IP Library Granted Patent US 9,043,603
Granted Patent B2
US 9,043,603 · App. 12/360,811 · Granted May 26, 2015

Security threshold enforcement in anchor point-based digital rights management

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,043,603
App. No.
12/360,811
Granted
May 26, 2015
Kind
B2
Abstract

Digital rights management (DRM) can be effectively implemented through use of an anchor point and binding records within a user's anchor point domain. Assigning security levels to various components within an anchor point based DRM system and evaluating them against a security criterion provides additional protection against authorized access of the digital content. The content provider may specify the security criterion (e.g., a security level threshold), and the ability to use the digital content is denied or granted based on the ability of components to satisfy this criterion. For example, the ability to use a digital property instance is granted to a content handler that satisfies the security criterion and denied to a content handle that does not satisfy the security criterion.

Claims (44)

1. A method comprising:

learning a security level of a content handler coupled to an anchor point, the anchor point comprising a secure unique hard-to-falsify physical circuit that can store data, the security level including a value stored to a digital certificate of the content handler;

receiving at the anchor point a title pre-key;

decrypting the title pre-key with a binding key stored within the anchor point to yield a title key, the title key being configured to decrypt an encrypted digital property instance;

establishing a security level in the anchor point, wherein the security level in the anchor point quantifies effort and resources needed to compromise security of the anchor point and is judged by a certification authority trusted by a content provider from which the encrypted digital property instance was received;

determining a security level of a transaction based on the lowest of the security level in the anchor point and the security level of the content handler, including comparing the value of the security level of the content handler to a value of a security criterion associated with the digital property instance; and

issuing the title key to the content handler when the value of the security level of the transaction satisfies the security criterion associated with the encrypted digital property instance.

2. The method of claim 1 further comprising:

rating the content handler to designate the security level of the content handler, wherein the security level of the content handler quantifies effort and resources needed to compromise security of the content handler to reveal a secret or to behave in a way that violates procedural restrictions of the content handler, and is judged by a certification authority trusted by a content provider from which the encrypted digital property instance was received.

3. The method of claim 1 wherein the binding key is stored in a binding record associated with the encrypted digital property instance.

4. The method of claim 1 further comprising:

generating the title key by decrypting the received title pre-key using the binding key stored within the anchor point, the binding key being stored in a binding record associated with the encrypted digital property instance.

5. The method of claim 1 wherein the security criterion is designated by a content provider from which the encrypted digital property instance was received.

6. The method of claim 1 wherein the security criterion specifies a security threshold that a security level must equal or exceed to satisfy the security criterion.

7. The method of claim 1 wherein the issuing operation comprises:

evaluating the security level of the content handler against the security criterion.

8. The method of claim 1 further comprising:

establishing the security level in the anchor point, wherein the issuing operation comprises issuing the title key to the content handler, if both the security level of the anchor point and the security level of the content handler satisfy the security criterion associated with the encrypted digital property instance.

9. A computer-readable storage device storing instructions, that when executed by a processor cause the processor to perform a method comprising:

learning a security level of a content handler connected to an anchor point, the anchor point comprising a secure unique hard-to-falsify physical circuit that can store data, the security level including a value stored to a digital certificate of the content handler;

receiving at the anchor point a title pre-key;

decrypting the title pre-key with a binding key stored within the anchor point to yield a title key, the title key being configured to decrypt an encrypted digital property instance;

establishing a security level in the anchor point, wherein the security level in the anchor point quantifies effort and resources needed to compromise security of the anchor point and is judged by a certification authority trusted by a content provider from which the encrypted digital property instance was received;

determining a security level of a transaction based on the lowest of the security level in the anchor point and the security level of the content handler, including comparing the value of the security level of the content handler to a value of a security criterion associated with the digital property instance; and

issuing the title key to the content handler when the value of the security level of the transaction satisfies the security criterion associated with the encrypted digital property instance.

10. The computer-readable storage device of claim 9 wherein the security level of the content handler quantifies effort and resources needed to compromise security of the content handler and is judged by a certification authority trusted by a content provider from which the encrypted digital property instance was received.

11. The computer-readable storage device of claim 9 wherein the binding key is stored in a binding record associated with the encrypted digital property instance.

12. The computer-readable storage device of claim 9 wherein the method further comprises:

generating the title key by decrypting the received title pre-key using the binding key stored within the anchor point, the binding key being stored in a binding record associated with the encrypted digital property instance.

13. The computer-readable storage device of claim 9 wherein the security criterion is designated by a content provider from which the encrypted digital property instance was received.

14. The computer-readable storage device of claim 9 wherein the security criterion specifies a security threshold that a security level must equal or exceed to satisfy the security criterion.

15. The computer-readable storage device of claim 9 wherein the issuing operation comprises:

evaluating the security level of the content handler against the security criterion.

16. The computer-readable storage device of claim 9 wherein the method further comprises:

establishing the security level in the anchor point, wherein the issuing operation comprises issuing the title key to the content handler, if both the security level of the anchor point and the security level of the content handler satisfy the security criterion associated with the encrypted digital property instance.

17. A system comprising:

a content handler storing a security level attributed to the content handler;

a secure unique physical anchor point circuit communicatively coupled to the content handler and configured to:

establish a security level in the anchor point, wherein the security level in the anchor point quantifies effort and resources needed to compromise security of the anchor point and is judged by a certification authority trusted by a content provider from which an encrypted digital property instance was received;

determine a security level of a transaction based on the lowest of the security level in the anchor point and the security level of the content handler, including evaluate the security level of the content handler against a security criterion associated with the encrypted digital property instance;

issue a title key to the content handler when the security level of the transaction satisfies the security criterion; and

the content handler is configured to decrypt the encrypted digital property instance using the title key.

18. The system of claim 17 further comprising:

a digital rights management circuit module communicatively coupled to pass a title pre-key to the anchor point, wherein the title pre-key can be decrypted by a binding key stored within the anchor point to yield the title key.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Jul 23, 2025
From: THE BANK OF NOVA SCOTIA
To: SEAGATE TECHNOLOGY PUBLIC LIMITED COMPANY; SEAGATE TECHNOLOGY; SEAGATE TECHNOLOGY HDD HOLDINGS; I365 INC.; SEAGATE TECHNOLOGY LLC; SEAGATE TECHNOLOGY INTERNATIONAL; SEAGATE HDD CAYMAN; SEAGATE TECHNOLOGY (US) HOLDINGS, INC.
Reel/Frame 072193/0001 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jul 19, 2013
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT AND SECOND PRIORITY REPRESENTATIVE
To: SEAGATE TECHNOLOGY LLC; EVAULT INC. (F/K/A I365 INC.); SEAGATE TECHNOLOGY INTERNATIONAL; SEAGATE TECHNOLOGY US HOLDINGS, INC.
Reel/Frame 030833/0001 →
SECURITY AGREEMENT Recorded Mar 24, 2011
From: SEAGATE TECHNOLOGY LLC
To: THE BANK OF NOVA SCOTIA, AS ADMINISTRATIVE AGENT
Reel/Frame 026010/0350 →
RELEASE Recorded Jan 19, 2011
From: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
To: SEAGATE TECHNOLOGY HDD HOLDINGS; MAXTOR CORPORATION; SEAGATE TECHNOLOGY LLC; SEAGATE TECHNOLOGY INTERNATIONAL
Reel/Frame 025662/0001 →
SECURITY AGREEMENT Recorded May 15, 2009
From: MAXTOR CORPORATION; SEAGATE TECHNOLOGY LLC; SEAGATE TECHNOLOGY INTERNATIONAL
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND FIRST PRIORITY REPRESENTATIVE; WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT AND SECOND PRIORITY REPRESENTATIVE
Reel/Frame 022757/0017 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2009
From: SWEAZEY, PAUL M.
To: SEAGATE TECHNOLOGY, LLC
Reel/Frame 022310/0307 →