Method and system for providing secure handling of information for complete internet anywhere
Abstract
An Internet capable set-top-box (STB) may be operable to extend a security boundary from the Internet capable STB to an application server to allow support of web browsing operations from the application server. A secure link between the Internet capable STB and the application server may be established. The Internet capable STB may communicate a request for web page information from a secure web server along with cryptographic credentials to the application server, via the secure link. The application server may be. allowed to receive the web page information directly from the secure web server and process at least the unsupported portion of the received web page information. The Internet capable STB may then receive the web page information with at least the unsupported portion processed from the application server, via the secure link, for further processing and rendering.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
10 claims: 2 independent, 8 dependent
- 1A method of securing an Internet connection, the method comprising:performing by one or more processors and/or circuits in an Internet-accessible STB: extending a security boundary from the Internet-enabled STB to an application server Implementing support for secure network browsing operations from the application server, wherein the secure network browsing operation comprises transmitting a password based on the received Internet-enabled STB encryption certificate through a secure network server Web page information to the application server;and the secure web server receives the encryption certificate via the application server. 一種保障互聯網連接安全的方法,其特徵在於,所述方法包括:由可上網STB中的一個或更多處理器和/或電路執行:將安全邊界從所述可上網STB擴展到應用伺服器以實現從所述應用伺服器獲得對安全網路流覽操作的支援,其中所述安全網路流覽操作包括透過一安全網路服務器基於接收到的所述可上網STB的加密證書,以傳輸一網頁資訊至所述應用伺服器;以及所述安全網路服務器經由所述應用伺服器以接收到所述加密證書。 一種保障互聯網連接安全的方法,其特徵在於,所述方法包括:由可上網STB中的一個或更多處理器和/或電路執行:將安全邊界從所述可上網STB擴展到應用伺服器以實現從所述應用伺服器獲得對安全網路流覽操作的支援,其中所述安全網路流覽操作包括透過一安全網路服務器基於接收到的所述可上網STB的加密證書,以傳輸一網頁資訊至所述應用伺服器;以及所述安全網路服務器經由所述應用伺服器以接收到所述加密證書。
- 8A system for securing an Internet connection, comprising:one or more processors and/or circuits for use in an Internet-accessible STB, wherein the one or more processors and/or circuits are used to: secure a boundary Extending from the Internet-enabled STB to an application server to obtain support for secure network browsing operations from the application server, wherein the secure network browsing operation comprises receiving based on a secure network server The networked STB encryption certificate is configured to transmit a webpage information to the application server;and the secure web server receives the encryption certificate via the application server. 一種保障互聯網連接安全的系統,包括:用於可上網STB中的一個或更多處理器和/或電路,其特徵在於,所述一個或多個處理器和/或電路用於:將安全邊界從所述可上網STB擴展到應用伺服器以實現從所述應用伺服器獲得對安全網路流覽操作的支援,其中所述安全網路流覽操作包括透過一安全網路服務器基於接收到的所述可上網STB的加密證書,以傳輸一網頁資訊至所述應用伺服器;以及所述安全網路服務器經由所述應用伺服器以接收到所述加密證書。 一種保障互聯網連接安全的系統,包括:用於可上網STB中的一個或更多處理器和/或電路,其特徵在於,所述一個或多個處理器和/或電路用於:將安全邊界從所述可上網STB擴展到應用伺服器以實現從所述應用伺服器獲得對安全網路流覽操作的支援,其中所述安全網路流覽操作包括透過一安全網路服務器基於接收到的所述可上網STB的加密證書,以傳輸一網頁資訊至所述應用伺服器;以及所述安全網路服務器經由所述應用伺服器以接收到所述加密證書。
Independent claims2
76 paragraphs, as filed
Method and system for guaranteeing internet connection security
METHOD AND SYSTEM FOR PROVIDING SECURE HANDLING OF INFORMATION FOR COMPLETE INTERNET ANYWHERE
The present invention relates to Internet access technologies, and more particularly to a method and system for providing information security processing for a complete Internet at any location.
As e-commerce, social networking, and other online services and applications continue to grow, users may want to access the Internet in many places or places in a flexible and/or appropriate manner. Nowadays, most users can only access the Internet through a web browser running on a personal computer. At the same time, only some families own computers, most families only have TVs, and in many cases have multiple TVs. Therefore, users may find it convenient to use a flat-panel TV and/or other display devices in the home to access the Internet. For example, by providing network browsing software, network protocols, and Internet connection media for set-top-box (STB) connected to flat-panel TVs, users can easily and conveniently locate places such as bedrooms. Access the internet and/or check emails.
In some practical situations, the STB is not configured to support and/or be able to process specific content in a web page. What's more, in some cases, due to limited STB capabilities, the waiting time for rendering or displaying specific content on a web page can be lengthy. These will affect the user's experience.
Other limitations and disadvantages of the prior art will be apparent to those of ordinary skill in the art in view of the present invention, which will be described in conjunction with the drawings.
The present invention provides a system and/or method for providing information security processing for a complete Internet at any location, which is described in detail below in conjunction with at least one of the accompanying drawings.
According to one aspect, a method of securing an Internet connection is provided, the method comprising: being performed by one or more processors and/or circuits in an Internet-ready STB: extending a security boundary from the Internet-enabled STB to an application server The device is configured to obtain support for secure network browsing operations from the application server.
Advantageously, the method further comprises establishing a secure link between said internet enabled STB and said application server.
Preferably, the Internet-enabled STB and the application server mutually authenticate to determine the identity of the other party.
Advantageously, the method further comprises applying encryption techniques to ensure said link security between said internet enabled STB and said application server.
Preferably, the encryption technique includes symmetric key cryptography, public key cryptography, and/or hash function cryptography.
Preferably, the method further includes: transmitting, by the secure link, a webpage information request submitted by the secure network server and the encrypted certificate of the internetable STB to the application server, wherein the webpage information includes Supported part and unsupported part.
Preferably, the unsupported part of the webpage information includes a plug-in program and/or multimedia content that is not supported by the Internet-enabled STB.
Advantageously, the method further comprises allowing said application server to receive said requested web page information directly from said secure web server.
Advantageously, the method further comprises requiring the application server to process at least the unsupported portion of the web page information received from the application server.
Advantageously, the method further comprises receiving, by said secure link, said web page information from said application server, said web page information having at least processed The unsupported portion for further processing and rendering.
Advantageously, said one or more processors and/or circuits are operative to establish a secure link between said internet enabled STB and said application server.
Preferably, the Internet-enabled STB and the application server mutually authenticate to determine the identity of the other party.
Advantageously, said one or more processor and/or circuit application encryption techniques ensure said link security between said internet enabled STB and said application server.
Preferably, the encryption technique includes symmetric key cryptography, public key cryptography, and/or hash function cryptography.
Preferably, the one or more processors and/or circuits transmit, by the secure link, a webpage information request submitted by the secure network server and the encrypted certificate of the internetable STB to the application server, The webpage information includes a supported part and an unsupported part.
Preferably, the unsupported part of the webpage information includes a plug-in program and/or multimedia content that is not supported by the Internet-enabled STB.
Advantageously, said one or more processors and/or circuits allow said application server to receive said requested web page information directly from said secure web server.
Advantageously, said one or more processors and/or circuits request said application server to process at least said unsupported portion of said web page information received from said application server.
Advantageously, said one or more processors and/or circuits are operative to receive said web page information from said application server over said secure link, said web page information having at least said not processed Supported parts for further processing and rendering.
The various advantages, aspects, and novel features of the invention, as well as the details of the embodiments illustrated herein, are set forth in the Detailed Description.
<p>100Internet network</p><p>110Display equipment</p><p>120Internet access STB</p><p>130Application Server</p><p>140Secure web server</p><p>150Common web server</p><p>125, 135, 145, 155, 165 links</p><p>200Internet access STB</p><p>210STB processor</p><p>220STB memory</p><p>230STB interface module</p><p>240A/V output</p><p>250STB Security Module</p><p>300Application Server</p><p>310Server Processor</p><p>320Server memory</p><p>330Server Security Module</p><p>340Server Interface Module</p>
1 is a diagram showing a typical Internet network in accordance with an embodiment of the present invention. The Internet network can be used to provide information security processing for the complete Internet at any location; FIG. 2 is a block diagram showing a typical Internet-enabled STB in accordance with an embodiment of the present invention, which can be used for the Internet-based STB. Providing information security processing for the complete Internet at any location; FIG. 3 is a block diagram showing a typical application server in accordance with an embodiment of the present invention, which can be used to provide information for a complete Internet at any location Security Processing; Figure 4 is a flow diagram showing exemplary steps for providing information security processing for a complete Internet at any location, in accordance with an embodiment of the present invention.
The present invention provides some embodiments of methods and systems that provide information security processing for a complete Internet anywhere. In various embodiments of the present invention, the Internet-enabled STB can be used to extend the security boundary from the Internet-enabled STB to the application server to enable support for secure network browsing operations from the application server. In this regard, the Internet-enabled STB can be used to establish a secure link between the Internet-enabled STB and the application server. The application server and the internet-ready STB mutually authenticate each other to determine the identity of the other party. Encryption technology is used to ensure link security between the Internet-enabled STB and the application server, such as symmetric key cryptography, public key cryptography, and/or hash function cryptography.
The Internet-enabled STB can be used to transmit the webpage information request submitted by the secure network server and the encrypted certificate of the Internet-enabled STB to the application server through a secure link between the Internet-enabled STB and the application server. The requested web page information may include a supported portion and an unsupported portion, wherein the unsupported portion may include, for example, a plug-in program and/or multimedia content that is not supported by the Internet-enabled STB. Thus, the application server can be allowed to receive requested web page information directly from a secure web server, such as a HTTPS (hypertext transfer protocol secure) URL (uniform resource locator, Uniform resource locator) access. The application server can be requested to process the At least the unsupported part of the received web page information. The Internet-enabled STB can then be used to receive web page information from the application server via a secure link between the Internet-enabled STB and the application server, the web page information having processed at least unsupported portions for further Processing and rendering.
The various embodiments of the invention described herein can be used to implement a complete Internet at any location where a user wants to access the Internet, such as at home, at work, or in a public place.
1 is a block diagram showing a typical Internet network in accordance with an embodiment of the present invention that can be used to provide information security processing for a complete Internet anywhere. As shown in Figure 1, an internet network 100 is shown. The internet network 100 can include a display device 110, an internet enabled STB 120, an application server 130, a secure web server 140, a general web server 150, and links 125, 135, 145, 155, 165.
Display device 110 and internet enabled STB 120 may be installed at home, at a company, at a school, at a library, and/or other similar facilities where a user would like to access the Internet and/or receive email. For example, when the installation location is located at home (eg, a home, an apartment), the display device 110 and the Internet-enabled STB 120 can be installed in a bedroom, living room, or family room. In another example, display device 110 and internet enabled STB 120 may be installed in a conference room when the installation location is at a company or public facility. The application server 130 can be installed locally, such as near the display device 110 and/or the Internet-enabled STB 120, or can be installed at the remote end, such as in the server computing cloud. A web server, such as secure web server 140 and/or normal web server 150, may be installed in the server computing cloud.
Display device 110 may include suitable logic, circuitry, interfaces, and/or code for displaying or presenting processed or decoded media content or television programming and web page information received from an internet enabled STB to a user.
The Internet-enabled STB 120 can include suitable logic, circuitry, interfaces, and/or code that can be used to connect the display device 110 to an external signal source and convert these signals into The content that can be displayed on the screen of the display device 110. The STB can be used for related processing of managing, transmitting, and/or storing video content that can be displayed on display device 110.
Internet access STB 120 can also be used to run web browsers, such as IE browser (Internet Explorer), Firefox browser (Mozilla, Firefox), Apple Safari browser (Apple Safari), Google View (Google Chrome), and/or Opry Mapper (Opera) to reproduce or render web page information that can be displayed on display device 110 for user interaction. Web page information from a web server, such as normal web server 150 or secure web server 140, may include, for example, images, audio, video, text, graphics, and/or other types of multimedia content. In the case that the webpage information includes plug-ins and/or multimedia content that are not supported by the Internet-enabled STB 120, the Internet-enabled STB 120 may request the application server 130 to assist in processing, for example, processing at least the unsupported portion of the webpage information. . Specific plugins include, for example, Flash applications and Java applets. In this regard, secure communication between the Internet-enabled STB 120 and the application server 130 is required.
The Internet-enabled STB 120 can be used to extend the security boundary to the application server 130 to enable secure network browsing support from the application server 130. A secure link 125 established between the Internet-enabled STB 120 and the application server 130 can be used, such as two-way authentication and/or encryption techniques. Encryption technology is the process of converting ordinary information (plaintext) into illegible (dark text) that cannot be understood using, for example, an encryption algorithm. Encryption techniques may include, for example, symmetric key cryptography, public key cryptography, and/or hash function encryption.
When the web page information of the normal web server 150 is requested, the online STB 120 can receive and process the supported portion of the web page information. In an exemplary embodiment of the present invention, the web-enabled STB 120 may request the application server 130 via the secure link 125 to process at least portions of the web page information that are not supported for rendering.
When the secure web server 140 web page information is requested, the internet-enabled STB 120 can transmit the request and the corresponding encryption certificate to the application server 130 via the secure link 125. Therefore, the application server 130 can be used to secure from the secure link 135. The web server 140 directly receives the requested web page information and processes at least the unsupported portion of the web page information. The web page information containing the processed portions that are at least unsupported can then be transmitted from the application server 130 to the web-enabled STB 120 over the secure link 125. The web-enabled STB 120 can complete processing of webpage information, such as processing of the supported portions of the webpage information, and then rendering the webpage information for display on the display device 110.
Application server 130 may include suitable logic, circuitry, interfaces, and/or code that may be used to run or execute a particular software application to access Internet-enabled STB 120 over secure link 125. In this regard, the application server 130 can be used to provide support for network browsing operations on the Internet-enabled STB 120, for example, to process at least portions of the web page information that are not supported during rendering.
When the web page information of the normal web server 150 is requested, the application server 130 can be configured to receive a request from the web-enabled STB 120 via the secure link 125 to process at least the unsupported portion of the web page information. In this regard, the application server 130 can transmit the processed portion of the web page information to the web-enabled STB 120 via the secure link 125 for rendering.
When the web page information of the secure web server 140 is requested, based on the encryption certificate provided by the web-enabled STB 120 over the secure link 125, the application server 130 can receive the web page sent from the secure web server 140 directly through the secure link 135. News. The application server 130 will process at least the unsupported portion of the web page information, and then send the web page information to the internet-accessible STB 120 via the secure link 125 for further processing and rendering.
The secure web server 140 can include suitable logic, circuitry, interfaces, and/or code that can be used to transmit protected web page information, such as the Internet-enabled STB 120, to the client. The web-enabled STB 120 can make a web page information request to the secure web server 140 using, for example, an HTTPS URL. HTTPS provides a secure channel or link over the Internet network 100 to provide reasonable protection from eavesdroppers and/or unnecessary man-in-the-middle attacks. Web page information can be transmitted, for example, via secure link 165 to Internet STB 120 for processing and rendering. In an exemplary embodiment of the present invention, based on the encryption certificate provided by the Internet-enabled STB 120, the secure network server 140 can be configured to transmit the webpage information requested by the Internet-enabled STB 120 to the application server 130 via the secure link 135 to process at least no The part that is supported.
The generic web server 150 can include logic, circuitry, interfaces, and/or code that can be used to send web page information, such as the web-enabled STB 120, to the client. The Internet-enabled STB 120 can make a webpage information request to the secure web server 140 using an HTTP (hypertext transfer protocol) URL. The normal web server 150 can be used to send webpage information requested by the web-enabled STB 120 to the web-enabled STB 120 via the link 145. In an exemplary embodiment of the present invention, the normal web server 150 may send at least the unsupported portion of the requested web page information to the application server 130 via the link 155, for example, to cause the application server 130 to process the at least not Supported parts to support web page rendering.
In operation, the Internet-enabled STB 120 can be used to establish a secure link 125 between the Internet-enabled STB 120 and the application server using, for example, two-way authentication and/or encryption techniques. When the web page information of the normal web server 150 is requested, the online STB 120 can receive and process the supported portion of the web page information. The Internet-enabled STB 120 can request the application server 130 via the secure link 125 to process at least portions of the web page information that are not supported. When the web page information of the secure web server 140 is requested, the web-enabled STB 120 can transmit the request and the corresponding encryption certificate to the application server 130 via the secure link 125. In this regard, the application server 130 can be configured to receive the requested web page information directly from the secure web server 140 over the secure link 135 and then process at least portions of the web page information that are not supported. The application server 130 can transmit web page information including the processed at least unsupported portion to the web-enabled STB 120 via the secure link 125. The web-based STB can process the webpage information, for example, processing the supported portion of the webpage information, and then rendering the webpage information so that it can be displayed on the display device 110.
Although the Internet-ready STB 120 as shown in Figure 1 is only used for the full Internet However, the present invention is not limited to this. Thus, without the departure of the spirit and scope of the various embodiments of the present invention, the Internet-enabled STB 120 is not employed, and a display device 110 that itself has a broadband connection function to achieve a comprehensive Internet experience can be supported.
2 is a block diagram showing a typical Internet-ready STB that can be used to provide information security processing for a complete Internet anywhere, in accordance with an embodiment of the present invention. As shown in Figure 2, an internet enabled STB 200 is shown. The Internet-enabled STB 200 can include an STB processor 210, an STB memory 220, an STB interface module 230, an A/V output 240, and an STB security module 250.
The STB processor 210 can include suitable logic, circuitry, interfaces, and/or code that can be used to provide processing related to managing, transmitting, and/or storing video content that can be displayed, for example, on the display device 110 described above. The STB processor 210 can also be used to run or execute a web browser to render or display web page information that can be displayed on the display screen of the display device 110 for user interaction.
When the web page information of the normal web server 150 is requested, the STB processor 210 can receive and process the supported portion of the web page information. The STB processor 210 can request the application server 130 to process at least the unsupported portion of the web page information for rendering, for example, via the secure link 125.
When the webpage information of the secure web server 140 described above is requested, the STB processor 210 can transmit the request and the corresponding encryption certificate to the application server 130 via the secure link 125. Accordingly, the application server 130 can be configured to receive the requested web page information directly from the secure web server 140 over the secure link 135 and process at least portions of the web page information that are not supported. After receiving the webpage information including the at least unsupported portion from the application server 130 via the secure link 125, the STB processor 210 can complete the processing of the webpage information, for example, the processing of the supported portion of the webpage information. The STB processor 210 can then render the web page information for display on the display device 110 via the A/V output 240.
STB memory 220 may include suitable logic, circuitry, interfaces, and/or code. It can be used to store information related to the operation of the STB processor 210.
The STB interface module 230 can include suitable logic, circuitry, interfaces, and/or code that can be used to enable the web-enabled STB 200 to be compatible with a variety of devices, including, for example, the application server 130 and/or the general web server 150. The STB interface module 230 can support connections to cable television services and/or satellite services. The STB interface module 230 can support multiple interfaces, such as a High-Definition Multimedia Interface (HDMI), an Ethernet Physical Layer (PHY), and a Universal Serial Bus (USB). ) and RS232 interface. Other types of connections, protocols, and/or interfaces may also be supported. The STB interface module 230 can support communication with the application server 130 over the secure link 125 and/or with the normal web server 150 over the secure link 145.
The A/V output 240 can include suitable logic, circuitry, interfaces, and/or code that can be used to provide audio and/or video content for display and reproduction on, for example, the display device 110 described above. In this regard, the A/V output 240 can support a variety of technical standards, such as DTV (Digital television), HDTV (high-definition television), and/or multi-screen solutions.
The STB security module 250 can include suitable logic, circuitry, interfaces, and/or code that can be used to support authentication operations, certificate usage, and/or encryption operations to provide a secure connection, such as the above-described Internet-enabled STB 200 and application server (eg, A secure link 125 between the application servers 130) described above. The STB security module 250 can transmit the corresponding encryption certificate of the Internet-enabled STB 200 to the application server 130 through the secure link 125.
In operation, the STB processor 210 can be used to run and execute a web browser to render or display web page information that can be displayed on the display screen of the display device 110 for user interaction. The STB security module 250 can be used, such as two-way authentication and/or encryption techniques, to establish a secure link 125 between the Internet-enabled STB 200 and the application server 130.
When the web page information of the normal web server 150 is requested, the STB processor 210 can receive and process the supported portion of the web page information. The STB processor 210 can request the application server 130 to process at least the webpage information through, for example, the secure link 125. The supported part is for rendering.
When the web page information of the secure web server 140 is requested, the STB processor 210 can transmit the request and the corresponding encryption certificate to the application server 130 via the secure link 125 along with the STB security module 250. In this regard, the application server 130 can be configured to receive the requested web page information directly from the secure web server 140 over the secure link 135 and process at least the unsupported portion of the web page information. After receiving web page information including the processed at least unsupported portion from the application server 130 via the secure link 125, the STB processor 210 may complete processing of the web page information, such as processing the supported portion of the web page information. . The STB processor 210 can then render the web page information for display or presentation on the display device 110 via the A/V output 240.
3 is a block diagram showing a typical application server in accordance with an embodiment of the present invention, which can be used to provide information security processing for a complete Internet at any location; as shown in FIG. 3, The application server 300 is applied. The application server 300 can include a server processor 310, a server memory 320, a server security module 330, and a server interface module 340.
The server processor 310 can include suitable logic, circuitry, interfaces, and/or code for processing requests from the STB, such as the above-described Internet-ready STB, to process at least portions of the webpage information that are not supported, such that the Internet-enabled STB 120 Complete the subsequent rendering. In this regard, the server processor 310 can be used to convert and/or decode web page information content in one format into another format. For example, the server processor 310 can be used to process plug-ins that are not supported by the web browser of the Internet-enabled STB 120 and to encode the processed plug-ins with a low-latency H.264/ACC encoder. For example, server processor 310 can include a number of different encoders that can be used to encode different types of content in a web page into different formats.
In some embodiments of the invention, server processor 310 may include an x86 architecture that may support operations in an x86 processor architecture, such as upgrading or encoding a particular plug-in. In other embodiments, the server processor 310 is available An emulator that provides an x86 processor to handle specific content that is not supported by the Internet-enabled STB 120.
When the STB requests the webpage information of the above-mentioned common web server 150 as described above, the server processor 310 can receive the request sent by the online STB 120 through a secure link such as the secure link 125 to process at least the webpage information. Part that is not supported. In this regard, the server processor 310 can transmit the processed portion of the web page information to the web-enabled STB 120 via the secure link 125 for rendering.
When the web-enabled STB 120 requests webpage information on the secure web server 140, based on the corresponding encryption certificate of the web-enabled STB 120 received by the server processor 310 over the secure link 125, the server security module 330 can be used to pass The secure link 135 directly receives the web page information of the secure web server 140. The server processor 310 can process at least the unsupported portion of the web page information, and then send the web page information to the web-enabled STB 120 via the secure link 125 for further processing and rendering.
Server memory 320 may include suitable logic, circuitry, interfaces, and/or code for storing information related to the operation of server processor 310. The server memory 320 can be used to store information (eg, coefficients, tables) related to the encoding operations supported by the server processor 310.
Server security module 330 may include suitable logic, circuitry, interfaces, and/or code to support authentication operations, certificate usage, and/or encryption operations for providing secure links, such as at server 300 and STB ( The above secure link 125 between the Internet access STBs as described above. The server security module 330 can receive a corresponding encryption certificate from the internet enabled STB 120. The server security module 330 can then forward the encryption certificate to a secure network server, such as secure network server 140, to support the network browsing operations requested by the Internet STB 120.
The server interface module 340 can include suitable logic, circuitry, interfaces, and/or code for enabling the server 300 to interface with an STB (eg, an Internet-ready STB) and/or as a network. A server, such as normal web server 150 or secure web server 140, communicates to obtain, for example, web page information. The server interface module 340 can support a variety of physical and/or logical connections or interfaces. The server interface module 340 can support, for example, communication with the Internet-enabled STB 120 over the secure link 125, communication with the normal network server 150 over the link 155, and/or communication with the secure network server 140 over the secure link 135. .
In operation, the server processor 310 can be configured to process requests sent from the Internet-enabled STB 120 to process at least a portion of the web page information for subsequent rendering by the Internet STB 120. The server security module 330 can be used to establish a secure link 125 between the application server 300 and the web-enabled STB 120 using, for example, two-way authentication and/or encryption techniques.
When the web-enabled STB 120 requests web page information of the normal web server 150, the server processor 310 can receive a request from the web-enabled STB 120 over the secure link 125 to process at least a portion of the web page information that is not supported. The server processor 310 sends the processed portion of the web page information to the internet enabled STB 120 via the secure link 125 for rendering.
When the web-enabled STB 120 requests the webpage information of the secure web server 140, based on the corresponding encryption certificate received by the server security module 330 from the web-enabled STB 120 via the secure link 125, the server processor 310 can be used to pass the secure chain. The way 135 receives web page information directly from the secure web server 140. The server processor 310 can process at least the unsupported portion of the web page information and then send the web page information over the secure link 125 to the internet enabled STB 120 for further processing and rendering.
4 is a flow chart showing exemplary steps for providing information security processing for a complete Internet at any location, in accordance with an embodiment of the present invention. As shown in FIG. 4, the example steps begin at step 401. In step 402, the Internet-enabled STB 120 can be used to establish a secure link 125 between the Internet-enabled STB 120 and the application server 130 to obtain network browsing support from the application server 130. In step 403, a secure website browsing request is detected. When requesting a secure website tour, the sample steps will Go to step 404. In step 404, the Internet-enabled STB 120 can be used to transmit a web page information request and a corresponding encryption certificate to the secure web server 140 to the application server 130 via the secure link 125. In step 405, the application server 130 can be allowed to receive the requested web page information directly from the secure web server 140. In step 406, the application server 130 can be configured to process at least the unsupported portion of the webpage information received by the application server 130, and send the processed webpage information to the web-enabled STB 120. In step 407, the Internet-enabled STB 120 can be configured to receive, from the application server 130, the webpage information including the processed at least unsupported portion through the secure link 125, and complete the processing of the webpage information. In step 408, the Internet STB is available. 120 can render the processed web page information. The example steps will proceed to the final step 410. In step 403, the example step will perform step 409 when no site browsing is requested. In step 409, the Internet-enabled STB 120 can be used to receive and process the supported portions of the web page information of the normal web server 150, and/or to submit the processing web page information to the application server 130 via the secure link 125, at least not supported. Part of the request. The example steps will perform step 408.
In various embodiments of the present invention, the Internet-enabled STB 120 can be used to extend the security boundary from the Internet-enabled STB 120 to the application server 130 to enable support from the application server 130 for secure network browsing operations. In this regard, the Internet-enabled STB 120 can be used to establish a secure link 125 between the Internet-enabled STB 120 and the application server 130. The application server 130 and the internet-ready STB 120 can mutually authenticate to confirm the identity of the other party. Encryption operations such as symmetric key cryptography, public key cryptography, and/or hash function cryptography may be used to secure the link 125 between the Internet-enabled STB 120 and the application server 130.
The Internet-enabled STB 120 can be used to transmit the webpage information request submitted by the secure web server 140 and the encrypted certificate of the web-enabled STB 120 to the application server 130 through the secure link 125 between the web-enabled STB 120 and the application server 130. The requested web page information may include a supported portion and an unsupported portion, and the unsupported portion herein may include, for example, a plug-in and/or not supported by the Internet-enabled STB 120. Multimedia content. Thus, the application server 130 can be allowed to receive the requested web page information directly from the secure web server 140. The application server 130 can be requested to process at least a portion of the received web page information that is not supported. The Internet-enabled STB 120 can then be used to receive webpage information from the application server 130 via the secure link 125 between the Internet-enabled STB 120 and the application server 130, the webpage information including processed at least unsupported portions for further processing. Processing and rendering.
Another embodiment of the present invention can provide a machine and/or computer readable memory and/or media on which machine code and/or computer programs are stored, the machine code and/or computer program having a machine and/or Or at least one code segment executed by the computer, thereby enabling the machine and/or computer to perform the steps described herein to provide secure information processing at any location for a complete Internet experience.
Therefore, the present invention will be realized by a combination of a hardware, a soft body or a hardware and a soft body. The present invention can be implemented in a centralized manner in at least one computer system, or by dispersing the various elements in a plurality of interconnected computer systems. Any type of computer system or other device suitable for implementing the methods described herein is suitable. A typical combination of hardware and software can be a general purpose computer with a computer program that, once installed and executed, can control the computer system to perform the methods described herein.
The present invention can also be embedded in a computer software product that includes all of the features capable of implementing the methods described herein and that can be implemented when it is installed in a computer system. The computer program in this document refers to any expression of a set of instructions written in any programming language, code or symbol that enables the system to have information processing capabilities to directly implement a particular function, or to perform the following Specific functions are implemented after one or two steps: a) conversion to other languages, codes or symbols; b) reproduction in a different format.
While the invention has been described by way of specific embodiments, the embodiments of the invention In addition, for specific situations or materials, Various modifications are possible without departing from the scope of the invention. Therefore, the invention is not limited to the specific embodiments disclosed, but all the embodiments falling within the scope of the appended claims.
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| CN101350808A | Cites | China | Examiner |
| US2009019151A1 | Cites | United States of America | Examiner |
| TW200933356A | Cites | Taiwan Province of China | Examiner |
36 members in 5 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 26178009 | United States of America | P | |
| 61261780 | United States of America | – | |
| 12650020 | United States of America | – | |
| 65002009 | United States of America | A | |
| 12650020 | – | – | – |
| 61261780 | – | – | – |
| US20090261780P | – | – | – |
| US20090650020 | – | – | – |
Members36
| Document | Office | Kind | |
|---|---|---|---|
| CN102063464A | China | A | |
| EP2323048A1 | European Patent Office (EPO) | A1 | |
| EP2323338A1 | European Patent Office (EPO) | A1 | |
| US2011119722A1 | United States of America | A1 | |
| US2011119723A1 | United States of America | A1 | |
| US2011161393A1 | United States of America | A1 | |
| US2011161400A1 | United States of America | A1 | |
| US2011161511A1 | United States of America | A1 | |
| US2011161523A1 | United States of America | A1 | |
| US2011162023A1 | United States of America | A1 | |
| US2011162025A1 | United States of America | A1 | |
| US2011162027A1 | United States of America | A1 | |
| CN102118384A | China | A | |
| TW201145929A | Taiwan Province of China | A | |
| TW201146013A | Taiwan Province of China | A | |
| HK1157889A1 | Hong Kong, China | A1 | |
| HK1159363A1 | Hong Kong, China | A1 | |
| US8448214B2 | United States of America | B2 | |
| US2013254821A1 | United States of America | A1 | |
| CN102063464B | China | B | |
| US8656443B2 | United States of America | B2 | |
| US8713622B2 | United States of America | B2 | |
| US2014137175A1 | United States of America | A1 | |
| US2014165123A1 | United States of America | A1 | |
| TWI450587B | Taiwan Province of China | B | |
| US8918827B2 | United States of America | B2 | |
| US8954538B2 | United States of America | B2 | |
| TWI474696BThis record | Taiwan Province of China | B | |
| US9106437B2 | United States of America | B2 | |
| CN102118384B | China | B | |
| US2015350734A1 | United States of America | A1 | |
| US9219948B2 | United States of America | B2 | |
| US9294791B2 | United States of America | B2 | |
| US9357269B2 | United States of America | B2 | |
| US9621957B2 | United States of America | B2 | |
| US10419821B2 | United States of America | B2 |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A | |
| Annulment or lapse of patent due to non-payment of feesLapsedMM4A | MM4A |
Numbers
- Publication
- I474696
- Publication, DOCDB
- I474696
- Publication, EPODOC
- TWI474696B
- Application
- 99139477
- Application, DOCDB
- 99139477
- Application, EPODOC
- TW20100139477
Titles2
- English
- Method and system for providing secure handling of information for complete internet anywhere
- Chinese
- 一種保障互聯網連接安全的方法和系統
Classification
- CPC, 12
- H04N21/4782
- G06F16/972
- H04L9/0838
- H04L12/2834
- H04L63/0209
- H04L63/0272
- H04L67/02
- H04N21/2355
- H04N21/4622
- H04N21/4753
- H04N21/63775
- H04N21/6581
- IPC, 1
- H04L29 02