Portable DRM Credential Management via Smart Card

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DRM systems for mobile devices face challenges in ensuring secure and portable access to digital content, as rights objects are typically device-specific, requiring reinstallation upon device change and lacking a unified trust mechanism across different handsets and smart cards.

Innovation Solution

A method involving remote server authentication of the device, secure credential provision to a portable device, and subsequent authentication and decryption key delivery, allowing the portable device to manage and authenticate the device for access to digital content, ensuring secure and portable usage rights management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rights objects are stored on the handset, then device-specific access control is achieved, but portability and ease of operation deteriorate when device changes occur

Engineering Contradiction:
Improveaccess control securityVSAvoidportability across devices
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments the DRM functionality by separating rights object storage from the handset and placing it on the smart card instead. This allows the rights objects to be independently portable while the handset maintains its authentication capabilities. The segmentation resolves the contradiction by enabling rights portability without compromising device-specific security verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The smart card acts as an intermediary between the Rights Issuer and the handset. It receives rights objects from the Rights Issuer and provides them to authorized handsets, mediating the access control process. This intermediary role enables seamless portability while maintaining security through the card's involvement in the authentication chain.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If smart cards are used for rights object storage, then portability and security are improved, but device complexity increases due to additional authentication mechanisms

Engineering Contradiction:
Improveportability of rights objectsVSAvoidauthentication mechanism complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The smart card is designed with multi-functionality, serving both as a rights object repository and as an authentication credential provider. It contains both the rights objects and the credentials needed for handshake authentication with the Rights Issuer. This universality reduces overall system complexity by consolidating multiple functions into a single portable component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The smart card is pre-configured with credentials during its personalization process, enabling it to independently authenticate with the Rights Issuer before rights object delivery. This preliminary setup eliminates the need for complex real-time credential management during operation, simplifying the authentication process while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If handsets are individually authenticated by the Rights Issuer, then security is improved, but time and productivity are reduced due to re-authentication requirements on device change

Engineering Contradiction:
ImproveDRM compliance verificationVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Instead of re-authenticating each handset individually with the Rights Issuer, the system creates a copy of the authentication capability in the form of credentials stored on the smart card. The card receives credentials from the Rights Issuer that replicate the authentication function, allowing it to verify handset compliance locally without repeated server interactions. This copying mechanism eliminates time loss while maintaining security verification.

Inventive Principle:
Principle #26Copying

4Ease of operation

If credentials are stored on the handset, then authentication capability is maintained, but security deteriorates when the handset is compromised

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity against compromise
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The critical security credentials are extracted from the handset and relocated to the smart card, which provides a more secure isolated environment for their storage. The card's tamper-resistant design and isolated processing facility protect credentials from handset-level compromises. This extraction maintains authentication capability while significantly improving security against device compromise.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS7937750B2DRM system for devices communicating with a portable device
Publication Date: 2011.05.03 THALES DIS FRANCE SA
  • US7937750B2 patent drawing
  • US7937750B2 patent drawing

AI summary

Access of a first device, communicating with a second, portable device, to digital content is controlled by authentication of the first device by a remote server; upon successful authentication of the first device by the remote server, securely providing by the remote server credentials to the portable device, the credentials enabling the portable device to authenticate the first device; securely providing by the remote server rights objects to the portable device, the rights objects comprising usage rights and information which is necessary to access the content; authentication of the first device by the portable device using the credentials received from the remote server; and, upon successful authentication of the first device by the portable device, delivering by the portable device to the first device the information which is necessary to access the content.