Execution Environment Authenticity Verification for DRM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Digital rights management systems face vulnerabilities in the execution environment, particularly in software plug-ins and key handling, where attackers can tamper with the program code and retrieve decryption keys, compromising content protection.
Innovation Solution
A method is introduced to verify the authenticity of the execution environment by deriving digital parameters from it using a predetermined algorithm, ensuring the program module processes input data correctly and securely, thereby preventing tampering and maintaining content integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital rights management systems use encryption techniques and key distribution to protect content, then content security is improved, but the execution environment becomes vulnerable to tampering and key retrieval attacks
Solution Approach 1:
The patent applies preliminary action by verifying the authenticity of the execution environment before executing the computer program module. The system checks whether the execution environment meets predetermined criteria and derives digital parameters from it to ensure it has not been tampered with, preventing attackers from retrieving decryption keys or tampering with protected content
Solution Approach 2:
The patent introduces an intermediary verification mechanism that acts as a mediator between the encrypted content and the execution environment. The system derives digital parameters from the execution environment and uses these parameters to verify its authenticity, creating a security layer that prevents direct access to decryption keys and protected content
2Ease of operation
If the execution environment is made open and accessible for content processing, then ease of operation is improved, but security against tampering deteriorates
Solution Approach 1:
The patent applies local quality by making different parts of the system have different security properties. The execution environment is made open and accessible for normal content processing operations, while specific critical components (decryption keys, protected content) remain secured through the verification mechanism that checks digital parameters derived from the execution environment
3Adaptability or versatility
If decryption keys are distributed to enable content playback, then content accessibility is improved, but vulnerability to key retrieval attacks increases
Solution Approach 1:
The patent extracts the decryption keys from the executable code and stores them separately in the execution environment. The computer program module cannot directly access the keys; instead, the system derives digital parameters from the execution environment to verify its authenticity before enabling content playback, preventing attackers from retrieving keys through reverse engineering or memory observation
4Adaptability or versatility
If software plug-ins are used to enforce terms and conditions, then functionality is improved, but susceptibility to code tampering increases
Solution Approach 1:
The patent applies preliminary action by verifying the authenticity of the execution environment and deriving digital parameters from it before the software plug-ins execute. This verification ensures that the plug-ins run in a trusted environment, preventing attackers from tampering with the code to remove terms and conditions or bypass content protection mechanisms
Data Source
AI summary
A method and system for verifying authenticity of at least part of an execution environment for executing a computer module is provided. The computer program module is operative to cause processing of digital input data in dependence on a plurality of predetermined digital parameters. At least part of one of the plurality of predetermined digital parameters is driven from the at least part of the execution environment.


