Streaming License Keys for Encrypted Content Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital content protection systems, such as Conditional Access (CA) and Digital Rights Management (DRM), face security challenges as they lose control over content security and distribution once encrypted content and license files are transmitted to and stored on playback devices, which are less secure than the content provider's trusted area.

Innovation Solution

The system securely delivers encrypted content from a content provider to a local device by storing encryption keys at the provider and streaming both the encrypted content and keys to the device over a secure channel, allowing the device to decrypt the content while maintaining control over key distribution and usage rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If encrypted content and license files are transmitted to and stored on playback devices, then content distribution and accessibility are improved, but security control is worsened

Engineering Contradiction:
Improvecontent distributionVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the content delivery process into two distinct phases: offline content distribution (improving accessibility) and online license validation (maintaining security control). The content is distributed to playback devices in advance, but the decryption capability is controlled through real-time license validation with the content provider, thus separating distribution from security enforcement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary validation mechanism where the playback device must communicate with the content provider's server to validate licenses before decrypting content. This intermediary step acts as a mediator that allows offline distribution while maintaining online security control, preventing unauthorized playback even when content is stored locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If content is delivered in real-time over Internet, then security control is improved, but bandwidth requirements and real-time demands increase

Engineering Contradiction:
Improvesecurity controlVSAvoidbandwidth requirements
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system performs preliminary content distribution offline to playback devices before actual playback occurs. This preliminary action allows the content to be cached locally, eliminating the need for high-bandwidth real-time streaming while maintaining security through subsequent online license validation. The heavy data transfer is done in advance when bandwidth constraints are less critical.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a dynamic content delivery model that adapts between offline and online modes. Content distribution occurs offline when possible to reduce bandwidth demands, while security validation dynamically switches to online mode when needed. This dynamic approach optimizes bandwidth usage by performing heavy data transfer only when necessary rather than continuously.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If encryption keys are stored with content on playback device, then content accessibility is improved, but security vulnerability increases

Engineering Contradiction:
Improvecontent accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption keys from the playback device and keeps them securely stored at the content provider's server. Instead of storing keys locally with the content, the system retrieves keys dynamically from the server during license validation. This extraction eliminates the security vulnerability of local key storage while maintaining content accessibility through controlled key delivery.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary key management system where the content provider's server acts as the intermediary between the content and the playback device. Encryption keys are not stored locally but are delivered through the intermediary server during license validation, adding a security layer that prevents unauthorized key access while enabling legitimate content playback.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7801820B2Real-time delivery of license for previously stored encrypted content
Publication Date: 2010.09.21 SONY GROUP CORP
  • US7801820B2 patent drawing
  • US7801820B2 patent drawing
  • US7801820B2 patent drawing

AI summary

Content is stored as ClearText by a content provider within a trusted area. Specific content is requested by an end user, preferably via a service provider, and the requested content is encrypted and then delivered over a secure communications channel to a home server system. While the encrypted content is stored on the home server system, the associated encryption keys are stored as a license with the content provider. When a playback device on the home server system is instructed to play back the encrypted content, the encrypted content is streamed from local storage within the home server system while the associated encrypted keys are simultaneously streamed from the content provider to the playback device.