Subscriber-Centric DRM Keys on Secure Element

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing device-centric digital rights management (DRM) system restricts content portability, as DRM keys are device-specific and not transferable, leading to inadequate security and limited content accessibility across different devices.

Innovation Solution

Implementing a subscriber-centric DRM system where DRM keys are stored on a secure element associated with the user, allowing seamless transfer and use across various devices, with the network carrier actively managing and distributing these keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If DRM keys are stored on device memory in a device-centric system, then device-specific content protection is achieved, but content portability is restricted and security is inadequate

Engineering Contradiction:
Improvecontent protectionVSAvoidcontent portability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

A secure element acts as an intermediary component between the device processor and DRM key storage. This secure element is a tamper-resistant hardware module that securely stores DRM keys and manages their distribution, preventing direct access to keys while enabling controlled usage across multiple devices. The secure element mediates between content protection requirements and portability needs by providing a trusted execution environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system separates DRM key management functions from the main device processor by implementing a dedicated secure element. This segmentation isolates sensitive cryptographic operations and key storage in a protected enclave, allowing the main device to focus on content delivery while the secure element handles security-critical functions independently and tamper-resistently.

Inventive Principle:
Principle #1Segmentation

2Reliability

If device-specific DRM keys are used, then content security on the specific device is improved, but the DRM keys cannot be transferred to other devices

Engineering Contradiction:
ImproveDRM key securityVSAvoidkey transferability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system transitions from static device-bound DRM keys to dynamic subscriber-centric keys managed by the secure element. DRM keys are now associated with subscriber identities rather than specific device hardware, allowing flexible reassignment and transfer between devices while maintaining security through the tamper-resistant secure element that controls key distribution and validation.

Inventive Principle:
Principle #15Dynamics

3Reliability

If a chain of certificates is used to verify device authenticity, then authorization is improved, but device complexity increases

Engineering Contradiction:
Improvedevice authorizationVSAvoidcertificate chain structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex certificate chain verification process is extracted from the device and relocated to the secure element and content service provider servers. The secure element contains pre-configured cryptographic credentials and performs local verification, while the content service provider handles centralized certificate management. This extraction simplifies the device architecture by removing the need for complex certificate chain processing in the main processor.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9524380B2Secure element-centric digital rights management
Publication Date: 2016.12.20 CELLCO PARTNERSHIP INC
  • US9524380B2 patent drawing
  • US9524380B2 patent drawing
  • US9524380B2 patent drawing

AI summary

The examples provided herein relate to digital rights management keys that allow for the presentation of content on output devices of a content presentation device. The examples describe subscriber-specific digital rights management keys that are provided to a subscriber by a mobile network operator instead of a device manufacturer. The digital rights management keys are associated with the subscriber account maintained by the mobile network operator. As a result, the mobile network operator provides the capability to transfer the digital rights management keys between multiple devices because the digital rights management keys are subscriber-specific instead of device-specific.