Execution Environment Authenticity Verification for DRM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital rights management systems face vulnerabilities in the execution environment, particularly in software plug-ins and key handling, where attackers can tamper with the program code and retrieve decryption keys, compromising content protection.

Innovation Solution

A method is introduced to verify the authenticity of the execution environment by deriving digital parameters from it using a predetermined algorithm, ensuring the program module processes input data correctly and securely, thereby preventing tampering and maintaining content integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If digital rights management systems use encryption techniques and key distribution to protect content, then content security is improved, but the execution environment becomes vulnerable to tampering and key retrieval attacks

Engineering Contradiction:
Improvecontent securityVSAvoidexecution environment vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by verifying the authenticity of the execution environment before executing the computer program module. The system checks whether the execution environment meets predetermined criteria and derives digital parameters from it to ensure it has not been tampered with, preventing attackers from retrieving decryption keys or tampering with protected content

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism that acts as a mediator between the encrypted content and the execution environment. The system derives digital parameters from the execution environment and uses these parameters to verify its authenticity, creating a security layer that prevents direct access to decryption keys and protected content

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the execution environment is made open and accessible for content processing, then ease of operation is improved, but security against tampering deteriorates

Engineering Contradiction:
Improveexecution accessibilityVSAvoidtamper resistance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by making different parts of the system have different security properties. The execution environment is made open and accessible for normal content processing operations, while specific critical components (decryption keys, protected content) remain secured through the verification mechanism that checks digital parameters derived from the execution environment

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If decryption keys are distributed to enable content playback, then content accessibility is improved, but vulnerability to key retrieval attacks increases

Engineering Contradiction:
Improvecontent accessibilityVSAvoidkey retrieval vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the decryption keys from the executable code and stores them separately in the execution environment. The computer program module cannot directly access the keys; instead, the system derives digital parameters from the execution environment to verify its authenticity before enabling content playback, preventing attackers from retrieving keys through reverse engineering or memory observation

Inventive Principle:
Principle #2Taking out (Extraction)

4Adaptability or versatility

If software plug-ins are used to enforce terms and conditions, then functionality is improved, but susceptibility to code tampering increases

Engineering Contradiction:
Improvefunctional capabilityVSAvoidcode integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by verifying the authenticity of the execution environment and deriving digital parameters from it before the software plug-ins execute. This verification ensures that the plug-ins run in a trusted environment, preventing attackers from tampering with the code to remove terms and conditions or bypass content protection mechanisms

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8700915B2Method and system for verifying authenticity of at least part of an execution environment for executing a computer module
Publication Date: 2014.04.15 IRDETO BV
  • US8700915B2 patent drawing
  • US8700915B2 patent drawing
  • US8700915B2 patent drawing

AI summary

A method and system for verifying authenticity of at least part of an execution environment for executing a computer module is provided. The computer program module is operative to cause processing of digital input data in dependence on a plurality of predetermined digital parameters. At least part of one of the plurality of predetermined digital parameters is driven from the at least part of the execution environment.