首页> 外文会议>Workshop on New security paradigms >Support for multi-level security policies in DRM architectures
【24h】

Support for multi-level security policies in DRM architectures

机译:支持DRM架构中的多级安全策略

获取原文

摘要

Digital rights management systems allow copyrighted content to be commercialized in digital format without the risk of revenue loss due to piracy. Making such systems secure is no easy task, given that content needs to be protected while accessed through electronic devices in the hands of potentially malicious end-users; in this context, intrusion tolerance becomes a very useful system property. In this paper we point out a limitation shared by all current DRM architectures, namely their weakness in reacting to possible device compromise and confining the damage caused by such a compromise. As a solution, we propose a paradigm shift - moving from the original DRM system model where all devices are equally trustworthy and have discretionary control over all protected content, to a new model where information flow is controlled through a multi-level security policy that differentiates between devices based on their tamper-resistance properties. We show that besides improved intrusion-tolerance, supporting such policies has other advantages, such as the ability to define more flexible business models for supplying content. We also show that for a given DRM architecture, the type authentication protocol used when accepting new devices in the system has a big impact on how well multi-level security policies can be supported, and that a number of protocols currently being considered are not very well suited for this job.
机译:数字版权管理系统允许以数字格式商业化的受版权保护内容,而不会因盗版而导致收入损失的风险。鉴于在通过潜在恶意最终用户手中访问的电子设备访问时需要保护这些内容,使此类系统安全不易任务;在这种情况下,入侵公差成为一个非常有用的系统属性。在本文中,我们指出了所有当前DRM架构共享的限制,即他们对可能的设备妥协并限制由这种妥协造成的损害的弱点。作为解决方案,我们提出了一种范式转换 - 从原始DRM系统模型移动,所有设备都同样可靠,并对所有受保护内容的酌情控制,以通过区别的多级安全策略控制信息流的新模型基于其篡改性能的设备之间。我们表明,除了改进的入侵容忍外,支持此类策略还具有其他优点,例如定义更灵活的商业模型来供应内容的能力。我们还表明,对于给定的DRM架构,在系统中接受新设备时使用的类型认证协议对如何支持多级安全策略如何支持,并且当前被视为的许多协议不是很好适合这份工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号