IP Library Patent Application 13328843
Patent Application
App. No. 13/328,843

Storage Device and Method for Super-Distribution of Content Protected with a Localized Content Encyrption Key

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
13/328,843
Abstract

In one embodiment, a storage device stores a content encryption key, content encrypted with the content encryption key, and a super-distribution key. To re-distribute the content, the storage device creates a super-distribution token by encrypting the content encryption key with the super-distribution key and provides the encrypted content and the super-distribution token to a host device for storage in a target storage device. To access the encrypted content on the target storage device, the target storage device provides the super-distribution token to a server via the host device. The server generates an activation token from the super-distribution token, wherein the activation token contains the content encryption key. The target storage device receives the activation token from the server via the host device, retrieves the content encryption key from the activation token, and decrypts the encrypted content using the retrieved content encryption key.

Claims (64)

1 . A storage device comprising:

an interface through which the storage device can connect to and communicate with a host device;

one or more memories storing a super-distribution key and a content encryption key; and

a controller in communication with the interface and the one or more memories, wherein the controller is operative to:

create a super-distribution token by encrypting the content encryption key with a first encryption key and then encrypting a result of that encryption with the super-distribution key, wherein the super distribution token includes a reference to the first encryption key; and

provide the super-distribution token to the host device for storage in a target storage device, wherein the target storage device stores a plurality of encryption keys and uses the reference in the super distribution token to select one of the plurality of encryption keys to decrypt the content encryption key.

2 . The storage device of claim 1 , wherein the one or more memories further stores content encrypted with the content encryption key, and wherein the controller is further operative to receive data that associates the encrypted content with the super-distribution token so that when the encrypted content is copied from the storage device, the super-distribution token is also copied.

3 . The storage device of claim 1 , wherein the one or more memories further stores content encrypted with the content encryption key, and wherein a number of copies of the content is pre-authorized.

4 . The storage device of claim 1 , wherein the controller is further operative to receive the super-distribution key from a server via the host device.

5 . The storage device of claim 4 , wherein the controller is further operative to provide a credential to the server to prove that the storage device is authorized to receive the super-distribution key.

6 . The storage device of claim 4 , wherein the server is unaware of the content encryption key when the server provides the super-distribution key to the host device.

7 . The storage device of claim 1 , wherein the controller is further operative to receive information from a server to import the super-distribution key via the host device.

8 . The storage device of claim 1 , wherein the super-distribution token further comprises additional data, and wherein both the additional data and the content encryption key are encrypted by the super-distribution key.

9 . The storage device of claim 1 , wherein the super-distribution token further comprises additional data, and wherein the super-distribution key is used to encrypt only the content encryption key and the additional data is free of such super-distribution key encryption.

10 . The storage device of claim 9 , wherein the additional data includes at least one of a reference to the super distribution key, a content ID, a reference to the storage device, and a reference to the target storage device.

11 . The storage device of claim 1 , wherein the controller is further operative to generate the content encryption key.

12 . The storage device of claim 1 , wherein the controller is further operative to receive the content encryption key from a source external to the storage device.

13 . The storage device of claim 1 , wherein the super-distribution key is dynamically generated as a result of an authentication and key exchange process between the storage device and a server.

14 . A method for super-distribution of content, the method comprising:

performing the following in a storage device having an interface through which the storage device can connect to and communicate with a host device, wherein the storage device stores a super-distribution key and a content encryption key:

creating a super-distribution token by encrypting the content encryption key with a first encryption key and then encrypting a result of that encryption with the super-distribution key, wherein the super distribution token includes a reference to the first encryption key; and

providing the encrypted content and the super-distribution token to the host device for storage in a target storage device, wherein the target storage device stores a plurality of encryption keys and uses the reference in the super distribution token to select one of the plurality of encryption keys to decrypt the content encryption key.

15 . The method of claim 14 , wherein the storage device further stores content encrypted with the content encryption key, and wherein the method further comprises receiving data that associates the encrypted content with the super-distribution token so that when the encrypted content is copied from the storage device, the super-distribution token is also copied.

16 . The method of claim 14 , wherein the one or more memories further stores content encrypted with the content encryption key, and wherein a number of copies of the content is pre-authorized.

17 . The method of claim 14 further comprising receiving the super-distribution key from a server via the host device.

18 . The method of claim 17 further comprising providing a credential to the server to prove that the storage device is authorized to receive the super-distribution key.

19 . The method of claim 17 , wherein the server is unaware of the content encryption key when the server provides the super-distribution key to the host device.

20 . The method of claim 14 , wherein the controller is further operative to receive information from a server to import the super-distribution key via the host device.

21 . The method of claim 14 , wherein the super-distribution token further comprises additional data, and wherein both the additional data and the content encryption key are encrypted by the super-distribution key.

22 . The method of claim 14 , wherein the super-distribution token further comprises additional data, and wherein the super-distribution key is used to encrypt only content encryption key and the additional data is free of such super-distribution key encryption.

23 . The method of claim 22 , wherein the additional data includes at least one of a reference to the super-distribution key, a content ID, a reference to the storage device, and a reference to the target storage device.

24 . The method of claim 14 further comprising generating the content encryption key.

25 . The method of claim 14 further comprising receiving the content encryption key from a source external to the storage device.

26 . A storage device comprising:

an interface through which the storage device can connect to and communicate with a host device;

one or more memories storing content encrypted with a content encryption key, a plurality of additional encryption keys, and a super-distribution token, wherein the super-distribution token comprises the content encryption key encrypted with one of the plurality of additional encryption keys and then encrypted with a super-distribution key; and

a controller in communication with the interface and the one or more memories, wherein the controller is operative to:

provide the super-distribution token to a server via the host device, wherein the server is operative to generate an activation token from the super-distribution token by decrypting the super-distribution token with the super-distribution key, wherein the activation token contains the content encryption key encrypted with the one of the plurality of additional encryption keys and further contains a reference to the one of the plurality of additional encryption keys;

receive the activation token from the server via the host device;

select one of the additional keys based on the reference in the activation token;

decrypt the content encryption key from the activation token using the selected one of the additional keys; and

decrypt the encrypted content using the content encryption key.

27 . The storage device of claim 26 , wherein a number of copies of the content is pre-authorized.

28 . The storage device of claim 26 , wherein the encrypted version of the content encryption key is encrypted with a super-distribution key.

29 . The storage device of claim 26 , wherein, in addition to the content encryption key, the activation token contains additional data.

30 . The storage device of claim 29 , wherein the additional data includes at least one of a reference to the super-distribution key, a content ID, a reference to the storage device, and a reference to a storage device that was the source of the encrypted content.

31 - 33 . (canceled)

34 . The storage device of claim 26 , wherein the activation token is encrypted with a transport encryption key known to the server, and wherein the controller is further operative to decrypt the encrypted activation token with the transport encryption key.

35 . The storage device of claim 26 , wherein the controller is further operative to provide a credential to the server to prove that the storage device is authorized to receive the authorization token.

36 . A method for super-distribution of content, the method comprising:

performing the following in a storage device having an interface through which the storage device can connect to and communicate with a host device, wherein the storage device stores content encrypted with a content encryption key, a plurality of additional encryption keys, and a super-distribution token, and wherein the super-distribution token comprises the content encryption key encrypted with one of the plurality of additional encryption keys and then encrypted with a super-distribution key:

providing the super-distribution token to a server via the host device, wherein the server is operative to generate an activation token from the super-distribution token by decrypting the super-distribution token with the super-distribution key, and wherein the activation token contains the content encryption key encrypted with the one of the plurality of additional encryption keys and further contains a reference to the one of the plurality of additional encryption keys;

receiving the activation token from the server via the host device;

selecting one of the additional keys based on the reference in the activation token;

decrypting the content encryption key from the activation token using the selected one of the additional keys; and

decrypting the encrypted content using the content encryption key.

37 . The method of claim 36 , wherein a number of copies of the content is pre-authorized.

38 . The method of claim 36 , wherein the encrypted version of the content encryption key is encrypted with a super-distribution key.

39 . The method of claim 36 , wherein, in addition to the content encryption key, the activation token contains additional data.

40 . The method of claim 39 , wherein the additional data includes at least one of a reference to the super-distribution key, a content ID, a reference to the storage device, and a reference to a storage device that was the source of the encrypted content.

41 - 43 . (canceled)

44 . The method of claim 36 , wherein the activation token is encrypted with a transport encryption key known to the server, and wherein the method further comprises decrypting the encrypted activation token with the transport encryption key.

45 . The method of claim 36 further comprising providing a credential to the server to prove that the storage device is authorized to receive the authorization token.

46 . The method of claim 36 , wherein a number of copies of the content is pre-authorized.

Assignments (2)
CHANGE OF NAME Recorded May 25, 2016
From: SANDISK TECHNOLOGIES INC
To: SANDISK TECHNOLOGIES LLC
Reel/Frame 038809/0672 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 16, 2011
From: JOGAND-COULOMB, FABRICE E.; HUTTON, HENRY R.; LIN, JASON T.; HALPERN, JOSEPH E.; SELA, ROTEM
To: SANDISK TECHNOLOGIES INC.
Reel/Frame 027400/0155 →