IP Library Granted Patent US 12,621,131
Granted Patent B2
US 12,621,131 · App. 18/802,706 · Granted May 5, 2026

System and method for securely delivering keys and encrypting content in cloud computing environments

Inventors: Rafie Shamsaasef (San Diego, CA); Lawrence Cook (Santee, CA)
Assignee: ARRIS Enterprises LLC
H04L9/083H04L67/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,621,131
App. No.
18/802,706
Granted
May 5, 2026
Kind
B2
Abstract

A cloud-based system and method for encrypting media content is disclosed. The system comprises a key server microservice, for receiving control word requests and for generating encoded control words and a software encryption microservice, communicatively coupled to the key server microservices, the encryption microservice for receiving the media content, for generating the control word requests, for receiving the encoded control words, and for white-box encrypting the media content according to the generated encoded control words.

Claims (68)

1 . A system, including a hardware processor and a memory accessible by said hardware processor, encrypting media content, comprising:

a key server service, receiving control word requests and generating encoded control words according to entitlement information; and

a software encryption service, communicatively coupled to the key server service, the software encryption service receiving the media content, generating the control word requests, receiving the encoded control words, and white-box encrypting the media content according to the generated encoded control words;

wherein the key server service and the encryption service are hosted in a cloud hosted by a first entity.

2 . The system of claim 1 , wherein the cloud is a private cloud hosted by said first entity.

3 . The system of claim 1 , wherein:

the cloud comprises a private cloud hosted by a first entity and a public cloud hosted by a second entity; and

the key server service is hosted in the private cloud and the software encryption service is hosted in the public cloud.

4 . The system of claim 1 , wherein the encoded control words are provided from the key server service to the software encryption service via a first communication path independent from a second communication path in which the media content is received.

5 . The system of claim 1 , wherein the key server service further generates entitlement control information authorizing access to the media content and further provides the entitlement control information to the software encryption service for distribution.

6 . The system of claim 1 , wherein:

the media content is received from a media content provider;

the key server service hosted in said cloud further comprises:

a media content information interface hosted in said cloud:

said media content information interface receiving entitlement information having an encrypted control word;

said media content information interface receiving media content information;

an entitlement management information handler hosted in said cloud:

said entitlement management information handler receiving entitlement information having the encrypted control word;

said entitlement management information handler decrypting the encrypted control word; and

a control word generator hosted in said cloud accepting the entitlement information from the entitlement management information handler and generating the encoded control words according to the entitlement information.

7 . The system of claim 6 , wherein:

the key server service includes:

a security abstraction layer, for interfacing with a secure processor for decrypting the encrypted control word.

8 . A method for encrypting media content, including a hardware processor and a memory accessible by said hardware processor, comprising:

receiving, in a key server service hosted in a cloud computing environment, a request to generate an encoded control word for encrypting media content;

generating, in the key server service, the encoded control word according to entitlement information;

transmitting the encoded control word to a software encryption service hosted in the cloud; and

white-box encrypting the media content according to the encoded control word in the software encryption service hosted by a first entity.

9 . The method of claim 8 , wherein the cloud is a private cloud hosted by said first entity.

10 . The method of claim 8 , wherein:

the cloud comprises a private cloud hosted by a first entity and a public cloud hosted by a second entity; and

the key server service is hosted in the private cloud and the software encryption service is hosted in the public cloud.

11 . The method of claim 8 , wherein:

the method further comprises:

receiving a media content stream having the media content in the software encryption service; and

wherein the encoded control words are provided from the key server service to the software encryption service via a first communication path independent from a second communication path in which the media content stream is received.

12 . The method of claim 8 , wherein:

the method further comprises:

receiving media content information;

receiving entitlement information having an encrypted control word;

decrypting the encrypted control word; and

the encoded control word is generated according to the received entitlement information, the media content information, and the decrypted control word.

13 . The method of claim 12 , wherein the encrypted control word is decrypted via a media provider specific hardware security module.

14 . The method of claim 8 , wherein:

the method further comprises:

receiving media content information;

generating said entitlement information including the control word; and

wherein generating, in the key server service, the encoded control word according to said entitlement information comprises:

generating the encoded control word according to the generated said entitlement information.

15 . A method for encrypting media content, including a hardware processor and a memory accessible by said hardware processor, comprising:

transmitting, to a key server service hosted in a cloud computing environment, a request to generate an encoded control word for encrypting media content;

receiving the encoded control word to a software encryption service hosted in the cloud, the encoded control word generated by the key server service according to entitlement information; and

white-box encrypting the media content according to the encoded control word in the software encryption service hosted by a first entity.

16 . The method of claim 15 , wherein the cloud is a private cloud hosted by said first entity.

17 . The method of claim 15 , wherein:

the cloud comprises a private cloud hosted by a first entity and a public cloud hosted by a second entity; and

the key server service is hosted in the private cloud and the software encryption service is hosted in the public cloud.

18 . The method of claim 15 , wherein:

the method further comprises:

receiving a media content stream having the media content in the software encryption service; and

wherein the encoded control words are provided from the key server service to the software encryption service via a first communication path independent from a second communication path in which the media content stream is received.

19 . The method of claim 18 , wherein:

the encoded control word is generated according to received entitlement information, media content information and an encrypted control word received by the key server service, the encrypted control word decrypted by the key server service.

20 . The method of claim 19 , wherein the encrypted control word is decrypted via a media provider specific hardware security module of the key server service.

21 . The method of claim 15 , wherein:

the encoded control word is generated by the key server microservice according to:

the entitlement information including the control word, the entitlement information generated in the key server service; and

media content information received in the key server service.

Assignments (2)
SECURITY INTEREST Recorded Apr 8, 2026
From: ARRIS ENTERPRISES LLC; RUCKUS IP HOLDINGS LLC
To: CITIBANK, N.A., AS COLLATERAL AGENT
Reel/Frame 075476/0814 →
SECURITY INTEREST Recorded Dec 17, 2024
From: ARRIS ENTERPRISES LLC; COMMSCOPE TECHNOLOGIES LLC; COMMSCOPE INC., OF NORTH CAROLINA; OUTDOOR WIRELESS NETWORKS LLC; RUCKUS IP HOLDINGS LLC
To: APOLLO ADMINISTRATIVE AGENCY LLC
Reel/Frame 069889/0114 →
Continuity (3)
Continuation 17848089 · Jun 23, 2022
Provisional Application 63214132 · Jun 23, 2021
Related Publication 20240405975A1 · Dec 5, 2024
References Cited (21)
US 8819843B2 · Kannan et al. · 2014 [cited by applicant]
US 9716696B2 · Narayan et al. · 2017 [cited by applicant]
US 20070253551A1 · Guillot et al. · 2007 [cited by applicant]
US 20090028331A1 · Millar et al. · 2009 [cited by applicant]
US 20100211797A1 · Westerveld et al. · 2010 [cited by applicant]
US 20110268271A1 · Benedetti et al. · 2011 [cited by applicant]
US 20150163054A1 · Roelse et al. · 2015 [cited by applicant]
US 20160050190A1 · Mooij · 2016 [cited by examiner]
US 20170373828A1 · Michiels · 2017 [cited by examiner]
US 20180083933A1 · Mullen · 2018 [cited by examiner]
US 20180167197A1 · Anderson · 2018 [cited by applicant]
US 20190222878A1 · Cocchi et al. · 2019 [cited by applicant]
US 20200044837A1 · Bos · 2020 [cited by examiner]
CN 101827248A · 2010 [cited by applicant]
CN 1679066B · 2011 [cited by applicant]
CN 103107889B · 2013 [cited by applicant]
CN 106604070B · 2017 [cited by applicant]
EP 2326043A1 · 2011 [cited by applicant]
“Re-encryption use cases;ECI(15)006006_Re-encryption_use_cases”, ETSI Draft; ECI(15)006006_RE-Encryption_Use_Cases, European Telecommunications Standards Institute (ETSI), 650, Route Des Lucioles; F-06921 Sophia-Antipol… [cited by applicant]
Diaz-Sanchez D et al: “Sharing conditional access modules through the home network for pay TV access”, IEEE Transactions On Consumer Electronics, IEEE Service Center, New York, NY, US, col. 55, No. 1, Feb. 1, 2009 (Feb.… [cited by applicant]
International Search Report and Written Opinion RE: Application No. PCT/US22/34768, dated Oct. 7, 2022. [cited by applicant]