Managing permissions for different wireless devices to control a common host device

By establishing permission level management and encrypted communication channels between the set-top box and wireless devices, the issues of set-top box security and operational flexibility are resolved, achieving secure and flexible permission management.

CN113630770BActive Publication Date: 2026-03-20APPLE INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2018-01-08
Publication Date
2026-03-20

AI Technical Summary

Technical Problem

In the prior art, the security issues of set-top boxes and wireless devices increase with the complexity of the devices, and it is difficult to effectively manage the licenses of different wireless devices to ensure security and the expected functional operation.

Method used

When establishing a wireless connection between a host device and a wireless device, different permissions are granted according to the different permission levels of the devices, and a secure communication channel is established through encryption technology to suppress the leakage of sensitive information and achieve anonymity and security.

Benefits of technology

It enables flexible management of permissions for different wireless devices while maintaining security, thereby enhancing the overall security and operational flexibility of the set-top box.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113630770B_ABST
    Figure CN113630770B_ABST
Patent Text Reader

Abstract

Disclosed herein are techniques for managing permissions of different wireless devices to control a common host device. More specifically, disclosed is a technique for managing permissions associated with control of a host device provided to a group of wireless devices. The host device is configured to pair with a first wireless device. In response to pairing with the first wireless device, the host device grants the first wireless device a first permission level for controlling the host device. Subsequently, the host device can receive a second request from a second wireless device to pair with the host device. In response to pairing with the second wireless device, the host device can grant the second wireless device a second permission level for controlling the host device, where the second permission level is different from the first permission level.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of Chinese Patent Application No. 201880006916.4, filed January 8, 2018, entitled “Managing Permissions of Different Wireless Devices to Control a Common Host Device.” TECHNICAL FIELD

[0002] Embodiments described herein set forth techniques for managing permissions associated with control of a host device (e.g., a set-top box) provided to a group of wireless devices. BACKGROUND

[0003] Wireless devices (e.g., smartphones, tablets, wearable devices, etc.) are often used to broadcast content to an auxiliary display (e.g., a “smart” television) or a set-top box connected to such an auxiliary display. A common use case scenario involves a user loading a slide presentation onto their smartphone, using a web-based interface to connect their smartphone to a set-top box, and then causing the smartphone to output the slide presentation to the auxiliary display (e.g., through the set-top box). One example of a web-based interface includes of This enables portable computing devices (e.g., iOS-based devices like ) equipped with to play content to components equipped with (e.g. ).

[0004] In most cases, the owner of a set-top box can allow different wireless devices to wirelessly broadcast content to the set-top box without worrying about the overall security of the set-top box’s operation. However, as set-top boxes and wireless devices become more complex—and additional functionality is developed that enables wireless devices to control set-top boxes in new and enhanced ways—security concerns will also increase. In this regard, it is desirable to limit permissions assigned to some wireless devices while increasing permissions assigned to other wireless devices to ensure that the set-top box operates in a secure and intended manner. SUMMARY

[0005] Accordingly, representative embodiments set forth herein disclose various techniques for managing permissions to control a host device (e.g., a set-top box), where different permissions can be assigned to different wireless device / user accounts associated with different wireless devices.

[0006] One embodiment sets forth a method implemented by a host device for managing permissions associated with control of the host device by different wireless devices. According to some embodiments, the host device receives a first request from a first wireless device to wirelessly pair with the host device. In response to the first request, the host device can establish a first wireless connection with the first wireless device (i.e., pair with it). In conjunction with establishing the first wireless connection, the host device can grant the first wireless device a first permission level for controlling the host. Subsequently, the host device can receive a second request from a second wireless device to wirelessly pair with the host device. In response to the second request, the host device can establish a second wireless connection with the second wireless device. In conjunction with establishing the second wireless connection, the host device can grant the second wireless device a second permission level for controlling the host device, where the second permission level is different than the first permission level.

[0007] Another embodiment sets forth a method for establishing a secure communication channel between a host device and a wireless device while facilitating anonymity of the wireless device. According to some embodiments, the method involves the host device receiving a request from the wireless device to wirelessly pair with the host device. In response to the request, the host device can establish a wireless connection with the wireless device. The method can further include the host device receiving from the wireless device: i) a first message encrypted with a private key associated with the wireless device, and ii) a corresponding public key corresponding to the private key. The host device can store the public key in a public key depository (received from / associated with other wireless devices). Subsequently, the host device can receive a second message from the wireless device, where the second message is also encrypted with the private key but does not include identifying information associated with the wireless device (e.g., the public key, a unique identifier associated with the wireless device, etc.). The host device can then determine that the second message is associated with the wireless device by: i) attempting to perform decryption of the second message using each public key in the public key depository, and ii) identifying the public key that successfully decrypts the second message. In this manner, the host device and the wireless device can establish a secure connection while suppressing information about the wireless device that might otherwise be obtained through snooping / malicious devices, thereby enhancing overall security.

[0008] Other embodiments include a non-transitory computer-readable storage medium configured to store instructions that, when executed by a processor included in a computing device, cause the computing device to perform the steps of any of the above-described methods. Additional embodiments include a computing device configured to perform the various steps of any of the aforementioned methods.

[0009] Other aspects and advantages of the present application will become apparent from the following detailed description, taken in conjunction with the accompanying drawings, which illustrate, by way of example, the principles of the embodiments described herein. BRIEF DESCRIPTION OF DRAWINGS

[0010] The present disclosure will be more readily understood with reference to the following, detailed description taken in conjunction with the accompanying drawings, in which like reference numerals refer to like elements in the several figures.

[0011] Figure 1 A system including different computing devices that can be configured to perform the various techniques described herein is shown in accordance with some embodiments.

[0012] Figure 2A A conceptual diagram of a mobile device pairing with a set-top box is shown in accordance with some embodiments.

[0013] Figure 2B A method for enabling a set-top box to pair with a wireless device and manage permissions assigned to the wireless device associated with controlling the set-top box is shown in accordance with some embodiments.

[0014] Figure 2C A method for establishing a trusted connection between a set-top box and a wireless device while facilitating anonymity of the wireless device is shown in accordance with some embodiments.

[0015] Figure 3A A conceptual diagram of a wireless device granting another wireless device to unlock a set-top box is shown in accordance with some embodiments.

[0016] Figure 3B A method for granting a wireless device to perform a particular function (associated with a set-top box) that is not currently allowed to be performed by the wireless device is shown in accordance with some embodiments.

[0017] Figure 4A A conceptual diagram of a wireless device purchasing a content item in conjunction with a set-top box is shown in accordance with some embodiments.

[0018] Figure 4B A method for a wireless device to purchase a content item through a set-top box is shown in accordance with some embodiments.

[0019] Figure 5A A conceptual diagram of a mobile device causing a set-top box to perform different functions in accordance with permissions assigned to the mobile device is shown in accordance with some embodiments.

[0020] Figure 5B A method involving a mobile device causing a set-top box to perform different functions in accordance with permissions assigned to the mobile device is shown in accordance with some embodiments.

[0021] Figures 6A-6B A method for automatically establishing a privilege level of a wireless device based on an initial pairing and / or operation performed in conjunction with the wireless device is shown in accordance with some embodiments.

[0022] Figure 7Detailed views of a computing device that can be used in implementing the various techniques described herein in accordance with some embodiments are shown. DETAILED DESCRIPTION

[0023] Representative applications of methods and apparatuses according to this application are described in this section. These examples are being provided solely to add context and aid in the understanding of the described embodiments. It will thus be apparent to one skilled in the art that the described embodiments can be practiced without some or all of these specific details. In other instances, well known process steps have not been described in detail in order to avoid

[0024] In the following detailed description, references are made to the accompanying drawings that form a part hereof, and in which are shown by way of illustration specific embodiments in accordance with the described embodiments. While these embodiments are described in sufficient detail to enable those skilled in the art to practice the described embodiments, it should be understood that these examples are not limiting, and that other embodiments can be used, and that

[0025] The representative embodiments described herein set forth techniques for managing permissions assigned to wireless devices for controlling host devices. According to some embodiments, a host device can be configured to communicate with any number of wireless devices through a direct connection (e.g., a local wireless connection or a local wired connection) or through an indirect connection (e.g., the Internet). One example of a direct connection scenario can involve a host device receiving a request from a wireless device to establish a wireless connection between the host device and the wireless device. Once the wireless connection is established, the host device can grant permissions to the wireless device specifying how the wireless device can control the host device. For example, a wireless device can be granted a default permission upon successfully pairing with a host device, where the default permission enables the wireless device to stream content to the host device and remotely navigate a user interface (UI) of the host device. In another example, a wireless device can be granted a management permission, where the management permission allows the wireless device to cause the host device to perform enhanced activities (e.g., manage permissions associated with other wireless devices, authorize payments, unlock the host device for operation, approve content for playback at the host device, etc.). As additional wireless devices pair with the host device, the host device can grant additional permissions to these wireless devices, and can add or subtract these permissions according to selections made by a user account / wireless device with a management level permission.

[0026] The representative embodiments described herein also propose a technique for enabling a host device to establish a secure connection with a wireless device in a manner that promotes anonymity to enhance overall security. According to some embodiments, the host device may receive a request to establish a secure connection with a wireless device. To establish a secure connection, the wireless device, for example during an initial pairing process, provides i) a first message to the host device, wherein the first message is encrypted with a private key owned by the wireless device, and ii) the corresponding public key of the private key. The host device may then store the public key in a public key store (associated with different wireless devices previously paired with the host device). Subsequently—for example, when the wireless device later returns to the vicinity of the host device—the wireless device provides a second message to the host device, wherein the second message is also encrypted with the private key, but does not include information associated with the wireless device that uniquely identifies the wireless device (e.g., public key, software-based / hardware-based unique identifier, etc.). The host device may then determine that the second message is associated with the first wireless device by i) attempting to decrypt the second message using each public key in the public key store, and ii) identifying the public key that successfully decrypted the second message. In this way, host devices and wireless devices can establish secure connections while suppressing identification information of wireless devices that might otherwise be obtained through snooping / malicious devices, thereby enhancing overall security.

[0027] Therefore, the techniques described in this paper enable a highly flexible environment in which licenses associated with the set-top box and assigned to various wireless devices can be modified to provide the intended functionality while maintaining security. The following section combines... Figures 1-7 More detailed descriptions of these hardware components are provided.

[0028] Figure 1 A system 100 is shown that can be configured to perform the various technologies described herein. For example... Figure 1 As shown, system 100 includes a display device 102, a set-top box 104, a mobile device 106, a tablet device 108, and a wearable device 110. It should be noted that throughout this disclosure, each of the mobile device 106, tablet device 108, and wearable device 110 is collectively referred to herein as a "wireless device." Furthermore, it should be noted that throughout this disclosure, the terms "host device" and "set-top box" are used interchangeably to describe any computing device that manages licenses allocated to various wireless devices for controlling computing devices.

[0029] like Figure 1As shown, the set-top box 104 can be a standalone device. However, it should be appreciated that the set-top box 104 can also be integrated into another device, such as the display device 102. The display device 102 can be any conventional display device, such as a monitor, a television, etc. The display device 102 can be communicatively connected to the set-top box 104 using any suitable communication protocol, whether through a wired connection or a wireless connection. According to some embodiments, the display device 102 can be configured to interface with the set-top box 104 and display a user interface (UI) generated by the set-top box 104 and provided to the display device 102. The display device 102 displays content generated at the set-top box 104.

[0030] According to some embodiments, each of the set-top box 104, the mobile device 106, the tablet device 108, and the wearable device 110 are configured to execute respective software applications that enable these devices to perform the various techniques described herein. For example, the mobile device 106, the tablet device 108, and the wearable device 110 can be configured to execute a software application (e.g., Apple TV Remote), which enables these wireless devices to remotely navigate a user interface of a software application (e.g., an operating system (OS)) executing on the set-top box 104 (e.g., Apple TV). Moreover, each of the wireless devices can be configured to allow home automation technology. For example, the mobile device 106 can be configured to control external devices associated with the set-top box 104 through a home automation network (e.g., Apple's HomeKit). Notably, although not shown in FIG. 1, it can be appreciated that these computing devices can include various hardware components that enable the execution of the respective applications. For example, these devices can include at least one storage device (e.g., a solid state drive, a hard disk drive, etc.), at least one processor (e.g., a multi-core central processing unit (CPU)), and at least one memory (e.g., a random access memory (RAM)) that can execute an OS, where the OS can be configured to load / execute different applications. Figure 1

[0031] ​​​​According to some embodiments, and as previously described, the set-top box 104 can be configured to grant a wireless device (e.g., one of the mobile device 106, the tablet device 108, or the wearable device 110) specific permissions that allow the wireless device to control different functions provided by the set-top box 104. For example, the specific permissions that can be granted to the wireless device can include, but are not limited to, streaming content to the set-top box 104, paying for content (e.g., movies, television shows, music, etc.) accessible to the set-top box 104, navigating a user interface of the set-top box 104, accessing parental controls of the set-top box 104, changing configuration settings of the set-top box 104, unlocking the set-top box 104, etc. In some embodiments, unlocking the set-top box 104 can enable a user operating the wireless device to access a specific set of functions provided by the set-top box 104. More specifically, when the set-top box 104 is locked and the wireless device is not assigned permissions to unlock the set-top box 104, certain functions of the set-top box 104 can be denied to the wireless device. However, in some embodiments, certain functions of the set-top box 104 (e.g., default low-security functions) can be accessible to the wireless device without unlocking the set-top box 104. For example, all wireless devices can be allowed to stream content to the set-top box 104 without unlocking the set-top box 104.

[0032] Additionally, the set-top box 104 can be configured to grant functionality to paired wireless devices according to a user account associated with (e.g., logged into) the set-top box 104. According to some embodiments, the user account can be associated with user account-specific payment information, configuration settings, parental controls, encryption operation information (e.g., keys used to encrypt / decrypt messages), etc. According to some embodiments, the set-top box 104 can grant permission to a wireless device currently paired with the set-top box 104 to utilize one or more functionalities associated with a particular user account at the direction of an administrator. For example, consider a scenario in which a parent's user account is currently logged into the set-top box 104, where the user account is associated with the parent's payment credentials (e.g., a family credit card). In this case, the set-top box 104 can grant permission to a child to use the parent's user account (i.e., payment credentials associated therewith) to purchase a movie with the parent's permission. In another case, the set-top box 104 can provide functionality permitted to a parent when the parent unlocks the set-top box 104 using biometric authentication (e.g., locally or remotely from the set-top box 104 via a wireless device) when another user (e.g., a child) is operating the set-top box 104. In this way, a child can gain access to parent user account-specific functionality, where these functionalities can be removed at the discretion of the parent. In another case, several members of a family can use the set-top box 104 when the parent's user account is logged into the set-top box 104. In this example, if the family is performing a movie search query, a drop-down menu or keyboard (allowed according to permissions assigned to the parent's user account) can be provided by the set-top box 104 to each paired wireless device to allow different family members to provide input. In this way, each family member can have access to the same functionality accessible through the parent's user account. Furthermore, because each of these functionalities can be provided according to a single user account, each device interacting with the set-top box 104 can do so using cryptographic information (e.g., encryption signatures) associated with the user account.

[0033] It should be noted that the implementation described herein involves associating different license levels with different wireless devices. However, it should also be noted that such licenses can be specifically associated with a user / user account configured on / associated with a wireless device to enhance the overall flexibility of system 100. For example, a specific user can be associated with each of mobile device 106, tablet device 108, and wearable device 110 through a public user account (e.g., a username / password combination associated with a cloud service). By using a public account, multiple wireless devices can share passwords (e.g., via iCloud Keychain), share encryption information (e.g., share encryption keys), share payment information (e.g., via Apple Pay), etc. In this example, when a user pairs mobile device 106 with set-top box 104 and receives a first license level (either as a result of pairing or by being granted enhanced licenses by an administrator), these licenses are associated with the user account, not with the wireless device used to perform the function. In this way, allowing a user to access the same functionality of set-top box 104 from his / her different wireless devices can enhance the overall user experience.

[0034] In addition, although not in Figure 1 As shown, but to be understood, mobile device 106, tablet device 108, and wearable device 110 are merely examples of computing devices that can be configured to interface with set-top box 104. Additionally, it should be noted that although the different computing devices discussed herein... Figure 1 The terms are shown in the singular, but the embodiments described herein are not limited thereto. For example, system 100 may include a plurality of display devices 102, set-top boxes 104, mobile devices 106, tablet devices 108, wearable devices 110, etc., configured to implement the techniques described herein.

[0035] therefore, Figure 1 Example system 100 is described, which includes various computing devices configured to perform the various techniques described herein. The following is in conjunction with... Figures 2A-2C 3A-3B, 4A-4B, and 5A-5B provide more detailed descriptions of these various technologies.

[0036] Figure 2A A conceptual diagram 200 illustrates a mobile device 106-0 paired with a set-top box 104 according to some embodiments. According to some embodiments, when the mobile device 106-0 establishes a direct communication channel with the set-top box 104 (e.g., via...), When within range of Wi-Fi, Near Field Communication (NFC), etc., the mobile device 106-0 and / or set-top box 104 can initiate a pairing process. According to some implementations, the pairing process may involve... Figure 2CThe techniques shown and described in more detail below form a secure communication channel.

[0037] In some implementations, set-top box 104 can be configured to authenticate mobile device 106-0 before pairing with it. For example, authentication can be performed to ensure that the operator of mobile device 106-0 is near set-top box 104 and / or has access to display device 102 to which set-top box 104 is connected. For example, set-top box 104 can, according to… Figure 2A User interfaces 202 and 204, as depicted, require a PIN number displayed on display device 102 to be entered into mobile device 106-0 to verify mobile device 106-0. According to some embodiments, the PIN number may be randomly generated by set-top box 104 and displayed via display device 102. For example, as... Figure 2A As shown, when the PIN number "1838" (displayed on display device 102) is successfully entered at mobile device 106-0 and provided to set-top box 104, set-top box 104 can authenticate mobile device 106-0. In some embodiments, the randomly generated PIN number used to authenticate mobile device 106-0 can be used as a seed to securely establish a secure communication channel between set-top box 104 and mobile device 106-0. It should be noted that other forms of authentication can be used to carry the functionality provided herein. For example, biometric authentication (e.g., facial recognition, iris recognition, fingerprint recognition, etc.) can be used to replace or supplement the PIN-based technologies described above.

[0038] Once mobile device 106-0 is paired with set-top box 104, a specific license level can be granted to mobile device 106-0 / the user account associated with mobile device 106-0. According to some implementations, the license level refers to a dynamic set of licenses for controlling the functions of set-top box 104, wherein the dynamic license set can be modified by set-top box 104 and / or a wireless device known to set-top box 104 (e.g., with administrative privileges), as described in more detail herein. In one example, upon pairing with set-top box 104, mobile device 106-0 can be granted a license level that allows mobile device 106-0 to control a limited number of functions provided by set-top box 104. See references... Figures 3A-3B As described, an additional license level can be granted to the mobile device 106-0 to increase the level of functionality that the set-top box 104 can perform when paired with the mobile device 106-0.

[0039] It is worth noting, and according to some implementations, mobile device 106-0 does not need to be paired with set-top box 104 before set-top box 104 grants a license level to mobile device 106-0. Specifically, and according to some implementations, the license for mobile device 106 can be pre-assigned before pairing with set-top box 104. In one example, a known administrator of set-top box 104 (e.g., a parent in the household) can refer to mobile devices 106 linked to the parent (e.g., via a different user account associated with the parent / mobile device 106) and specify the license level automatically assigned to mobile device 106 when they are eventually paired with set-top box 104. For example, when a child pairs his / her mobile device 106-0 with set-top box 104, mobile device 106-0 can be allowed to view previously purchased content based on the prior license chosen by the child's parents, but new content purchases / rentals can be restricted. In this way, licenses can be flexibly assigned within the household without requiring prior pairing of all mobile devices 106, which could otherwise be inconvenient.

[0040] Figure 2B A method 250, according to some embodiments, is shown for enabling a set-top box 104 to pair with wireless devices and manage licenses assigned to wireless devices associated with controlling the set-top box 104. Figure 2B As shown, method 250 begins at step 252, where set-top box 104 receives an initial request to enter pairing mode. In some embodiments, the initial request to enter pairing mode can be initiated via remote control of set-top box 104 (e.g., a setup UI for navigating set-top box 104), via a wireless device capable of communicating with set-top box 104 (e.g., via a direct or indirect connection), etc. In step 254, set-top box 104 receives a first request from a first wireless device to pair with set-top box 104. In response, in step 256, set-top box 104 can establish a first wireless connection, i.e., pair with a first wireless device, for example, via Bluetooth, NFC, etc.

[0041] In response to the first wireless device successfully pairing with the set-top box 104, at step 258, the set-top box 104 can grant the first wireless device a first permission level for controlling the set-top box 104. In one example, the pairing between the first wireless device and the set-top box 104 can be performed during initial setup of the set-top box 104. To further illustrate this example, the set-top box 104 can consider the first wireless device to be an administrator because the pairing occurred during initial setup of the set-top box 104, or because the first wireless device is the first (i.e., only) wireless device to pair with the set-top box 104. In one example, the first permission level can include authorization to make payments, unlock the set-top box 104 for operation, approve content (e.g., video, audio, or other media) for playback at the set-top box 104, change parental controls, change configuration settings, access confidential information (e.g., financial information), and so forth. In another example, the first wireless device as an administrator gains the authority to assign specific permissions to wireless devices that subsequently become known to the set-top box 104. For instance, a first wireless device / user account associated with the first wireless device can be permitted to assign administrative authority to some wireless devices that become known to the set-top box 104, or to assign more restrictive privileges to other wireless devices that become known to the set-top box 104.

[0042] For instance, at step 260, the set-top box 104 receives a second request from a second wireless device to pair with the set-top box 104. In response, at step 262, the set-top box 104 can establish a second wireless connection with the second wireless device. In conjunction with establishing the second wireless connection, at step 264, the set-top box 104 can grant the second wireless device a second permission level for controlling the set-top box 104. In some embodiments, the second permission level is different from the first permission level, e.g., based on instructions received from the first wireless device, based on settings of the set-top box 104 (e.g., automatically assigning limited permissions to all secondary wireless devices), and so forth.

[0043] According to some embodiments, the second permission level that can be granted by the set-top box 104 is associated with functions of the set-top box 104 that do not pose a significant risk of compromising the security of the set-top box 104. The second permission level can include, for instance, allowing the second wireless device to stream content to the set-top box 104. After the initial pairing and granting of the second permission level, an administrator known to the set-top box 104 (e.g., associated with the first wireless device according to the foregoing example) can grant the second wireless device an additional permission level. For instance, to enable the second wireless device to rent content through the set-top box 104, the second wireless device can need a higher permission level. In some embodiments, the set-top box 104 can query the administrator (or other administrator) for approval to assign the higher permission level to the second wireless device, as described in further detail below. Figure 3A ​

[0044] Figure 2C A method 270 for establishing a trusted connection between a set-top box 104 and a wireless device while facilitating anonymity of the wireless device is shown in accordance with some embodiments. As shown, the method 270 begins at step 272, where the set-top box 104 establishes a first wireless connection with a first wireless device. In some embodiments, the first wireless connection occurs during an initial pairing, e.g., when the first wireless device and the set-top box 104 are first paired. During this initial pairing, a randomly generated PIN number can be used to authenticate the first wireless device (e.g., as described above in connection with FIG. 2). Moreover, and as previously described, the randomly generated PIN number used to authenticate the first wireless device can be used as a seed to cryptographically establish a secure communication channel between the set-top box 104 and the first wireless device. In this manner, subsequent messages communicated between the set-top box 104 and the first wireless device, e.g., those described below in connection with steps 274-282, can be transmitted over the secure communication channel. Figure 2C Figure 2A

[0045] At step 274, the set-top box 104 receives a first message encrypted with a private key from the first wireless device over the secure communication channel. In some embodiments, the first wireless device encrypts the first message according to a public key encryption scheme. For example, the first wireless device can encrypt the first message using a private key that is only possessed by the first wireless device. Thereafter, the first message can be transmitted over the secure communication channel with the respective public key (for the private key) attached, which the set-top box 104 can use to decrypt the first message without exposing the private key to the set-top box 104.

[0046] At step 276, the set-top box 104 can store the public key in a public key depository (e.g., in a storage device accessible to the set-top box 104). According to some embodiments, the public key depository can include each public key previously and currently shared with the set-top box 104, e.g., different public keys provided to the set-top box 104 during pairing processes with other wireless devices. In some embodiments, the set-top box 104 can selectively store public keys of wireless devices that have successfully paired with the set-top box 104, while ignoring public keys of wireless devices that have not successfully paired with the set-top box 104, thereby improving overall efficiency.

[0047] ​​At step 278, the set-top box 104 receives a second message from the first wireless device, where the second message is encrypted with the private key. According to some embodiments, the second message can be provided by the first wireless device at a subsequent time, e.g., after the first wireless device disconnects from the set-top box 104 (e.g., when the user leaves his / her house), and then attempts to reconnect to the set-top box 104 (e.g., when the user returns home). In some embodiments, the second message is sent from the first wireless device to the set-top box 104 without identifying information associated with the first wireless device, e.g., a public key associated with the first wireless device, a unique identifier associated with the first wireless device (e.g., a serial number of the first wireless device, a unique ID of a user account associated with the first wireless device, etc.). In this way, the second message lacks identifying information that can otherwise be used to track messages sent from the first wireless device, e.g., a malicious device attempting to snoop on input / output communications associated with the set-top box 104.

[0048] At step 280, the set-top box 104 attempts to decrypt the second message using each public key in the public key depository to identify a public key that successfully decrypts the second message. More specifically, any public key that does not correspond to the private key used to encrypt the second message fails to successfully decrypt the second message, which effectively enables the set-top box 104 to identify the appropriate corresponding public key - and, transitively, the first wireless device - by a process of elimination. Thus, when the set-top box 104 identifies a public key that successfully decrypts the second message, the set-top box 104 can then associate the second message with the wireless device that originally provided the identified public key, which is performed at step 282.

[0049] Thus, Figure 2C A technique is provided that enables a wireless device to establish a secure communication channel with the set-top box 104 without revealing sensitive information about the wireless device that can be collected by a snooping / malicious device. Again, to achieve this beneficial effect, the set-top box 104 receives a message from a wireless device that is encrypted with a private key, and attempts to decrypt the encrypted message with different public keys (that were retained by the set-top box 104 during initial pairing) to identify whether the set-top box 104 knows the wireless device. By using this approach, when the set-top box 104 is able to decrypt the encrypted message using a particular public key, the wireless device can be identified based on the particular public key and authenticated. Conversely, when the set-top box 104 is unable to decrypt the message, the wireless device cannot be identified and is not authenticated.

[0050] Thus, Figure 1 and 2A -2C sets forth embodiments in which the set-top box 104 is able to pair with multiple wireless devices and manage permissions associated with those wireless devices. The following discussion is made in connection with Figures 3A-3BFIGS. 4A-4B and 5A-5B provide more detailed breakdowns and various examples of how these permissions can be managed.

[0051] Figure 3A A conceptual diagram 300 of a wireless device granting permission to another wireless device to unlock a set-top box 104 is shown in accordance with some embodiments. As shown, a mobile device 106-1 that is currently paired with the set-top box 104 is attempting to unlock the set-top box 104. As previously set forth herein, the mobile device 106-1 is granted a basic level of permission by the set-top box 104 to interface with the set-top box 104 (e.g., stream content to the set-top box 104). However, the basic level of permission can exclude other functions, such as unlocking the set-top box 104 to navigate a user interface provided by the set-top box 104. To address this deficiency, when the mobile device 106-1 attempts to access the prohibited function, the set-top box 104 can be configured to identify a wireless device associated with a management privilege and forward the request to the wireless device to authorize the attempt, which will be described below in connection with steps 1-3 shown in FIG. 3. Figure 3A Figure 3A

[0052] As depicted in step 1, the mobile device 106-1 displays a user interface that depicts various functions that the mobile device 106-1 can request the set-top box 104 to perform, including a function 302 to "unlock set-top box." In the example shown, the mobile device 106-1 is associated with a basic level of permission. According to some examples, the mobile device 106-1 receives the basic level of permission by pairing with the set-top box 104 (e.g., during initial setup of the set-top box 104) or by receiving an assignment of the basic level of permission from another wireless device / user account that has a sufficient level of permission to grant the mobile device 106-1 the basic level of permission. Figure 3A

[0053] ​​​As shown in step 2, mobile device 106-1 requests to unlock set-top box 104 by selecting "Unlock Set-Top Box" function 302. In response, a message 304 reading "Requesting permission to unlock set-top box" can be displayed while the user of mobile device 106-1 waits for an administrator to grant permission to unlock set-top box 104. In response to the request from mobile device 106-1, set-top box 104 can notify mobile device 106-2 that mobile device 106-1 is requesting permission to unlock set-top box 104. Again, this can involve set-top box 104 identifying mobile device 106-2 as being associated with administrator-level permissions and forwarding the request to mobile device 106-2, and / or other wireless devices associated with administrator-level permissions (or sufficient to grant the requested permission to unlock set-top box 104).

[0054] In some cases, when mobile device 106-1 makes the request to set-top box 104, the administrator (e.g., mobile device 106-2) can not currently be communicably coupled with set-top box 104 through a direct connection. To address this deficiency, set-top box 104 can query mobile device 106-2 for permission through an indirect communication channel (e.g., the Internet). In one example interface 310, mobile device 106-2 can present an indication reading "Karen's device wants to unlock set-top box," where "Karen's device" corresponds to mobile device 106-1, and user interface elements enabling the user to operate mobile device 106-2 to respond to the request. In response to receiving the request to unlock set-top box 104, using graphical user interface elements 312 (i.e., "Allow") and 314 (i.e., "Deny"), the administrator can decide whether to allow the request from "Karen's device" to unlock set-top box 104 or deny the request to unlock set-top box 104.

[0055] According to some embodiments, mobile device 106-2 can employ various security prompts to help ensure that an authorized user is operating mobile device 106-2. For example, mobile device 106-2 can require input of security credentials (e.g., password data, biometric data, etc.) in response to the user accepting or denying the request at mobile device 106-2. In this way, a malicious user operating mobile device 106-1 (as well as a person with access to mobile device 106-2 (e.g., a left-behind mobile device)) cannot simply click an "Accept" button on mobile device 106-2 when attempting to unlock set-top box 104 from mobile device 106-1. Rather, the malicious user would also need to be able to provide the security credentials required by mobile device 106-2, which he / she is unlikely to be able to do.

[0056] At step 3, mobile device 106-2 grants the request to unlock set-top box 104 (e.g., as shown by element 316 in FIG. 3). In accordance with some embodiments, in response to mobile device 106-2 granting the request, set-top box 104 can grant mobile device 106-1 the necessary permissions for unlocking set-top box 104. In some embodiments, such permissions can be granted on a "one-time" basis. For example, when permissions are granted on a "one-time" basis, and mobile device 106-1 is unpaired from set-top box 104, the permissions can be automatically revoked from mobile device 106-1, e.g., by updating the permissions configuration managed by set-top box 104. In another example, when permissions are granted on a "one-time" basis, the permissions are automatically revoked after mobile device 106-1 issues a request to unlock set-top box 104. Alternatively, in other embodiments, when permissions are granted, the permissions can remain valid until one or more conditions are met. For example, a condition can require that the permissions from mobile device 106-1 be manually revoked by an administrator. In another example, a condition can be a time-based condition that expires after a threshold amount of time elapses (e.g., permissions are granted for one hour, one day, one week, etc.). In yet another example, a geographic boundary can be defined (e.g., a radius around the building in which set-top box 104 is located), and the permissions can be automatically revoked when mobile device 106-1 falls outside the geographic boundary (e.g., a geofence). Note that these are merely examples, and any conditions can be implemented to cause the permissions from mobile device 106-1 to be revoked in appropriate circumstances.

[0057] Additionally, note that in the examples described herein, the assignment of temporary / conditional permissions is not necessarily required to implement the unlocking of set-top box 104, and other methods can be used. For example, set-top box 104 can be configured to simply unlock itself in response to receiving approval from mobile device 106-2, rather than assigning temporary / conditional permissions to mobile device 106-1. In this manner, mobile device 106-1 can need to go through the authentication process each time it attempts to unlock set-top box 104 when set-top box 104 is in a locked state.

[0058] Additionally, and as Figure 3AAs shown, a license page 318 can be displayed on mobile device 106-2, allowing different licenses to be assigned to different wireless devices known to set-top box 104. For example, in section 322 of license page 318, which describes a list of licenses for "Karen's devices," licenses associated with unlocking set-top box 104 and streaming content are switched to the "on" position, indicating the current configuration status after mobile device 106-2 grants mobile device 106-1 a request to unlock set-top box 104. For example, after granting the request, mobile device 106-2 can prompt the administrator to determine whether he / she wants mobile device 106-1 to be able to unlock set-top box 104 at any time so that the administrator will not be disturbed in the future. Additionally, licenses associated with initiating payments using set-top box 104 (e.g., purchasing / renting movies) are switched to the "off" position because the administrator may still be unfamiliar with purchasing content through set-top box 104 using mobile device 106-1. In contrast, under section 320 of the license page 318, which indicates the licenses provided to "John's device" (e.g., mobile device 106 belonging to a user trusted by the administrator), the licenses associated with unlocking set-top box 104, streaming content to set-top box 104, and initiating payments through set-top box 104 can be switched to the "on" position.

[0059] Figure 3B A method 350, according to some embodiments, for granting a wireless device permission to perform specific functions (associated with set-top box 104) that are currently not permitted for wireless devices, is illustrated. Specifically, method 350 provides a more detailed breakdown of the various steps performed by set-top box 104, as described above in conjunction with... Figure 3A As described. Figure 3B As shown, method 350 begins at step 352, where set-top box 104 receives a request from the first wireless device for permission not currently assigned to the first wireless device / a first user account associated with the first wireless device. In one example, this request could be permission associated with unlocking set-top box 104 for operation, as described above in conjunction with... Figure 3A As described in step 1. In some implementations, set-top box 104 may determine that the user account associated with the first wireless device has not been granted the necessary permission level to unlock set-top box 104 for operation.

[0060] In step 354, set-top box 104 can identify a second wireless device associated with a second user account, which has been allocated sufficient permissions to grant permissions not currently assigned to the first user account. In one example, set-top box 104 can identify an administrator (i.e., the second user account referenced in step 354) and query for administrator approval to grant the permission associated with that request to the first wireless device / first user account. In step 356, when the second wireless device is identified, set-top box 104 can send a second request to the second wireless device to grant the permission not currently assigned to the first user account. Subsequently, based on the above combination... Figure 3A In step 2, as described, the second wireless device may display a prompt (e.g., to an authorized user of the second wireless device) and an option to allow the first wireless device to be granted a license.

[0061] In step 358, set-top box 104 receives a response from the second wireless device indicating whether the second wireless device approves the second request. In one example, step 360 may indicate that the administrator of the second wireless device rejects the request, wherein set-top box 104 subsequently does not grant permission to the first wireless device. According to some embodiments, the request may time out after a threshold amount of time, and the rejection may be appropriately issued by set-top box 104 on behalf of the administrator / second wireless device. In this case, the first wireless device may be configured to display a timeout indication, allowing the user of the first wireless device to attempt to contact the administrator by other means. Alternatively, step 362 may indicate that the administrator of the second wireless device accepts the request from the first wireless device, and set-top box 104 then grants the request to the first wireless device.

[0062] Figure 4A A conceptual diagram 400 of a wireless device for purchasing content items in conjunction with a set-top box 104, according to some implementation schemes, is shown. Figure 4A In the example scenario shown, mobile device 106-3 has been paired with set-top box 104 and has at least obtained permission to navigate to the user interface of set-top box 104. In one example, mobile device 106-3 receives permission from set-top box 104 as part of a permission level initially granted to mobile device 106-3 in response to its initial pairing with set-top box 104.

[0063] As shown in step 1, mobile device 106-3 (used for the user interface of navigation set-top box 104) indicates interest in purchasing movie title 402. To complete the purchase, mobile device 106-3 must obtain permission associated with the purchased content item. In one example, set-top box 104 may display the ability to purchase movie title 402 and read the user interface element 408 for "Pay using wireless device". Similarly, mobile device 106-3 can use mobile device 106-3 to display movie title 402 and option 404 to purchase the movie title. However, when mobile device 106-3 is assigned permission associated with initiating payment using set-top box 104, mobile device 106-3 will only be allowed to complete the purchase, which may or may not be the case depending on the permission currently assigned to mobile device 106-3.

[0064] In step 2, the user operating mobile device 106-3 expresses the desire to purchase movie title 402 (e.g., by selecting option 404 to purchase movie title 402 at mobile device 106-3), and set-top box 104 waits for mobile device 106-3 to initiate payment (e.g., as...). Figure 4A (As shown in element 412). As described above, the mobile device 106-3 / its associated user account may have already been assigned a license for purchasing content items (in conjunction with set-top box 104). Alternatively, if no license has been assigned, set-top box 104 can... Figures 3A-3B The instruction is to request permission from the administrator (or other appropriately equipped licensed devices / users known to the set-top box 104).

[0065] In either case, when a license is granted to mobile device 106-3, the user operating mobile device 106-3 may be prompted to complete a payment (e.g., as...). Figure 4A (as shown in element 410). According to some implementations, a user can apply payment credentials associated with mobile device 106-3 to purchase content items at set-top box 104, for example, via... Apple Pay can be used. In other implementations, users can use payment credentials associated with another wireless device. For example, an administrator can grant mobile device 106-3 permission to use its payment credentials at any time. In this example, each wireless device is associated with a corresponding user account (e.g., wireless devices owned by family members) and can purchase media content (e.g., movie title 402) using a single set of payment credentials shared by the family (e.g., a family credit card). It is worth noting that allowing users to purchase content items using payment credentials associated with their mobile device 106 can increase the security of set-top box 104 because these users will be prevented from simply accessing payment credentials managed on set-top box 104 (if any) to complete the payment.

[0066] In step 3, set-top box 104 determines that mobile device 106-3 has successfully completed payment for the content item. According to some embodiments, when payment is successfully completed at mobile device 106-3, mobile device 106-3 can be configured to send a secure message to set-top box 104 indicating successful payment. In turn, set-top box 104 can display an indication 416 confirming payment, and mobile device 106-3 can display an indication 414 that the content item is ready to be viewed on set-top box 104.

[0067] Figure 4B A method 450 for a wireless device to purchase content items via a set-top box 104, according to some embodiments, is illustrated. In particular, method 450 provides alternatives to various steps performed by the set-top box 104, as described above in conjunction with… Figure 4A As described. Figure 4B As shown, method 450 begins at step 452, where set-top box 104 receives a request to purchase a content item from a first wireless device. In step 454, set-top box 104 may identify a second wireless device associated with a user account, which has been allocated sufficient permissions to grant the permission associated with the content item purchase. In step 456, set-top box 104 may send a request to the second wireless device to grant the requested permission. In decision block 458, set-top box 104 may wait for a response from the second wireless device (e.g., an administrator operating the second wireless device), which may grant or deny the request. According to some embodiments, in step 460, the second wireless device denies the request, and set-top box 104 may cause a message to be displayed at the first wireless device indicating that the first wireless device will not be granted the permission associated with the content item purchase. Alternatively, in step 462, set-top box 104 may allow the first wireless device to purchase the content item and may wait to receive an indication that the first wireless device has completed the purchase. Subsequently, in frame 464, set-top box 416 can enable access to content items, such as playback of content items by display device 102 communicatively coupled to set-top box 104.

[0068] Figure 5AA conceptual diagram 500 of mobile device 106-4 causing set-top box 104 to perform different functions according to permissions assigned to mobile device 106-4 is shown in accordance with some embodiments. As depicted in step 1, mobile device 106-4 is streaming a media item 502 to display device 102 (e.g., via set-top box 104). Specifically, display device 102 is displaying media item 502 in an example interface 504. In this example, streaming media item 502 is associated with a permission level granted to mobile device 106-4 upon successful pairing with set-top box 104, and does not require unlocking set-top box 104. In some embodiments, an administrator can specify that certain actions, such as streaming content, require first unlocking set-top box 104. In other embodiments, some actions such as streaming can be provided without unlocking set-top box 104.

[0069] In step 2, mobile device 106-4 has stopped streaming content to set-top box 104 and is attempting to navigate the user interface of set-top box 104 (e.g., using a trackpad 506 provided by an application to remotely control set-top box 104). In this example, navigating set-top box 104 is an action that requires a higher permission level, and mobile device 106-4 can be prevented from navigating set-top box 104 until mobile device 106-4 receives a permission associated with unlocking set-top box 104. As shown, as mobile device 106 transitions to navigating set-top box 104, display device 102 can display a screen saver 510. Figure 5A

[0070] In step 3, mobile device 106-4 is prevented from unlocking set-top box 104 because mobile device 106-4 has not obtained the higher permission level required to unlock the set-top box. In an example user interface 512, mobile device 106-4 is warned that set-top box 104 is locked. In addition, in step 4, set-top box 104 can issue a request to an administrator on behalf of mobile device 106-4 for the necessary permission to unlock set-top box 104. Similarly, set-top box 104 can display an indication that set-top box 104 is locked / requesting administrator permission to grant mobile device 106-4 the necessary permission to unlock set-top box 104 (e.g., as shown by element 514 in FIG. 5).

[0071] In step 4, an administrator (or other authorized wireless device / user account) has granted mobile device 106-4 the permission required to unlock set-top box 104. The user of mobile device 106-4 is now able to navigate trackpad 516 to control set-top box 104. Similarly, set-top box 104 can now allow mobile device 106-4 to navigate set-top box 104, as shown in example interface 518.

[0072] Figure 5B ​Methods 550 involving a wireless device that causes a set-top box 104 to perform different functions in accordance with permissions assigned to the wireless device are shown in accordance with some embodiments. In particular, methods 550 provide a more detailed breakdown of the various steps performed by a set-top box 104 as described above in connection with Figure 5A Figure 5B As shown, methods 550 begin at step 552 where a set-top box 104 receives a request from a wireless device to perform a particular action at the set-top box 104. In one example, the particular action can involve streaming content to the set-top box 104.

[0073] At step 554, the set-top box 104 can determine whether the particular action requires unlocking the set-top box 104. Again, an administrator associated with the set-top box 104 can specify actions that are able to be performed at the set-top box 104 without requiring the set-top box 104 to be unlocked. In this example, the administrator can specify that streaming content from the wireless device to the set-top box 104 does not require the set-top box 104 to be unlocked. However, the administrator can specify that other actions, such as accessing payment credentials or purchasing a movie, do require the set-top box 104 to be unlocked first. Thus, the wireless device must be granted a higher permission level associated with unlocking the set-top box 104 in order to perform the particular action that requires the set-top box 104 to be unlocked.

[0074] At step 556, the set-top box 104 determines that the particular action does not require the set-top box 104 to be unlocked and allows the wireless device to perform the particular action at the set-top box 104. In one example, when the set-top box 104 does not need to be unlocked to perform the particular action, the wireless device can perform the action without receiving a higher permission level.

[0075] At step 558, the set-top box 104 determines that the particular action requires the set-top box 104 to be unlocked. In response, the set-top box 104 can identify different wireless devices associated with user accounts that are assigned permissions sufficient to grant permission to unlock the set-top box 104. Next, at step 560, the set-top box 104 can obtain (e.g., from an administrator) permissions for a wireless device to unlock the set-top box 104 and perform the particular action. In response to receiving the permissions, the set-top box 104 can grant the wireless device permission to unlock the set-top box 104 and allow the wireless device to perform the particular action at step 562. Further, in some embodiments, the set-top box 104 can remember the granted permission such that the wireless device will be allowed to unlock the set-top box 104 each time the wireless device is paired with the set-top box 104.

[0076] Additionally, Figures 6A-6B Methods 600 implemented by a set-top box 104 for automatically establishing a privilege level for a wireless device based on an initial pairing and / or operation performed in connection with the wireless device are shown in accordance with some embodiments. As Figure 6A ​As shown, the method 600 begins at step 602, where the set-top box 104 enters a pairing mode. For example, the set-top box 104 can actively broadcast pairing availability to wireless devices through a direct wireless connection (e.g., Bluetooth, WiFi, etc.), through an existing wireless connection (e.g., a WiFi network) that the set-top box 104 and the wireless device are already connected to, etc.

[0077] Next, at step 604, the set-top box 104 receives a first request from a wireless device to pair with the set-top box. For example, the wireless device can issue the first request with a user seeking to perform one or more operations associated with the set-top box 104 (e.g., stream content to the set-top box 104, remotely control the set-top box 104 (e.g., using an application installed on the wireless device), etc.). In any case, the set-top box 104 can use different methods to pair with the wireless device to establish different levels of authorization to perform the desired initial operation (described below in step 606). For example, when the wireless device seeks to only stream content to the set-top box 104, the pairing can be established through a direct connection between the set-top box 104 and the wireless device (e.g., using Bluetooth) where no on-screen code (e.g., as described above in connection with Figure 2A In another example, when the wireless device attempts to remotely control the set-top box 104, the set-top box 104 can require a higher level of pairing (e.g., the on-screen code method described above in connection with Figure 2A

[0078] ​In any case, at step 606, the set-top box 104 pairs with the wireless device. Next, at step 608, the set-top box 104 receives a second request from the wireless device to perform an initial operation in association with the wireless device. In response, at step 610, the set-top box 104 provides a set of access rights to the wireless device. According to some embodiments, the set of access rights can be based on (1) the manner in which the wireless device and set-top box 104 initially paired (e.g., at step 606), and / or (2) the second request to perform the initial operation. For example, when the initial operation involves performing a screen projection from the wireless device to the set-top box 104, the set of access rights can limit the wireless device to only being able to perform screen projection with the set-top box 104. In another example, when the initial operation involves performing a remote control operation between the wireless device and set-top box 104, the set of access rights can limit the wireless device to only being able to perform: (1) remote control operations between the wireless device and set-top box 104, and (2) screen projection from the wireless device to the set-top box 104. In yet another example, when the initial operation involves performing a screen recording at the set-top box 104 (e.g., at the direction of the wireless device), the set of access rights can limit the wireless device to only being able to perform: (1) screen recording at the set-top box 104 at the direction of the wireless device, (2) remote control operations between the wireless device and set-top box 104, and (3) screen projection from the wireless device to the set-top box 104. Note that the foregoing examples are merely exemplary, and any number of operations can be specified in the set of access rights described herein.

[0079] In any case, at step 612, the set-top box 104 performs the initial operation. Next, at Figure 6B In any case, at step 612, the set-top box 104 performs the initial operation. Next, at Figure 2A In any case, at step 612, the set-top box 104 performs the initial operation. Next, at

[0080] Therefore, in step 618, set-top box 104 determines whether the second operation is permitted based on the group of access permissions. If, in step 618, set-top box 104 determines that the second operation is permitted based on the group of access permissions, method 600 proceeds to step 620, where set-top box 104 performs the second operation in association with the wireless device. Otherwise, method 600 proceeds to step 622, where set-top box 104 rejects the third request to perform the second operation. According to some embodiments, in conjunction with the rejection request, set-top box 104 may indicate to the wireless device (and the operating user) that a more secure pairing process is required.

[0081] It should be noted that the aforementioned scenarios involving set-top box 104 and wireless devices are merely exemplary and do not imply any limitation in any way. In contrast, any form of computing device can be configured to implement the functions of set-top box 104, and any form of computing device can be configured to implement the functions of a wireless device. It should also be noted that the various interactions described herein can be performed via both wireless and wired connections.

[0082] Figure 7 Detailed views of a computing device 700, according to some embodiments, for implementing the various components described herein are shown. Specifically, the detailed views show components that may be included in... Figure 1 Various components in the mobile device 106, tablet device 108, wearable device 110, set-top box 104, and display device 102 shown. For example... Figure 7 As shown, computing device 700 may include a processor 702 representing a microprocessor or controller for controlling the overall operation of computing device 700. Computing device 700 may also include a user input device 708 that allows a user of computing device 700 to interact with computing device 700. For example, user input device 708 may take various forms, such as buttons, keypad, dial pad, touchscreen, audio input interface, visual / image capture input interface, sensor data input, etc. Furthermore, computing device 700 may include a display 710 (screen display) that can be controlled by processor 702 to display information to a user. Data bus 716 facilitates data transfer between at least storage device 740, processor 702, and controller 713. Controller 713 can be used to interact with and control different devices via device control bus 714. Computing device 700 may also include a network / bus interface 711 coupled to data link 712, wherein, for example, network / bus interface 711 can be used to transmit references. Figure 1 , Figures 2A-2C , Figures 3A-3B , Figures 4A-4B and Figures 5A-5B The message under discussion. In the case of wireless connectivity, the network / bus interface 711 may include a wireless transceiver.

[0083] As described above, computing device 700 also includes storage 740, which can include a single disk or a plurality of disks (e.g., hard drives), and includes a storage management module that manages one or more partitions within storage 740. In some embodiments, storage 740 can include flash memory, semiconductor (solid state) memory, etc. The computing device 700 can also include random access memory (RAM) 720 and read only memory (ROM) 722. ROM 722 can store programs, utilities or processes to be executed in a non-volatile manner. RAM 720 can provide volatile data storage and store instructions related to the operation of applications executing on set-top box 104, as well as mobile device 106, tablet device 108, and wearable device 110.

[0084] Various aspects of the described implementations can be used alone, in combination, or in any combination. Various aspects of the described implementations can be implemented by software, hardware, or a combination of hardware and software. The described implementations can also be embodied as computer readable code on a computer readable medium. Any of the described implementations can be embodied on the computer readable medium, which can be a non-transitory computer readable medium in which the data can only be read once but not modified or initialized. Computer readable media include both computer storage media and communication media including any medium that facilitates transfer of a computer program from one place to another. The computer storage media can be any available media that can be accessed by a computer. By way of example, and not limitation, such computer storage media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other storage device comprising a combination of the

[0085] For purposes of explanation and illustration, specific nomenclature has been set forth to provide a thorough understanding of the described implementations. However, it will be apparent to those skilled in the art that the described implementations can be practiced without the specific details. Thus, the foregoing description is presented for purposes of illustration and description. It is not intended to be exhaustive or to limit the described implementations to the precise form disclosed. Many modifications and variations are possible in light of the above teaching. It is intended that the scope of the described implementations be limited not by this detailed description, but rather by the claims and the metes and bounds thereof.

Claims

1. A method for establishing a secure and anonymous communication channel, the method comprising, at a host device: Receive a request from the electronic device to wirelessly pair with the host device; Establish a wireless connection with the electronic device to grant the electronic device a permission level to interact with the host device; Receive from the electronic device i) a first message encrypted with a private key and ii) the corresponding public key; The public key is stored in the public key storage area of ​​the host device, wherein the public key storage area includes multiple public keys, which are associated with multiple devices that have previously been paired with the host device; Receive a second message from the electronic device, wherein the second message is encrypted using the private key; The second message is associated with the electronic device as follows: i) Attempt to decrypt the second message using multiple public keys from the public key's storage area, and ii) The public key was successfully recognized and the second message was decrypted.

2. The method of claim 1, wherein the second message: The public key is not included, and Information identifying the electronic device is not included.

3. The method of claim 1, wherein: The public key storage area includes a lookup table with at least a first entry and a corresponding second entry. The first entry includes an electronic device identifier associated with the electronic device, and The corresponding second entry includes the public key.

4. The method of claim 1, further comprising: In response to determining that the second message is associated with the electronic device, a first license level is granted to the electronic device for controlling the host device.

5. The method of claim 4, wherein the first license level comprises at least: Wireless streaming of content to the host device, and Remote navigation of the user interface (UI) provided by the host device.

6. The method of claim 5, wherein the first permission level is associated with the public key.

7. The method of claim 1, wherein the electronic device provides the request in response to input received at the electronic device.

8. A host device configured to establish a secure and anonymous communication channel, the host device comprising: A means for receiving a request from an electronic device to wirelessly pair with the host device; A means for establishing a wireless connection with the electronic device in order to grant the electronic device a permission level to interact with the host device; A means for receiving from the electronic device i) a first message encrypted with a private key and ii) a corresponding public key; A means for storing the public key in a public key storage area of ​​the host device, wherein the public key storage area includes a plurality of public keys associated with a plurality of devices that have been previously paired with the host device; A means for receiving a second message from the electronic device, wherein the second message is encrypted using the private key; A means for determining that the second message is associated with the electronic device by: i) Attempt to decrypt the second message using multiple public keys from the public key's storage area, and ii) The public key was successfully recognized and the second message was decrypted.

9. The host device as claimed in claim 8, wherein the second message: The public key is not included, and Information identifying the electronic device is not included.

10. The host device as claimed in claim 8, wherein: The public key storage area includes a lookup table with at least a first entry and a corresponding second entry. The first entry includes an electronic device identifier associated with the electronic device, and The corresponding second entry includes the public key.

11. The host device as claimed in claim 8, further comprising: Means for granting the electronic device a first license level for controlling the host device in response to determining that the second message is associated with the electronic device.

12. The host device of claim 11, wherein the first license level includes at least: Wireless streaming of content to the host device, and Remote navigation of the user interface (UI) provided by the host device.

13. The host device of claim 12, wherein the first license level is associated with the public key.

14. The host device of claim 8, wherein the electronic device provides the request in response to input received at the electronic device.

15. A host device configured to establish a secure and anonymous communication channel, wherein the host device includes at least one processor configured to cause the host device to perform steps including: Receive a request from the electronic device to wirelessly pair with the host device; Establish a wireless connection with the electronic device to grant the electronic device a permission level to interact with the host device; Receive from the electronic device i) a first message encrypted with a private key and ii) the corresponding public key; The public key is stored in the public key storage area of ​​the host device, wherein the public key storage area includes multiple public keys, which are associated with multiple devices that have previously been paired with the host device; Receive a second message from the electronic device, wherein the second message is encrypted using the private key; The second message is associated with the electronic device as follows: i) Attempt to decrypt the second message using multiple public keys from the public key's storage area, and ii) The public key was successfully recognized and the second message was decrypted.

16. The host device of claim 15, wherein the second message: The public key is not included, and Information identifying the electronic device is not included.

17. The host device as claimed in claim 15, wherein: The public key storage area includes a lookup table with at least a first entry and a corresponding second entry. The first entry includes an electronic device identifier associated with the electronic device, and The corresponding second entry includes the public key.

18. The host device according to claim 15, wherein the step further comprises: In response to determining that the second message is associated with the electronic device, a first license level is granted to the electronic device for controlling the host device.

19. The host device of claim 18, wherein the first license level includes at least: Wireless streaming of content to the host device, and Remote navigation of the user interface (UI) provided by the host device.

20. The host device of claim 19, wherein the first license level is associated with the public key.

Citation Information

Patent Citations

  • Process authentication and resource permissions

    CN105408912A