Secure Digital Document Distribution via Server-Authenticating Smart Cards

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for secure distribution of digital documents, such as musical and software works, fail to prevent unauthorized distribution and decryption due to vulnerabilities in encryption techniques and the ease of creating 'pirate' readers, especially when private keys are compromised.

Innovation Solution

A method and system that securely distribute digital documents by using a server-connected storage means to authenticate and authorize document readers, transmitting decryption keys only to authorized readers, and maintaining lists of unauthorized readers to prevent fraudulent use and deactivate unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If documents are encrypted and distributed freely over the Internet, then document circulation is improved, but unauthorized decryption and piracy increase

Engineering Contradiction:
Improvedocument circulationVSAvoidunauthorized decryption
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a server as an intermediary between the encrypted document and the reader. The server stores decryption keys and only provides them to authenticated readers through a controlled authentication process. This mediator architecture allows documents to circulate freely in encrypted form while preventing unauthorized decryption, as the decryption key is only released after successful authentication of the reader with the server.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If private keys are distributed to readers for decryption, then document playback is enabled, but security is compromised when private keys are obtained by pirates

Engineering Contradiction:
Improvedocument playbackVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the decryption key from the reader device and stores it securely on the server instead. The reader only contains authentication credentials, not the actual decryption key. This separation removes the security vulnerability of storing private keys in readers, as the key never resides in the reader and cannot be extracted from it by pirates.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements dynamic key management where decryption keys are not static in the reader but are retrieved from the server on-demand after authentication. The system transitions from a static key storage model to a dynamic retrieval model, allowing the server to revoke or update keys as needed, thereby maintaining security even if a key is compromised.

Inventive Principle:
Principle #15Dynamics

3Reliability

If authentication systems are implemented to control document access, then unauthorized distribution is reduced, but system complexity increases

Engineering Contradiction:
Improveaccess controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The server acts as a centralized intermediary that handles all authentication and key management operations. This concentrates the complexity in a single centralized system rather than distributing it across multiple reader devices. The readers themselves remain relatively simple, containing only authentication credentials and playback functionality, while the complex authentication logic resides on the server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7653946B2Method and system for secure distribution of digital documents
Publication Date: 2010.01.26 STMICROELECTRONICS FRANCE
  • US7653946B2 patent drawing
  • US7653946B2 patent drawing

AI summary

The secure circulation of digital documents to be reproduced includes providing each user with a smart card containing identification information associated therewith, and identifying from a server connected to a digital data transmission network the smart card connected thereto. Information identifying a document to be played back is transmitted to the server from a terminal connected to the smart card. In response, a decryption key specific to the document to be reproduced is transmitted to the smart card for storing therein. The document to be played back is decrypted using an adapted reader connected to the smart card, and includes the stored decryption key for document playback with the reader. Information identifying the readers is inserted into the smart card, and fraudulent use of the smart card is determined according to the reader identification information stored in the smart card.