IP Library Granted Patent US 11,843,686
Granted Patent B2
US 11,843,686 · App. 17/004,610 · Granted Dec 12, 2023

Multi-party cryptographic systems and methods

Inventors: Stephen G. Mitchell (Ben Lomond, CA); Vanishree Rao (San Mateo, CA)
Assignee: Intertrust Technologies Corporation
H04L9/006H04L9/008H04L9/0825H04L9/0866H04L2209/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,843,686
App. No.
17/004,610
Granted
Dec 12, 2023
Kind
B2
Abstract

This disclosure relates to systems and methods for performing cryptographic operations in connection with the management of electronic content using multiple license services. In some circumstances, a content service may not wish to share unencrypted content keys with a single license service for a variety of security reasons. Embodiments of the disclosed systems and methods may use multi-party cryptographic methods in connection with the management of protected content keys and/or associated licenses and/or the distribution of content keys and/or licenses to authorized users and/or devices. In various embodiments, a content service may split a content key into a plurality of key shares and may transmit the key shares to a plurality of different license services. The license services may coordinate operations to generate a protected content key without revealing unencrypted content key to any of the participating license services.

Claims (21)

1. A method for managing an electronic content item performed by a first license service system comprising a processor and a non-transitory computer-readable medium storing instructions that, when executed by the processor, cause the first license service system to perform the method, the method comprising:

receiving a public key from a device;

receiving a first padded content key share of a content key and first key identification information associated with the first padded content key share from a content service managing the electronic content item, wherein the first padded content key share comprising a first padding string and wherein the first key identification information identifies that the first padded key share is associated with the content key;

receiving a protected second padded content key share of the content key and second key identification information associated with the protected second padded content key share from a second license service, wherein the protected second padded content key share comprises a second padded content key share of the content key encrypted by the second license service using the public key, wherein the second padded content key share comprises a second padding string and wherein the second key identification information identifies that the second padded key share is associated with the content key;

generating a protected first padded content key share of the content key by encrypting the first padded content key share using the public key;

determining that both the first padded content key share and the second padded key share are associated with the content key based on the first key identification information and the second key identification information respectively;

generating, responsive to the determining, a protected content key by multiplying the protected first padded content key share and the protected second padded content key share, wherein the protected content key comprises the content key encrypted with the public key, wherein generating the protected content key is performed by the first license service system without exposing an unencrypted version of the content key to the first license service system, the first license service system being an untrusted system by the content service and not possessing information which may be used by the first license service system to decrypt the protected content key and access the unencrypted version of the content key, and wherein the first padding string and the second padding string being configured to allow for generation of the protected content key by the first license service system without decrypting the protected first padded content key share and the protected second padded content key share;

and transmitting the protected content key to the device for use in accessing the electronic content item by decrypting the protected content key using a private key corresponding to the public key.

2. The method of claim 1 , wherein the method further comprises receiving a request for a license to access the electronic content item from the device.

3. The method of claim 2 , wherein the method further comprises generating an electronic license for the electronic content item, the electronic license comprising the protected content key.

4. The method of claim 3 , wherein transmitting the protected content key to the device comprises transmitting the electronic license to the device.

5. The method of claim 1 , wherein the first license service is separate from the second license service.

6. The method of claim 1 , wherein the content key comprises a content decryption key associated with the electronic content item.

7. The method of claim 1 , wherein the content key is generated by the content service.

8. The method of claim 1 , wherein the first padded content key share is generated by the content service.

9. The method of claim 1 , wherein the second padded content key share is generated by the content service.

10. The method of claim 1 , wherein the protected content key comprises the content key encrypted with the public key with a homomorphic encryption algorithm.

11. The method of claim 1 , wherein the protected second padded content key share comprises the second padded content key share encrypted by the second license service with the public key using a homomorphic encryption algorithm.

12. The method of claim 1 , wherein the protected content key comprises a protected padded content key.

13. The method of claim 1 , wherein the public key is associated with the device.

14. The method of claim 1 , wherein the public key is associated with a user of the device.

Assignments (5)
SECURITY INTEREST Recorded Mar 25, 2026
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JAMSTER CAPITAL LLC
Reel/Frame 075228/0345 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jul 26, 2024
From: INTERTRUST TECHNOLOGIES CORPORATION
To: JERA CO., INC.
Reel/Frame 068173/0212 →
RELEASE OF SECURITY INTEREST Recorded Feb 14, 2023
From: ORIGIN FUTURE ENERGY PTY LTD.
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 062747/0742 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 29, 2021
From: MITCHELL, STEPHEN G.; RAO, VANISHREE
To: INTERTRUST TECHNOLOGIES CORPORATION
Reel/Frame 056706/0365 →
SECURITY INTEREST Recorded Jun 29, 2021
From: INTERTRUST TECHNOLOGIES CORPORATION
To: ORIGIN FUTURE ENERGY PTY LTD
Reel/Frame 056713/0513 →
Continuity (2)
Provisional Application 62892357 · Aug 27, 2019
Related Publication 20210067315A1 · Mar 4, 2021