METHOD AND APPARATUS FOR SECURELY MOVING AND RETURNING DIGITAL CONTENT
    11.
    发明申请
    METHOD AND APPARATUS FOR SECURELY MOVING AND RETURNING DIGITAL CONTENT 审中-公开
    用于安全移动和返回数字内容的方法和装置

    公开(公告)号:US20080015997A1

    公开(公告)日:2008-01-17

    申请号:US11457219

    申请日:2006-07-13

    IPC分类号: G06Q99/00

    摘要: The present invention discloses an apparatus and method for transferring digital content data. In one example, original digital content data stored on a first device content data. In one example, original digital content data stored on a first device in an encrypted state is transcoded (after being decrypted) to create a modified version of the original digital content data. The modified version of the original digital content data is then encrypted with a new content key. The modified version and at least one content key generator are transferred to a second device, where the at least one content key generator is used to recreate the new content key for enabling (and decrypting) the modified version of the original digital content data at the second device. Notably, the original digital content data stored in the first device is disabled contemporaneously with the transfer of the modified version and the at least one content key generator to the second device. Afterwards, the disabled original digital content data is re-enabled on the first device, and disabled on the second device.

    摘要翻译: 本发明公开了一种用于传送数字内容数据的装置和方法。 在一个示例中,存储在第一设备内容数据上的原始数字内容数据。 在一个示例中,以加密状态存储在第一设备上的原始数字内容数据被转码(在被解密之后)以创建原始数字内容数据的修改版本。 然后用新的内容密钥对原始数字内容数据的修改版本进行加密。 修改版本和至少一个内容密钥生成器被传送到第二设备,其中使用至少一个内容密钥生成器来重新创建新的内容密钥,以便在(或)解密)原始数字内容数据的修改版本 第二设备 值得注意的是,存储在第一设备中的原始数字内容数据与修改版本和至少一个内容密钥生成器的传送同时被禁用到第二设备。 之后,禁用的原始数字内容数据在第一个设备上重新启用,并在第二个设备上禁用。

    Temporary registration of devices
    13.
    发明授权
    Temporary registration of devices 有权
    设备临时注册

    公开(公告)号:US08788810B2

    公开(公告)日:2014-07-22

    申请号:US12648768

    申请日:2009-12-29

    IPC分类号: G06F11/30

    摘要: In a method of temporarily registering a second device with a first device, in which the first device includes a temporary registration mode, the temporary registration mode in the first device is activated, a temporary registration operation in the first device is initiated from the second device, a determination as to whether the second device is authorized to register with the first device is made, and the second device is temporarily registered with the first device in response to a determination that the second device is authorized to register with the first device, in which the temporary registration requires that at least one of the second device and the first device delete information required for the temporary registration following at least one of a determination of a network connection between the first device and the second device and a powering off of at least one of the first device and the second device.

    摘要翻译: 在第一设备暂时注册第二设备的方法中,其中第一设备包括临时注册模式,激活第一设备中的临时注册模式,从第二设备启动第一设备中的临时注册操作 进行关于第二设备是否被授权向第一设备注册的确定,并且响应于第二设备被授权向第一设备注册的确定,第二设备被临时登记到第一设备, 所述暂时注册要求所述第二设备和所述第一设备中的至少一个删除在所述第一设备和所述第二设备之间的网络连接的确定中的至少一个之后临时注册所需的信息,以及至少 第一个设备和第二个设备之一。

    Registering client devices with a registration server
    14.
    发明授权
    Registering client devices with a registration server 有权
    使用注册服务器注册客户端设备

    公开(公告)号:US08364964B2

    公开(公告)日:2013-01-29

    申请号:US12648416

    申请日:2009-12-29

    IPC分类号: H04L9/14 H04L9/28 H04L9/08

    摘要: In a method of registering a plurality of client devices with a device registration server for secure data communications, a unique symmetric key is generated for each of the client devices using a cryptographic function on a private key of the device registration server and a respective public key of each of the client devices, and a broadcast message containing the public key of the device registration server is sent to the client devices, in which the client devices are configured to generate a respective unique symmetric key from the public key of the device registration server and its own private key using a cryptographic function, and in which the unique symmetric key generated by each client device matches the respective unique symmetric key generated by the device registration server for the respective client device.

    摘要翻译: 在使用用于安全数据通信的设备注册服务器登记多个客户端设备的方法中,使用设备注册服务器的私钥的密码功能和相应的公钥来为每个客户端设备生成独特的对称密钥 并且将包含设备注册服务器的公开密钥的广播消息发送到客户端设备,其中客户端设备被配置为从设备注册服务器的公开密钥生成相应的唯一对称密钥 和其自己的私钥使用加密功能,并且其中由每个客户端设备生成的唯一对称密钥与由相应客户端设备的设备注册服务器生成的相应唯一对称密钥匹配。

    Method and Apparatus for Providing a Secure Trick Play
    15.
    发明申请
    Method and Apparatus for Providing a Secure Trick Play 审中-公开
    提供安全技巧播放的方法和装置

    公开(公告)号:US20080270308A1

    公开(公告)日:2008-10-30

    申请号:US11843335

    申请日:2007-08-22

    IPC分类号: G06Q10/00

    摘要: A process may be utilized by a DVR. The process characterizes a set of content as a plurality of segments as the set of content is received. Each of the segments has a segment length according to a predetermined time interval. Further, the process encrypts each of the segments with a corresponding content encryption key to generate a plurality of encrypted segments. The corresponding content encryption key for each of the segments is generated by the DRM component. In addition, the process stores each of the encrypted segments for playback with trick play features in accordance with an expiration content rule having a time limit on the temporary playability of the set of content.

    摘要翻译: DVR可以利用进程。 当接收到内容集合时,该过程将一组内容表征为多个段。 每个段具有根据预定时间间隔的段长度。 此外,该过程使用对应的内容加密密钥来加密每个段,以生成多个加密段。 每个段的相应内容加密密钥由DRM组件产生。 此外,该过程根据具有对该组内容的临时播放性具有时间限制的期满内容规则,将每个加密段用于播放特技播放特征。

    Key management protocol and authentication system for secure internet protocol rights management architecture
    16.
    发明授权
    Key management protocol and authentication system for secure internet protocol rights management architecture 有权
    用于安全互联网协议权限管理架构的密钥管理协议和认证系统

    公开(公告)号:US07243366B2

    公开(公告)日:2007-07-10

    申请号:US10092347

    申请日:2002-03-04

    摘要: A digital rights management architecture for securely delivering content to authorized consumers. The architecture includes a content provider and a consumer system for requesting content from the content provider. The content provider generates a session rights object having purchase options selected by the consumer. A KDC thereafter provides authorization data to the consumer system. Also, a caching server is provided for comparing the purchase options with the authorization data. The caching server forwards the requested content to the consumer system if the purchase options match the authorization data. Note that the caching server employs real time streaming for securely forwarding the encrypted content, and the requested content is encrypted for forwarding to the consumer system. Further, the caching server and the consumer system exchange encrypted control messages (and authenticated) for supporting transfer of the requested content. In this manner, all interfaces between components are protected by encryption and/authenticated.

    摘要翻译: 数字版权管理架构,用于将权限安全地传递给授权消费者。 该架构包括内容提供商和用于从内容提供商请求内容的消费者系统。 内容提供商生成具有由消费者选择的购买选项的会话权限对象。 KDC此后向消费者系统提供授权数据。 此外,还提供了一个缓存服务器,用于将购买选项与授权数据进行比较。 如果购买选项与授权数据匹配,则缓存服务器将所请求的内容转发到消费者系统。 请注意,缓存服务器采用实时流式传输安全地转发加密的内容,并且所请求的内容被加密以转发到消费者系统。 此外,缓存服务器和消费者系统交换加密的控制消息(并被认证)以支持所请求的内容的传送。 以这种方式,组件之间的所有接口都受到加密和/或认证的保护。

    Method and system for registering a DRM client
    18.
    发明授权
    Method and system for registering a DRM client 有权
    用于注册DRM客户端的方法和系统

    公开(公告)号:US09184917B2

    公开(公告)日:2015-11-10

    申请号:US13170261

    申请日:2011-06-28

    IPC分类号: H04L29/06 H04L9/32 G06F21/10

    摘要: A client, method and system for registering a DRM client is disclosed. The method (100) includes the steps of: initiating (110) a registration request via a DRM client with an encrypted registration message including an asymmetric key cryptographic identity, a customer identifier and an application specific information (AINFO) field including a digital signature and a device certificate chain; validating (120) information in the application specific information (AINFO) field by a DRM registration server; and receiving (130) a registration response, the registration response being encrypted and including access information, to obtain content. Advantageously, this method provides an enhanced and reliable means of authentication.

    摘要翻译: 公开了用于注册DRM客户端的客户端,方法和系统。 所述方法(100)包括以下步骤:通过DRM客户端发起(110)注册请求,所述注册请求具有加密的注册消息,所述加密的注册消息包括非对称密钥加密标识,客户标识符和包括数字签名的应用专用信息(AINFO) 设备证书链; 通过DRM注册服务器验证应用程序特定信息(AINFO)字段中的信息(120); 并且接收(130)注册响应,所述注册响应被加密并包括访问信息,以获得内容。 有利地,该方法提供了增强和可靠的认证手段。

    Method and apparatus for delivering certificate revocation lists
    19.
    发明授权
    Method and apparatus for delivering certificate revocation lists 有权
    交付证书吊销清单的方法和装置

    公开(公告)号:US09054879B2

    公开(公告)日:2015-06-09

    申请号:US11455574

    申请日:2006-06-19

    摘要: The present invention discloses an apparatus and method for delivering a revocation list over a one-way broadcast network to receivers with limited memory capabilities. In one example, the revocation list is partitioned to form a first certificate revocation list (CRL) sequence if the number of entries in the revocation list exceeds a predetermined value. Individual identification numbers belonging to a first identification number series are subsequently assigned to partitions of the first CRL sequence. Afterwards, the first CRL sequence is interleaved into a first content transport stream.

    摘要翻译: 本发明公开了一种用于通过单向广播网络将撤销列表递送到具有有限存储能力的接收机的装置和方法。 在一个示例中,如果撤销列表中的条目数超过预定值,则撤销列表被分割以形成第一证书撤销列表(CRL)序列。 属于第一标识号序列的个体标识号随后被分配给第一CRL序列的分区。 之后,第一CRL序列被交织到第一内容传输流中。