IP Library › Granted Patent US 10,140,432
Granted Patent B2
US 10,140,432 · App. 14/950,882 · Granted Nov 27, 2018

Method for scalable access control decisions

Inventor: Jonathan T. Moore (Philadelphia, PA)
Assignee: Comcast Interactive Media, LLC
G06F21/10G06F21/31H04L63/0807H04L63/123H04L63/168G06F2221/07H04N7/163
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,140,432
App. No.
14/950,882
Granted
Nov 27, 2018
Kind
B2
Abstract

Content access may be provided and processed by assigning responsibility for obtaining entitlement data to the client's browser. Thus, in one example, the client may be configured to synchronize and coordinate data lookups associated with a content request, rather than relying on the server to do so. The network architecture may use a mediator design pattern, in which the client's browser acts as the mediator (i.e., middleman) between a content server and an entitlement data server. Accordingly, synchronous calls between server-side services might not be required. Instead, data necessary for the content server to process a client request for access to protected content may be received in the incoming request from the client's browser.

Claims (54)

1. A method comprising:

receiving, by a first computing device and from a second computing device, a redirect to a third computing device, wherein the redirect comprises a digital token comprising an indication that the redirect is authorized by the second computing device;

obtaining entitlement data for the first computing device or a user of the first computing device based, at least in part, on transmitting the digital token to the third computing device associated with the redirect;

transmitting, to the second computing device, the entitlement data for the first computing device or the user of the first computing device, wherein the entitlement data authorizes the first computing device or the user of the first computing device to access a content item; and

after transmitting the entitlement data to the second computing device, receiving, by the first computing device and from the second computing device, an unencrypted version of a location of the content item.

2. The method of claim 1 , further comprising:

transmitting, to the second computing device and using the unencrypted version of the location, a request for the content item, wherein the request comprises content data specific to the content item.

3. The method of claim 2 , wherein the content data comprises the digital token and an encrypted address of the content item.

4. The method of claim 3 , wherein the content data further comprises an expiration time for the digital token.

5. The method of claim 2 , further comprising receiving an application, wherein the application is configured to execute on the first computing device and to interface with the second computing device.

6. The method of claim 1 , further comprising:

prior to receiving the redirect, receiving an encrypted version of the location of the content item.

7. The method of claim 1 , wherein obtaining the entitlement data comprises obtaining a content subscription of the first computing device or the user of the first computing device.

8. A first computing device comprising:

one or more processors;

memory storing instructions that, when executed by the one or more processors, cause the first computing device to:

receive, from a second computing device, a redirect to a third computing device, wherein the redirect comprises a digital token comprising an indication that the redirect is authorized by the second computing device;

obtain entitlement data for the first computing device or a user of the first computing device based, at least in part, on transmitting the digital token to the third computing device associated with the redirect;

transmit, to the second computing device, the entitlement data for the first computing device or the user of the first computing device, wherein the entitlement data authorizes the first computing device or the user of the first computing device to access a content item; and

after transmitting the entitlement data to the second computing device, receive, from the second computing device, an unencrypted version of a location of the content item.

9. The first computing device of claim 8 , wherein the instructions, when executed by the one or more processors, cause the first computing device to:

transmit, to the second computing device and using the unencrypted version of the location, a request for the content item, wherein the request comprises content data specific to the content item.

10. The first computing device of claim 9 , wherein the content data comprises the digital token and an encrypted address of the content item.

11. The first computing device of claim 10 , wherein the content data further comprises an expiration time for the digital token.

12. The first computing device of claim 9 , wherein the instructions, when executed by the one or more processors, cause the first computing device to:

receive an application, wherein the application is configured to execute on the first computing device and to interface with the second computing device.

13. The first computing device of claim 8 , wherein the instructions, when executed by the one or more processors, cause the first computing device to:

prior to receiving the redirect, receive an encrypted version of the location of the content item.

14. The first computing device of claim 8 , wherein the instructions, when executed by the one or more processors, cause the first computing device to obtain the entitlement data by obtaining a content subscription of the first computing device or the user of the first computing device.

15. A system comprising:

a first computing device; and

a second computing device;

wherein the first computing device comprises:

one or more processors; and

memory storing instructions that, when executed by the one or more processors, cause the first computing device to:

receive, from the second computing device, a redirect to a third computing device, wherein the redirect comprises a digital token comprising an indication that the redirect is authorized by the second computing device;

obtain entitlement data for the first computing device or a user of the first computing device based, at least in part, on transmitting the digital token to the third computing device associated with the redirect;

transmit, to the second computing device, the entitlement data for the first computing device or the user of the first computing device, wherein the entitlement data authorizes the first computing device or the user of the first computing device to access a content item; and

after transmitting the entitlement data to the second computing device, receive, from the second computing device, an unencrypted version of a location of the content item; and

wherein the second computing device comprises:

one or more processors; and

memory storing instructions that, when executed by the one or more processors of the second computing device, cause the second computing device to:

send the redirect;

receive the entitlement data; and

send the unencrypted version of the location of the content item.

16. The system of claim 15 , wherein the instructions stored in the memory of the first computing device, when executed by the one or more processors of the first computing device, cause the first computing device to:

transmit, to the second computing device and using the unencrypted version of the location, a request for the content item, wherein the request comprises content data specific to the content item.

17. The system of claim 16 , wherein the content data comprises the digital token and an encrypted address of the content item.

18. The system of claim 17 , wherein the content data further comprises an expiration time for the digital token.

19. The system of claim 16 , wherein the instructions stored in the memory of the first computing device, when executed by the one or more processors of the first computing device, cause the first computing device to:

receive an application, wherein the application is configured to execute on the first computing device and to interface with the second computing device.

20. The system of claim 15 , wherein the instructions stored in the memory of the first computing device, when executed by the one or more processors of the first computing device, cause the first computing device to:

prior to receiving the redirect, receive an encrypted version of the location of the content item.

21. The system of claim 15 , wherein the instructions stored in the memory of the first computing device, when executed by the one or more processors stored of the first computing device, cause the first computing device to obtain the entitlement data by obtaining a content subscription of the first computing device or the user of the first computing device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2015
From: MOORE, JONATHAN T.
To: COMCAST INTERACTIVE MEDIA, LLC
Reel/Frame 037140/0230 →
Continuity (3)
Continuation 14279895 · May 16, 2014
Continuation 12624783 · Nov 24, 2009
Related Publication 20160078199A1 · Mar 17, 2016