Systems and methods for utilizing hardware assisted protection for media content
Abstract
This disclosure describes systems and methods related to utilizing hardware assisted protection for media content. In some embodiments, a provided method comprises: receiving, from a content server and by a computing device processor of a secure enclave of a device, first encrypted media content; decrypting, by the computing device processor, the first encrypted media content using a first decryption key; generating, by the computing device processor, a second decryption key; encrypting, by the computing device processor, the first decrypted media content using the second key, thereby resulting in second encrypted media content; and sending, by the computing device processor and to one or more graphical processing units (GPUs) comprised in a graphics component of the device, the second encrypted media content and the second decryption key.
Claims
exact text as granted — not AI-modified1 . A device comprising:
a graphics component in communication with the display and comprising one or more graphical processing units (GPUs); and a secure enclave in communication with the graphics component, comprising:
at least one memory comprising computer-executable instructions stored thereon; and
one or more processing elements to execute the computer-executable instructions to:
receive first encrypted media content;
decrypt the first encrypted media content using a first decryption key;
generate a second decryption key;
encrypt the first decrypted media content using the second key, thereby resulting in second encrypted media content; and
send, to the one or more GPUs, the second encrypted media content and the second decryption key.
2 . The device of claim 1 , wherein the device further comprises:
at least one second memory comprising second computer-executable instructions stored thereon; one or more second processing elements to execute the second computer-executable instructions to:
receive the first encrypted media content from a content server;
determine the first encrypted media content is intended for the secure enclave; and
send at least a portion of the first encrypted media content to the secure enclave.
3 . The device of claim 1 , wherein the computer-executable instructions further comprise computer-executable instructions that cause the one or more processing elements to:
retrieve a platform identity associated with the device or secure enclave; and encode the platform identity into the decrypted media content as a watermark.
4 . The device of claim 3 wherein the platform identity is based at least in part on one or more of a media access control (MAC) address of the device, an identification number of the device, an identification of the secure enclave, or an Internet Protocol (IP) address associated with the device.
5 . The device of claim 1 , wherein the computer-executable instructions further cause the one or more processing elements to:
cause to send, to the content server, information associated with the device or a user account associated with the device, wherein the information comprises at least one of payment information and license information; and identify the first decryption key received from the content server.
6 . The device of claim 1 , wherein the one or more GPUs:
receive the second encrypted media content and the second decryption key; decrypt the second encrypted media content using the second decryption key, thereby resulting in second decrypted media content; render the second decrypted media content; and transmit the second decrypted media content to a media player.
7 . The device of claim 1 , wherein the media player is outside the secure enclave, and wherein the computer-executable instructions further comprise computer-executable instructions that cause the one or more processing elements to:
retrieve a platform identity associated with the device or secure enclave; and encode the platform identity into the decrypted media content as a watermark.
8 . The device of claim 7 , wherein the computer-executable instructions further cause the one or more processing elements to; cause to send, to the content server, an indication that the media content has been sent to one or more GPUs.
9 . The device of claim 1 , wherein the computer-executable instructions further cause the one or more processing elements to:
store the first encrypted media content, the second encrypted media content, the first decryption key, the second decryption key, the first decrypted media content, and the second decrypted media content, wherein the first encrypted media content, the second encrypted media content, the first decryption key, the second decryption key, the first decrypted media content, and the second decrypted media content are secure from access from outside the secure enclave.
10 . A non-transitory computer readable storage device including instructions stored thereon, which when executed by the one or more processing elements, cause the secure enclave to perform operations of:
identifying first encrypted media content; decrypting the first encrypted media content using a first decryption key; generating a second decryption key; encrypting the first decrypted media content using the second key, thereby resulting in second encrypted media content; and causing to send, to one or more GPUs or a media player, the second encrypted media content and the second decryption key.
11 . The non-transitory computer readable storage device of claim 10 , wherein the instructions, when executed by the one or more processing elements, further cause the secure enclave to perform operations of:
retrieving a platform identity associated the device or secure enclave; and encoding the platform identity into the decrypted media content as a watermark.
12 . The non-transitory computer readable storage device of claim 11 , wherein the platform identity in based at least in part on one or more or a media access control (MAC) address of the device, an identification number of the device, an identification of the secure enclave, or an Internet Protocol (IP) address associated with the device.
13 . The non-transitory computer readable storage device of claim 11 , wherein the platform identity in based at least in part on one or more or a media access control (MAC) address of the device, an identification number of the device, an identification of the secure enclave, or an Internet Protocol (IP) address associated with the device.
14 . The non-transitory computer readable storage device of claim 10 , wherein the instructions, when executed by the one or more processing elements, further cause the secure enclave to perform operations of:
causing to send, to the content server, information associated with the device or a user account associated with the device, wherein the information comprises at least one of payment information and license information; and identifying the first decryption key received from the content server.
15 . The non-transitory computer readable storage device of claim 10 , wherein the instructions, when executed by the one or more processing elements, further cause the secure enclave to perform operations of:
determining a media player outside the secure enclave; retrieving a platform identity associated the device or secure enclave; and
encoding the platform identity into the decrypted media content as a watermark.
16 . The non-transitory computer readable storage device of claim 15 , wherein the instructions, when executed by the one or more processing elements, further cause the secure enclave to perform operations of:
causing to send, to the content server, an indication that the media content has been sent to the one or more GPUs
17 . The non-transitory computer readable storage device of claim 10 , wherein the instructions, when executed by the one or more processing elements, further cause the secure enclave to perform operations of:
storing the first encrypted media content, the second encrypted media content, the first decryption key, the second decryption key, the first decrypted media content, and the second decrypted media content, wherein the first encrypted media content, the second encrypted media content, the first decryption key, the second decryption key, the first decrypted media content, and the second decrypted media content are secure from access from outside the secure enclave.
18 . A method, comprising:
receiving, from a content server and by a computing device processor of a secure enclave of a device, first encrypted media content; decrypting, by the computing device processor, the first encrypted media content using a first decryption key; generating, by the computing device processor, a second decryption key; encrypting, by the computing device processor, the first decrypted media content using the second key, thereby resulting in second encrypted media content; and sending, by the computing device processor and to one or more graphical processing units (GPUs) comprised in a graphics component of the device, the second encrypted media content and the second decryption key.
19 . The method of claim 18 , further comprising:
causing to send, to the content server, information associated with the device or a user account associated with the device, wherein the information comprises at least one of payment information and license information; and identifying the first decryption key received from the content server.
20 . The method of claim 18 , wherein the method further comprises:
receiving the second encrypted media content and the second decryption key; decrypting the second encrypted media content using the second decryption key, thereby resulting in second decrypted media content; rendering the second decrypted media content; and transmitting the second decrypted media content to a media player.Join the waitlist — get patent alerts
Track US2017093572A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.