EP1477879A2

Tying a digital license to a user and tying the user to multiple computing devices in a digital rights management (DRM) system

Abstract

A first trusted component on a first computing device performs cryptography, evaluation, and enforcement and is tied thereto, and a first user-machine certificate associated with the first computing device is tied to a user. Correspondingly, a second trusted component on a second computing device performs cryptography, evaluation, and enforcement and is tied thereto, and a second user-machine certificate associated with the second computing device is also tied to the user. The first trusted component obtains the content for rendering on the first computing device by way of the first user-machine certificate and the license, and the second trusted component obtains the content for rendering on the second computing device by way of the second user-machine certificate and the same license.

EP1477879A2, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Projected expiry passed 11 February 2024, 2.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

18 claims: 5 independent, 13 dependent

  1. 1
    A digital rights management (DRM) system to allow a user to render digital content on a plurality of computing devices according to a corresponding digital license, the license being tied to the content and to the user, the system comprising:a first trusted component on a first one of the computing devices for performing cryptography and DRM evaluation and enforcement for the first one of the computing devices, the first trusted component being tied to the first one of the computing devices;a first user-machine certificate associated with the first one of the computing devices, the first user-machine certificate being tied to the user, whereby the first trusted component can obtain the content for rendering on the first one of the computing devices by way of the first user-machine certificate and the license;a second trusted component on a second one of the computing devices for performing cryptography and DRM evaluation and enforcement for the second one of the computing devices, the second trusted component being tied to the second one of the computing devices;anda second user-machine certificate associated with the second one of the computing devices, the second user-machine certificate being tied to the user, whereby the second trusted component can obtain the content for rendering on the second one of the computing devices by way of the second user-machine certificate and the license.
  2. 5
    A method to allow a user to render digital content on a plurality of computing devices according to a corresponding digital license, the license being tied to the content and to the user, the method comprising:providing a first trusted component on a first one of the computing devices to perform cryptography and DRM evaluation and enforcement for the first one of the computing devices, the first trusted component being tied to the first one of the computing devices;providing a first user-machine certificate associated with the first one of the computing devices, the first user-machine certificate being tied to the user, whereby the first trusted component can obtain the content for rendering on the first one of the computing devices by way of the first user-machine certificate and the license;providing a second trusted component on a second one of the computing devices for performing cryptography and DRM evaluation and enforcement for the second one of the computing devices, the second trusted component being tied to the second one of the computing devices;andproviding a second user-machine certificate associated with the second one of the computing devices, the second user-machine certificate being tied to the user, whereby the second trusted component can obtain the content for rendering on the second one of the computing devices by way of the second user-machine certificate and the license.
  3. 9
    A method for a user to render digital content on a plurality of computing devices, the content being encrypted according to a content key (KD) to result in (KD(content)), the user having a public key / private key pair (PU-USER, PR-USER) associated therewith, the method comprising:obtaining a license including (KD) encrypted according to a, (PU-USER) to result in (PU-USER(KD));obtaining a first trusted component on a first one of the computing devices for performing cryptography and DRM evaluation and enforcement for the first one of the computing devices, the first trusted component having a first public key / private key pair (PU-1, PR-1) associated therewith;obtaining a first user-machine certificate associated with the first one of the computing devices, the first user-machine certificate including (PU-USER) and also including (PR-USER) encrypted according to (PU-1) to result in (PU-1 (PR-USER));applying (PR-1) to (PU-1 (PR-USER)) from the first user-machine certificate to obtain (PR-USER);applying (PR-USER) to (PU-USER(KD)) from the license to obtain (KD) at the first one of the computing devices;applying (KD) to (KD(content)) to obtain the content for rendering on the first one of the computing devices;obtaining a second trusted component on a second one of the computing devices for performing cryptography and DRM evaluation and enforcement for the second one of the computing devices, the second trusted component having a second public key / private key pair (PU-2, PR-2) associated therewith;obtaining a second user-machine certificate associated with the second one of the computing devices, the second user-machine certificate including (PU-USER) and also including (PR-USER) encrypted according to (PU-2) to result in (PU-2(PR-USER));applying (PR-2) to (PU-2(PR-USER)) from the second user-machine certificate to obtain (PR-USER);applying (PR-USER) to (PU-USER(KD)) from the license to obtain (KD) at the second one of the computing devices;applying (KD) to (KD(content)) to obtain the content for rendering on the second one of the computing devices;,
  4. 10
    A method in combination with a digital rights management (DRM) system to allow a particular user to render digital content on a particular computing device according to a corresponding digital license, the license being tied to the content and to the user, the method for providing a user-machine certificate associated with the particular computing device and tied to the particular user, the method comprising:receiving a request from the user for the user-machine certificate with regard to the computing device, the request including an identification (ID) of the user and a computing device certificate associated with the computing device, the computing device certificate including a public key (PU-x) associated with the computing device;determining based on the ID of the user whether the user has a record in a user-machine database;if not, creating the record for the user in the database, the record including the ID of the user and a public key / private key pair for the user (PU-USER, PR-USER);if so, locating the record for the user in the database;obtaining (PU-x) from the computing device certificate;encrypting (PR-USER) according to (PU-x) to result in (PU-x(PR-USER));forming (PU-USER) and (PU-x(PR-USER)) into the to-be-provided user-machine certificate;andreturning the formed user-machine certificate to the user, whereby the content is encrypted according to a content key (KD) to result in (KD(content)), the license includes (KD) encrypted according to (PU-USER) to result in (PU-USER(KD)), and a trusted component of the computing device having a private key (PR-x) corresponding to (PU-x) can decrypt the content for rendering on the computing device by applying (PR-x) to (PU-x(PR-USER)) from the user-machine certificate to obtain (PR-USER), applying (PR-USER) to (PU-USER(KD)) from the license to obtain (KD), and applying (KD) to (KD(content)) to obtain the content.
  5. 18
    A method of providing a digital license to a requestor requesting such license on behalf of a user to allow the user to render corresponding digital content according to the digital license, the content being encrypted according to a content key (KD) to result in (KD(content)), the method comprising:receiving an identification (ID) of the user from the requestor;determining from a database based on the ID of the user whether a record with a public key for the user (PU-USER) exists for such user;if not, creating the record for the user in the database, the record including the ID of the user and a public key / private key pair for the user (PU-USER, PR-USER);if so, locating the record for the user in the database;employing (PU-USER) to encrypt the content key (KD) for the content to result in (PU-USER(KD));forming (PU-USER(KD)) into the to-be-provided license;andreturning the formed license to the requestor, whereby the requestor forwards the license to the user, and the user having (PR-USER) can decrypt the content by applying (PR-USER) to (PU-USER to (PU-USER(KD)) from the license to obtain (KD), and applying (KD) to (KD(content)) to obtain the content.