DRM Credential Provisioning via Update Server and Gateway Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing media copy protection systems, such as cable boxes and DVRs, restrict the transfer of recorded content to non-television devices due to digital rights management concerns, limiting consumer flexibility in accessing media content across devices.

Innovation Solution

A system and method for provisioning client devices with new or updated digital rights management (DRM) credentials through an update server, using an authorization token from a gateway device to authenticate and validate requests, ensuring only authorized devices can access and play back protected media content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If DRM credentials are distributed to client devices, then authorized playback is enabled, but unauthorized copying and credential exhaustion become risks

Engineering Contradiction:
Improvedevice flexibilityVSAvoidcopy protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an update server as an intermediary between the DRM credential authority and client devices. This server manages credential distribution, validates authorization tokens, and maintains inventory control. The gateway device acts as another intermediary that issues tokens only to devices in its physical vicinity, creating a trusted distribution chain that prevents unauthorized copying while enabling flexible device access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authorization by requiring client devices to obtain authorization tokens from gateway devices before they can request DRM credentials from the update server. This preliminary validation step ensures that only legitimately authorized devices can obtain credentials, preventing unauthorized copying while maintaining device flexibility for authorized users.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If DRM credentials are pre-loaded on deployed devices, then immediate playback capability is achieved, but inventory management and security control become difficult

Engineering Contradiction:
Improveimmediate playback capabilityVSAvoidcredential inventory management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements dynamic credential distribution where DRM credentials are not permanently embedded but can be provisioned, updated, or revoked through the update server. This dynamic approach allows the system to maintain immediate playback capability for authorized devices while enabling flexible inventory management, as credentials can be distributed on-demand and their distribution tracked and controlled through the server infrastructure.

Inventive Principle:
Principle #15Dynamics

3Reliability

If authorization tokens are required for credential requests, then unauthorized access is prevented, but the provisioning process becomes more complex

Engineering Contradiction:
Improveauthorization controlVSAvoidprovisioning process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The gateway device automatically issues authorization tokens to client devices that are in its physical vicinity without requiring manual intervention. The client device autonomously presents this token to the update server to obtain DRM credentials. This self-service approach maintains strong authorization control while minimizing the complexity of the provisioning process for end users, as the authorization is handled automatically through proximity-based verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9438584B2Provisioning DRM credentials on a client device using an update server
Publication Date: 2016.09.06 ARRIS ENTERPRISES LLC
  • US9438584B2 patent drawing
  • US9438584B2 patent drawing
  • US9438584B2 patent drawing

AI summary

A method of provisioning DRM credentials on a client device, comprising receiving DRM credentials at an update server from a key generation system, the DRM credentials having been encrypted by the key generation system, receiving a DRM credential request from a client device, the DRM credential request comprising a digital signature, a device class certificate, and an authorization token, authenticating the DRM credential request by validating the digital signature and the device class certificate, extracting and validating the authorization token, and providing the DRM credentials to the client device.