|Title||Integration of non-repudiation services in mobile DRM scenarios|
|Publication Type||Journal Article|
|Year of Publication||2007|
|Authors||J. A. Onieva, J. Lopez, R. Roman, J. Zhou, and S. Gritzalis|
|Keywords||digital rights management, Mobile applications, Non-repudiation, Secure electronic commerce|
In any kind of electronic transaction, it is extremely important to assure that any of the parties involved can not deny their participation in the information exchange. This security property, which is called non-repudiation, becomes more important in Digital Rights Management (DRM) scenarios, where a consumer can freely access to certain contents but needs to obtain the proper Right Object (RO) from a vendor in order to process it. Any breach in this process could result on financial loss for any peer, thus it is necessary to provide a service that allows the creation of trusted evidence. Unfortunately, non-repudiation services has not been included so far in DRM specifications due to practical issues and the type of content distributed. In this paper we analyze how to allow the integration of non-repudiation services to a DRM framework, providing a set of protocols that allows the right objects acquisition to be undeniable, alongside with a proof-of-concept implementation and a validation process.
Integration of non-repudiation services in mobile DRM scenarios