Portable Object Secure Access File Adaptation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital rights management systems are incompatible, leading to issues when users switch terminals, as the encryption key for secure digital content is tied to the old terminal's certificate and cannot be read on a new terminal, causing access issues even if the old terminal is broken or stolen.
Innovation Solution
A method that adapts the encryption key and access rights to the new terminal's digital right type, allowing the portable communicating object to produce a secure access file accessible to the new terminal, enabling seamless processing of secure digital content without requiring a secure channel or knowledge of the old terminal's certificate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the encryption key is tied to the old terminal's certificate for secure access, then security is maintained, but compatibility with new terminals is lost
Solution Approach 1:
The system separates the security functions into distinct components: the portable communicating object stores the decryption key and access rights independently, while the terminal contains only the processing agent. This segmentation allows the key to be transferred to new terminals without being bound to any specific terminal's certificate, resolving the contradiction between security and compatibility.
Solution Approach 2:
The portable communicating object acts as an intermediary that bridges the secure content and various terminals. It holds the decryption key and can provide it to any terminal with a compatible agent, serving as a universal mediator that maintains security while enabling cross-terminal compatibility without requiring the key to be tied to any single terminal's certificate.
2Reliability
If the secure access file is linked to the old terminal's certificate, then access control is enforced, but access on new terminals becomes impossible
Solution Approach 1:
The portable communicating object is designed with universal functionality to work with any terminal that has a compatible processing agent. The access rights and decryption key stored in the portable object can be utilized across multiple terminals without requiring reconfiguration or being bound to a specific terminal's certificate, enabling seamless terminal switching while maintaining access control.
Solution Approach 2:
The system transitions from a static model where access rights are permanently bound to a specific terminal's certificate, to a dynamic model where the portable communicating object can be moved between terminals. The association between the decryption key and terminal certificate becomes flexible rather than fixed, allowing the same key to serve multiple terminals over time while maintaining security through the portable object's controlled distribution.
3Reliability
If the key is enciphered with the public key of the old terminal's certificate, then security is ensured, but the key cannot be read in a new terminal
Solution Approach 1:
The decryption key is extracted from the context of any specific terminal's certificate and placed into the portable communicating object. Instead of being enciphered with and bound to a particular terminal's public key, the key is stored in the portable object in a form that can be decrypted and used by any terminal possessing the appropriate processing agent, achieving both security and terminal independence.
Solution Approach 2:
The portable communicating object is pre-configured with the decryption key and access rights before terminal switching occurs. This preliminary preparation ensures that when the user moves to a new terminal, the key is already available in the portable object and can be immediately utilized by the new terminal's agent without requiring re-enciphering or reconfiguration for the new terminal's certificate.
Data Source
AI summary
The invention concerns a terminal (T) comprising an agent (AS) for processing a secure content encrypted with a key (KCN) and transmitted by a first server (SCN). In order to manage a secure access to the secure content, an application (AG) of a portable communicating object, such as a chip card, associated with a terminal stores one type of related digital right (TDN) and a certificate and transmitted by the agent and stores an access right (DA) and the key (KCN) related to the secure content transmitted from a second server (SAD). The application adapts the access right and the key and modifies the secure content, based on the type of right, and produces a secure access file based on the adapted access right and the key and on the certificate, the produced file being accessible by the terminal so that the agent may process the modified content.


