Entitlement Update Message Encapsulation in Access Control Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control systems for protected audiovisual content lack a comprehensive method for updating rights, particularly in scenarios where immediate and localized access is required, and they often fail to efficiently manage rights updates across different content types.
Innovation Solution
The method involves encapsulating a rights update message within a rights verification message, allowing the receiving equipment to decrypt and process the update message only if the access criteria are met, thereby enabling more elaborate rights updates while maintaining compatibility with existing access control formats and devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If rights update messages are sent separately from rights verification messages, then the access control system is simpler to implement, but the system cannot provide immediate and localized rights updates
Solution Approach 1:
The patent combines the rights update message (EMM) and the rights verification message (ECM) into a single integrated message structure. The EMM containing entitlement update data is embedded within the ECM that also carries access criteria and decryption keys. This merging allows the receiver to obtain both rights updates and verification information simultaneously, enabling immediate and localized rights updates without requiring separate message transmission sequences.
Solution Approach 2:
The patent implements a nested message structure where the rights update message (EMM) is encapsulated within the rights verification message (ECM). The outer ECM layer contains access criteria and decryption information, while the inner EMM layer contains the entitlement update data. This nesting allows the receiver to first verify access rights through the ECM layer, then process the embedded EMM layer for rights updates, creating a hierarchical message structure that provides both verification and update functionality in one transmission.
2Reliability
If rights update messages are encrypted with strong encryption, then security is improved, but the decryption process becomes more time-consuming
Solution Approach 1:
The patent applies preliminary action by pre-sharing symmetric encryption keys between the transmitter and receiver before the actual rights update transmission. The ECM contains pre-configured decryption information and access criteria that enable the receiver to quickly decrypt the embedded EMM without requiring complex real-time key exchange or computation. This preliminary key establishment phase separates the time-consuming key management from the actual rights update decryption, improving both security and speed.
3Adaptability or versatility
If the system supports multiple content types with different rights, then versatility is improved, but the rights management becomes more complex
Solution Approach 1:
The patent implements local quality by including content-specific rights information within the EMM structure embedded in each ECM. Different content types (live TV, VOD, pay-per-view) have their own specific entitlement data and access criteria localized within their respective message instances. This allows the receiver to process only the relevant rights information for each content type without being overwhelmed by the complexity of managing all possible content types system-wide, enabling versatile multi-content support with manageable local processing complexity.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
The invention relates to a method for updating the entitlements of a destination apparatus, including a step (500) comprising the receipt of an entitlements verification message (ECM) by a receiving apparatus, said message containing: at least one criterion for access (CA) to a protected audiovisual content, and encrypted data comprising a means for accessing the protected audiovisual content (CW) and at least one entitlements update message (EMM). In the course of a test step (501), the receiving apparatus checks whether the entitlements associated therewith satisfy the access criterion. In the event of a positive access criterion test, the receiving apparatus decrypts the entitlements update message (502). The decrypted entitlements update message is transmitted in order for the entitlements of the destination apparatus to be updated.