PKI Trust Authority for Content Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current content provision systems face inefficiencies due to the need for individual trust relationships between numerous content providers and consumer devices, leading to a complex network of trust pairings, which becomes cumbersome and inefficient as the number of providers and users increases.

Innovation Solution

Implementing a Public Key Infrastructure (PKI) with a central trust authority that issues and manages certificates, allowing devices and content providers to mutually recognize each other as authorized, reducing the need for individual trust relationships and enabling secure, efficient data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual trust relationships are established between each content provider and each consumer device, then security is improved, but device complexity and system complexity increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoidtrust relationship management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trust authority as an intermediary entity that issues certificates to both content providers and consumer devices. This mediator eliminates the need for direct individual trust relationships between every provider and device pair, while maintaining security through certificate-based authentication. The trust authority acts as a central mediator that enables mutual recognition without requiring complex peer-to-peer trust management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements a universal certificate system where a single trust authority serves all content providers and consumer devices in the ecosystem. This universal approach allows any authorized device to access content from any authorized provider through mutual certificate verification, eliminating the need for multiple specialized trust relationships and simplifying the overall system architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If individual trust relationships are established between each content provider and each consumer device, then mutual authentication is improved, but the number of required trust pairings increases

Engineering Contradiction:
Improvemutual authenticationVSAvoidnumber of trust pairings
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The trust authority serves as a central mediator that issues certificates to all participants in the ecosystem. Instead of requiring N×M individual trust pairings between N content providers and M consumer devices, the system only requires N+M certificate issuances from the trust authority, dramatically reducing the total number of trust relationships needed while maintaining mutual authentication capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If a central trust authority is implemented, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improvetrust management simplicityVSAvoidcertificate management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where consumer devices and content providers automatically verify each other's certificates through cryptographic validation. The trust authority pre-issues certificates, and the system participants independently perform mutual authentication without requiring manual intervention or complex configuration, simplifying operation while managing complexity through automated cryptographic processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2807810B1Method and system for auhtorisation in a content provision system
Publication Date: 2020.01.22 YOUVIEW TV
  • EP2807810B1 patent drawingFigure 1
  • EP2807810B1 patent drawingFigure 2
  • EP2807810B1 patent drawingFigure 3

AI summary

A method and system for authorising multiple devices (56) and multiple content providers (52) in a content provision system is provided. Each content provider is issued with a content provider authorisation certificate. Each user device is issued with a user device authorisation certificate, the two certificates for coming from a common source. A determination is then made as to whether each content provider and each user device is authorised to participate in the content provision system via a mutual exchange and comparison of the certificates between respective content providers and user devices.