Encrypted Key Chain for Secure Content Relay

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital rights management (DRM) systems in video-on-demand systems provide incomplete solutions for protecting content from piracy, as they often restrict access to specific hardware devices and fail to effectively trace unauthorized distribution in highly distributed content delivery architectures.

Innovation Solution

A method for generating chains of encrypted decryption keys within an Entitlement Control Message (ECM) is implemented, where an access key is provided using an out-of-band mechanism or Entitlement Management Message (EMM), and each relaying device encrypts the session key with a new access key, creating a key chain that allows secure content relay through trusted and untrusted systems without decrypting the content key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-encryption techniques are used to protect content in highly distributed systems, then content protection is improved, but the ability to trace unauthorized distribution sources is lost

Engineering Contradiction:
Improvecontent protectionVSAvoidtracing unauthorized distribution
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The encryption key management is segmented into a chain structure where each relaying device has its own key pair. The content key is encrypted with the first relaying device's public key, which then encrypts the second device's public key, and so on. This segmentation allows each device to be individually tracked while maintaining end-to-end encryption, resolving the contradiction between protection and traceability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary encryption layers at each relaying device in the chain. Each intermediary device encrypts the content key with its own public key before passing it down the chain. This intermediary structure enables both secure transmission through untrusted systems and the ability to identify which intermediary may have compromised the content, thus maintaining both protection and traceability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If DRM systems restrict access to specific hardware devices, then content protection is improved, but user flexibility and enjoyment are reduced

Engineering Contradiction:
Improvecontent protectionVSAvoiduser flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal encryption scheme where content can be securely transmitted through multiple different relaying devices in a chain. Each device in the chain can be trusted or untrusted, and the system adapts to any configuration. This multi-functionality allows the same content protection mechanism to work across diverse hardware platforms and network configurations, maintaining both security and user flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The encryption key chain is dynamic and can be configured differently for each content delivery path. The system adapts the encryption chain based on the specific relaying devices involved, allowing flexible deployment across various hardware environments while maintaining consistent security. This dynamic adaptation resolves the contradiction between rigid hardware restriction and flexible user access.

Inventive Principle:
Principle #15Dynamics

3Reliability

If content is encrypted and relayed through multiple systems, then content protection is improved, but system complexity increases

Engineering Contradiction:
Improvecontent protectionVSAvoidrelay system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent employs a nested encryption structure where each relaying device's public key encrypts the next device's public key in the chain. This nested arrangement creates a compact key chain where multiple encryption layers are contained within a single data structure. The nesting principle simplifies the relay mechanism by providing a clear, hierarchical structure for key management, reducing operational complexity while maintaining strong protection.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The system manages complexity by standardizing the encryption parameters and key chain structure across all relaying devices. Each device uses the same cryptographic operations and data formats, allowing the complexity of multi-system relay to be managed through parameter consistency rather than device-specific complexity. This standardization reduces the burden on individual devices while maintaining secure content relay.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7349886B2Securely relaying content using key chains
Publication Date: 2008.03.25 GOOGLE LLC
  • US7349886B2 patent drawing
  • US7349886B2 patent drawing
  • US7349886B2 patent drawing

AI summary

A system, apparatus, and method are directed towards generating chains of encrypted decryption keys for content in a highly distributed environment. In one embodiment, the key chain may be provided within an Entitlement Control Message (ECM). An access key that enables decryption of a current link within the chain of decryption keys may be provided to a downstream recipient using an out-of-band mechanism. Alternatively, the access key may be provided through an in-band mechanism, such as through the use of Entitlement Management Message (EMM), or the like. In one embodiment, the access key within the EMM may be further encrypted by another encryption key that may be unique to the downstream recipient.