Hardware-Based DRM System for Secure Media Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital rights management systems fail to reliably prevent unauthorized copying and time restriction circumvention of digital media content, particularly due to vulnerabilities in software-based methods on local devices.

Innovation Solution

A system utilizing symmetric and public-private key cryptography, combined with hardware-based cryptography engines and counters, ensures secure transmission and playback of media content by encrypting content with user-specific keys and enforcing time restrictions through secure key management and association processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based digital rights management methods are used, then media content can be transmitted to local devices, but the operating system and applications can be easily attacked by end-users to circumvent time or duplication restrictions

Engineering Contradiction:
Improveease of media content transmissionVSAvoidsecurity of time and duplication restrictions
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-based DRM mechanisms with hardware-based security measures. Specifically, it uses hardware security modules (HSMs) and trusted platform modules (TPMs) embedded in the device to manage encryption keys and enforce DRM policies. This hardware-based approach prevents software-based attacks by moving critical security functions out of the operating system and applications that can be compromised.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a DRM server as an intermediary between the media content source and the local device. This server manages the encryption keys, authenticates devices, and controls the distribution of media content. The intermediary architecture ensures that even if the local device's software is compromised, the security maintained by the centralized DRM server and hardware security modules prevents circumvention of restrictions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-based or server side software-based methods are used to prevent copying, then unauthorized copying is reduced, but the technical complexity increases and fewer individuals can engage in these attacks

Engineering Contradiction:
Improveprotection against unauthorized copyingVSAvoidtechnical complexity of security measures
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the DRM system into distinct functional components: a centralized DRM server for key management and policy enforcement, hardware security modules for cryptographic operations, and client applications for media playback. This segmentation allows each component to be optimized independently and simplifies the overall system architecture by distributing security functions across multiple specialized elements rather than requiring a single complex system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9185094B2Systems, methods and apparatuses for the secure transmission and restricted use of media content
Publication Date: 2015.11.10 OLOGN TECH AG
  • US9185094B2 patent drawing
  • US9185094B2 patent drawing
  • US9185094B2 patent drawing

AI summary

The systems, methods and apparatuses described herein permit encrypted media content to be displayed by an apparatus for a restricted time period. The apparatus may comprise a communication interface configured to couple to a controlling device to transmit a first nonce and to receive the encrypted media content and an association encryption envelope. The association encryption envelope may comprise at least a second nonce and a first time restriction expressed as a first time interval. The apparatus may further comprise a counter, a storage configured to store a value of the counter representing a time of when the first nonce is transmitted, and an engine configured to perform operations according to the first time restriction.