IP Library Granted Patent US 8,831,217
Granted Patent B2
US 8,831,217 · App. 13/460,616 · Granted Sep 9, 2014

Digital rights management system and methods for accessing content from an intelligent storage

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,831,217
App. No.
13/460,616
Granted
Sep 9, 2014
Kind
B2
Abstract

The present invention relates to accessing content stored on a storage device and protecting the content with a digital rights management (DRM) scheme. The storage device may be a disk drive, or network attached storage. The storage device can perform cryptographic operations and provide a hardware root of trust. The DRM employs a binding key, a content key, and an access key. The binding key binds the content to the storage device and is based on a key concealed on the storage device. The binding key itself is not stored anywhere on the storage device. The content key is a key assigned to the content. The access key is determined based on a cryptographic combination of the content key and binding key. In one embodiment, the content is encrypted based on the access key and stored in encrypted form in the storage device.

Claims (44)

1. A storage device configured to provide content to a player system for rendering of the content, said storage device comprising:

a storage medium comprising a user area that is accessible by the player system and a non-user area that is not accessible by the player system; and

a controller comprising a cryptographic module providing a hardware root of trust and a secured memory, wherein the controller is configured to:

authenticate the player system;

establish a secured communication channel with the player system based on the authentication;

provide, to the player system, a first cryptographic key, wherein the first cryptographic key is unique to the storage device, the first cryptographic key based at least partly on defect information of the storage medium and cryptographic data stored on the non-user area;

provide, to the player system, a second cryptographic key that is associated with the content, wherein the second cryptographic key is based at least partly on cryptographic data previously obtained, over a communication network, from an audit system distinct from the player system; and

provide, to the player system, the content in encrypted form from the user area of the storage medium,

wherein the content is accessible based on a cryptographic combination of the first cryptographic key and the second cryptographic key.

2. The storage device of claim 1 , wherein the first cryptographic key is based on a key that is concealed in the storage device.

3. The storage device of claim 2 , wherein the cryptographic module stores the concealed key in a one-time-programmable, non-volatile memory in the secured memory.

4. The storage device of claim 1 , wherein the controller is configured to provide the first cryptographic key as an ephemeral key.

5. The storage device of claim 1 , wherein the defect information comprises data on manufacturing defects of the storage medium.

6. The storage device of claim 1 , wherein the storage medium comprises magnetic media.

7. A player system configured to play encrypted content, said system comprising:

a first interface configured to communicate with a storage device storing encrypted content; and

a processor configured to:

authenticate the storage device;

establish a secured communication channel with the storage device via the first interface;

receive, from the storage device, a binding cryptographic key that is unique to the storage device, the binding cryptographic key based at least partly on defect information of a storage medium of the storage device;

receive, from the storage device, a second cryptographic key that is associated with the content, wherein the second cryptographic key is based at least partly on cryptographic data previously obtained, over a communication network, from an audit system distinct from the player system;

determine an access key for the content based on a cryptographic combination of the binding cryptographic key and the second cryptographic key;

receive, from the storage device, the encrypted content; and

decrypt the content based on the access key.

8. The player system of claim 7 , wherein the binding cryptographic key is based on a key that is concealed in the storage device.

9. The player system of claim 7 , wherein the processor is configured to authenticate the storage device based on a public key infrastructure.

10. The player system of claim 7 , wherein the processor is configured to mutually authenticate with the storage device based on a public key infrastructure.

11. The player system of claim 7 , wherein the processor is configured to receive an ephemeral binding cryptographic key based on a request sent to the storage device.

12. The player system of claim 7 , wherein the processor is configured to receive a temporary binding cryptographic key based on a request sent to the storage device.

13. The player system of claim 7 , wherein the processor is configured to determine an ephemeral access key based on the cryptographic combination of the binding cryptographic key and the second cryptographic key.

14. The player system of claim 7 , wherein the processor is configured to obtain a digital certificate for the content.

15. The player system of claim 14 , wherein the processor is configured to determine authorization for access to the content based on the digital certificate and the authentication of the storage device.

16. The player system of claim 7 , wherein the defect information comprises data on manufacturing defects of the storage medium.

17. A method of accessing encrypted content from a storage device, said method comprising:

receiving, from the storage device, a binding cryptographic key that binds the content to the storage device, the binding cryptographic key based at least partly on defect information of a storage medium of the storage device;

receiving, from the storage device, a second cryptographic key that is associated with the content, wherein the second cryptographic key is based at least partly on cryptographic data previously obtained, over a communication network, from an audit system distinct from a player system;

determining an access key for the content based on a cryptographic combination of the binding cryptographic key and the second cryptographic key;

receiving, from the storage device, the encrypted content; and

decrypting the content based on the access key.

18. The method of claim 17 , wherein the binding cryptographic key is based on a key that is concealed in the storage device.

19. The method of claim 17 , wherein authenticating the storage device comprises mutually authenticating with the storage device based on a public key infrastructure.

20. The method of claim 17 , wherein receiving the binding cryptographic key comprises receiving an ephemeral binding cryptographic key based on a request sent to the storage device.

21. The method of claim 17 , wherein determining the access key comprises determining an ephemeral access key based on the cryptographic combination of the binding cryptographic key and the second cryptographic key.

22. The method of claim 17 , wherein the defect information comprises manufacturing defects of the storage medium.

Assignments (13)
PARTIAL RELEASE OF SECURITY INTERESTS Recorded Apr 25, 2025
From: JPMORGAN CHASE BANK, N.A., AS AGENT
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 071382/0001 →
SECURITY AGREEMENT Recorded Apr 25, 2025
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 071050/0001 →
PATENT COLLATERAL AGREEMENT Recorded Aug 23, 2024
From: SANDISK TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS THE AGENT
Reel/Frame 068762/0494 →
CHANGE OF NAME Recorded Jun 27, 2024
From: SANDISK TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067982/0032 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 29, 2024
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: SANDISK TECHNOLOGIES, INC.
Reel/Frame 067567/0682 →
PATENT COLLATERAL AGREEMENT - A&R LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 064715/0001 →
PATENT COLLATERAL AGREEMENT - DDTL LOAN AGREEMENT Recorded Aug 21, 2023
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 067045/0156 →
RELEASE OF SECURITY INTEREST AT REEL 038744 FRAME 0481 Recorded Feb 8, 2022
From: JPMORGAN CHASE BANK, N.A.
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 058982/0556 →
RELEASE OF SECURITY INTEREST Recorded Mar 5, 2018
From: U.S. BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 045501/0714 →
SECURITY AGREEMENT Recorded May 17, 2016
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 038722/0229 →
SECURITY AGREEMENT Recorded May 17, 2016
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 038744/0481 →
SECURITY AGREEMENT Recorded May 17, 2016
From: WESTERN DIGITAL TECHNOLOGIES, INC.
To: U.S. BANK NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 038744/0281 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 17, 2012
From: BLANKENBECKLER, DAVID L.; YBARRA, DANNY O.; HESSELINK, LAMBERTUS
To: WESTERN DIGITAL TECHNOLOGIES, INC.
Reel/Frame 028570/0595 →