Media Asset Guard System for Multi-DRM Delivery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing infrastructure for delivering encrypted media assets faces challenges in managing multiple DRM technologies and licensing complexities, particularly in over-the-top (OTT) services, where different end user platforms require different encryption and decryption methods, and there is a need for efficient asset delivery without duplicating encrypted versions across platforms.

Innovation Solution

A computer system with a guard module that manages multiple DRM technologies by using a key server to associate assets with environments based on characteristics, enabling a single set of assets to be used across different platforms, and includes a verification method to ensure valid user requests, simplifying the workflow and reducing storage and encryption costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple DRM technologies are supported for different end user platforms, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvesupport for multiple DRM technologiesVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The guard system is designed as a universal platform that can handle multiple DRM technologies (PlayReady, Widevine, FairPlay) through a single interface. The system uses environment configurations that define sets of DRM technologies, allowing one guard system instance to serve multiple platforms and DRM standards without requiring separate systems for each technology.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary layer consisting of environment configurations and license request modifications that translate between different DRM technologies and the underlying asset delivery system. This intermediary handles the complexity of multiple DRM formats by abstracting them into standardized environment definitions, shielding the core asset delivery infrastructure from DRM-specific complexities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If a single set of assets is shared across multiple platforms, then storage costs are reduced, but manufacturing precision requirements increase

Engineering Contradiction:
Improvestorage requirementsVSAvoidencryption format compatibility
Core Design Contradiction:
Quantity of substanceVSManufacturing precision

Solution Approach 1:

The system changes the parameters of asset encryption by using environment-specific configurations that define how assets are encrypted and delivered. Different environments can specify different encryption schemes, key management approaches, and delivery formats for the same underlying asset, allowing a single asset to be adapted to multiple platforms through parameter modification rather than creating separate asset copies.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements preliminary action by pre-defining environment configurations that encapsulate all necessary encryption and delivery parameters for different platforms. These environment definitions are established in advance, allowing the system to automatically select and apply the appropriate configuration when an asset needs to be delivered to a specific platform, eliminating the need for runtime encryption decisions or asset duplication.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If environment configurations define multiple DRM technologies, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvemulti-DRM support in configurationsVSAvoidconfiguration management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the complexity of supporting multiple DRM technologies by organizing them into environment configurations. Each environment can define a set of DRM technologies that are relevant to that particular delivery context. This segmentation allows the system to manage complexity by dividing it into manageable environment-specific groups rather than handling all DRM technologies simultaneously in a single monolithic configuration.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3170116B1Controlling delivery of encrypted media assets
Publication Date: 2023.07.05 PRJ HLDG CO LLC
  • EP3170116B1 patent drawingFigure 1
  • EP3170116B1 patent drawingFigure 1a
  • EP3170116B1 patent drawingFigure 2

AI summary

The invention relates to a computer guard system for controlling delivery of encrypted media assets in a service which governs the delivery of a set of media assets to a group of authorised users comprising: an administrator interface configured to receive configuration data from an administrator to define at least one environment defining how media assets in that service are to be delivered to authorised users, wherein the configuration data defines, for each environment, (a) multiple DRM technologies for decrypting the same asset at multiple end user platforms, each DRM technology being associated with its own set of default license properties;(b)at least one software plug-in to be instantiated to perform a verification method to verify if an end user request for delivery of an asset is valid; a store for holding defined environments with respective environment identifiers; a key server module having an interface connectable to an encryption module and configured to: exchange (i) an asset identifier, which identifies an asset to be encrypted, (ii) a secret key for use in encrypting the asset, and (iii) a key identifier which is to be located in the encrypted asset and which identifies the secret key; execute a set of rules to compare a characteristic associated with the asset with multiple environments to associate at least one environment with the asset wherein the characteristic represents the service for which the asset is provided; and store an association between the asset and at least one determined environment, whereby multiple assets for the same service intended for delivery on different end users platforms are associated with a single environment, and wherein the configuration data for each environment identifies the default license properties and software plug-in to be applied to the asset, in dependence on the DRM technology used at the end user platform to enable the computer system to automatically respond to end user requests to play out an asset.