Traceable Digital Data Broadcasting System for White-Box Attack Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital rights management systems face challenges in protecting against white-box attacks, where pirates analyze and replicate decryption software, and combinatorial traitor tracing methods require a large volume of headers for broadcasting.

Innovation Solution

A method and system using the GGM construction with pseudo-random functions g0 and g1, where users obtain a derived value Kr by composing these functions based on an input parameter r, with a master value S kept secret, allowing for tracing of illicit redistribution and resistance to white-box attacks with reduced header volume.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If combinatorial traitor tracing methods are used to trace illicit redistribution, then the ability to identify traitors is improved, but the volume of headers that must be broadcast increases significantly

Engineering Contradiction:
Improvetraitor tracing capabilityVSAvoidheader volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the traitor tracing functionality by separating the identification of traitors from the broadcast data. Instead of embedding traitor identification information in every broadcast header, the system uses a centralized tracing authority that receives anonymous identification data and independently identifies traitors, thus eliminating the need for large header volumes while maintaining tracing capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary tracing authority that acts as a mediator between the broadcast system and traitor identification. This intermediary receives anonymous device identifiers from the broadcast and performs the actual traitor identification separately, allowing the broadcast system to maintain minimal headers while the intermediary handles the complex tracing analysis

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If decryption software is made accessible to users, then the ease of operation is improved, but the vulnerability to white-box attacks increases

Engineering Contradiction:
Improvesoftware accessibilityVSAvoidwhite-box attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the secret key material from the decryption software and stores it securely in a trusted platform module (TPM) or secure element within the user's device. The software itself contains only public key information and encryption algorithms, making it accessible and operable without exposing sensitive cryptographic material, thus maintaining ease of operation while resisting white-box attacks

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs disposable or frequently rotating encryption keys that are generated and destroyed in controlled cycles. Each user session uses temporary key material that is discarded after use, preventing attackers from recovering long-term secret keys even if they successfully conduct white-box attacks on the software, thus maintaining software accessibility while limiting attack impact

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS8774408B2Traceable method and system for broadcasting digital data
Publication Date: 2014.07.08 ORANGE SA
  • US8774408B2 patent drawing
  • US8774408B2 patent drawing
  • US8774408B2 patent drawing

AI summary

A method and system for a user to obtain a derived value Kr of m bits, in which, given two pseudo-random functions g0 and g1 from m bits to m bits, said user obtains, on the basis of an input parameter consisting of a word r of n bits, a derived value Kr=gr<sub2>n</sub2>∘ . . . gr<sub2>2</sub2>∘gr<sub2>1 </sub2>(S), where, for i=1, . . . , n, gr<sub2>i</sub2>=g0 if ri=0, and gr<sub2>i</sub2>=g1 if ri=1, and where S is a master value of m bits which is not disclosed to said user. This method comprises the following steps: a search is conducted, from among a set of words of m bits Uj, where j=1, . . . , p, recorded in a table TU and equal to Uj=gv<sub2>l(j)</sub2><sup2>(j)</sup2>∘ . . . gv<sub2>2</sub2><sup2>(j)</sup2>∘gv<sub2>1</sub2><sup2>(j) </sup2>(S), where, for i=1, . . . , l(j), the indices vi(j) are predetermined bits, for a word Uσ equal to Uσ=gr<sub2>l(σ)</sub2>∘ . . . gr<sub2>2</sub2>∘gr<sub2>1 </sub2>(S); said derived value Kr is thereafter obtained by calculating Kr=gr<sub2>n</sub2>∘ . . . gr<sub2>l(σ)+1 </sub2>(Uσ).Application to the encryption/decryption of pay-per-use digital contents, and to authentication.