Key Server Attestation for Secure Content Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing content distribution technologies do not allow data owners to impose restrictions on data consumers, limiting the ability to control access to their content based on trustworthiness, geography, purpose, or other criteria, which can compromise data privacy and security.

Innovation Solution

A content distribution system that enables data owners to set restrictions on data consumers, using a key server to authenticate and attest the trustworthiness of data consumer devices before distributing key materials, ensuring access is granted only if restrictions such as attestation, geography location, or purpose requirements are met.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data owners can impose restrictions on data consumers, then data privacy and security are improved, but device complexity increases due to additional authentication and attestation mechanisms

Engineering Contradiction:
Improvedata privacy and securityVSAvoidauthentication and attestation mechanisms
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a key server as an intermediary component that handles the complex authentication and attestation processes. The key server receives attestation data from data consumer devices, verifies it against restrictions set by data owners, and selectively distributes key materials. This intermediary approach allows data owners to maintain control over content access without directly managing complex authentication logic in their own systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the access control functionality into separate components: data owners define restrictions, data consumer devices provide attestation data, the key server performs verification and key distribution, and content servers handle actual content delivery. This segmentation allows each component to focus on specific tasks, reducing overall system complexity while maintaining strong security controls.

Inventive Principle:
Principle #1Segmentation

2Reliability

If key materials are distributed with restrictions, then access control is improved, but the ease of operation deteriorates due to additional authentication steps required by data consumers

Engineering Contradiction:
Improveaccess controlVSAvoidauthentication steps
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs attestation verification and restriction checking in advance before key material distribution. The key server pre-verifies that data consumer devices meet the required criteria (such as geographic location, device trustworthiness, or organizational affiliation) before granting access. This preliminary action ensures that only authorized devices receive keys, while legitimate users experience streamlined access once authentication is complete.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3583740B1Data owner restricted secure key distribution
Publication Date: 2024.05.15 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • EP3583740B1 patent drawingFigure 1
  • EP3583740B1 patent drawingFigure 2~4
  • EP3583740B1 patent drawingFigure 3

AI summary

A content distribution system is described herein which enables a data owner of content to set one or more restrictions on a data consumer where the one or more restrictions need to be satisfied by a data consumer device before the data consumer has 5 access to the content. In addition, the content distribution system's components are described herein which include a data owner device, a key server, a data consumer device, a data producer device, and a content server.