IP Library Granted Patent US 12,244,881
Granted Patent B2
US 12,244,881 · App. 17/973,138 · Granted Mar 4, 2025

Method and system for secure over-the-top live video delivery

Inventors: Kevin J. Ma (Nashua, NH); Robert Hickey (Bedford, MA); Paul Tweedale (Andover, MA)
Assignee: Telefonaktiebolaget LM Ericsson (publ)
H04N21/2541G11B27/10H04L9/0819H04L9/0891H04L9/14H04L63/0428H04N21/2347H04N21/2387H04N21/2393H04N21/42623H04N21/4627H04N21/63345H04N21/8456H04L2209/24H04L2209/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,244,881
App. No.
17/973,138
Granted
Mar 4, 2025
Kind
B2
Abstract

A method is provided for managing key rotation (use of series of keys) and secure key distribution in over-the-top content delivery. The method provided supports supplying a first content encryption key to a content packaging engine for encryption of a first portion of a video stream. Once the first content encryption key has expired, a second content encryption key is provided to the content packaging engine for encryption of a second portion of a video stream. The method further provides for notification of client devices of imminent key changes, as well as support for secure retrieval of new keys by client devices. A system is also specified for implementing a client and server infrastructure in accordance with the provisions of the method.

Claims (29)

1. A method for managing secure distribution of audio or video content, comprising:

generating a series of content encryption keys for encrypting a single audio or video content item, each content encryption key associated with a different portion of the single audio or video content item wherein client devices requesting the single audio or video content item is further provided with key expiration information usable by the client devices to identify transitions between portions of the single audio or video content item that use different ones of the content encryption keys; and

providing the content encryption keys to a license server for delivery to the client devices for use in decrypting the content item, the license server being operative to establish that a requesting client device is authorized to access the content item, the license server being further operative to securely deliver the content encryption keys to a requesting client device whose authorization to access the content item has been established.

2. The method of claim 1 , wherein the client device is notified at session initiation of a target fixed period for content key expiration.

3. The method of claim 1 , wherein the client device is notified in real time of content key expiration.

4. The method of claim 3 , wherein the key expiration information is provided to the client device by inserting a key change notification into a content encryption metadata header as part of the unencrypted portion of the encrypted file, the content encryption metadata header.

5. The method of claim 3 , wherein the key expiration information is provided to the client device by inserting a key change notification into a content manifest file accessible to the client devices, the content manifest file being selected from an m3u8 file, an IIS Smooth Streaming manifest file, a DASH MPD file and a proprietary manifest file.

6. The method of claim 3 , wherein the key expiration information is provided to the client device by inserting a key change notification into the file name of the segment files being generated.

7. The method of claim 1 , wherein the license server distributes content encryption keys and content encryption key expiration information to client devices using a secure channel.

8. The method of claim 7 , wherein the secure channel is secured using a selected one of Secure Sockets Layer and a token-based technique using a token encrypted with a symmetric key.

9. The method of claim 1 , wherein the license server sends content encryption keys and expiration information only in response to requests from the client devices.

10. The method of claim 1 , wherein the license server is operative when establishing that a requesting client device is authorized to access the content item to verify client device identity and content access rights before returning content encryption key or expiration information.

11. A computerized device operable as a workflow manager for managing secure distribution of audio or video content, comprising:

memory operative to store computer program instructions;

one or more processors;

input/output interface circuitry; and

interconnect circuitry coupling the memory, processors and input/output interface circuitry together,

wherein the processors are operative to execute the computer program instructions from the memory to cause the computerized device to:

generate a series of content encryption keys for encrypting a single audio or video content item, each content encryption key associated with a different portion of the single audio or video content item wherein client devices requesting the single audio or video content item is further provided with key expiration information usable by the client devices to identify transitions between portions of the single audio or video content item that use different ones of the content encryption keys; and

provide the content encryption keys to a license server for delivery to the client devices for use in decrypting the content item, the license server being operative to establish that a requesting client device is authorized to access the content item, the license server being further operative to securely deliver the content encryption keys to a requesting client device whose authorization to access the content item has been established.

12. The computerized device of claim 11 , wherein the client device is notified at session initiation of a target fixed period for content key expiration.

13. The computerized device of claim 11 , wherein the client device is notified in real time of content key expiration.

14. The computerized device of claim 11 , wherein the key expiration information is provided to the client device by inserting a key change notification into a content encryption metadata header as part of the unencrypted portion of the encrypted file, the content encryption metadata header.

15. The computerized device of claim 11 , wherein the key expiration information is provided to the client device by inserting a key change notification into a content manifest file accessible to the client devices, the content manifest file being selected from an m3u8 file, an IIS Smooth Streaming manifest file, a DASH MPD file and a proprietary manifest file.

16. The computerized device of claim 15 , wherein the key expiration information is provided to the client device by inserting a key change notification into the file name of the segment files being generated.

17. The computerized device of claim 11 , wherein the license server distributes content encryption keys and content encryption key expiration information to client devices using a secure channel.

18. The computerized device of claim 17 , wherein the secure channel is secured using a selected one of Secure Sockets Layer and a token-based technique using a token encrypted with a symmetric key.

19. The computerized device of claim 11 , wherein the license server sends content encryption keys and expiration information only in response to requests from the client devices.

20. The computerized device of claim 11 , wherein the license server is operative when establishing that a requesting client device is authorized to access the content item to verify client device identity and content access rights before returning content encryption key or expiration information.

Continuity (8)
Continuation 17388389 · Jul 29, 2021
Continuation 16672463 · Nov 3, 2019
Continuation 15910911 · Mar 2, 2018
Continuation 15067219 · Mar 11, 2016
Continuation 14266368 · Apr 30, 2014
Continuation 13530997 · Jun 22, 2012
Provisional Application 61500316 · Jun 23, 2011
Related Publication 20230042354A1 · Feb 9, 2023
References Cited (75)
US 7010808B1 · Leung et al. · 2006 [cited by applicant]
US 7995755B2 · Duval · 2011 [cited by applicant]
US 8677428B2 · Lewis et al. · 2014 [cited by applicant]
US 8756673B2 · Barrus et al. · 2014 [cited by applicant]
US 8789196B2 · Pestoni et al. · 2014 [cited by applicant]
US 8806050B2 · Chen et al. · 2014 [cited by applicant]
US 9697363B1 · Dorwin · 2017 [cited by applicant]
US 20020012432A1 · England et al. · 2002 [cited by applicant]
US 20020172368A1 · Peterka · 2002 [cited by applicant]
US 20040105549A1 · Suzuki et al. · 2004 [cited by applicant]
US 20050060316A1 · Kamath · 2005 [cited by applicant]
US 20050138362A1 · Kelly · 2005 [cited by applicant]
US 20060026293A1 · Virdi et al. · 2006 [cited by applicant]
US 20070033399A1 · Takeda · 2007 [cited by applicant]
US 20070038857A1 · Gosnell · 2007 [cited by examiner]
US 20080267398A1 · Peterka · 2008 [cited by applicant]
US 20080270308A1 · Peterka · 2008 [cited by applicant]
US 20090132823A1 · Grimen et al. · 2009 [cited by applicant]
US 20090254708A1 · Bairaj · 2009 [cited by applicant]
US 20100235528A1 · Bocharov et al. · 2010 [cited by applicant]
US 20110067012A1 · Eisen · 2011 [cited by applicant]
US 20110099594A1 · Chen · 2011 [cited by applicant]
US 20110231660A1 · Kanungo · 2011 [cited by applicant]
US 20110311044A1 · Westerveld et al. · 2011 [cited by applicant]
US 20120047542A1 · Lewis et al. · 2012 [cited by applicant]
US 20120114118A1 · Verma · 2012 [cited by applicant]
US 20120124612A1 · Adimatyam et al. · 2012 [cited by applicant]
US 20120174150A1 · Reddy et al. · 2012 [cited by applicant]
US 20120246462A1 · Moroney et al. · 2012 [cited by applicant]
US 20120254456A1 · Visharam · 2012 [cited by applicant]
US 20120331293A1 · Ma et al. · 2012 [cited by applicant]
US 20130129095A1 · Fahrny et al. · 2013 [cited by applicant]
EP 1418756A2 · 2004 [cited by applicant]
JP 2004166153A · 2004 [cited by applicant]
WO 2010107625A2 · 2010 [cited by applicant]
WO 2010108053A1 · 2010 [cited by applicant]
WO 2010111261A1 · 2010 [cited by applicant]
WO 2011020088A1 · 2011 [cited by applicant]
Microsoft, Using Silverlight DRM, Powered by PlayReady, with Windows Media DRM Content , Microsoft Corporation, Nov. 2008. [cited by applicant]
R. Pantos et al., HTTP Live Streaming draft-pantos-http-live-streaming-06, Mar. 31, 2011, http://tools.ietf.org/html/draft-pantos-http-live-streaming-06. [cited by applicant]
Declaration of Aviel Rubin, Ph. D., IPR 2022-00618. [cited by applicant]
Joint Motion to Terminate Proceeding, IPR 2022-00618. [cited by applicant]
Patent Owner Response, IPR 2022-00618. [cited by applicant]
Patent Owner's Contingent Motion to Amend, IPR 2022-00618. [cited by applicant]
Patent Owner's Preliminary Response, IPR 2022-00618. [cited by applicant]
Petition for Inter Partes Review of U.S. Pat. No. 9,313,178 Pursuant to 25 U.S.C. § §311-319, 37 C.F.R. § 42. IPR 2022-00618. [cited by applicant]
PTAB Decision, Granting of Inter Partes Review 35 U.S.C. §314. IPR 2022-00618. [cited by applicant]
PTAB's Termination Decision, IPR 2022-00618. [cited by applicant]
“3rd Generation Partnership Project; Technical Specification Group Services and System Aspects; Transparent end-to-end Packet-switched Streaming Service (PSS); Protocols and codecs (Release 9)”, Technical Specification,… [cited by applicant]
“Analysis of Netflix's security framework for Watch Instantly service”, Pomelo, LLC Tech Memo, Mar.-Apr. 2009, 18 Pages. [cited by applicant]
Apple Inc., “Http Live Streaming Overview”, Apple Inc., Apr. 1, 2011, 36 Pages. [cited by applicant]
Carrara, E., et al., “The Key ID Information Type for the General Extension Payload in Multimedia Internet KEYing (MIKEY)”, Network Working Group, Request for Comments: 4563, Category: Standards Track, Jun. 2006, 10 Pag… [cited by applicant]
Chow, S., et al., “A White-Box DES Implementation for DRM Applications*”, Pre-proceedings for ACM DRM-2002 workshop, Oct. 15, 2022, 16 Pages. [cited by applicant]
Diehl, E., “Securing Digital Video: Techniques for DRM and Content Protection”, ISBN-10 : 9783642173448, Springer; 2012th edition, Jun. 28, 2012, 276 pages. [cited by applicant]
Fecheyr-Lippens, A., “A Review of HTTP Live Streaming”, Jan. 2010, http://files.andrewsblog.org/ http_live_streaming.pdf, 30 Pages. [cited by applicant]
Fielding, R., et al.,“ Hypertext Transfer Protocol--HTTP/1.1”, Network Working Group, Request for Comments: 2616, Obsoletes: 2068, Category: Standards Track, Jun. 1999, 114 Pages. [cited by applicant]
Freier, A., et al., “The SSL Protocol”, Version 3.0, https://web.archive.org/web/19970614041044/http://home.netscape.com/eng/ss/3/ssl-toc.html, Mar. 1996, 27 Pages. [cited by applicant]
Guidelines for Implementation: DASH-AVC/264 Interoperability Points , DASH Industry Forum, Version 2.0, Aug. 15, 2013, 47 Pages. [cited by applicant]
HBBTV, “HbbTV@ Specification Version 1.5”, HbbTV, Mar. 16, 2012, 24 Pages. [cited by applicant]
Held, G., “A Practical Guide to Content Delivery Networks”, CRC Press, Oct. 12, 2010, Chapters 1 and 2 pp. 1-82. Only bibliographic information provided. [cited by applicant]
In the Matter of Certain Electronic Devices, Including Mobile Phones, Tablets, Laptops, Components Thereof, and Products Containing the Same, Inv. No. 337-TA-1376, Complaint, Exhibit 28 (Oct. 12, 2023), 39 Pages. [cited by applicant]
In the Matter of Certain Electronic Devices, Including Mobile Phones, Tablets, Laptops, Components Thereof, and Products Containing the Same, Inv. No. 337-TA-1376, Order No. 25 (Mar. 13, 2024), 35 Pages. [cited by applicant]
Information Sciences Institute, “Transmission Control Protocol, Darpa Internet Program, Protocol Specification”, RFC: 793, Sep. 1981, 91 Pages. [cited by applicant]
International Standard, “Information technology—MPEG systems technologies—Part 7: Common encryption in SO base media file format files Amendment 1: AES-CBC-128 and key rotation”, ISO/IEC 23001-7, First edition 2012-02-0… [cited by applicant]
Kurose, J., et al., “Computer Networking: A Top-Down Approach Featuring the Internet”, file:///D|/Downloads/Livros/ computação/Computer%20Netw . . . 20Approach%20Featuring%20the%20Internet/Contents-1.htm (1 of 4)Nov. 20… [cited by applicant]
Lancker, W., et al., “Http Adaptive Streaming With Media Fragment Uris”, 2011 IEEE International Conference on Multimedia and Expo, Jul. 11-15, 2011, 6 Pages. [cited by applicant]
Menezes, A., et al., “Handbook of Applied Cryptography,” ISBN:978-0-8493-8523-0, Publisher: CRC Press, Inc. Subs. of Times Mirror 2000 Corporate Blvd. NW Boca Raton, FL United States, Published:Oct. 1, 1996, 794 Pages. [cited by applicant]
Paar, C., et al., Understanding Cryptography, A Textbook for Students and Practitioners, ISBN-10: 3642446493, Publisher: Springer; 2010th edition (Nov. 8, 2014), 382 Pages. [cited by applicant]
Pantos, R., “Http Live Streaming draft-pantos-http-live-streaming-00”, Informational Internet-Draft Intended status: Informational Expires: Nov. 2, 2009, May 1, 2009, 17 Pages. [cited by applicant]
Pantos, R., et al., “HTTP Live Streaming draft-pantos-http-live-streaming-06”, Informational Internet-Draft Intended status: Informational Expires: Oct. 2, 2011, Mar. 31, 2011, 24 Pages. [cited by applicant]
Pierce, B., “Types and Programming Languages”, The MIT Press @, ISBN:0262162091, Feb. 1, 2002, Chapters 1 & 5, 625 Pages. [cited by applicant]
Schneier, B., “Applied Cryptography Protocols, Algorithms, and Source Code”, John Wiley & Sons Inc; 2nd edition, Oct. 18, 1996, ISBN-10:9780471117094, Chapters 1, 3, 4, 7, 8 and 10. Only providing bibliographic informat… [cited by applicant]
Stockhammer, T., “Dynamic Adaptive Streaming over HTTP—Standards and Design Principles”, MMSys '11: Proceedings of the second annual ACM conference on Multimedia systems https://doi.org/10.1145/1943552.1943572, Feb. 23,… [cited by applicant]
Wang, J., et al., “On Modeling Capacity and Responsiveness of HTTP Streaming”, 2011 International Conference on Computer Science and Service System (CSSS), Jun. 27-29, 2011, 5 Pages. [cited by applicant]
Yuan, C., et al., “Layered access control for MPEG-4 Fgs video”, Proceedings 2003 International Conference on Image Processing (Cat. No.03CH37429), Sep. 14-17, 2003, 4 Pages. [cited by applicant]