DRM License Provisioning with Dynamic Key Protection Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DRM systems face challenges in providing flexible and reliable security enhancements, particularly due to standardized and open-source clients, lack of regular revalidation, and vulnerabilities in Trusted Execution Environments (TEE), leading to potential breaches and revenue losses.
Innovation Solution
A DRM system that includes a license server and client device with server-directed security elements, allowing dynamic provisioning and updating, ensuring compatibility with existing systems, and incorporating a hierarchical key protection mechanism to enhance security and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If standardized open-source DRM clients are used, then ease of manufacture and deployment is improved, but security reliability deteriorates due to porting requirements and potential breaches
Solution Approach 1:
The patent implements dynamic security elements that can be updated and changed over time. Security functions and keys are not static but can be modified through remote provisioning, allowing the system to adapt to new threats while maintaining standardized client deployments.
Solution Approach 2:
The patent pre-provisions security material and security functions to client devices before they are vulnerable to attacks. Security configurations, keys, and functions are installed in advance and can be updated before threats materialize, rather than reacting after breaches occur.
2Reliability
If TEE-based security is implemented, then security protection is improved, but vulnerability to hacking deteriorates due to lack of certified hardware secure elements
Solution Approach 1:
The patent combines software-based security functions with hardware-based key storage. Instead of relying solely on TEE or solely on hardware secure elements, it creates a composite security architecture where security functions run in software while cryptographic keys are protected in hardware, leveraging the strengths of both approaches.
Solution Approach 2:
The patent introduces security functions as intermediary components between the cryptographic keys and the DRM operations. These functions act as a protective layer that can be updated and managed remotely, mediating between the hardware secure elements and the application layer without exposing the keys directly.
3Adaptability or versatility
If dynamic security updates are implemented, then security flexibility is improved, but system complexity deteriorates due to provisioning and management requirements
Solution Approach 1:
The patent creates universal security functions that can operate across different device types and DRM scenarios. The same security function framework can handle multiple security requirements and can be provisioned through standardized interfaces, reducing the need for device-specific customizations.
Solution Approach 2:
The patent implements self-service provisioning mechanisms where client devices can automatically receive and install security updates without manual intervention. The system manages its own security provisioning through automated processes, reducing the operational complexity of deploying and maintaining security across distributed devices.
4Reliability
If regular revalidation is implemented, then security reliability is improved, but loss of time increases due to additional validation steps
Solution Approach 1:
The patent implements periodic revalidation of security elements at predetermined intervals rather than continuously. Security functions and keys are validated at scheduled times, providing regular security checks while minimizing disruption to normal operations. This periodic approach balances reliability with time efficiency.
Data Source
Figure 1
Figure 2~3A
Figure 3B
AI summary
A license server, conditionally authorizing access by a DRM client device to protected contents upon receiving a license request from the device, receives a device-associated encryption key (K'DRM) exploited for protecting access information (Kc) to the protected contents, and if authorization conditions are met, generates protected access information from the access information with the encryption key and with a security function (UP-S) available to the license server independently from the received license request and generates a license (LIC3-1S) containing the protected access information and sent to the device. The license request includes server-directed security elements (S-DATA, PF-S) that are exploited for protecting the access information so as to generate pre-protected access information (P-Kc), to which the security function is applied with the device-associated key to generate the protected access information.