IP Library › Granted Patent US 10,333,978
Granted Patent B2
US 10,333,978 · App. 15/368,047 · Granted Jun 25, 2019

Communication system, user apparatus, content source and method for secure content delivery

Inventor: Sven van den Berghe (Marlow Bucks, GB)
Assignee: FUJITSU LIMITED
H04L63/18G06F21/606G06F21/64H04L9/0825H04L63/0428H04L63/0442H04L63/083H04L65/607H04L67/10H04L67/2842
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,333,978
App. No.
15/368,047
Filed
Dec 2, 2016
Granted
Jun 25, 2019
Kind
B2
Examiner
ALATA, AYOUB
Art Unit
2494
USPC
713/171
Abstract

A user apparatus configured to request and receive data divided into chunks from a content source over a network, the apparatus comprising: a network module configured to establish a secure path to the content source and to establish an unsecure path to the content source; a determination module configured to determine that a next chunk of data is required and to determine whether the next chunk of data is protected; and a request module configured to request and receive the next chunk of data, wherein the next chunk of data is requested and received via the unsecure path if or when the next chunk of data is unprotected.

Claims (92)

1. A user apparatus configured to request and receive data divided into chunks from a content source over a network, the user apparatus comprising:

a memory and a processor configured to:

establish a secure path to the content source and establish an unsecure path to the content source;

determine that a next chunk of data is required and determine, using a streaming protocol, whether the next chunk of data is marked as one of protected and unprotected;

request and receive the next chunk of data, wherein the next chunk of data is requested and received via the unsecure path when the next chunk of data is marked as unprotected;

request authorization from the content source via the secure path;

receive an authorization token from the content source via the secure path when the authorization is given by the content source; and

request and receive a chunk of data marked as protected via the unsecure path using the authorization token, wherein the authorization token is useable to limit access to the chunk of data marked as protected based on at least one of a time and a location of one or more users defined in association with the authorization token.

2. The user apparatus according to claim 1 , wherein the next chunk of data is requested and received via the secure path when the next chunk of data is marked as protected.

3. The user apparatus according to claim 1 , wherein, when the authorization is given by the content source, the processor is configured to negotiate a public key and a private key pair with the content source, and

the processor is configured to:

request and receive chunks of data encrypted using the public key; and

decrypt received encrypted chunks of data using the private key.

4. The user apparatus according to claim 1 , wherein the streaming protocol includes a list of chunks of data marked as protected.

5. The user apparatus according to claim 1 , wherein the processor is configured to request the next chunk of data via the secure path when an error message is received when the next chunk of data is requested via the unsecure path.

6. The user apparatus according to claim 1 , wherein the processor is configured to receive a content hash key from the content source via the secure path and, when a chunk of data is received via the unsecure path, to check integrity of the received chunk of data using the content hash key.

7. The user apparatus according to claim 1 , wherein the data comprises encoded chunks of data and one or more decoding tables, and the one or more decoding tables are chunks of data marked as protected and the encoded chunks of data are chunks of data marked as unprotected.

8. A method, in a user apparatus, of requesting and receiving data divided into chunks from a content source over a network, the method comprising:

establishing a secure path to the content source and establishing an unsecure path to the content source;

determining that a next chunk of data is required and determining, using a streaming protocol, whether the next chunk of data is marked as one of protected and unprotected;

requesting and receiving the next chunk of data, wherein the next chunk of data is requested and received via the unsecure path when the next chunk of data is marked as unprotected;

requesting authorization from the content source via the secure path;

receiving an authorization token from the content source via the secure path when the authorization is given by the content source; and

requesting and receiving a chunk of data marked as protected via the unsecure path using the authorization token, wherein the authorization token is useable to limit access to the chunk of data marked as protected based on at least one of a time and a location of one or more users defined in association with the authorization token.

9. A content source apparatus configured to deliver data to a user, the content source apparatus comprising:

a memory and a processor configured to:

establish a secure path to the user and to establish an unsecure path to the user;

split the data into two or more chunks;

mark chunks of data as one of protected and unprotected; and

receive a request for a chunk of data of the marked chunks of data and transmit the chunk of data, wherein the chunk of data being transmitted via the unsecure path when the chunk of data is marked as unprotected:

receive an authorization request from the user via the secure path;

authorize the user by transmitting an authorization token to the user via the secure path; and

transmit a protected chunk of data via the unsecure path when the protected chunk of data is requested using the authorization token, wherein the authorization token is useable to limit access to the protected chunk of data based on at least one of a time and a location of the user defined in association with the authorization token.

10. The content source apparatus according to claim 9 , wherein the secure path through which the authorization request is received from the user and through which the authorization token is transmitted to the user is different than the unsecure path through which the protected chunk of data is transmitted.

11. The content source apparatus according to claim 10 , wherein, when the authorization is given, the processor is configured to:

negotiate a public key and a private key pair with the user;

encrypt the chunk of data using the public key; and

transmit the encrypted chunk of data via the unsecure path when requested using the public key.

12. The content source apparatus according to claim 9 , wherein the processor is configured to simultaneously receive requests for and transmit the chunks of data via the secure path and the unsecure path.

13. The content source apparatus according to claim 9 , wherein the processor is configured to transmit a content hash key for checking integrity of the chunk of data to the user via the secure path.

14. The content source apparatus according to claim 9 , wherein the processor is configured to perform one or more of:

marking all low importance chunks of data as unprotected; and

marking all high importance chunks of data as protected.

15. The content source apparatus according to claim 14 , wherein the processor is further configured to mark, chunks of data that have not been marked as protected or marked as unprotected, some of the chunks of data as protected and any remaining chunks of data as unprotected.

16. A method in a content source apparatus of delivering data to a user, the method comprising:

establishing a secure path to the user and establishing an unsecure path to the user;

splitting the data into two or more chunks;

marking chunks of data as one of protected and unprotected; and

receiving a request for a chunk of data of the marked chunks of data and transmitting the chunk of data, wherein the chunk of data being transmitted via the unsecure path when the chunk of data is marked as unprotected;

receiving an authorization request from the user via the secure path;

authorizing the user by transmitting an authorization token to the user via the secure path; and

transmitting a protected chunk of data via the unsecure path when the protected chunk of data is requested using the authorization token, wherein the authorization token is useable to limit access to the protected chunk of data based on at least one of a time and a location of the user defined in association with the authorization token.

17. A communications system comprising:

a user apparatus; and

a content source apparatus comprises a memory and processor, the content source apparatus being connected to the user apparatus via a secure path and via an unsecure path, the content source apparatus is configured to:

split data into two or more chunks of data,

mark the two or more chunks of data as one of protected and unprotected,

receive a request for a chunk of data from the user apparatus and deliver the chunk of data to the user apparatus,

receive an authorization request from the user apparatus via the secure path, and

authorize the user apparatus by transmitting an authorization token to the user apparatus via the secure path; and

the user apparatus is configured to:

determine, using a streaming protocol, whether a next chunk of data is required and to determine whether the next chunk of data is marked as one of protected and unprotected,

request and receive the next chunk of data via the unsecure path when the next chunk of data is marked as unprotected,

request authorization from the content source via the secure path,

receive an authorization token from the content source via the secure path when the authorization is given by the content source, and

request and receive a chunk of data marked as protected via the unsecure path using the authorization token, wherein the authorization token is useable to limit access to the chunk of data marked as protected based on at least one of a time and a location of one or more users defined in association with the authorization token.

18. The communications system according to claim 17 , wherein the unsecure path includes a cache to cache one or more chunks of data and the user apparatus is connected to the content source apparatus via the cache, and

wherein the cache is configured to request and receive chunks of data that are not marked as protected from the content source apparatus and to transmit the chunks of data to the user apparatus in response to the request from the user apparatus.

19. A method for use in a communications system, comprising:

splitting, by a content source, data into two or more chunks of data, and marking the two or more chunks of data as one of protected and unprotected;

receiving a request for a chunk of data from a user and delivering the chunk of data to the user;

receiving an authorization request from the user via the secure path, and authorizing the user by transmitting an authorization token to the user via the secure path; and

enabling the user to determine whether a next chunk of data is required and whether the next chunk of data is marked as one of protected and unprotected using a streaming protocol;

requesting and receiving the next chunk of data via an unsecure path when the next chunk of data is marked as unprotected;

requesting authorization from the content source via the secure path;

receiving an authorization token from the content source via the secure path when the authorization is given by the content source; and

requesting and receiving a chunk of data marked as protected via the unsecure path using the authorization token, wherein the authorization token is useable to limit access to the chunk of data marked as protected based on at least one of a time and a location of the user defined in association with the authorization token.

20. A non-transitory computer readable storage medium storing a method for a user apparatus of requesting and receiving data divided into chunks from a content source over a network, the method comprising:

establishing a secure path to the content source and establishing an unsecure path to the content source;

determining that a next chunk of data is required and determining, using a streaming protocol, whether the next chunk of data is marked as one of protected and unprotected; and

requesting and receiving the next chunk of data, wherein the next chunk of data is requested and received via the unsecure path when the next chunk of data is marked as unprotected;

requesting authorization from the content source via the secure path;

receiving an authorization token from the content source via the secure path when the authorization is given by the content source; and

requesting and receiving a chunk of data marked as protected via the unsecure path using the authorization token, wherein the authorization token is useable to limit access to the chunk of data marked as protected based on at least one of a time and a location of one or more users defined in association with the authorization token.

21. A method in a user apparatus of requesting and receiving data divided into chunks from a content source over a network, the method comprising:

establishing a secure path to the content source and establishing an unsecure path to the content source;

establishing a cache at an edge of the network in the unsecure path;

determining that a next chunk of data is required and determining, using a streaming protocol, whether the next chunk of data is marked as one of protected and unprotected; and

requesting and receiving the next chunk of data, wherein the next chunk of data is requested and received from the cache via the unsecure path when the next chunk of data is marked as unprotected,

requesting authorization from the content source via the secure path;

receiving an authorization token from the content source via the secure path when the authorization is given by the content source; and

requesting and receiving a chunk of data marked as protected via the unsecure path using the authorization token source, wherein the authorization token is useable to limit access to the protected chunk of data marked as protected based on at least one of a time and a location of one or more users defined in association with the authorization token.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2016
From: VAN DER BERGHE, SVEN
To: FUJITSU LIMITED
Reel/Frame 040532/0237 →
Priority Claims (1)
GB 1521551 · Dec 7, 2015 · national
Continuity (1)
Related Publication 20170163683A1 · Jun 8, 2017