IP Library Granted Patent US 11,032,253
Granted Patent B2
US 11,032,253 · App. 16/534,966 · Granted Jun 8, 2021

Secure application processing systems and methods

Inventors: Gary Ellison (San Mateo, CA); Gilles Boccon-Gibod (San Francisco, CA); Pierre Chavanne (Davis, CA)
Assignee: Intertrust Technologies Corporation
H04L63/0428G06F21/10G06F21/72H04L2463/061H04L2463/101
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,032,253
App. No.
16/534,966
Granted
Jun 8, 2021
Kind
B2
Abstract

Systems and methods are described for securely and efficiently processing electronic content. In one embodiment, a first application running on a first computing system establishes a secure channel with a second computing system, the secure channel being secured by one or more cryptographic session keys. The first application obtains a license from the second computing system via the secure channel, the license being encrypted using at least one of the one or more cryptographic session keys, the license comprising a content decryption key, the content decryption key being further encrypted using at least one of the one or more cryptographic session keys or one or more keys derived therefrom. The first application invokes a second application to decrypt the license using at least one of the one or more cryptographic session keys, and further invokes the second application to decrypt the content decryption key using at least one of the one or more cryptographic session keys or one or more keys derived therefrom, and to decrypt a piece of content using the content decryption key. The first application then provides access to the decrypted piece of content in accordance with the license.

Claims (21)

1. A method performed by a first application running on a first computing system, the method comprising:

invoking a second application running in a secure execution environment separate from an execution environment of the first application to establish a secure channel between the second application and a second computing system, the secure channel being secured by one or more protected cryptographic session keys, wherein the one or more protected cryptographic session keys are not exposed to the first application;

invoking the second application to obtain a license from the second computing system, the license comprising a content decryption key, the content decryption key being further encrypted, at least in part, using at least one of the one or more protected cryptographic session keys;

invoking the second application to decrypt the content decryption key included in the license using, at least in part, at least one of the one or more protected cryptographic session keys; and

receiving access to the piece of content.

2. The method of claim 1 , wherein receiving access to the piece of content comprises receiving the decrypted piece of content from the second application.

3. The method of claim 1 , wherein the license is encrypted using, at least in part, at least one of the one or more protected cryptographic session keys.

4. The method of claim 3 , wherein the method further comprises invoking the second application to decrypt the license using, at least in part, at least one of the one or more protected cryptographic session keys.

5. The method of claim 1 , wherein the one or more protected cryptographic session keys are not exposed to the first application by the second application.

6. The method of claim 1 , wherein the decrypted content decryption key is not exposed to the first application by the second application.

7. The method of claim 1 , wherein the second application executes on the first computing system.

8. The method of claim 1 , wherein the second application comprises a secure key box application.

9. The method of claim 1 , wherein the second application is invoked by the first application via an application programming interface.

10. The method of claim 1 , wherein the second application comprises a firmware application executing on a secure processing unit.

11. The method of claim 1 , wherein the first application comprises a web browser application.

12. The method of claim 1 , wherein the first application comprises a media player application.

13. The method of claim 1 , where the method further comprises receiving, by the first application, a request to access the piece of content.

14. The method of claim 1 , wherein the content decryption key is encrypted using at least one derived key generated based on at least one of the one or more protected cryptographic session keys.

15. The method of claim 14 , wherein invoking the second application to decrypt the content decryption key comprises generating the at least one derived key using at least one of the one or more protected cryptographic session keys and decrypting the content decryption key using the generated at least one derived key.

16. The method of claim 15 , wherein generating the at least one derived key further comprises generating the at least one derived key using secret information shared by the second application and the second computing system.

17. The method of claim 16 , wherein the secret information is not exposed to the first application by the second application.

Assignments (5)
SECURITY INTEREST Recorded Mar 25, 2026
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JAMSTER CAPITAL LLC
Reel/Frame 075228/0345 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 26, 2024
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JERA CO., INC.
Reel/Frame 068173/0212 →
RELEASE OF SECURITY INTEREST Recorded Feb 14, 2023
From: ORIGIN FUTURE ENERGY PTY LTD.
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 062747/0742 →
SECURITY INTEREST Recorded Mar 18, 2020
From: INTERTRUST TECHNOLOGIES CORPORATION
To: ORIGIN FUTURE ENERGY PTY LTD
Reel/Frame 052189/0343 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 7, 2019
From: ELLISON, GARY; BOCCON-GIBOD, GILLES; CHAVANNE, PIERRE
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 049995/0003 →
Continuity (3)
Continuation 14609288 · Jan 29, 2015
Provisional Application 61932994 · Jan 29, 2014
Related Publication 20200045024A1 · Feb 6, 2020