On-demand protection and authorization of playback of media assets
Abstract
On-demand protection and authorization of playback of media assets includes receiving digital media at a server computer, storing intermediary data in a data store, and receiving a request from a client for the digital media. The method also includes generating a protected copy of the digital media from the digital media and the intermediary data. The method also includes storing a description of the protected copy in a database and sending the protected copy to the client. The method also includes receiving a request from the client to access the digital media and reading the description from the database based on information in the request. The method also includes sending a response to the client, the response indicating whether the client is authorized to access the digital media, and the response including cryptographic data to decrypt the protected digital media if the client is authorized to access the digital media.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer implemented method comprising:
by a server computer, receiving a request from a client for digital media, the digital media including at least one or more files or portions thereof, the one or more files or portions thereof including at least a video sample and an audio sample; sending a protected copy of the digital media to the client; receiving a request from the client to access the digital media; sending cryptographic data to decrypt the protected digital media if the client is authorized to access the digital media; and sending to the client cryptographic data that is different from cryptographic data sent to the client in response to previous requests for access to the protected data, to decrypt the protected digital media upon each subsequent request for access to the protected digital data.
2 . The method of claim 1 wherein the one or more files or portions include a format comprising one more blocks of movie data and a header containing references to portions of the blocks of movie data.
3 . The method of claim 1 wherein the protected copy of the digital media comprises the samples encrypted using a checkout key, the checkout key comprising a movie portion and a server portion, wherein there is a one-to-one mapping between each combination of movie portion and server portion and each checkout key; the movie portion of the checkout key; and a numerical checkout ID.
4 . The method of claim 1 wherein
the request comprises the checkout ID and an authorization response key, the authorization response key comprising a randomized binary value generated by the client; and
the method further comprises denying the request if it is determined that the response key was used by a previous request.
5 . The method of claim 4 , further comprising storing the response key if it is determined that the response key was not used by a previous request.
6 . The method of claim 5 , further comprising encrypting the response using the response key before sending the response to the client.
7 . A computer implemented method comprising:
by a client computer,
sending, a request to a server for digital media;
receiving a protected copy of the digital media, the digital media including at least one or more files or portions thereof, the one or more files or portions thereof including at least a video sample and an audio sample;
after receiving the protected copy, sending a request to access the digital media;
receiving cryptographic data to decrypt the protected digital media if the client computer is authorized to access the digital media;
if the client computer is authorized to access the digital media,
decrypting a sample of the protected digital media using the cryptographic data; and
rendering the sample; and
receiving from the server cryptographic data that is different from cryptographic data received from the server in response to previous requests for access to the protected data, to decrypt the protected digital media upon each subsequent request for access to the protected digital data.
8 . The method of claim 7 wherein the one or more files or portions include a format comprising one more blocks of movie data and a header containing references to portions of the blocks of movie data.
9 . The method of claim 7 wherein the protected copy of the digital media comprises the samples encrypted using a checkout key, the checkout key comprising a movie portion and a server portion, wherein there is a one-to-one mapping between each combination of movie portion and server portion and each checkout key; the movie portion of the checkout key; and a numerical checkout ID.
10 . The method of claim 7 wherein the request comprises a checkout ID and an authorization response key, the authorization response key comprising a randomized binary value generated by the client.
11 . The method of claim 10 , further comprising displaying an error message if the decrypting fails or if the response comprises an error code.
12 . The method of claim 7 , further comprising continuing to decrypt and render samples until the user stops playback or the movie ends.
13 . An apparatus comprising:
one or more processors configured to:
receive digital media;
receive a request from a client for digital media;
send the protected copy to the client;
receive a request from the client to access the digital media;
send cryptographic data to decrypt the protected digital media if the client is authorized to access the digital media and a key and authorization instructions; and
wherein the key and authorization instructions permit the client to decrypt and view the media a finite number of times without sending a further request to access the digital media.
14 . The apparatus of claim 13 wherein the digital media comprises one or more QuickTime movies, each of the one or more QuickTime movies comprising one or more of a video sample and an audio sample.
15 . The apparatus of claim 13 wherein the protected copy of the digital media comprises the samples encrypted using a checkout key, the checkout key comprising a movie portion and a server portion, wherein there is a one-to-one mapping between each combination of movie portion and server portion and each checkout key;
the movie portion of the checkout key; and a numerical checkout ID.
16 . The apparatus of claim 13 wherein
the request comprises a checkout ID and an authorization response key, the authorization response key comprising a randomized binary value generated by the client; and
the one or more processors are further configured to deny the request if it is determined that the response key was used by a previous request or if the client is not authorized to play the media.
17 . The apparatus of claim 16 wherein the one or more processors are further configured to store the response key if it is determined that the response key was not used by a previous request.
18 . The apparatus of claim 17 wherein the one or more processors are further configured to encrypt the response using the response key before sending the response to the client.
19 . A nontransitory program storage device readable by a machine, embodying a program of instructions executable by the machine to perform a method, the method comprising:
receiving a request from a client for a protected copy of a digital media file; updating the metadata in the requested media file to reflect the expansion of each sample due to encryption; creating a stub file with the updated metadata; inserting at least one encrypted sample of the digital media file into the stub file; and sending the stub file with the encrypted sample inserted to the client.
20 . The method of claim 19 wherein the digital medial file comprises header data and video data.
21 . The method of claim 20 wherein the stub is initially created without video data before insertion of the encrypted portion.
22 . The method of claim 19 wherein the metadata includes at least one of header data, track metadata, or sample metadata.
23 . The method of claim 19 , where in the header data includes track atoms.Join the waitlist — get patent alerts
Track US2014082657A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.