IP Library Granted Patent US 10,270,591
Granted Patent B2
US 10,270,591 · App. 15/199,503 · Granted Apr 23, 2019

Remotely managed trusted execution environment for digital-rights management in a distributed network with thin clients

Inventors: Ronald Brockmann (Utrecht, NL); Gerrit Hiddink (Amersfoort, NL)
Assignee: ActiveVideo Networks, Inc.
H04L9/08G06F21/10G06F21/57H04L63/06
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,270,591
App. No.
15/199,503
Granted
Apr 23, 2019
Kind
B2
Abstract

A method is performed at a client device distinct from an application server. In the method, a first key is stored in a secure store of the client device. A wrapped second key is received from the application server. The first key is retrieved from the secure store and used to unwrap the second key. Encrypted media content is received from the application server, decrypted using the unwrapped second key, and decoded for playback.

Claims (59)

1. A method, comprising:

at a client device distinct from an application server:

storing a first key in a secure store of the client device;

receiving a wrapped second key from the application server;

retrieving the first key from the secure store;

using the first key to unwrap the second key;

receiving encrypted media content from the application server;

decrypting the encrypted media content using the unwrapped second key; and

decoding the decrypted media content for playback;

transmitting, to a display device that is coupled to the client device, the decrypted media content;

while transmitting, to the display device, the decrypted media content, periodically transmitting the second key to the application server; and

terminating transmission of the encrypted media content by the application server when the second key received by the application server from the client device is not the same as the second key received by the client device from the application server.

2. The method of claim 1 , wherein receiving the encrypted media content from the application server comprises receiving an encrypted elementary stream from the application server.

3. The method of claim 2 , wherein decrypting the encrypted media content comprises:

providing a decryption command from an elementary-stream player executing on the client device to a digital-rights-management (DRM) agent executing on the client device, the decryption command specifying the unwrapped second key; and

decrypting the encrypted media content using the unwrapped second key at the DRM agent.

4. The method of claim 1 , wherein:

the first key is a device key provided by a manufacturer of the client device; and

the second key is associated with a DRM scheme specified by a content provider of the encrypted media content.

5. The method of claim 1 , wherein the encrypted media content has DRM header data specifying the DRM scheme.

6. The method of claim 1 , wherein the wrapped second key is received from the application server in response to a user of the client device launching the encrypted media content.

7. The method of claim 1 , further comprising:

receiving a query from the application server for secure data; and

in response to the query, retrieving a device identity of the client device from the secure store and transmitting the device identity to the application server;

wherein the wrapped second key is received in response to transmitting the device identity to the application server.

8. The method of claim 7 , wherein the device identity is a unique serial number for the client device.

9. The method of claim 7 , further comprising:

receiving a message from the application server specifying a policy corresponding to one or more business rules for access to the encrypted media content by the client device; and

setting the policy in response to the message;

wherein the decrypting is performed in accordance with the one or more business rules.

10. The method of claim 9 , further comprising writing data corresponding to the policy to the secure store, in response to the message.

11. The method of claim 9 , wherein the policy corresponds to a license for the client device obtained by the application server from a license server.

12. The method of claim 1 , wherein:

the second key is a content key; and

the client device is configured to unwrap content keys for a plurality of DRM schemes using the first key.

13. A client device, comprising:

one or more processors; and

memory storing one or more programs configured to be executed by the one or more processors, the one or more programs including instructions for:

storing a first key in a secure store of the client device;

receiving a wrapped second key from an application server;

retrieving the first key from the secure store;

using the first key to unwrap the second key;

receiving encrypted media content from the application server;

decrypting the encrypted media content using the unwrapped second key;

decoding the decrypted media content for playback;

transmitting, to a display device that is coupled to the client device, the decrypted media content;

while transmitting, to the display device, the decrypted media content, periodically transmitting the second key to the application server; and

terminating transmission of the encrypted media content by the application server when the second key received by the application server from the client device is not the same as the second key received by the client device from the application server.

14. A non-transitory computer-readable storage medium storing one or more programs for execution by one or more processors of a client device, the one or more programs including instructions for:

storing a first key in a secure store of the client device;

receiving a wrapped second key from an application server;

retrieving the first key from the secure store;

using the first key to unwrap the second key;

receiving encrypted media content from the application server;

decrypting the encrypted media content using the unwrapped second key; and

decoding the decrypted media content for playback;

transmitting, to a display device that is coupled to the client device, the decrypted media content;

while transmitting, to the display device, the decrypted media content, periodically transmitting the second key to the application server; and

terminating transmission of the encrypted media content by the application server when the second key received by the application server from the client device is not the same as the second key received by the client device from the application server.

Assignments (3)
CONFIRMATORY ASSIGNMENT Recorded Mar 26, 2024
From: BROCKMANN, RONALD A
To: ACTIVEVIDEO NETWORKS, LLC
Reel/Frame 066910/0348 →
CONFIRMATORY ASSIGNMENT Recorded Mar 26, 2024
From: HIDDINK, GERRIT WILLEM
To: ACTIVEVIDEO NETWORKS, LLC
Reel/Frame 066910/0484 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2018
From: BROCKMANN, RONALD A.; HIDDINK, GERRIT
To: ACTIVEVIDEO NETWORKS, INC.
Reel/Frame 044954/0103 →
Continuity (2)
Provisional Application 62187140 · Jun 30, 2015
Related Publication 20170005790A1 · Jan 5, 2017