DRM Domain Session Key Exchange for Secure User Device Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital rights management (DRM) systems face challenges in ensuring secure communications between user devices and domain enforcement agents, as existing authentication methods can lead to high loads and compromised security, especially when using shared keys for encryption.
Innovation Solution
A method is introduced where a domain session key is exchanged between a user device and a domain enforcement agent to establish a secure session, with information encrypted using this shared key for secure information exchange, and a new session key can be generated for secure communication between user devices within the same domain.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing authentication methods such as OCSP are used for security communications between user devices, then authentication can be performed, but a large load is applied to user devices and communication security cannot be ensured
Solution Approach 1:
The patent introduces a domain enforcement agent (DEA) as an intermediary between user devices and the rights issuer. The DEA manages domain rights objects and handles authentication, reducing the direct authentication burden on user devices while ensuring secure communications through the intermediary's verification processes
Solution Approach 2:
The patent extracts the authentication and key management functions from the user devices and concentrates them in the domain enforcement agent. This separation removes the complex authentication burden from individual devices while maintaining security through centralized management
2Adaptability or versatility
If a domain key stored in the domain rights object is used for encryption, then all members of the user domain can access content, but communication security between user devices is compromised since the domain key is known to all members
Solution Approach 1:
The patent segments the domain key into multiple individual keys, each assigned to specific user devices. Instead of all devices sharing a single domain key, each device has its own key derived from the domain rights object, allowing content access while ensuring that communication between devices remains secure since individual keys are not shared
Solution Approach 2:
The patent applies local quality by giving each user device a unique key derived from the domain rights object rather than a universal key. This allows each device to have appropriate access rights while maintaining local security for communications, as each device's key is specific to that device
3Reliability
If a new session key is generated for communication between user devices, then communication security is improved, but additional key management complexity is introduced
Solution Approach 1:
The patent enables user devices to self-generate session keys for communication using their individual keys derived from the domain rights object. This self-service approach improves communication security through unique session keys while avoiding additional key management complexity, as devices autonomously generate keys without requiring centralized key distribution
Data Source
AI summary
A method for joining a user domain based on digital right management (DRM), a method for exchanging information between a user device and a domain enforcement agent, and a method for exchanging information between user devices belonging to the same user domain include sharing a domain session key between the user device and the domain enforcement agent or between the user devices belonging to the same user domain. Information is exchanged through a secure session set up between the user device and domain enforcement agent or between the user devices, and information exchange occurs through encryption/decryption using the domain session key.


