IP Library Granted Patent US 10,104,342
Granted Patent B2
US 10,104,342 · App. 14/133,050 · Granted Oct 16, 2018

Techniques for secure provisioning of a digital content protection scheme

Inventors: Akshat Nanda (El Dorado Hills, CA); Changliang Wang (Bellevue, WA); Scott W. Cheng (Folsom, CA); Michael L. Coulter (Chandler, AZ)
Assignee: INTEL CORPORATION
H04N7/1675G11B20/00224H04N21/42623H04N21/4367H04N21/43853H04N21/4405H04N21/4433H04N21/4627H04N21/8355
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,104,342
App. No.
14/133,050
Granted
Oct 16, 2018
Kind
B2
Abstract

Techniques for improved decryption of an encrypted media stream are described. In one embodiment, a system may include a receiver to receive an encrypted media stream, an extraction module to extract an encryption characteristic of the encrypted media stream, a first processor to produce configuration commands from the extracted encryption characteristic, a second processor to receive the encrypted media stream and the configuration commands, and to produce decrypted media based upon a decryption scheme indicated by the configuration commands, and a key distribution module, to distribute a decryption key to the second processor.

Claims (32)

1. An apparatus to decrypt an encrypted media stream, comprising:

a receiver to receive an encrypted media stream;

a first processor component to execute a graphics driver, the graphics driver to generate a message indicating a type of algorithm used to encrypt at least video in the encrypted media stream, the first processor component comprising a central processing unit (CPU) located in an unprotected domain of an operating system of a mobile device;

a second processor component to receive the encrypted media stream and the message indicating the type of algorithm, and to decrypt at least the video of the encrypted media stream using the indicated algorithm and a first key, the second processor component to be controlled by the graphics driver executed by the first processor component;

a feedback communication path from the second processor component to the first processor component, the second processor component to detect a metric about the encrypted media stream, determine the metric will affect operation of an operating system executed by the first processor component, and pass, after decryption, feedback information descriptive of the encrypted media stream and the metric to the first processor component via the feedback communication path; and

a media buffer in the unprotected domain from which the video is retrieved to be displayed, the second processor component to re-encrypt at least the video using a second key prior to storage of at least the video in the media buffer.

2. The apparatus of claim 1 , the encrypted media stream comprising a streaming media encrypted by Advanced Encryption Standard (AES).

3. The apparatus of claim 1 , the feedback information to indicate at least one of a type of video stream, resolution, frame rate, encoding sequence or timing information associated with at least the video.

4. A system to decrypt an encrypted media stream, comprising:

a receiver to receive an encrypted media stream;

a first processor circuit to execute a graphics driver, the graphics driver to generate a message indicating a type of algorithm used to encrypt at least video in the encrypted media stream, the first processor circuit comprising a central processing unit (CPU) located in an unprotected domain of an operating system of a mobile device;

a second processor circuit to receive the encrypted media stream and the message indicating the type of algorithm, and to decrypt at least the video of the encrypted media stream using the indicated algorithm and a decryption key, the second processor circuit to be controlled by the graphics driver executed by the first processor circuit;

a key distribution module to distribute the decryption key to the second processor circuit;

a feedback communication path from the second processor circuit to the first processor circuit, the second processor circuit to detect a metric about the encrypted media stream, determine the metric will affect operation of an operating system executed by the first processor circuit, and pass, after decryption, feedback information descriptive of the encrypted media stream and the metric to the first processor circuit via the feedback communication path; and

a media buffer in the unprotected domain from which the video is retrieved to be displayed, the second processor circuit to re-encrypt at least the video using another key prior to storage of at least the video in the media buffer.

5. The system of claim 4 , the encrypted media stream comprising a streaming media encrypted by Advanced Encryption Standard (AES).

6. The system of claim 4 , the feedback information to indicate at least one of a type of video stream, resolution, frame rate, encoding sequence or timing information associated with at least the video.

7. The system of claim 4 , further comprising an interface to a user-video interface and an interface to a user-audio interface.

8. The system of claim 4 , the key distribution module further comprising:

a first input to receive an encryption license;

a second input to receive a key provision; and

a processor to produce the decryption key from the encryption license and the key provision.

9. At least one machine-readable medium comprising a plurality of instructions that, in response to being executed on a computing device, cause the computing device to:

receive an encrypted media stream;

execute a graphics driver at a first processor component, the graphics driver to generate a message indicating a type of algorithm used to encrypt at least video in the encrypted media stream, the first processor component comprising a central processing unit (CPU) located in an unprotected domain of an operating system of a mobile device;

receive, at a second processor component, the encrypted media stream and the message indicating the type of algorithm, and decrypt, at the second processor component, at least the video of the encrypted media stream using the indicated algorithm and a first key, the second processor component to be controlled by the graphics driver executed at the first processor component; and

detect, at the second processor component, a metric about the encrypted media stream;

determine, at the second processor component, the metric will affect operation of an operating system executed by the first processor component;

after decryption, pass feedback information descriptive of the encrypted media stream and the metric from the second processor component to the first processor component via a feedback communication path from the second processor component to the first processor component; and

re-encrypt at least the video at the second processor component using a second key and to store at least the video in a media buffer in the unprotected domain following the re-encryption.

10. The at least one machine-readable medium of claim 9 , the encrypted media stream comprising a streaming media encrypted by Advanced Encryption Standard (AES).

11. The at least one machine-readable medium of claim 9 , the feedback information to indicate at least one of a type of video stream, resolution, frame rate, encoding sequence or timing information associated with at least the video.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 12, 2014
From: NANDA, AKSHAT; WANG, CHANGLIANG; CHENG, SCOTT; COULTER, MICHAEL
To: INTEL CORPORATION
Reel/Frame 032416/0674 →
Continuity (1)
Related Publication 20150172600A1 · Jun 18, 2015