Click here to learn
about this Sponsor:
Home  |  News  |  Articles  |  Forum

  Home arrow Linux For Devices Articles arrow Guest opinion: DRM out of balance

Guest opinion: DRM out of balance
By Linux Devices

Rate This Article: Add This Article To:

In a Linuxdevices.com guest column back in 2002, I argued that without a major attitude change, digital rights management (DRM) technologies would cause software security failures and generate...

safety problems for everything from medical equipment to military systems. (That article basically said that systems with built-in DRM would create security problems for non-target cases.)

The recent Sony BMG DRM fiasco, which resulted from a common failure of requirements management logic, shows that developers of DRM systems have not had that attitude adjustment.

DRM brings up engineering problems that stress the weakest points of both system security and reliable device control software. Essentially the DRM problem is the problem of adding a complex constraint about copy protection to a very wide range of existing software and standard platforms.

When this constraint is added, what other constraints will be violated and what will be the consequences of the failure of those constraints? Consider these interesting cases:
  • If PC hardware and base software prevents digitizing of copyrighted images, can an armed robber turn off security cameras by wearing a T-shirt with a copyrighted image on it?

  • Will DRM mechanisms be able to tell the difference between a teenager making a copy of music over the Internet and someone calling emergency services while a CD plays in the background?

  • What guarantees that a physician accessing the network in the middle of the night won't see her computer shut down because her children watched a video with the wrong country code on it?

  • Where are the security and confidentiality safeguards so DRM will not result in bank or medical records being exposed on the Internet?

  • What mechanisms are in place to prevent false DRM violations from interfering with the operation of networked computer systems or from spreading.

  • and ...
There are off-the-shelf PCs managing safety systems in nuclear power plants, guarding the confidentiality of medical records, controlling warehouse conveyor belts and factory assembly lines, and managing power load on transmission lines. It's totally irresponsible to develop DRM systems without taking these types of uses into account.

And the obvious solutions won't work. For example, you cannot separate DRM locked "home" editions from DRM-free "industrial" software. If the DRM-free software is easily available, it will be used to circumvent DRM. If the DRM-free software is hard to get, DRM-locked software will be used in inappropriate devices.

Any ambiguity that allows DRM to be triggered on a supposedly DRM-free system will have unpredictable consequences. And worse, if DRM-locked software is near ubiquitous, the interactions between DRM-free and DRM-locked software will also be unpredictable. For example, will a DRM-locked database refuse to upload prescribing data to a DRM-free pharmacy computer?

The technical problem can be described quite concisely. A working computer system is a solution to a system of constraints. Often these constraints are informally specified or poorly understood, but they may be critical parts of a larger engineered system.

For example, think of a networked hospital integrated software management system in a hospital with the following constraints:
  1. Access to patient records requires explicit authorization
  2. Sensed data must be timestamped precisely and must arrive at monitors within 10 seconds of generation.
  3. Physicians must be able to download records to PDAs
  4. Physicians must be able to upload orders to PDAs
  5. Patients should be able to connect to the network and see their own records and get patient information
Now let's add constraint #6: Any download to a computer must be scanned by DRM software and without appropriate licenses it must be rejected.

Does imposing constraint #6 mean that the system is no longer a solution to the other five constraints? That's a tough question to answer with much assurance, particularly because DRM requires global constraints. That is, the DRM constraint is a constraint on total system behavior, not on the behavior of a known set of operations.

If the DRM constraint was "Windows Media will not play software lacking XYX credentials," the constraint would be easier to bound. But DRM is not being developed in this bounded way. Adding a DRM constraint affects the entire operation of the system.

The safety and reliability implications of these constraints do not seem to have been addressed by DRM-developers. One possible answer is that DRM is not compatible with safety and confidentiality. But in that case, isn't it better to consider the consequences now, while they are still in the future?


Note: an updated version of Yodaiken's earlier article appears on his blog.


Talk back!


Do you have comments on this story? Join the discussion here.


About the Author


Victor Yodaiken, CEO and Co-Founder of FSMLabs, came up with the basic technology of RTLinux, a technology that adds hard-real-time performance to Linux. Yodaiken began his career in 1983 as one of the chief developers of Auragen's distributed fault-tolerant UNIX, and he had an active consulting business before starting FSMLabs. He has also worked in academia, as a professor and department chair at New Mexico Tech, and as a research professor and port-doctoral fellow at the University of Massachusetts in Amherst. Currently he is an adjunct faculty member at the University of New Mexico.


Related Stories




Discuss Guest opinion: DRM out of balance
 
>>> Be the FIRST to comment on this article!
 
 
 
>>> More Linux For Devices Articles Articles          >>> More By Linux Devices
 



FUEL Database on MontaVista Linux
Whether building a mobile handset, a car navigation system, a package tracking device, or a home entertainment console, developers need capable software systems, including an operating system, development tools, and supporting libraries, to gain maximum benefit from their hardware platform and to meet aggressive time-to-market goals.

Breaking New Ground: The Evolution of Linux Clustering
With a platform comprising a complete Linux distribution, enhanced for clustering, and tailored for HPC, Penguin Computing¿s Scyld Software provides the building blocks for organizations from enterprises to workgroups to deploy, manage, and maintain Linux clusters, regardless of their size.

Data Monitoring with NightStar LX
Unlike ordinary debuggers, NightStar LX doesn¿t leave you stranded in the dark. It¿s more than just a debugger, it¿s a whole suite of integrated diagnostic tools designed for time-critical Linux applications to reduce test time, increase productivity and lower costs. You can debug, monitor, analyze and tune with minimal intrusion, so you see real execution behavior. And that¿s positively illuminating.

Virtualizing Service Provider Networks with Vyatta
This paper highlights Vyatta's unique ability to virtualize networking functions using Vyatta's secure routing software in service provider environments.

High Availability Messaging Solution Using AXIGEN, Heartbeat and DRBD
This white paper discusses a high-availability messaging solution relying on the AXIGEN Mail Server, Heartbeat and DRBD. Solution architecture and implementation, as well as benefits of using AXIGEN for this setup are all presented in detail.

Understanding the Financial Benefits of Open Source
Will open source pay off? Open source is becoming standard within enterprises, often because of cost savings. Find out how much of a financial impact it can have on your organization. Get this methodology and calculator now, compliments of JBoss.

Embedded Hardware and OS Technology Empower PC-Based Platforms
The modern embedded computer is the jack of all trades appearing in many forms.

Data Management for Real-Time Distributed Systems
This paper provides an overview of the network-centric computing model, data distribution services, and distributed data management. It then describes how the SkyBoard integration and synchronization service, coupled with an implementation of the OMG¿s Data Distribution Service (DDS) standard, can be used to create an efficient data distribution, storage, and retrieval system.

7 Advantages of D2D Backup
For decades, tape has been the backup medium of choice. But, now, disk-to-disk (D2D) backup is gaining in favor. Learn why you should make the move in this whitepaper.

Got a HOT tip?   please tell us!
Free weekly newsletter
Enter your email...
Click for a profile of each sponsor:
SUPER-PLATINUM SPONSOR
MOBLIN NEWS & LINKS
Moblin Official Blog
Aigo to Go
Wind River's Moblin stack
Adobe AIR for devices
FEATURED VIDEO

Moblin v2 "Fastboot"
PLATINUM SPONSORS
GOLD SPONSORS
(Become a sponsor)

ADVERTISEMENT
(Advertise here)

Check out the latest Linux powered...

Mobile phones!

MIDs, UMPCs
& tablets

Mobile devices

Other cool
gadgets

Resource Library

• Unix, Linux Uptime and Reliability Increase: Patch Management Woes Plague Windows Yankee Group survey finds IBM AIX Unix is highest in ...
• Scalable, Fault-Tolerant NAS for Oracle - The Next Generation For several years NAS has been evolving as a storage ...
• Managing Software Intellectual Property in an Open Source World This whitepaper draws on the experiences of the Black Duck ...
• Open Source Security Myths Dispelled Is it risky to trust mission-critical infrastructure to open source ...
• Bringing IT Operations Management to Open Source & Beyond Download this IDC analyst report to learn how open source ...


BREAKING NEWS

• NAS system houses 2.5-inch drives for up to 6TB
• Atom SBC boasts special low-power mode
• Android leaps to rugged handheld, and more phones
• Simulator runs Android apps on Ubuntu
• Fanless industrial PC taps Atom
• Router platform runs OpenWRT Linux
• Feature-packed UMPC survives four-foot drops
• UMPC pioneer gives up the ghost
• Biodegradable, solar-powered netbook runs Linux
• Hypervisor rev'd for higher reliability
• Eurotech spins Atom development kits
• Home media server to demo on Intel Atom platform
• Atom boards feature fanless DC operation
• Low-cost pluggable NAS adds Linux support
• Taiwan open source conference sets agenda


Most popular stories -- past 90 days:
• Linux boots in 2.97 seconds
• Tiniest Linux system, yet?
• Linux powers "cloud" gaming console
• Report: T-Mobile sells out first 1.5 million G1s
• Open set-top box ships
• E17 adapted to Linux devices, demo'd on Treo650
• Android debuts
• First ALP Linux smartphone?
• Cortex-A8 gaming handheld runs Linux
• Ubuntu announces ARM port


DesktopLinux headlines:
• Simulator runs Android apps on Ubuntu
• Hypervisor rev'd for higher reliability
• Pluggable NAS now supports Linux desktops
• Moblin v2 beta targets netbooks
• Linux-ready netbook touted as "Student rugged"
• USB display technology heading for Linux
• Ubuntu One takes baby step to the cloud
• Game over for Linux netbooks?
• Linux Foundation relaunches Linux web site
• Dell spins lower-cost netbook


Also visit our sister site:


Sign up for LinuxForDevices.com's...

news feed


Or, follow us on Twitter...