Single-Use DRM Token for Secure Content Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users authorized to view rights-protected content face cumbersome processes when accessing it on unauthorized devices, as they need to enter authorization information, and there are risks of unauthorized access if this information is stored or shared.
Innovation Solution
A system where a first consumer electronics device provides a private key to a second device upon physical contact, allowing access to rights-managed content without requiring additional authentication, with the key being single-use and tied to a specific time threshold, ensuring secure and seamless access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authorization information is entered on a foreign device to access proprietary content, then the user can view the content on the unauthorized device, but the process becomes cumbersome and there is risk of unauthorized access
Solution Approach 1:
The patent introduces a digital token as an intermediary mechanism. Instead of requiring users to enter their authorization information directly on foreign devices, the system issues a token to the authorized user's device, which then presents this token to the content provider. This mediator (the token) enables content access on unauthorized devices without requiring users to manually input their credentials, thus simplifying the operation while maintaining security through the token's limited scope and expiration.
2Ease of operation
If authorization information is stored on a device to enable content access, then the user can easily access content, but subsequent unauthorized access may be permitted and the information must be changed back
Solution Approach 1:
The patent employs disposable, single-use tokens that automatically expire after being used once or after a predetermined time period. These tokens are designed to be inexpensive and short-lived, eliminating the need for permanent storage of authorization information on devices. After the token is consumed or expires, it cannot be reused, thereby preventing unauthorized access while maintaining ease of operation during its valid period.
3Extent of automation
If a private key is provided to a second device for single-use access, then seamless content access is enabled without manual login, but the key must be managed securely and cannot be reused
Solution Approach 1:
The patent extracts the authentication burden from the user and shifts it to the system. Instead of requiring users to manually handle and manage private keys, the system automatically generates, stores, and manages these cryptographic credentials. The user simply needs to present themselves (e.g., through biometric verification), and the system handles the complex key management operations in the background, thereby achieving high automation while reducing the complexity burden on the user.
Data Source
AI summary
A first consumer electronics device includes a computer readable storage medium bearing instructions executable by a processor, and a processor configured for accessing the computer readable storage medium to execute the instructions to configure the processor for receiving a signal indicative of close proximity of the first CE device to a second CE device. The instructions also configure the processor for providing a private key to the second CE device in response to receiving the signal. The private key is associated with a digital rights management (DRM) account for which the first CE device has been configured to access, and is configured for a single use by the second CE device to access a first audio video (AV) content without the second CE device communicating any other authentication information associated with the DRM account to access the first AV content to a content provider associated with the first AV content.


