IP Library Granted Patent US 7,404,082
Granted Patent B2
US 7,404,082 · App. 11/228,180 · Granted Jul 22, 2008

System and method for providing authorized access to digital content

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,404,082
App. No.
11/228,180
Granted
Jul 22, 2008
Kind
B2
Abstract

Described herein are embodiments that provide an approach to cryptographic key management for a digital rights management (DRM) architecture that includes multiple levels of key management for minimizing bandwidth usage while maximizing security for the DRM architecture. In one embodiment, there is provided a data structure for cryptographic key management that includes a public/private key pair and three additional layers of symmetric keys for authorizing access to a plurality of contents.

Claims (41)

1. A method for authorizing access to content received by a device, the method comprising:

providing a public key, a private key, and an associated digital certificate that the device use to provide public key decryption;

providing a device unit key that is a symmetric key encrypted by the public key and decrypted by the private key, wherein the device unit key is unique to the device;

providing at least one service key that is a symmetric key encrypted and authenticated by the device unit key; and

providing at least one program key that is a symmetric key used to decrypt a first type of content access and a different second type of content access;

wherein the device unit key provides encryption and authentication of the at least one program key for use to decrypt the first type of content access, and the at least one service key provides encryption and authentication of the at least one program key for use to decrypt the second type of content access.

2. The method of claim 1 , wherein the device unit key comprises:

a first symmetric key that provides encryption of the at least one service key or the at least one program key; or

a second symmetric key that provides authentication of the at least one service key or the at least one program key.

3. The method of claim 1 , wherein the second record is updated on a predetermined period basis.

4. The method of claim 1 , wherein the at least one service key comprises a plurality of service keys, and the at least one program key comprises a plurality of program keys; and wherein each of the plurality of service keys is unique to and provides decryption of each of the plurality of program keys.

5. The method of claim 1 , wherein the at least one service key comprises:

a first symmetric key that provides encryption of the at least one program key; and

a second symmetric key that provides authentication of the at least one program key.

6. The method of claim 5 , wherein the at least one service key is updated on a predetermined periodic basis.

7. The method of claim 1 , wherein the first type of content access is for a content pay-per-view event, and the second type of content is for a content subscription service.

8. The method of claim 1 , further comprising:

a fifth record encoded on the computer-readable medium, the fifth record includes a content decryption key that is derived from a combination of the at least one program key and information from the second type of content access.

9. The method of claim 1 , wherein the computer-readable data structure is encoded in one of a smart card and computer-readable medium accessible by the device for receiving content.

10. A method for providing authorized access to content, comprising:

receiving a request for content access;

responsive to the request, providing an asymmetric key pair having a public encryption key and a private encryption key;

providing an entitlement management message (EMM), the providing the EMM comprises:

a) encrypting a device unit key with the public encryption key, wherein the device unit key is unique to a source of the request; and

b) encrypting a service key with at least the device unit key, the service key is operable to provide decryption of a program key;

providing an entitlement control message (ECM) for a first type of content access or a second different type of content access, the providing the ECM comprises:

a) providing the program key in the ECM for decrypting the first type of content access or the second type of content access;

b) encrypting the ECM with the service key for the first type of content access;

c) encrypting the ECM with the device unit key for the second type of content access.

11. The method of claim 10 , wherein:

the encrypting the ECM with the service key includes encrypting the program key with the service key; and

the encrypting the ECM with the device unit key includes encrypting the program key with the device unit key.

12. The method of claim 10 , wherein the first type of content access is a content subscription service type, and the second type of content access is a content-pay-per-view-event type.

13. The method of claim 10 , wherein the providing the EMM further comprises:

Encrypting another service key with at least the device unit key, wherein the another service key provides decryption of the first type of content access upon an expiration of the service key; and

wherein the EMM includes the service key and the another service key.

14. The method of claim 10 , further comprising:

Periodically repeating the providing the EMM to generate additional EMMs, wherein each of the EMMs includes a key identifier that sequentially increases in value based on a sequential order of the generation of each of the EMMs from first to last.

15. The method of claim 12 , wherein the providing the ECM further comprises:

providing a first access rule that specifies how long a content of the second type content access is to be stored once it is decrypted with the program key.

16. The method of claim 10 , wherein the source of the request for content access includes a receiver having access to the asymmetric key pair and providing access to content.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2014
From: MOTOROLA MOBILITY LLC
To: GOOGLE TECHNOLOGY HOLDINGS LLC
Reel/Frame 034358/0264 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2013
From: GENERAL INSTRUMENT CORPORATION
To: GENERAL INSTRUMENT HOLDINGS, INC.
Reel/Frame 030764/0575 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 9, 2013
From: GENERAL INSTRUMENT HOLDINGS, INC.
To: MOTOROLA MOBILITY LLC
Reel/Frame 030866/0113 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 14, 2005
From: MEDVINSKY, ALEXANDER; MORONEY, PAUL; SPRUNK, ERIC; PETERKA, PETR
To: GENERAL INSTRUMENT CORPORATION
Reel/Frame 017241/0458 →