Rights Issuer Key Encapsulation for Secure Digital Rights Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital rights management (DRM) systems face security issues as un-trusted rights issuers can generate illegal rights objects (ROs) for devices other than the target device, compromising the integrity of content consumption.
Innovation Solution
The method involves encapsulating key information with a public key of the target device, ensuring that only the target device can access the real key, thereby preventing un-trusted rights issuers from generating illegal ROs for other devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the RI obtains key information in plain text, then the RI can generate ROs for multiple devices, but un-trusted RIs can generate illegal ROs for devices other than the target device
Solution Approach 1:
The patent segments the key information transmission by encrypting it with the target device's public key before sending to the RI. This segmentation separates the key information from plain text form, allowing the RI to process encrypted data for multiple devices while maintaining security through individual device-specific encryption.
Solution Approach 2:
The patent introduces encryption as an intermediary mechanism between the key information and the RI. The encrypted key information acts as a mediator that the RI can handle without exposing the actual key, enabling the RI to serve multiple devices while preventing unauthorized RO generation.
2Device complexity
If the LRM directly generates RO for SCE device, then the import process is simplified, but the SCE device cannot identify the LRM requiring RI involvement
Solution Approach 1:
The patent merges the LRM's RO generation capability with the RI's device identification capability. By having the LRM request RO generation from the RI (which knows the device identity), the system combines both functions in a unified process, eliminating the need for separate identification steps.
3Reliability
If public key encryption is used to protect key information, then security against un-trusted RIs is improved, but the complexity of key management increases
Solution Approach 1:
The patent implements self-service key management where each device automatically generates its own public-private key pair and uses its own public key to encrypt key information received from the LRM. This eliminates the need for centralized key distribution infrastructure, reducing overall system complexity while maintaining strong security.
Data Source
AI summary
A method for importing or moving a rights object (RO) is provided, a rights issuer (RI) receives a request message of importing or moving an RO to a target device, the request message including key information encapsulated by a public key of the target device; the RI generates the RO according to the request message, the RO including the key information encapsulated by the public key of the target device; and the RI provides the RO for the target device. An RI is also provided. In the present invention, the key information encapsulated by the public key of the target device is provided for the RI, and the real key is hidden from the RI, such that the un-trust RI cannot generate the illegal RO for other devices except the target device, thereby enhancing the security of importing or moving the RO through the RI.


