DRM Engine Decoy Cipher Blocks for Plaintext Injection Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Digital rights management (DRM) systems are vulnerable to plaintext injection attacks, where attackers can manipulate ciphertext to locate and extract plaintext data in device memory, especially in open non-trusted environments like PCs and smartphones, due to the lack of cryptographic binding between ciphertext and its license.
Innovation Solution
A DRM engine system that outputs decoy cipher blocks with specific patterns to different memory regions during decryption, making it difficult for attackers to distinguish between plaintext and decoy blocks, thereby enhancing protection against plaintext injection attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If plaintext cipher blocks are output to memory regions during decryption, then the DRM system can process and deliver content, but attackers can locate and extract plaintext data through pattern recognition
Solution Approach 1:
The patent applies the 'Blessing in disguise' principle by converting the harmful pattern recognition capability of attackers into a beneficial security mechanism. Decoy cipher blocks with deliberate patterns (e.g., alternating identical blocks) are injected into memory regions during decryption. These patterns, which would normally help attackers locate plaintext, now serve to confuse attackers by creating false positive matches that lead them away from actual plaintext data, thereby protecting the DRM system while maintaining normal decryption operations
Solution Approach 2:
The patent applies the 'Intermediary' principle by introducing decoy cipher blocks as intermediary elements between the decryption process and the plaintext output. These decoy blocks act as mediators that interfere with the attacker's pattern recognition process. The decoys are inserted into memory regions alongside or instead of actual plaintext blocks, serving as a protective layer that disrupts the direct mapping between ciphertext patterns and plaintext locations without affecting the legitimate decryption functionality
2Reliability
If decoy cipher blocks with patterns are output to memory regions, then protection against plaintext injection attacks is enhanced, but the system complexity increases
Solution Approach 1:
The patent applies the 'Segmentation' principle by dividing the memory output into distinct segments: legitimate plaintext cipher blocks and decoy cipher blocks. Each segment serves a specific function - plaintext blocks for content delivery and decoy blocks for security protection. The decoys are segmented into different memory regions and can use different patterns, allowing the system to maintain complex security measures while keeping the overall architecture manageable through clear functional separation
Solution Approach 2:
The patent applies the 'Parameter changes' principle by dynamically adjusting parameters of the decoy cipher blocks, such as their patterns, frequencies, and distribution across memory regions. The system can vary the pattern characteristics (e.g., alternating identical blocks versus other patterns) and the proportion of decoys to plaintext blocks based on security requirements. This allows the system to adapt its complexity level and security posture without fundamental architectural changes
Data Source
AI summary
A system including a memory having regions including a first and second region, the first region being different from the second region, and a digital rights management engine to receive a plurality of ciphertext cipher blocks, decrypt the ciphertext cipher blocks yielding plaintext cipher blocks, output the plaintext cipher blocks to the first region of the memory over a period of time, provide a plurality of decoy cipher blocks in addition to the plaintext cipher blocks, the decoy cipher blocks having a pattern in which: a first one of the decoy cipher blocks consists of data, and a second one of the decoy cipher blocks consists of data which is the same as the data of the first one of the decoy cipher blocks, and output the decoy cipher blocks to the second region of the memory during the period of time. Related apparatus and methods are also included.


