Proxy Certificate Decentralization for License Server Load Reduction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital rights management (DRM) systems face challenges in managing access to digital content across multiple devices, leading to management overload for central license servers and potential privacy violations, as well as difficulties in flexibly controlling content access due to single domain key binding.

Innovation Solution

A method involving a Local Licence Manager (LLM) that delegates authority from a central License Server to issue licenses using a proxy certificate, allowing for decentralized management and flexible access control through a bearer-proxy method, with features like proxy certificate issuance, renewal, and verification to maintain transparency and system stability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a central license server directly manages all domains, then domain management can be centralized and controlled, but the central license server experiences management overload

Engineering Contradiction:
Improvedomain management controlVSAvoidlicense server performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the centralized license management function into hierarchical segments: a root license server that issues proxy certificates to local license servers, and local license servers that handle domain-specific license operations. This segmentation distributes the management load while maintaining centralized control through the proxy certificate verification mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces proxy certificates as an intermediary mechanism between the root license server and local license servers. The proxy certificate acts as a mediator that delegiates authority from the central server to local servers, allowing local servers to operate independently while maintaining trust in the centralized system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a central license server manages all domains, then centralized control is achieved, but user privacy may be violated due to centralized information storage

Engineering Contradiction:
Improvecentralized controlVSAvoidprivacy violation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments user information storage and processing across multiple local license servers rather than centralizing it in one server. Each local license server handles information for its specific domain, reducing the privacy risk associated with centralized information storage while maintaining control through the proxy certificate system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The proxy certificate serves as an intermediary that enables decentralized operation while maintaining centralized trust. It allows local license servers to operate autonomously without requiring users to trust a single central server with all their information, thus protecting privacy while maintaining control.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If a domain is bound to a single domain key, then simple key management is achieved, but flexible access control to content becomes difficult

Engineering Contradiction:
Improvekey management simplicityVSAvoidaccess control flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent makes the domain key system dynamic by allowing local license servers to generate multiple domain keys under a single proxy certificate. This enables flexible access control where different content can be associated with different domain keys, while the overall key management remains organized under the hierarchical proxy certificate structure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The proxy certificate provides universal authority that can be used to generate multiple domain keys for different purposes. This multi-functional approach allows a single proxy certificate to support multiple domain keys, enabling flexible access control while maintaining simplified key management at the higher level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If multiple domains are provided for a single network, then access control flexibility improves, but the load on central license servers increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidcentral server load
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent segments the management of multiple domains across different local license servers, each operating independently within its domain. This segmentation allows multiple domains to exist with flexible access control while distributing the operational load away from the central root license server, which only performs proxy certificate verification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The proxy certificate acts as an intermediary that enables multiple local license servers to operate independently managing their own domains. This intermediary mechanism allows the system to support multiple domains with flexible access control without increasing the load on the central server, as local servers handle their own domain operations autonomously.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2012494B1License management system and method
Publication Date: 2014.08.06 SAMSUNG ELECTRONICS CO LTD
  • EP2012494B1 patent drawingFigure 1
  • EP2012494B1 patent drawingFigure 2
  • EP2012494B1 patent drawingFigure 3

AI summary

A license-management system and method is provided. A method of issuing a proxy certificate includes transmitting a proxy-certificate-issuance-request message (S301) to a license server (300) in order for a local license manager (310) to acquire an authority to issue a license; enabling the license server (300) to verify the proxy-certificate-issuance-request message (S311); if the proxy-certificate-issuance-request message is valid, transmitting a proxy certificate to the local license manager (310) by the license server (300), the proxy certificate including information regarding the authority to issue a license (S321); and verifying the proxy certificate by the local license manager (300), (S331).