Hierarchical Key Management for Digital Rights

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing hundreds of thousands of digital keys for content protection in a distributed system is challenging, especially when users rent content, requiring key return and distribution, which complicates digital rights management.

Innovation Solution

A distributed key management system with a hierarchical set of repositories, including a master server, intermediate servers, and local servers, that pre-populates key material for content fragments before requests, ensuring timely and efficient key delivery across multiple server nodes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single key is used to protect content across multiple users, then content protection is simplified, but only one user can access the content at any one time

Engineering Contradiction:
Improvekey management complexityVSAvoidcontent access availability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the single key into multiple distinct keys, with each key assigned to a specific user or device. This allows multiple users to simultaneously access and decrypt the same content file, resolving the contradiction between simplified key management and content access availability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If multiple keys are distributed to manage content access, then multiple users can access content simultaneously, but key management becomes difficult

Engineering Contradiction:
Improvecontent access availabilityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a hierarchical key structure where a master key controls access to multiple content keys, and each content key is associated with specific content files. This nested structure simplifies key management by providing a centralized control mechanism while still enabling multiple users to access content simultaneously.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The master key serves multiple functions: it can generate content keys, revoke access rights, and manage key distribution across the system. This multi-functionality reduces the overall complexity of key management while maintaining the ability for multiple simultaneous content accesses.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If keys are downloaded and returned for rental content, then rental functionality is enabled, but key management becomes more complex

Engineering Contradiction:
Improverental functionalityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system pre-associates keys with content files during the content creation and upload process. When rental transactions occur, the pre-configured key relationships enable automatic key distribution and return processing, reducing the complexity of managing rental keys compared to creating and managing key relationships in real-time.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9876991B1Hierarchical key management system for digital rights management and associated methods
Publication Date: 2018.01.23 VECIMA NETWORKS INC
  • US9876991B1 patent drawing
  • US9876991B1 patent drawing
  • US9876991B1 patent drawing

AI summary

An intermediate server (104) is operable in a distributed key management system (300). The intermediate server comprises one or more processors (205) and an intermediate key material repository (302) to store digital rights management key material. The intermediate server can be operable in the system between a master server (101) and a local server (106), with the local server to deliver content (108) to one or more subscriber devices (109,110). The intermediate server, or optionally a management system (117) can pre-populate the intermediate key material repository with one or key material (1005) corresponding to fragments (1001) of the content prior to the fragments of content being requested by the one or more subscriber devices.