Digital Rights Management via Trusted Code Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital rights management systems face challenges in effectively controlling access to digital content due to the ease of copying and distribution of digital media, which threatens the security and value of copyrighted material.

Innovation Solution

A digital rights management system that includes a policy server, reader applications, and authoring software, which enforce permissions and authenticate trusted code through a public key infrastructure, ensuring only authorized code can access and manipulate digital content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If digital content is made easily copyable and distributable, then accessibility and convenience are improved, but security and copyright protection deteriorate

Engineering Contradiction:
Improveease of copying and distributionVSAvoidsecurity and copyright protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A rights management server acts as an intermediary between content owners and users. The server issues digital rights management policies that control how digital content can be accessed and used. This mediator enables easy distribution while maintaining security by enforcing copyright rules automatically in the digital realm, similar to how traditional publishing controls reproduction.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent uses digital certificates and cryptographic keys as copyable digital objects that enforce rights management. Instead of controlling physical copies, the system controls digital representations of access rights that can be distributed and verified automatically, maintaining security while enabling digital distribution.

Inventive Principle:
Principle #26Copying

2Reliability

If digital rights management policies are enforced, then copyright protection is improved, but ease of use and accessibility deteriorate

Engineering Contradiction:
Improvecopyright protectionVSAvoidease of use and accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The rights management server automatically enforces copyright policies without requiring manual intervention from users or copyright holders. The system self-manages the issuance and verification of digital rights, automatically controlling access and usage based on embedded policies, thus maintaining protection while reducing operational complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If trusted code authentication is implemented, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The rights management server serves as a trusted intermediary that handles the complexity of authentication and certificate verification. Application developers don't need to implement complex security systems themselves; they simply integrate with the server's authentication mechanism, which manages the cryptographic verification and policy enforcement centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10229276B2Method and apparatus for document author control of digital rights management
Publication Date: 2019.03.12 ADOBE INC
  • US10229276B2 patent drawing
  • US10229276B2 patent drawing
  • US10229276B2 patent drawing

AI summary

Method, apparatus, computer programs and data structures are provided, according to at least one embodiment, wherein an author of digital content identifies at least some trusted code that the author trusts to be used to read digital content, and stores information in the unit of digital content that is capable of identifying the trusted code. In at least some embodiments, the unit of digital content is an electronic document. In other embodiments, a publisher of the trusted code, or an author of the digital content, signs the trusted code with a private key, and a certificate associated with the private key is embedded in the unit of digital content. The certificate may provide public key information associated with the private key. The public key may be used to verify that code is trusted before it is allowed access to the unit of digital content.