Hierarchical Key Derivation for Secure Content Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely managing access to computing resources and data across multiple geographic boundaries, particularly in balancing widespread distribution of content with preventing unauthorized copying, as conventional techniques often fail to effectively identify the source of unauthorized content copies.
Innovation Solution
The implementation of a key generation and management system that uses a hierarchical approach to derive keys from shared secret credentials, allowing for secure authentication and authorization across multiple authorities, while minimizing the risk of key compromise by using restrictions such as time stamps and geographic regions, and enabling identification of unauthorized content copies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional access control techniques are used to distribute content widely, then ease of operation is improved, but the ability to identify unauthorized copies deteriorates
Solution Approach 1:
The patent segments the cryptographic key into multiple shares distributed to different authorities. Each authority holds a portion of the key material, and combining shares from multiple authorities reconstructs the full key. This segmentation enables widespread content distribution while embedded identifiers in the key shares allow tracing unauthorized copies to specific authority combinations.
2Reliability
If centralized key storage is used to maintain security, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent divides centralized key storage into distributed key shares held by multiple authorities. Instead of one centralized repository, key material is segmented and distributed, reducing the complexity burden on any single system while maintaining security through the requirement of multiple authorities for key reconstruction.
Solution Approach 2:
The patent introduces key shares and authority intermediaries between the content and the decryption process. These intermediaries hold portions of key material and can independently verify authenticity without requiring direct access to the full key, simplifying the overall system architecture while maintaining security.
3Device complexity
If hierarchical key derivation is implemented to reduce centralized storage burden, then device complexity is reduced, but the security risk of key compromise increases
Solution Approach 1:
The patent segments the master key into hierarchical key shares distributed across multiple authorities at different levels. Each authority holds encrypted key material that can only be combined with specific other authorities' shares. This segmentation reduces centralized storage burden while the hierarchical structure with multiple required authorities mitigates key compromise risk.
Solution Approach 2:
The patent implements local quality by giving different authorities different levels and types of key shares with specific access permissions. Each authority's key material has localized security properties - some authorities have higher-level shares, others have lower-level shares, and combinations are required for different operations. This localized differentiation reduces overall system complexity while maintaining security through diversity.
Data Source
AI summary
Systems and methods for authentication generate keys from secret credentials shared between authenticating parties and authenticators. Generation of the keys may involve utilizing specialized information in the form of parameters that are used to specialize keys. Keys and/or information derived from keys held by multiple authorities may be used to generate other keys such that signatures requiring such keys and/or information can be verified without access to the keys. Keys may also be derived to form a hierarchy of keys that are distributed such that a key holder's ability to decrypt data depends on the key's position in the hierarchy relative to the position of a key used to encrypt the data. Key hierarchies may also be used to distribute key sets to content processing devices to enable the devices to decrypt content such that sources or potential sources of unauthorized content are identifiable from the decrypted content.


