LinuxDevices: Digital Rights Management Issues in Real-Time and Safety/Mission Critical Systems

Oct 14, 2002, 09:00 (4 Talkback[s])
"Digital Rights Management Passport (DRMP) technology (TCPA from Intel and Palladium from Microsoft and similar) is intended to make it hard to copy downloaded music or pirated software. Preventing teenagers from making copies of Eminem songs may seem harmless, but Internet Age technology is all about convergence. When a technology gets pervasively embedded in microprocessors, computer boards, and software, it will alter the performance of power turbines, jet engines, medical instruments, cell phones and missile guidance systems. Unfortunately, DRMP technology is incompatible with security and with the kinds of reliability needed in safety critical or mission critical applications. Ross Anderson has written an excellent comprehensive analysis of DRMP. Here I want to look at some concrete consequences that are important in defense and manufacturing.

"Despite marketing, DRMP is a licensing technology, not a security technology (see note 1). The combination of hardware and software being championed and fought over by the entertainment companies , Microsoft, and Intel, enforces something like an identity card or passport system on software. The idea is that DRM agents will be incorporated into software, processors (see note 2), and other computer hardware and the DRM agents will examine files containing programs and data (such as digitized music) to make sure the file is attached to a valid digital passport. The passports prove that the file is being used within its license terms. Before you can play a movie on your PC, the DRM agent in the processor will demand the passport on the video player and the video player software will demand the passport of the video file. Before you run a word processor, some DRM agent will make sure you have a valid license and have not violated any of the fine print of the shrink-wrap license and that the file you are opening is something you have a license to read. Programs that do not incorporate certified DRM agents will not be able to get passports, so there will be a world-wide web of DRM agents working together..."

