DRM Client Super-Encryption for Cross-Device Content Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital rights management (DRM) systems require multiple DRM systems to be implemented by service providers due to different content packaging and encryption methods, leading to increased costs, limited content distribution between devices, and varying security levels, as each device may use a different type of DRM system.

Innovation Solution

A method where a DRM client and content decryption module are separate entities, with the DRM client super-encrypting content keys to bind itself to a specific DRM domain, allowing only compliant DRM systems to decrypt, enabling a single DRM system to be used across multiple devices while maintaining security and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple DRM systems are implemented by service providers to support different content packaging and encryption methods, then device compatibility and content distribution flexibility are improved, but system complexity and implementation costs increase

Engineering Contradiction:
Improvedevice compatibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the DRM system into two independent components: a DRM client that handles licensing and authorization, and a content decryption module that handles decryption. This segmentation allows the decryption module to be standardized and reused across multiple DRM systems, reducing overall system complexity while maintaining device compatibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The content decryption module is designed with universal functionality to work with multiple DRM systems. By creating a standardized decryption interface and architecture, the same decryption module can serve different DRM clients and content formats, eliminating the need for separate decryption implementations for each DRM system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If multiple DRM systems are implemented by service providers, then support for different encryption methods is improved, but implementation costs increase

Engineering Contradiction:
Improveencryption method supportVSAvoidimplementation cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The content decryption module implements universal support for multiple encryption methods through a standardized interface. The module can handle different encryption algorithms (AES, DES, RC4, etc.) without requiring separate implementation for each DRM system, thereby reducing development and maintenance costs while maintaining broad encryption method support.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent enables copying of content and DRM licenses between devices within the same DRM domain. The standardized decryption module allows decrypted content to be copied and played back on different devices without requiring re-encryption or additional licensing, reducing the need for multiple DRM system implementations across the device ecosystem.

Inventive Principle:
Principle #26Copying

3Reliability

If device-specific DRM systems are used, then security is improved, but content distribution between devices is limited

Engineering Contradiction:
ImprovesecurityVSAvoidcontent distribution flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

By separating the DRM client (which maintains security through device-specific licensing) from the content decryption module (which enables cross-device playback), the system achieves both security and distribution flexibility. The decryption module can be standardized and shared across devices while the DRM client ensures device-specific authorization and security control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2815345B1Digital rights management
Publication Date: 2022.08.03 IRDETO BV
  • EP2815345B1 patent drawingFigure 1
  • EP2815345B1 patent drawingFigure 2
  • EP2815345B1 patent drawingFigure 3

AI summary

There is disclosed a method of controlling use of encrypted content by a plurality of client terminals each provided with a digital rights management (DRM) client and a content decryption module separate to the DRM client. First key information is provided for use by one or more selected ones of the DRM clients, and second key information is provided for use by one or more selected ones of the content decryptions modules. Content key information is encrypted to form encrypted content key information such that the selected ones of the content decryption modules are enabled by the second key information to recover the content key information from encrypted content key information. The encrypted content key information is further encrypted to form super-encrypted content key information such that the selected ones of the DRM clients are enabled by the first key information to recover the encrypted content key information from the super-encrypted content key information. Corresponding head-end and client terminal apparatus are also disclosed.