Initial viewing period for authorization of multimedia content
Abstract
According to one embodiment of the invention, a free preview of a program can be provided to client computers in a multicasting system. This can allow viewers in the multicasting system to view a first portion of the program before deciding whether to order the program content. According to another embodiment, various distribution methods can be accomplished using encryption keys to distribute program content. According to yet another embodiment, an initial viewing period can be provided to allow negotiation of the encryption keys. According to another embodiment, rules and conditions for providing content in a multicasting environment can be utilized.

Term
Term ended
Projected expiry passed 26 October 2021, 4.9 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
18 claims: 16 independent, 2 dependent
- 1A method of multicasting, the following includes:Provide ( 1610 ) A program content for multicasting to a plurality of customers;encrypt ( 1620 ) a first portion of said program content by utilizing a first key to an encrypted to produce the first portion of the program content;Provided ( 1605 ) Of the plurality of clients with said first key;multicasting ( 1640 ) The encrypted first portion of said program content to said plurality of clients, before the plurality of clients indicating an intent to program content to acquire, marked by: Provide ( 1670 ) a guaranteed period during the multicasting of encrypted the first portion of the program content, to enable a customer, To purchase the program content without the presentation of the program content is interrupted.
- 2A method as described in claim 1, and further comprising:encrypt ( 1650 ) of the first Portion of the program content with the first key via a predetermined period of time, to allow a user to to get a free preview of the program content.
- 4A method as described in claim 1, and further comprising:Provide ( 1674 ) one second key;encrypt ( 1680 ) a second portion of said program content with the second key to an encrypted to produce the second portion of the program content;Provided ( 1684 ) Of each of the customers that the program content in the purchased guaranteed period, with the second key, wherein the second key operational is the encrypted second portion of the program content to decipher;and then multicasting ( 1690 ) The encrypted second portion of said program content to said plurality of clients.
- 5A method as described in claim 4, wherein the second key under a third key encoded and wherein the third key provided a purchasing client after the acquisition of the program content is.
- 7A method as described in claim 6, and further comprising:Set to ( 1760 ) The initial Key distribution period.
- 8A method as described in claim 7, wherein the Adjusting the initial Key distribution period Comprising:Extend the initial Key distribution period.
- 9A method as in one of claims 6, 7 or 8 described, and further comprising:Determining an actual Number of purchasing clients;Determine that the actual Number of purchasing clients is greater than the-assessed Number of customers is;Extend the initial Key distribution period, to allow that the presentation of the program content in which at least one purchasing client is not interrupted.
- 10A machine-readable medium having machine- Code for performing a method which comprises:Provide ( 1610 ) a program content for multicasting to a plurality of customers;encrypt ( 1620 ) a first portion of said program content by utilizing a first key to an encrypted to produce the first portion of the program content;Provided ( 1605 ) Of the plurality of clients with said first key;multicasting ( 1640 ) The encrypted first portion of said program content to said plurality of clients, before the plurality of clients indicating an intent to program content to acquire, marked by: Provide ( 1670 ) a guaranteed period during the multicasting of encrypted the first portion of the program content, to enable a customer, To purchase the program content without the presentation of the program content is interrupted.
- 11A machine readable medium as described in claim 10, and further comprising computer-executable code operable, to perform the following:encrypt ( 1650 ) the first portion of the program content with the first key via a predetermined period of time, to allow a user to to get a free preview of the program content.
- 12A machine readable medium as in any one of claims 10 or described 11, and further comprising a machine- includes code operable is to perform the following:ask ( 1660 ) A user to purchase the program content.
- 13A machine readable medium as described in claim 10, and further comprising computer-executable code operable, to perform the following:Provide ( 1674 ) Of a second key;encrypt ( 1680 ) a second portion of said program content with the second key to an encrypted to produce the second portion of the program content;Provided ( 1684 ) Of each of the customers that the program content in the purchased guaranteed period, with the second key, wherein the second key operational is the encrypted second portion of the program content to decipher;and then multicasting ( 1690 ) The encrypted second portion of said program content to said plurality of clients.
- 14A machine readable medium as described in claim 13, and further comprising computer-executable code for encrypting the second key under a third key and providing a purchasing client with the third key to includes the acquisition of the program content.
- 16A machine readable medium as described in claim 15, and further comprising computer-executable code operable, to perform the following:Set to ( 1760 ) The initial Key distribution period.
- 17A machine readable medium as described in claim 16, and further comprising computer-executable code operable, to perform the following:Extend the initial Key distribution period.
- 18A machine readable medium as in any one of claims 15, 16 or 17 described above, and further comprising a machine- includes code operable is to perform the following:Determine an actual Number of purchasing clients;Determine that the actual Number of purchasing clients is greater than the-assessed Number of customers is;Extend the initial Key distribution period, to allow that the presentation of the program content in which at least one purchasing client is not interrupted.
Independent claims16
137 paragraphs in 4 sections, as filed
These Invention relates generally to the field of multicast networks. More particularly, the invention relates to providing a preview section a program, which is distributed to the clients in the network.
BACKGROUND
It are a variety of systems for distributing content, such as audiovisual content, to users over networks. An example is the per-mission-pay TV programming, in which a user for a program pays before he looks at it. Another example is programming on a subscription basis, where a user a Service provider for a subscription is charged to the program for a particular channel for a to receive prearranged period. For example, HBO<sup>TM</sup> or SHOWTIME<sup>TM</sup> Examples for programs subscription-based, in which a user pays a monthly fee, broadcast to any on the designated channel for those programs to receive programs. Therefore, the user does not for each individual Broadcast or every single event that / which specific on these channels occurs, pay. Instead, the subscription payment covers the entire Programming from.
With the advent of multicast networks can program content, such as Movies and music, now in multicast transmissions over networks be distributed. For example, a server on the Internet a movie collecting terminate at customer computer. This can be achieved that the content distributed simultaneously to the address of each customer is. However, there seems no cipher system available to be in order to facilitate the commercialization of such transmissions. And seems no cipher system to be in use, that allows a user, a preview of a program that is encrypted and later to the user not available will be to see.
In Consequently must most multicast transmissions transmitted to a group of customers be, the interested public in advance as to the type of programming are. This reduces the commercial use of the program content provider the fact that the program content provider interested no other Viewers can tempt you to purchase the program by sending a free Preview of the program provides.
The Document WO9907150 discloses a cable television system, the conditional providing access to services. The service objects are under Using public and / or private keys, of service providers or central authorization agents Provided, encrypted. Key, that are used by the set tops for selective decryption may also of public or private nature, and such keys can different times to be reassigned to a cable television system provide, in minimizing the concerns about piracy are.
To can to a certain amount interactive services are used without authorization. "Free Previews "are possible.
SUMMARY
Of the The present application is defined in the appended claims.
SHORT DESCRIPTION THE DRAWINGS
<figref idrefs="S63">1</figref> is a block diagram of one embodiment of a content distribution system such as those for multicasting of Program content over the Internet can be used.
<figref idrefs="S63">2</figref> is a block diagram of one embodiment a client computer portion of the content distribution system, the in <figref idrefs="S63">1</figref> is shown.
<figref idrefs="S64">3</figref> is a flow diagram embodiment of a the invention to provide a customer a free preview illustrated.
<figref idrefs="S64">4</figref> is a flow diagram for another embodiment of the invention Providing free preview content illustrated.
<?page 3?>
<figref idrefs="S65">5</figref> is a flow diagram embodiment of a the invention for distributing a non-encrypted portion of a program and an encrypted illustrates a portion of a program.
<figref idrefs="S65">6</figref> is a flow diagram embodiment of a the invention to enable illustrates the display of a free preview.
<figref idrefs="S66">7A</figref> and <figref idrefs="S66">7B</figref> are Graphs showing an exemplary distribution of cryptographic keys during portions show a program.
<figref idrefs="S67">8</figref> illustrated a flow chart for distributing keys according to an embodiment of the Invention.
<figref idrefs="S67">9</figref> illustrated another flow chart for distributing keys according to a Alternatively, the invention.
<figref idrefs="S68">10</figref> illustrated a flowchart for an embodiment of the invention in the key at several customers are collecting sent.
<figref idrefs="S68">11</figref> illustrated a flow diagram embodiment of a the invention demonstrates, in the customer key from a server for receiving Request of multicast content.
<figref idrefs="S69">12</figref> illustrated an embodiment the invention of the distribution of keys to customers at the customer an acknowledgment message, that a key was received, to send.
<figref idrefs="S69">13</figref> illustrated a flowchart for an embodiment the invention in which a list of active participants, a program receive, create and send customer confirmation messages Show that they should remain on the list.
<figref idrefs="S70">14</figref> illustrated a flowchart for an embodiment of the invention in which a modified RTP packet for signaling of changes a cryptographic key is created.
<figref idrefs="S70">15</figref> illustrated a flow diagram according to an embodiment the invention, to customers in a multicast system a common key provide.
<figref idrefs="S71">16A</figref> and <figref idrefs="S72">16B</figref> illustrate a flow diagram according to an embodiment the invention for providing an initial preview of program content.
<figref idrefs="S72">17</figref> illustrated a flow diagram according to an embodiment the invention to provide an adjustable initial Key distribution period for acquiring program content.
<figref idrefs="S73">18</figref> illustrated a flow diagram according to an embodiment the invention for providing uninterrupted intuition of Program content by a late purchasing client.
<figref idrefs="S73">19</figref> shows a network for use in accordance with a embodiment the invention.
<figref idrefs="S74">20A</figref> and <figref idrefs="S74">20B</figref> illustrate a flow chart for conveying of records from an origin content server to a caching server in accordance with a embodiment the invention.
<figref idrefs="S75">21</figref> illustrated a flow diagram according to an embodiment the invention includes determining whether a customer to program content is entitled, on the basis of providing at least one rule to is the program content associated for use by a caching server.
<figref idrefs="S75">22</figref> illustrated a data structure according to a embodiment the invention for conveying information from an origin content server to a caching server.
<figref idrefs="S75">23</figref> illustrated a record according to a embodiment of the invention which are an individual customer provided can in order to claim this particular customer on different program content define.
<?page 4?>
DESCRIPTION THE SPECIFIC EMBODIMENTS
Among with reference to <figref idrefs="S63">1</figref> is a block diagram of a Content distribution system <figref>100</figref> shown. In this embodiment, closes the content distribution system <figref>100</figref> a current directory <figref>104</figref>. one or more origin servers <figref>108</figref>, One or more customer computer <figref>112</figref>, One or more content exchanges <figref>116</figref>. one or more external origin server <figref>118</figref>, a net such as the Internet <figref>120</figref> and a web-search directory (Crawling directory) <figref>124</figref> on. A certain customer computer<figref>112</figref> becomes shown connected to the current directory <figref>104</figref> interacts, a content object select to download. The object can during be downloading played if it is a streaming media is, or it may for later Display are stored. The content object might different types of be information such as audio, video or data to download the network available to stand. Furthermore, it may for multicasting and / or single ended be used.
at some embodiments determine the origin server <figref>108</figref> the preferred source, to lead to the customer's computer for downloading content objects. The preference the client computer <figref>112</figref> and the location of copies of the Content object are all considerations, the source server <figref>108</figref> can use it, the customer computer redirect to a preferred source of information. This source may the origin server <figref>108</figref> be yourself or the content exchanges <figref>116</figref>,
content objects an external source server <figref>118</figref> can on a for providing preinstalled this content objects allocated content exchange (s) will. To the latency when first requesting a content object reduce, can the current directory <figref>104</figref> the external origin server <figref>118</figref> call to the external of the origin server <figref>118</figref> to determine the available content objects. The available Content objects can the Web search directory <figref>124</figref> to be added. Once the available content objects are known, can the current directory <figref>104</figref> each Content object of the / the associated Content exchange (s) Request to the loading of each content object to / the associated Content exchange (s) to effect. In this way, content objects to the corresponding Contents Replacing be preinstalled.
<figref idrefs="S63">2</figref> illustrated roughly how individual system elements <figref idrefs="S63">1</figref> on a separate or more integrated manner in various, generally similarly configured can be implemented processing systems. The system shown<figref>200</figref> includes Hardware elements, which a bus <figref>208</figref> are electrically coupled, including a processor <figref>201</figref>, An input device <figref>202</figref>. an output device <figref>203</figref>, A storage device <figref>204</figref>. a reader <figref>205a</figref> for machine-readable Storage medium, a communication system <figref>206</figref>, a Processing acceleration (z. B. DSP or special purpose processors) <figref>207</figref> and a memory <figref>209</figref>, The reader<figref>205a</figref> for machine-readable Storage medium is further provided with a machine-readable storage medium <figref>205b</figref> connected, wherein the combination across remote location, local, fixed and / or removable storage devices plus Storage media, memory, etc. for temporarily and / or more permanent is holding machine-readable information that the storage device <figref>204</figref>. memory <figref>209</figref> and / or any other such accessible Resource system <figref>200</figref> may include. The system<figref>200</figref> includes and software elements (in the present one memory <figref>291</figref> located are shown), including an operating system <figref>292</figref> and other coding <figref>293</figref> as about programs, applets, data and the like.
The system <figref>200</figref> is mainly because of its long-range flexibility and configurability desirable as an implementation alternative. In this way could For example, a single architecture can be used one or to implement more servers, further according to currently desirable protocols, Protokollvariationen-, extensions, etc. can be configured. the Skilled in the art, however, it will be seen that in accordance with more specific application requirements quite substantial variations may be used. To the example could one or more elements within a component of the system <figref>200</figref> (Z. B. within the communication system <figref>206</figref>) As sub-elements be implemented. It could Also, custom hardware can be used, and / or in hardware, Software (including so-called "portable Software "such as Applets) or both could certain elements are implemented. During a connection to other Computing devices such as network input - / - output devices (Not shown) may be employed, it will further be appreciated, that (a) wired, wireless, modem and / or other use connection or connections to other computing devices could become. The distributed processing, the viewing of multiple locations, the Sharing Information, collaboration, remote retrieval and the remote associations of information and related skills are each considered. Use of the operating system varies also depending on the particular host device and / or process types (Z. B. Computer, use, portable <?page 5?>Device, etc.), and it certainly not all components of the system <figref>200</figref> in all make to be required.
The network of <figref idrefs="S63">1</figref> can to a variety of Due to be implemented. According to a embodiment can We, for example, the use of UDP Prokolls (UDP = User Datagram Protocol) assume the "real-time transport protocol" / "Real Time Control Protocol" (RTP / RTCP = Real-Time Transport Protocol / Real-Time Control Protocol), "Internet Group Management Protocol" (IGMP = Internet Group Management Protocol), "Real Time Streaming Protocol" (RTSP = Real-Time Streaming Protocol) and possibly "Session Announcement Protocol" / "Session Description Protocol" (SAP / SDP = Session can carry Announcement Protocol / Session Description Protocol). Furthermore, leaves take it for purposes of multicast addressing that Multicast IP address allocation and assignment of Every management system is Internet Protocol rights transparent. The session description can be accomplished using either the SAP protocol, the RTSP-announce (Ankündigungs-) command or HTTP distributed. As a business model let yourself also assume that per-mission-pay TV, Subscription and Per-term pay-TV all desirable Purchase options are. Furthermore, it is assumed that a television-like channel hopping a expected user experience for is broadcast as multicast distribution.
The Some terms used in this patent understand as follows: <ul><li>Content provider - an instance, the content distributed z. B. to the caching server, without necessarily content to consume.</li><li>Consumer - a Instance, which consumes a obtained from a caching server content and optional content redistributed to other consumers in the system. The roles of the consumer, the caching server and the content provider can be used as a matrix of content sources and sinks are considered, the by allowing behaviors and transfers related to each other to stand.</li><li>Program - an piece specific marked content with a beginning and an end.</li><li>Service - a ongoing Collection of programs on the same stream.</li><li>A running program - a Program not specifically defined beginning and no specific defined end, which viewers usually any at all take or leave time. This is for "TV Shopping", "fashion shows", running sports content etc. suitable.</li><li>Purchase option - a Mechanism that allows a client to purchase content.</li><li>Subscription - a Acquisition mechanism in which the customer for the content substantially logs in advance and may for in Advance pay. The client is typically used for more than one program (eg. B. the whole service) authorized. If only a single program is authorized, it is known as book-ahead-PPV.</li><li>Per-mission-pay TV (PPV = Pay-Per-View) - an acquisition mechanism in where the customer for logs a single program or program bundle and simultaneously it pays. This mechanism can the network or be released locally. In the shared over the network Case contacted the customer the infrastructure when the acquisition hopes and the infrastructure enables the acquisition. This approach has due of maximum demands often before a program Skalierprobleme on. In the locally shared case, often "IPPV" or "pulse" -PPV called, takes the customer to acquire itself locally before and stores a record the acquisition. At a later Time, recording the infrastructure systems for billing notified. This approach is effective when events collecting sent are, for example, since the network before the program beginning no sudden Increase in demand experienced. In the locally shared case the customer also see the content immediately, as there is no network latency or message exchange delays are. In both cases apply PPV acquisitions typically for an entire program, regardless of how many actually is considered.</li><li>Per-term pay-TV (PBT = Pay-Per-Time) - a purchase mechanism in where the customer for the period of time over the content of the actual was considered, pays. In different programs or services can having individual time increments different durations. PBT is limited to a small set of programs and services, at where a viewer an indiscriminate access without loss of perceived can tolerate value. Some sports and music events belong to this Type.</li><li>Per-quality pay-TV (PBQ = Pay-Per-Quality) - Content can with a different quality (ie bit rate) offered be, either as separate streams or as layered streams, each additional layer containing additional quality confers. The customer can the highest offered notified bitrate that he can consume, and it can are to acquire the program with this or a lower quality. The server can also be the rate in real time based on the immediate Setting the state of the network. If a temporary network congestion is detected, the quality the contents of a period of time can be reduced and then return to the publicized quality go back. The server can track such incidents and the accounting center notified that the user is less than the original Price could calculate. The customer can also perceive genome of the user<?page 6?>mene bit rate according to the user choice set to. For example, a thumbnail image program for the user a Value, but not if its cost is equal to those for a program are, that is viewable on the full screen in the living room.</li></ul>
time of acquiring customers can acquire content at different times: <ul><li>In advance - the customer decides to the content on a considerable time in advance purchase. Such a purchase may be the entire service such as be a subscription rather than a single program belongs.</li><li>Just before or during program - the Customer decides the content just before the start of the content or during of the content, very close to acquire start out.</li><li>Video on demand (VOD = Video On Demand) - VOD is a point-to-point delivery system a single consumer with a stream based on its individual selection stored content served. The consumer can such functions as a Pause ", fast forward 'and' call return to the Anschauerlebnis on his immediate needs tailor.</li><li>Multicasting - multicasting is similar to the existing TV broadcasting. It delivers the same content at the same time to one or more Consumer. This is usually schedule and can live Content be.</li><li>Free Preview - the free preview is a mechanism that the consumer allows a small piece (Z. B. several minutes) to look before he has to pay for the content. This is used to attract users to content. Another Using lies periods dense server traffic, such as the start of a PPV event, when most consumers for be logged in the content, to compensate. The consumer may they may be See, while His credentials are validated. (After the end of the free preview period, or when there is no preview, it is possible to Periods dense server traffic further compensate the fact that a separate group key is used, the registered customer is known in advance.) The free preview may offer a lower quality will.</li><li>Origin Content Server (OCS = Origin Content Server) - server on a computer of a content provider, the z. B. a caching store provides content.</li></ul>
acquisition models
at the model of the point-to-point VOD delivery of content are the Purchase Options relatively simple because on each piece of content (An event) is negotiated separately. Therefore, the per-mission-pay model suitable for point-to-point VOD delivery. Since the communication between consumer and server typically a two-way connection is carried to the primary Mechanism to negotiate access to the contents of the addition before watching the content (As opposed to the store-and-Forwarding IPPV mechanism is used in traditional systems).
The Multicast model offers different mechanisms to content on the base (<figref>1</figref>) Of consumer preferences, (<figref>2</figref>) of the Nature of the ingredient or (<figref>3</figref>) The nature of the publication the content for sale.
Per-mission-pay TV
Per-mission-pay TV (PPV) therein may be similar to the point-to-point VOD model in the multicast model, that a customer buys a single event. A difference lies in the fact that the event is encrypted once and shared by multiple clients; therefore negotiate a Computer a user and the caching server does not have a unique content encryption key per user.
On Another difference is that a large number of clients with access to the same event at the same time - the beginning of this event - Request will. This creates a high load on the system within a relatively small time window. is to empowering scalability it is possible to set up a free preview period to the caching server enough time to give the content encryption key to be distributed to all participants.
The The following example illustrates an embodiment of implementation the per-mission-pay model. This PPV scenario is the "content similar on-call "case, in which the user determines what content they wish to receive when. If the origin content server (OCS) will recognize that the customer is not a subscriber is leading he the customer through a set of warrants and other content access rules and restrictions. Once the customer selects the purchase option, it is in the secured If<?page 7?>project included. The protected premises can also all rules, the piece given to the content associated are, or include a subset thereof.
Of the Customer supplies the secured object and a label with its own Authorization data (z. B. a list of subscribed services, location, ability for the paid content, etc.). to the caching server The caching server examines the presented by the customer To determine secured object and label to that customer choice from the hedged object and the credentials of the label with the content access rules match. If all the rules are respected, granted the caching server access to the requested content, by the content encryption key on the program key provides, for. example is the program key using its unique key delivered to the customer, while the content key under the program key encoded is.
subscription
In one embodiment leaves it assume that there is a great Number (thousands or tens of thousands) of video on demand servers and a relatively smaller number (hundreds, possibly thousands) of servers, the multicast content offer are. The subscription model is useful if there is a continuous stream of content, the most of the time available is and to return to a consumer tendency.
If viewers subscribed to the service, the viewer may at his first access to the service be given a service key a extended Useful life than a program key that each one Program event would be assigned. With this key, the return viewers to the service and view the content without going over any new key negotiate. This contributes helping to create the experience of TV channel hopping.
On Target a related embodiment, for a Such a model is that the caching server keeps track of how many Customers the content and when actually watch. If for accounting purposes a certain set of consumers when prompted, the server each time it seeks such a service to contact (as in the Nielsen audience tracking for terrestrial Television) must, given that consumer computers no service key be, but only a new program key. This would be a Configuration or a subscription option included in the label would.
It Note that the subscription model for the point-to-point VOD scenario is useful as a fixed monthly fee for video rental.
The The following example illustrates an embodiment of an implementation the subscription model. If an origin content server (OCS) part the distribution network is, it indicates whether he VOD content or multicast content will provide. If an option is offered to subscribe, shares a provisioning center OCS one or more service identifiers to.
If the customer / consumer this service would like to subscribe, he has a credit card number or provide another suitable method for billing, and its server label, for example, in a Kerberosumgebung, with the list of subscribed services and other authorization data as about authorization, solvency etc. updated.
If the customer / consumer initiates a connection to an OCS provides, he provide the following information: its unique consumer identifier, be acquiring assets (An indication of been that the credit card number is recorded and verified ), and a list of the services he has subscribed to. If the offering OCS payment content, it first checks whether the customer / consumer for can pay the content. If the content on a subscription basis available is the list of subscribed services with the / the service identifier (s) the OCS compared. If the OCS is on the list, the acquisition menus bypassed and the client will be redirected to the correct cache server. If the customer has not subscribed to the service, his acquisition options presents. In both cases created by the OCS a secured object that the OCS service identifier, the source identifier, the selected Acquisition methods (eg. B. Subscription, PPV, PBT etc.) and an indication, whether it is free or cash managed content, and other Include access rules can.
If the customer / consumer with the caching server, the selected content to disposal may provide, links, presents he caching server label, the information on the identity <?page 8?>of Customers be acquiring assets and a list of subscribed services together with that of the OCS including preserved secured object. It should be noted that the customer has neither the label nor the secured object of the OCS Read or change can.
Of the Caching server compares the information of the secured object and the label. If the information matches, the client will granted access to the content (It is the content encryption key given - directly delivered or indirectly in this case using a service key). Otherwise, access to the content will be denied. The caching server also shares the selected purchase option in the products delivered to the billing service usage and Invoice data.
Of the Client can cache the secured property and the service key, so it does not contact the OCS or the caching server again must, if he leaves the service and then comes back to him (Although this is for transparent to the user, leads this a delay the acquisition time).
It Note that the Subscription mode described below from the PPV mode can be simulated without using the service key. The caching server or the billing system recognizes that This customer is a subscriber, and therefore will not account for individual Create events on this service.
Per-term pay-TV
Per-term pay-TV (PBT) is for suitable content that is not well-defined or start or end time having a self-contained sequence of actions, such as fashion shows or persistent sporting events (eg. as the Olympics).
Some existing alternatives to this invention are based on a tree hierarchy keys and an algorithm for transcoding subtrees the hierarchy, when a consumer leaves the group. These existing alternatives size manage multicast group, but only if the frequency, with the consumer to leave the group, relatively small and temporary is well distributed. An embodiment of the invention, on the other hand is designed to be large ball increases the number to cope with consumers, leaving a multicast.
For one Quasi-PBT approach, a caching server in the content payment segments divide and assign key segment. All consumer computers would a key for each Segment negotiate to keep track of how many segments they viewed have. This produces a large Load on the cache server at the segment boundaries. This can be done a key management approach be mitigated, in which each client machine keys for the current as also for the next segment are given. This will give the caching server enough time to get the key for the next segment while the current distribute segment.
The The following example illustrates an embodiment of implementation the per-time-pay model. To some content may be suitable not for sale as PPV. An example of this is content that is not good defined beginning and no well-defined end or a specific Storyline has. This can content such as fashion shows, certain Types of sporting events, etc. Include. At the time at which the viewer with the OCS negotiates the purchase options, it can search for the viewer, select the Per-term pay-TV option, if it is offered. The audience is about elucidated which are the payment periods and the costs of each payment period wearing. The selection of the viewer is trapped in a secured object.
If the client negotiates with the caching server over encryption keys, begins he to receive the multicast content. The client monitors the expiration time for each pay period and calls for a new set of keys the caching server. When the viewer finished viewing or moves to another service, the customer does not request new key or notify the caching server active that he present the wants to leave multicast session. The caching server records the time when each customer the multicast takes up or leaves, for billing purposes on.
<?page 9?>
Free preview
In one embodiment the invention can provide customers computers in the multicast system a free preview of a program are provided. Among with reference to <figref idrefs="S64">3</figref> is a flow chart <figref>300</figref> to the Implementing this embodiment the invention to be seen. In block<figref>304</figref> is encrypted Material provided for distribution to a customer. such encrypted could material for example, a content exchange such as a metropolitan Video exchange or an origin server that supplied the content, to be provided. In block<figref>308</figref> is a key to Use by the customer's computer to decrypt the first portion the encrypted Program material in advance, for example, during deployment, provided. In block <figref>312</figref> the process <figref>300</figref> is the first Section of encrypted Program material distributed to at least one customer. Finally, in block <figref>316</figref> the customer the key to getting him provided the free preview portion of the program was used. Until the program encrypted with a different key, The customer can thus decrypt the program material and get a preview of the program without charge.
Of the Service Provider may allow a user in this manner, a first portion of to receive program material by a predetermined amount of time refrains from changing the code of the encryption. This would a Allow user to look at the preview by using the encryption key.
<figref idrefs="S64">4</figref> illustrated a still further embodiment the invention. In flowchart<figref>400</figref> from <figref idrefs="S64">4</figref> becomes a customer key for free preview in advance, z. B. during deployment, provided, in block <figref>420</figref> shown. In block<figref>404</figref> is encrypted Material provided for distribution to a customer. In block<figref>408</figref> becomes a content key provided. The content key is a key for free preview encrypted, in block <figref>412</figref> shown. The encrypted content key then provided the large number of customers, as of block <figref>416</figref> shown. Customers can then the key for free preview in which customers use to the encrypted content key decrypt in block <figref>424</figref> shown. A first portion of the encrypted Program material can be distributed to the plurality of clients, in block <figref>428</figref> shown. The customer can then the content key use to the encrypted decrypt program content and thereby obtain a free preview of the program content, in block <figref>436</figref> shown. During this process, can a user of a display on the screen with an offer for the acquisition of program material <figref>440</figref> will be prompted. At this time the user may be agreement to the offer on Show a user interface and thus the program content purchase. could at this time a new key for use in decrypting the remaining encrypted Portion of the program will be distributed to the user.
Instead of the delivery of a content key, of a key is encrypted for free preview (FPK = Free Preview Key) , the FPK also be used as an alternative to the initial encrypting portion of the content directly, in which case the initial content key the same value as the FPK.
Still another alternative is a program segment key (PSK = Distribute Program Segment Key), which is encrypted with the FPK. The PSC is then used to identify the content key verschlü with the PSC is sselt, to deliver.
It it should be understood that the various described in this patent Embodiments for Example with repetitive operations while a program multicast can be achieved. In this way, in<figref idrefs="S64">4</figref> the blocks <figref>412</figref> and <figref>428</figref> more than be repeated once. Similarly, it should be understand that some described operations at the same time take place can. The blocks <figref>412</figref> and <figref>428</figref> can turn occur, for example at the same time. While some examples for the sake of Simplification is a relationship between a server and a client can describe, should It addition to understood in more than one client can participate.
Among with reference to <figref idrefs="S65">5</figref> is yet another embodiment of of the invention. In the process<figref>500</figref> out <figref idrefs="S65">5</figref> becomes Program material initially provided for distribution, in block <figref>504</figref> shown. On first portion of the program material over the network to customers Computer distributed as in Block <figref>508</figref> shown. In block<figref>512</figref> becomes allows the user, the remainder of the program content to purchase. While the first portion of the Program material is not encrypted is the remaining portion of is <?page 10?>Program encrypted as in block <figref>516</figref> shown. In this way, a key z. B. be deployed to a server to these remaining encrypting portion of the program. In block<figref>520</figref> is the spread remaining portion of the program to the client computer, to the remaining program content in block <figref>512</figref> requested have to keep the remaining customers computer from the encrypted remaining portion of the program without the proper decryption means received or to view. In this way, the user can be provided with a key which is operable to the encrypted Portion of the program material to decipher. This is yet another A method of providing a free preview, insofar than the initial Program material without encryption is distributed, while the remaining portion is encrypted. Thus, the need Customer computer no decryption key, around the original Portion of the program material to watch. A user can access Thus, the initial watch for free portion of the program material and free decide whether to purchase the remaining portion of the program would like or not.
<figref idrefs="S65">6</figref> illustrated a still further embodiment the invention. In the process<figref>600</figref> out <figref idrefs="S65">6</figref> becomes a Server to communicate with multiple customer computers in block <figref>604</figref> provided. The server is configured to control the plurality of client computers, a provide program content material, as in Block <figref>608</figref> illustrated. For example, could a multicast configuration can be implemented. In block<figref>612</figref> becomes a free preview portion of the program for viewing by the customer's computer provided. It is assumed that the customer is chosen at the end of the free preview period has to look at the rest of the content. It is probably not enough Time left, to communicate with the server and the decrypting Films necessary keys to recieve; therefore the intuited content will come to a halt and then some time later resumed after such keys have arrived. The invention with the concept of the initial Preview period provides a way in which the continuous viewing despite a latency in the server key distribution is possible. block <figref>620</figref> illustrates that an initial Preview period for a period can be provided which is sufficient for that a predetermined number of customer key to decrypt the encrypted receiving portion of the program.
<figref idrefs="S66">7A</figref> illustrated a graph of the number of requests a program via the program duration shows. As from<figref idrefs="S66">7A</figref> It can be seen, provides a initial free preview period before that client computer an initial key for viewing an encrypted Request portion of the program. This number needs probably in the free preview period high and then falls in the remaining program duration. In this way it enables the free preview period that the system requirements of keys while the initial houses intuiting the program.
Below in <figref idrefs="S66">7A</figref> is the distribution of content keys 0, 1 and 2. The content key 0 is supplied to the user in one embodiment for obtaining the free preview provided. The content key 1 and 2 illustrate an example where only two keys are required are to decrypt the rest of the program content.
For example may be the key 0 a well-known key the free preview to be, a content encryption key under the key encrypted for free preview is, or the content may be in the free preview period even not encrypted be. The key 1 would a group key itself or a content encryption key, the under the initial in the is encrypted Anschauperiode group key used, represent. (In the latter case block is used<figref>616</figref> to the encrypted content key Collecting send to the customer.) And the key 2 would be the actual content encryption key, which is delivered only to those customers who purchased the content have. In this way, look Customers who vote on the content, first a free preview on and make a decision to purchase. Those who make such requests, using the group key, so her Anschauerlebnis can continue. The server would the key 2 during provide this time, so that those viewers the rest of the content can look in a continuous manner on. It Note that the concept of the initial Anschauperiode is valid, whether the program offers a free preview or not.
key distribution
Among various distribution methods such as Per-term pay-TV, Per-mission-pay TV, subscription-based, etc., may encryption keys are distributed to customers in order to receive the <?page 11?>Program content to facilitate. An embodiment the invention provides a multi-level key hierarchy ready to various acquisition options such as per-mission-pay TV or Per-term pay- TV accommodate. In one embodiment, the invention can the different types of keys and their relationships be configured as follows: <ul><li>Unique Key (UK = Unique Key): This could For example, a session key be of a customer in a Kerberosumgebung of the Kerberos Key Distribution Center (KDC Key Distribution Center) during the label request message exchange is given. This key is for each viewer and each session unique. The customer retains a List several UK, one for each caching server. Each UK is used to the key request message exchange to initiate with a specific caching server. The UK may also be used to create an encrypted content key (CK = Content Key), service key (SK = Key Service) program key (PK = Program Key) or program segment key (PSK = Program Segment Key) to deliver.</li><li>service key (SK = Key Service): This key spans more than one program span and is a subscription key with a duration of several days to several months is used. He is shared by all subscribers to the service, but may be different from Caching server to distinguish caching server. If a customer a subscribed requested from a particular caching server service has, it is the first time at which the caching server from the Customers will be examined during the key request message exchange the SK added, which was encrypted using the UK by the customer. Once the customer the key has, the client can decrypt the contents of this service until the SK expires. At the time (or preferably appropriately long enough in advance, to overcharge the server to avoid), the customer calls the next version the SK of the caching server.</li></ul>
This mechanism allows , The service to acquire it customers with subscriptions quickly, without having the caching server on key to negotiate, so that the load of the caching server is reduced. This assumes that the content encryption key, Program Segment Key, and the program key frequently be distributed.
Program key (PK = Program Key) This key is for a program margin valid. It is used to gain access to an individual program event which was acquired using the per-mission-pay TV option to grant. Similar to SK he is the customer during the key request message exchange given. The PK can also be encrypted with the SK and to all customers, possessing the SK, are distributed.
Program Segment Key (PSK = Program Segment Key): This key is used to a single Program event or an entire service in erwerbliche segments to divide. The PSC will be using either unicast or multicast distribution delivered. Customers who use the per-time-pay TV-purchase option, obtain the PSC using the key request message exchange. Customers PPV purchase option use, receive the PSK encrypted under the PK using the multicast distribution. Customers with a subscription to the PSK encrypted under the SK or PK using the multicast distribution receive. can (Alternatively, encrypted customer with a subscription a right under the SK CK received.) These segments may overlap, to promote scalability. At any given time two PSK are distributed: the current PSK and the next. this makes possible customers to receive the content further, while the next set Request PSK from the caching server.
Content key (CK = Content Key) This key is used to encrypt the content itself. He should at least so often Change how the PSC. It can be distributed in various ways, eg. B .: (1) encrypted under the PSC for those viewers who select the Per-term pay-TV option, (2) encoded under the PK or UK for Users who select the PPV option, or (3) encrypted an SK for those who have subscribed to the service.
Group Key (GK = Group Key) This key is used to the CK or the PSK that in turn the CK for the initial Anschauperiode encrypted, to distribute. Customers receive the GK before the on PPV or PBT base selling program events, for example, during deployment. Which gives viewers the option to watch the beginning of the content, while the Customer with the caching server on the (The) other key negotiated.
key to free preview (FPK = Free Preview Key): This key is used to the CK or the PSK that in turn the CK for the content in the initial free preview period encrypted distribute. This can a fixed key be known to all customers or during <?page 12?>distributed deployment is.
table 1 shows various embodiments the invention of the distribution of the various keys on Customers. As shown in Table 1, only keys that are be distributed to individual customers using the UK (shown encrypted as under the UK Key), delivered to a single end manner. This einheitenaddressierten meet news the function of the release message (EMM = Entitlement Management Message). Alternatively, can several EMM, encrypted with different UK, for improved efficiency in a single multicast message be combined. Other key can encrypted only once per group of authorized clients and be collecting sent because it the only by those customers, key higher own right, decrypts can be. Accept this group addressed multicast messages the role of tax return messages (ECM messages, ECM = Entitlement Control Message).
<img img-content="tb" img-format="tif" he="93" wi="154" file="00290001.tif" /> table 1
The different embodiments the invention provide models for the distribution of key ready which are outlined above. For example, could a "request" model ( "pull" model), a "delivery" model ( "push" model) and a combined "request delivery" model ( "Push-Pull" model) uses will. The inquiry model to follow pursued every customer the keys and their expiration times and calls for new keys to active before the current keys expire, to avoid service interruptions. Alternatively, transfers the Levy Scheme pursued the responsibility to the server, the active customers and new key distributed to them before the current keys expire. Reine delivery models can also include a form of repeated distribution of reliability reasons. To the Example, the per-mission-pay TV-acquisition model the request mode for key distribution use, because the server must know which customer the program acquires to create a bill that customer. Content key, d. h. the key, the encrypting the program content itself can be used, must during a per-mission-pay TV event not changed will. A customer can request a program key to encrypt the content key for the Per-mission-pay TV program is used. are in this way while the per-mission-pay TV event No other key required; the server can pursue but which customer the key for receiving the per-mission-pay TV event has requested. Similarly Example, the subscription payment model, in which a user a Subscription price is charged to receive a program over a longer period, also Using the request mode. In the initial request for the Subscription model calls for the customer, for example, the subscription and asks a service key to which is encrypted under the unique key for that client. The subscription model allows then to use the output mode by the program key for per-mission-pay TV events or program segment key for Per-term pay-TV events under the service key encoded to the client <?page 13?>be issued. Similarly, the content key is under the program segment key encoded delivered to the customer. The subscription model can thus both use the inquiry as well as the output mode. The key distribution request model that key distribution Levy Scheme and the combined key distribution request / delivery models be detail below explained.
The Key distribution request model allows it that every customer keys active requests from the server. In<figref idrefs="S67">8</figref> is a Flowchart 800 to implement a key distribution request system illustrated. In block<figref>810</figref> a server receives a request a cryptographic key by a customer. The server logs the request of the key in block <figref>814</figref>, So a log entry might, for example, in a Protocol, such as a maintained by the server database be made. In block<figref>818</figref> be the key and its expiration time to the customer in response to the request from the customer spread. In this way, the server must have a status the key of not monitor customers; instead, the responsibility of determining when a new key is required, passed to the customer will. In block<figref>822</figref> is the program content for decryption by the customer using the requested cryptographic key distributed. Finally, in block <figref>826</figref> log entries are used to the customer based on the billing parameters of billing arrangement to create an invoice.
<figref idrefs="S67">9</figref> illustrated a flow chart <figref>900</figref> according to still another embodiment the invention. The method<figref>900</figref> illustrates, for example, that two program segment key can be used to the same content key in two different multicast messages to a customer transferred to. If a user does not have any new program segment key receiving has, the content key may are thus obtained by using the old program segment key is. This "soft" key transition allows flexibility upon receipt of the key updates. While this it to customers who had not requested the new program segment key, enable would, the next receiving segment, it prevents the loss of service for those Customers who ordered the new program segment key. This Problem is attenuated be by the program segment into smaller content encryption tensioning is divided.
In block <figref>910</figref> in turn is a requirement of a cryptographic key received from a customer. The request for the key is in block<figref>914</figref> shown logged. In block<figref>918</figref> is the segment of the program content, for the the key can be used logged in the log record. The server in turn needs the need for a key by not to monitor a customer. Instead, the customer can independently proceed from the server with the request of the key. In block<figref>926</figref> becomes the desired key encrypted with a first program segment key. In block <figref>930</figref> is the encrypted key as part of a first Multicast message distributed. Alternatively, when the key Alternatively, are individually sent to the customer. In this way could a unique key for one use certain customers to the new key to distribute this particular customer. The desired key is as part of a second multicast message is distributed. This is in block<figref>934</figref> shown, in which the key encrypted under a second program segment key and is distributed as part of a second multicast message. In block<figref>938</figref> becomes the program content for decryption distributed by the customer using the transmitted key. After all is the customer in block <figref>942</figref> on the basis of any log entries a Create account.
At the Logging the request of a key, a server a Variety of information on log the request. For example, the time and the segment, for the The requested key was to be recorded. These records can then later be forwarded to the billing system in order to Determining the length the respected by each customer content to evaluate. The server must key customer not follow and actively distribute; may instead he simply wait that the customer requests a new key.
Among a key distribution request model asks every customer to a new key, and it is individually from the key distribution server answered. The server displays a list of active participants in a Multicast session on the basis of this first key requirement to chat. All customers on this list periodically new key can then added , whereby a multicast UDP message is used, the a new program segment key which the for each participant using the unique key of the oPERATOR encrypted is. If a customer chooses, the multicast session leave, the customer sends an authenticated request <?page 14?>the Server with the application to be removed from the list. This signal to the server, the time at which the customer is stopped, the to receive content to monitor, so that the customer for future content no account is created. In this way, the customer the list of active participants are deleted and receives the next Key update message not. In theory Although the customer the key own and thus decrypt the content; However, the server can periodically updates key output to the active participants, to prevent the deleted Customer further content decrypted.
After a further embodiment the invention can implement a key distribution Levy Scheme be to key from a server to distribute to a customer. <figref idrefs="S68">10</figref> illustrated in Thus, a flow chart <figref>1000</figref> to implement a Key Distribution Levy Scheme. In block <figref>1010</figref> receives a server a request for a first key from a client. In block <figref>1020</figref> the server creates a list of customers who the first key have requested. In block<figref>1030</figref> is a multicast message distributed to customers to distribute a second key of the decrypt the Program content is used directly or indirectly.
<figref idrefs="S68">11</figref> illustrated a flow chart <figref>1100</figref>That a more detailed embodiment to the in <figref idrefs="S68">10</figref> shown method shows. In block <figref>1110</figref> A requirement of a first key receive a customer. The server creates in block<figref>1120</figref> a List of customers who request this first key. In block<figref>1130</figref> becomes a unique key each of the customers used to encrypt a second key before This second key is distributed to each customer each. The server then distributes a Multicast message to the customer to the second key, the for example under the unique key of each customer is encrypted, in block <figref>1140</figref> shown distribute. In block<figref>1150</figref> shows a client to the server that it leaves the multicast session. To this point is the customer in response to the message of customers removed from the list as shown in block <figref>1160</figref> shown. In block <figref>1170</figref> an entry is logged so as to record, When the customer has left the session, so that the customer does not bill for additional Content is created. A third key is distributed to customers, which remain on the list to prevent a coated customer later receives occurring content, in block <figref>1180</figref> shown. The third key may are thus distributed on the remaining client list. On this way the first, second and third key as a program segment key to decipher respective content key Program Content to be used.
The Key delivery model and the key-request model can in a combined model of the distribution of keys to Customers are combined. As in<figref idrefs="S69">12</figref> shown, a method <figref>1200</figref> for this embodiment the invention may be used. In block<figref>1210</figref> is a key to Use in decrypting program content distributed to a customer. The server that the key distributed, awaiting confirmation, that the customer the key has received, in block <figref>1220</figref> shown. In block<figref>1230</figref> waiting the server a predetermined period that the customer receipt the key confirmed. When the confirmation message is not received by the server, the server deletes the customer of the list as shown in block <figref>1240</figref> shown, so that a confirmation message as a "heartbeat" message acts. The server is therefore not only the key to the customer from, but receives from each customer also messages similar as in the inquiry mode.
On A method to achieve this, is that each client at least once during each program segment an "At-life will get" message sends. The server receives a list of active participants and distributed to them new segment key via a multicast UDP message with the new key, the for each customer is encrypted between the different individual unique keys. If a server the duration of a segment no "keepalive received" message perceives He sweeps the clients of the active list. When the customer from some reason no "keepalive received" message sends, but wants to receive the content further, it may the expiration time monitor the program segment key and an individual key update request send, before the key expires. Again, this is a way to implement the "request" -Aspektes the combined model. (It is also possible, the "keepalive received" interval to be longer than to define a single program segment.)
<figref idrefs="S69">13</figref> illustrated a flow chart <figref>1300</figref> for implementation of this embodiment the invention. In block<figref>1310</figref> starts a server so that, Program content collecting send to a variety of customers. In block<figref>1320</figref> becomes created a list of active participants, showing which customers receive the program. In block<figref>1330</figref> is a message received from a customer, such as a "keepalive received" message, indicating that the customer should remain on the list. In block<figref>1340</figref> sends the server <?page 15?>a multicast message to the list of active participants, the new keys, z. B. a program segment key, to decrypt the next Segment of the program content includes. When a customer of the List is deleted, thus a second list of active participants is created.
As Part of the key distribution system is the content key to decrypt the program content over the whole course of distribution of the program content used. If a new content key is implemented, the implementation will thus signaling the customer, so that customers can begin the new content key, with which they have been provided for use. Often, customers are with an encrypted Version of the content key provided that is decoded as a program segment key. Similarly way could This program segment key with a service key or even be encrypted a unique key.
It can be used a signaling method to the implementation of a new key display. For example, a predetermined bit can be used, to indicate whether an old or current content key instead a new content key the recently has been distributed to the customer, should be used. On Thus, a customer can check the predetermined bit in one package and the right content key determine for use. For example, if a single bit is used, will be "1" is used, to the present Content key is already in use, indicate during a could be used to "0", to indicate that the new content key should be used. <figref idrefs="S70">14</figref> illustrated a flow chart <figref>1400</figref> for implementing a signaling method. <figref idrefs="S70">14</figref> refers to the use of an RTP packet of the distribution of program content; they could but equally also for other protocols are that used when distributing content will. Thus, it is merely an example of a method could also be implemented with other protocols. In block <figref>1410</figref> is a package for use as a RTP packet provided that both the payload portion and the head portion having. In block<figref>1420</figref> is a field between the head portion and the payload portion is inserted, the operative is a key change display. this could be a fixed field such as an extended header in which a predetermined Value for the indicating fixed field that the content key for the payload portion of the packet changed has been. Alternatively, to Show it that the next occurring payload portion is decrypted using the new content key could, or such a similar Implementation. In block<figref>1430</figref> is a modified RTP packet created. This modified RTP packet is in block<figref>1440</figref> from transmitted to the server to the client. The customer receives the modified RTP packet as shown in block <figref>1450</figref> shown, and determines from the inserted Box whether the key changed , as shown in block <figref>1460</figref> shown. block<figref>1470</figref> removed the pasted Field portion of the modified RTP packet and recovers the original RTP packet again, as in Block <figref>1470</figref> shown. Then can the recovered RTP packet is processed in block <figref>1480</figref> shown, and the packet may be accomplished using the current or the next key depending be on the indicator in the enlarged head, decrypted.
It could other signaling methods are used. For example could an RTP header extension is used. In this way could the Include extended portion of the head at least the content key-parity bit in order key changes display.
Similarly way could a payload specific marker bit are used. This bit is already in some payload types such as the MPEG-4 payload, which uses the marker bit to indicate the start of a frame, used.
Of Furthermore, could for example, a padding bit to be used. The padding bit could in the RTP header are used to the key change display. This requires that the applied to the RTP packets encryption method no padding used.
At the Multicasting program content such as audio and visual material can Released messages and control messages from a server to a Customer computer are sent. An embodiment of the invention provides a format for Such messages ready. Under this format, a sequence number or a timestamp to protect against attacks by replaying provided. Furthermore, in another field of the EMM and ECM messages ciphered message authentication code (MAC Message Authentication Code) or a digital signature of a public key provided for authentication. It should be noted that neither the encrypted hash to authenticate the message source (HMAC) nor the signature can be verified to a customer the key request exchange performs. Still would another field the kind of trapped in the message key, as about content key, Group keys, Program segment key, service key <?page 16?>etc, lock in. Furthermore, would a field for the type of key, the encrypting the key is used in the message, are provided. To this way could a unique key for eg a message which transmits a service keys that are displayed. Another one Field can for provided the remaining of the life of the key time will. Furthermore, a Schlüsselparitätsbit that in the parity bit the RTP packet corresponds, to be provided. also may include a user identification, which is often needed when multiple EMMs are delivered in a single multicast message, provided will. Each field of the data structure applies to each of these fields. On this way they are arranged in any order, so that the Data structure of one or more of these fields includes.
<figref idrefs="S66">7B</figref> illustrated a control message for a free preview period in which a content key CK0 with a key is coded: the free preview ([CK0] FPK ECM). Similarly fashion shows <figref idrefs="S66">7B</figref> a control message, in the a content key with a group key (ECM: [CK1] GK) is coded. A second control message is shown, the second content key of the program key (ECM: [CK2] PK) encrypted is promoted. Furthermore, several enable messages shown with new program keys, with a unique key for one specific customer's computer is encrypted. The PK can to Individual customers are single sent. Alternatively, a single message can be created to a linked message Program keys form, which is sent to collect multiple clients. Thus, everyone could Customer the for analyze and decipher these customers special new program key.
alternative to CK0 must not be distributed in an ECM. The value of the by the large number of customers already owned FPK can taken as CK0 will.
alternative to CK1 must not be distributed in an ECM. The value of the by the large number of customers already owned GK can be taken as CK1 will.
alternative to CK2 can be encrypted with the UK and are supplied in the form of an EMM directly to the customer, instead of the ECM form shown in the figure.
Initial Anschauperiode
at some multicast events, such as per-mission-pay TV events is, expected that a system most of the load, ie the heaviest Transport requesting program keys, very close to the planned Beginning of a program is experienced. If the totality of customers, take up a multicast session, is very large, a server is not able immediately to key distribute all participants. There is therefore needed a system that allows viewers the beginning of a program while this period, in which the server key distributed to those who have purchased the program material to look at. <figref idrefs="S70">15</figref> illustrated an embodiment a method for distributing keys during an initial Anschauperiode.
On A method for implementing an initial Anschauperiode is distributing a shared key to potential participants in advance, z. B. prior to the distribution of the program content. Such a key is here as a group key designated. A group key can be given customers when a particular caching server Request, or it can be a truly global key, the Customers receive when they during the provision in the distribution system are initialized. Since each customer received in such a situation, a group key would, could theoretically all customers receive free the first part of the content. <figref idrefs="S70">15</figref> illustrated a flow chart <figref>1500</figref> for implementing an embodiment the invention. In block<figref>1510</figref> out <figref idrefs="S70">15</figref> becomes customers a first key such as a group key provided. In block<figref>1520</figref> A second key to Use in decrypting a first portion of the program content provided. On Such a key could be used as content key are designated. The second key is at least one the large number of customers in the first key encrypts provided, in block <figref>1530</figref> shown. This second key can be encrypted prior to distribution to the customer with the group key. In block <figref>1540</figref> is used on the server, this second key, to encrypt a first portion of the program content. Of the encrypted first portion of the program content is then sent to the group of Customers distributed in block <figref>1550</figref> shown. Therefore, the customer, the second key has received the encrypted Program content decipher. And can the customers the content key using the group key decipher and then the content key use to the encrypted program content to decipher. This will block <figref>1560</figref> shown.
<?page 17?>
If a multicast event starts , the initial content key under the group key and the program key for per-mission-pay TV-Events or a first program segment key for Per-term pay-TV events (PSK may be encrypted under the GK) are distributed. Since the group key is distributed in advance, must customers do not wait for the program key or the program segment key, the later be distributed to them to receive. Instead, set the server the duration of the initial Anschauperiode based on the expected demand for the program content by customers determine what also based on the instantaneous load , Dynamically adjusted by customers who purchase the program over time can be. In this way, the server can on the basis of Set the demand for a particular program in real time. It should be noted that an initial Anschauperiode of "N" content key periods may be composed, instead intended as a single interval to be. In this case, the server can dynamically adjust N.
<figref idrefs="S71">16A</figref> and <figref idrefs="S72">16B</figref> illustrate a flow chart <figref>1600</figref> for implementing an embodiment the invention. In block<figref>1610</figref> is program content for multicasting provided to a plurality of customers. A first section of the program content is by using a first key, such as a group key, encrypted an encrypted first portion of the program content in block <figref>1620</figref> produce. In block <figref>1630</figref> are customers with this first key to Use in decrypting the program content provided, typically in advance, z. B. during Provision. In block<figref>1640</figref> the encrypted first Portion of the program content prior to purchase by the customer these customers collect sent. In block<figref>1650</figref> is the first Portion of the program content for a Period encrypted, to allow a user to an initial get watching the program content, as this first section be decrypted, for example with the group key previously distributed can. This period may be based on the anticipated demand are predetermined by the program. In block<figref>1660</figref> becomes prompts the user to purchase the program content, for example the a user interface at the customer at the end of the free Preview period. Then shows the block<figref>1670</figref>That a guaranteed Period is provided to allow a user to To purchase the program content, interrupted without the program service is. When a user program in the guaranteed period acquires the user the necessary keys can be expected therefore, time to receive, so that no loss of Programmanschau occurs. In block <figref>1674</figref> server generates a second key that is then used to form a second portion of said program content encrypt, in block <figref>1680</figref> shown. Each of the customers, the program content to have acquired in the guaranteed period, is also a second key provided, as in Block <figref>1684</figref> shown. For example may participate in the acquisition of a key program of the program key be distributed to customers. This program key can then be used, to the second key decrypt when the second key transferred to the customer is. In this manner, in block<figref>1690</figref> the encrypted second Portion of the program content collecting sent to the plurality of clients. In this way, those customers who purchased the program content and the second key have received, decrypt the second portion of the program content.
<figref idrefs="S66">7B</figref> shows the guaranteed time period in one example of the invention. In<figref idrefs="S66">7B</figref> becomes shown the guaranteed period, used in the group key can be to decrypt a content key which to decrypt encrypted Program content is used. Any user who program content to acquires in the guaranteed period, receives the next necessary decryption key in the initial Key distribution. In this way, the initial Key distribution period as of longer Duration shown than the guaranteed period so as to make it possible that a key to a customer who has purchased him in the guaranteed period, is distributed. The content key (CK1) is thus as about the entire initial Key distribution period permanently shown. In this manner, the next content key of an acquiring user received before the initial Key distribution period elapses.
Around to provide a satisfactory user experience, all customer, guaranteed in the " Period "access an event Request (z. B. they call a program key on a per-mission-pay TV event on), the Reception of the content guarantee uninterrupted. This means, that the server does not stop, content key under the group key distribute to the program key to all customers whose Requests were received in the guaranteed period, distributed has been. This is again the initial Anschauperiode or equivalent, the initial Key distribution period called.
customers requesting the content after the guaranteed period, have already the beginning of the film, <?page 18?>for example, missed; therefore the supply is the program key or the program segment key not alike decisive, and this viewer can tolerate a slight delay. In fact, it is likely preferable that a user a continuous Anschauerlebnis later begins when that it at an earlier Time a Anschauerlebnis starts which are temporarily suspended is.
As previously noted, the initial Key distribution period based on the predicted popularity of a particular program initially be fixed and then modified by the server to be in the current adjust exposure. In this way, the distribution period to the basis of the number of requests or the performance of the Server computer can be extended. <figref idrefs="S72">17</figref> illustrated a method for an embodiment of the invention, to achieve this. In block<figref>1710</figref> becomes Program content provided for multicasting. In block<figref>1720</figref> becomes a first portion of the program content without charge to a Many of our customers collect sent. During the multicasting of the first portion of the program content is a guaranteed period provided, as in Block <figref>1730</figref> shown. block<figref>1740</figref> shows, that the number of customers is assessed, the program content to will acquire in the guaranteed period. In block<figref>1750</figref> becomes an initial Key distribution period provided having a duration that is long enough to the purchasing client provide cryptographic keys, so an interruption of the reception of the program content in the purchasing Customer is prevented. In block<figref>1760</figref> is the initial Key distribution period set. The setting of the initial key distribution period may, for example, by the initial key distribution period simply extended is. In this way, a content key can be used to the Program content over a period of the additional Load of viewers who purchase the content, houses. The actual Number of purchasing clients can further determined and with the assessed Number of customers of which had been expected to program content to would acquire are compared. The initial Key distribution period can on the basis of the additional prolonged exposure to customers will. Furthermore, the delay on a load the server or the network is based, the performance of these Components are evaluated and the initial distribution period adjusted accordingly can be.
<figref idrefs="S73">18</figref> illustrated a procedure <figref>1800</figref>, To allow users, after the expiration of the guaranteed period described above content to acquire. In block<figref>1810</figref> is program content distribution for a Variety of clients provided. A first period for acquiring an uninterrupted Anschau the program content is in block <figref>1820</figref> provided. This is consistent with the guaranteed time period described above. acquiring a purchase request of the program content of a Customers, as shown in block <figref>1830</figref> shown, during received first period. A second period is to acquire the program content provided, in the second period after the first period occurs, as in Block <figref>1840</figref> illustrated. A purchase request from a late purchasing client during this received second period, as in Block <figref>1850</figref> shown. The program content is distributed to the purchasing client without that the viewing of the program content is interrupted, as in block <figref>1860</figref> shown as a delay decryption of the late acquiring customers distribute program content occurs until this decrypted program content can be, without watching the late purchasing client interrupted is. This is in block<figref>1870</figref> shown. This method can in this way to the communicating of a key a late purchasing client delay, until the server determines that the late acquired customer a the receive uninterrupted viewing of the program content necessary keys is.
content rights and conditions
Among with reference to <figref idrefs="S73">19</figref> is a system for implementing of rules and conditions for providing content in a To see multicast environment. The system<figref>1900</figref> shows a Client-server network, the at least one customer <figref>1908</figref> includes, via a network <figref>1916</figref> such as the Internet with a server such as the origin content server <figref>1904</figref> coupled. Additionally shows <figref idrefs="S73">19</figref> a caching server <figref>1912</figref> and an authorization center <figref>1920</figref>That also with the network are coupled. The origin content server is a server illustrate, the program content stores or controls access to it. For example could such content be multimedia, or it could be for a film distribution over act a Webcastingsystem. The caching server<figref>1912</figref> can used in this multicast environment, a copy of Program content, which comes from the origin content server to save.
In one embodiment the invention, a customer logs on the authorization center <figref>1920</figref><?page 19?>at, to obtain a label that defines what type of content the customer is entitled to receive. If a customer desires, a to obtain content, can A variety of procedures are implemented to confirm whether entitled the customer to receive this specific program content is. At least three options for obtaining the program content could be used will. For example, could the content provider for the origin content server <figref>1904</figref> in <figref idrefs="S73">19</figref> verifying perform. alternative could to Caching Server <figref>1912</figref> in <figref idrefs="S73">19</figref> the check routine carry out, or the review could at carried out the customer themselves will.
In the case that the origin content server carrying out the verification, evaluates the origin content server the customer's requirement of program content and checks the authorization center, to determine whether the customer for authorized this particular content. This method allows early to make decision in particular, whether the customer the access should be denied, which further processing and possibly a frustration of the viewer that his access to the content denied, eliminated.
alternative could to checking on the carried out the customer will. For example, could the customer with a hardware security device or a security chip be equipped, the / of the goods distributed to each individual customer could enforce rules. In this way could the rules used by the hardware security device with Anschauberechtigungen of customers or other features such as the physical location of the customer, such as the country in be where the customer is compared. Such physical Location can be important, because different countries have different Spread its laws regarding what type of program content may be, have.
Still another embodiment the invention enables it is that the check on the performed caching server is. The caching server the content rules can compare with the privileges of customers and the rules certainly prevail. The privileges of the clients can safely in a record (label) be included, the customer presented to the caching server or to the caching server on other means receives. The rules can are distributed from the origin server to the caching server. Of Furthermore, the purchase option from the origin server to the client can be distributed, and the customer then the purchase option to Caching server convey.
In addition to Compare the content rules with the privileges of a user (Customers), the selected by the user purchase option with compared to the rules in making the authorization decision will.
<figref idrefs="S74">20A</figref> and <figref idrefs="S74">20B</figref> illustrate a procedure <figref>2000</figref> for implementing an embodiment the invention. In block<figref>2004</figref> out <figref idrefs="S74">20A</figref> becomes a rule set that defines whether a customer is entitled to is to receive program content. The customer may program content from a server such as the origin content server <figref>1904</figref> in <figref idrefs="S73">19</figref> . Request This is in block <figref>2008</figref> illustrated. In block<figref>2012</figref> becomes received a request of the program content. The customer can for Example Request the program content from the origin content server. In block <figref>2016</figref> is formatted by the origin server, a record, of an identifier for identifying the program content and rules, that define who may have access to the program content, and selected by the user includes purchase options. In block<figref>2020</figref> may the record signed and encrypted , whereby it is a secured object. block<figref>2024</figref> illustrates a trusted third party can be used to sign the data record. Such trustworthy third party could be used, for example, a signing key for Use when signing the record output to the originating content server. Similarly way could the same trusted third party are used to a caching server, the later the will use the authenticated data to provide a verification key. In block <figref>2028</figref> the data set is shown, to the customer promoted is. The customer can then convey the data to the caching server, as in block <figref>2032</figref> shown, where the data integrity by checking Signature is verified, as in Block <figref>2034</figref> shown. alternative could to the record directly from the origin content server to the caching server promoted be without on the customer to go. In block<figref>2036</figref> in <figref idrefs="S74">20B</figref> is at the caching server, a determination made as to whether the customer is entitled to the program content to recieve. The caching server can use the data set contained in the rule, defining who is entitled to receive the program content, and the server may also be responsible for the client requesting the program content, specific permission use. This provision allows the caching server determine whether program content key to shall provide for use by the customer or not. The caching server also distributes its encrypted copy of the program content material for use by the client (or plurality of clients), <?page 20?>as in block <figref>2040</figref> illustrated.
A another embodiment the invention illustrated from the perspective of the cache server is, in <figref idrefs="S75">21</figref> shown. In flowchart<figref>2100</figref> out <figref idrefs="S75">21</figref> receives the Caching server, a program content identifier from a customer, as of block <figref>2110</figref> illustrated. This program content identifier can be used to identify the specific program content, the user of the client computer wishes to receive. Of the block <figref>2120</figref> illustrates that the selected by the user payment methods is also communicated to the server. For example, the of the client to the origin server negotiated payment method are communicated to the caching server. At block<figref>2130</figref> will associated to the program content Rules by the caching server for use in determining whether the customer is entitled to the program content received. The program content identifier, Chosen by the user Payment methods and associated to the program content rules can all in a secure object by the client to the caching server is sent, are communicated to the caching server. This secured object or the secured data can then by analyze the caching server to the relevant information to obtain. additionally this may require the customer a label can be obtained as in Block <figref>2140</figref> shown. It should be noted that the blocks <figref>2110</figref>. <figref>2120</figref>. <figref>2130</figref> and <figref>2140</figref> in occur with respect to each other in any order can. This label includes authorization information used can be, to determine whether the customer is entitled to receive the program content is. For example, the tag may store a list of services, which the customer subscribes to the location of the customer, eg. as in the United States, the ability of the customer, for to pay the content, etc. Such information can with label the rules obtained by the caching server compared, be to determine whether the customer is entitled to the program content , as shown in block <figref>2150</figref> displayed. If the customer is entitled to, to receive the program content, a key to the direct or indirect Use in decrypting the encrypted Program contents are transferred to the customer, as in Block <figref>2160</figref> shown. If the customer is not entitled to the program content, have no such key be distributed. In this way, the multicast of the program content for customers, the key to for the Program are eligible and receive the key to the received key decrypts will.
Of the Caching server, the content rules for program material with the Permissions compare each customer and enforce the rules safely. The permissions of customers in a record, the customer presents the caching server, when requesting specific content, be contained safely. content rules can be delivered at least two ways. For example, content rules can directly be delivered to the caching server, z. B. together with the content. In this way the rules are applied only once to each caching server Posted. In the case of subscription acquisition of program material must not have a bystander every piece Content negotiate individually, since it included in his or her subscription agreement is. If a viewer purchase options, such as per-mission-pay TV Select or per-time-pay TV, has negotiated the viewers it with the origin content server. The selected purchase options, For example, signed and encrypted and delivered to the customer (independently of the delivery mechanism for Content Rules) and then in by the client to the caching server sent request included. Since the selected purchase options under a key encoded are, which is the caching server but not to the customer, known they will not be modified by the customer. Alternatively, content rules can from the content provider, that created the origin content server, be if the customer negotiated access to the contents of the original content server. Such rules may with the specific purchase options chosen by the audience, such as per-mission-pay TV or per-time-pay TV, are combined. The content rules can, in combination with the selected purchase options then signed for example, and encrypted and delivered to the customer and then in the sent by the client to the caching server Request be included. Since the content rules under a key encoded are, which is the caching server but not to the customer, known they will not be modified by the customer. This approach makes a direct interface between an origin content server and a caching server for delivery the content rules unnecessary.
At the Deal about an acquisition between the origin content server and the client maintains the Origin content server, the rules and purchase option information local. He can the customer then all the different purchase options offer, so that the customer can make a decision. To this Example, encapsulated the purchase option in the secured data are the returned to the customer is. The customer can then secured the record along with Customer label that the credentials of the customer includes (Z. B. the purchase assets, the list of subscribed services <?page 21?>etc.) to the correct caching server hand off. The customer in<figref idrefs="S73">19</figref> can the authorization information from the authorization center <figref>1920</figref> receive, if the customer for the multicast system logs.
<figref idrefs="S75">22</figref> illustrated a set of data provided by the origin content server can be. This record can before promotion to the customer or are encrypted to the caching server. <figref idrefs="S75">22</figref> illustrated different fields that are used as part of the data set can. On thus showing <figref idrefs="S75">22</figref> Fields for program content identifiers, the specific program content such as the name of a film mark. Zus ätzlich to this, the record <figref>2200</figref> a field for storing a Rule that defines who the program content has access included. In that in <figref idrefs="S75">22</figref> illustrated embodiment, shows a classification information field that is a can adapt certain classification standard. It could also a field is provided, as in <figref idrefs="S75">22</figref> shown, the acquisition preference (Selection) of the customer, such as per-mission-pay TV or per-time-pay TV, on the been negotiated by the customer and the originating content server was to save. <figref idrefs="S75">22</figref> also shows an authentication field, that prevents the customer modifies the record.
<figref idrefs="S75">23</figref> illustrated a record that an individual customer are provided can. Such a data set can be used to set the permissions the particular customer to define different program content. In this way shows <figref idrefs="S75">23</figref> For example, a record, of a field for identifying the location of a customer such as the country where the customer is located comprises. It is also shown a field which identifies subscriptions that subscribe to the customer has, for. example, HBO<sup>TM</sup> or SHOWTIME<sup>TM</sup>, It could additional presents fields will. This information could authenticated and encrypted , so that the customer does not revise its own permissions can.
While various embodiments the invention as a method or means for implementation the invention have been described, it is understood that the Invention by a processor coupled to a computer code such. B. a resident on a computer or accessible computer Code may be implemented. For example, software and databases could be used to implement many of the methods discussed above. additionally to embodiments, where the invention is accomplished by hardware, it is thus also be noted that these embodiments can be achieved by the use of a manufacturing article, the a computer usable medium having performed in machine-readable Program code to activate the in this specification disclosed functions effected comprises. It is therefore desirable that embodiments the invention also with their program code means as by this patent to be viewed as.
It is also envisioned that embodiments the invention than in a carrier wave executed Computer signals could be achieved, as well as signals (eg. B. electrical and optical) propagated through a transmission medium, the would. Thus could the various information discussed above in a structure, such as a data structure formatted and as an electric signal transmitted a transmission medium or stored on a machine readable medium.
It Note also that many of the structures presented herein, Materials and processes as a means for carrying out a function or presented as steps to perform a function can be. Therefore, it is understood that such language is entitled All these structures, materials, or operations, which in this specification be disclosed, and to cover their equivalents.
Contents4
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
70 members in 13 offices
Priority claims10
| Document | Office | Kind | Date |
|---|---|---|---|
| 24392500 | United States of America | P | |
| 24392500 | United States of America | P | |
| 24392500 | United States of America | – | |
| 0151051 | United States of America | W | |
| 0151051 | United States of America | W | |
| 0151051 | United States of America | – | |
| 243925P | – | – | – |
| PCTUS0151051 | – | – | – |
| US20000243925P | – | – | – |
| WO2001US51051 | – | – | – |
Members70
| Document | Office | Kind | |
|---|---|---|---|
| US2002051539A1 | United States of America | A1 | |
| US2002076050A1 | United States of America | A1 | |
| US2002083438A1 | United States of America | A1 | |
| US2002087971A1 | United States of America | A1 | |
| CA2435316A1 | Canada | A1 | |
| WO02058398A2 | World Intellectual Property Organization (WIPO) | A2 | |
| CA2427136A1 | Canada | A1 | |
| WO02062054A2 | World Intellectual Property Organization (WIPO) | A2 | |
| CA2425159A1 | Canada | A1 | |
| WO02063850A2 | World Intellectual Property Organization (WIPO) | A2 | |
| CA2426159A1 | Canada | A1 | |
| WO02069567A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US2002170053A1 | United States of America | A1 | |
| US2002172366A1 | United States of America | A1 | |
| US2002172368A1 | United States of America | A1 | |
| US2002174366A1 | United States of America | A1 | |
| CA2427181A1 | Canada | A1 | |
| WO02096024A2 | World Intellectual Property Organization (WIPO) | A2 | |
| EP1274243A2 | European Patent Office (EPO) | A2 | |
| CA2452618A1 | Canada | A1 | |
| WO03005724A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2002354779A1 | Australia | A1 | |
| WO02069567A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO02058398A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO02063850A3 | World Intellectual Property Organization (WIPO) | A3 | |
| TW540245B | Taiwan Province of China | B | |
| KR20030060923A | Republic of Korea | A | |
| WO02096024A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1329072A2 | European Patent Office (EPO) | A2 | |
| TW545052B | Taiwan Province of China | B | |
| EP1334583A2 | European Patent Office (EPO) | A2 | |
| TW548983B | Taiwan Province of China | B | |
| TW550949B | Taiwan Province of China | B | |
| EP1274243A3 | European Patent Office (EPO) | A3 | |
| WO02062054A3 | World Intellectual Property Organization (WIPO) | A3 | |
| EP1352496A2 | European Patent Office (EPO) | A2 | |
| EP1354476A2 | European Patent Office (EPO) | A2 | |
| WO02096024A9 | World Intellectual Property Organization (WIPO) | A9 | |
| KR20030094216A | Republic of Korea | A | |
| EP1371205A2 | European Patent Office (EPO) | A2 | |
| KR20040005848A | Republic of Korea | A | |
| KR20040007409A | Republic of Korea | A | |
| CN1471773A | China | A | |
| WO03005724A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO02062054A9 | World Intellectual Property Organization (WIPO) | A9 | |
| CN1483263A | China | A | |
| EP1415472A2 | European Patent Office (EPO) | A2 | |
| TW589896B | Taiwan Province of China | B | |
| MXPA04000131A | Mexico | A | |
| CN1529987A | China | A | |
| JP2004529538A | Japan | A | |
| JP2004533735A | Japan | A | |
| CN1633794A | China | A | |
| US2005157877A1 | United States of America | A1 | |
| US6978022B2 | United States of America | B2 | |
| TWI247513B | Taiwan Province of China | B | |
| BR0206590A | Brazil | A | |
| EP1371205B1 | European Patent Office (EPO) | B1 | |
| AT319256T | Austria | T | |
| ATE319256T1 | Austria | T1 | |
| CN1251442C | China | C | |
| DE60117618D1 | Germany | D1 | |
| US7076661B2 | United States of America | B2 | |
| US7080397B2 | United States of America | B2 | |
| US2006159264A1 | United States of America | A1 | |
| EP1274243B1 | European Patent Office (EPO) | B1 | |
| DE60214799D1 | Germany | D1 | |
| DE60117618T2This record | Germany | T2 | |
| US7257227B2 | United States of America | B2 | |
| DE60214799T2 | Germany | T2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Ceased/non-payment of the annual feeCeased8339 | 8339 | |
| No opposition during term of oppositionOpposition8364 | 8364 |
Numbers
- Publication
- 60117618
- Publication, DOCDB
- 60117618
- Publication, EPODOC
- DE60117618T
- Application
- 60117618
- Application, DOCDB
- 60117618
- Application, EPODOC
- DE2001617618T
Titles2
- German
- Anfängliche Betrachtungsperiode für die Autorisierung von Multimedia-Inhalten
- English
- Initial observation period for the authorization of multimedia content
Classification
- CPC, 25
- H04N21/23473
- G06F17/00
- H04N7/165
- H04N7/1675
- H04N7/17336
- H04N21/2225
- H04N21/23106
- H04N21/2347
- H04N21/2541
- H04N21/2543
- H04N21/26606
- H04N21/26609
- H04N21/4143
- H04N21/4405
- H04N21/44204
- H04N21/4627
- H04N21/47202
- H04N21/47211
- H04N21/63345
- H04N21/63775
- H04N21/6405
- H04N21/6587
- H04N21/8355
- H04N21/8549
- G06F21/00
- IPC, 32
- G06F12 14
- H04L29 06
- G06F19 00
- G06F21 00
- G06F21 10
- G06F21 33
- G06F21 60
- G06F21 62
- G06Q10 00
- G06Q30 00
- H04L9 08
- H04N5 765
- H04N7 16
- H04N7 167
- H04N7 173
- H04N21 2225
- H04N21 231
- H04N21 2347
- H04N21 254
- H04N21 2543
- H04N21 266
- H04N21 4143
- H04N21 4405
- H04N21 442
- H04N21 4627
- H04N21 472
- H04N21 6334
- H04N21 6377
- H04N21 6405
- H04N21 6587
- H04N21 8355
- H04N21 8549