USRE47730E

System and method for controlled copying and moving of content between devices and domains based on conditional encryption of content key depending on usage state

Claim Score by NHIP

Read claim 1, the broadest

Abstract

A system and method is disclosed for allowing content providers to protect against widespread copying of their content, while enabling them to give their customers more freedom in the way they use the content. In accordance with one embodiment, content providers identify their content as protected by watermarking the content. Consumers use compliant devices to access protected content. All of a user's compliant devices, or all of a family's devices, can be organized into an authorized domain. This authorized domain is used by content providers to create a logical boundary in which they can allow users increased freedom to use their content.

Term

Term ended

Expired 18 October 2021, 4.9 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

31 claims: 9 independent, 22 dependent

  1. 1
    Broadest claimClaim Score 67, broad(NHIP)A method, comprising:at a first device within an authorized domain, checking a usage state record contained in a voucher which accompanies a piece of encrypted content, the voucher including the usage state record and an encrypted content key;if the usage state record is not unrestricted and allows copying: decrypting the encrypted content key with a device key;re-encrypting the decrypted content key with a public key of a target device within said authorized domain;updating the usage state record;and storing the re-encrypted content key and the updated usage state record in a re-targeted voucher;and determining to send the encrypted content and the re-targeted voucher to the target device.
  2. 6
    A method, comprising:at a first device within a first authorized domain, checking a usage state record contained in a voucher which accompanies a piece of encrypted content, the voucher including the usage state record and an encrypted content key;if the usage state record or a domain traversal flag in said voucher indicates that inter- domain copying is allowed: decrypting the encrypted content key with a device key;re-encrypting the decrypted content key with a public key of a target device within a second authorized domain;updating the usage state record;and storing the re-encrypted content key and the updated usage state record in a re- targeted voucher;and determining to send the encrypted content and the re-targeted voucher to the target device.
  3. 10
    An apparatus, comprising:a processor;and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the processor, cause the apparatus at least to perform: at a first device within an authorized domain, check a usage state record contained in a voucher which accompanies a piece of encrypted content, the voucher including the usage state record and an encrypted content key;if the usage state record is not unrestricted and allows copying: decrypt the encrypted content key with a device key;re-encrypt the decrypted content key with a public key of a target device within said authorized domain;update the usage state record;and store the re-encrypted content key and the updated usage state record in a re- targeted voucher;and determine to send the encrypted content and the re-targeted voucher to the target device.
  4. 13
    An apparatus, comprising:a processor;and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the processor, cause the apparatus at least to perform: at a first device within a first authorized domain, check a usage state record contained in a voucher which accompanies a piece of encrypted content, the voucher including the usage state record and an encrypted content key;if the usage state record or a domain traversal flag in said voucher indicates that inter-domain copying is allowed: decrypt the encrypted content key with a device key;re-encrypt the decrypted content key with a public key of a target device within a second authorized domain;update the usage state record;and store the re-encrypted content key and the updated usage state record in a re- targeted voucher;and determine to send the encrypted content and the re-targeted voucher to the target device.
  5. 17
    A computer program product comprising computer executable program code recorded on a non-transitory computer readable storage medium, the computer executable program code comprising:code for causing, at a first device within an authorized domain, check of a usage state record contained in a voucher which accompanies a piece of encrypted content, the voucher including the usage state record and an encrypted content key;code for causing if the usage state record is not unrestricted and allows copying: decryption of the encrypted content key with a device key;re-encryption of the decrypted content key with a public key of a target device within said authorized domain;update of the usage state record;and store of the re-encrypted content key and the updated usage state record in a re- targeted voucher;and code for causing determination to send the encrypted content and the re-targeted voucher to the target device.
  6. 20
    A computer program product comprising computer executable program code recorded on a non-transitory computer readable storage medium, the computer executable program code comprising:code for causing, at a first device within a first authorized domain, check of a usage state record contained in a voucher which accompanies a piece of encrypted content, the voucher including the usage state record and an encrypted content key;code for causing if the usage state record or a domain traversal flag in said voucher indicates that inter-domain copying is allowed: decryption of the encrypted content key with a device key;re-encryption of the decrypted content key with a public key of a target device within a second authorized domain;update of the usage state record;and store of the re-encrypted content key and the updated usage state record in a re-targeted voucher;and code for causing determination to send the encrypted content and the re-targeted voucher to the target device.
  7. 24
    A method comprising:providing, by a trust management provider server, certification that a new device to be added to an authorized domain, meets requirements of the authorized domain;communicating, by the trust management provider server, with a content provider that dictates rules for the authorized domain for the new device for certifying that the new device meets requirements of having a domain key for the authorized domain, the content provider being a provider of a content key seed to encrypt with the domain key to generate a content key useable in the authorized domain;determining, by the trust management provider server, that the new device has the domain key for the authorized domain;and joining, by the trust management provider server, the new device into the authorized domain and maintaining the authorized domain, including replacing unusable content keys produced with content key seeds;wherein the new device is the device of a user or a family or both, and wherein a content protection scheme is provided for any type of content or device, which enables a multitude of content providers and device manufacturers to implement the content protection scheme.
  8. 30
    An apparatus comprising:a processor;and at least one memory including computer program code, the at least one memory and the computer program code configured to, with the processor, cause the apparatus at least to perform: providing, by a trust management provider server, certification that a new device to be added to an authorized domain, meets requirements of the authorized domain;communicating, by the trust management provider server, with a content provider that dictates rules for the authorized domain for the new device for certifying that the new device meets requirements of having a domain key for the authorized domain, the content provider being a provider of a content key seed to encrypt with the domain key to generate a content key useable in the authorized domain;determining, by the trust management provider server, that the new device has the domain key for the authorized domain;and joining, by the trust management provider server, the new device into the authorized domain and maintaining the authorized domain, including replacing unusable content keys produced with content key seeds;wherein the new device is the device of a user or a family or both, and wherein a content protection scheme is provided for any type of content or device, which enables a multitude of content providers and device manufacturers to implement the content protection scheme.
  9. 31
    A computer program product comprising computer executable program code recorded on a non-transitory computer readable storage medium, the computer executable program code, which when executed, performs steps comprising:causing providing, by a trust management provider server, certification that a new device to be added to an authorized domain, meets requirements of the authorized domain;causing communicating, by the trust management provider server, with a content provider that dictates rules for the authorized domain for the new device for certifying that the new device meets requirements of having a domain key for the authorized domain, the content provider being a provider of a content key seed to encrypt with the domain key to generate a content key useable in the authorized domain;causing determining, by the trust management provider server, that the new device has the domain key for the authorized domain;and causing joining, by the trust management provider server, the new device into the authorized domain and maintaining the authorized domain, including replacing unusable content keys produced with content key seeds;wherein the new device is the device of a user or a family or both, and wherein a content protection scheme is provided for any type of content or device, which enables a multitude of content providers and device manufacturers to implement the content protection scheme.