Secure Content Distribution via Segmented Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure content distribution systems face challenges in ensuring secure access control for encrypted audio/video/data content, as unauthorized devices can potentially obtain decryption keys, compromising content security.

Innovation Solution

A secure content distribution system that separates content and access control information distribution systems, using encrypted program content and access control information to ensure only authorized devices can decrypt and access the content, with decryption keys determined based on received access control information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If decryption keys are distributed through the same system as encrypted content, then content access is convenient, but security is compromised as unauthorized devices can obtain keys

Engineering Contradiction:
Improvecontent securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the distribution of content and access control information into separate channels. Encrypted content is distributed through a content distribution system while decryption keys are distributed through a separate access control information distribution system, preventing unauthorized devices from obtaining both content and keys simultaneously

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A receiving device acts as an intermediary that must successfully receive and process information from both the content distribution system and the access control information distribution system before it can decrypt and access the content. This intermediary role adds a security layer as the device must be properly configured and authorized to receive both streams

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a single distribution system is used for both content and access control, then system complexity is reduced, but access control reliability deteriorates

Engineering Contradiction:
Improveaccess control reliabilityVSAvoiddistribution system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The distribution infrastructure is segmented into two independent systems: a content distribution system for delivering encrypted content and an access control information distribution system for delivering decryption keys. This segmentation ensures that failures or compromises in one system do not directly compromise the other, enhancing access control reliability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access control information distribution system is extracted as a separate entity from the content distribution system. By taking out the key distribution function and placing it in a separate system, the patent ensures that access control operates independently and can be more reliably enforced without being constrained by the content delivery infrastructure

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8675872B2Secure content distribution apparatus, systems, and methods
Publication Date: 2014.03.18 DISH TECHNOLOGIES LLC
  • US8675872B2 patent drawing
  • US8675872B2 patent drawing
  • US8675872B2 patent drawing

AI summary

Various embodiments facilitate program content access management. One embodiment is a system with a secure content provider communicatively coupled to a first system and a second system, operable to stream encrypted content over the first system, and operable to communicate access control information over the second system; and a receiving device coupled to the first system and the second system, operable to receive the encrypted program content from the first system, operable to receive the access control information over the second system such that the encrypted program content is decrypted based on the access control information to generate program content, and operable to communicate the program content to a presentation device.