Protecting media items using a media security controller

    公开(公告)号:US10902096B2

    公开(公告)日:2021-01-26

    申请号:US16665113

    申请日:2019-10-28

    Abstract: A media storage device includes a media security controller circuit and a memory to store data that relates to a media item to be rendered by a rendering device. The media security controller circuit sends a message to the rendering device that causes the rendering device to obtain a portion of data from memory of the media storage device and provide it to the media security controller circuit. The portion is received and transformed by the media security controller circuit. The media security controller circuit sends the transformed portion to the rendering device.

    AUDITING AND PERMISSION PROVISIONING MECHANISMS IN A DISTRIBUTED SECURE ASSET-MANAGEMENT INFRASTRUCTURE
    15.
    发明申请
    AUDITING AND PERMISSION PROVISIONING MECHANISMS IN A DISTRIBUTED SECURE ASSET-MANAGEMENT INFRASTRUCTURE 有权
    分布式安全资产管理基础设施的审计和许可提供机制

    公开(公告)号:US20150326541A1

    公开(公告)日:2015-11-12

    申请号:US14535202

    申请日:2014-11-06

    Abstract: The embodiments described herein describe technologies for ticketing systems used in consumption and provisioning of data assets, such as a pre-computed (PCD) asset. A ticket may be a digital file or data that enables enforcement of usage count limits and uniqueness issuance ore sequential issuance of target device parameters. On implementation includes an Appliance device of a cryptographic manager (CM) system that receives a Module and a ticket over a network from a Service device. The Module is an application that securely provisions a data asset to a target device in an operation phase of a manufacturing lifecycle of the target device. The ticket is digital data that grants permission to the Appliance device to execute the Module. The Appliance device verifies the ticket to execute the Module. The Module, when executed, results in a secure construction of a sequence of operations to securely provision the data asset to the target device.

    Abstract translation: 这里描述的实施例描述了在诸如预先计算(PCD)资产的数据资产的消费和供应中使用的票务系统的技术。 票可以是数字文件或数据,其能够执行使用计数限制和唯一性发放矿石连续发放目标设备参数。 实施时包括通过网络从服务设备接收模块和故障单的密码管理器(CM)系统的电器设备。 该模块是在目标设备的制造生命周期的操作阶段中将数据资产安全地提供给目标设备的应用程序。 该票是允许电器设备执行模块的数字数据。 电器设备验证机票以执行模块。 该模块在执行时会导致一系列操作的安全构造,以将数据资产安全地提供给目标设备。

    Digital Content Protection Method and Apparatus
    18.
    发明申请
    Digital Content Protection Method and Apparatus 有权
    数字内容保护方法与设备

    公开(公告)号:US20020099948A1

    公开(公告)日:2002-07-25

    申请号:US09948473

    申请日:2001-09-06

    Abstract: Abstract of DisclosureBefore use, a population of tamper-resistant cryptographic enforcement devices is partitioned into groups and issued one or more group keys. Each tamper-resistant device contains multiple computational units to control access to digital content. One of the computational units within each tamper-resistant device communicates with another of the computational units acting as an interface control processor, and serves to protect the contents of a nonvolatile memory from unauthorized access or modification by other portions of the tamper-resistant device, while performing cryptographic computations using the memory contents. Content providers enforce viewing privileges by transmitting encrypted rights keys to a large number of recipient devices. These recipient devices process received messages using the protected processing environment and memory space of the secure unit. The processing result depends on whether the recipient device was specified by the content provider as authorized to view some encrypted digital content. Authorized recipient devices can use the processing result in decrypting the content, while unauthorized devices cannot decrypt the content. A related aspect of the invention provides for securing computational units and controlling attacks. For example, updates to the nonvolatile memory, including program updates, are supported and protected via a cryptographic unlocking and validation process in the secure unit, which can include digital signature verification.

    Abstract translation: 摘要在使用之前,将一批防篡改加密强制设备分成几组,并发出一个或多个组密钥。 每个防篡改设备包含多个计算单元来控制对数字内容的访问。 每个防篡改设备中的一个计算单元与作为接口控制处理器的另一个计算单元进行通信,并且用于保护非易失性存储器的内容免受篡改设备的其他部分的未经授权的访问或修改, 同时使用存储器内容执行加密计算。 内容提供商通过将加密的权限密钥发送到大量的收件人设备来强制执行查看权限。 这些收件人设备使用受保护的处理环境和安全单元的存储空间处理接收到的消息。 处理结果取决于收件人设备是否被内容提供商指定为授权查看某些加密的数字内容。 授权收件人设备可以使用处理结果解密内容,而未经授权的设备则无法解密内容。 本发明的相关方面提供了保护计算单元和控制攻击。 例如,通过安全单元中的加密解锁和验证过程来支持和保护对非易失性存储器的更新,包括程序更新,这可以包括数字签名验证。

Patent Agency Ranking