Multimedia data protection
Abstract
A method of transmitting a media work such as a movie to a client is disclosed. The method includes (a) encrypting the work using a sequence of different keys corresponding to respective temporally spaced segments of the document, (b) transmitting software code containing an algorithm from a security server to the client, the algorithm having a result that is a function of the state of the client, (c) executing the code at the client and returning the result to the security server, (d) determining whether the result is indicative of an unmodified client. The method further includes (e) transmitting a segment from a server to the client, (f) securely streaming a key corresponding to the transmitted segment from a secure remote server to the client, (g) decrypting the segment using the obtained media key, (h) if step (d) indicates a modified client, preventing further keys from being transmitted, otherwise repeating steps (e) to (g) and repeating steps (b) to (d).
Claims
exact text as granted — not AI-modified1 . A method of transmitting a media work to a client comprising:
(a) encrypting the work using a sequence of different keys corresponding to respective temporally spaced segments of the work; (b) securely transmitting a first key from a secure server to the client and transmitting the corresponding segment from a server to the client; (c) in the client, using the first key to decrypt the corresponding segment, (d) in the client, presenting the decrypted portion; and (e) repeating steps (b) to (d) in respect of further segments and keys, wherein the keys are transmitted using a key exchange protocol that makes use of a random data generator and the public key of the secure server, the public key being known to the client.
2 . The method as claimed in claim 1 , wherein the client encrypts random data generated by the random data generator with the public key of the secure server to create encrypted data, and requests a key from the secure server, the encrypted data being sent to the secure server with the request for the key.
3 . The method as claimed in claim 2 , wherein the secure server decrypts and extracts the random data, and uses the random data to encrypt the requested key.
4 . The method as claimed in claim 3 , wherein the secure server performs a function using the random data in order to encrypt the key.
5 . The method as claimed in claim 4 , wherein the key and the random data are XOR'd.
6 . The method as claimed in claim 2 , wherein the encrypted requested key is sent to the client and the client extracts the requested key using the random data previously generated.
7 . The method as claimed in claim 2 , wherein the client comprises the random data generator.
8 . The method as claimed in claim 2 , wherein sixteen bytes of random data are used in each key request.
9 . The method as claimed in claim 1 , wherein the keys are delivered cryptographically independently of each other such that no key can be used to decrypt more than one segment.
10 . The method as claimed in claim 1 , wherein keys are only supplied following a check that the client is entitled to receive the document.
11 . The method as claimed in claim 1 , wherein each key corresponds to a segment of a pre-determined length.
12 . The method as claimed in claim 1 , wherein the secure server is remote from the client.
13 . The method as claimed in claim 1 , wherein the server and the secure server are different servers.
14 . The method as claimed in claim 1 , wherein the server and the secure server are the same server.
15 . The method as claimed in claim 1 , wherein each key must be requested individually by the client.
16 . The method as claimed in claim 1 , further comprising checking the integrity of the client to ensure that the client has not been tampered with.
17 . The method as claimed in claim 16 , wherein the secure server is arranged to cease the supply of keys in the event that either client modification is detected or if the client integrity check is not successful.
18 . The method as claimed in claim 16 , wherein the integrity of the client is checked by software code containing an algorithm which is transmitted from a security server to the client.
19 . The method as claimed in claim 18 , wherein each key is transmitted only during a trust interval of the transmitted software code that has successfully verified the integrity of the client.
20 . The method as claimed in claim 16 , wherein checking the integrity of the client comprises the use of randomly generated algorithms which will only return the correct result if the client is unmodified.
21 . The method as claimed in claim 1 , further comprising transmitting software code containing an algorithm from a security server to the client, the algorithm having a result that is a function of the state of the client, executing the code at the client, and determining whether the result is indicative of an unmodified client.
22 . The method as claimed in claim 21 , wherein the secure server and the security server are the same server.
23 . The method as claimed in claim 21 , wherein the result is returned to the security server.
24 . The method as claimed in claim 21 , wherein keys are only transmitted if the result is indicative of an unmodified client.
25 . The method as claimed in claim 21 , wherein the code contains a checksum calculation into which program code of the client and/or memory image of the client is input.
26 . The method as claimed in claim 1 , wherein the media work is streamed to the client from a remote server.
27 . An apparatus configured to operate according to the method of claim 1 .
28 . A system for transmitting a media work to a client, the system comprising:
i) a protection tool arranged to encrypt the work using a sequence of different keys corresponding to respective temporally spaced segments of the work; ii) a secure server arranged to a) transmit a first key to the client; iii) a server arranged to b) transmit a first segment corresponding to the first key to the client; and iv) a client arranged to c) receive the first key and the first segment, decrypt the first segment using the first key, and present the decrypted portion; wherein the secure server, server and client are arranged to carry out steps a), b) and c) for further segments and keys, and wherein the secure server is arranged to transmit the keys using a key exchange protocol that makes use of a random data generator and the public key of the secure server, the public key being known to the client.
29 . A system for transmitting a media work to a client, the system comprising:
i) a secure server arranged to a) transmit a first key to the client, the first key being one of a sequence of different keys with which temporally spaced segments of the work are encrypted; and ii) a server arranged to b) transmit a first segment corresponding to the first key to the client; wherein the secure server and server are arranged to carry out steps a) and b) for further segments and keys, and wherein the secure server is arranged to transmit the keys using a key exchange protocol that makes use of a random data generator and the public key of the secure server, the public key being known to the client.Join the waitlist — get patent alerts
Track US2014189358A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.