Subscriber-Centric DRM Keys on Secure Element
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing device-centric digital rights management (DRM) system restricts content portability, as DRM keys are device-specific and not transferable, leading to inadequate security and limited content accessibility across different devices.
Innovation Solution
Implementing a subscriber-centric DRM system where DRM keys are stored on a secure element associated with the user, allowing seamless transfer and use across various devices, with the network carrier actively managing and distributing these keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If DRM keys are stored on device memory in a device-centric system, then device-specific content protection is achieved, but content portability is restricted and security is inadequate
Solution Approach 1:
A secure element acts as an intermediary component between the device processor and DRM key storage. This secure element is a tamper-resistant hardware module that securely stores DRM keys and manages their distribution, preventing direct access to keys while enabling controlled usage across multiple devices. The secure element mediates between content protection requirements and portability needs by providing a trusted execution environment.
Solution Approach 2:
The system separates DRM key management functions from the main device processor by implementing a dedicated secure element. This segmentation isolates sensitive cryptographic operations and key storage in a protected enclave, allowing the main device to focus on content delivery while the secure element handles security-critical functions independently and tamper-resistently.
2Reliability
If device-specific DRM keys are used, then content security on the specific device is improved, but the DRM keys cannot be transferred to other devices
Solution Approach 1:
The system transitions from static device-bound DRM keys to dynamic subscriber-centric keys managed by the secure element. DRM keys are now associated with subscriber identities rather than specific device hardware, allowing flexible reassignment and transfer between devices while maintaining security through the tamper-resistant secure element that controls key distribution and validation.
3Reliability
If a chain of certificates is used to verify device authenticity, then authorization is improved, but device complexity increases
Solution Approach 1:
The complex certificate chain verification process is extracted from the device and relocated to the secure element and content service provider servers. The secure element contains pre-configured cryptographic credentials and performs local verification, while the content service provider handles centralized certificate management. This extraction simplifies the device architecture by removing the need for complex certificate chain processing in the main processor.
Data Source
AI summary
The examples provided herein relate to digital rights management keys that allow for the presentation of content on output devices of a content presentation device. The examples describe subscriber-specific digital rights management keys that are provided to a subscriber by a mobile network operator instead of a device manufacturer. The digital rights management keys are associated with the subscriber account maintained by the mobile network operator. As a result, the mobile network operator provides the capability to transfer the digital rights management keys between multiple devices because the digital rights management keys are subscriber-specific instead of device-specific.


