Key Server Attestation for Secure Content Distribution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing content distribution technologies do not allow data owners to impose restrictions on data consumers, limiting the ability to control access to their content based on trustworthiness, geography, purpose, or other criteria, which can compromise data privacy and security.
Innovation Solution
A content distribution system that enables data owners to set restrictions on data consumers, using a key server to authenticate and attest the trustworthiness of data consumer devices before distributing key materials, ensuring access is granted only if restrictions such as attestation, geography location, or purpose requirements are met.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data owners can impose restrictions on data consumers, then data privacy and security are improved, but device complexity increases due to additional authentication and attestation mechanisms
Solution Approach 1:
The patent introduces a key server as an intermediary component that handles the complex authentication and attestation processes. The key server receives attestation data from data consumer devices, verifies it against restrictions set by data owners, and selectively distributes key materials. This intermediary approach allows data owners to maintain control over content access without directly managing complex authentication logic in their own systems.
Solution Approach 2:
The system segments the access control functionality into separate components: data owners define restrictions, data consumer devices provide attestation data, the key server performs verification and key distribution, and content servers handle actual content delivery. This segmentation allows each component to focus on specific tasks, reducing overall system complexity while maintaining strong security controls.
2Reliability
If key materials are distributed with restrictions, then access control is improved, but the ease of operation deteriorates due to additional authentication steps required by data consumers
Solution Approach 1:
The system performs attestation verification and restriction checking in advance before key material distribution. The key server pre-verifies that data consumer devices meet the required criteria (such as geographic location, device trustworthiness, or organizational affiliation) before granting access. This preliminary action ensures that only authorized devices receive keys, while legitimate users experience streamlined access once authentication is complete.
Data Source
Figure 1
Figure 2~4
Figure 3
AI summary
A content distribution system is described herein which enables a data owner of content to set one or more restrictions on a data consumer where the one or more restrictions need to be satisfied by a data consumer device before the data consumer has 5 access to the content. In addition, the content distribution system's components are described herein which include a data owner device, a key server, a data consumer device, a data producer device, and a content server.