Decoupling Authentication and Licensing in Digital Rights Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Digital Rights Management (DRM) systems face issues such as license destruction when content is damaged, difficulty in revoking user rights, and limitations in limited-connectivity environments, particularly in 'impulse buying' scenarios where users cannot access content without network connectivity.
Innovation Solution
A system that allows clients to request operations on digital content by interacting with a rights-management server, using a protocol like DReaM-MMI, which sends requests with usage parameters, receives responses indicating permission, and facilitates subsequent requests through hints, even in offline scenarios, enabling periodic updates and aggregated operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the license is stored along with the content in existing DRM systems, then the license is readily available for content access, but the license is destroyed when the content or device is damaged
Solution Approach 1:
The patent separates the license from the content by introducing a distinct license storage location (secure element or remote server) independent of the content storage. This segmentation ensures that content damage does not affect license integrity, resolving the contradiction between easy access and reliability.
Solution Approach 2:
The patent introduces a license service as an intermediary between the content and the client device. The license service manages license issuance, storage, and revocation independently from content delivery, allowing licenses to survive content damage while maintaining secure access control.
2Adaptability or versatility
If the license is stored with the content in existing DRM systems, then users can access content without continuous server connection, but rights revocation becomes impossible without server contact
Solution Approach 1:
The patent implements dynamic license management where licenses have embedded expiration dates and can be remotely revoked through the license service. This allows offline access within valid periods while enabling dynamic revocation when policies change, resolving the contradiction between offline versatility and revocation ease.
Solution Approach 2:
The patent establishes a feedback mechanism where the license service can send revocation commands to client devices. When rights need to be revoked, the system communicates this back to the client, ensuring policy compliance while maintaining offline functionality until revocation is processed.
3Reliability
If existing DRM systems require network connectivity for license verification, then rights management is secure, but impulse buying in limited-connectivity environments fails
Solution Approach 1:
The patent implements preliminary license issuance where licenses are granted in advance before actual content consumption. This allows users to purchase and receive licenses offline, then verify and use them later when connectivity is available, enabling impulse buying in limited-connectivity environments while maintaining security through subsequent verification.
Solution Approach 2:
The patent provides a cushioning mechanism by allowing licenses to be issued and stored locally before network verification. This preliminary licensing approach cushions against connectivity issues during impulse purchases, allowing the transaction to proceed with post-purchase verification when connection is restored.
Data Source
AI summary
One embodiment of the present invention provides a system that facilitates issuing rights in a digital rights management system. The system operates by sending a request to perform an operation on an item of content from a client to a rights-management server, wherein the request includes a usage parameter which specifies constraints involved in performing the operation. Next, the system receives a response from the rights-management server, wherein the response indicates whether or not the client has rights to perform the operation in accordance with the constraints specified by the usage parameter. Note that the response may also include a hint that facilitates generating subsequent requests to perform the operation. Finally, if the client has rights to perform the operation, the system performs the operation on the item of content.


