Inclusive Authentication for Secure Content Reproduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional DRM technologies, such as GBA, only support mutual authentication between a user identity module and a service provider, failing to ensure security through authentication between the user identity module and the terminal, which hinders safe reproduction of purchased content across various terminals.

Innovation Solution

A method for inclusive authentication and management that involves transferring notification messages between a service provider, a terminal, and a user identity module, verifying response messages, and generating authentication result messages to enable mutual authentication between the terminal and the user identity module, ensuring secure access to content on any terminal device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If GBA technology is used for mutual authentication between user identity module and service provider, then authentication between these two parties is supported, but authentication between user identity module and terminal is not supported

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication scope
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The authentication method is extended to support multiple authentication scenarios (user identity module-service provider, user identity module-terminal, terminal-service provider) through a universal authentication framework, allowing the same authentication mechanism to serve multiple purposes and relationships

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If only mutual authentication between user identity module and service provider is implemented, then security for that specific relationship is ensured, but security for terminal involvement is not ensured

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication process is segmented into distinct phases and message exchanges, with each authentication relationship (user identity module-service provider, user identity module-terminal, terminal-service provider) handled as a separate but coordinated authentication sequence, making the complex multi-party authentication manageable and systematic

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7953391B2Method for inclusive authentication and management of service provider, terminal and user identity module, and system and terminal device using the method
Publication Date: 2011.05.31 SAMSUNG ELECTRONICS CO LTD
  • US7953391B2 patent drawing
  • US7953391B2 patent drawing
  • US7953391B2 patent drawing

AI summary

Disclosed are a method and a system for mutual inclusive authentication between a service provider, a terminal and a user identity module. The authentication system is configured in a structure that can interact with a public key infrastructure of the current network security environment and can be independently used in a specific network system. The inclusive authentication method is divided into public key authentication and symmetric key authentication. Mutual authentication can be made between a service provider, a terminal and a user identity module using any of the two authentication schemes. Then a user can access content on any terminal device using the content license based on the user's identity.