Method and apparatus for securing transfer of and access to digital content
First Claim
Patent Images
1. A method of providing secure access to content comprising:
- determining a secure medium identification (disk ID) from a secure medium including content, wherein the content is stored as encrypted content on the secure medium;
sending an encrypted one-time session key and the disk ID to a server;
requesting user authentication;
if the user is successfully authenticated, receiving a copy of the encrypted one-time session key from the server to enable reading of the content on the secure medium;
receiving a content decryption key from the server, in response to the disk ID and the user authentication, wherein the content decryption key is determined based on the disk ID;
using the content decryption key and the session key returned by the server to decrypt the content received from the secure medium; and
playing the decrypted content.
7 Assignments
0 Petitions
Accused Products
Abstract
A method and apparatus for securely accessing digital content is provided. The method of providing secure access to content comprises determining an identification (ID) from a secure medium including content. The method further comprises sending a session key and the ID to a server. Furthermore, the method includes requesting user authentication and if the user is successfully authenticated, receiving the session key from the server to enable reading of the content on the secure medium.
43 Citations
16 Claims
-
1. A method of providing secure access to content comprising:
-
determining a secure medium identification (disk ID) from a secure medium including content, wherein the content is stored as encrypted content on the secure medium; sending an encrypted one-time session key and the disk ID to a server; requesting user authentication; if the user is successfully authenticated, receiving a copy of the encrypted one-time session key from the server to enable reading of the content on the secure medium; receiving a content decryption key from the server, in response to the disk ID and the user authentication, wherein the content decryption key is determined based on the disk ID; using the content decryption key and the session key returned by the server to decrypt the content received from the secure medium; and playing the decrypted content. - View Dependent Claims (2, 3, 4, 5, 6, 7, 8, 9)
-
-
10. An apparatus comprising a secure device for accessing secure content coupled to a client system comprising:
-
a reader to read an identification (ID) and content from a secure medium; a session key generation logic to generate a one-time session key; an encryption logic to send the ID and the session key encrypted to a server; an authentication logic to receive authentication from the server indicating approval to read the content of the secure medium; the reader further to pass the ID and the content to the encryption logic; the encryption logic further to encrypt the content prior to sending the content to an application; and an application on the client system, the application comprising; a user authentication interface to request a user authentication in response to a server request, and to send data received from a user to the server; a key logic to receive a decryption key from the server, if the user is successfully authenticated, wherein the decryption key includes both the session key and a content decryption key; and a streaming decryption logic to receive content from the secure device and to decrypt the content using the decryption key received from the server, and to play the content. - View Dependent Claims (11, 12, 13, 14)
-
-
15. A client system to securely access digital content on a secure medium, the client system comprising:
-
a secure device comprising; a reader to read a disk identification (disk ID) and content from the secure medium; an authentication logic to receive authentication from a server indicating approval to read the content of the secure medium; and an encryption logic further to encrypt the content prior to sending the content to an application; the application comprising; a user authentication interface to request a user authentication in response to a server request, and to send user authentication data received from a user to the server; an association logic to determine if the disk ID is associated with the user, and; if the disk ID is not yet associated with the user, to associate the user authentication data with the disk ID; and if the disk ID is associated with the user, determining that the current user authentication matches the user associated with the disk ID, to authenticate the user; a key logic to receive a decryption key from the server, if the user is successfully authenticated; and a streaming decryption logic to receive encrypted content from the secure device and decrypt the encrypted content using the key received from the server, and play the decrypted content. - View Dependent Claims (16)
-
Specification