Secure Key Management for DRM-Protected Broadcast Recordings
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely managing keys for re-encrypting CA-protected broadcast content under a DRM system, ensuring secure key processing, and maintaining interoperability between different DRM technologies while allowing random recording initiation during broadcasts without compromising bandwidth.
Innovation Solution
The method involves generating and transmitting recording information and entitlement control messages that include keys and location information, enabling secure key management and encryption within the secure environment of the CA system, and using these messages to initiate recordings under the DRM system, ensuring secure key processing and interoperability across different DRM technologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If DRM keys are generated within a consumer electronics device for re-encrypting CA broadcast content, then the content can be transformed into DRM format for storage and playback, but security risks increase significantly as access to keys would allow creation of right objects for any distributed content
Solution Approach 1:
The patent extracts the DRM key generation function from the consumer electronics device and relocates it to a secure head-end system. The head-end generates DRM keys securely and distributes only encrypted content and key identifiers to consumer devices, eliminating the security vulnerability of local key generation while maintaining DRM format compatibility for recording and playback across different devices
Solution Approach 2:
The patent introduces a secure head-end system as an intermediary between the CA broadcast system and consumer devices. This intermediary securely generates DRM keys, encrypts content with both CA and DRM protection, and distributes it to consumers. The intermediary architecture maintains security by keeping key generation centralized while enabling versatile DRM format support at the consumer level
2Ease of operation
If all recording information is made available to CA receivers at every point in time during broadcast, then random recording initiation is enabled, but bandwidth consumption increases
Solution Approach 1:
The patent applies preliminary action by pre-encrypting content with both CA and DRM keys at the head-end before transmission. Recording information including DRM key identifiers and encryption parameters is embedded in advance in the broadcast stream, allowing consumer devices to initiate recording at any point without requiring real-time key distribution, thus enabling random recording initiation while minimizing bandwidth consumption
Solution Approach 2:
The patent uses copying by distributing encrypted content that contains embedded DRM key identifiers and recording information. Instead of transmitting separate key data, the system copies the necessary recording information directly into the encrypted content stream, allowing receivers to extract and use the information locally without additional bandwidth consumption while maintaining the capability for random recording initiation
Data Source
AI summary
Methods and a systems are described for processing recordable content in a broadcast stream sent to a receiver, wherein said broadcast stream is protected in accordance with a conditional access system and wherein said receiver is configured for storing and consuming content in said broadcast stream in accordance with a digital rights management system. In this methods and systems recording information is sent in one or more entitlement control messages over a broadcast network to a receiver. Using the recording information in the entitlement control messages the receiver is able to store recordable events in a broadcast stream on a storage medium and to consume said recorded events in accordance with a digital rights management system.


