DRM Engine Decoy Cipher Blocks for Plaintext Injection Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital rights management (DRM) systems are vulnerable to plaintext injection attacks, where attackers can manipulate ciphertext to locate and extract plaintext data in device memory, especially in open non-trusted environments like PCs and smartphones, due to the lack of cryptographic binding between ciphertext and its license.

Innovation Solution

A DRM engine system that outputs decoy cipher blocks with specific patterns to different memory regions during decryption, making it difficult for attackers to distinguish between plaintext and decoy blocks, thereby enhancing protection against plaintext injection attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If plaintext cipher blocks are output to memory regions during decryption, then the DRM system can process and deliver content, but attackers can locate and extract plaintext data through pattern recognition

Engineering Contradiction:
Improvedecryption processing capabilityVSAvoidplaintext injection attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies the 'Blessing in disguise' principle by converting the harmful pattern recognition capability of attackers into a beneficial security mechanism. Decoy cipher blocks with deliberate patterns (e.g., alternating identical blocks) are injected into memory regions during decryption. These patterns, which would normally help attackers locate plaintext, now serve to confuse attackers by creating false positive matches that lead them away from actual plaintext data, thereby protecting the DRM system while maintaining normal decryption operations

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent applies the 'Intermediary' principle by introducing decoy cipher blocks as intermediary elements between the decryption process and the plaintext output. These decoy blocks act as mediators that interfere with the attacker's pattern recognition process. The decoys are inserted into memory regions alongside or instead of actual plaintext blocks, serving as a protective layer that disrupts the direct mapping between ciphertext patterns and plaintext locations without affecting the legitimate decryption functionality

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If decoy cipher blocks with patterns are output to memory regions, then protection against plaintext injection attacks is enhanced, but the system complexity increases

Engineering Contradiction:
Improvesecurity protection against attacksVSAvoiddecryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies the 'Segmentation' principle by dividing the memory output into distinct segments: legitimate plaintext cipher blocks and decoy cipher blocks. Each segment serves a specific function - plaintext blocks for content delivery and decoy blocks for security protection. The decoys are segmented into different memory regions and can use different patterns, allowing the system to maintain complex security measures while keeping the overall architecture manageable through clear functional separation

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies the 'Parameter changes' principle by dynamically adjusting parameters of the decoy cipher blocks, such as their patterns, frequencies, and distribution across memory regions. The system can vary the pattern characteristics (e.g., alternating identical blocks versus other patterns) and the proportion of decoys to plaintext blocks based on security requirements. This allows the system to adapt its complexity level and security posture without fundamental architectural changes

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9262639B2Plaintext injection attack protection
Publication Date: 2016.02.16 CISCO TECHNOLOGY INC
  • US9262639B2 patent drawing
  • US9262639B2 patent drawing
  • US9262639B2 patent drawing

AI summary

A system including a memory having regions including a first and second region, the first region being different from the second region, and a digital rights management engine to receive a plurality of ciphertext cipher blocks, decrypt the ciphertext cipher blocks yielding plaintext cipher blocks, output the plaintext cipher blocks to the first region of the memory over a period of time, provide a plurality of decoy cipher blocks in addition to the plaintext cipher blocks, the decoy cipher blocks having a pattern in which: a first one of the decoy cipher blocks consists of data, and a second one of the decoy cipher blocks consists of data which is the same as the data of the first one of the decoy cipher blocks, and output the decoy cipher blocks to the second region of the memory during the period of time. Related apparatus and methods are also included.