Method and apparatus for secure distribution of digital content
Abstract
A method and apparatus for secure distribution of digital content is provided. In accordance with at least one embodiment, an intermediate device maintains an authorized content sink list which it uses to allow reauthorization of a first content sink for access to first content from a first content source when the first content sink has a first content sink entry on the authorized content sink list. In accordance with at least one embodiment, reauthorization is conditioned upon a first content sink entry currency status having not yet expired. In accordance with at least one embodiment, the intermediate device allows authentication of the first content sink by the first content source when no first content sink entry exists on the authorized content sink list or when the first content sink entry currency status has expired.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An intermediate device for distributing protected content from a first source device to one or more sink devices, the intermediate device being configured to:
obtain authorization from the first source device to receive protected content from the first source device; detect a connection of a first sink device to the intermediate device; start authentication of the first sink device by transmitting first cryptographic public key information of the intermediate device to the first sink device; receive second cryptographic public key information of the first sink device from the first sink device; determine whether the second cryptographic public key information of the first sink device is in an authorized list maintained by the intermediate device; if the second cryptographic public key information of the first sink device is in the authorized list, complete the authentication of the first sink device provide the protected content to the first sink device without requiring authentication of the first sink device by the first source device; if the second cryptographic public key information of the first sink device is not in the authorized list, end authentication of the first sink device, provide a connection between the first source device and the first sink device, passively monitor authentication transactions between the first source device and the first sink device, and upon observing authentication of the second cryptographic public key information of the first sink device by the first source device, associate time information with the second cryptographic public key information of the first sink device and add the second cryptographic public key information of the first sink device to the authorized list maintained by the intermediate device.
2 . The intermediate device of claim 1 wherein the first cryptographic public key of the intermediate device comprises a key selection vector (KSV) of the intermediate device.
3 . The intermediate device of claim 1 further configured to determine whether the second cryptographic public key information of the first sink device meets currency requirements and to end authentication of the first sink device if the second cryptographic public key information of the first sink device does not meet the currency requirements.
4 . The intermediate device of claim 1 further configured to act as a sink device for the first source device.
5 . The intermediate device of claim 4 further configured to act as a source device for the first sink device.
6 . The intermediate device of claim 1 further configured to determine whether a maximum device number for the first source device has been exceeded.
7 . The intermediate device of claim 1 wherein the intermediate device comprises a distribution amplifier.
8 . The intermediate device of claim 1 wherein the intermediate device comprises a switcher.
9 . An intermediate device configured to be connected to a first source device and to one or more sink devices and further configured to:
receive public key information for each sink device connected to the intermediate device of the sink device; provide a connection between the sink device and the first source device; monitor authentication transactions between the sink device and the first source device; upon observing by the intermediate device that the cryptographic public key information of the sink device has been authenticated by the first source device, add the cryptographic public key information of the sink device to an authorized list maintained by the intermediate device; propagate cryptographic public key information in the authorized list to other devices.
10 . The intermediate device of claim 9 wherein the intermediate device comprises a distribution amplifier.
11 . The intermediate device of claim 9 wherein the intermediate device comprises a switcher.
12 . An intermediate device configured to be connected to a first source device and to one or more sink devices and further configured to:
receive public key information for each sink device connected to the intermediate device of the sink device; provide a connection between the sink device and the first source device; monitor authentication transactions between the sink device and the first source device; upon observing by the intermediate device that the cryptographic public key information of the sink device has been authenticated by the first source device, associate time information with the cryptographic public key information of the sink device and add the cryptographic public key information of the sink device to an authorized list maintained by the intermediate device.
13 . The intermediate device of claim 12 further configured to reauthenticate a sink device if the cryptographic public key information of the sink device is found by the intermediate device in the authorized list maintained by the intermediate device after detecting a connection of the sink device to the intermediate device.
14 . The intermediate device of claim 12 further configured to propagate cryptographic public key information in the authorized list maintained by the intermediate device to other devices.
15 . The intermediate device of claim 12 further configured to transmit cryptographic public key information contained in the authorized list to the first source device for authentication.
16 . The intermediate device of claim 12 further configured to transmit cryptographic public key information contained in the authorized list to the first source device for authentication during a time during which the first source device is inactive.
17 . The intermediate device of claim 12 wherein the intermediate device comprises a distribution amplifier.
18 . The intermediate device of claim 12 wherein the intermediate device comprises a switcher.Join the waitlist — get patent alerts
Track US2014270171A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.