User-Based Content Key Encryption for DRM Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Digital Rights Management (DRM) systems face challenges in securely distributing content keys within authorized domains, particularly in allowing seamless access to content across multiple devices while preventing unauthorized dissemination outside the domain, and in efficiently moving content to new domains without re-encryption or backend processes.
Innovation Solution
A DRM system utilizing user-based content key encryption, where a user key is stored and shared among devices within an authorized domain, allowing secure decryption and use of encrypted content keys, enabling seamless access and management of digital media across interconnected devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If content is encrypted with a content key and the content key is securely stored on devices within the domain, then content access security is improved, but device complexity and secure session requirements increase
Solution Approach 1:
The patent extracts the secure session requirement from the content key distribution process by using pre-shared domain keys. Instead of requiring secure sessions during content access, the system pre-distributes domain keys to all devices in the domain, separating key distribution from content access operations.
Solution Approach 2:
The patent performs preliminary action by pre-distributing domain keys to all devices within the authorized domain before content access occurs. This allows devices to independently decrypt content keys without requiring secure sessions or real-time communication with the rights issuer.
2Ease of operation
If domain keys are shared among all devices in the domain, then content accessibility across devices is improved, but security risks increase
Solution Approach 1:
The patent applies local quality by making domain keys locally available to each device within the authorized domain through pre-distribution. Each device has the domain key stored locally, enabling independent content access without requiring centralized key management or secure sessions, thus achieving both accessibility and security.
3Adaptability or versatility
If content keys are encrypted with user keys instead of domain keys, then content portability between domains is improved, but key management complexity increases
Solution Approach 1:
The patent applies universality by using domain keys that are shared across all devices in the domain, allowing the same key to serve multiple devices simultaneously. This eliminates the need for individual user keys per device while maintaining the ability to move content between domains through license redistribution.
4Reliability
If secure sessions are required for content key exchange, then content key distribution security is improved, but operational efficiency decreases
Solution Approach 1:
The patent performs preliminary action by pre-distributing domain keys to all devices in the domain during domain setup. This eliminates the need for secure sessions during content access operations, as devices can independently decrypt content keys using their pre-shared domain keys, significantly improving operational efficiency.
Solution Approach 2:
The patent extracts the secure session requirement from the content access process by using pre-shared domain keys. The security mechanism is separated into the domain setup phase (where domain keys are distributed) rather than being required during each content access operation.
Data Source
AI summary
A digital rights management (DRM) system, device and method having an authorized domain (12) for managing digital media, wherein the authorized domain or entity such as a rights issuer utilizes user based content key encryption. In one aspect, the system includes plurality of interconnected devices (16) that comprise: a storage system for storing a user key (19) from a user belonging to the authorized domain; a system for downloading content (13) encrypted with a content key (32); a system for downloading a content key encrypted with the user key; a decryption system (28) for decrypting the encrypted content key with the user key; and a system (28) for decrypting the encrypted content with the decrypted content key.


