Digital Rights Management via Trusted Code Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Digital rights management systems face challenges in effectively controlling access to digital content due to the ease of copying and distribution of digital media, which threatens the security and value of copyrighted material.
Innovation Solution
A digital rights management system that includes a policy server, reader applications, and authoring software, which enforce permissions and authenticate trusted code through a public key infrastructure, ensuring only authorized code can access and manipulate digital content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If digital content is made easily copyable and distributable, then accessibility and convenience are improved, but security and copyright protection deteriorate
Solution Approach 1:
A rights management server acts as an intermediary between content owners and users. The server issues digital rights management policies that control how digital content can be accessed and used. This mediator enables easy distribution while maintaining security by enforcing copyright rules automatically in the digital realm, similar to how traditional publishing controls reproduction.
Solution Approach 2:
The patent uses digital certificates and cryptographic keys as copyable digital objects that enforce rights management. Instead of controlling physical copies, the system controls digital representations of access rights that can be distributed and verified automatically, maintaining security while enabling digital distribution.
2Reliability
If digital rights management policies are enforced, then copyright protection is improved, but ease of use and accessibility deteriorate
Solution Approach 1:
The rights management server automatically enforces copyright policies without requiring manual intervention from users or copyright holders. The system self-manages the issuance and verification of digital rights, automatically controlling access and usage based on embedded policies, thus maintaining protection while reducing operational complexity.
3Reliability
If trusted code authentication is implemented, then security is improved, but system complexity increases
Solution Approach 1:
The rights management server serves as a trusted intermediary that handles the complexity of authentication and certificate verification. Application developers don't need to implement complex security systems themselves; they simply integrate with the server's authentication mechanism, which manages the cryptographic verification and policy enforcement centrally.
Data Source
AI summary
Method, apparatus, computer programs and data structures are provided, according to at least one embodiment, wherein an author of digital content identifies at least some trusted code that the author trusts to be used to read digital content, and stores information in the unit of digital content that is capable of identifying the trusted code. In at least some embodiments, the unit of digital content is an electronic document. In other embodiments, a publisher of the trusted code, or an author of the digital content, signs the trusted code with a private key, and a certificate associated with the private key is embedded in the unit of digital content. The certificate may provide public key information associated with the private key. The public key may be used to verify that code is trusted before it is allowed access to the unit of digital content.


