Usage Rights Object Binding Content Keys to Client Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional digital rights management (DRM) and conditional access systems (CAS) deliver content keys and usage rights information separately, lacking control over which client devices these keys work with and for how long, and are vulnerable to key leakage.

Innovation Solution

Integrating functionality into a system-on-chip (SOC) to bind usage rights within content keys, transforming actual keys into transmitted keys that can only be reversed by the intended client device, ensuring secure delivery and usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional DRM and CAS deliver content keys and usage rights information separately, then the system structure is simple, but the system lacks control over which client devices can use keys and for how long, and is vulnerable to key leakage

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines usage rights information and content keys into a single integrated structure called a usage rights object. This usage rights object contains both the content key and associated usage rights information (such as device identifiers, time limits, and usage conditions), allowing the system to control which client devices can use keys and for how long while maintaining system security without excessive complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The usage rights information is nested within the content key structure. The content key is embedded inside a usage rights object that also contains usage rights information. This nested structure allows the key to carry its own usage restrictions and device bindings, enabling controlled key distribution while preventing key leakage and unauthorized use

Inventive Principle:
Principle #7Nested doll (Nesting)

2Adaptability or versatility

If usage rights information is delivered separately from content keys, then the delivery mechanism is simple, but control over device-specific key usage and duration is lost

Engineering Contradiction:
Improvedevice control capabilityVSAvoidkey structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges usage rights information with content keys into a unified usage rights object structure. This structure includes the content key, device identifiers, usage time limits, and usage conditions all in one package, enabling the system to adapt to different client devices with specific control policies while managing complexity through a standardized object format

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If content keys are delivered without device binding, then the distribution process is simple, but key leakage and unintended distribution cannot be prevented

Engineering Contradiction:
Improvekey distribution securityVSAvoidtransmitted key complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The content key is nested within a usage rights object that also contains device-specific identifiers and usage restrictions. This nested structure ensures that the key is inherently bound to specific devices and usage conditions, preventing key leakage and unintended distribution while maintaining a manageable transmitted key structure through standardized object formatting

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS9485095B2Client control through content key format
Publication Date: 2016.11.01 CISCO TECHNOLOGY INC
  • US9485095B2 patent drawing
  • US9485095B2 patent drawing
  • US9485095B2 patent drawing

AI summary

Client control may be provided. First, content may be encrypted using an actual key. Then an identifier corresponding to a client device may be received and a transformation may be performed on the actual key and the identifier to produce a transmitted key. The transmitted key and the encrypted content may then be sent to the client device where it may be received. The client device may then receive the identifier corresponding to the client device and perform a reverse transformation on the transmitted key using the identifier to produce the actual key. The content may then be decrypted with the actual key.