Software Component Revocation Lists for Secure Digital Media
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current digital media protection methods are passive and prone to being compromised, lacking flexibility and failing to address varying levels of risk posed by different computing components, which limits content owners' ability to control security and user flexibility.
Innovation Solution
A system that distributes and manages lists of computing components to be disabled, allowing for global or flexible revocation of components, with supplemental lists for specific media objects, enabling content owners to specify revocation policies and update protection levels, while using secure transmission and certification techniques to prevent unauthorized alteration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is used to protect digital media, then security against unauthorized copying is improved, but the system remains vulnerable to interception and decryption attacks
Solution Approach 1:
The system performs preliminary actions by disabling potentially compromised software components before digital media is decrypted and exposed to consumers. Revocation lists are distributed in advance to identify and disable components that may be vulnerable to interception, preventing security breaches before they can occur during media playback
Solution Approach 2:
The system applies preliminary anti-action by proactively disabling software components that could potentially be used for unauthorized interception or decryption. By maintaining and enforcing revocation lists that identify compromised components, the system counteracts potential security threats before they can compromise the encrypted media
2Device complexity
If passive protection systems are used, then implementation simplicity is maintained, but adaptability to varying risk levels and user needs deteriorates
Solution Approach 1:
The system introduces dynamics by implementing an active revocation mechanism that can adapt to changing security conditions. Revocation lists are distributed and updated dynamically to reflect current security threats, allowing the protection system to adapt its behavior based on identified compromised components while maintaining a relatively simple underlying architecture
Solution Approach 2:
The system applies segmentation by dividing the protection mechanism into separate revocation lists that can be distributed and enforced independently. This allows different levels of revocation to be applied to different media objects or users, providing adaptability without requiring complete system redesign
3Ease of operation
If maximum flexibility and power are provided in software products, then user satisfaction is improved, but security risks from compromised components increase
Solution Approach 1:
The system introduces an intermediary mechanism in the form of revocation lists that mediate between software components and digital media. The lists act as a filtering layer that allows legitimate components to operate with full flexibility while blocking potentially compromised components, thus maintaining user satisfaction without compromising security
Data Source
AI summary
A list of computing components to be disabled can be distributed through a computer readable medium to computing devices. A process on these computing devices can read the list and disable listed components. The components can be permanently disabled, or disabled for a limited purpose. A list or list update may be provided with a digital media object that specifies a more or less stringent revocation policy for that object. A media object may also specify a maximum age for the list. This allows owners of digital media to control the stringency of media protection for their property. The process that accesses the list may prompt updates to the list, informing users of component disabling, and prompt replacement of disabled components. Finally, the invention provides techniques for securely transmitting and storing the list to protect it from alteration by unauthorized entities.


