Hierarchical Key Derivation for Secure Content Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely managing access to computing resources and data across multiple geographic boundaries, particularly in balancing widespread distribution of content with preventing unauthorized copying, as conventional techniques often fail to effectively identify the source of unauthorized content copies.

Innovation Solution

The implementation of a key generation and management system that uses a hierarchical approach to derive keys from shared secret credentials, allowing for secure authentication and authorization across multiple authorities, while minimizing the risk of key compromise by using restrictions such as time stamps and geographic regions, and enabling identification of unauthorized content copies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional access control techniques are used to distribute content widely, then ease of operation is improved, but the ability to identify unauthorized copies deteriorates

Engineering Contradiction:
Improveease of content consumptionVSAvoiddifficulty of identifying unauthorized copies
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the cryptographic key into multiple shares distributed to different authorities. Each authority holds a portion of the key material, and combining shares from multiple authorities reconstructs the full key. This segmentation enables widespread content distribution while embedded identifiers in the key shares allow tracing unauthorized copies to specific authority combinations.

Inventive Principle:
Principle #1Segmentation

2Reliability

If centralized key storage is used to maintain security, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity of key storageVSAvoidcomplexity of key management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides centralized key storage into distributed key shares held by multiple authorities. Instead of one centralized repository, key material is segmented and distributed, reducing the complexity burden on any single system while maintaining security through the requirement of multiple authorities for key reconstruction.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces key shares and authority intermediaries between the content and the decryption process. These intermediaries hold portions of key material and can independently verify authenticity without requiring direct access to the full key, simplifying the overall system architecture while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If hierarchical key derivation is implemented to reduce centralized storage burden, then device complexity is reduced, but the security risk of key compromise increases

Engineering Contradiction:
Improveburden on centralized key storageVSAvoidrisk of key compromise
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the master key into hierarchical key shares distributed across multiple authorities at different levels. Each authority holds encrypted key material that can only be combined with specific other authorities' shares. This segmentation reduces centralized storage burden while the hierarchical structure with multiple required authorities mitigates key compromise risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by giving different authorities different levels and types of key shares with specific access permissions. Each authority's key material has localized security properties - some authorities have higher-level shares, others have lower-level shares, and combinations are required for different operations. This localized differentiation reduces overall system complexity while maintaining security through diversity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11146541B2Hierarchical data access techniques using derived cryptographic material
Publication Date: 2021.10.12 AMAZON TECH INC
  • US11146541B2 patent drawing
  • US11146541B2 patent drawing
  • US11146541B2 patent drawing

AI summary

Systems and methods for authentication generate keys from secret credentials shared between authenticating parties and authenticators. Generation of the keys may involve utilizing specialized information in the form of parameters that are used to specialize keys. Keys and/or information derived from keys held by multiple authorities may be used to generate other keys such that signatures requiring such keys and/or information can be verified without access to the keys. Keys may also be derived to form a hierarchy of keys that are distributed such that a key holder's ability to decrypt data depends on the key's position in the hierarchy relative to the position of a key used to encrypt the data. Key hierarchies may also be used to distribute key sets to content processing devices to enable the devices to decrypt content such that sources or potential sources of unauthorized content are identifiable from the decrypted content.