DRM Credential Provisioning via Update Server and Gateway Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing media copy protection systems, such as cable boxes and DVRs, restrict the transfer of recorded content to non-television devices due to digital rights management concerns, limiting consumer flexibility in accessing media content across devices.
Innovation Solution
A system and method for provisioning client devices with new or updated digital rights management (DRM) credentials through an update server, using an authorization token from a gateway device to authenticate and validate requests, ensuring only authorized devices can access and play back protected media content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If DRM credentials are distributed to client devices, then authorized playback is enabled, but unauthorized copying and credential exhaustion become risks
Solution Approach 1:
The patent introduces an update server as an intermediary between the DRM credential authority and client devices. This server manages credential distribution, validates authorization tokens, and maintains inventory control. The gateway device acts as another intermediary that issues tokens only to devices in its physical vicinity, creating a trusted distribution chain that prevents unauthorized copying while enabling flexible device access.
Solution Approach 2:
The system performs preliminary authorization by requiring client devices to obtain authorization tokens from gateway devices before they can request DRM credentials from the update server. This preliminary validation step ensures that only legitimately authorized devices can obtain credentials, preventing unauthorized copying while maintaining device flexibility for authorized users.
2Ease of operation
If DRM credentials are pre-loaded on deployed devices, then immediate playback capability is achieved, but inventory management and security control become difficult
Solution Approach 1:
The patent implements dynamic credential distribution where DRM credentials are not permanently embedded but can be provisioned, updated, or revoked through the update server. This dynamic approach allows the system to maintain immediate playback capability for authorized devices while enabling flexible inventory management, as credentials can be distributed on-demand and their distribution tracked and controlled through the server infrastructure.
3Reliability
If authorization tokens are required for credential requests, then unauthorized access is prevented, but the provisioning process becomes more complex
Solution Approach 1:
The gateway device automatically issues authorization tokens to client devices that are in its physical vicinity without requiring manual intervention. The client device autonomously presents this token to the update server to obtain DRM credentials. This self-service approach maintains strong authorization control while minimizing the complexity of the provisioning process for end users, as the authorization is handled automatically through proximity-based verification.
Data Source
AI summary
A method of provisioning DRM credentials on a client device, comprising receiving DRM credentials at an update server from a key generation system, the DRM credentials having been encrypted by the key generation system, receiving a DRM credential request from a client device, the DRM credential request comprising a digital signature, a device class certificate, and an authorization token, authenticating the DRM credential request by validating the digital signature and the device class certificate, extracting and validating the authorization token, and providing the DRM credentials to the client device.


