IP Library Granted Patent US 8,595,492
Granted Patent B2
US 8,595,492 · App. 12/544,008 · Granted Nov 26, 2013

On-demand protection and authorization of playback of media assets

Inventors: Paul McReynolds (Seaside, CA); Eric B. Dachs (Burlingame, CA); Erik Bielefeldt (Stanford, CA); Craig Wood (Berkeley, CA)
Assignee: Pix System, LLC
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,595,492
App. No.
12/544,008
Granted
Nov 26, 2013
Kind
B2
Abstract

On-demand protection and authorization of playback of media assets includes receiving digital media at a server computer, storing intermediary data in a data store, and receiving a request from a client for the digital media. The method also includes generating a protected copy of the digital media from the digital media and the intermediary data. The method also includes storing a description of the protected copy in a database and sending the protected copy to the client. The method also includes receiving a request from the client to access the digital media and reading the description from the database based on information in the request. The method also includes sending a response to the client, the response indicating whether the client is authorized to access the digital media, and the response including cryptographic data to decrypt the protected digital media if the client is authorized to access the digital media.

Claims (101)

1. A computer implemented method comprising:

by a server computer,

receiving a request from a client for digital media;

sending a protected copy of the digital media to the client;

receiving a request from the client to access the digital media;

sending cryptographic data to decrypt the protected digital media if the client is authorized to access the digital media; and

sending to the client cryptographic data that is different from cryptographic data sent to the client in response to previous requests for access to the protected data, to decrypt the protected digital media upon each subsequent request for access to the protected digital data.

2. The method of claim 1 wherein the digital media comprises one or more QuickTime movies, each of the one or more QuickTime movies comprising one or more of a video sample and an audio sample.

3. The method of claim 2 wherein the protected copy of the digital media comprises the samples encrypted using a checkout key, the checkout key comprising a movie portion and a server portion, wherein there is a one-to-one mapping between each combination of movie portion and server portion and each checkout key; the movie portion of the checkout key; and a numerical checkout ID.

4. The method of claim 2 wherein

the request comprises the checkout ID and an authorization response key, the authorization response key comprising a randomized binary value generated by the client; and

the method further comprises denying the request if it is determined that the response key was used by a previous request.

5. The method of claim 4 , further comprising storing the response key if it is determined that the response key was not used by a previous request.

6. The method of claim 5 , further comprising encrypting the response using the response key before sending the response to the client.

7. A computer implemented method comprising:

by a client computer,

sending, a request to a server for digital media;

receiving a protected copy of the digital media;

after receiving the protected copy, sending a request to access the digital media;

receiving cryptographic data to decrypt the protected digital media if the client computer is authorized to access the digital media;

if the client computer is authorized to access the digital media,

decrypting a sample of the protected digital media using the cryptographic data; and

rendering the sample; and

receiving from the server cryptographic data that is different from cryptographic data received from the server in response to previous requests for access to the protected data, to decrypt the protected digital media upon each subsequent request for access to the protected digital data.

8. The method of claim 7 wherein the digital media comprises one or more QuickTime movies, each of the one or more QuickTime movies comprising one or more of a video sample and an audio sample.

9. The method of claim 8 wherein the protected copy of the digital media comprises the samples encrypted using a checkout key, the checkout key comprising a movie portion and a server portion, wherein there is a one-to-one mapping between each combination of movie portion and server portion and each checkout key; the movie portion of the checkout key; and a numerical checkout ID.

10. The method of claim 8 wherein the request comprises a checkout ID and an authorization response key, the authorization response key comprising a randomized binary value generated by the client.

11. The method of claim 10 , further comprising displaying an error message if the decrypting fails or if the response comprises an error code.

12. The method of claim 7 , further comprising continuing to decrypt and render samples until the user stops playback or the movie ends.

13. An apparatus comprising:

one or more processors configured to:

receive digital media;

receive a request from a client for digital media;

send the protected copy to the client;

receive a request from the client to access the digital media;

cryptographic data to decrypt the protected digital media if the client is authorized to access the digital media; and

send to the client cryptographic data that is different from cryptographic data sent to the client in response to previous requests for access to the protected data, to decrypt the protected digital media upon each subsequent request for access to the protected digital data.

14. The apparatus of claim 13 wherein the digital media comprises one or more QuickTime movies, each of the one or more QuickTime movies comprising one or more of a video sample and an audio sample.

15. The apparatus of claim 14 wherein the protected copy of the digital media comprises the samples encrypted using a checkout key, the checkout key comprising a movie portion and a server portion, wherein there is a one-to-one mapping between each combination of movie portion and server portion and each checkout key;

the movie portion of the checkout key; and a numerical checkout ID.

16. The apparatus of claim 14 wherein

the request comprises a checkout ID and an authorization response key, the authorization response key comprising a randomized binary value generated by the client; and

the one or more processors are further configured to deny the request if it is determined that the response key was used by a previous request or if the client is not authorized to play the media.

17. The apparatus of claim 16 wherein the one or more processors are further configured to store the response key if it is determined that the response key was not used by a previous request.

18. The apparatus of claim 17 wherein the one or more processors are further configured to encrypt the response using the response key before sending the response to the client.

19. An apparatus comprising:

one or more processors configured to:

send a request to a server for digital media;

receive a protected copy of the digital media;

after receiving the protected copy, send a request to access the digital media;

receive cryptographic data to decrypt the protected digital media if the apparatus is authorized to access the digital media;

if the apparatus is authorized to access the digital media,

decrypt a sample of the protected digital media using the cryptographic data; and

render the sample; and

receive from the server cryptographic data that is different from cryptographic data received from the server in response to previous requests for access to the protected data, to decrypt the protected digital media upon each subsequent request for access to the protected digital data.

20. The apparatus of claim 19 wherein the digital media comprises one or more QuickTime movies, each of the one or more QuickTime movies comprising one or more of a video sample and an audio sample.

21. The apparatus of claim 20 wherein the protected copy of the digital media comprises the samples encrypted using a checkout key, the checkout key comprising a movie portion and a server portion, wherein there is a one-to-one mapping between each combination of movie portion and server portion and each checkout key; the movie portion of the checkout key; and a numerical checkout ID.

22. The apparatus of claim 20 wherein the request comprises a checkout ID and an authorization response key, the authorization response key comprising a randomized binary value generated by the client.

23. The apparatus of claim 22 wherein the one or more processors are further configured to display an error message if the decrypting fails or if the response comprises an error code.

24. The apparatus of claim 19 wherein the one or more processors are further configured to continue to decrypting and rendering samples until the user stops playback or the movie ends.

25. A nontransitory program storage device readable by a machine, embodying a program of instructions executable by the machine to perform a method, the method comprising:

by a server computer,

receiving a request from a client for digital media;

sending a protected copy of the digital media to the client;

receiving a request from the client to access the digital media;

sending cryptographic data to decrypt the protected digital media if the client is authorized to access the digital media;

sending a response to the client, the response indicating whether the client is authorized to access the digital media, the response further comprising cryptographic data to decrypt the protected digital media if the client is authorized to access the digital media; and

sending to the client cryptographic data that is different from cryptographic data sent to the client in response to previous requests for access to the protected data, to decrypt the protected digital media upon each subsequent request for access to the protected digital data.

26. A nontransitory program storage device readable by a machine, embodying a program of instructions executable by the machine to perform a method, the method comprising:

by a client computer,

sending a request to a server for digital media;

receiving a protected copy of the digital media;

after receiving the protected copy, sending a request to access the digital media;

receiving a response, the response indicating whether the client computer is authorized to access the digital media, the response further comprising cryptographic data to decrypt the protected digital media if the client computer is authorized to access the digital media;

if the client computer is authorized to access the digital media,

decrypting a sample of the protected digital media using the cryptographic data; and

rendering the sample; and

receiving from the server cryptographic data that is different from cryptographic data received from the server in response to previous requests for access to the protected data, to decrypt the protected digital media upon each subsequent request for access to the protected digital data.

27. A computer implemented method comprising:

receiving, at a server computer, a digital media file comprising:

one or more digital video or audio samples; and

a header identifying the samples by their offsets from the start of the file;

computing the new offset for each sample that will result from encryption of preceding samples in the file;

storing intermediary data comprising the new offsets in a data store;

after storing the original digital media file and intermediary data, receiving a request from a client for the digital media;

generating from the original digital media file and the intermediary data a protected copy of the digital media file in which samples from the original digital media file have been encrypted and the sample offsets replaced with those in the intermediary data; and

sending the protected copy to the client.

28. A computer implemented method comprising:

receiving, at a server computer, a digital media file comprising:

one or more digital video or audio samples; and

a header identifying the samples by their offsets from the start of the file;

computing the new offset for each sample that will result from encryption of preceding samples in the file;

storing intermediary data comprising the new offsets in a data store;

after storing the original digital media file and intermediary data, receiving a request from a client for the digital media;

generating from the original digital media file and the intermediary data a protected copy of the digital media file in which samples from the original digital media file have been encrypted and the sample offsets replaced with those in the intermediary data;

storing a description of the protected copy in a database;

sending the protected copy of the digital media file to the client;

after sending the protected copy, receiving a request from the client to access the digital media;

reading the description from the database based on information in the request; and

sending a response to the client, the response indicating whether the client is authorized to access the digital media, the response further comprising cryptographic data to decrypt the protected digital media if the client is authorized to access the digital media; and

sending to the client cryptographic data that is different from cryptographic data sent to the client in response to previous requests for access to the protected data, to decrypt the protected digital media upon each subsequent request for access to the protected digital data.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 19, 2024
From: X2X, LLC
To: AUTODESK, INC.
Reel/Frame 069639/0610 →
CHANGE OF NAME Recorded Sep 21, 2023
From: PIX SYSTEM, LLC
To: X2X, LLC
Reel/Frame 065018/0881 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 4, 2009
From: MCREYNOLDS, PAUL; DACHS, ERIC B.; BIELEFELDT, ERIK; WOOD, CRAIG
To: PIX SYSTEM, LLC
Reel/Frame 023609/0165 →
Continuity (2)
Provisional Application 61090848 · Aug 21, 2008
Related Publication 20100077212A1 · Mar 25, 2010