Federated DRM Certification with Trusted Systems and Layered Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital rights management systems face challenges in enabling secure playback of multimedia content while maintaining confidentiality of encryption keys, as content providers and player manufacturers often do not share keys, leading to insufficient access control and potential unauthorized use.
Innovation Solution
A federated digital rights management scheme using trusted systems and distributed registration entities that issue playback certifications, allowing content providers to manage access rights without direct communication with a central registration service, employing multiple encryption keys and secure hardware to protect content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single encryption key is used to protect content, then content security is improved, but access control flexibility deteriorates
Solution Approach 1:
The patent divides the single encryption key into multiple layers: a content encryption key for protecting the actual content, a playback certification key for controlling access rights, and a device-specific key for authentication. This segmentation allows each key to serve a specific function, providing both strong security and flexible access control as described in the embodiment where 'Layers of keys and protection policies can be used so a single encryption key alone is insufficient for the user to access the content'.
2Reliability
If content providers share encryption keys with player manufacturers, then access control is improved, but key confidentiality deteriorates
Solution Approach 1:
The patent introduces a trusted third party (registration entity) as an intermediary that manages key distribution without requiring direct key sharing between content providers and player manufacturers. The registration entity issues playback certifications to authorized devices, enabling access control while maintaining key confidentiality through the trusted intermediary model described in the embodiment where 'the registration entity also distributes trusted systems to content providers'.
3Reliability
If a centralized registration service is used to manage device registration, then access control is improved, but system complexity deteriorates
Solution Approach 1:
The patent extracts the key management function from a centralized registration service and distributes it to individual content providers through trusted systems. Each content provider receives a trusted system from the registration entity and can independently manage their own key distribution, eliminating the need for continuous centralized intervention while maintaining access control as described in the embodiment where 'content providers can issue content with playback certificates... without needing to exchange information with a central registration service'.
4Adaptability or versatility
If multiple encryption keys and playback certificates are implemented, then access control flexibility is improved, but device complexity deteriorates
Solution Approach 1:
The patent applies local quality by tailoring the key management approach to specific device types and usage scenarios. Different playback devices receive appropriate playback certificates based on their capabilities and the content protection requirements. The system issues customized certificates for different device classes (e.g., set-top boxes, televisions, mobile devices) as mentioned in the embodiment where 'the registration entity is configured to register each different class of device' and 'Different classes of devices can be registered with different sets of keys'.
Data Source
AI summary
Federated systems for issuing playback certifications granting access to technically protected content are described. One embodiment of the system includes a registration server connected to a network, a content server connected to the network and to a trusted system, a first device including a non-volatile memory that is connected to the network and a second device including a non-volatile memory that is connected to the network. In addition, the registration server is configured to provide the first device with a first set of activation information in a first format, the first device is configured to store the first set of activation information in non-volatile memory, the registration server is configured to provide the second device with a second set of activation information in a second format, and the second device is configured to store the second set of activation information in non-volatile memory.


