Secure Watermarking via Encrypted Metadata Binding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In the pay media environment, digital media content is vulnerable to unauthorized copying after being descrambled, as the application software used for decryption and watermarking is untrusted and can bypass or modify the watermarking process, compromising the security of the copyright information.

Innovation Solution

A method and system where encrypted digital media content is processed through a secure environment that separates the application software from sensitive metadata, using a transport key to decrypt and authenticate the content key and initialization vector, ensuring that watermarking occurs within a trustworthy environment, binding the watermarking metadata with the content key and initialization vector for secure embedding.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If application software performs decryption and watermarking on unprotected content, then the watermarking process is flexible and accessible, but the security of copyright information is compromised as the software can bypass or modify the watermarking process

Engineering Contradiction:
Improveaccessibility of watermarking processVSAvoidsecurity of copyright information
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system separates the watermarking process into two independent segments: (1) embedding a first watermark in the encrypted content before distribution, and (2) embedding a second watermark in the decrypted content after playback. This segmentation allows each watermark to serve different security functions - the first provides pre-decryption protection while the second provides post-decryption tracking, together resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary watermarking by embedding a first watermark in the encrypted content before it reaches the user's application software. This preliminary action ensures that even if the application software is compromised and modifies or bypasses the decryption process, the first watermark remains intact and provides evidence of the original content source and authorization.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encrypted content is watermarked before decryption, then copyright protection is maintained during transmission, but the watermark cannot be applied to the actual playable content

Engineering Contradiction:
Improvecopyright protection during transmissionVSAvoidwatermark applicability to playable content
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The watermarking process is divided into two segments applied at different stages: first watermark embedding in encrypted content for transmission protection, and second watermark embedding in decrypted content for playback tracking. This segmentation resolves the contradiction by ensuring both transmission security and content-specific adaptability are achieved through complementary watermarking approaches.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses an intermediary approach by embedding reference information in the first watermark that can be used to generate or verify the second watermark. This intermediary mechanism allows the watermarks at different stages to be connected, ensuring that the watermark protection is consistent across both encrypted transmission and decrypted playback phases.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If a single watermark is embedded in decrypted content, then the watermarking is simple to implement, but it can be easily bypassed or modified by untrusted application software

Engineering Contradiction:
Improvesimplicity of watermarking implementationVSAvoidsecurity against bypass or modification
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The single watermark is segmented into two distinct watermarks applied at different stages of the content lifecycle. The first watermark is embedded in encrypted content requiring minimal processing, while the second watermark is embedded in decrypted content for playback tracking. This segmentation maintains implementation simplicity while dramatically improving security against bypass or modification by untrusted software.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first watermark serves as a preliminary anti-action by establishing copyright protection before the content is decrypted and potentially modified by untrusted application software. This preemptive watermarking creates a security layer that cannot be bypassed, as it exists in the encrypted content itself, while the second watermark provides additional protection for the decrypted content.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP2989803B1Method for watermarking media content and system for implementing this method
Publication Date: 2019.03.27 NAGRAVISION SA
  • EP2989803B1 patent drawingFigure 1~2
  • EP2989803B1 patent drawingFigure 3

AI summary

The present invention refers to a method and a system (20) for watermarking digital media content (1) received by application software (APP) in a form of at least one encrypted sample (15). The digital media content (1) is related to metadata (10) assigned to each sample (15). The latter is encrypted by means of a sample key (Kc'). The metadata (10) comprises first data (11), second data (12) and a digital signature (13) resulting from the signature of said first and second data. The first data (11) comprises at least a content key (Kc) and watermarking metadata (WM) and at least said first data (11) is encrypted by a transport key (KT). The second data (12) comprises an initialization vector (IV) so that the content key (Kc) and the initialization vector (IV) form a unique pair of cryptographic data equivalent to the sample key (Kc'). The application software (APP) communicates with a secure environment (30) in charge of handling said metadata (10). The watermarking of the digital media content (1) is performed by the following steps: - instructing the application software (APP) to extract the metadata (10) from the digital media content (1) before transmitting the metadata (10) to the secure environment (30), - decrypting at least a part of the first data (11) by means of the transport key (KT), - verifying the authentication of said digitally signed data (11, 12) and in the case of positive outcome, then transmitting the content key (Kc) and the initialization vector (IV) to a descrambler (37) and transmitting the watermarking metadata (WM) to a watermarking unit (39), - transmitting the digital media content (1) to the descrambler (37) for descrambling each sample (15) by means of said pair of cryptographic data, - transmitting each descrambled sample (15') to the watermarking unit (39) for digitally marking it by means of at least said watermarking metadata, - transmitting the sample (15', 15") from the watermarking unit (39) to the application software (APP) or to a secure media path for rendering purposes.