Single-Use DRM Token for Secure Content Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users authorized to view rights-protected content face cumbersome processes when accessing it on unauthorized devices, as they need to enter authorization information, and there are risks of unauthorized access if this information is stored or shared.

Innovation Solution

A system where a first consumer electronics device provides a private key to a second device upon physical contact, allowing access to rights-managed content without requiring additional authentication, with the key being single-use and tied to a specific time threshold, ensuring secure and seamless access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authorization information is entered on a foreign device to access proprietary content, then the user can view the content on the unauthorized device, but the process becomes cumbersome and there is risk of unauthorized access

Engineering Contradiction:
Improvecontent access processVSAvoidauthorization security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a digital token as an intermediary mechanism. Instead of requiring users to enter their authorization information directly on foreign devices, the system issues a token to the authorized user's device, which then presents this token to the content provider. This mediator (the token) enables content access on unauthorized devices without requiring users to manually input their credentials, thus simplifying the operation while maintaining security through the token's limited scope and expiration.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authorization information is stored on a device to enable content access, then the user can easily access content, but subsequent unauthorized access may be permitted and the information must be changed back

Engineering Contradiction:
Improvecontent accessVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent employs disposable, single-use tokens that automatically expire after being used once or after a predetermined time period. These tokens are designed to be inexpensive and short-lived, eliminating the need for permanent storage of authorization information on devices. After the token is consumed or expires, it cannot be reused, thereby preventing unauthorized access while maintaining ease of operation during its valid period.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Extent of automation

If a private key is provided to a second device for single-use access, then seamless content access is enabled without manual login, but the key must be managed securely and cannot be reused

Engineering Contradiction:
Improveauthentication processVSAvoidkey management system
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent extracts the authentication burden from the user and shifts it to the system. Instead of requiring users to manually handle and manage private keys, the system automatically generates, stores, and manages these cryptographic credentials. The user simply needs to present themselves (e.g., through biometric verification), and the system handles the complex key management operations in the background, thereby achieving high automation while reducing the complexity burden on the user.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9223942B2Automatically presenting rights protected content on previously unauthorized device
Publication Date: 2015.12.29 SONY GROUP CORP
  • US9223942B2 patent drawing
  • US9223942B2 patent drawing
  • US9223942B2 patent drawing

AI summary

A first consumer electronics device includes a computer readable storage medium bearing instructions executable by a processor, and a processor configured for accessing the computer readable storage medium to execute the instructions to configure the processor for receiving a signal indicative of close proximity of the first CE device to a second CE device. The instructions also configure the processor for providing a private key to the second CE device in response to receiving the signal. The private key is associated with a digital rights management (DRM) account for which the first CE device has been configured to access, and is configured for a single use by the second CE device to access a first audio video (AV) content without the second CE device communicating any other authentication information associated with the DRM account to access the first AV content to a content provider associated with the first AV content.