Secure Content Distribution via Hardware-Isolated Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing distribution of digitized content, such as DVDs, incurs substantial costs for providers due to warehousing and piracy concerns, as content providers are reluctant to store content in centralized databases for fear of unauthorized access.

Innovation Solution

A secure digital content distribution system that uses double encryption (AES and FDE) with a hardware-based encryption engine isolated from the host processor, where the decryption keys are remote and unknown to the distribution server, ensuring secure retrieval and burning of content upon user request.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If content is stored in a centralized database for easy retrieval and distribution, then distribution efficiency is improved, but security risks increase due to piracy and unauthorized access

Engineering Contradiction:
Improvedistribution efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments the encryption process into two distinct stages: first encryption when content is stored in the database, and second encryption when content is retrieved for distribution. This segmentation allows the database to store only encrypted content without requiring the decryption keys, thereby maintaining security while enabling efficient retrieval and distribution operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary encryption layer where content is encrypted with a first key for database storage and then encrypted again with a second key for distribution. This intermediary double-encryption mechanism allows the system to maintain both security (by keeping keys separate) and distribution efficiency (by enabling key-based access control).

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If content is encrypted with remote unknown keys to enhance security, then piracy protection is improved, but decryption complexity increases

Engineering Contradiction:
Improvepiracy protectionVSAvoiddecryption complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses separate encryption keys for different purposes: a first encryption key for securing content in the database and a second encryption key for securing content during distribution. This copying of encryption functions to different stages simplifies the decryption process at the consumer end, as only the second key needs to be managed for playback, while the first key remains securely stored remotely.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If physical DVDs are warehoused to satisfy consumer needs, then content availability is improved, but storage costs increase

Engineering Contradiction:
Improvecontent availabilityVSAvoidstorage requirements
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The system replaces physical DVD warehousing with a digital copying approach where content is stored as encrypted digital copies in a database. This allows unlimited consumers to access the same content simultaneously without requiring physical duplication, dramatically reducing storage requirements while maintaining content availability.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent substitutes the mechanical physical DVD warehousing system with a digital encryption-based system. Instead of storing physical discs that must be manually handled and inventoried, the system uses encrypted digital storage with key-based access control, eliminating the need for physical storage infrastructure while improving content availability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10181166B2Secure content distribution system
Publication Date: 2019.01.15 ADOBE INC
  • US10181166B2 patent drawing
  • US10181166B2 patent drawing
  • US10181166B2 patent drawing

AI summary

A user selection of one or more of a plurality of content is received. The selected content is encrypted by a first encryption key that is remote and unknown to the distribution server. Payment information associated with the user selection is also received and verified. The selected content from is retrieved from a remote database. The first encryption key corresponding to the selected content to decrypt the encrypted content corresponding to the user selection is obtained. Decryption is performed by a hardware-based engine of the distribution server that is isolated from a host processor of the distribution server. The content corresponding to the user selection is encrypted according to a second encryption key that is known to the distribution server.