Software Validation via Revocation Lists for Secure Content Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content protection systems face challenges in ensuring the security and flexibility of user devices, as proprietary devices restrict users from switching between content providers, and there is a need to detect tampered or inappropriate software to prevent misuse.

Innovation Solution

A device and method that validate system and client software modules using revocation lists and digital signatures to ensure only authorized and intact software is used for decryption, allowing content providers to control the decryption process and prevent misuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If proprietary user devices are used to ensure high security, then security is improved, but user flexibility to change content providers deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiduser flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The user device is segmented into proprietary components (security module, decryption module) and standardized components (ECI interface). This allows the security-critical parts to remain proprietary while the interface layer becomes standardized, enabling users to switch content providers without changing the entire device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Embedded Common Interface (ECI) acts as an intermediary layer between the proprietary security module and the content provider. It provides a standardized interface that allows different content providers to communicate with the secure module without compromising security, thus enabling user flexibility while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If content providers control user device hardware and system software, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security-critical functions (cryptographic algorithms, security mechanisms) are extracted into a separate, dedicated security module. This isolates the complex security requirements from the rest of the system, allowing the main device to remain simpler while the security module handles all security-related complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security module is designed with specialized local quality - it contains only the necessary security functions and interfaces, while the rest of the device uses general-purpose components. This concentrates complexity only where needed for security, rather than distributing it throughout the entire device.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If client software is installed for multiple content providers, then adaptability is improved, but security risks increase due to potential tampering

Engineering Contradiction:
Improvemulti-provider supportVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The ECI interface acts as a trusted intermediary that all client software must communicate through. Even though multiple content providers can install their client software, all communications with the security module go through this standardized, controlled interface, preventing tampering and ensuring security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements validation mechanisms where the security module verifies the integrity of client software and the authenticity of requests through the ECI interface. This feedback loop ensures that only authorized, un tampered software can access content, maintaining security even with multiple providers.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2958039B1Device for decrypting and providing content of a provider and method for operating the device
Publication Date: 2019.12.18 VODAFONE GMBH
  • EP2958039B1 patent drawingFigure 1

AI summary

The invention relates to a device for decrypting protected content and for providing the decrypted content for playback. The device comprises one or more system software modules providing functions for facilitating the decryption of the protected content and a least one client software module assigned to a provider of protected content. The client software module is adapted to access functions of the system software modules in order to control the system software to decrypt the protected content of the provider. Moreover, the device is adapted to validate the system software and/or a further client software module and to prevent the decryption and/or provision of the protected content of the provider, if the system software and/or the further client software module are not validated successfully. The validation of the system software and/or a further client software module comprises a comparison of identification data of software modules of the system software and/or further client software modules loaded in a processor of the device and identification data included in a revocation list assigned to the provider. In addition to the device, the invention relates to a method for operating the device.