Information Processing Device Application Signature Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In systems like HbbTV, the XML-AIT used for managing application lifecycles is vulnerable to falsification by malicious third parties, potentially leading users to download unintended applications, and existing solutions require significant effort to prevent unauthorized functions, compromising application reliability.

Innovation Solution

An information processing apparatus and method that calculates and compares representative values for applications, using mode information to control available functions and determine if electronic signature validation is required, enhancing application reliability by validating XML signatures and hash values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If XML-AIT is used to manage application lifecycles over the Internet, then application delivery flexibility is improved, but security against falsification deteriorates

Engineering Contradiction:
Improveapplication delivery flexibilityVSAvoidsecurity against falsification
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-calculating and embedding the hash value of the application into the XML-AIT before the application is delivered to the terminal. This allows the terminal to verify the application's integrity upon receipt by comparing the calculated hash with the embedded hash, preventing falsification attacks while maintaining the flexibility of XML-AIT-based application delivery.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses the hash value as an intermediary element that mediates between the application content and the XML-AIT metadata. This intermediary enables secure verification without requiring direct cryptographic signatures or complex authentication mechanisms, thus maintaining system flexibility while improving security against falsification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If application functions are restricted to prevent unauthorized usage, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling the terminal device to autonomously verify application integrity through hash comparison and automatically control function availability based on verification results. This eliminates the need for complex centralized authentication systems or manual security configurations, achieving enhanced security while minimizing device complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent uses parameter changes by modifying the XML-AIT structure to include hash value information and application mode descriptors. These parameter additions enable automated security verification and function control without requiring fundamental changes to the system architecture, thus improving security while keeping complexity manageable.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2797023B1Information processing device, server device, information processing method, server processing method, and program
Publication Date: 2022.04.06 SATURN LICENSING LLC
  • EP2797023B1 patent drawingFigure 1
  • EP2797023B1 patent drawingFigure 2
  • EP2797023B1 patent drawingFigure 3

AI summary

[Object] To improve the reliability of an application processed together with broadcast content. [Solving Means] An application controller of an information processing apparatus acquires an application information table to which an electronic signature is attached and in which location information necessary for acquiring an application processed together with broadcast content is stored, and validates the electronic signature. The application controller can acquire the application based on the location information in a case of succeeding at least in the validation.