Proxy Certificate Decentralization for License Server Load Reduction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital rights management (DRM) systems face challenges in managing access to digital content across multiple devices, leading to management overload for central license servers and potential privacy violations, as well as difficulties in flexibly controlling content access due to single domain key binding.
Innovation Solution
A method involving a Local Licence Manager (LLM) that delegates authority from a central License Server to issue licenses using a proxy certificate, allowing for decentralized management and flexible access control through a bearer-proxy method, with features like proxy certificate issuance, renewal, and verification to maintain transparency and system stability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a central license server directly manages all domains, then domain management can be centralized and controlled, but the central license server experiences management overload
Solution Approach 1:
The patent divides the centralized license management function into hierarchical segments: a root license server that issues proxy certificates to local license servers, and local license servers that handle domain-specific license operations. This segmentation distributes the management load while maintaining centralized control through the proxy certificate verification mechanism.
Solution Approach 2:
The patent introduces proxy certificates as an intermediary mechanism between the root license server and local license servers. The proxy certificate acts as a mediator that delegiates authority from the central server to local servers, allowing local servers to operate independently while maintaining trust in the centralized system.
2Reliability
If a central license server manages all domains, then centralized control is achieved, but user privacy may be violated due to centralized information storage
Solution Approach 1:
The patent segments user information storage and processing across multiple local license servers rather than centralizing it in one server. Each local license server handles information for its specific domain, reducing the privacy risk associated with centralized information storage while maintaining control through the proxy certificate system.
Solution Approach 2:
The proxy certificate serves as an intermediary that enables decentralized operation while maintaining centralized trust. It allows local license servers to operate autonomously without requiring users to trust a single central server with all their information, thus protecting privacy while maintaining control.
3Device complexity
If a domain is bound to a single domain key, then simple key management is achieved, but flexible access control to content becomes difficult
Solution Approach 1:
The patent makes the domain key system dynamic by allowing local license servers to generate multiple domain keys under a single proxy certificate. This enables flexible access control where different content can be associated with different domain keys, while the overall key management remains organized under the hierarchical proxy certificate structure.
Solution Approach 2:
The proxy certificate provides universal authority that can be used to generate multiple domain keys for different purposes. This multi-functional approach allows a single proxy certificate to support multiple domain keys, enabling flexible access control while maintaining simplified key management at the higher level.
4Adaptability or versatility
If multiple domains are provided for a single network, then access control flexibility improves, but the load on central license servers increases
Solution Approach 1:
The patent segments the management of multiple domains across different local license servers, each operating independently within its domain. This segmentation allows multiple domains to exist with flexible access control while distributing the operational load away from the central root license server, which only performs proxy certificate verification.
Solution Approach 2:
The proxy certificate acts as an intermediary that enables multiple local license servers to operate independently managing their own domains. This intermediary mechanism allows the system to support multiple domains with flexible access control without increasing the load on the central server, as local servers handle their own domain operations autonomously.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A license-management system and method is provided. A method of issuing a proxy certificate includes transmitting a proxy-certificate-issuance-request message (S301) to a license server (300) in order for a local license manager (310) to acquire an authority to issue a license; enabling the license server (300) to verify the proxy-certificate-issuance-request message (S311); if the proxy-certificate-issuance-request message is valid, transmitting a proxy certificate to the local license manager (310) by the license server (300), the proxy certificate including information regarding the authority to issue a license (S321); and verifying the proxy certificate by the local license manager (300), (S331).