IP Library Granted Patent US 9,985,781
Granted Patent B2
US 9,985,781 · App. 15/475,806 · Granted May 29, 2018

Ensuring authenticity in a closed content distribution system

Inventors: John Princen (Cupertino, CA); Pramila Srinivasan (Pleasanton, CA); David Blythe (Kirkland, WA); Wei Yen (Clyde Hill, WA)
Assignee: Acer Cloud Technology, Inc.
H04L9/0891G06F21/105G06F21/602H04L9/0861H04L9/0894H04L9/16H04L9/3247G06F2212/402G06F2221/0704G06F2221/0755H04L2209/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,985,781
App. No.
15/475,806
Granted
May 29, 2018
Kind
B2
Abstract

A technique for maintaining encrypted content received over a network in a secure processor without exposing a key used to decrypt the content in the clear is disclosed.

Claims (47)

1. A method executed by a secure processor of a secure player, the secure player comprising secure memory secured against access outside the secure player and insecure memory, the method comprising:

receiving encrypted content comprising a plurality of data portions in an encrypted format;

receiving a license having a first cryptographic key and a plurality of signatures, the first cryptographic key configured to facilitate first decryption of the encrypted content, and each of the plurality of signatures configured to verify validity of at least one of the plurality of data portions, the license;

performing the first decryption of the encrypted content using the first cryptographic key;

verifying the validity of the plurality of data portions using the plurality of signatures;

generating, in response to verifying the validity, a second cryptographic key to facilitate re-encryption of the encrypted content, the second cryptographic key being independent of the first decryption key;

storing the second cryptographic key in the secure memory;

performing the re-encryption of the encrypted content using the second cryptographic key to obtain re-encrypted content;

storing the re-encrypted content in the insecure memory.

2. The method of claim 1 , wherein the plurality of data portions comprises a plurality of data chunks.

3. The method of claim 1 , further comprising:

determining if verifying the validity of the plurality of data portions fails;

limiting access to the plurality of data portions if verifying the validity of the plurality of data portions fails.

4. The method of claim 1 , wherein verifying the validity of the plurality of data portions comprises performing a run-time verification of the validity of the plurality of data portions.

5. The method of claim 1 , further comprising maintaining an association between the second cryptographic key and the re-encrypted content.

6. The method of claim 1 , further comprising:

maintaining association data between the second cryptographic key and the re-encrypted content;

storing the association data in an external storage external to the secure player.

7. The method of claim 1 , wherein one or more of the first cryptographic key and the second cryptographic key is part of a cryptographic key pair used for the secure player.

8. The method of claim 1 , wherein the encrypted content comprises multimedia content or game content.

9. The method of claim 1 , wherein the encrypted content is received from a dynamic content server configured to dynamically create the encrypted content.

10. The method of claim 1 , wherein the content is encrypted at a content server.

11. A secure player comprising:

secure memory;

insecure memory;

a secure processor coupled to the secure memory and the insecure memory, the secure processor configured to execute a computer-implemented method, the computer-implemented method comprising:

receiving encrypted content comprising a plurality of data portions in an encrypted format;

receiving a license having a first cryptographic key and a plurality of signatures, the first cryptographic key configured to facilitate first decryption of the encrypted content, and each of the plurality of signatures configured to verify validity of at least one of the plurality of data portions, the license;

performing the first decryption of the encrypted content using the first cryptographic key;

verifying the validity of the plurality of data portions using the plurality of signatures;

generating, in response to verifying the validity, a second cryptographic key to facilitate re-encryption of the encrypted content, the second cryptographic key being independent of the first decryption key;

storing the second cryptographic key in the secure memory;

performing the re-encryption of the encrypted content using the second cryptographic key to obtain re-encrypted content;

storing the re-encrypted content in the insecure memory.

12. The secure player of claim 11 , wherein the plurality of data portions comprises a plurality of data chunks.

13. The secure player of claim 11 , wherein the computer-implemented method further comprises:

determining if verifying the validity of the plurality of data portions fails;

limiting access to the plurality of data portions if verifying the validity of the plurality of data portions fails.

14. The secure player of claim 11 , wherein verifying the validity of the plurality of data portions comprises performing a run-time verification of the validity of the plurality of data portions.

15. The secure player of claim 11 , further comprising maintaining an association between the second cryptographic key and the re-encrypted content.

16. The secure player of claim 11 , wherein the computer-implemented method further comprises:

maintaining association data between the second cryptographic key and the re-encrypted content;

storing the association data in an external storage external to the secure player.

17. The secure player of claim 11 , wherein one or more of the first cryptographic key and the second cryptographic key is part of a cryptographic key pair used for the secure player.

18. The secure player of claim 11 , wherein the encrypted content comprises multimedia content or game content.

19. The secure player of claim 11 , wherein the encrypted content is received from a dynamic content server configured to dynamically create the encrypted content.

20. The secure player of claim 11 , wherein the content is encrypted at a content server.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 26, 2021
From: ACER CLOUD TECHNOLOGY INC.
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 055029/0142 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 31, 2017
From: PRINCEN, JOHN; SRINIVASAN, PRAMILA; BLYTHE, DAVID; YEN, WEI
To: BROADON COMMUNICATIONS CORP.
Reel/Frame 041811/0519 →
CHANGE OF NAME Recorded Mar 31, 2017
From: BROADON COMMUNICATIONS CORP.
To: IGWARE INC.
Reel/Frame 042127/0681 →
MERGER Recorded Mar 31, 2017
From: IGWARE INC.
To: ACER CLOUD TECHNOLOGY, INC.
Reel/Frame 042127/0780 →
Continuity (5)
Continuation 15131883 · Apr 18, 2016
Continuation 12507050 · Jul 21, 2009
Continuation In Part 10463224 · Jun 16, 2003
Continuation In Part 10360827 · Feb 7, 2003
Related Publication 20170230176A1 · Aug 10, 2017