IP Library Granted Patent US 12,353,519
Granted Patent B2
US 12,353,519 · App. 16/837,854 · Granted Jul 8, 2025

Digital rights management authorization token pairing

Inventor: Karl M. Gallagher (Londonderry, GB)
Assignee: ARRIS Enterprises LLC
G06F21/105H04L9/3213H04L9/3263H04N21/835
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,353,519
App. No.
16/837,854
Filed
Apr 1, 2020
Granted
Jul 8, 2025
Kind
B2
Examiner
ASGARI, SIMA
Art Unit
3698
USPC
705/59
Abstract

A method and apparatus for providing a license to a client device, the license providing a key for decrypting a content instance. In one embodiment, the method comprises accepting a license request, the license request including a client identifier and an access token having an access token identifier and key request data comprising a content identifier identifying the content instance, determining if the received access token identifier is currently bound to a stored client device identifier, and temporarily binding the received access token identifier with the received client device identifier and providing the received access token for validation or returning an error without providing the received access token for validation depending upon the determination.

Claims (57)

1. A method of providing a key to a client device for decrypting and displaying a content instance on the client device, the method comprising:

receiving a request from the client device, the request including a client device identifier and an access token having an access token identifier and key request data comprising a content identifier identifying the content instance;

determining that the received access token identifier is currently not bound to a stored client device identifier;

based upon the determination, modifying the access token to temporarily bind the received access token identifier with the received client device identifier and providing the modified access token to a token validator for validation; and

upon validation by the token validator, delivering the key to the client device.

2. The method of claim 1 , further comprising:

determining if the received access token has been validated;

if the received access token has not been validated, returning an error without providing the key; and

if the received access token has been validated, returning the key for decrypting the content instance identified by the content identifier.

3. The method of claim 2 , wherein binding the received access token identifier with the received client device identifier and providing the received access token for validation comprises:

temporarily binding the received access token identifier with the received client device identifier and providing the received access token for validation.

4. The method of claim 3 , wherein:

binding the received access token identifier with the received client device identifier comprises associatively storing the received access token identifier and the received client device identifier.

5. The method of claim 4 , wherein:

the key is characterized at least in part by a maximum temporal key duration; and

the received access token identifier is bound with the received client device identifier for only the maximum temporal key duration.

6. The method of claim 4 , wherein the received access token identifier and the received client device identifier are associatively stored in a first-in-first-out (FIFO) memory cache.

7. The method of claim 4 , wherein the received access token is a JavaScript object notation (JSON) access token appended to a license request.

8. The method of claim 7 , wherein:

the JSON access token includes a signature of data including at least access token identifier; and

the method further comprises

verifying the token identifier according to the signature; and

returning the error to the client device if the token identifier is not verified.

9. The method of claim 1 , wherein:

binding the received access token identifier with the received client device identifier and providing the received access token for validation or returning an error without providing the received access token for validation depending upon the determination comprises:

if the received access token identifier is not currently bound to a stored client device identifier:

temporarily binding the received access token identifier with the received client device identifier and providing the received access token for validation;

if the received access token identifier is currently bound to a stored client device identifier:

determining if the received access token identifier is currently bound to a different client device identifier than the received client device identifier of the license request;

if the received access token identifier is currently bound to a different client device identifier than the received client device identifier of the license request, returning an error without providing the received access token for validation; and

if the received access token identifier is currently bound to the received client device identifier of the license request, providing the received access token for validation.

10. An apparatus for providing a key to a client device for decrypting a content instance on the client device, the method comprising:

a processor;

a memory, communicatively coupled to the processor, the memory comprising processor instructions including processor instructions for:

receiving a request from the client device, the request including a client device identifier and an access token having an access token identifier and key request data comprising a content identifier identifying the content instance;

determining that the received access token identifier is currently not bound to a stored client device identifier;

based upon the determination, modifying the access token to temporarily bind binding the received access token identifier with the received client device identifier and providing the modified access token to a token validator for validation; and

upon validation by the token validator, delivering the key to the client device.

11. The apparatus of claim 10 , further comprising:

determining if the received access token has been validated;

returning an error without providing the key if the received access token has not been validated; and

returning the key for decrypting the content instance identified by the content identifier if the received access token has been validated.

12. The apparatus of claim 11 , wherein the instructions for binding the received access token identifier with the received client device identifier and providing the received access token for validation comprise instructions for:

temporarily binding the received access token identifier with the received client device identifier and providing the received access token for validation.

13. The apparatus of claim 12 , wherein:

the instructions for binding the received access token identifier with the received client device identifier comprise instructions for associatively storing the received access token identifier and the received client device identifier.

14. The apparatus of claim 13 , wherein:

the key is characterized at least in part by a maximum temporal key duration; and

the received access token identifier is bound with the received client device identifier for only the maximum temporal key duration.

15. The apparatus of claim 13 , wherein the received access token identifier and the received client device identifier are associatively stored in a first-in-first-out (FIFO) memory cache.

16. The apparatus of claim 13 , wherein the received access token is a JavaScript object notation (JSON) access token appended to a license request.

17. The apparatus of claim 10 , wherein:

the instructions for binding the received access token identifier with the received client device identifier and providing the received access token for validation or returning an error without providing the received access token for validation depending upon the determination comprises:

temporarily binding the received access token identifier with the received client device identifier and providing the received access token for validation if the received access token identifier is not currently bound to a stored client device identifier;

determining if the received access token identifier is currently bound to a different client device identifier than the received client device identifier of the license request if the received access token identifier is currently bound to a stored client device identifier;

returning an error without providing the received access token for validation if the received access token identifier is currently bound to a different client device identifier than the received client device identifier of the license request; and

providing the received access token for validation if the received access token identifier is currently bound to the received client device identifier of the license request.

Assignments (8)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058843/0712 Recorded Jan 12, 2026
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC; COMMSCOPE NORTH CAROLINA, LLC (F/K/A COMMSCOPE, INC. OF NORTH CAROLINA); COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 074591/0389 →
RELEASE OF SECURITY INTEREST AT REEL/FRAME 058875/0449 Recorded Dec 19, 2024
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: ARRIS ENTERPRISES LLC (F/K/A ARRIS ENTERPRISES, INC.); COMMSCOPE, INC. OF NORTH CAROLINA; COMMSCOPE TECHNOLOGIES LLC
Reel/Frame 069743/0057 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 1, 2023
From: GALLAGHER, KARL M.
To: ARRIS ENTERPRISES LLC
Reel/Frame 065428/0486 →
SECURITY INTEREST Recorded Nov 19, 2021
From: ARRIS SOLUTIONS, INC.; ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA; RUCKUS WIRELESS, INC.
To: WILMINGTON TRUST
Reel/Frame 060752/0001 →
ABL SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058843/0712 →
TERM LOAN SECURITY AGREEMENT Recorded Nov 15, 2021
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE, INC. OF NORTH CAROLINA
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 058875/0449 →
Continuity (2)
Provisional Application 62828737 · Apr 3, 2019
Related Publication 20200320178A1 · Oct 8, 2020
References Cited (15)
US 9614829B1 · Molina-Markham · 2017 [cited by examiner]
US 10356053B1 · Zubovsky · 2019 [cited by examiner]
US 11303627B2 · Maria · 2022 [cited by examiner]
US 20100185869A1 · Moore et al. · 2010 [cited by applicant]
US 20130152221A1 · Yin et al. · 2013 [cited by applicant]
US 20130167253A1 · Seleznev et al. · 2013 [cited by applicant]
US 20140047566A1 · Kidron · 2014 [cited by applicant]
US 20160077901A1 · Roth et al. · 2016 [cited by applicant]
US 20160077902A1 · Feng et al. · 2016 [cited by applicant]
US 20170111338A1 · Malatesha · 2017 [cited by examiner]
US 20170192803A1 · Martori et al. · 2017 [cited by applicant]
US 20180115544A1 · Feng · 2018 [cited by examiner]
US 20190052621A1 · Sahraei · 2019 [cited by examiner]
PCT International Search Report & Written Opinion, RE: Application No. PCT/US2020/026239 dated Jun. 29, 2020. [cited by applicant]
Search Report in European Patent Application No. 20785168.4-1218, dated Nov. 25, 2022. [cited by applicant]