Secret-less DRM Application for Game Console Video Streaming
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing DRM technologies face compatibility issues on game consoles like Xbox 360 due to proprietary security models and media frameworks, making secure playback of protected multimedia content challenging, as they often require unique cryptographic keys that can be exposed to attacks and are not compatible with non-native DRM systems.
Innovation Solution
Implementing a secret-less application that uses a Single Sign On (SSO) model for client authentication, where no secret information is stored on the game console, and an encrypted content key is generated using a public cryptographic key, stored remotely, and delivered through a key server, ensuring secure playback without embedding cryptographic keys within the application or certificate.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional DRM technologies with cryptographic keys are implemented on game consoles, then secure playback of protected content is achieved, but compatibility with proprietary security models is lost and security vulnerabilities arise
Solution Approach 1:
The patent introduces a key server as an intermediary between the content protection system and the game console. The key server mediates the authentication process by verifying credentials and providing content keys without requiring the console to store or process cryptographic secrets locally, thus bridging the gap between DRM requirements and proprietary security models
Solution Approach 2:
The patent extracts the secret key storage and management functions from the game console application entirely. By removing cryptographic keys from the client side and placing them exclusively on the key server, the system eliminates the conflict between having secrets on the console and maintaining compatibility with proprietary security models that prohibit secret storage
2Reliability
If cryptographic keys are stored on the game console for DRM playback, then content protection is enabled, but security vulnerabilities to debugging and replay attacks increase
Solution Approach 1:
The patent removes cryptographic keys from the game console entirely, extracting them to a remote key server. This elimination of local secret storage fundamentally prevents debugging attacks that would otherwise extract keys from memory or storage, and prevents replay attacks by requiring time-limited, session-specific key retrieval through authenticated requests
Solution Approach 2:
The system implements self-service authentication where the key server automatically validates credentials and provides appropriate content keys without human intervention. The server maintains security by itself managing key distribution and expiration, eliminating the need for vulnerable client-side key management
3Reliability
If secret keys are embedded in the application or certificate, then DRM functionality is achieved, but compatibility across different game console models is lost
Solution Approach 1:
The key server is designed as a universal authentication service that handles multiple types of credentials and supports different game console models through a unified interface. It can verify various credential formats and provide appropriate content keys, making the DRM system compatible across different console architectures without requiring model-specific key embedding
Solution Approach 2:
The key server acts as a universal mediator that translates between different credential formats from various console models and the standardized DRM key format. This intermediary layer abstracts away model-specific differences, allowing the same DRM functionality to work across different console architectures
Data Source
AI summary
Techniques are disclosed for secure playback of protected multimedia content on a game console using a secret-less application. An SSO model can be used for client authentication at a key server, which eliminates the need of storing or using any secret information in the client application. Further, an encrypted content key generated by a content packager using a public key can be deployed in the key URI of a playlist file, which is sent to the key server. The key server can be configured to decrypt the content key using a corresponding private key. Further, the content key and unencrypted samples are protected in the game console client application from debugging and replay attacks by using additional security checks at both the client and key server. By storing secret information remotely from the game console and using the SSO model, DRM policies can be enforced on an untrusted client application.


