Rights Issuer Key Encapsulation for Secure Digital Rights Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital rights management (DRM) systems face security issues as un-trusted rights issuers can generate illegal rights objects (ROs) for devices other than the target device, compromising the integrity of content consumption.

Innovation Solution

The method involves encapsulating key information with a public key of the target device, ensuring that only the target device can access the real key, thereby preventing un-trusted rights issuers from generating illegal ROs for other devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the RI obtains key information in plain text, then the RI can generate ROs for multiple devices, but un-trusted RIs can generate illegal ROs for devices other than the target device

Engineering Contradiction:
Improveability to generate ROs for multiple devicesVSAvoidsecurity of RO generation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the key information transmission by encrypting it with the target device's public key before sending to the RI. This segmentation separates the key information from plain text form, allowing the RI to process encrypted data for multiple devices while maintaining security through individual device-specific encryption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encryption as an intermediary mechanism between the key information and the RI. The encrypted key information acts as a mediator that the RI can handle without exposing the actual key, enabling the RI to serve multiple devices while preventing unauthorized RO generation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If the LRM directly generates RO for SCE device, then the import process is simplified, but the SCE device cannot identify the LRM requiring RI involvement

Engineering Contradiction:
Improvesimplicity of RO import processVSAvoiddevice identification capability
Core Design Contradiction:
Device complexityVSEase of operation

Solution Approach 1:

The patent merges the LRM's RO generation capability with the RI's device identification capability. By having the LRM request RO generation from the RI (which knows the device identity), the system combines both functions in a unified process, eliminating the need for separate identification steps.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If public key encryption is used to protect key information, then security against un-trusted RIs is improved, but the complexity of key management increases

Engineering Contradiction:
Improvesecurity of key informationVSAvoidcomplexity of key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service key management where each device automatically generates its own public-private key pair and uses its own public key to encrypt key information received from the LRM. This eliminates the need for centralized key distribution infrastructure, reducing overall system complexity while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8737622B2Method for importing rights object and rights issuer
Publication Date: 2014.05.27 HUAWEI TECH CO LTD
  • US8737622B2 patent drawing
  • US8737622B2 patent drawing
  • US8737622B2 patent drawing

AI summary

A method for importing or moving a rights object (RO) is provided, a rights issuer (RI) receives a request message of importing or moving an RO to a target device, the request message including key information encapsulated by a public key of the target device; the RI generates the RO according to the request message, the RO including the key information encapsulated by the public key of the target device; and the RI provides the RO for the target device. An RI is also provided. In the present invention, the key information encapsulated by the public key of the target device is provided for the RI, and the real key is hidden from the RI, such that the un-trust RI cannot generate the illegal RO for other devices except the target device, thereby enhancing the security of importing or moving the RO through the RI.