Session Integrity Key for Streaming Content Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital rights management systems for streaming content are vulnerable to manipulation, particularly when the content encryption key is not changed frequently enough, leading to potential attacks on encrypted content streams during transit between streaming servers and content clients.

Innovation Solution

A method is introduced where a master integrity key is encrypted and used to form a session integrity key, which is then employed to protect the integrity of the content stream, allowing for real-time verification of the stream's integrity using a one-way hash function, thereby preventing unauthorized manipulation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If the content encryption key is not changed frequently, then the system complexity is reduced, but the security against manipulation attacks deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity against manipulation attacks
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the security mechanism by introducing a separate integrity protection layer using session integrity keys, distinct from the content encryption keys. This allows the encryption key to remain stable while the integrity key changes frequently per session, resolving the contradiction between system complexity and security against manipulation attacks

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces session integrity keys as an intermediary mechanism between the content encryption key and the content stream verification. This intermediary allows frequent key changes for integrity protection without requiring frequent changes to the underlying encryption key, thus maintaining security while limiting system complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If integrity protection mechanisms are added to verify content stream authenticity, then the security is improved, but the device complexity increases

Engineering Contradiction:
Improvecontent stream authenticity verificationVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the integrity verification function into the existing DRM agent and digital rights management means. By combining these functions within existing components rather than adding separate systems, the patent achieves content stream authenticity verification while minimizing the increase in device complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The DRM agent and digital rights management means are designed to perform multiple functions: content decryption, rights verification, and integrity protection. This multi-functionality allows integrity protection to be added without proportionally increasing device complexity, as the same components handle multiple security tasks

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If frequent key changes are implemented, then the protection against attacks is improved, but the loss of time for key management increases

Engineering Contradiction:
Improveprotection against attacksVSAvoidtime for key management
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements dynamic key management where session integrity keys are generated and changed frequently for each content stream session, while the underlying content encryption keys remain stable. This dynamic approach provides strong protection against attacks while minimizing key management overhead by differentiating between session-level and content-level key changes

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8094825B2Integrity protection of streamed content
Publication Date: 2012.01.10 NOKIA CORP
  • US8094825B2 patent drawing
  • US8094825B2 patent drawing
  • US8094825B2 patent drawing

AI summary

The invention relates to a method, a system, an electronic device and a computer program for providing at least one content stream to an electronic device applying Digital Rights Management (DRM). In the method a master integrity key is obtained in a streaming node. An encrypted master integrity key is obtained in an electronic device. The encrypted master integrity key is decrypted in the electronic device. At least one session integrity key is formed in the streaming node and in the electronic device using at least the master integrity key and the integrity of at least one content stream is protected between the streaming node and the electronic device using the at least one session integrity key.