We describe the problem of unknown-compromised devices communicating with compliant devices in the context of rights transfer mechanisms within a DRM system. An unknown-compromised device can be used to acquire content rights in the usual manner (from either a backend Rights Issuer or a peer device), but it is not constrained by rules of legitimate processing other than to remain undetected. The compromise must remain undiscovered in order to avoid revocation which would result in rejection by compliant devices aware of this. Techniques to minimize the damage that can be caused by such rogue devices are introduced and contrasted.
More...