Rights Validator System for Spoofed Time Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Digital rights management systems face challenges in managing time information accurately, particularly in devices like SIM cards and cell phone handsets, where time can be spoofed or not updated reliably, leading to potential unauthorized access to DRM-protected content.
Innovation Solution
A rights validator system that computes an estimated time based on a Most Recently Updated Trusted Time (MRUTT) from trusted sources, combining elapsed time estimates from various sources using a weighted average, and associates a degree of certainty with the estimated time, incorporating significant events and user behavior to mitigate spoofing and ensure secure access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Duration of action of stationary object
If time is kept by SIM card or cell phone handset, then time information can be maintained without continuous power, but the time can be spoofed or not updated reliably when device is cut off from power
Solution Approach 1:
The patent introduces a trusted time server as an intermediary authority that provides time information to the DRM system. Instead of relying on potentially spoofable local time sources (SIM card or handset clock), the system obtains time data from a remote trusted source, thereby resolving the contradiction between maintaining time without power and ensuring time accuracy.
Solution Approach 2:
The system implements feedback mechanisms where the DRM module receives time information from the trusted time server and uses this information to validate DRM rules. The system continuously updates time information based on feedback from the trusted source, ensuring accuracy even when local time sources may be spoofed or stale.
2Ease of operation
If user sets time manually in cell phone handset, then time can be adjusted to user's wish, but user can spoof the handset and SIM card time
Solution Approach 1:
The patent uses a trusted time server as an intermediary that overrides manual time settings from the user. Instead of accepting time data from the handset or SIM card (which can be spoofed), the system obtains time information from the remote trusted source, thereby maintaining ease of operation while preventing time spoofing.
Solution Approach 2:
The system takes preliminary anti-action by proactively obtaining time information from a trusted source before using it for DRM validation. This prevents the user from successfully spoofing time, as the trusted time server provides authentic time data that counteracts any manual time setting attempts.
3Loss of energy
If SIM card does not advance time when cut off from power, then power consumption is reduced, but time update requires communication with time source upon reconnection
Solution Approach 1:
The patent introduces a trusted time server as an intermediary that provides time information to the DRM system upon reconnection. This resolves the contradiction by allowing the SIM card to conserve power without continuously updating time, while still enabling timely DRM validation through the remote time source.
Data Source
AI summary
A rights validator system for controlling access to content, the system including a query processor to receive a rights query and to provide a result to the rights query based on an estimated time, and a time-based query response module operationally connected to the query processor, the time-based query response module being operative to determine the estimated time as a function of a most recently updated time, and a plurality of indications of elapsed time since the most recently updated time, the indications of elapsed time being from a plurality of different sources of time indication. Related apparatus and methods are also included.


