Tuesday, November 3, 2009

Making DRM More Usable...or Profitable?

A. Arnab and A. Hutchison, “Fairer usage contracts for DRM,” in Proceedings of the 5th ACM workshop on Digital rights management, 2005, 7.

This article from two students at the University of Cape Town takes a look at the functionality of DRM.

DRM is widely discussed as a tool to enforce copyright as we move into the digital medium. The authors agree with many other critics of the various software technologies that constitute DRM in observing that DRM does not really enforce copyright. They argue that while copyright enforcement is theoretically possible, DRM lacks the sophistication to allow for
fair use of digital objects. Fair use is an exception to a usually applicable copyright restriction and is frequently argued on a case-by-case basis; it's therefore extremely difficult to allow for this very important exception in a programmatic way. Consequently it's overlooked and rights holders instead are allowed to sidestep the whole issue by issuing some agreed contractual terms that usually favor themselves over the consumer or user.

The authors take some further time to observe how DRM is unable to restrict reproduction and distribution (the core protections of copyright) because of the nature of hardware and software. DRM at the application (iTunes) and operating system level (Windows, OS X) cannot prevent reproduction and distribution. Media-specific DRM (like CSS and AACS) can be compromised, moreover media is trending toward direct digital distribution. DRM at the chip level can also be skipped so long as computers continue to have removable components. Provided this continues (I certainly hope so) and systems can support multiple operating systems (again, let's hope so) DRM doesn't seem to have a future as a legitimate copyright enforcement tool.

The authors instead argue that DRM is used as a licensing tool. They present two improvements to the licensing model that might allow for more input from the user and more granularity in the rights holders' licensing terms.

Use licenses in DRM systems are typically explained to a computer through a Rights Expression Language (REL). They authors argue that RELs should be expanded to incorporate a more nuanced license-negotiation process that goes beyond a simple request-response that is used today (i.e., do you accept this license? Yes or no). In this model users would request a set of rights, the licensing server would evaluate the request and serve up a license with those rights and the terms, user accepts, denies or renegotiates.

This process could begin again after the user has purchased the digital object and the license if the user wants some new right. This could allow for better fair use control.

A second approach provides a credential construct in RELs that would allow users to identify themselves as various roles (a journalist, a university student, a researcher, etc.) and thereby request different rights.

While I agree that DRM is a poor copyright enforcement tool, I'm hesitant to embrace these more nuanced licensing models and processes right off the bat. As the authors note, their models allow for a lot of flexibility and "newer business models for the rights holders." Is that a good thing? I can easily see a business micromanaging their rights model to create a maximum profit. In fact they could read this article and wonder why it hadn't occur to them to create a pay-as-you-go licensing model that kept users coming back for more rights.

But, so long as digital objects like datasets, music, recordings, and so on have rights holders that need to exert control over their materials, a better model is needed, one that works. The authors here have faith that a more nuanced licensing model ultimately would create fairer deals because users/researchers have a say in what they'll accept and in what they want. To the extent that a model would facilitate such feedback, I'm for it. The DRM industry is looking for standards, I hope they settle on one that's reasonable and expandable.

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.