Entitlement Control Message for Secure Media Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing content delivery networks face challenges in delivering high definition (HD) video at broadcast audience scale to various runtime environments and mobile devices without incurring high costs and while ensuring content security from unauthorized access.

Innovation Solution

An integrated HTTP-based delivery platform that generates and uses entitlement control messages to derive decryption keys for secure media delivery, encrypting content at the edge server and decrypting it at runtime within the client browser, thereby protecting content from unauthorized access without relying on digital rights management (DRM).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If dedicated platforms with proprietary technologies and media servers are used to deliver content to multiple runtime environments, then content delivery capability is improved, but implementation and maintenance costs increase significantly

Engineering Contradiction:
Improvecontent delivery capabilityVSAvoidplatform complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal encryption platform that serves multiple runtime environments (Flash, Silverlight, iOS, Android, etc.) through a single HTTP-based delivery system. The encryption and decryption functionality is standardized across all platforms, eliminating the need for separate dedicated platforms for each runtime environment while maintaining broad compatibility and delivery capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If content is delivered in clear text for easy playback, then ease of operation is improved, but content security deteriorates due to unauthorized access and attacks

Engineering Contradiction:
Improveplayback easeVSAvoidcontent security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary encryption to content before delivery, transforming clear text into encrypted form during the preparation phase. The decryption process is automatically triggered at playback time through entitlement control messages, ensuring content security is maintained throughout delivery while preserving ease of playback operation for authorized users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an encryption/decryption intermediary layer between content delivery and playback. Entitlement control messages act as mediators that facilitate automatic decryption at the client side, allowing content to remain encrypted during transmission while being seamlessly decrypted for authorized playback without requiring user intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encryption is applied to protect content during delivery, then content security is improved, but processing complexity increases due to key management and decryption requirements

Engineering Contradiction:
Improvecontent securityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service decryption where the client-side player automatically obtains entitlement control messages and derives decryption keys without requiring complex server-side key management or user intervention. The system handles key generation, distribution, and decryption autonomously, reducing processing complexity while maintaining robust content security through client-side autonomous operation.

Inventive Principle:
Principle #25Self-service

4Reliability

If digital rights management (DRM) systems are implemented to prevent unauthorized access, then content security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvecontent securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the essential security functionality from complex DRM systems, implementing a streamlined encryption approach that focuses specifically on content protection during delivery and playback. By removing unnecessary DRM components and retaining only the core encryption/decryption mechanism with entitlement control messages, the system achieves adequate content security with significantly reduced complexity compared to full DRM implementations.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10698985B2Extending data confidentiality into a player application
Publication Date: 2020.06.30 AKAMAI TECHNOLOGIES INC
  • US10698985B2 patent drawing
  • US10698985B2 patent drawing
  • US10698985B2 patent drawing

AI summary

In a content protection scheme, and in response to a request for a content segment received by a server, the server generates and associates with the segment a message that confers entitlement to a session-specific key from which one or more decryption keys may be derived. The decryption keys are useful to decrypt the segment at runtime as it is about to be rendered by a player. Before delivery, the server encrypts the segment to generate an encrypted fragment, and it then serves the encrypted fragment (and the message) in response to the request. At the client, information in the message is used to obtain the session-specific key. Using that key, the decryption keys are derived, and those keys are then used to decrypt the received encrypted fragment. The decryption occurs at runtime. The approach protects content while in transit to and at rest in the client browser environment.