Hierarchical Key Derivation for Unauthorized Copy Source Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional techniques for controlling access to content struggle to balance widespread distribution with preventing unauthorized copying, particularly in identifying the source of unauthorized copies, and face challenges in securing shared secret credentials in distributed computing environments.

Innovation Solution

The implementation of a key generation and management system that uses Hash Message Authentication Code (HMAC) algorithms and multiple authority key derivation techniques to authenticate requests, derive keys from shared secret credentials, and distribute keys hierarchically, allowing for secure access and identification of unauthorized content sources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional access control techniques are used to distribute content widely, then content accessibility is improved, but the ability to identify unauthorized copy sources deteriorates

Engineering Contradiction:
Improvecontent accessibilityVSAvoidunauthorized copy source identification
Core Design Contradiction:
Ease of operationVSDifficulty of detecting and measuring

Solution Approach 1:

The patent segments the secret credential into multiple key components (first key, second key, third key) that are distributed to different devices. Each device receives a unique combination of key components, allowing individual identification while maintaining secure access control. This segmentation enables both widespread distribution and source identification of unauthorized copies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by giving each device a unique local key component derived from the segmented credential. Each device's key material is locally specific and different from other devices, enabling identification of the specific device that created an unauthorized copy while all devices can access the content.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If shared secret credentials are distributed to multiple devices, then access control scalability is improved, but security against credential compromise deteriorates

Engineering Contradiction:
Improveaccess control scalabilityVSAvoidcredential security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The secret credential is segmented into multiple key components that are separately distributed to different devices. This segmentation allows scalable distribution to many devices while maintaining security, because compromising one device's key components does not expose the complete credential needed to access all content.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic key derivation where key components are derived on-demand using HMAC functions with device-specific parameters. The key material is not statically stored but dynamically generated, enhancing security against compromise while enabling scalable access control.

Inventive Principle:
Principle #15Dynamics

3Productivity

If hierarchical key distribution is implemented, then key management efficiency is improved, but system complexity deteriorates

Engineering Contradiction:
Improvekey distribution efficiencyVSAvoidkey management system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The hierarchical key distribution system segments the credential into multiple levels (first key, second key, third key) where each level serves a specific function. This segmentation improves key management efficiency by allowing selective distribution and derivation while the modular structure helps manage system complexity through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-segmenting the secret credential into key components and establishing the hierarchical key derivation structure in advance. This preliminary setup enables efficient on-demand key generation and distribution without complex real-time computations, improving productivity while managing complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9872067B2Source identification for unauthorized copies of content
Publication Date: 2018.01.16 AMAZON TECH INC
  • US9872067B2 patent drawing
  • US9872067B2 patent drawing
  • US9872067B2 patent drawing

AI summary

Systems and methods for authentication generate keys from secret credentials shared between authenticating parties and authenticators. Generation of the keys may involve utilizing specialized information in the form of parameters that are used to specialize keys. Keys and/or information derived from keys held by multiple authorities may be used to generate other keys such that signatures requiring such keys and/or information can be verified without access to the keys. Keys may also be derived to form a hierarchy of keys that are distributed such that a key holder's ability to decrypt data depends on the key's position in the hierarchy relative to the position of a key used to encrypt the data. Key hierarchies may also be used to distribute key sets to content processing devices to enable the devices to decrypt content such that sources or potential sources of unauthorized content are identifiable from the decrypted content.