EP1579693B1

Method and apparatus for access control in an overlapping multiserver network environment

Abstract

This record has no abstract on file.

EP1579693B1, drawing sheet 1
Sheet 1 of 32

Term

Term ended

Expired 16 December 2023, 2.8 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

14 claims: 6 independent, 8 dependent

  1. 1
    A system providing a network media environment, the system comprising a server device (105, 120, 145, 1705, 1715, 2705, 2715, 2755) operable to receive a media item, characterised in that:the media is received in a discrete state in which the media item can be copied by the server (105, 120, 145, 1705, 1715, 2705, 2715, 2755) but cannot be copied by a client device, and the server device is operable: to receive a discrete licence with the media item, the discrete license defining permissions for copying the media item in the discrete state, to convert the discrete license to a root license, the root licence defining permissions for copying the media item in a bound state to convert the received media item from the discrete state to the bound state in which the media item can be copied to one or more client devices (105, 120, 125, 130, 145, 1705, 1715, 1720, 1725, 1730, 2705, 2755) connected to the server (105, 120, 145, 1705, 1715, 2705, 2715, 2755), by locking the media item to the server (105, 120, 145, 1705, 1715, 2705, 2715, 2755) and the one or more client devices (105, 120, 125. 130, 145, 1705, 1715, 1720, 1725, 1730, 2705, 2755) by encryption, to generate a sub-copy of the media item in the bound state and a first licence derived from the root licence, the first licence defining permissions for presenting the sub-copy of the media item, and to provide the sub-copy of the media item and the first licence to the client device (105, 120, 125, 130, 145, 1705, 1715, 1720, 1725, 1730, 2705, 2755), the server (105, 120, 145, 1705, 1715, 2705, 2715, 2755) and the client device (105, 120, 125, 130, 145, 1705, 1715, 1720, 1725, 1730, 2705, 2755) forming a hub network.
  2. 2
    A system as claimed in Claim 1, wherein the server (105, 120, 145, 1705, 1715, 2705, 2715, 2755) is operable to confirm the identity of the client device (105, 120, 125, 130, 145, 1705, 1715, 1720, 1725, 1730, 2705, 2755), to authorise the client device (105, 120, 125, 130, 145, 1705, 1715, 1720, 1725, 1730, 2705, 2755) as a compliant client device (105, 120, 125, 130, 145, 1705, 1715, 1720, 1725, 1730, 2705, 2755) if the identity of the client device (105, 120, 125, 130, 145, 1705, 1715, 1720, 1725, 1730, 2705, 2755) has been confirmed, and if the server (105, 120, 145, 1705, 1715, 2705, 2715, 2755) has authorised the client device (105, 120, 125, 130, 145, 1705, 1715, 1720, 1725, 1730, 2705, 2755) as a compliant device, to provide the sub-copy of the media item to the compliant device in the bound state.
  3. 3
    A system as claimed in Claim 1 or 2, wherein the server is a first server (105, 1705, 2705) forming a first hub network with the client device (120, 1715, 2715), and the client device is operable as a second server (120, 1715, 2715) to provide further bound sub-copies of the media item to one or more other client devices (125, 1725, 2720) connected thereto, the second server (120, 1715, 2715) and the one or more other client devices (125, 130, 1725, 1730, 2720) forming a second hub-network, the media item being shared between the first and the second hub networks.
  4. 4
    A system as claimed in Claim 3, wherein the media item is bound to the second server (120) and the one or more other client devices (125, 130) forming the second hub network using different encryption to that used to bind the media item to the first hub network.
  5. 5
    A system as claimed in Claim 4, wherein each sub-copy of the media item is bound by encryption to only one of the first and second hub networks.
  6. 6
    A system as claimed in any preceding Claim, wherein the first hub network is defined by an area with respect to the first server providing a first local environment, and the second hub network is defined by an area with respect to the second server providing a second local environment.
  7. 7
    A system as claimed in any of Claims 1 to 6, wherein the first hub network is defined by a limited logical area with respect to the first server providing a first local environment, and the second hub network is defined by a limited logical area with respect to the second server providing a second local environment.
  8. 8
    A system as claimed in any of Claims 1 to 6, wherein the first hub network is defined by a travel time of packets to and/or from the first server providing a first local environment, and the second hub network is defined by a travel time of packets to and/or from the second server providing a second local environment.
  9. 9
    A system as claimed in any of Claims 6, 7 or 8, wherein the first local environment and the second local environment overlap to the first server (105) and the second server (120) are in both the first local environment and the second local environment.
  10. 10
    A method of providing a network media environment, the method comprising receiving, at a server, a media item; characterised in that the media item is received in a discrete state in which the media item can be copied by the server but cannot be copied by a client device, and by:receiving a discrete licence with the media item, the discrete license defining permissions for copying the media item in the discrete state, converting the discrete license to a root license, the root licence defining permissions for copying the media item in a bound state, converting the received media item from the discrete state to the bound state in which the media item can be copied to one or more client devices connected to the server, by locking the media item to the server and the one or more client devices by encryption, generating a sub-copy of the media item in the bound state and a first licence derived from the root licence, the first licence defining permissions for presenting the sub-copy of the media item, and providing the sub-copy of the media item and the first licence to the client device, the server and the client device forming a hub network.
  11. 11
    A method as claimed in Claim 10, the providing the sub-copy of the media item comprises confirming the identity of the client device, authorising the client device as a compliant client device if the identity of the client device has been confirmed, and if the server has authorised the client device as a compliant device, providing the sub-copy of the media item to the compliant device in the bound state.
  12. 12
    A method as claimed in Claim 10 or 11, wherein the server is a first server forming a first hub network with the client device, and the client device is operable as a second server to provide further bound sub-copies of the media item to one or more other client devices connected thereto, the second server and the one or more other client devices forming a second hub-network, the media item being shared between the first and the second hub networks.
  13. 13
    A method as claimed in Claim 12, wherein the media item is bound to the second server and the one or more other client devices forming the second hub network using different encryption to that used to bind the media item to the first hub network.
  14. 14
    A method as claimed in Claim 13, wherein each sub-copy of the media item is bound by encryption to only one of the first and second hub networks.