DRM Certificate Authority Pseudonym Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DRM systems are vulnerable to unauthorized introduction and distribution of commercial content, and users cannot maintain anonymity in networks containing both commercial and personal content items, as any user can create content rights for personal items, leading to potential substitution attacks and lack of privacy.

Innovation Solution

A method and system that utilize a fingerprint of the content item and an identifier of the content introducer, with a certificate authority generating a pseudonym and a signed content identifier certificate, ensuring only authorized users can introduce and access content items, preventing unauthorized distribution and maintaining user anonymity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If any user is authorized to create content rights for personal content items, then users can effectively become content providers and introduce personal content, but malicious users can substitute commercial content items by hacking compliant devices and re-encrypting content with leaked content keys

Engineering Contradiction:
Improveuser ability to create content rightsVSAvoidcontent security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

A certificate authority acts as an intermediary between users and the DRM system. The certificate authority verifies user identities and issues digital certificates that bind user identities to content introduction rights. This intermediary prevents unauthorized substitution attacks by ensuring that only verified users can introduce content, while still allowing users to create content rights for personal content items.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

User identity verification and certificate issuance are performed in advance before content introduction. The certificate authority pre- validates user identities and issues certificates that users carry when introducing content. This preliminary action prevents security breaches by ensuring user authenticity before content rights are created, rather than attempting verification after a potential attack occurs.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If content rights are digitally signed by content providers, then unauthorized distribution of commercial content is prevented, but users cannot introduce personal content items without involving the content provider

Engineering Contradiction:
Improvecontent distribution controlVSAvoiduser content introduction capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The certificate authority provides a universal authentication mechanism that serves multiple functions: it verifies user identities, enables users to introduce personal content, and maintains content provider control over commercial content. Users receive certificates that allow them to act as content providers for personal content while the system still enforces proper authorization for commercial content through the same certificate verification process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system segments content introduction rights by content type. Commercial content introduction requires content provider-signed certificates, while personal content introduction requires user certificates issued by the certificate authority. This segmentation allows users to introduce personal content without involving content providers, while maintaining strict control over commercial content distribution through separate authorization pathways.

Inventive Principle:
Principle #1Segmentation

3Reliability

If compliant devices check content right signatures and refuse improperly signed content, then content provider authorization is enforced, but users cannot maintain anonymity in the network

Engineering Contradiction:
Improveauthorization enforcementVSAvoiduser privacy
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

Instead of using users' real identities in content rights and certificates, the system uses pseudonymous certificates issued by the certificate authority. These pseudonymous certificates verify user authorization while preventing the linkage of content usage to users' real identities. The certificate authority can maintain the mapping between real identities and pseudonyms for accountability, but this information is not exposed in the content distribution chain, thereby protecting user privacy while maintaining authorization enforcement.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7978859B2Private and controlled ownership sharing
Publication Date: 2011.07.12 KONINKLIJKE PHILIPS NV
  • US7978859B2 patent drawing
  • US7978859B2 patent drawing
  • US7978859B2 patent drawing

AI summary

The present invention relates to a method, a device and a system for preventing unauthorized introduction of content items in a network containing compliant devices and enabling users in the network to be anonymous. A basic idea of the present invention is to provide a CA (206) with a fingerprint of a content item to be introduced in a network at which the CA is arranged. Further, the CA is provided with an identifier of a content introducer (201), which introduces the particular content item in the network. The CA compares the fingerprint to a predetermined set of fingerprints, and content item intro duction is allowed if the content item fingerprint cannot be found among the fingerprints comprised in the set. On introduction of the content item, the CA generates a pseudonym for the content introducer and creates a signed content ID certificate comprising at least said fingerprint and a unique content identifier for the content item and the pseudonym of the content introducer.