Dynamic Secure Module Loading for Content Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing content on computers using security devices like dongles or smart cards are inadequate in providing dynamic and secure decryption of encrypted content, especially in a general-purpose computer or content rendering device context.

Innovation Solution

A method involving a secure module source that establishes communication with a content rendering device, loads a dynamically generated pseudo-unique secure module, and transfers a decryption key to enable decryption of encrypted content, using a sequence of software primitives that can be sequentially executed, and establishing secure authenticated channels for communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a static security device is used for content decryption, then the device structure is simple, but the security is insufficient and lacks flexibility

Engineering Contradiction:
ImprovesecurityVSAvoiddevice structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic secure modules that are loaded into the content rendering device during operation rather than being statically embedded. These modules can be dynamically generated, loaded, and unloaded to provide flexible security updates and key management without requiring hardware changes, thus improving security while avoiding complex permanent device structures.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security functionality is segmented into separate secure modules that can be independently managed, loaded, and updated. This allows the security mechanism to be divided from the main content rendering device, providing enhanced security through modular architecture while keeping the overall system structure relatively simple.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a dynamically generated secure module is used, then the security and flexibility are improved, but the system complexity increases

Engineering Contradiction:
ImproveflexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system uses dynamically generated secure modules that can adapt to different content and security requirements. These modules are created on-demand and loaded into the content rendering device, providing high adaptability for different decryption scenarios while managing complexity through automated generation processes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The secure modules are automatically generated and loaded by the system itself without requiring manual configuration or complex external management. The content rendering device autonomously manages the lifecycle of secure modules, including generation, loading, and unloading, which reduces operational complexity despite the dynamic nature of the security mechanism.

Inventive Principle:
Principle #25Self-service

3Reliability

If secure communication channels are established for key transfer, then the decryption security is enhanced, but the communication overhead increases

Engineering Contradiction:
Improvedecryption securityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Secure communication channels are established and authenticated before the actual key transfer occurs. This preliminary setup ensures that the decryption key is transmitted over a secure channel, enhancing decryption security while minimizing overhead by performing the secure channel establishment once before multiple key transfers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements authentication and verification mechanisms during the secure channel establishment and key transfer process. Feedback loops ensure that the communication channel is properly secured and that keys are successfully transferred, enhancing security while managing overhead through efficient verification protocols.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP1932275B1Security device and building block functions
Publication Date: 2016.11.23 NDS
  • EP1932275B1 patent drawingFigure 1
  • EP1932275B1 patent drawingFigure 2
  • EP1932275B1 patent drawingFigure 3

AI summary

A method and system of securing content is described, the method including establishing communication between a secure module source and a content rendering device, loading a dynamically generated pseudo-unique secure module to the content rendering device from the secure module source, establishing communication between the secure module source and the dynamically generated pseudo-unique secure module, and transferring a decryption key from the secure module source to the dynamically generated pseudo-unique secure module, thereby enabling decryption of encrypted content, the encrypted content being encrypted according to the decryption key. Related methods and apparatus are also described.