Portable Object Secure Access File Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital rights management systems are incompatible, leading to issues when users switch terminals, as the encryption key for secure digital content is tied to the old terminal's certificate and cannot be read on a new terminal, causing access issues even if the old terminal is broken or stolen.

Innovation Solution

A method that adapts the encryption key and access rights to the new terminal's digital right type, allowing the portable communicating object to produce a secure access file accessible to the new terminal, enabling seamless processing of secure digital content without requiring a secure channel or knowledge of the old terminal's certificate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the encryption key is tied to the old terminal's certificate for secure access, then security is maintained, but compatibility with new terminals is lost

Engineering Contradiction:
ImprovesecurityVSAvoidterminal compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system separates the security functions into distinct components: the portable communicating object stores the decryption key and access rights independently, while the terminal contains only the processing agent. This segmentation allows the key to be transferred to new terminals without being bound to any specific terminal's certificate, resolving the contradiction between security and compatibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The portable communicating object acts as an intermediary that bridges the secure content and various terminals. It holds the decryption key and can provide it to any terminal with a compatible agent, serving as a universal mediator that maintains security while enabling cross-terminal compatibility without requiring the key to be tied to any single terminal's certificate.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the secure access file is linked to the old terminal's certificate, then access control is enforced, but access on new terminals becomes impossible

Engineering Contradiction:
Improveaccess controlVSAvoidterminal switching
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The portable communicating object is designed with universal functionality to work with any terminal that has a compatible processing agent. The access rights and decryption key stored in the portable object can be utilized across multiple terminals without requiring reconfiguration or being bound to a specific terminal's certificate, enabling seamless terminal switching while maintaining access control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system transitions from a static model where access rights are permanently bound to a specific terminal's certificate, to a dynamic model where the portable communicating object can be moved between terminals. The association between the decryption key and terminal certificate becomes flexible rather than fixed, allowing the same key to serve multiple terminals over time while maintaining security through the portable object's controlled distribution.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the key is enciphered with the public key of the old terminal's certificate, then security is ensured, but the key cannot be read in a new terminal

Engineering Contradiction:
Improveencryption securityVSAvoidterminal independence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The decryption key is extracted from the context of any specific terminal's certificate and placed into the portable communicating object. Instead of being enciphered with and bound to a particular terminal's public key, the key is stored in the portable object in a form that can be decrypted and used by any terminal possessing the appropriate processing agent, achieving both security and terminal independence.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The portable communicating object is pre-configured with the decryption key and access rights before terminal switching occurs. This preliminary preparation ensures that when the user moves to a new terminal, the key is already available in the portable object and can be immediately utilized by the new terminal's agent without requiring re-enciphering or reconfiguration for the new terminal's certificate.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8488787B2Management of secure access to a secure digital content in a portable communicating object
Publication Date: 2013.07.16 THALES DIS FRANCE SA
  • US8488787B2 patent drawing
  • US8488787B2 patent drawing
  • US8488787B2 patent drawing

AI summary

The invention concerns a terminal (T) comprising an agent (AS) for processing a secure content encrypted with a key (KCN) and transmitted by a first server (SCN). In order to manage a secure access to the secure content, an application (AG) of a portable communicating object, such as a chip card, associated with a terminal stores one type of related digital right (TDN) and a certificate and transmitted by the agent and stores an access right (DA) and the key (KCN) related to the secure content transmitted from a second server (SAD). The application adapts the access right and the key and modifies the secure content, based on the type of right, and produces a secure access file based on the adapted access right and the key and on the certificate, the produced file being accessible by the terminal so that the agent may process the modified content.