DRM Key Segmentation for Secure Content Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital rights management methods are not effective in controlling and protecting digital content after sale, failing to provide secure access to restricted content.
Innovation Solution
A system and method that uses digital rights management keys to authorize access to restricted content by receiving a content request message, determining the validity of user and content identifiers, and providing access upon successful validation, with additional determinations based on fingerprints and encryption properties to ensure secure decryption and usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If digital rights management methods are used to control and protect digital content after sale, then access control capability is improved, but reliability of protection is worsened because existing DRM methods are not effective
Solution Approach 1:
The patent segments the DRM key into multiple parts and distributes them across multiple servers. No single server holds the complete key, so compromising one server does not reveal the entire key. This segmentation approach maintains access control capability while significantly improving protection reliability by eliminating single points of failure.
Solution Approach 2:
The patent introduces a trusted third-party authority that generates and manages the DRM key distribution. This intermediary entity coordinates between content owners, users, and multiple servers, ensuring that key fragments are properly distributed and reconstructed only when appropriate. This mediator layer enhances both access control versatility and protection reliability through centralized coordination.
2Reliability
If multiple determination checks are performed for content access validation, then security and reliability are improved, but device complexity increases due to multiple validation modules and determination processes
Solution Approach 1:
The validation process is segmented into distinct determination modules, each responsible for specific checks (user authentication, content ownership verification, key validity). This modular segmentation improves security through comprehensive validation while managing complexity by organizing checks into separate, manageable units with clear responsibilities.
Solution Approach 2:
The system performs preliminary validation checks before granting access to DRM-protected content. User credentials, content ownership, and key validity are verified in advance through multiple determination steps. This preliminary action ensures high security reliability while organizing complexity into a structured sequence of pre-access validations.
3Reliability
If digital rights management keys are distributed across multiple servers, then reliability and security are improved, but device complexity and system complexity increase
Solution Approach 1:
The DRM key is divided into multiple fragments and stored across different servers. Each server holds only a portion of the key, making it impossible to compromise the entire key by attacking a single server. This segmentation improves key storage reliability and security while the modular fragment structure helps manage system complexity.
Solution Approach 2:
The patent implements a nested structure where key fragments are embedded within encrypted containers that include metadata about the fragment's purpose and validity conditions. This nesting approach secures the key distribution across multiple servers while organizing the complexity through hierarchical encryption layers and structured data formats.
Data Source
AI summary
According to an example embodiment of the invention, there is provided a system for providing access to access restricted content to a user, the system including a communication arrangement operable to receive a content request message, the content request message including a content identifier, a processor configured to cause a first determination to be performed to yield a positive or a negative result, a validation module configured to, in response to the first determination yielding a positive result, obtain a first digital rights management key, the processor being further configured to cause a second determination to be performed to yield a positive or a negative result, and responsive to the first and second determinations yielding a positive result, the validation module is configured to cause access to the access restricted content to be provided to the user.


