Secure Content Exchange System for DRM Rights Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing digital rights management (DRM) systems face challenges in securely managing and transferring user domain rights objects across different domains, particularly in legacy systems, where DRM Agents need to register with multiple Rights Issuers and Local Rights Managers, leading to complexity and insecurity in rights management and transfer.

Innovation Solution

The implementation of a secure content exchange (SCE) system that allows SCE-conformant DRM Agents to join a User Domain managed by a Domain Enforcement Agent (DEA) under the oversight of a Domain Authority, enabling secure association and transfer of User Domain Rights Objects without requiring direct registration with each Rights Issuer or Local Rights Manager, using symmetric and message integrity keys for secure communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DRM Agents register with each Rights Issuer and Local Rights Manager in legacy systems, then rights management coverage is comprehensive, but system complexity increases and security is compromised

Engineering Contradiction:
Improverights management securityVSAvoidregistration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a Domain Authority (DA) as an intermediary that issues domain authorization certificates to Rights Issuers and Local Rights Managers. SCE-conformant DRM Agents register with the DA once to obtain domain authorization, which then allows them to access User Domain Rights Objects from any authorized RI/LRM in the domain without individual registration. This mediator approach resolves the contradiction by centralizing authentication while maintaining comprehensive rights management coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple Rights Issuers and Local Rights Managers manage separate domains, then rights management is distributed, but security vulnerabilities increase and management becomes complex

Engineering Contradiction:
Improvedomain compatibilityVSAvoidrights transfer security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent merges multiple distributed domain authorities into a single User Domain managed by one Domain Enforcement Agent (DEA) under the DA's oversight. Multiple RIs and LRMs are consolidated into the same User Domain, allowing SCE-conformant DRM Agents to access rights from any source without leaving the domain. This merging maintains adaptability across multiple rights sources while improving security through centralized domain management and reduced attack surfaces.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If legacy DRM Agents use individual RI registration, then rights issuance is direct, but backwards compatibility with SCE systems is lost

Engineering Contradiction:
Improverights acquisition simplicityVSAvoidsystem interoperability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal Domain Authorization certificate issued by the DA that serves multiple functions: it authenticates SCE-conformant DRM Agents to the DEA, enables access to User Domain Rights Objects from any authorized RI/LRM, and maintains compatibility with the broader SCE ecosystem. This single universal credential replaces the need for multiple individual registrations while preserving simple rights acquisition through the domain-wide authorization mechanism.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10567371B2System and method for securing the life-cycle of user domain rights objects
Publication Date: 2020.02.18 GOOGLE TECHNOLOGY HOLDINGS LLC
  • US10567371B2 patent drawing
  • US10567371B2 patent drawing
  • US10567371B2 patent drawing

AI summary

In a method for enabling support for backwards compatibility in a User Domain, in one of a Rights Issuer (RI) and a Local Rights Manager (LRM), a Rights Object Encryption Key (REK) and encrypted REK are received from an entity that generated a User Domain Authorization for the one of the RI and the LRM and the REK is used to generate a User Domain Rights Object (RO) that includes the User Domain Authorization and the encrypted REK.