Streamlined Digital Rights Management via Session Grants
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital rights management (DRM) systems cause delays in content delivery due to the need for specialized client software and servers to perform authentication and entitlement checks, leading to user frustration and inefficiencies.
Innovation Solution
Implementing an authentication server that establishes an authenticated session with a client device, which then uses session grants and security mechanisms to authorize access to digital content, reducing the need for repeated authentication and entitlement checks by integrating DRM licensing into the content delivery system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If specialized DRM client software and servers are used to perform authentication and entitlement checks, then security is improved, but content delivery speed deteriorates due to processing delays
Solution Approach 1:
The system performs authentication and entitlement checks in advance by embedding DRM information in content manifests before delivery. Client systems pre-resolve DRM protection forms and obtain licensing information ahead of actual content playback, eliminating real-time authentication delays while maintaining security through pre-validated session grants
Solution Approach 2:
The patent extracts DRM authentication functionality from the content server processing chain by implementing a separate DRM information embedding system. The authentication logic is moved to client-side manifest processing, allowing content servers to deliver content without performing DRM checks, thus improving delivery speed while security is handled independently through pre-embedded licensing data
2Reliability
If content servers perform digital rights management functions, then security control is improved, but content delivery efficiency deteriorates due to additional processing time
Solution Approach 1:
The patent extracts DRM management functions from content servers by implementing a separate DRM information embedding system in manifests. Content servers only handle content delivery while DRM authentication is performed independently through pre-embedded licensing information in manifests, allowing parallel processing and eliminating sequential delays
Solution Approach 2:
The patent introduces manifests as an intermediary layer between content servers and client systems. Manifests contain pre-processed DRM information that mediates authentication, allowing content servers to deliver content without direct DRM processing while maintaining security through the manifest-based licensing system
3Reliability
If separate license servers are used for DRM licensing, then security is improved, but system complexity increases and delivery delays occur
Solution Approach 1:
The patent merges DRM licensing information directly into content manifests, combining what were previously separate DRM server and manifest systems into a unified structure. This integration eliminates the need for separate license server communications while maintaining security through embedded licensing data, reducing both system complexity and delivery delays
Data Source
AI summary
A streamlined workflow for digital rights management (DRM) licensing for content such as media assets is achieved via an authentication server establishing an authenticated session that is referenced by other processes, whereby a content grant may include a key to desired encrypted content with a portion of the content or content meta-data. The authentication server verifies the user's identity and provides a session grant including a session security mechanism, such as a token, session key, or negotiated secret. The session grant may be used to obtain a content authorization from a content router. The content authorization includes an address at which the content may be found and may be decorated with security mechanisms. The session grant and/or content authorization may include an entitlement record reflecting the user's entitlements to access content. The session grant and/or content authorization may be used to obtain a content grant from a content server.


