Federated DRM Policy Management via SSO Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In federated environments, existing digital rights management (DRM) systems face challenges in efficiently managing user sessions and enforcing DRM policies across multiple entities, leading to complexities in authentication and authorization processes.

Innovation Solution

A method is introduced where a service provider, participating in a federation with identity and DRM policy providers, receives a single sign-on message containing DRM privileges and evaluates them against applicable DRM policies to provide access to digital content, integrating DRM privileges and policy providers to facilitate a DRM policy-enabled federation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DRM license enforcement is done at the player/client, then content security is improved, but device complexity and administrative burden on service providers increase

Engineering Contradiction:
Improvecontent securityVSAvoidadministrative burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a DRM policy provider as an intermediary entity that centralizes DRM policy management and enforcement. Instead of each service provider implementing DRM enforcement locally (which increases complexity), the DRM policy provider acts as a mediator that receives SSO messages, evaluates DRM privileges against policies, and returns authorization decisions. This reduces the administrative burden on individual service providers while maintaining content security through centralized policy control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If federated environment is implemented, then ease of operation for users is improved, but complexity of authentication and authorization management worsens

Engineering Contradiction:
Improveuser authenticationVSAvoidauthorization management
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the authentication and authorization processes into distinct functional components: identity providers handle authentication and issue SSO messages, while DRM policy providers handle authorization by evaluating DRM privileges against policies. This segmentation allows each component to specialize in its function, simplifying the overall federated environment implementation while maintaining ease of user operation through single-sign-on.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If DRM privileges are integrated into SSO message, then user experience is improved, but message complexity and processing overhead increase

Engineering Contradiction:
Improveuser experienceVSAvoidmessage processing
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent makes the SSO message structure universal by designing it to carry both authentication information and DRM privilege information in a standardized format. This multi-functionality allows the same message structure to serve dual purposes: proving user identity and conveying content access rights. The standardized format reduces processing overhead compared to separate authentication and authorization messages, while improving user experience through seamless single-sign-on with DRM protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8196177B2Digital rights management (DRM)-enabled policy management for a service provider in a federated environment
Publication Date: 2012.06.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8196177B2 patent drawing
  • US8196177B2 patent drawing
  • US8196177B2 patent drawing

AI summary

A method operative at a service provider enforces a digital rights management (DRM) scheme associated with a piece of content. The service provider typically is a content provider. The service provider is an entity that participates in a “federation” with one or more other entities including, for example, an identity provider, a DRM privileges provider, and a DRM policy provider. In one embodiment, the method begins upon receipt at the service provider of a single sip on (SSO) message generated by the identity provider entity that includes a reference to a set of DRM privileges associated with an end user requesting access to the piece of content. In response to receiving the message, the service provider as necessary obtains the DRM privileges and at least one applicable DRM policy. It then evaluates the DRM privileges associated with the end user against the DRM policy, and provides the end user a response.