Dynamic Rights Sharing via Sub-Right Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Digital Rights Management (DRM) systems face limitations in dynamic rights sharing, particularly in allowing users to share rights according to their needs, as they are often tied to specific networks, devices, or environments, and lack multi-level delegation and portability, with existing mechanisms being error-prone and not suitable for hierarchical structures or general-purpose resource sharing.

Innovation Solution

A system that allows users to derive and integrate sub-rights from a pool of rights, enabling dynamic and multi-tier rights sharing by dividing granted rights into sub-rights, which can be further shared and re-integrated, with a group license mechanism that supports maximum rights distribution among users and devices based on their policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If rights are tied to a network server and specific environment, then access control and rights management are enforced, but portability and flexibility of rights sharing are limited

Engineering Contradiction:
Improveaccess control enforcementVSAvoidportability of rights
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments rights into transferable units that can be independently shared and delegated. Rights are divided into specific components (viewing, copying, printing) that can be separately controlled and transferred, enabling flexible sharing without being bound to a specific network server or environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal rights management system where rights can be exercised across multiple devices and networks. The rights are designed to be environment-agnostic, allowing users to access and exercise their rights on any device that supports the rights management protocol, not just on a specific network server.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If a custom access control mechanism with option files is used, then rights sharing can be controlled according to specific needs, but the system becomes error-prone and difficult to manage

Engineering Contradiction:
Improverights sharing controlVSAvoidconfiguration management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where users can automatically manage their own rights sharing without manual configuration. The system provides automated tools for users to define sharing policies, allocate rights, and manage delegation hierarchies, eliminating the need for error-prone manual option file configuration.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent transforms the static option file configuration into dynamic parameter-based control. Rights sharing is managed through programmable parameters and policies that can be automatically adjusted based on usage patterns, user roles, and organizational requirements, replacing manual text-based configuration with automated parameter management.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If the option file is protected only by administrator password, then configuration is simple, but security and integrity verification of rights management are insufficient

Engineering Contradiction:
Improveconfiguration simplicityVSAvoidsecurity and integrity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent replaces the mechanical password-based protection system with cryptographic security mechanisms. Rights management relies on digital signatures, encryption, and cryptographic verification to ensure the integrity and authenticity of rights configurations, replacing simple password protection with robust cryptographic security while maintaining ease of use through automated authentication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If content access is restricted to the network server perimeter, then access control is enforced, but the portability of content access is limited

Engineering Contradiction:
Improveaccess controlVSAvoidcontent portability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces rights as an intermediary layer between content and access control. Instead of restricting access to a specific network perimeter, the system uses portable rights that can be validated by any authorized entity. Rights act as a mediator that carries access permissions across different networks and devices, enabling content portability while maintaining security through cryptographic verification of rights validity.

Inventive Principle:
Principle #24Intermediary (Mediator)

5Device complexity

If single-level delegation is implemented, then administrator control is simplified, but hierarchical structures and multi-level rights distribution are not supported

Engineering Contradiction:
Improvedelegation structureVSAvoidhierarchical rights distribution
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements nested delegation hierarchies where administrators can create multi-level rights distribution structures. Rights can be delegated from top-level administrators to intermediate managers, who can further delegate to end users, creating a nested hierarchy similar to Russian dolls. This enables complex organizational structures while maintaining centralized control through the rights management system.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS7720767B2Method and system to support dynamic rights and resources sharing
Publication Date: 2010.05.18 CONTENTGUARD INC
  • US7720767B2 patent drawing
  • US7720767B2 patent drawing
  • US7720767B2 patent drawing

AI summary

The invention relates to method for deriving a sub-right from a right, the right comprising a plurality of components, each of which specifies an aspect of the right. A component may be, for example, a principal, an action, a resource, and a condition. The invention also relates to a method for integrating a first right with a second right. Furthermore, the invention relates to a method of sharing rights by deriving a sub-right from a right, allowing use of the sub-right, and integrating the sub-right with the right. In addition, the invention relates to a system to support rights sharing by enabling the derivation of a sub-right from a right, the right comprising plural components each of which specifies an aspect of the right, the system comprising a receiving module for receiving a sub-right, the sub-right comprising plural components each of which specifies an aspect of the sub-right, and a confirmation module for confirming that the values of the components of the sub-right can be derived from the values of the corresponding components of the right. The invention further relates to a method for deriving a sub-right from a pool of rights granted by a grantor to a grantee for controlling use of resources within a computing environment, the computing environment having a mechanism for enforcing rights within the environment to control use of resources in accordance with the rights.