Secret-less DRM Application for Game Console Video Streaming

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing DRM technologies face compatibility issues on game consoles like Xbox 360 due to proprietary security models and media frameworks, making secure playback of protected multimedia content challenging, as they often require unique cryptographic keys that can be exposed to attacks and are not compatible with non-native DRM systems.

Innovation Solution

Implementing a secret-less application that uses a Single Sign On (SSO) model for client authentication, where no secret information is stored on the game console, and an encrypted content key is generated using a public cryptographic key, stored remotely, and delivered through a key server, ensuring secure playback without embedding cryptographic keys within the application or certificate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional DRM technologies with cryptographic keys are implemented on game consoles, then secure playback of protected content is achieved, but compatibility with proprietary security models is lost and security vulnerabilities arise

Engineering Contradiction:
Improvesecure playbackVSAvoidcompatibility with proprietary security models
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a key server as an intermediary between the content protection system and the game console. The key server mediates the authentication process by verifying credentials and providing content keys without requiring the console to store or process cryptographic secrets locally, thus bridging the gap between DRM requirements and proprietary security models

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the secret key storage and management functions from the game console application entirely. By removing cryptographic keys from the client side and placing them exclusively on the key server, the system eliminates the conflict between having secrets on the console and maintaining compatibility with proprietary security models that prohibit secret storage

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If cryptographic keys are stored on the game console for DRM playback, then content protection is enabled, but security vulnerabilities to debugging and replay attacks increase

Engineering Contradiction:
Improvecontent protectionVSAvoiddebugging and replay attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent removes cryptographic keys from the game console entirely, extracting them to a remote key server. This elimination of local secret storage fundamentally prevents debugging attacks that would otherwise extract keys from memory or storage, and prevents replay attacks by requiring time-limited, session-specific key retrieval through authenticated requests

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system implements self-service authentication where the key server automatically validates credentials and provides appropriate content keys without human intervention. The server maintains security by itself managing key distribution and expiration, eliminating the need for vulnerable client-side key management

Inventive Principle:
Principle #25Self-service

3Reliability

If secret keys are embedded in the application or certificate, then DRM functionality is achieved, but compatibility across different game console models is lost

Engineering Contradiction:
ImproveDRM functionalityVSAvoidcompatibility across different game console models
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The key server is designed as a universal authentication service that handles multiple types of credentials and supports different game console models through a unified interface. It can verify various credential formats and provide appropriate content keys, making the DRM system compatible across different console architectures without requiring model-specific key embedding

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The key server acts as a universal mediator that translates between different credential formats from various console models and the standardized DRM key format. This intermediary layer abstracts away model-specific differences, allowing the same DRM functionality to work across different console architectures

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9853957B2DRM protected video streaming on game console with secret-less application
Publication Date: 2017.12.26 ADOBE INC
  • US9853957B2 patent drawing
  • US9853957B2 patent drawing
  • US9853957B2 patent drawing

AI summary

Techniques are disclosed for secure playback of protected multimedia content on a game console using a secret-less application. An SSO model can be used for client authentication at a key server, which eliminates the need of storing or using any secret information in the client application. Further, an encrypted content key generated by a content packager using a public key can be deployed in the key URI of a playlist file, which is sent to the key server. The key server can be configured to decrypt the content key using a corresponding private key. Further, the content key and unencrypted samples are protected in the game console client application from debugging and replay attacks by using additional security checks at both the client and key server. By storing secret information remotely from the game console and using the SSO model, DRM policies can be enforced on an untrusted client application.