Digital Rights Management for Movie Systems

By receiving and decrypting session information at the server, the problem of existing DRM technology being limited in content protection when a specific trusted device is not available is solved, and the secure transmission and playback of digital content is realized.

CN111506883BActive Publication Date: 2025-05-16NBCUNIVERSAL MEDIA LLC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN201911376848.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-12-13
Filing Date
2019-12-27
Publication Date
2025-05-16
Estimated Expiration
2039-12-27

AI Technical Summary

Technical Problem

When existing DRM technologies support content playback and access protection, there is a problem that content protection functions are limited when a particular trusted device does not exist or is not available.

Method used

By receiving session information at the server, including information for authorizing decryption of digital content, and determining and decrypting the digital content based on this information, it is ensured that the content can be safely transmitted even if a particular trusted device is unavailable.

Benefits of technology

It enables content protection to ensure the secure transmission and playback of digital content even when a particular trusted device does not exist or is not available.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111506883B_ABST
    Figure CN111506883B_ABST
Patent Text Reader

Abstract

Systems and methods for controlling the transmission of digital content stored at a server are disclosed. According to at least one embodiment, the method includes: receiving session information from a device at a server, the session information including information authorizing the server to decrypt digital content for transmission to a playback device; determining, based on the session information, at the server to decrypt the digital content for transmission to the playback device; decrypting the digital content for transmission to the playback device at the server in response to determining to decrypt the digital content; and transmitting the decrypted digital content to the playback device at the server.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims the benefit of U.S. Provisional Application No. 62 / 798,958, filed on January 30, 2019, the contents of which are incorporated herein by reference in their entirety. Background Art

[0003] Digital rights management (DRM) technology provides protection for managing access rights to digital content. For example, in a digital cinema, where a server holds encrypted content for playback on a projector, the server can be allowed to provide digital content to the projector for playback only when the server identifies the projector as a trusted device. In this regard, once the device has the appropriate required security capabilities and protocols, the device can become a trusted device. In addition, link encryption and other security parameters may also be required before the server provides digital content to the projector. Although some of these DRM technologies have a role in providing robust content security, they may also act as technical barriers when the full (or more complete) range of dedicated equipment required to support the technology is not available. An example of this aspect is an electronic cinema system (E-Cinema) environment, where more general equipment can be used, but content playback and access protection are still required. Summary of the invention

[0004] For various embodiments disclosed herein, alternative DRM techniques are presented.According to various embodiments, features related to content protection are provided even when one or more specific trusted devices are not present and / or unavailable.

[0005] According to at least one embodiment, a method for controlling the transmission of digital content stored at a server is disclosed. The method includes: receiving session information from a device at the server, the session information including information for authorizing the server to decrypt the digital content for transmission to a playback device; and determining at the server to decrypt the digital content for transmission to the playback device based on the session information. The method also includes: in response to determining to decrypt the digital content, decrypting the digital content for transmission to the playback device at the server; and transmitting the decrypted digital content to the playback device at the server.

[0006] According to at least one embodiment, a device for controlling the transmission of stored digital content is disclosed. The device includes: a network communication unit configured to transmit and receive data; and one or more controllers. The one or more controllers are configured to: receive session information from a device, the session information including information for authorizing the device to decrypt the digital content for transmission to a playback device; determine to decrypt the digital content for transmission to the playback device based on the session information; decrypt the digital content for transmission to the playback device in response to determining to decrypt the digital content; and transmit the decrypted digital content to the playback device.

[0007] According to at least one embodiment, a machine-readable non-transitory medium is disclosed, on which machine-executable instructions for controlling the transmission of digital content stored at a server are stored. The instructions include: receiving session information from a device at the server, the session information including information for authorizing the server to decrypt the digital content for transmission to a playback device; determining at the server to decrypt the digital content for transmission to the playback device based on the session information; in response to determining to decrypt the digital content, decrypting at the server the digital content for transmission to the playback device; and transmitting the decrypted digital content to the playback device at the server.

[0008] According to at least one embodiment, a method for controlling the transmission of digital content stored at a server is disclosed. The method includes: transmitting a request at a device to a network, the request requesting permission to play the digital content, the request including credential information identifying a user as a party or entity authorized to access the digital content. The method also includes: receiving session information at the device from the network based on the request, the session information including information for authorizing the server to decrypt the digital content for transmission to a playback device; and transmitting the session information at the device to the server. Without transmitting the session information to the server, the server lacks the ability to authenticate the playback device as a trusted device. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] The above and other aspects and features of the present disclosure will become more apparent upon consideration of the following description of the embodiments in conjunction with the accompanying drawings.

[0010] Figure 1 is an illustration of a system for controlling the transmission of digital content according to at least one embodiment.

[0011] Figure 2 A DRM system for controlling and tracking playback of digital content according to at least one embodiment is illustrated.

[0012] Figure 3 is a flow chart illustrating a method of controlling transmission of digital content according to at least one embodiment.

[0013] Figure 4 is an illustration of a computing environment in accordance with at least one embodiment.

[0014] Figure 5 is a block diagram of an apparatus according to at least one embodiment. DETAILED DESCRIPTION

[0015] In the following detailed description, reference is made to the accompanying drawings, which form a part of the detailed description and show by way of illustration specific embodiments of the invention. It should be understood by those of ordinary skill in the art that other embodiments may be utilized and structural and procedural changes may be made without departing from the scope of the invention. Wherever possible, the same reference numerals will be used throughout the drawings to refer to the same or similar parts.

[0016] refer to Figure 1 , illustrates a system 100 for controlling the transmission of digital content. The system 100 may be configured to generate, encode, distribute, and / or store audio and / or video content, and receive and process requests from client terminals to present content. Content suitable for delivery via wireless communications, etc., will be discussed. Figure 1 However, the present disclosure is not limited thereto, and one of ordinary skill in the art will appreciate that the features discussed herein may be applied to many other applications, platforms, and content delivery methods known to one of ordinary skill in the art.

[0017] System 100 may include content input 101, where content is created and / or generated for encoding and distribution. At content input 101, content of a particular segment may be captured and / or uploaded. According to other embodiments of system 100, content may be provided in other ways from various sources including video (e.g., television broadcasts, cable video distribution systems, satellite content distribution, Internet video, streaming video, mobile video distribution systems, digital video downloads, etc.). For the purpose of brevity, this article will mainly describe examples of content with respect to uploaded non-advertising content or movie-related content. However, it is understood that other types of content may be utilized. For example, although embodiments are described herein with reference to video content, it is understood that non-video or text-based content (such as interactive games, articles, e-books, etc.) may be utilized.

[0018] Embodiments of the system 100 may further include a content metadata source 102 that creates, collects, compiles, and / or provides metadata associated with the content for compilation and association with the distributed content. For example, the metadata may describe topic elements, underlying topics, and other data.

[0019] In system 100, content metadata source 102 and content input 101 may be coupled to a media encoder 103, which is configured to encode the content along with the content's encoded metadata. The encoded files are then made available for transmission (eg, according to a particular schedule).

[0020] In some embodiments, the encoded file may correspond to a known compressed or uncompressed file format, including MPEG-1, MPEG-2, MPEG-4, H.264, AVC, DV, DVCAM, AVI, ASF, MOV, WMV, etc. However, it is understood that the present disclosure is not limited thereto, and many other compressions and formats may be utilized. The encoder may encode the content and cause the generated encoded file to be distributed by the content server 104.

[0021] The media encoder 103 may also be configured such that the encoded media file is simultaneously stored in a memory associated with the content server 104. In some embodiments, the media encoder 103 may also be configured to provide the encoded media file to the retrieval content source 107, where the encoded media file may be stored for retrieval. In other embodiments, the encoded media file may be stored in a database external to the system, and the content server 104 or the retrieval content source 107 may be configured to store a pointer or path description for querying and / or requesting the encoded media file from the external database for subsequent retrieval.

[0022] According to at least one embodiment, the encoded media files may be stored in the retrieved content source 107 along with metadata associated with the media files, including encoding metadata, closed captioning information, etc. In some embodiments, the retrieved content source 107 may also receive metadata directly from the content metadata source 102 to be associated with and stored with the encoded media files.

[0023] Returning to the content server 104 of the system 100, the content server 104 may include a plurality of content servers, each content server being configured to handle requests for media files and facilitate transmission of the media files to the requesting party. Figure 1 As shown in , content server 104 can communicate with client terminal 106 via network 105 .

[0024] The content server 104 may be configured to receive a request for media content from the client terminal 106 and provide information to the client terminal 106 in response to the request. The information may include data associated with the encoded media content or address information of a file for retrieving the encoded media content. It will be appreciated that the content server 104 may be configured to provide information, data, and media content other than video, including audio, text, metadata, etc.

[0025] For example, content server 104 may be an enterprise server, a web server, a media server, a mobile data server, or any other type of server. In some embodiments, content server 104 may be a computer or computer program responsible for accepting requests from client terminals 106 (e.g., HTTP, RTSP, or other protocols capable of initiating a media session) and serving client terminals 106 with streaming media. Figure 1 Not shown, but consider an embodiment in which client terminal 106 is configured to transmit and receive data directly to and from a separate web server, which in turn transmits and receives data transmissions to and from content server 104 via a network such as network 105.

[0026] In some embodiments, content server 104 can be configured to provide one or more manifest data files including information related to the encoded media content to client terminal 106. The manifest data file can be provided to client terminal 106 in response to a request for the encoded media content. The manifest can include information about the recommended bandwidth for each encoding level, the location where each encoded data file is available (such as, an address, link, or other pointer to the location where the encoded file can be retrieved), and various metadata related to the encoded media content, such as, event information, media type, aspect ratio, codec information, etc. In some embodiments, the manifest can be provided in the form of an XML file. However, various implementations and file types known to those of ordinary skill in the art are considered.

[0027] The network 105 may include various systems for distributing content, including any desired combination of hardwired and wireless communication links, including a wide area network (WAN), a local area network (LAN), a wireless network suitable for packet-type communications, air, satellite, cable, Internet, other network connection systems, etc., which implement networks and hardware known and used in the relevant art, including broadcast technology, cable or satellite distribution systems, Internet Protocol (IP) or other networking technologies, etc. Examples of content include live and recorded television, movies, Internet streaming video, and audio, music, radio or other audio-visual content, etc. The system 100 may also include a gateway (not depicted), such as a server, a router, a firewall server, a host, a proxy server, a request redirector, etc.

[0028] The client terminal 106 may be connected to the network 105. The client terminal 106 may be a hardware component including software code and applications configured to allow the client terminal to communicate, transmit, request, and receive data packets via the network 105, which may correspond to streaming media data. The client terminal 106 may include any terminal or system configured to receive a content signal, and in some embodiments, the client terminal 106 may be configured to decode the received encoded media file and prepare the content for presentation to a user via an output device such as a display. The output device may be implemented in the same hardware as the client terminal 106, or in some embodiments, the output device may be implemented in separate hardware or location from the client terminal 106 and coupled and / or associated with the client terminal in other ways (such as by a wired connection or wireless communication).

[0029] For example, the client terminal 106 may correspond to an Internet video streaming device that is configured to request, transmit and receive data packets corresponding to Internet streaming video, and the client terminal may also be configured to decode the received data packets and prepare media content to be displayed via a separate output such as a television. In some embodiments, the client terminal 106 may also be configured to transmit information about content data received and decoded by the client terminal 106 to one or more other aspects of the system 100 via the network 105 or a similar network. Various other embodiments of the client terminal 106 may include a television, a desktop computer, a laptop computer, a tablet computer, a mobile smart phone, a personal media device, a wearable device, a set-top box receiver, a streaming Internet content device, a satellite television receiver, etc. In other embodiments, the client terminal 106 may be implemented in more than one connected device.

[0030] In an embodiment, the client terminal 106 may request, retrieve and / or receive specific content from the content server 104 via the network 105. The request, retrieval and / or receipt of specific content may correspond to a user of the client terminal selecting (one or more) specific segments of content, entering a specific URL or address at the client terminal, or transmitting and receiving instructions or requests to retrieve specific content items using a content provider-specific application configured to connect to the content server 104. In some embodiments, the content server 104 may be configured to provide the client terminal 106 with a single or multiple encoded information streams, including audio / video content and data associated with the audio / video content, such as metadata.

[0031] For metadata, the client terminal 106 may request information (eg, an identifier) ​​that is more general (or generic) than a specific identifier that identifies a discrete broadcast signal.

[0032] Some aspects of the present disclosure are directed to a method (or structure) for controlling the transmission of digital content stored at a server (e.g., server 104) or from other devices (e.g., in a movie system environment). According to one or more specific aspects, the digital content will be received at a client terminal 106 including a playback device. However, the playback device is not a trusted device, for example, from the perspective of the server.

[0033] Various aspects of the present disclosure are directed to controlling the transmission of digital content to such playback devices so that at least a certain level of content security is provided. Although various embodiments will be described with reference to a movie system environment (e.g., a digital movie environment), it is understood that the features described herein also apply to other environments including those in which improved content security is sought.

[0034] Figure 2 2 illustrates a DRM system 200 for controlling and tracking the playback of digital content according to at least one embodiment. The digital content may include digital video content and / or digital audio content. Figure 2 , the server 206 stores the encrypted digital content. The content may be made available for playback on a playback device 208. For example, the playback device 208 may be a projector (or projection device) configured to project the content onto a screen 210. The connection between the playback device 208 and the server 206 may be a wired connection (e.g., a High Definition Multimedia Interface (HDMI) or Ethernet) or a wireless connection based on an Internet Protocol (IP) or Bluetooth.

[0035] In one or more embodiments, the connection between the playback device 208 and the server 206 may be an unsecured and / or unencrypted connection. In one or more embodiments, the playback device 208 is not a trusted device. For example, the playback device 208 is not a device recognized by the server 206, but is a generic playback device. However - according to one or more embodiments, the server 206 does not need to verify that the playback device 208 has the appropriate one or more required security capabilities, protocols, or identifications.

[0036] Such verification need not be performed by the server 206 before the server 206 decrypts the digital content for transmission to the playback device 208. For example, according to one or more embodiments, in order for the server 206 to decrypt the digital content for transmission, the server 206 first receives authentication information. The authentication information may be received from another device. The other device may be a mobile device 204 (e.g., a cellular phone, a tablet, a computing device, or any other electronic device). The authentication information includes information that authorizes the server 206 to decrypt the digital content for transmission to the playback device 208. Although various embodiments are described herein with reference to the mobile device 204, it is understood that the other device may be a device having wired or wireless connectivity to the network 202 and / or to the server 206.

[0037] For example, a user (such as a theater owner, manager, or projector operator at or within a movie environment) may wish to play digital content stored on server 206. Using mobile device 204, the user may transmit a request to network 202 to request permission to play the digital content. The request may include user credentials that identify the user as a party authorized to access the digital content. If an organization with which the user is associated is a party or entity authorized to play encrypted digital content, the request may include information identifying the organization.

[0038] The request may include location information (e.g., GPS coordinates) associated with the user, with the mobile device 204, with the server 206, and / or with the playback device 208. The location information may also include information about the distance between the server 206 and the mobile device 204. The request may include timing information indicating one or more specific times or time periods at which playback is requested (or will occur).

[0039] Based on the received request (the request transmitted by the user), the network 202 can determine whether the user is authorized to play the digital content. For example, the determination can be based on the requested content(s). According to one or more embodiments, the determination can be based on user credentials that identify the user as a party authorized to access the digital content and / or information that identifies the organization with which the user is associated.

[0040] Additionally (or alternatively), the determination may be further based on location information received from the user - e.g., the user's geographic location (as provided by mobile device 204) - and / or the specific time(s) or time period(s) in which playback is requested. For example, playback may be authorized for specific users in a specific geographic area but not for specific users in another geographic area. Furthermore - even if playback in a specific geographic area is authorized, playback may be permitted only within a specific time window.

[0041] Additionally (or alternatively), the determination may be based on the distance between the server 206 and the mobile device 204. As an example, if the distance between the server 206 and the mobile device 204 is greater than a certain threshold (e.g., fifty feet), the network 202 may deny authorization. However—if the distance is less than or equal to the threshold, the network 202 may grant authorization. Such authorization may be granted if other parameters are met.

[0042] Additionally (or alternatively), a user or organization authorized to play encrypted digital content may be provided or granted no more than a certain number of plays. In this case, when (e.g., within a specific time period) the user or organization has exceeded the number of plays, the user or organization is no longer authorized to play the digital content within that time period. In this case, the user or organization may request another number of plays by again requesting permission to play the digital content (e.g., by transmitting the request using mobile device 204).

[0043] If network 202 determines that the user is authorized to play the digital content, network 202 may generate session information and transmit the session information to mobile device 204. In one or more embodiments, the session information includes one or more keys for decrypting the content and / or authenticating that the user is authorized to play the content.

[0044] Alternatively (or additionally), the session information may include information corresponding to the authentication information previously described with reference to the request that was transmitted by the mobile device 204 to the network 202. For example, the session information may include (one or more) regional restrictions regarding one or more specific locations where the digital content may be played and / or timing restrictions indicating (one or more) specific times or (one or more) time periods where the digital content may be played. As an example, the session information may include a restriction indicating that the playback is to occur between the times of 5:00 p.m. and 8:00 p.m. in Mumbai, India. In this way, the time period may indicate the following time period: the session information is actually valid during this time period. In another example, the session information may include playback radius information indicating a distance threshold between the server 206 and the mobile device 204, exceeding which the server 206 will stop decrypting content for playback. The playback radius information may be the same or different from the distance included in the request from the mobile device 204 to the network 202. For another example, the session information may include a counter that functions to limit the number of times the digital content may be played within a time period.

[0045] As previously mentioned, the session information may include one or more keys for decrypting content and / or authenticating that the user is authorized to play the content. Alternatively (or additionally), the session information may include an updated set of keys for decrypting digital content stored at the server 206 that is different from the digital content being requested by the user. If the connection between the mobile device 204 and the server 206 is secure (or at least sufficiently secure), including the updated keys in the session information may facilitate the network 202 to perform a secure (or more secure) update of the one or more keys stored at the server 206. Alternatively (or additionally), the keys stored at the server 206 may be updated by physically (or manually) installing the updated keys at the server 206. Such physical installation may be performed, for example, by an operator.

[0046] Mobile device 204 may transmit session information to server 206. According to one or more embodiments—upon receiving the session information, server 206 analyzes one or more keys included in the session information to determine whether mobile device 204 (e.g., a user of mobile device 204) is authorized to enable playback. For example, if server 206 determines that a key included in the session information is invalid (e.g., server 206 determines that the included key does not match a corresponding key that was stored in server 206 to help protect access to digital content), server 206 may determine not to decrypt the digital content. However, if server 206 determines that the key included in the session information is valid, server 206 may proceed to determine whether other conditions are met before decrypting the content for playback. For example, server 206 may determine whether geographic playback restrictions / rules, timed playback restrictions / rules, and / or playback count restrictions included in the session information are met before decrypting the digital content.

[0047] According to one or more embodiments, the server 206 may lack the capability for long (or longer) range network connectivity. In this case, the server 206 may be configured to operate using only shorter range network connectivity technologies such as Bluetooth, near field communication (NFC), or other similar technologies. In this regard, if the server 206 determines that it is located within a specific physical proximity of the mobile device 204, the server 206 may determine to decrypt the digital content for playback. The determination made by the server 206 may be based on, for example, location information included in the session information, or as another example, based on the latency (e.g., round-trip travel time) of the signal(s) received back by the server from the mobile device 204.

[0048] For example, if the server 206 is configured to operate using only Bluetooth communications (and / or similar technologies), the server 206 may need to be within the Bluetooth communications range of the mobile device 204 (e.g., less than forty feet, depending on the Bluetooth class of the server 206) in order to receive session information from the mobile device 204 and potentially decrypt the digital content for playback.

[0049] As another example, session information provided by network 202 (e.g., as relayed by mobile device 204) may specify that server 206 is located within a particular proximity of the mobile device in order for decryption to occur. For example, session information may specify that server 206 is within a predetermined distance (e.g., five feet) of mobile device 204 in order for digital content to be decrypted.

[0050] If the server 206 determines that it is outside the predetermined distance, the server 206 may determine not to decrypt the digital content. This determination may be made even if, for example, it is determined that the key included in the session information is otherwise valid. As another example, the server 206 may determine not to decrypt the digital content even if the server 206 can detect the presence of the mobile device 204 using a technology other than Bluetooth (e.g., ranging technology). By effectively requiring that the server 206 and the mobile device 204 are within a certain distance of each other, content security may be increased. For example, such a requirement makes it less likely that playback will be performed at the request of a user located outside of a geographic area that has been authorized by the network 202.

[0051] According to at least one embodiment—in order for decryption to occur, the server 206 may require that the mobile device 204 be within a certain distance (or radius) of the server 206 at or during an initial interval (e.g., in an interval in which at least an initial portion of the digital content is decrypted). However, according to at least one further embodiment, the mobile device 204 need not be within the certain distance during the entire time that the server 206 is decrypting the content and transmitting the decrypted content to the server 104. Alternatively—according to at least another embodiment, the server 206 may require that the mobile device 204 be within a predetermined distance for the entire duration of playback (e.g., during the entire time that the server 206 is decrypting the content and transmitting the decrypted content to the server 104 for playback). In this case—if it is determined that the mobile device 204 has moved (or is caused to have moved) relative to the server 206 beyond a threshold distance, the server 206 will stop decryption and playback of the digital content.

[0052] According to at least one embodiment, the server 206 can configure at least one aspect of the playback of the digital content based on the distance between the server 206 and the mobile device 204. Such an aspect can be repeatedly (e.g., periodically) configured during the playback of the digital content. For example, the server 206 can configure the resolution at which the playback is performed. As an example-if it is determined that the mobile device 204 is relatively close to the server 206 (within five feet from the server 206), the server 206 can play the digital content at a specific resolution (e.g., a higher or highest available visual resolution). However, if the mobile device 204 is determined to be not located so close to the server 206 (e.g., the mobile device 204 is located between five feet and ten feet from the server 206), the server 206 can reduce the resolution at which the playback is performed, and periodically reduce the resolution when it is determined that the distance has increased.

[0053] Additionally (or alternatively), the server 206 can configure the volume of the audio played. For example, when it is determined that the distance between the server 206 and the mobile device 204 has increased, the volume of the audio played can be reduced or lowered. Finally, when it is determined that the distance has exceeded a certain threshold, the server 206 can mute the volume.

[0054] One or more embodiments are directed to restricting the mobile device 204 from moving outside of a particular geographic area (to a different geographic area) after receiving session information. According to at least one further embodiment, the session information is configured such that the time period required for playback begins shortly after the mobile device 204 receives the session information from the network 202. For example, playback may be required to begin within thirty minutes to one hour after the mobile device 204 has received the session information. Additionally (or alternatively), the mobile device 204 may be required to send its current location information along with the session information to the server 206. The session information may include location information of the mobile device 204 at an earlier time when the mobile device 204 requested the session information (e.g., at an earlier time when the mobile device had sent a request to the network 202 for permission to play the digital content). If the difference between the current location information of the mobile device 204 and the location information at the earlier time exceeds a certain threshold, the server 206 may determine not to decrypt and not to play the digital content.

[0055] According to one or more embodiments, when the server 206 decrypts the digital content and transmits the digital content to the playback device 208, the counter is incremented and stored. For example - each time a threshold portion of the digital content (e.g., 10 minutes, 30 minutes, 60 minutes, etc.) has been played, the server 206 can increment the value of the counter and store the value as content playback information. The server 206 can provide the content playback information to the mobile device 204, for example, along with the decrypted digital content. According to at least one specific embodiment - based on the received content playback information, the mobile device 204 can display an indicator indicating the remaining number of playbacks available within a particular session.

[0056] According to at least one specific embodiment, the playback device 208 can start and maintain such a playback counter and store the playback counter as content playback information. The playback device 208 can provide the content playback information to the server 206, and the server 206 can transmit the content playback information to the mobile device 204.

[0057] According to at least one specific embodiment - if the value of the counter is less than the authorized (maximum) number of plays, the server 206 may enable additional plays to occur (e.g., within a particular session). However - if the count is equal to (or greater than) the authorized number of plays, the server 206 may stop decrypting and playing (or the mobile device 204 may cause the server 206 to stop decrypting and playing).

[0058] According to one or more other embodiments, if there is a communication link (e.g., a Bluetooth connection) between the playback device 208 and the mobile device 204, the playback device 208 can provide the content playback information directly to the mobile device 204. According to one or more embodiments, the mobile device 204 can forward the content playback information to the network 202, which updates and maintains a metric about the actual number of times the content is played compared to the authorized number of times. Therefore, the network 202 can determine the remaining number of times the content is played available at the server 206 or the mobile device 204.

[0059] To provide an additional layer of security, when the server 206 decrypts the digital content, the server 206 may insert a session-based visual and / or audio watermark into the digital content before transmitting the content to the playback device 208. According to one or more embodiments, the server 206 may generate the watermark using session information obtained from the mobile device 204. For example, the watermark may be generated based on one or more authorization keys, user information (e.g., user identifier information), organization information, geographic playback restriction information, playback time period information, playback count information, and / or distance information between the server 206 and the mobile device 204.

[0060] If the generated watermark is an audio watermark, the mobile device 204 may receive the audio watermark via audio output by the playback device 208 (e.g., at an internal microphone). In this case, the mobile device 204 may verify that the correct audio watermark has been generated and provide confirmation of the audio watermark to the network 202. According to one or more embodiments, the mobile device 204 may transmit at least a portion of the audio watermark to the network 202 for independent confirmation by the network 202. If an incorrect audio watermark is generated (or no audio watermark is generated), the mobile device 204 or the network 202 (via the mobile device 204) may interrupt decryption and playback at the server 206.

[0061] Similarly, if the generated watermark is a visual watermark, the mobile device 204 can verify that the correct visual watermark has been generated and provide confirmation of the visual watermark to the network 202. According to one or more embodiments, the mobile device 204 can transmit the visual watermark to the network 202 for independent confirmation. If an incorrect visual watermark is generated (or no visual watermark is generated), the mobile device 204 or the network 202 (via the mobile device 204) can interrupt decryption and playback at the server 206. With respect to audio watermarks and visual watermarks, verification and / or confirmation can be performed once at predetermined time intervals during playback, or a predetermined number of times.

[0062] In embodiments employing session-based watermarking, if any content is pirated from the server 206, the content can be easily traced back to the user who has obtained authorization to decrypt and display the content, as well as to the time and location where the digital content was displayed.

[0063] Figure 3 A flow diagram of a method 300 for controlling the transmission of digital content stored at a server is illustrated in accordance with at least one embodiment.

[0064] At block 302, a server receives session information from a device (eg, a mobile device). The session information includes information that authorizes the server to decrypt digital content for transmission to a playback device. As an example - return to reference Figure 2 , the server 206 receives session information from the mobile device 204. The session information includes information that authorizes the server 206 to decrypt the digital content for transmission to the playback device 208.

[0065] According to one or more specific embodiments, the session information includes one or more decryption keys or authentication keys.

[0066] According to one or more specific embodiments, the mobile device comprises a mobile phone. Additionally (or alternatively), the playback device comprises a projector (eg, a movie projector).

[0067] At block 304, the server determines, based on the session information, to decrypt the digital content for transmission to the playback device. Figure 2 The server 206 determines to decrypt the digital content for transmission to the playback device 208 based on the session information.

[0068] According to one or more specific embodiments - without determining to decrypt the digital content based on the session information, the server lacks the ability to authenticate the playback device as an authentic device.

[0069] The server can determine the decrypted digital content based on one or more decryption keys or authentication keys. Additionally (or alternatively), the server can further determine the decrypted digital content based on the distance between the server and the mobile device, the timing of requesting decryption and / or the threshold number of authorized playbacks.

[0070] For example - Return to reference Figure 2 , the server 206 may further determine to decrypt the digital content based on a detected or determined distance between the server 206 and the mobile device 204 being less than a predetermined threshold (eg, five feet).

[0071] In response to determining to decrypt the digital content, the server decrypts the digital content for transmission to the playback device at block 306. As an example - Return to reference Figure 2 In response to determining to decrypt the digital content, the server 206 decrypts the digital content for transmission to the playback device 208.

[0072] Here, the server may also include a session-based watermark in the decrypted digital content.

[0073] At block 308, the server transmits the decrypted digital content to the playback device. As an example - Return to reference Figure 2 , the server 206 transmits the decrypted digital content to the playback device 208.

[0074] Aspects of the various embodiments disclosed herein are directed to providing more flexible content protection. Unlike some DRM systems, the system according to the embodiments disclosed herein provides features related to content protection even when one or more specific trusted devices do not exist and / or are unavailable. For example, according to the various embodiments disclosed, the network 202 and the server 206 may be trusted entities relative to each other. However, from the perspective of the network 202 and / or the server 206, the playback device 208 and the mobile device 204 may not be trusted devices. For example, the playback device 208 and / or the mobile device 204 may not include any specialized components. For example, the playback device 208 and / or the mobile device 204 may not include any pre-installed keys or dedicated hardware for decrypting digital content on the server 206.

[0075] According to at least one embodiment, the mobile device 204 actually becomes a trusted device and receives keys or session information only after it has been authenticated by the network 202, for example, for a particular session. Once the session expires, re-authentication with the network 202 may be required. According to at least one further embodiment, the session information transmitted by the network 202 may also be encrypted, and the mobile device 204 need not be able to decrypt the session information. The mobile device 204 may instead act as a router or packet forwarding device that forwards the session information to the server 206 and facilitates communications between the server 206 and the network 202.

[0076] According to one or more embodiments, to allow for greater flexibility, if the user expects that the mobile device 204 will not have connectivity (e.g., connectivity to the network 202) at a time close to when the user needs to enable decryption and playback via the server 206, the user can pre-request session information at an earlier time using the mobile device 204. For example, the mobile device 204 can obtain the session information in advance, store the session information as a package, and provide the session information to the server 206 at a later time. The server 206 can recognize that the session information is stored in the pre-requested package and authorize the digital content for decryption and playback. In some aspects, when the pre-requested package is sent to the server 206, the server 206 can decrypt the digital content for playback at a maximum resolution or at a resolution reduced relative to the maximum resolution.

[0077] As previously described, in at least some embodiments, a client terminal, an encoder, a content server, a web server, or a system as described (e.g., Figure 1 System 100, Figure 2 Other aspects of the system 200 may include one or more software or hardware computer systems, and may further include (or may be operably coupled to) one or more hardware memory systems for storing information, including databases for storing, accessing, and querying various content, encoded data, shared addresses, metadata, etc. In a hardware implementation, one or more computer systems are combined with one or more computer processors and controllers.

[0078] The components of the various embodiments described herein may each include a hardware processor of one or more computer systems, and in one embodiment, a single processor may be configured to implement various components. For example, in one embodiment, an encoder, a content server, and a web server or a combination thereof may be implemented as a separate hardware system, or may be implemented as a single hardware system. The hardware system may include various temporary and non-temporary memories, wired and wireless communication receivers and transmitters, displays, and input and output interfaces and devices for storing information. The components of various computer systems, memories, and systems may be operably coupled to transfer information, and the system may also include various hardware and software communication modules, interfaces, and circuits to implement wired or wireless communications of information.

[0079] In selected embodiments, the features and aspects described herein may be found in Figure 4 , which may include one or more computer servers 601. Servers 601 may be operably coupled to one or more data stores 602 (e.g., databases, indices, files, or other data structures). Servers 601 may be connected to a data communications network 603, including a local area network (LAN), a wide area network (WAN) (e.g., the Internet), a telephone network, a satellite or wireless communications network, or some combination of these or similar networks.

[0080] One or more client devices 604, 605, 606, 607, 608 may communicate with the server 601 and a corresponding data store 602 via a data communications network 603. Such client devices 604, 605, 606, 607, 608 may include, for example, one or more laptop computers 607, desktop computers 604, smart phones and mobile phones 605, tablet computers 606, televisions 608, or combinations thereof. In operation, such client devices 604, 605, 606, 607, 608 may send data or instructions to or receive data or instructions from the server 601 in response to user input or other input received from a user input device. In response, the server 601 may provide data from the data store 602, change data within the data store 602, add data to the data store 602, etc., or a combination thereof.

[0081] In selected embodiments, server 601 may transmit one or more media files including audio and / or video content, encoded data, generated data and / or metadata from data storage 602 to one or more of client devices 604, 605, 606, 607, 608 via data communication network 603. Devices may use display screens, projectors or other display output devices to output audio and / or video content from media files. In certain embodiments, system 600 configured according to features and aspects described herein may be configured to operate within or support a cloud computing environment. For example, part or all of data storage 602 and server 601 may reside in a cloud server.

[0082] refer to Figure 5 , provides an illustration of an example computer 700. One or more of the devices 604, 605, 606, 607, 608 of the system 600 may be configured as or include such a computer 700. In addition, Figure 1 System 100 or Figure 2 One or more components of the system 200 may be configured as or include a computer 700 .

[0083] In selected embodiments, the computer 700 may include a bus 703 (or multiple buses) or other communication mechanism, a processor 701, a main memory 704, a read-only memory (ROM) 705, one or more additional storage devices 706, and / or a communication interface 702, etc. or a sub-combination thereof. The embodiments described herein may be implemented in one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), processors, controllers, microcontrollers, microprocessors, other electronic units designed to perform the functions described herein, or a selective combination thereof. In all embodiments, the various components described herein may be implemented as a single component, or alternatively may be implemented in various separate components.

[0084] The bus 703 or other communication mechanism including a plurality of such buses or mechanisms may support information communication within the computer 700. The processor 701 may be connected to the bus 703 and process information. In selected embodiments, the processor 701 may be a specialized or dedicated microprocessor configured to perform specific tasks according to the features and aspects described herein by executing machine-readable software codes defining specific tasks. A main memory 704 (e.g., a random access memory-or RAM-or other dynamic storage device) may be connected to the bus 703 and store information and instructions to be executed by the processor 701. The main memory 704 may also store temporary variables or other intermediate information during the execution of such instructions.

[0085] ROM 705 or some other static storage device may be connected to bus 703 and store static information and instructions for processor 701. Additional storage device 706 (e.g., magnetic disk, optical disk, memory card, etc.) may be connected to bus 703. Main memory 704, ROM 705, and additional storage device 706 may include non-transitory computer-readable media that store information, instructions, or some combination thereof—for example, instructions that, when executed by processor 701, cause computer 700 to perform one or more operations of the methods described herein. Communication interface 702 may also be connected to bus 703. Communication interface 702 may provide or support two-way data communication between computer 700 and one or more external devices (e.g., other devices included in the computing environment).

[0086] In selected embodiments, the computer 700 may be connected (e.g., via the bus 703) to a display 707. The display 707 may communicate information to a user of the computer 700 using any suitable mechanism. For example, the display 707 may include or utilize a liquid crystal display (LCD), a light emitting diode (LED) display, a projector, or other display device to present information to a user of the computer 700 using a visual display. One or more input devices 708 (e.g., an alphanumeric keyboard, a mouse, a microphone) may be connected to the bus 703 to communicate information and commands to the computer 700. In selected embodiments, one input device 708 may provide or support control of cursor positioning to allow for selection and execution of various objects, files, programs, etc. provided by the computer 700 and displayed by the display 707.

[0087] The computer 700 may be used to transmit, receive, decode, display one or more video files, etc. In selected embodiments, such transmission, reception, decoding, and display may be in response to the processor 701 executing one or more sequences of one or more instructions contained in the main memory 704. Such instructions may be read into the main memory 704 from another non-transitory computer-readable medium (e.g., a storage device).

[0088] Executing the sequence of instructions contained in the main memory 704 may cause the processor 701 to perform one or more of the processes or steps described herein. In selected embodiments, one or more processors in a multi-processing arrangement may also be employed to execute the sequence of instructions contained in the main memory 704. Alternatively or in addition, firmware may replace or be combined with software instructions to implement the processes or steps according to the features and aspects described herein. Therefore, embodiments according to the features and aspects described herein may not be limited to any specific combination of hardware circuitry and software.

[0089] Non-transitory computer-readable media may refer to any medium that participates in preserving instructions for execution by the processor 701 or storing data for computer processing and includes all computer-readable media, with the sole exception of temporary propagation signals. Such non-transitory computer-readable media may include, but are not limited to, non-volatile media, volatile media, and temporary storage media (e.g., cache memory). Non-volatile media may include optical or magnetic disks, such as attached storage devices. Volatile media may include dynamic memory, such as main memory. Common forms of non-transitory computer-readable media may include, for example, hard disks, floppy disks, tapes or any other magnetic media, CD-ROMs, DVDs, Blu-ray or other optical media, RAMs, PROMs, EPROMs, FLASH-EPROMs, any other memory cards, chips or cassettes, or any other memory media from which a computer can read.

[0090] In selected embodiments, the communication interface 702 may provide or support external two-way data communications with or via a network link. For example, the communication interface 702 may be a wireless network interface controller or a cellular radio device that provides a data communication network connection. Alternatively, the communication interface 702 may include a LAN card that provides a data communication connection with a compatible LAN. In any such embodiment, the communication interface 702 may send and receive electrical, electromagnetic or optical signals that convey information.

[0091] The network link may provide data communications to other data devices (e.g., client devices as shown in computing system 600) through one or more networks. For example, the network link may provide a connection through a local network of a host computer, or provide a connection to data equipment operated by an Internet Service Provider (ISP). The ISP may, in turn, provide data communications services through the Internet. Thus, computer 700 may send and receive commands, data, or a combination thereof, including program code, through one or more networks, network links, and communications interface 702. Thus, computer 700 may interface with or otherwise communicate with a remote server (e.g., server 601), or some combination thereof.

[0092] As discussed above, the various devices, modules, terminals, etc. described herein can be implemented on a computer by executing software including machine instructions read from a computer-readable medium. In some embodiments, a single computer can be used to implement several hardware aspects; in other embodiments, multiple computers, input / output systems, and hardware can be used to implement the system.

[0093] For software implementation, some embodiments described herein can be implemented using separate software modules such as processes and functions, each of which performs one or more of the functions and operations described herein. The software codes can be implemented using a software application written in any appropriate programming language and can be stored in a memory and executed by a controller or processor.

[0094] The embodiments and features described above are merely exemplary and are not to be construed as limiting the present invention. This teaching can be easily applied to other types of equipment and processes. The description of such embodiments is intended to illustrate, rather than limit the scope of the claims. Many alternatives, modifications, and variations will be apparent to those skilled in the art.

Claims

1. A method for controlling the transmission of digital content stored at a server, the method comprising: receiving, at the server, session information from a device, the session information including information for authorizing the server to decrypt the digital content for transmission to a playback device; Based on the session information, determining at the server to decrypt the digital content for transmission to the playback device; In response to determining to decrypt the digital content, decrypting at the server the digital content for transmission to the playback device; as well as transmitting the decrypted digital content to the playback device at the server, Wherein, transmitting the decrypted digital content to the playback device includes: configuring aspects of playback of the decrypted digital content at the playback device based on a distance between the server and the device.

2. The method of claim 1, wherein: Without determining to decrypt the digital content based on the session information, the server lacks the ability to authenticate the playback device as an authentic device.

3. The method of claim 1, wherein: The session information includes one or more decryption keys or authentication keys; and Determining to decrypt the digital content includes determining to decrypt the digital content based on the one or more decryption keys or authentication keys.

4. The method of claim 1, wherein determining to decrypt the digital content further comprises: The determination to decrypt the digital content is further based on at least one of a distance between the server and the device, a timing of requesting the decryption, or a threshold number of authorized plays.

5. The method of claim 1, wherein decrypting the digital content further comprises: A session-based watermark is included in the decrypted digital content before transmitting the decrypted digital content to the playback device. The method of claim 1 , wherein the aspect of the playback comprises a video resolution or an audio volume of the playback.

7. The method of claim 6, wherein configuring the aspects of the playback comprises: When it is determined that the distance between the server and the device has increased, the audio volume or the video resolution of the playback is reduced.

8. The method of claim 1, wherein the device comprises a mobile phone.

9. The method of claim 1, wherein the playback device comprises a movie projector.

10. A device for controlling the transmission of stored digital content, the device comprising: a network communication unit configured to transmit and receive data; as well as One or more controllers, configured to: receiving session information from a device, the session information including information for authorizing the device to decrypt the digital content for transmission to a playback device; Based on the session information, determining to decrypt the digital content for transmission to the playback device; In response to determining to decrypt the digital content, decrypting the digital content for transmission to the playback device; as well as transmitting the decrypted digital content to the playback device, Wherein the one or more controllers are further configured to transmit the decrypted digital content to the playback device by configuring aspects of playback of the decrypted digital content at the playback device based on a distance between the device and the apparatus.

11. The device according to claim 10, in, Without determining to decrypt the digital content based on the session information, the device lacks the ability to authenticate the playback device as an authentic device.

12. The apparatus of claim 10, wherein: The session information includes one or more decryption keys or authentication keys; and The one or more controllers are further configured to determine to decrypt the digital content based on the one or more decryption keys or authentication keys.

13. The device according to claim 10, The one or more controllers are further configured to determine to decrypt the digital content based further on at least one of a distance between the device and the apparatus, a timing of requesting the decryption, or a threshold number of authorized plays.

14. The apparatus of claim 10, wherein the one or more controllers are further configured to include a session-based watermark in the decrypted digital content prior to transmitting the decrypted digital content to the playback device.

15. The device of claim 10, wherein the aspect of the playback comprises a video resolution or an audio volume of the playback.

16. The device of claim 15, wherein the one or more controllers are further configured to configure the aspect of the playback by reducing the audio volume or the video resolution of the playback when it is determined that the distance between the device and the apparatus has increased.

17. The apparatus of claim 10, wherein: The device comprises a mobile phone; and The playback device comprises a movie projector.

18. A machine-readable non-transitory medium having stored thereon machine-executable instructions for controlling the transmission of digital content stored at a server, the instructions comprising: receiving, at the server, session information from a device, the session information including information for authorizing the server to decrypt the digital content for transmission to a playback device; Based on the session information, determining at the server to decrypt the digital content for transmission to the playback device; In response to determining to decrypt the digital content, decrypting at the server the digital content for transmission to the playback device; as well as The decrypted digital content is transmitted at the server to the playback device.

19. A method for controlling the transmission of digital content stored at a server, the method comprising: transmitting, at the device, a request to a network, the request requesting permission to play the digital content, the request including credential information identifying a user as a party or entity authorized to access the digital content; receiving, at the device, session information from the network based on the request, the session information including information for authorizing the server to decrypt the digital content for transmission to a playback device; as well as at the device, transmitting the session information to the server, Wherein, without transmitting the session information to the server, the server lacks the ability to verify the playback device as a trusted device.

Citation Information

Patent Citations

  • Digital cinema system hub multiple exhibitor distribution

    US20030204851A1

  • Method for acquiring access rights to conditional access content

    US20140258531A1