Temporary Trust Token for Untrusted Media Renderer WAN Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies do not enable the direct push of media content from network-based media services to digital media renderers over a Wide Area Network (WAN), specifically failing to establish a trusted relationship for untrusted devices, which limits media sharing across different networks and devices.
Innovation Solution
A method is introduced where a Digital Media Controller (DMC) with a trusted relationship to a network-based media service obtains a certificate from an untrusted Digital Media Renderer (DMR), generates a temporary token, and sends it to the media service to pre-authorize the DMR for a temporary media session, establishing a secure Uniform Resource Identifier (URI) for media content delivery.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a network-based media service allows media content sharing to untrusted devices over a WAN, then media sharing capability and adaptability are improved, but content protection and security are compromised
Solution Approach 1:
The system performs preliminary authentication and authorization actions before media content delivery. The media service authenticates the user account, determines device compatibility, and authorizes the untrusted device before allowing content sharing, thereby ensuring content protection is established in advance
Solution Approach 2:
The trusted device acts as an intermediary between the untrusted device and the media service. It obtains authentication information from the media service and transmits it to the untrusted device, enabling secure content sharing without requiring the untrusted device to have direct trust relationship with the media service
2Reliability
If existing service architectures require all devices to be provisioned, authenticated, and authorized by the network-based media service, then content protection is maintained, but device complexity and ease of operation are worsened
Solution Approach 1:
The trusted device serves as a mediator that handles the complex authentication and authorization processes. It obtains authentication information from the media service and provides it to the untrusted device, shielding users from complex authentication procedures while maintaining security
Solution Approach 2:
The trusted device performs preliminary authentication with the media service before the untrusted device needs to access content. This pre-established authentication relationship simplifies the overall process for end users while maintaining content protection
3Reliability
If DLNA and UPnP enable media sharing only within the same LAN, then network security is maintained, but adaptability and media sharing capability are limited
Solution Approach 1:
The trusted device acts as an intermediary that enables secure WAN-based media sharing while maintaining security protocols. It establishes secure communication channels and manages authentication, allowing DLNA/UPnP functionality to extend beyond LAN boundaries without compromising network security
Solution Approach 2:
The system performs preliminary authentication and security establishment before enabling WAN-based media sharing. The trusted device authenticates with the media service and establishes secure connections in advance, allowing untrusted devices to access content over WAN while maintaining network security
Data Source
AI summary
Systems and methods related to establishing a temporary trusted relationship between a network-based media service and a device that does not have a trusted relationship with the network-based media service are disclosed. In one embodiment, a method of operation of a first device having a trusted relationship with a network-based media service to establish a temporary trusted relationship between the network-based media service and a second device that does not have a trusted relationship with the network-based media service is provided. In one embodiment, the method of operation of the first device includes obtaining a certificate of the second device, generating a temporary token for the second device based on the certificate of the second device, and sending the temporary token for the second device to a server that provides the network-based media service to thereby pre-authorize the second device for temporary media service.


