Virtualized Video Processing Server Headend DRM Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing video processing systems in content distribution networks (CDNs) lack the capability to receive and process encrypted video streams, perform decryption, and re-encrypt them using standard digital rights management (DRM) systems without requiring a DRM client in the headend, which complicates the integration and maintenance of DRM clients.

Innovation Solution

A virtualized video processing solution on off-the-shelf hardware in a data center headend that authenticates with a key server, exchanges public keys, generates and manages content keys, decrypts incoming encrypted streams, and re-encrypts them using standard DRM formats compatible with proprietary DRM clients, utilizing the CPIX standard for key exchange and DRM signaling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a DRM client is implemented in the headend to decrypt and re-encrypt video streams, then the capability to process encrypted streams is improved, but the device complexity and integration maintenance burden increase

Engineering Contradiction:
Improvecapability to process encrypted streamsVSAvoidintegration and maintenance complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a key server as an intermediary component that manages cryptographic keys and authentication. Instead of embedding a full DRM client in the headend, the system uses a key server to handle key exchange, authentication, and key distribution. This mediator approach allows the headend to process encrypted streams without directly implementing complex DRM client functionality, thereby reducing integration and maintenance complexity while maintaining the capability to handle encrypted content

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The key server is designed as a universal component that can serve multiple functions: authentication, key generation, key distribution, and session management. This multi-functional approach consolidates what would otherwise require separate DRM client components in the headend, reducing overall system complexity while enabling the processing of encrypted video streams through a single centralized service

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If standard DRM formats are used for re-encryption to ensure compatibility with proprietary DRM clients, then adaptability is improved, but the processing time and computational resources increase

Engineering Contradiction:
Improvecompatibility with proprietary DRM clientsVSAvoiddecryption and re-encryption processing time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing authentication and key exchange before the actual video stream processing. The key server authenticates the headend and provides cryptographic keys in advance, so that when encrypted streams need to be processed, the necessary credentials are already in place. This preliminary setup reduces the processing time during actual decryption and re-encryption operations, as the complex authentication and key generation steps have been completed beforehand

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs parameter changes in the form of different cryptographic algorithms and key types. The key server can provide different types of keys (symmetric, asymmetric, session keys) depending on the specific processing requirements. By dynamically selecting and switching between different cryptographic parameters and algorithms, the system optimizes the balance between compatibility with various DRM clients and processing efficiency, avoiding the need to use the most computationally intensive method for all operations

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12047498B2Translating protected content in a video processing server
Publication Date: 2024.07.23 ARRIS ENTERPRISES LLC
  • US12047498B2 patent drawing
  • US12047498B2 patent drawing
  • US12047498B2 patent drawing

AI summary

A method and system provide the ability to process video content on a headend. A video processing server authenticates with a key server and public keys are exchanged. The key server generates and places a content key into a document that is signed with the public key. A client on the video processing server receives the document, extracts the content key, and saves the content key to a database. The video content is encrypted using the content key and DRM signaling elements are added to a manifest. The encrypted video content and manifest are received in the head end, a key ID is extracted from the manifest and provided to the CPIX client to retrieve the content key from the CPIX document. The encrypted video content is decrypted using the content key resulting in clear content that is provided to a downstream packager that encrypts and repackages the content for transmission to recipients.