IP Library › Granted Patent US 11,362,994
Granted Patent B2
US 11,362,994 · App. 16/869,236 · Granted Jun 14, 2022

Media flow transport security management

Inventors: Michael J. Strein (Bohemia, NY); Douglas R. Mason (Larchmont, NY); Craig L. Beardsley (Chicago, IL); Benjamin H. Kepler (Palisades, NY)
Assignee: Disney Enterprises, Inc.
H04L63/0236G06F9/455G06F9/45533G06F9/5011H04L12/1868H04L12/1886H04L41/04H04L41/069H04L43/04H04L43/062H04L47/82H04L65/1016H04L65/4076H04L65/60H04L65/602H04L65/607H04L65/608H04L67/10H04L67/1097H04L69/04H04N21/26616H04N21/6405H04N21/6408H04L63/0428
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,362,994
App. No.
16/869,236
Granted
Jun 14, 2022
Kind
B2
Abstract

A media flow transport security manager of a hybrid cloud-based media production system having a network orchestrator and an extensible resource manager (ERM) includes a firewall communicatively coupled to a computing platform having a hardware processor and a memory storing a security software code. The hardware processor executes the security software code to communicate with the network orchestrator to identify multicast production media flow(s) for processing in a cloud-based virtual production environment, and to communicate with the ERM to obtain an identifier of each cloud-based resource used for processing cloud production media flow(s) corresponding to the identified multicast production media flow(s). The hardware processor also executes the security software code to receive an alert that the cloud production media flow(s) have been processed to generate corresponding post-production cloud media flow(s), and to route, using the obtained identifier of the cloud-based resource(s), the post-production cloud media flow(s) through the firewall.

Claims (37)

1. A media flow transport security manager of a hybrid cloud-based media production system including a network orchestrator and an extensible resource manager (ERM), the media flow transport security manager comprising:

a firewall; and

a computing platform communicatively coupled to the firewall, the computing platform having a hardware processor and a memory storing a security software code;

the hardware processor configured to execute the security software code to:

communicate with the network orchestrator to identify at least one multicast production media flow for processing in a cloud-based virtual production environment;

communicate with the ERM to obtain an identifier of at least one cloud-based resource for processing, in the cloud-based virtual production environment, one or more cloud production media flows corresponding to the identified at least one multicast production media flow;

receive an alert that the one or more cloud production media flows have been processed using the at least one cloud-based resource to generate a corresponding one or more post-production cloud media flows; and

route, in response to receiving the alert and using the obtained identifier of the at least one cloud-based resource, the one or more post-production cloud media flows through the firewall.

2. The media flow transport security manager of claim 1 , wherein routing the one or more post-production cloud media flows through the firewall transports the one or more post-production cloud media flows from the cloud-based virtual production environment into a local environment including the media flow transport security manager.

3. The media flow transport security manager of claim 1 , wherein routing the one or more post-production cloud media flows through the firewall transports the one or more post-production cloud media flows from the cloud-based virtual production environment into an on-premises production environment.

4. The media flow transport security manager of claim 1 , wherein the obtained identifier of the at least one cloud-based resource comprises an IP address of the at least one cloud-based resource.

5. The media flow transport security manager of claim 4 , wherein the hardware processor is further configured to execute the security software code to:

control the firewall to block traffic originating from an IP address other than the IP address of the at least one cloud-based resource.

6. The media flow transport security manager of claim 1 , wherein the hardware processor is configured to execute the security software code to route the one or more post-production cloud media flows through the firewall during a transport time window after receiving the alert.

7. The media flow transport security manager of claim 6 , wherein the hardware processor is further configured to execute the security software code to:

control the firewall to block traffic from the cloud-based virtual production environment after the transport time window elapses.

8. The media flow transport security manager of claim 6 , wherein the transport time window is predetermined.

9. The media flow transport security manager of claim 1 , wherein the hardware processor is further configured to execute the security software code to:

route the one or more cloud production media flows corresponding to the identified at least one multicast production media flow through the firewall to transport the one or more cloud production media flows into the cloud-based virtual production environment.

10. The media flow transport security manager of claim 9 , wherein routing the one or more cloud production media flows through the firewall transports the one or more cloud production media flows from an on-premises production environment into the cloud-based virtual production environment.

11. A method for use by a media flow transport security manager of a hybrid cloud-based media production system including a network orchestrator and an extensible resource manager (ERM), the media flow transport security manager including a firewall and a computing platform communicatively coupled to the firewall, the computing platform having a hardware processor and a memory storing a security software code, the method comprising:

communicating, by the security software code executed by the hardware processor, with the network orchestrator to identify at least one multicast production media flow for processing in a cloud-based virtual production environment;

communicating, by the security software code executed by the hardware processor, with the ERM to obtain an identifier of at least one cloud-based resource for processing, in the cloud-based virtual production environment, one or more cloud production media flows corresponding to the identified at least one multicast production media flow;

receiving, by the security software code executed by the hardware processor, an alert that the one or more cloud production media flows have been processed using the at least one cloud-based resource to generate a corresponding one or more post-production cloud media flows; and

routing, in response to receiving the alert, by the security software code executed by the hardware processor and using the obtained identifier of the at least one cloud-based resource, the one or more post-production cloud media flows through the firewall.

12. The method of claim 11 , wherein routing the one or more post-production cloud media flows through the firewall transports the one or more post-production cloud media flows from the cloud-based virtual production environment into a local environment including the media flow transport security manager.

13. The method of claim 11 , wherein routing the one or more post-production cloud media flows through the firewall transports the one or more post-production cloud media flows from the cloud-based virtual production environment into an on-premises production environment.

14. The method of claim 11 , wherein the obtained identifier of the at least one cloud-based resource comprises an IP address of the at least one cloud-based resource.

15. The method of claim 14 , further comprising:

controlling the firewall, by the security software code executed by the hardware processor, to block traffic originating from an IP address other than the IP address of the at least one cloud-based resource.

16. The method of claim 11 , wherein routing the one or more post-production cloud media flows through the firewall is performed during a transport time window after receiving the alert.

17. The method of claim 16 , further comprising:

controlling the firewall, by the security software code executed by the hardware processor, to block traffic from the cloud-based virtual production environment after the transport time window elapses.

18. The method of claim 16 , wherein the transport time window is predetermined.

19. The method of claim 11 , further comprising:

routing, by the security software code executed by the hardware processor, the one or more cloud production media flows corresponding to the identified at least one multicast production media flow through the firewall to transport the one or more cloud production media flows into the cloud-based virtual production environment.

20. The method of claim 19 , wherein routing the one or more cloud production media flows through the firewall transports the one or more cloud production media flows from an on-premises production environment into the cloud-based virtual production environment.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 8, 2026
From: DISNEY ENTERPRISES, INC.
To: ADEIA MEDIA HOLDINGS INC.
Reel/Frame 075201/0892 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2020
From: STREIN, MICHAEL J.; MASON, DOUGLAS ROBERT; BEARDSLEY, CRAIG L.; KEPLER, BENJAMIN H.
To: DISNEY ENTERPRISES, INC.
Reel/Frame 052692/0837 →
Continuity (2)
Provisional Application 62864279 · Jun 20, 2019
Related Publication 20200403972A1 · Dec 24, 2020