US2021209236A1PendingUtilityA1

Multi-phase digital content protection

Assignee: AT & T IP I LPPriority: Jun 27, 2018Filed: Mar 22, 2021Published: Jul 8, 2021
Est. expiryJun 27, 2038(~11.9 yrs left)· nominal 20-yr term from priority
H04L 63/0876H04L 63/101G06F 21/602H04L 9/3268H04L 2209/60H04L 9/0869H04L 9/14H04L 63/0428G06F 21/33G06F 21/10H04L 2463/061
57
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

In one example, the present disclosure describes a device, computer-readable medium, and method for multi-phase protection of digital content. For instance, in one example, a method includes receiving a request for digital content from a client device, initiating a digital content protection process comprising a plurality of phases, where each phase of the plurality of phases includes verifying credentials provided by the client device, delivering a plurality of seeds to the client device, wherein each individual seed of the plurality of seeds is delivered to the client device upon a successful completion of one phase of the plurality of phases, encrypting the digital content, using an encryption key derived using the plurality of seeds, to generate encrypted content, and delivering the encrypted content to the client device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method comprising:
 receiving, by at least one processor, a request for accessing digital content from a client device;   initiating, by the at least one processor, a digital content protection process comprising a plurality of phases, where each phase of the plurality of phases includes verifying credentials provided by the client device;   delivering, by the at least one processor, a plurality of seeds to the client device, wherein each individual seed of the plurality of seeds is delivered to the client device upon a successful completion of one phase of the plurality of phases;   encrypting, by the at least one processor, the digital content, using an encryption key derived using the plurality of seeds, to generate encrypted content; and   delivering, by the at least one processor, the encrypted content to the client device.   
     
     
         2 . The method of  claim 1 , wherein the plurality of phases comprises at least two of:
 a manufacture phase for verifying a manufacture of the client device by an expected vendor;   a registration phase for verifying a registration of the client device with a global server that maintains a whitelist for a site;   an authentication phase for verifying authentication of the client device with the global server; or   an authorization phase for verifying that the client device is authorized to access the digital content.   
     
     
         3 . The method of  claim 2 , wherein the plurality of seeds comprises:
 a first seed delivered after a successful completion of the manufacture phase;   a second seed delivered after a successful completion of the registration phase;   a third seed delivered after a successful completion of the authentication phase; and   a fourth seed delivered after a successful completion of the authorization phase.   
     
     
         4 . The method of  claim 3 , wherein the first seed is associated with a collection of devices, and the first seed is pre-installed by the expected vendor on the client device at a time of manufacture of the client device. 
     
     
         5 . The method of  claim 3 , wherein the first seed is associated with a collection of devices, and the first seed is updated by the expected vendor. 
     
     
         6 . The method of  claim 3 , wherein the second seed is associated with registered devices at the site, and the second seed is updated by the global server. 
     
     
         7 . The method of  claim 3 , wherein the third seed is associated with authenticated devices, and the third seed is updated by a local server that serves the site. 
     
     
         8 . The method of  claim 3 , wherein the fourth seed is associated with authorized digital content, and the fourth seed is updated by a local server that serves the site. 
     
     
         9 . The method of  claim 3 , wherein the first seed is used to derive a first root key from a set of root keys. 
     
     
         10 . The method of  claim 9 , wherein the second seed is delivered in an encrypted form that is decrypted using the first root key. 
     
     
         11 . The method of  claim 10 , wherein the third seed is delivered in an encrypted form that is decrypted using a second root key, wherein the second root key is derived from the first root key and the second seed. 
     
     
         12 . The method of  claim 11 , wherein the fourth seed is delivered in an encrypted form that is decrypted using a third root key, wherein the third root key is derived from the second root key and the third seed. 
     
     
         13 . The method of  claim 12 , wherein the encryption key is derived from the third root key and the fourth seed. 
     
     
         14 . The method of  claim 12 , wherein the fourth seed is delivered in-band with the encrypted content. 
     
     
         15 . A method comprising:
 sending, by a client device, a request for accessing digital content;   engaging, by the client device, in a digital content protection process with a server, wherein the digital content protection process comprises a plurality of phases, and wherein each phase of the plurality of phases includes providing credentials to the server;   receiving, by the client device, a plurality of seeds from the server, wherein each individual seed of the plurality of seeds is received by the client device upon a successful completion of one phase of the plurality of phases;   receiving, by the client device, the digital content in an encrypted form upon a successful completion of all phases of the plurality of phases; and   decrypting, by the client device, the digital content using a decryption key derived using the plurality of seeds.   
     
     
         16 . A non-transitory computer-readable medium storing instructions which, when executed by the processor of a client device, cause the processor to perform operations, the operations comprising:
 sending a request for accessing digital content;   engaging in a digital content protection process with a server, wherein the digital content protection process comprises a plurality of phases, and wherein each phase of the plurality of phases includes providing credentials to the server;   receiving a plurality of seeds from the server, wherein each individual seed of the plurality of seeds is received by the client device upon a successful completion of one phase of the plurality of phases;   receiving the digital content in an encrypted form upon a successful completion of all phases of the plurality of phases; and   decrypting the digital content using a decryption key derived using the plurality of seeds.   
     
     
         17 . The non-transitory computer-readable medium of  claim 16 , wherein the plurality of phases comprises at least two of:
 a manufacture phase for verifying a manufacture of the client device by an expected vendor;   a registration phase for verifying a registration of the client device with a global server that maintains a whitelist for a site;   an authentication phase for verifying authentication of the client device with the global server; or   an authorization phase for verifying that the client device is authorized to access the digital content.   
     
     
         18 . The non-transitory computer-readable medium of  claim 17 , wherein the plurality of seeds comprises:
 a first seed delivered after a successful completion of the manufacture phase;   a second seed delivered after a successful completion of the registration phase;   a third seed delivered after a successful completion of the authentication phase; and   a fourth seed delivered after a successful completion of the authorization phase.   
     
     
         19 . The non-transitory computer-readable medium of  claim 18 , wherein the first seed is used to derive a first root key from a set of root keys. 
     
     
         20 . The non-transitory computer-readable medium of  claim 19 , wherein:
 the second seed is delivered in an encrypted form that is decrypted using the first root key;   the third seed is delivered in an encrypted form that is decrypted using a second root key, wherein the second root key is derived from the first root key and the second seed;   the fourth seed is delivered in an encrypted form that is decrypted using a third root key, wherein the third root key is derived from the second root key and the third seed; and   the encryption key is derived from the third root key and the fourth seed.

Join the waitlist — get patent alerts

Track US2021209236A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.