target device from the list of media devices (914). The transceiver (902) communicates an address (916) associated with the target device and the encryption key (920) to the originating device. Thus, the originating device is able to encrypt the permissions using the encryption key (920) and send the encrypted permissions to the address (916) associated with the target device.