Compliance and Robustness

Compliance and Robustness

Compliance and Robustness, sometimes abbreviated as C&R, refers to the legal structure or regime underlying a Digital Rights Management (DRM) system. In many cases, the C&R regime for a given DRM is provided by the same company that sells the DRM solution. For example, RealNetworks Helix or Microsoft Windows Media DRM.

However, for standardised DRM systems, it is fairly common for a separate body to be established to run the C&R regime.

Contents

Elements

C&R Body

The legal entity that establishes and maintains the regime. Usually this will be a joint venture or forum with representation from multiple companies, structured in such as way as to avoid accusations of antitrust violations. The nature of the business is that such bodies will generally be composed of manufacturers and content owners, with little or no direct representation from consumer advocates.

Trust Model

The C&R body is responbile for ensuring a chain of trust, such that the original content provider is sufficiently satisfied that their content will remain adequately secure throughout all future links in the chain. This may include export of content from one DRM system to another.

To meet this requirement, it is normal that any device planning to receive DRMed content is required to validate that it meets the C&R requirements, and this is usually done using a device certificate of some kind. The issuance of such certificates is the stamp of approval for both the manufacturer and the device.

If two devices can verify that they both have trusted certificates, they can then reasonably expect that content passed between them will remain secure.

Compliance Rules

In many cases there will be gaps, ambiguities or options left open in a DRM technical specification. The C&R regime must clarify exactly how a compliant device is to behave in these cases. For example, a compliance rule may define which other types of interfaces are acceptable on a device, something that the technical specification itself will never do.

Robustness Rules

The most controversial aspect of C&R is the agreement on how to ensure that a device is sufficiently robust at resisting attacks. These rules may require that certain elements are implemented only in hardware, or run on secure CPUs, or that the code must not be available as open source. Manufacturers then have to satisfy the C&R body that they meet this requirement before they are granted access to the certificates needed to establish their products as trusted.

"Hook IP"

One particular trick that is often used is to include some patented technology, often as part of the trust establishment mechanism. This means that anyone wanting to implement the DRM in a way that will work with others is forced to license these patents. A condition of obtaining such a license is to follow the rules of the C&R regime itself. Thus a C&R body has a 20-year window to pursue legal measures against a "rogue" implementation on the grounds of patent violation, rather than having to rely on a DMCA-style regulation provided by the relevant government. The need to license hook IP patents also impacts anyone thinking of building a product covered by the GPL.

One well-known example of a system employing such Hook IP is the DVB Common Scrambling Algorithm DVB-CSA, which though standardised by ETSI, includes secret patented elements that are only licensed to approved Conditional access systems vendors who agree to maintain the secrecy and integrity of the algorithm in their chip designs.

Examples

  • OMA DRM is governed by the CMLA C&R regime
  • DTCP-IP is governed by the DTLA C&R regime

Wikimedia Foundation. 2010.

Игры ⚽ Нужно сделать НИР?

Look at other dictionaries:

  • Verification and validation — IV V redirects here. For NASA s IV V Facility, see Independent Verification and Validation Facility. Verification and validation is the process of checking that a product, service, or system meets specifications and that it fulfills its intended… …   Wikipedia

  • Verification and Validation — Verification Validation is the process of checking that a product, service, or system meets specifications and that it fulfils its intended purpose. These are critical components of a quality management system such as ISO… …   Wikipedia

  • Independent software verification and validation — ISVV stands for Independent Software Verification and Validation. ISVV is targeted at safety critical software systems and aims to increase the quality of software products, thereby reducing risks and costs through the operational life of the… …   Wikipedia

  • Broadcast Protection Discussion Group — The Broadcast Protection Discussion Group (BPDG) is a working group of content providers, television broadcasters, consumer electronics manufacturers, information technology companies, interested individuals and consumer activists. The group was… …   Wikipedia

  • DVB-CPCM — DVB Content Protection Copy Management often abbreviated to DVB CPCM or CPCM is a digital rights management standard being developed by the DVB Project. Its main application is interoperable rights management of European digital television,… …   Wikipedia

  • Digital rights management — (DRM) is a term for access control technologies that are used by hardware manufacturers, publishers, copyright holders and individuals to limit the use of digital content and devices. The term is used to describe any technology that inhibits uses …   Wikipedia

  • Antipsychotic — Advertisement for Thorazine (chlorpromazine) from the 1950s[1] An antipsychotic (or neuroleptic) is a tranquilizing psychiatric medication primarily used to manage psychosis (including delusions or hallucinations, as well as disordered tho …   Wikipedia

  • Forest Stewardship Council — Infobox Non profit Non profit name = Forest Stewardship Council Non profit founded date = 1993 founder = location = Bonn, Germany origins = key people = Greenpeace, FERN, World Wide Fund for Nature area served = Global focus = Sustainable… …   Wikipedia

  • ATSC tuner — Multiple MPEG programs are combined then sent to a transmitting antenna. In the US broadcast digital TV system, an ATSC receiver then decodes the TS and displays it on a TV. An ATSC (Advanced Television Systems Committee) tuner, often called an… …   Wikipedia

  • The Nature of Rationality — is an exploration of practical rationality written by Robert Nozick and published in 1993. It views human rationality as an evolutionary adaptation. Its delimited purpose and function may be responsible for biases and blind spots, possibly… …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”