US2017093572A1PendingUtilityA1

Systems and methods for utilizing hardware assisted protection for media content

Assignee: MCAFEE INCPriority: Sep 25, 2015Filed: Sep 25, 2015Published: Mar 30, 2017
Est. expirySep 25, 2035(~9.2 yrs left)· nominal 20-yr term from priority
G06F 21/53G09C 5/00G06Q 2220/00H04L 2209/60H04L 9/3247G06Q 20/3829G06Q 20/1235H04L 2209/76H04L 9/14G06F 21/16G06Q 20/3227H04L 9/3242G06F 2221/0755G06F 21/107H04L 9/0819G06F 2221/2149G06F 21/602G06F 21/1063
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

This disclosure describes systems and methods related to utilizing hardware assisted protection for media content. In some embodiments, a provided method comprises: receiving, from a content server and by a computing device processor of a secure enclave of a device, first encrypted media content; decrypting, by the computing device processor, the first encrypted media content using a first decryption key; generating, by the computing device processor, a second decryption key; encrypting, by the computing device processor, the first decrypted media content using the second key, thereby resulting in second encrypted media content; and sending, by the computing device processor and to one or more graphical processing units (GPUs) comprised in a graphics component of the device, the second encrypted media content and the second decryption key.

Claims

exact text as granted — not AI-modified
1 . A device comprising:
 a graphics component in communication with the display and comprising one or more graphical processing units (GPUs); and   a secure enclave in communication with the graphics component, comprising:
 at least one memory comprising computer-executable instructions stored thereon; and 
 one or more processing elements to execute the computer-executable instructions to:
 receive first encrypted media content; 
 decrypt the first encrypted media content using a first decryption key; 
 generate a second decryption key; 
 encrypt the first decrypted media content using the second key, thereby resulting in second encrypted media content; and 
 send, to the one or more GPUs, the second encrypted media content and the second decryption key. 
 
   
     
     
         2 . The device of  claim 1 , wherein the device further comprises:
 at least one second memory comprising second computer-executable instructions stored thereon;   one or more second processing elements to execute the second computer-executable instructions to:
 receive the first encrypted media content from a content server; 
 determine the first encrypted media content is intended for the secure enclave; and 
 send at least a portion of the first encrypted media content to the secure enclave. 
   
     
     
         3 . The device of  claim 1 , wherein the computer-executable instructions further comprise computer-executable instructions that cause the one or more processing elements to:
 retrieve a platform identity associated with the device or secure enclave; and   encode the platform identity into the decrypted media content as a watermark.   
     
     
         4 . The device of  claim 3  wherein the platform identity is based at least in part on one or more of a media access control (MAC) address of the device, an identification number of the device, an identification of the secure enclave, or an Internet Protocol (IP) address associated with the device. 
     
     
         5 . The device of  claim 1 , wherein the computer-executable instructions further cause the one or more processing elements to:
 cause to send, to the content server, information associated with the device or a user account associated with the device, wherein the information comprises at least one of payment information and license information; and   identify the first decryption key received from the content server.   
     
     
         6 . The device of  claim 1 , wherein the one or more GPUs:
 receive the second encrypted media content and the second decryption key;   decrypt the second encrypted media content using the second decryption key, thereby resulting in second decrypted media content;   render the second decrypted media content; and   transmit the second decrypted media content to a media player.   
     
     
         7 . The device of  claim 1 , wherein the media player is outside the secure enclave, and wherein the computer-executable instructions further comprise computer-executable instructions that cause the one or more processing elements to:
 retrieve a platform identity associated with the device or secure enclave; and   encode the platform identity into the decrypted media content as a watermark.   
     
     
         8 . The device of  claim 7 , wherein the computer-executable instructions further cause the one or more processing elements to; cause to send, to the content server, an indication that the media content has been sent to one or more GPUs. 
     
     
         9 . The device of  claim 1 , wherein the computer-executable instructions further cause the one or more processing elements to:
 store the first encrypted media content, the second encrypted media content, the first decryption key, the second decryption key, the first decrypted media content, and the second decrypted media content, wherein the first encrypted media content, the second encrypted media content, the first decryption key, the second decryption key, the first decrypted media content, and the second decrypted media content are secure from access from outside the secure enclave.   
     
     
         10 . A non-transitory computer readable storage device including instructions stored thereon, which when executed by the one or more processing elements, cause the secure enclave to perform operations of:
 identifying first encrypted media content;   decrypting the first encrypted media content using a first decryption key;   generating a second decryption key;   encrypting the first decrypted media content using the second key, thereby resulting in second encrypted media content; and   causing to send, to one or more GPUs or a media player, the second encrypted media content and the second decryption key.   
     
     
         11 . The non-transitory computer readable storage device of  claim 10 , wherein the instructions, when executed by the one or more processing elements, further cause the secure enclave to perform operations of:
 retrieving a platform identity associated the device or secure enclave; and   encoding the platform identity into the decrypted media content as a watermark.   
     
     
         12 . The non-transitory computer readable storage device of  claim 11 , wherein the platform identity in based at least in part on one or more or a media access control (MAC) address of the device, an identification number of the device, an identification of the secure enclave, or an Internet Protocol (IP) address associated with the device. 
     
     
         13 . The non-transitory computer readable storage device of  claim 11 , wherein the platform identity in based at least in part on one or more or a media access control (MAC) address of the device, an identification number of the device, an identification of the secure enclave, or an Internet Protocol (IP) address associated with the device. 
     
     
         14 . The non-transitory computer readable storage device of  claim 10 , wherein the instructions, when executed by the one or more processing elements, further cause the secure enclave to perform operations of:
 causing to send, to the content server, information associated with the device or a user account associated with the device, wherein the information comprises at least one of payment information and license information; and   identifying the first decryption key received from the content server.   
     
     
         15 . The non-transitory computer readable storage device of  claim 10 , wherein the instructions, when executed by the one or more processing elements, further cause the secure enclave to perform operations of:
 determining a media player outside the secure enclave;   retrieving a platform identity associated the device or secure enclave; and   
       encoding the platform identity into the decrypted media content as a watermark. 
     
     
         16 . The non-transitory computer readable storage device of  claim 15 , wherein the instructions, when executed by the one or more processing elements, further cause the secure enclave to perform operations of:
 causing to send, to the content server, an indication that the media content has been sent to the one or more GPUs   
     
     
         17 . The non-transitory computer readable storage device of  claim 10 , wherein the instructions, when executed by the one or more processing elements, further cause the secure enclave to perform operations of:
 storing the first encrypted media content, the second encrypted media content, the first decryption key, the second decryption key, the first decrypted media content, and the second decrypted media content, wherein the first encrypted media content, the second encrypted media content, the first decryption key, the second decryption key, the first decrypted media content, and the second decrypted media content are secure from access from outside the secure enclave.   
     
     
         18 . A method, comprising:
 receiving, from a content server and by a computing device processor of a secure enclave of a device, first encrypted media content;   decrypting, by the computing device processor, the first encrypted media content using a first decryption key;   generating, by the computing device processor, a second decryption key;   encrypting, by the computing device processor, the first decrypted media content using the second key, thereby resulting in second encrypted media content; and   sending, by the computing device processor and to one or more graphical processing units (GPUs) comprised in a graphics component of the device, the second encrypted media content and the second decryption key.   
     
     
         19 . The method of  claim 18 , further comprising:
 causing to send, to the content server, information associated with the device or a user account associated with the device, wherein the information comprises at least one of payment information and license information; and   identifying the first decryption key received from the content server.   
     
     
         20 . The method of  claim 18 , wherein the method further comprises:
 receiving the second encrypted media content and the second decryption key;   decrypting the second encrypted media content using the second decryption key, thereby resulting in second decrypted media content;   rendering the second decrypted media content; and   transmitting the second decrypted media content to a media player.

Join the waitlist — get patent alerts

Track US2017093572A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.