Terminal Device Title Key Reconstruction for AACS Signature Leakage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The use of Advanced Access Content System (AACS) for copyright protection in next-generation SD memory cards is compromised due to the risk of signature key leakage since the content server is connected to a network, allowing malicious use of unauthorized content.
Innovation Solution
A terminal device is designed with a read unit to read encrypted content and a content signature, a title key reconstruction unit to generate a reconstructed title key using the content signature, and a playback unit to decrypt the content, ensuring that even if a leaked signature key is used, the unauthorized content cannot be played back by preventing the reconstruction of the correct title key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the content server is connected to a network to distribute content, then content distribution and access are improved, but the risk of signature key leakage increases
Solution Approach 1:
The patent introduces a signature verification device as an intermediary component that operates independently from the content server. This device verifies content signatures using a verification key stored in a secure area of the recording medium device, rather than relying on the network-connected content server for signature verification. This intermediary approach allows the system to maintain network connectivity for content distribution while separating the security verification function to prevent signature key leakage through the network.
Solution Approach 2:
The patent extracts the signature verification function from the content server and places it in the recording medium device. Specifically, the verification key is stored in a secure area of the recording medium device (such as an SD card), which is independent from the content server's network connection. This extraction ensures that even if the content server is compromised or the network is attacked, the signature verification capability remains secure and functional.
2Productivity
If the content signature is generated by a network-connected content server, then content distribution efficiency is improved, but the risk of malicious use of leaked signature keys increases
Solution Approach 1:
The patent implements preliminary verification of content signatures before content playback. The verification key is pre-stored in the secure area of the recording medium device, and the signature verification is performed automatically when content is accessed. This preliminary action prevents malicious content from being played back by verifying the signature integrity before the content is decrypted and displayed, thereby blocking harmful factors before they can affect the user.
Solution Approach 2:
The verification device acts as an intermediary that stands between the content server and the playback device. It receives content signatures from the content server, verifies them using the stored verification key, and only allows content playback if the signature is valid. This intermediary layer prevents leaked or malicious signature keys from directly enabling unauthorized content playback, as the verification process detects and blocks such attempts.
3Ease of operation
If the title key is stored in the recording medium device, then content playback capability is improved, but the risk of unauthorized key access increases
Solution Approach 1:
The patent introduces a secure area within the recording medium device as a protected intermediary space for storing the title key. This secure area is accessed only through authenticated operations, creating a barrier between the title key and unauthorized access. The secure area acts as a mediator that allows legitimate playback operations to access the key while blocking unauthorized attempts, thus maintaining both playback capability and key protection.
Solution Approach 2:
The patent applies local quality protection by creating a specialized secure area within the recording medium device with enhanced security properties. This secure area has different access characteristics compared to the rest of the device memory, providing localized protection for the title key. The secure area can be accessed only through specific authenticated operations, while the rest of the device maintains normal operational characteristics, thus balancing accessibility and security.
Data Source
AI summary
The terminal device 600 comprises: a read unit configured to read encrypted content and a content signature from a regular region of a recording medium device 700, and to read a converted title key from an authorized region of the recording medium device 700, the converted title key having been converted from a title key with use of a content signature generated by an authorized signature device 500; a title key reconstruction unit configured to generate a reconstructed title key by reversely converting the converted title key with use of the content signature read by the read unit; and a playback unit configured to decrypt the encrypted content with use of the reconstructed title key to obtain decrypted content, and to play back the decrypted content.


