Access Management to Protected Content Using a Device Security Profile

The system addresses the challenge of dynamically managing access to content items by using a dynamically updateable device security profile (DSP) to restrict access based on client device security and resolution level, ensuring secure and compliant content access.

JP7693117B2Active Publication Date: 2025-06-16GOOGLE LLC
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024534583
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-02-11
Filing Date
2022-08-23
Publication Date
2025-06-16
Estimated Expiration
2042-08-23

AI Technical Summary

Technical Problem

Existing digital rights management (DRM) systems struggle to dynamically manage access to content items based on changing security profiles of client devices, particularly in response to new hardware or security vulnerabilities.

Method used

A system that utilizes a device security profile (DSP) which can be dynamically updated by content owners. The DSP specifies requirements for client devices to access content items, varying by resolution level and including hardware and security requirements. The system includes a DRM server that receives and stores DSP data, and a content server that restricts access based on the DSP.

Benefits of technology

The system effectively manages access to content items by ensuring that only compliant client devices can access content at various resolution levels, thereby protecting content owners' rights and preventing unauthorized access or distribution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007693117000001
    Figure 0007693117000001
  • Figure 0007693117000002
    Figure 0007693117000002
  • Figure 0007693117000003
    Figure 0007693117000003
Patent Text Reader

Abstract

A Digital Rights Management (DRM) server receives data associated with a Device Security Profile (DSP) from a content owner device. The DSP specifies requirements for a client device to access a content item associated with the content owner. The requirements vary depending on the resolution level of the content item being accessed. The DRM server stores the DSP and an indication of the content owner. The DRM server receives a pull request for a DSP update from a content server that stores the content items associated with the content owner. The DRM server sends the DSP to the content server in response to the pull request. The DSP enables the content server to restrict client devices from accessing the content item according to the DSP.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross - Reference to Related Applications This application claims priority based on U.S. Provisional Patent Application No. 63 / 289,067, filed on December 13, 2021, and U.S. Patent Application No. 17 / 670,301, filed on February 11, 2022, the entire contents of which are incorporated herein by reference.

Background Art

[0002] Contents such as digital images and videos can be stored in a server or a content storage and distribution system connected to a network such as the Internet. A client device can download the content and display it to the user of the client device. Content owners may wish to prevent unauthorized distribution of the content or degrade the quality of copies made without permission on a client device. In some cases, digital rights management (DRM) technology may be used to prevent copying of content by a client device or degrade the quality of copies of content made by a client device.

Summary of the Invention

[0003] Disclosed herein are aspects of a system, method, computer program product, and apparatus for managing access to content protected using a device security profile.

[0004] One aspect of the teachings described herein is a method for managing access to content protected using a device security profile. The method can include receiving, at a digital rights management (DRM) server, data associated with a device security profile (DSP) from a content owner device, where the DSP specifies requirements for a client device to access content items associated with a content owner, and those requirements vary depending on the resolution level of the content items being accessed. The method can include storing, at the DRM server, an indication of the DSP and the content owner. The method can include receiving, at the DRM server, a pull request regarding a DSP update from a content server that stores content items associated with the content owner. The method can include transmitting the DSP to the content server in response to the pull request, where the DSP causes the content server to restrict client devices that access content items according to the DSP (e.g., the DSP is configured to cause the content server to restrict access to content items by client devices according to the DSP).

[0005] The resolution level can be based on at least one of the total number of pixels, the number of pixels per frame, or pixel dimension measurements. The resolution level can include at least one of standard definition (SD), high definition (HD), or 4K. The requirements can vary according to tags of the content items being accessed. The requirements can include hardware requirements and / or security requirements of a client device (e.g., each client device) accessing the content item. The DSP can be composed of a first data structure representing the resolution level and requirements for each resolution level, a second data structure representing tags of the content items and requirements for each tag, and a third data structure representing a device configuration having exceptions to the requirements of the first data structure or the second data structure.

[0006] The method may further comprise pushing the DSP to the second content server if a pull request regarding DSP update cannot be received from the second content server that stores content items associated with the content owner within a predetermined time period. The method may further comprise receiving an update to the DSP from the content owner device, receiving a second pull request from the content server, and sending an update to the DSP or an updated version of the DSP to the content server in response to the second pull request.

[0007] The method may further comprise sending, to the content owner device, code for generating a graphical user interface (GUI) for inputting data associated with the DSP, and generating, at the DRM server, a DSP based on the data associated with the DSP obtained at the content owner device via the GUI. The method may comprise receiving, at the content server, the content owner's DSP, receiving, at the content server, from the client device, a content request for a content item that is one of the content items associated with the content owner, determining, based on the content request and the DSP, a resolution level of the content item to be provided to the client device, and sending, from the content server to the client device, the content item at the determined resolution level.

[0008] Another aspect of the teachings described herein is a computer system that manages access to content protected using a device security profile. The system includes a memory for storing instructions. The system includes a processor capable of executing instructions to perform the method of any of the aspects described above. In particular, the processor can execute instructions to receive, at a DRM server, data associated with a DSP from a content owner device, where the DSP specifies requirements for a client device to access content items associated with the content owner, and those requirements vary depending on the resolution level of the content item being accessed. The processor can execute instructions to store, at the DRM server, an indication of the DSP and the content owner. The processor can execute instructions to receive, from a content server storing content items associated with the content owner, a pull request regarding a DSP update. The processor can execute instructions to send the DSP to the content server in response to the pull request, where the DSP causes the content server to restrict client devices accessing the content items according to the DSP.

[0009] In another aspect, it is a computer-readable medium (e.g., a computer program product) for managing access to content protected using a device security profile. The computer-readable medium stores instructions that can cause a processor to perform operations such as those in the methods of the aspects described above. The instructions may include code for receiving, at a digital rights management (DRM) server, data associated with a device security profile (DSP) from a content owner device, where the DSP specifies requirements for a client device to access content items associated with the content owner, and those requirements vary depending on the resolution level of the content items being accessed. The instructions may include code for storing, at the DRM server, an indication of the DSP and the content owner. The instructions may include code for receiving, from a content server storing content items associated with the content owner, a pull request regarding a DSP update. The instructions can include code for sending the DSP to the content server in response to the pull request, where the DSP causes the content server to restrict client devices that access content items according to the DSP.

[0010] Variations of these and other aspects will be described in detail later.

[0011] In this specification, reference is made to the accompanying drawings, and unless otherwise noted or apparent from the context, like reference numerals refer to like parts throughout the several views.

Brief Description of the Drawings

[0012]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Mode for Carrying Out the Invention

[0013] A content owner may develop content (e.g., digital video, audio file, image) and provide storage content to a content server. The content server can deliver the content to a client device and display or play it there. The content owner may wish to prevent unauthorized distribution of the content or degrade the quality of copies made without permission on the client device. It may be difficult to provide content for playback while restricting further distribution or copying of the provided content.

[0014] In some cases, digital rights management (DRM) technology may be used to prevent copying of content by client devices or to degrade the quality of copies of content created by client devices. The DRM server may provide DRM policy information to the content server. The DRM server may provide support for encryption schemes and hardware security to restrict client devices accessing the distributed content according to rules defined by the content owner.

[0015] The content owner may wish to dynamically update rules regarding the hardware and security policies of devices accessing the content owner's content. This may be desirable, for example, when new hardware comes onto the market, when the security policy is changed, or when new security vulnerabilities (which can be exploited for unauthorized copying of content) are discovered.

[0016] At least some embodiments of the teachings herein relate to the technical problem of how to protect access to content items in a distribution system in response to dynamic changes in the security of devices accessing the content items. A technical solution may include establishing a device security profile (DSP) that can be dynamically updated by the content owner. For example, the content owner may update the DSP in response to changes in the security credentials of the client device. A technical solution may include providing a distribution architecture for enabling the DSP to be used safely and timely at the content server.

[0017] In some embodiments, the DRM server receives data associated with the DSP from the content owner device. The DSP specifies requirements for a client device to access content items associated with the content owner. The requirements vary depending on the resolution level of the content item being accessed. The resolution level may be based on the total number of pixels, the number of pixels per frame, pixel dimension measurements, or a combination thereof. For example, the resolution level may be at least one of standard definition (SD) (e.g., 720x480 pixels), high definition (HD) (e.g., 1280x720 pixels or 1920x1080 pixels), or 4K (e.g., 4096x2160 pixels). The DRM server stores the DSP along with an indication of the content owner, for example, within a data structure associated with the content owner. The DRM server receives a pull request regarding DSP updates from a content server that stores content items associated with the content owner. The DRM server transmits the DSP to the content server in response to the pull request. The DSP restricts client devices that access content items from the content server according to the DSP.

[0018] In some embodiments, the content server receives the content owner's DSP in response to, for example, a pull request regarding DSP updates from the content server. The DSP specifies requirements for a client device to access content items associated with the content owner. The requirements vary depending on the resolution level of the content item being accessed. The content server receives a content request for a content item from the client device. The content server determines the resolution level of the content item to provide to the client device based on the content request and the DSP. The content server transmits the content item to the client device at the determined resolution level.

[0019] The details of these and other embodiments are described in further detail below, first with reference to the environments in which they may be implemented.

[0020] FIG. 1 is a block diagram showing an example of a computing device 100. The illustrated computing device 100 includes a memory 110, a processor 120, a user interface (UI) 130, an electronic communication unit 140, a sensor 150, a power supply 160, and a bus 170. As used herein, the term "computing device" includes any unit, or combination of units, that can execute any method, or any part (singular or plural) thereof, disclosed herein.

[0021] The computing device 100 may be a fixed computing device such as a personal computer (PC), a server, a workstation, a minicomputer, a mainframe computer, or a mobile computing device such as a mobile phone, a personal digital assistant (PDA), a notebook computer, a tablet PC, etc. Although shown as a single unit, any one or more elements of the computing device 100 can be integrated into any number of individual physical units. For example, the user interface 130 and the processor 120 may be integrated into a first physical unit, and the memory 110 may be integrated into a second physical unit. The processor 120 may be a hardware unit or may be composed of processing hardware or a processing circuit. The processor 120 may be a single processor or may include a plurality of processors.

[0022] The memory 110 can include any non - transitory computer - usable medium or computer - readable medium, such as any tangible device that can contain, store, communicate, or transfer data 112, instructions 114, operating system 116, or any information related thereto, which is used by or in relation to other components of the computing device 100. Examples of non - transitory computer - usable media or computer - readable media include solid - state drives, memory cards, removable media, read - only memory (ROM), random - access memory (RAM), hard disks, floppy disks, optical disks, any type of disk such as magnetic or optical cards, application - specific integrated circuits (ASICs), or any type of non - transitory medium suitable for storing electronic information, or combinations thereof.

[0023] Although shown as a single unit, the memory 110 may comprise multiple physical units, such as one or more primary memory units, such as random - access memory units, one or more secondary data storage units, such as disks, or combinations thereof. For example, data 112 or a portion thereof, instructions 114 or a portion thereof, or both may be stored in the secondary storage unit and loaded or transferred to the primary storage unit in conjunction with the processing of respective data 112, the execution of respective instructions 114, or both. In some embodiments, the memory 110 or a portion thereof may be a removable memory.

[0024] Data 112 may be, for example, input data, encoded data, decoded data, etc., or may include these. Instruction 114 may include instructions such as code for executing any method disclosed herein, or any part (s) thereof. Instruction 114 can be implemented in hardware, software, or any combination thereof. For example, Instruction 114 can be implemented as information stored in Memory 110, such as a computer program or application, and executed by Processor 120 to execute any of the respective methods, algorithms, aspects, or combinations thereof described herein.

[0025] Although shown as being had by Memory 110, in some embodiments, Instruction 114 or a part thereof may be implemented as a special-purpose processor or circuit that may include dedicated hardware for executing any of the methods, algorithms, aspects, or combinations thereof described herein. A part of Instruction 114 can be distributed to multiple processors of the same machine or different machines, or to a network such as a local area network, wide area network, Internet, etc., or combinations thereof.

[0026] Processor 120 may include any device or system that can operate or process existing or future-developed digital signals or other electronic information, such as an optical processor, a quantum processor, a molecular processor, or a combination thereof. For example, processor 120 may include a special-purpose processor, a central processing unit (CPU), a digital signal processor, multiple microprocessors, one or more microprocessors associated with a digital signal processor core, a controller, a microcontroller, an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a programmable logic array, a programmable logic controller, microcode, firmware, any type of integrated circuit (IC), a state machine, or any combination thereof. As used herein, the term "processor" includes a single processor or multiple processors.

[0027] User interface 130 may include any unit that can interface with a user, such as a virtual keypad or a physical keypad, a touchpad, a display, a touch display, a speaker, a microphone, a video camera, a sensor, or any combination thereof. For example, user interface 130 may be an audio-visual display device, and computing device 100 may use user interface 130, an audio-visual display device, to present decoded audio, such as audio, in combination with the display of video, such as decoded video. Although shown as a single unit, user interface 130 may comprise one or more physical units. For example, user interface 130 may include an audio interface for voice communication with the user and a touch display for visual- and touch-based communication with the user.

[0028] The electronic communication unit 140 can transmit, receive, or both transmit and receive signals via a wired or wireless electronic communication medium 180 such as a radio frequency (RF) communication medium, an ultraviolet (UV) communication medium, a visible light communication medium, an optical fiber communication medium, a wired communication medium, or a combination thereof. For example, as shown in the figure, the electronic communication unit 140 is operatively connected to an electronic communication interface 142 such as an antenna configured to communicate by wireless signals.

[0029] In FIG. 1, the electronic communication interface 142 is shown as a wireless antenna, but the electronic communication interface 142 can be a wired communication port such as a wireless antenna, an Ethernet port, an infrared port, a serial port, etc. as shown in the figure, or any other wired or wireless unit that can interface with the wired or wireless electronic communication medium 180. FIG. 1 shows a single electronic communication unit 140 and a single electronic communication interface 142, but any number of electronic communication units and any number of electronic communication interfaces can be used.

[0030] The sensor 150 may include, for example, an audio detection device, a visible light detection device, a motion detection device, or a combination thereof. For example, the sensor 150 may include a sound detection device such as a microphone, or any other existing or future-developed sound detection device that can detect sounds in the vicinity of the computing device 100, such as voices or other utterances by a user operating the computing device 100. In another example, the sensor 150 may include a camera, or any other existing or future-developed image detection device that can detect images such as an image of a user operating the computing device. Although a single sensor 150 is shown, the computing device 100 may include multiple sensors 150. For example, the computing device 100 may include a first camera having a field of view directed towards the user of the computing device 100 and a second camera having a field of view directed in a direction away from the user of the computing device 100.

[0031] The power supply 160 can be any device suitable for supplying power to the computing device 100. For example, the power supply 160 can include a wired external power supply interface, one or more dry batteries such as nickel-cadmium (NiCd) batteries, nickel-zinc (NiZn) batteries, nickel-metal hydride (NiMH) batteries, lithium-ion (Li-ion) batteries, solar cells, fuel cells, or any other device capable of supplying power to the computing device 100. Although a single power supply 160 is shown in FIG. 1, the computing device 100 may include multiple power supplies 160 such as batteries or wired external power supply interfaces.

[0032] Although shown as separate units, the electronic communication unit 140, the electronic communication interface 142, the user interface 130, the power supply 160, or portions thereof may be configured as combined units. For example, the electronic communication unit 140, the electronic communication interface 142, the user interface 130, and the power supply 160 may interface with an external display device and be implemented as a communication port capable of providing communication, power, or both.

[0033] One or more of the memory 110, the processor 120, the user interface 130, the electronic communication unit 140, the sensor 150, or the power supply 160 may be operatively connected via the bus 170. Although a single bus 170 is shown in FIG. 1, the computing device 100 may include multiple buses. For example, the memory 110, the processor 120, the user interface 130, the electronic communication unit 140, the sensor 150, and the bus 170 may receive power from the power supply 160 via the bus 170. In another example, the memory 110, the processor 120, the user interface 130, the electronic communication unit 140, the sensor 150, the power supply 160, or combinations thereof may communicate data such as by transmitting and receiving electronic signals via the bus 170.

[0034] Although not shown separately in FIG. 1, one or more of the processor 120, user interface 130, electronic communication unit 140, sensor 150, or power supply 160 may include internal memory such as an internal buffer or register. For example, the processor 120 may include internal memory (not shown), and may read and process data 112 from the memory 110 into the internal memory (not shown).

[0035] Although shown as separate elements, the memory 110, processor 120, user interface 130, electronic communication unit 140, sensor 150, power supply 160, and bus 170, or any combination thereof, can be integrated into one or more electronic units, circuits, or chips.

[0036] FIG. 2 is a diagram of a computing and communication system 200. The computing and communication system 200 shown in the figure includes computing and communication devices 100A, 100B, 100C, access points 210A, 210B, and network 220. For example, the computing and communication system 200 can be a multi-connection system that provides communication such as voice, audio, data, video, messaging, broadcast, or a combination thereof to one or more wired communication devices or wireless communication devices such as the computing and communication devices 100A, 100B, 100C. For simplicity, FIG. 2 shows three computing and communication devices 100A, 100B, 100C, two access points 210A, 210B, and one network 220, but any number of computing and communication devices, access points, and networks can be used.

[0037] Computing and communication devices 100A, 100B, 100C can be, for example, computing devices such as the computing device 100 described in FIG. 1. For example, computing and communication devices 100A, 100B can be user devices such as mobile computing devices, notebook computers, thin clients, or smartphones, and computing and communication device 100C can be a server such as a mainframe or a cluster. Although computing and communication device 100A and computing and communication device 100B are described as user devices and computing and communication device 100C is described as a server, any computing and communication device can perform some or all of the server functions, some or all of the user device functions, or some or all of the server functions and user device functions. For example, the computing and communication device 100C of the server can receive data such as audio data and video data, perform processing such as encoding, processing, storage, transmission, or a combination thereof, and one or both of the computing and communication device 100A and the computing and communication device 100B can receive data, perform processing such as decoding, processing, storage, presentation, or a combination thereof.

[0038] Each computing and communication device 100A, 100B, 100C may include a user equipment (UE), a mobile station, a fixed subscriber unit or a mobile subscriber unit, a mobile phone, a personal computer, a tablet computer, a server, a home appliance, or any similar device, and can be configured to perform wired or wireless communication, such as via network 220. For example, computing and communication devices 100A, 100B, 100C can be configured to transmit or receive wired communication signals or wireless communication signals. Although each computing and communication device 100A, 100B, 100C is shown as a single unit, the computing and communication device can include any number of interconnected elements.

[0039] Each access point 210A, 210B can be any type of device configured to communicate with computing and communication devices 100A, 100B, 100C, network 220, or both via wired or wireless communication links 180A, 180B, 180C. For example, access points 210A, 210B can include base stations, radio base stations (BTS), NodeBs, evolved NodeBs (eNode-Bs), home NodeBs (HNode-Bs), wireless routers, wired routers, hubs, repeaters, switches, or any similar wired or wireless device. Each access point 210A, 210B is shown as a single unit, but an access point can include any number of interconnected elements.

[0040] Network 220 can be any type of network configured to provide services such as voice, data, applications, voice over internet protocol (VoIP), or any other communication protocol or combination of communication protocols via wired or wireless communication links. For example, network 220 can be a local area network (LAN), wide area network (WAN), virtual private network (VPN), mobile or cellular phone network, the internet, or any other means of electronic communication. The network can use communication protocols such as transmission control protocol (TCP), user datagram protocol (UDP), internet protocol (IP), real-time transport protocol (RTP), hypertext transfer protocol (HTTP), or combinations thereof.

[0041] Computing and communication devices 100A, 100B, 100C can communicate with each other via network 220 using one or more wired or wireless communication links, or a combination of wired and wireless communication links. For example, as shown in the figure, computing and communication devices 100A, 100B can communicate via wireless communication links 180A, 180B, and computing and communication device 100C can communicate via wired communication link 180C. Any of the computing and communication devices 100A, 100B, 100C may communicate using any wired or wireless communication link. For example, the first computing and communication device 100A can communicate via the first access point 210A using a first type of communication link, the second computing and communication device 100B can communicate via the second access point 210B using a second type of communication link, and the third computing and communication device 100C can communicate via a third access point (not shown) using a third type of communication link. Similarly, access points 210A, 210B can communicate with network 220 via one or more types of wired or wireless communication links 230A, 230B. FIG. 2 shows the communication of computing and communication devices 100A, 100B, 100C via network 220, but computing and communication devices 100A, 100B, 100C can communicate with each other via any number of communication links, such as direct wired or wireless communication links.

[0042] In some embodiments, for communication between one or more of the computing and communication devices 100A, 100B, 100C, communication via the network 220 may be omitted, and data transfer via another medium (not shown), such as a data storage device, may be provided. For example, the computing and communication device 100C of the server may store data, such as encoded data, in a data storage device, such as a portable data storage unit, and one or both of the computing and communication device 100A or the computing and communication device 100B may, for example, physically disconnect the data storage device from the computing and communication device 100C of the server and physically connect the data storage device to the computing and communication device 100A or the computing and communication device 100B to access, read, or obtain the audio data stored from the data storage unit.

[0043] Other embodiments of the computing and communication system 200 are also possible. For example, in one embodiment, the network 220 can be an ad hoc network, and one or more of the access points 210A, 210B can be omitted. The computing and communication system 200 may include devices, units, or elements not shown in FIG. 2. For example, the computing and communication system 200 may further include more communication devices, networks, and access points.

[0044] As described above, to protect access to content items of the distribution system in response to dynamic changes in the security of the devices accessing the content items, this can be achieved by establishing a device security profile (DSP) that can be dynamically updated by the content owner. The DSP may be used to manage access to such protected content.

[0045] FIG. 3 is a block diagram of an example of a system 300 that can implement access management to content protected using a DSP. As shown, system 300 includes content owner devices 302A, 302B, 302C, a DRM server 304, content servers 306A, 306B, and client devices 308A, 308B. The content owner devices 302A, 302B, 302C, the DRM server 304, the content servers 306A, 306B, and the client devices 308A, 308B can each correspond to a computing device 100. Also, although three content owner devices 302A, 302B, 302C, one DRM server 304, two content servers 306A, 306B, and two client devices 308A, 308B are shown, depending on the embodiment, other numbers of these devices may be used. The content owner devices 302A, 302B, 302C, the DRM server 304, the content servers 306A, 306B, and the client devices 308A, 308B communicate with each other via a network (e.g., network 220). Each content server 306A, 306B may be a license server or may include a license server.

[0046] According to some embodiments, the content owner devices 302A, 302B, 302C and the client devices 308A, 308B are user devices such as mobile phones, tablet computers, desktop computers, laptop computers, smart watches, personal digital assistants, digital music players, etc. The DRM server 304 and the content servers 306A, 306B may be server computers.

[0047] As shown in the figure, the DRM server 304 stores data associated with content owners 310A, 310B, and 310C. Content owner 310A is associated with content owner device 302A. Content owner 310B is associated with content owner device 302B. Content owner 310C is associated with content owner device 302C. The data associated with content owner 310A includes DSP 312A. The data associated with content owner 310B includes DSP 312B. The data associated with content owner 310C includes DSP 312C.

[0048] In some embodiments, the DRM server 304 transmits to the content owner device 302A code that generates a graphical user interface (GUI) for entering data associated with the DSP 312A. An example of a GUI for entering information associated with a device security profile is shown in FIG. 7. The data associated with the DSP 312A may include requirements for displaying content of the content owner associated with the content owner device 302A at one or more resolution levels (e.g., SD, HD, 4K, etc.), or requirements for having one or more tags (e.g., new, drama, comedy, romance, etc., providing descriptive data regarding the characteristics of the content item). For example, the data associated with the DSP 312A may include the data shown in FIG. 4 and described below.

[0049] The user of the content owner device 302A inputs data associated with the DSP 312A into the GUI. The content owner device 302A transmits the data associated with the DSP 312A input into the GUI to the DRM server 304. The DRM server 304 generates the DSP 312A based on the data and stores the DSP 312A in the data associated with the content owner 310A. The DSP 312A specifies the requirements for client devices such as the client devices 308A and 308B to access the content items associated with the content owner 310A. The requirements may vary depending on the resolution level of the content item being accessed. For example, the requirements may be different when accessing SD content and when accessing the HD version of the same content. In an embodiment, the requirements for accessing the HD version of ABC-MOVIE are different from the requirements for accessing the 4K version of ABC-MOVIE. The DSPs 312B and 312C are obtained from the content owner devices 302B and 302C and are stored in the data associated with the content owners 310B and 310C using the techniques described herein for the DSP 312A.

[0050] The DRM server 304 distributes the DSPs 312A, 312B, and 312C to the content servers 306A and 306B that store the content of the associated content owners 310A, 310B, and 310C. As shown in the figure, the content server 306A stores the content of the content owners 310A and 310B but not the content of the content owner 310C. Therefore, the content server 306A receives the DSPs 312A and 312B but not the DSP 312C. Similarly, the content server 306B stores the content of the content owners 310B and 310C but not the content of the content owner 310A. Therefore, the content server 306B receives the DSPs 312B and 312C but not the DSP 312A. In other embodiments, more, fewer, or different content servers may store the content.

[0051] According to another embodiment, the DRM server 304 receives a pull request regarding DSP update from the content server 306A that stores content items associated with the content owners 310A, 310B. In response to the pull request, the DRM server 304 transmits the DSPs 312A, 312B that have been updated or added since the previous pull request to the content server 306A. With the transmitted DSPs 312A, 312B, the content server sets restrictions or conditions on the client devices that access the content items of the content owners 310A, 310B according to the DSPs 312A, 312B. Similarly, the content server 306B also transmits a pull request and receives the DSPs 312B, 312C of the content owners 310B, 310C whose content is stored in the content server 306B.

[0052] After receiving the DSP 312A of the content owner 310A, or simultaneously with the reception of the DSP 312A of the content owner 310A, the content server 306A receives a content request 314A for the content item 316A of the content owner 310A from the client device 308A. The content request 314A may be a license request, or may include a license request, and may include the hardware status and security status of the client device 308A. For example, the hardware status may include the manufacturer and model of the client device 308A (e.g., Apple iPhone XR (registered trademark), Google Pixel 4 (registered trademark), etc.), and signs of any changes to the hardware. The security status may include the version of the operating system and an indicator of any security patches installed on the client device 308A.

[0053] Content server 306A determines the resolution level (e.g., SD, HD, 4K, etc.) of content item 316A to be provided to client device 308A based on content request 314A and DSP 312A. For example, the resolution level can be determined by comparing the hardware status and security status of content request 314A with the requirements of various resolution levels (and any tags of content item 316A) specified in DSP 312A.

[0054] In some embodiments, content server 306A may determine, based on content request 314A and DSP 312A, that there is a risk that the requested version of the content item will not be provided to client device 308A, and can send a message to client device 308A notifying it that content item 316A is unavailable. Content server 306A can determine, based on DSP 312A, whether client device 308A can access content item 316A requested after software update, and can send a message advising the user of client device 308A to update the software.

[0055] In some embodiments, content server 306A can determine that multiple different resolution levels (e.g., SD or HD, but not 4K) of a requested content item may be provided to client device 308A based on content request 314A and DSP 312A. In some cases, the highest resolution level may be sent to client device 308A. In some cases, the resolution level may be selected based on at least one of the network download speed of client device 308A, the display function of client device 308A, the audio playback function of client device 308A, or the user account settings of the user account associated with client device 308A. Content server 306A may send content item 316A to client device 308A at the determined resolution level. Similarly, content server 306B receives content request 314B (which may be a license request or may include a license request) from client device 308B and, in response, sends content item 316B.

[0056] FIG. 4 is a block diagram showing an example of the data structure of DSP 312 (e.g., one of DSPs 312A, 312B, 312C). As shown, DSP 312 includes a resolution requirement data structure 402, a tag requirement data structure 404, and an exception data structure 406.

[0057] As shown, the resolution requirement data structure 402 indicates various resolutions (SD, HD, or 4K in this example) and the requirements that a client device needs to meet for a content owner to provide content at the associated resolution level. The requirements may include hardware requirements and security requirements. For example, the hardware requirements may include the manufacturer, model, and / or other hardware identifiers of the client device. The security requirements may include at least one indicator of the version of the operating system installed on the client device, the security policy, security patches, or software updates.

[0058] Similarly, the tag requirement data structure 404 indicates the requirements for tags (e.g., "New Release", etc.) that a client device needs to meet for a content owner to provide content that includes the shown tags. The exception data structure 406 indicates various devices for which exceptions to the requirements of data structures 402 and 404 may be provided. For example, a company that is both the manufacturer of the client device and the content owner may want to provide the highest resolution version of its content to client devices it manufactures, even if these devices lack certain required hardware or security features.

[0059] Figure 4 shows an example of the data structure of the DSP 312. In addition to, or instead of, the data structure shown in Figure 4, other data structures of the DSP 312 may be used. The resolution requirement data structure 402 and the tag requirement data structure 404 are shown as a table or a two-dimensional array. However, other types of data structures (e.g., linked lists, stacks, queues, etc.) may be used for the resolution requirement data structure 402, the tag requirement data structure 404, or both.

[0060] In an example usage scenario, a user of the content owner device 302A creates a DSP312A via the graphical user interface displayed on the content owner device 302A. The DSP312A specifies that in order to access the SD content of the content owner 310A, there must be Hardware A and Security Policy A on the client device accessing it. To access the HD content of the content owner 310A, there must be Hardware B and Security Policy B on the client device accessing it. To access the 4K content of the content owner 310A, there must be Hardware C and Security Policy C on the client device accessing it. To access the new releases of the content owner 310A, there must be Hardware D and Security Policy D on the client device accessing it. The DSP312A can also indicate exceptions for client devices of a specific manufacturer. For example, client devices manufactured by Manufacturer ABC can access all new releases or 4K content of the content owner 310A regardless of the hardware or security policy of the client device. The DSP312A is sent from the content owner device 302A to the DRM server 304 and stored in the DRM server 304 in a data structure associated with the content owner 310A.

[0061] The content server 306A stores content (e.g., video files and / or audio files) associated with the content owner 310A. The content server 306A sends a pull request regarding DSP updates to the DRM server 304. In response to the pull request regarding DSP updates, the DRM server 304 sends the DSP312A to the content server 306A. The content server 306A stores the DSP312A.

[0062] Continuing with the above example, client device 308A sends a content request 314A to content server 306A to access video DEF stored in content server 306A and associated with content owner 310A. Content request 314A includes hardware A, security policy A, security policy B, and security policy C in client device 308A, indicating that it is manufactured by manufacturer ABC. Content server 306A attempts to determine whether client device 308A is permitted to receive the SD, HD, or 4K version of video DEF. Based on the hardware of client device 308A (having hardware A, no hardware B, and no hardware C) and the security policy of the client device (having security policy A), content server 306A determines that client device 308A has access rights to the SD version of video DEF but does not have access rights to the HD and 4K versions of video DEF. Content server 306A determines whether there is a new release tag for video DEF. If it determines that there is no new release tag for video DEF, it determines that client device 308A can continue to access the SD version of video DEF but cannot access the HD and 4K versions. Content server 306A checks the exceptions of DSP 312A and determines whether client device 308A is eligible to obtain the SD, HD, or 4K version of video DEF based on the fact that client device 308A is manufactured by manufacturer ABC.

[0063] Content server 306A determines the network speed and display function of client device 308A, and determines whether to send the SD, HD, or 4K version of video DEF to the client device. For example, if it is determined that client device 308A has a display unit that can display SD and HD but cannot display 4K files, and client device 308A is connected to the cellular network at a download speed exceeding the minimum speed for HD transmission (e.g., 5 megabits per second), content server 306A can provide the HD version of video DEF to client device 308A. If client device 308A is manufactured by a manufacturer other than manufacturer ABC, client device 308A cannot receive the HD or 4K version of video DEF under DSP 312A (because hardware B and hardware C are not available), and client device 308A will receive the SD version of video DEF.

[0064] Figure 5 is a flowchart showing an example of a method 500 for providing a device security profile to a content server. Method 500 can be implemented by a DRM server such as DRM server 304 shown in FIG. 3, one or more of the computing and communication devices 100A, 100B, 100C shown in FIG. 2, or the computing device 100 shown in FIG. 1.

[0065] In block 502, the DRM server receives data associated with a DSP (e.g., DSP 312, 312A, 312B, 312C) from a content owner device (e.g., content owner devices 302A, 302B, 302C). The DSP specifies the requirements for a client device (e.g., client devices 308A, 308B) to access content items associated with the content owner. The requirements vary depending on the resolution level of the content item being accessed. The requirements may also vary depending on the tag of the content item being accessed (e.g., "new release"). The requirements may include hardware requirements and security requirements.

[0066] In block 504, the DRM server stores indications of the DSP and content owners (e.g., content owners 310A, 310B, 310C). The indications of the DSP and content owners may be stored in the memory of the DRM server (e.g., memory 110) or a data repository (e.g., database) that communicates with the DRM server. The DSP may include a first data structure (e.g., resolution requirement data structure 402) representing resolution levels and requirements for each resolution level. The DSP may include a second data structure (e.g., tag requirement data structure 404) representing tags of content items and requirements for each tag. The DSP may include a third data structure (e.g., exception data structure 406) representing a device configuration with exceptions to the requirements of the first data structure or the second data structure.

[0067] In block 506, the DRM server receives a pull request regarding DSP updates from a content server (e.g., content server 306A) that stores content items associated with the content owner. The content server may send a pull request regarding DSP updates when the network speed of the content server exceeds a threshold network speed, when the load on the processor of the content server is below a threshold load, or both. The pull request can be sent once per threshold period (e.g., once a day).

[0068] In block 508, the DRM server sends the DSP to the content server in response to the pull request. The DSP restricts the client devices that access the content items according to the DSP. In some embodiments, the DRM server receives an update of the DSP from the content owner device. The DRM server receives a second pull request from the content server. The DRM server sends an update of the DSP (or a version of the update of the DSP) to the content server in response to the second pull request.

[0069] In some embodiments, the DRM server pushes the DSP to the second content server. The push may occur, for example, when the second content server storing content items associated with the content owner fails to receive a pull request regarding DSP updates within a predetermined time or a defined period (e.g., one day or seven days).

[0070] FIG. 6 is a flowchart showing an example of a method 600 for processing a content request using a device security profile. The method 600 can be implemented by a content server such as one or more of the content servers 306A, 306B shown in FIG. 3, one or more of the computing and communication devices 100A, 100B, 100C shown in FIG. 2, or the computing device 100 shown in FIG. 1.

[0071] In block 602, the content server receives the DSP of the content owner (e.g., DSPs 312, 312A, 312B, 312C). The DSP specifies the requirements for a client device to access content items associated with the content owner. In some cases, the content server sends a pull request regarding DSP updates to the DRM server (DRM server 304) and receives the DSP of the content owner in response to the pull request. Alternatively, the DSP may be pushed from the DRM server to the content server.

[0072] In block 604, the content server receives a content request (e.g., content requests 314A, 314B) for a content item from a client device (e.g., client devices 308A, 308B). For example, a user of the client device can direct the client device to an application or web page associated with the content server and request content via the application or web page.

[0073] In block 606, the content server determines the resolution level of content items (e.g., content items 316A, 316B) to be provided to the client device based on the content request and the DSP. For example, the content server may compare the hardware status and security status of the client device as indicated in the content request with the hardware requirements and security requirements for providing the content at various resolution levels of the DSP.

[0074] In block 608, the content server transmits the content items to the client device at the determined resolution level. The client device can play or display the content items through the user interface of the client device (e.g., user interface 130).

[0075] In some embodiments, the content server sends a second pull request regarding the DSP update to the DRM server. In response to the second pull request, the content server receives an updated DSP for replacing the DSP or an update of the previously stored DSP. The content server replaces the DSP with the updated DSP in the memory of the content server (e.g., memory 110), or the content server incorporates the update into the DSP.

[0076] FIG. 7 is a diagram showing a GUI 700 for inputting information related to a DSP. The GUI 700 can be displayed on the content owner devices 302A, 302B, and 302C. As shown in the figure, the GUI 700 includes blocks for inputting the name of the DSP 702, the minimum device security level 704, the minimum version of the decryption software 706, the minimum copy protection version 708, whether the manufacturer / model has been verified 710, and whether copy generation management system (CGMS) output protection is required 712. The name of the DSP 702 can be any name selected by the user. The minimum device security level 704 can correspond to the minimum security level, such as the display of security software installed on the client device. The minimum version of the decryption software 706 can correspond to the version of the software associated with the media player or other application for displaying the content on the client device. The minimum copy protection version 708 may include the version of the copy protection installed on the client device (e.g., high-bandwidth digital content protection (HDCP)). Whether the manufacturer / model 710 to be verified can correspond to whether the content requests 314A, 314B from the client device indicate the manufacturer / model of the client device. Whether CGMS output protection is required 712 can indicate whether CGMS output protection is required on the client device.

[0077] FIG. 8 is a diagram showing a GUI 800 for displaying device exceptions to a DSP. The GUI 800 can be displayed on the content owner devices 302A, 302B, and 302C. As shown, the GUI 800 includes a table of exceptions that includes columns for a series name 802, a manufacturer 804, a system identifier (ID) 806, a permission list status 808, and an exception status 810. The GUI 800 also includes an "Add Additional Exception" button 812, and selecting this allows the user to add a row to the exceptions table. The column for the series name 802 displays the series name of the devices to which the exception applies. The column for the manufacturer 804 displays the manufacturer of the devices to which the exception applies. The column for the system ID 806 displays the system ID of the devices to which the exception applies. The column for the permission list status 808 displays the permission list status (e.g., permitted or blocked) of the devices to which the exception applies. The column for the exception status 810 displays whether an exception is set for the devices to which the exception applies. The user can use the drop-down menu in the column for the exception status 810 to select "Yes" or "No" (or "True" or "False" or similar options) to indicate whether to apply the exception listed for a particular row.

[0078] The GUIs 700, 800 show examples of information included in the hardware profile and security profile of the DSP. Not all of the information shown there is required in all DSPs. The DSP may include different information, more information, or less information.

[0079] FIG. 9 is a diagram showing a GUI 900 for searching for a DSP. The GUI 900 can be displayed on the content owner devices 302A, 302B, and 302C. As shown in the figure, the GUI 900 includes input boxes for searching for a DSP with a content provider name 902 and a DSP name 904. The GUI 900 includes dropdown menus for searching for a DSP with a production status 906, a device security level 908, a decryption software version 910, and a copy protection version 912. The GUI 900 includes radio buttons for selecting whether the manufacturer / model of the client device is verified 914, whether CGMS output protection is enabled on the client device 916, and whether known security vulnerabilities are permitted 918. The GUI 900 includes a search button 920. When the search button 920 is selected, the device (e.g., the content owner devices 302A, 302B, 302C) displaying the GUI 900 searches for the DSP associated with the content owner corresponding to the device (or the account logged in to the device) based on the content entered in any of the input boxes 902, 904, the dropdown menus 906, 908, 910, 912, and the radio buttons 914, 916, 918 (e.g., searches in local memory or causes a search to be executed on the DRM server 304). When searched, search results are generated. All or part of the generated search results can be displayed on the device (e.g., in a list format).

[0080] Some embodiments are described below as numbered examples (Example 1, 2, 3, etc.). These examples are provided only as examples and do not limit the disclosed technology.

[0081] Example 1 is to receive, at a digital rights management (DRM) server, data associated with a device security profile (DSP) from a content owner device, where the DSP specifies requirements for a client device to access content items associated with the content owner, the requirements varying depending on the resolution level of the accessed content item, to receive, at the DRM server, to store the DSP and an indication of the content owner, to receive, from a content server storing content items associated with the content owner, a pull request regarding DSP updates, and to send, in response to the pull request, the DSP to the content server, where the DSP includes sending to restrict the content server to client devices accessing the content items according to the DSP.

[0082] In Example 2, the subject matter of Example 1 includes a subject matter where the resolution level is based on at least one of the total number of pixels, the number of pixels per frame, or the pixel dimension measurement.

[0083] In Example 3, the subject matter of Example 1, Example 2, or both includes a subject matter where the resolution level includes at least one of standard definition (SD), high definition (HD), or 4K.

[0084] In Example 4, the subject matter of any of Examples 1 to 3 includes a subject matter where the requirements vary depending on tags of the accessed content items.

[0085] In Example 5, the subject matter of any of Examples 1 to 4 includes a subject matter where the requirements include hardware requirements and security requirements of a client device accessing the content item.

[0086] In Example 6, any of the themes of Examples 1 to 5 includes a theme in which the DSP includes a first data structure representing a resolution level and requirements for each resolution level, a second data structure representing tags of content items and requirements for each tag, and a third data structure representing a device configuration having an exception to the requirements of the first data structure or the requirements of the second data structure.

[0087] In Example 7, any of the themes of Examples 1 to 6 includes pushing the DSP to a second content server when a pull request regarding DSP update cannot be received from the second content server that stores content items associated with the content owner within a defined period.

[0088] In Example 8, any of the themes of Examples 1 to 7 includes receiving an update from a content owner device to the DSP, receiving a second pull request from the content server, and sending an update to the DSP or an updated version of the DSP to the content server in response to the second pull request.

[0089] In Example 9, any of the themes of Examples 1 to 8 includes sending code for generating a graphical user interface (GUI) for inputting data associated with the DSP to the content owner device, and generating a DSP at a DRM server based on the data associated with the DSP obtained at the content owner device via the GUI.

[0090] In Example 10, any of the themes of Examples 1 to 9 includes receiving the content owner's DSP at the content server, receiving a content request for a content item that is one of the content items associated with the content owner from a client device at the content server, determining a resolution level of the content item to be provided to the client device based on the content request and the DSP, and sending the content item from the content server to the client device at the determined resolution level.

[0091] Example 11 is a digital rights management (DRM) server including a processor that executes commands, where the commands include: a command to store instructions; a command to receive data associated with a device security profile (DSP) from a content owner device, where the DSP specifies requirements for a client device to access content items associated with the content owner, the requirements varying according to a resolution level of the accessed content item and including hardware requirements and security requirements of the client device accessing the content item; a command to store an indication of the DSP and the content owner; a command to receive a pull request regarding DSP updates from a content server storing content items associated with the content owner; and a command to send the DSP to the content server in response to the pull request, where the DSP causes the content server to restrict client devices accessing the content item according to the DSP.

[0092] In Example 12, the subject matter of Example 11 includes subject matter where the resolution level is based on at least one of the total number of pixels, the number of pixels per frame, or pixel dimension measurements.

[0093] In Example 13, the subject matter of Example 11, Example 12, or both includes subject matter where the resolution level comprises at least one of standard definition (SD), high definition (HD), or 4K.

[0094] In Example 14, the subject matter of any of Examples 11 to 13 includes subject matter where the requirements vary according to tags of the accessed content item.

[0095] In Example 15, any of the themes of Examples 11 to 14 includes a theme in which the DSP includes a first data structure representing a resolution level and requirements for each resolution level, a second data structure representing tags of content items and requirements for each tag, and a third data structure representing a device configuration having an exception to the requirements of the first data structure or the requirements of the second data structure.

[0096] In Example 16, any of the themes of Examples 11 to 15 includes a theme in which the processor executes an instruction to push the DSP to a second content server when the processor fails to receive a pull request regarding DSP update from the second content server that stores content items associated with a content owner within a predetermined time.

[0097] In Example 17, any of the themes of Examples 11 to 16 includes a theme in which the processor executes an instruction to receive an update from a content owner device to the DSP, an instruction to receive a second pull request from a content server, and an instruction to transmit an update to the DSP or an updated version of the DSP to the content server in response to the second pull request.

[0098] In Example 18, any of the themes of Examples 11 to 17 includes a theme in which the processor executes an instruction to transmit code for generating a graphical user interface (GUI) for inputting data associated with the DSP to a content owner device, and an instruction to generate a DSP at a DRM server based on the data associated with the DSP obtained at the content owner device via the GUI.

[0099] Example 19 involves a Digital Rights Management (DRM) server receiving data associated with a Device Security Profile (DSP) from a content owner device, where the DSP specifies requirements for a client device to access content items associated with the content owner, the requirements varying according to the resolution level of the accessed content item, the resolution level being based on at least one of the total number of pixels, the number of pixels per frame, or pixel dimension measurements, receiving; storing, in the DRM server, the DSP and an indication of the content owner; receiving, from a content server storing content items associated with the content owner, a pull request regarding a DSP update; and transmitting, in response to the pull request, the DSP to the content server, where the DSP includes instructions for the processor to perform operations including causing the content server to restrict client devices accessing the content items according to the DSP, and is a non-transitory computer-readable medium storing the instructions.

[0100] In Example 20, the subject matter of Example 19 includes subject matter where the resolution level comprises at least one of Standard Definition (SD), High Definition (HD), or 4K.

[0101] In Example 21, the subject matter of Example 19, Example 20, or both includes subject matter where the requirements vary according to tags of the accessed content items.

[0102] In Example 22, the subject matter of any of Examples 19 to 21 includes subject matter where the requirements comprise hardware requirements and security requirements of a client device accessing the content item.

[0103] Example 23 is to receive, at a content server, a device security profile (DSP) of a content owner, where the DSP specifies requirements for a client device to access content items associated with the content owner, the requirements differing according to the resolution of the accessed content item, including receiving, receiving, at the content server, a content request for a content item from the client device, determining, based on the content request and the DSP, a resolution level of the content item to provide to the client device, and transmitting the content item to the client device at the determined resolution level.

[0104] In Example 24, the subject matter of Example 10 or Example 23 includes transmitting a pull request regarding a DSP update and receiving, in response to the pull request, the DSP of the content owner.

[0105] In Example 25, the subject matter of Example 24 includes transmitting a second pull request regarding a DSP update, receiving, in response to the second pull request, an updated DSP that replaces the DSP or an update to the DSP, and replacing, in the memory of the content server, the DSP with the updated DSP or incorporating the update into the DSP.

[0106] In Example 26, the subject matter of Example 10 or any of Examples 23 to 25 includes a subject matter with a resolution level having at least one of standard definition (SD), high definition (HD), or 4K.

[0107] In Example 27, the subject matter of Example 10 or any of Examples 23 to 26 includes a subject matter where the requirements differ according to the tag of the accessed content item.

[0108] In Example 28, the subject matter of Example 10 or any of Examples 23 to 27 includes a subject matter where the requirements include hardware requirements and security requirements.

[0109] In Example 29, any of the themes of Example 10 or 23 to 28 includes a theme in which the DSP includes a first data structure representing a resolution level and requirements for each resolution level, a second data structure representing tags of content items and requirements for each tag, and a third data structure representing a device configuration having an exception to the requirements of the first data structure or the second data structure.

[0110] Example 30 is a content server that includes a memory for storing instructions, and a processor that executes instructions for receiving a device security profile (DSP) of a content owner, where the DSP specifies requirements for a client device to access content items associated with the content owner, the requirements varying depending on the resolution of the accessed content item, instructions for receiving a content request for a content item from the client device, instructions for determining a resolution level of the content item to provide to the client device based on the content request and the DSP, and instructions for transmitting the content item to the client device at the determined resolution level.

[0111] In Example 31, the theme of Example 30 includes a theme in which the processor executes instructions for sending a pull request regarding DSP update, and in response to the pull request, a DSP of the content owner is received.

[0112] In Example 32, the theme of Example 31 includes a theme in which the processor executes instructions for sending a second pull request regarding DSP update, instructions for receiving, in response to the second pull request, an updated DSP that replaces the DSP or an update to the DSP, and instructions for replacing the DSP with the updated DSP in the memory of the content server, or instructions for incorporating the update into the DSP.

[0113] In Example 33, any of the themes of Example 30 to 32 includes a theme in which the resolution level includes at least one of standard definition (SD), high definition (HD), or 4K.

[0114] In Example 34, any one of the themes of Examples 30 to 33 includes themes with different requirements depending on the tags of the accessed content items.

[0115] In Example 35, any one of the themes of Examples 30 to 34 includes themes with requirements that include hardware requirements and security requirements.

[0116] In Example 36, any one of the themes of Examples 30 to 35 includes themes where the DSP includes a first data structure representing the resolution level and requirements for each resolution level, a second data structure representing the tags of the content items and requirements for each tag, and a third data structure representing a device configuration having exceptions to the requirements of the first data structure or the second data structure.

[0117] Example 37 is a non - transitory computer - readable medium storing instructions that cause a processor to perform operations including receiving, at a content server, a device security profile (DSP) of a content owner, where the DSP specifies requirements for a client device to access content items associated with the content owner, the requirements differing depending on the resolution of the accessed content items; receiving, at the content server from the client device, a content request for a content item; determining, based on the content request and the DSP, a resolution level of the content item to provide to the client device; and transmitting the content item to the client device at the determined resolution level.

[0118] In Example 38, the theme of Example 37 includes operations including transmitting a pull request regarding DSP update, where the DSP of the content owner is received in response to the pull request.

[0119] In Example 39, the subject matter of Example 38 includes operations of sending a second pull request regarding DSP update, receiving an updated DSP that replaces the DSP or the update to the DSP in response to the second pull request, and replacing the DSP with the updated DSP or incorporating the update into the DSP within the memory of the content server.

[0120] In Example 40, the subject matter of any one of Examples 37 to 39 includes a subject matter having at least one of standard definition (SD), high definition (HD), or 4K resolution levels.

[0121] In Example 41, the subject matter of any one of Examples 37 to 40 includes a subject matter with different requirements depending on the tags of the accessed content items.

[0122] In Example 42, the subject matter of any one of Examples 37 to 41 includes a subject matter with requirements including hardware requirements and security requirements.

[0123] Example 43 is a system including a processing circuit configured to execute the method described in any one of Examples 1 to 10 or 23 to 29.

[0124] The terms "example", "embodiment", and "aspect" are used herein to mean serving as an example, instance, or illustration. Any aspect or design described herein as an "example", "embodiment", or "aspect" should not necessarily be construed as more preferable or advantageous than other aspects or designs. Rather, the use of these terms is intended to present concepts in a concrete manner. As used in this application, the term "or" is intended to mean an inclusive "or" rather than an exclusive "or". That is, unless otherwise specified or clear from the context, "X includes A or B" is intended to mean a natural inclusive substitution. That is, "X includes A or B" is satisfied in any of the following cases: when X includes A, when X includes B, or when X includes both A and B. Further, the articles "a" and "an" used in this application and the appended claims should generally be construed to mean "one or more" unless specifically specified otherwise or it is clear from the context that they refer to the singular form. Further, the use of the terms "embodiment" or "implementation" is not intended to mean the same embodiment or implementation unless so described as such. The terms "determine" and "identify" used herein, or any variant thereof, include identifying or determining by selection, confirmation, calculation, search, reception, determination, establishment, acquisition, or other means using one or more devices shown in FIG. 1.

[0125] Further, for the sake of simplicity of explanation, the figures and descriptions in this specification may include a series of steps or stages, but the elements of the methods disclosed herein can occur in various orders and / or simultaneously. Further, the elements of the methods disclosed herein may occur with other elements not explicitly presented and described herein. Further, one or more of the elements of the methods described herein may be omitted from embodiments of the methods in accordance with the disclosed subject matter.

[0126] Embodiments of the computing and communication device 100A for transmitting and / or the computing and communication device 100B for receiving (and algorithms, methods, instructions, etc. stored therein and / or executed thereby) can be realized by hardware, software, or any combination thereof. The hardware can include, for example, a computer, an intellectual property (IP) core, an application specific integrated circuit (ASIC), a programmable logic array, an optical processor, a programmable logic controller, microcode, a microcontroller, a server, a microprocessor, a digital signal processor, or any other suitable circuit. In the claims, the term "processor" should be understood to include any of the foregoing hardware alone or in combination. The terms "signal" and "data" are used in the same meaning. Further, each part of the computing and communication device 100A for transmitting and the computing and communication device 100B for receiving does not necessarily have to be implemented in the same way.

[0127] Furthermore, in some embodiments, for example, the computing and communication device 100A for transmitting or the computing and communication device 100B for receiving can be implemented using a computer program that executes any of the respective methods, algorithms, and / or instructions described herein at runtime. Further, or alternatively, for example, a special-purpose computer / processor including special hardware for executing any of the methods, algorithms, or instructions described herein can be utilized.

[0128] Furthermore, all or part of an embodiment can take the form of, for example, a tangible computer-usable medium or a computer program product accessible from a computer-readable medium. A computer-usable medium or a computer-readable medium is any device that can tangibly store, store, communicate, or transfer a program for use by or in connection with any processor. Examples of the medium include electronic devices, magnetic devices, optical devices, electromagnetic devices, or semiconductor devices. Other suitable media are also available.

[0129] It will be understood that the embodiments can be implemented in any convenient form. For example, an embodiment may be implemented by an appropriate computer program, and the appropriate computer program may be executed on an appropriate carrier medium, which may be a tangible carrier medium (such as a disk) or an intangible carrier medium (such as a communication signal). An embodiment can also be implemented using an appropriate device that can take the form of a programmable computer that executes a computer program configured to implement the methods and / or techniques disclosed herein. Embodiments can be combined so that functions described in the context of one embodiment can be implemented in another.

[0130] The above embodiments are described to facilitate understanding of the present application and are not limiting. Rather, the present application covers various modifications and equivalent arrangements included within the scope of the appended claims, and the scope should be given the broadest interpretation so as to include all such modifications and equivalent structures permitted by law.

Claims

1. In a digital rights management (DRM) server, receiving data associated with a device security profile (DSP) from a content owner device, wherein the DSP specifies requirements regarding a client device for accessing a content item associated with the content owner, and the requirements vary depending on a resolution level of the content item to be accessed; receiving storing, in the DRM server, the DSP and an indication of the content owner; receiving, from a content server storing the content item associated with the content owner, a pull request regarding DSP update; in response to the pull request, sending the DSP to the content server, wherein the DSP is configured to cause the content server to restrict access to the content item by a client device according to the DSP; sending A method comprising the above.

2. The method according to claim 1, wherein the resolution level is based on at least one of the total number of pixels, the number of pixels per frame, or a pixel dimension measurement.

3. The method according to claim 1, wherein the resolution level includes at least one of standard definition (SD), high definition (HD), or 4K.

4. The method according to claim 1, wherein the requirements vary depending on a tag of the accessed content item.

5. The method according to claim 1, wherein the requirements regarding the client device include at least one requirement selected from the group consisting of hardware requirements, security requirements, or a combination thereof for each client device accessing a certain content item among the content items.

6. The DSP is A first data structure representing a resolution level and the requirements for each resolution level, A second data structure representing a tag of a content item and the requirements for each tag, A third data structure representing a device configuration having an exception to the requirements of the first data structure or the requirements of the second data structure The method according to claim 1, comprising: **Claim 7** When a pull request regarding the DSP update cannot be received from a second content server that stores the content items associated with the content owner within a predetermined time, pushing the DSP to the second content server, the method according to claim 1. **Claim 8** Receiving an update to the DSP from the content owner device, Receiving a second pull request from the content server, In response to the second pull request, sending the update to the DSP or an updated version of the DSP to the content server, The method according to claim 1, comprising: **Claim 9** Sending code for generating a graphical user interface (GUI) for inputting the data associated with the DSP to the content owner device, Generating, in the DRM server, the DSP based on the data associated with the DSP obtained in the content owner device via the GUI The method according to claim 1, comprising: **Claim 10** Receiving, in the content server, the DSP regarding the content owner, In the content server, receiving a content request regarding a content item from a client device, where the content item is one of the content items associated with the content owner; determining, based on the content request and the DSP, a resolution level of the content item for providing to the client device; transmitting the content item from the content server to the client device at the determined resolution level; The method according to claim 1, comprising: **Claim 11** at least one memory storing instructions; at least one processor that executes the instructions to implement the method according to any one of claims 1 to 10; A computer system comprising: **Claim 12** A computer-readable storage medium storing instructions operable to cause one or more processors to implement the method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Data communication method, client, gateway, server, service processing unit, relay terminal and recording medium recording its communication program

    JP2001251341A

  • Method and apparatus for content service

    US20080168132A1

  • Methods and apparatus for device capabilities discovery and utilization within a content distribution network

    US20170055013A1

  • Method and apparatus for storing base and additive streams of video

    US7733956B1