Secure Watermarking via Encrypted Metadata Binding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the pay media environment, digital media content is vulnerable to unauthorized copying after being descrambled, as the application software used for decryption and watermarking is untrusted and can bypass or modify the watermarking process, compromising the security of the copyright information.
Innovation Solution
A method and system where encrypted digital media content is processed through a secure environment that separates the application software from sensitive metadata, using a transport key to decrypt and authenticate the content key and initialization vector, ensuring that watermarking occurs within a trustworthy environment, binding the watermarking metadata with the content key and initialization vector for secure embedding.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If application software performs decryption and watermarking on unprotected content, then the watermarking process is flexible and accessible, but the security of copyright information is compromised as the software can bypass or modify the watermarking process
Solution Approach 1:
The system separates the watermarking process into two independent segments: (1) embedding a first watermark in the encrypted content before distribution, and (2) embedding a second watermark in the decrypted content after playback. This segmentation allows each watermark to serve different security functions - the first provides pre-decryption protection while the second provides post-decryption tracking, together resolving the contradiction between accessibility and security.
Solution Approach 2:
The system performs preliminary watermarking by embedding a first watermark in the encrypted content before it reaches the user's application software. This preliminary action ensures that even if the application software is compromised and modifies or bypasses the decryption process, the first watermark remains intact and provides evidence of the original content source and authorization.
2Reliability
If encrypted content is watermarked before decryption, then copyright protection is maintained during transmission, but the watermark cannot be applied to the actual playable content
Solution Approach 1:
The watermarking process is divided into two segments applied at different stages: first watermark embedding in encrypted content for transmission protection, and second watermark embedding in decrypted content for playback tracking. This segmentation resolves the contradiction by ensuring both transmission security and content-specific adaptability are achieved through complementary watermarking approaches.
Solution Approach 2:
The system uses an intermediary approach by embedding reference information in the first watermark that can be used to generate or verify the second watermark. This intermediary mechanism allows the watermarks at different stages to be connected, ensuring that the watermark protection is consistent across both encrypted transmission and decrypted playback phases.
3Ease of manufacture
If a single watermark is embedded in decrypted content, then the watermarking is simple to implement, but it can be easily bypassed or modified by untrusted application software
Solution Approach 1:
The single watermark is segmented into two distinct watermarks applied at different stages of the content lifecycle. The first watermark is embedded in encrypted content requiring minimal processing, while the second watermark is embedded in decrypted content for playback tracking. This segmentation maintains implementation simplicity while dramatically improving security against bypass or modification by untrusted software.
Solution Approach 2:
The first watermark serves as a preliminary anti-action by establishing copyright protection before the content is decrypted and potentially modified by untrusted application software. This preemptive watermarking creates a security layer that cannot be bypassed, as it exists in the encrypted content itself, while the second watermark provides additional protection for the decrypted content.
Data Source
Figure 1~2
Figure 3
AI summary
The present invention refers to a method and a system (20) for watermarking digital media content (1) received by application software (APP) in a form of at least one encrypted sample (15). The digital media content (1) is related to metadata (10) assigned to each sample (15). The latter is encrypted by means of a sample key (Kc'). The metadata (10) comprises first data (11), second data (12) and a digital signature (13) resulting from the signature of said first and second data. The first data (11) comprises at least a content key (Kc) and watermarking metadata (WM) and at least said first data (11) is encrypted by a transport key (KT). The second data (12) comprises an initialization vector (IV) so that the content key (Kc) and the initialization vector (IV) form a unique pair of cryptographic data equivalent to the sample key (Kc'). The application software (APP) communicates with a secure environment (30) in charge of handling said metadata (10). The watermarking of the digital media content (1) is performed by the following steps: - instructing the application software (APP) to extract the metadata (10) from the digital media content (1) before transmitting the metadata (10) to the secure environment (30), - decrypting at least a part of the first data (11) by means of the transport key (KT), - verifying the authentication of said digitally signed data (11, 12) and in the case of positive outcome, then transmitting the content key (Kc) and the initialization vector (IV) to a descrambler (37) and transmitting the watermarking metadata (WM) to a watermarking unit (39), - transmitting the digital media content (1) to the descrambler (37) for descrambling each sample (15) by means of said pair of cryptographic data, - transmitting each descrambled sample (15') to the watermarking unit (39) for digitally marking it by means of at least said watermarking metadata, - transmitting the sample (15', 15") from the watermarking unit (39) to the application software (APP) or to a secure media path for rendering purposes.