Entitlement Update Message Encapsulation in Access Control Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control systems for protected audiovisual content lack a comprehensive method for updating rights, particularly in scenarios where immediate and localized access is required, and they often fail to efficiently manage rights updates across different content types.

Innovation Solution

The method involves encapsulating a rights update message within a rights verification message, allowing the receiving equipment to decrypt and process the update message only if the access criteria are met, thereby enabling more elaborate rights updates while maintaining compatibility with existing access control formats and devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If rights update messages are sent separately from rights verification messages, then the access control system is simpler to implement, but the system cannot provide immediate and localized rights updates

Engineering Contradiction:
Improveimmediate and localized rights update capabilityVSAvoidmessage structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines the rights update message (EMM) and the rights verification message (ECM) into a single integrated message structure. The EMM containing entitlement update data is embedded within the ECM that also carries access criteria and decryption keys. This merging allows the receiver to obtain both rights updates and verification information simultaneously, enabling immediate and localized rights updates without requiring separate message transmission sequences.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements a nested message structure where the rights update message (EMM) is encapsulated within the rights verification message (ECM). The outer ECM layer contains access criteria and decryption information, while the inner EMM layer contains the entitlement update data. This nesting allows the receiver to first verify access rights through the ECM layer, then process the embedded EMM layer for rights updates, creating a hierarchical message structure that provides both verification and update functionality in one transmission.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If rights update messages are encrypted with strong encryption, then security is improved, but the decryption process becomes more time-consuming

Engineering Contradiction:
Improverights update securityVSAvoiddecryption processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-sharing symmetric encryption keys between the transmitter and receiver before the actual rights update transmission. The ECM contains pre-configured decryption information and access criteria that enable the receiver to quickly decrypt the embedded EMM without requiring complex real-time key exchange or computation. This preliminary key establishment phase separates the time-consuming key management from the actual rights update decryption, improving both security and speed.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If the system supports multiple content types with different rights, then versatility is improved, but the rights management becomes more complex

Engineering Contradiction:
Improvemulti-content rights management capabilityVSAvoidrights update processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements local quality by including content-specific rights information within the EMM structure embedded in each ECM. Different content types (live TV, VOD, pay-per-view) have their own specific entitlement data and access criteria localized within their respective message instances. This allows the receiver to process only the relevant rights information for each content type without being overwhelmed by the complexity of managing all possible content types system-wide, enabling versatile multi-content support with manageable local processing complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2297954B1Updating of entitlements to access a protected audiovisual content
Publication Date: 2017.11.08 ORANGE SA
  • EP2297954B1 patent drawingFigure 1~2
  • EP2297954B1 patent drawingFigure 3
  • EP2297954B1 patent drawingFigure 4~5

AI summary

The invention relates to a method for updating the entitlements of a destination apparatus, including a step (500) comprising the receipt of an entitlements verification message (ECM) by a receiving apparatus, said message containing: at least one criterion for access (CA) to a protected audiovisual content, and encrypted data comprising a means for accessing the protected audiovisual content (CW) and at least one entitlements update message (EMM). In the course of a test step (501), the receiving apparatus checks whether the entitlements associated therewith satisfy the access criterion. In the event of a positive access criterion test, the receiving apparatus decrypts the entitlements update message (502). The decrypted entitlements update message is transmitted in order for the entitlements of the destination apparatus to be updated.