Secure handling of media content for a group of users
A security framework using placeholder media objects and tokens within TEEs enables secure distribution of media content to a limited group of users, addressing the challenges of controlled access and exposure in existing technologies.
Patent Information
- Application Number
- PCT/EP2024/060243
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-16
- Publication Date
- 2025-10-23
AI Technical Summary
Existing methods struggle to securely distribute media content to a limited group of users without requiring separate transmissions to each device and without exposing the content to uncontrolled media platforms.
A security framework is implemented using a media server device and a media storage device, where placeholder media objects and tokens are used to enable secure access to media content within a Trusted Execution Environment (TEE) of communication devices, allowing controlled distribution and encryption of content.
Media content is securely distributed to a limited group of users, maintaining control over content exposure and distribution channels, while ensuring security and privacy.
Smart Images

Figure EP2024060243_23102025_PF_FP_ABST
Abstract
Description
[0001] SECURE HANDLING OF MEDIA CONTENT FOR A GROUP OF USERS
[0002] TECHNICAL FIELD
[0003] Embodiments presented herein relate to methods, a media server device, a media storage device, a communication device, computer programs, and a computer program product for secure handling of media content.
[0004] BACKGROUND
[0005] Media content, such as digital, or digitized, images, audio, and videos, can be shared among users on the Internet in several ways, and the growth of content-sharing media platforms (including and e-gaming platforms) has been significant over the last decade. Sharing of media content may be performed for different purposes. For example, some media content (e.g., public information or news) could be targeted to be shared with anyone. However, some media content may in many cases be targeted to attract a certain audience, where the publisher of the media content has a certain purpose with the media content sharing. Several media platforms have vast statistics capabilities, where the media platform owner and / or the content creator can collect a large amount of information on published media content, e.g., viewing statistics (such as number or views, length of views, etc. per media content) as well as potential reactions in terms of e.g., so-called likes, forwarding of media content to other users, and user comments. In general terms, a media platform refers to any technology or service that enables the distribution, sharing, and consumption of media content to users of the media platform. The media content can range from text, audio, video, and interactive media. Media platforms can be categorized into various types based on their primary mode of content delivery and interaction. For the present disclosure, the media platform is assumed to be a digital media platform (sometimes referred to as a New Media Platform. This category of media platforms encompasses a broad range of internet-based platforms that allow for the creation, sharing, and consumption of content. One non-limiting example is media platforms associated with Social Media Networks, i.e., media platforms (e.g., Facebook, X (formerly known as Twitter), Instagram, or the like) that facilitate social interaction and content sharing among its users.
[0006] Unwanted spreading of media content can, to some extent, be limited by the use of Digital Rights Management (DRM) tools. For example, it is common for communication devices and media servers to support so-called secure content path for DRM -protected media content. In this respect, a secure memory buffer is setup inside a trusted execution environment (TEE) of the communication devices that receive the media content from the media server. This secure memory buffer is inaccessible to the normal operating system of the communication device. The media is decrypted in the trusted memory and all affected hardware blocks are configured to read and write to these trusted memory buffers. In this way, the media content is not accessible to outside the TEE in the communication devices, and a communication device may therefore not forward the media content to another communication device.
[0007] For example, in US10754930B2 is disclosed a remotely managed TEE for digital rights management in a distributed network with thin clients. A DRM system is implemented that maintains the security of content entrusted to it, including completing the customer authentication process in a TEE located within the customer's set-top box.
[0008] Further, in US9866376B2 is disclosed a method for provisioning cryptographic data to electronic devices using so-called delegation messages. A delegation message is generated at a provisioning server. The delegation message indicates provisioning rights delegated by the provisioning server to other provisioning servers for later provisioning cryptographic assets to an electronic device.
[0009] However, there could be situations where a media content providing device requests media content to be made available only to a limited group of users. One way to accomplish this is to make separate transmissions of the media content from the media content providing device to the communication devices each of these users. However, in addition to requiring network resources for these transmissions, the media content providing device also needs to ensure that the media content is handled in a secure manner at each of the receiving communication devices. One way to overcome this would be for the media content providing device to publish the media content on a media platform with instructions that limits the users the media content is exposed to. However, although this resolves the issue of the media content providing device not having to make separate transmissions to each of the communication devices, it implies that the media content needs to be sent to the media platform, which is not under control of the media content providing device.
[0010] Hence, there is still a need for an improved handling of media content, targeted for a limited group of users.
[0011] SUMMARY
[0012] An object of embodiments herein is to make media content available to a limited group of users in a secure way, without requiring separate transmissions of the media content from the media content providing device to each of these users, and without having to publish the content on a (public) media platform.
[0013] A particular object is to provide a security framework for utilizing media platforms for handling of media content, without the media content actually being exposed to the media platform.
[0014] According to a first aspect there is presented a method for secure handling of media content. The method is performed by a media server device. The method comprises receiving information from a media storage device of availability of media content for a first group of users of a media service provided by the media server device. The method comprises providing a placeholder media object of the media content for accessing the media content and a token to a communication device associated with the first group of users upon having verified that the communication device comprises a TEE for processing the media content. The token indicates that the communication device is allowed to access the media content.
[0015] According to a second aspect there is presented a media server device for secure handling of media content. The media server device comprises processing circuitry. The processing circuitry is configured to cause the media server device to receive information from a media storage device of availability of media content for a first group of users of a media service provided by the media server device. The processing circuitry is configured to cause the media server device to provide a placeholder media object of the media content for accessing the media content and a token to a communication device associated with the first group of users upon having verified that the communication device comprises a TEE for processing the media content. The token indicates that the communication device is allowed to access the media content.
[0016] According to a third aspect there is presented a computer program for secure handling of media content, the computer program comprising computer program code which, when run on processing circuitry of a media server device, causes the media server device to perform actions. One action comprises the media server device to receive information from a media storage device of availability of media content for a first group of users of a media service provided by the media server device. One action comprises the media server device to provide a placeholder media object of the media content for accessing the media content and a token to a communication device associated with the first group of users upon having verified that the communication device comprises a TEE for processing the media content. The token indicates that the communication device is allowed to access the media content.
[0017] According to a fourth aspect there is presented a method for secure handling of media content. The method is performed by a media storage device. The method comprises receiving media content from a media content providing device. The method comprises providing information to a media server device of availability of the media content for a first group of users of a media service provided by the media server device. The method comprises receiving a request for accessing the media content from a communication device. The request comprises a token. The method comprises providing the media content in encrypted form to a TEE in the communication device upon having verified the token and that the communication device is associated with the first group of users.
[0018] According to a fifth aspect there is presented a media storage device for secure handling of media content. The media storage device comprises processing circuitry. The processing circuitry is configured to cause the media storage device to receive media content from a media content providing device. The processing circuitry is configured to cause the media storage device to provide information to a media server device of availability of the media content for a first group of users of a media service provided by the media server device. The processing circuitry is configured to cause the media storage device to receive a request for accessing the media content from a communication device. The request comprises a token. The processing circuitry is configured to cause the media storage device to provide the media content in encrypted form to a TEE in the communication device upon having verified the token and that the communication device is associated with the first group of users.
[0019] According to a sixth aspect there is presented a computer program for secure handling of media content, the computer program comprising computer program code which, when run on processing circuitry of a media storage device, causes the media storage device to perform actions. One action comprises the media storage device to receive media content from a media content providing device. One action comprises the media storage device to provide information to a media server device of availability of the media content for a first group of users of a media service provided by the media server device. One action comprises the media storage device to receive a request for accessing the media content from a communication device. The request comprises a token. One action comprises the media storage device to provide the media content in encrypted form to a TEE in the communication device upon having verified the token and that the communication device is associated with the first group of users.
[0020] According to a seventh aspect there is presented a method for secure handling of media content. The method is performed by a communication device. The communication device comprises a TEE. The method comprises receiving a placeholder media object of media content for accessing the media content and a token from a media server device providing a media service to a user of the communication device. The token indicates that the communication device is allowed to access the media content. The method comprises storing at least part of the placeholder media object in the TEE. The method comprises providing a request and the token to a media storage device for the communication device to access the media content. The method comprises, in response thereto, receiving the media content in encrypted form from the media storage device. The method comprises filling the placeholder media object with the media content in encrypted form in the TEE.
[0021] According to an eighth aspect there is presented a communication device for secure handling of media content. The communication device comprises a TEE and processing circuitry. The processing circuitry is configured to cause the communication device to receive a placeholder media object of media content for accessing the media content and a token from a media server device providing a media service to a user of the communication device. The token indicates that the communication device is allowed to access the media content. The processing circuitry is configured to cause the communication device to store at least part of the placeholder media object in the TEE. The processing circuitry is configured to cause the communication device to provide a request and the token to a media storage device for the communication device to access the media content. The processing circuitry is configured to cause the communication device to, in response thereto, receive the media content in encrypted form from the media storage device. The processing circuitry is configured to cause the communication device to fill the placeholder media object with the media content in encrypted form in the TEE.
[0022] According to a ninth aspect there is presented a computer program for secure handling of media content, the computer program comprising computer program code which, when run on processing circuitry of a communication device comprising a TEE, causes the communication device to perform actions. One action comprises the communication device to receive a placeholder media object of media content for accessing the media content and a token from a media server device providing a media service to a user of the communication device. The token indicates that the communication device is allowed to access the media content. One action comprises the communication device to store at least part of the placeholder media object in the TEE. One action comprises the communication device to provide a request and the token to a media storage device for the communication device to access the media content. One action comprises the communication device to, in response thereto, receive the media content in encrypted form from the media storage device. One action comprises the communication device to fill the placeholder media object with the media content in encrypted form in the TEE.
[0023] According to a tenth aspect there is presented a computer program product comprising a computer program according to at least one of the third aspect, the sixth aspect, and the ninth aspect and a computer readable storage medium on which the computer program is stored. The computer readable storage medium can be a non- transitory computer readable storage medium. Advantageously, these aspects enable the media content to be made available to a limited group of users in a secure way, such as with access limitations to the media content as defined by the media content providing device.
[0024] Advantageously, these aspects enable the media content to be made available to a limited group of users without the media content needing to be published at the media server device (representing a media platform). This enables the user of the media content providing device to retain control of the media content whilst enabling the media content to be shared using the media server device’s distribution channels.
[0025] Advantageously, these aspects can be used to utilize the media platform (as represented by the media server device) to set up security framework for provision of media content, without the media content actually being exposed to the media platform.
[0026] Advantageously, these aspects enable the media storage device to be in control of the exposure of the media content - without having to expose the media content to the media server device - but utilizing the media server device to facilitate the setup of TEEs in the communication devices consuming the media content.
[0027] Other objectives, features and advantages of the enclosed embodiments will be apparent from the following detailed disclosure, from the attached dependent claims as well as from the drawings.
[0028] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, apparatus, component, means, module, step, etc." are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, module, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated.
[0029] BRIEF DESCRIPTION OF THE DRAWINGS
[0030] The inventive concept is now described, by way of example, with reference to the accompanying drawings, in which: Fig. 1 is a schematic diagram illustrating an electronic media communication system according to embodiments;
[0031] Figs. 2, 3, and 4 are flowcharts of methods according to embodiments;
[0032] Fig. 5 is a signaling diagram of a method for secure handling of media content according to an embodiment;
[0033] Fig. 6 is a schematic diagram showing structural units of a media server device according to an embodiment;
[0034] Fig. 7 is a schematic diagram showing structural units of a media storage device according to an embodiment;
[0035] Fig. 8 is a schematic diagram showing structural units of a communication device according to an embodiment; and
[0036] Fig. 9 shows one example of a computer program product comprising computer readable means according to an embodiment.
[0037] DETAILED DESCRIPTION
[0038] The inventive concept will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the inventive concept are shown. This inventive concept may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided by way of examples so that this disclosure will be thorough and complete, and will fully convey the scope of the inventive concept to those skilled in the art. Like numbers refer to like elements throughout the description. Any step or feature illustrated by dashed lines should be regarded as optional.
[0039] Fig. 1 is a schematic diagram illustrating an electronic media communication system 10 where embodiments presented herein can be applied. The electronic media communication system 10 comprises media handling devices in terms of a media server device 100 and a media storage device 200 as well as communication devices 300, 400, 500. As a non-limiting example, the media server device 100 might provide content of a media platform to users of the communication devices 300, 400, 500. As previously disclosed, the media platform refers to any technology or service that enables the distribution, sharing, and consumption of media content to users of the media platform. The media server device 100 controls the operation of the media platform in terms of media content sharing to users of the media platform. Each of the communication devices 300, 400, 500 might therefore be configured to run a media application belonging to the media server device 100. Each of the communication devices 300, 400, 500 might for this purpose, as well as for other purposes, be provided with a user interface for displaying, or otherwise playing out, media content as belonging to the media application. The media content can range from text, audio, video, and interactive media. In some non-limiting examples, each of the communication devices 300, 400, 500 is a user equipment (UE) such as a smartphone, a tablet computer, a laptop computer, or any other type of communication device being provided with the capabilities required to implement the embodiments as disclosed herein. The media storage device 200 can be regarded as a cloud storage entity and is configured to store media content as provided by one or more of the communication devices 300, 400, 500.
[0040] Without loss of generality, it will hereinafter be assumed that communication device 400 will upload media content (ranging from text, audio, video, and interactive media) to the media storage device 200. The communication device 400 will therefore be referred to as a media content providing device 400. It will further be assumed that the communication device 400 is in control of the media storage device 200 but that neither communication device 300 nor communication device 500 is in control of the media storage device 200.
[0041] Without loss of generality, it will hereinafter further be assumed that the communication devices 300, 500 belong to different, distinct, groups of users. Specifically, the communication device 300 represents a communication device that belongs to a user in a first group of users, and the communication device 500 represents a communication device that belongs to a user in a second group of users, distinct from the first group of users. The first and second groups of users can be defined by the user of the media content providing device 400 (e.g., specifying user names, user account information, or other type of identification data). Alternatively, the first and second groups of users can be defined by the media server device 100 based on requirements received from the media content providing device 400 (e.g., age of users, sexual identity of users, location of users, etc.).
[0042] Reference is now made to Fig. 2 illustrating a method for secure handling of media content as performed by the media server device 100 according to an embodiment.
[0043] S102: The media server device 100 receives information from a media storage device 200 of availability of media content for a first group of users of a media service, where the media service is provided by the media server device 100.
[0044] As will be further disclosed below, the media storage device 200 sends this information to the media server device 100 once the media storage device 200 has received media content from the media content providing device 400.
[0045] S106: The media server device 100 provides a placeholder media object of the media content for accessing the thus protected media content and a token to a communication device 300 associated with the first group of users upon having verified that the communication device 300 comprises a TEE for processing the media content.
[0046] There could be different examples of tokens. In general terms, token can be used to secure and authorize access to resources, such as media content, without exposing user credentials. In further detail, the token might be embodied as a string of characters representing an authorization issued to the communication device 300. As will be disclosed in further detail below, the token grants the communication device 300 access to the media content on the media storage device 200. In other words, the token might be scoped, meaning that the token grant permission to access only specific media content. In some non-limiting examples, the token is an OAuth 2.0 token.
[0047] In general terms, a TEE is a segregated area of memory and processing circuitry in the communication device 300 that, using encryption, is protected from the rest of the processing circuitry in the communication device 300. Data in the TEE cannot be read or altered by any entity outside that the TEE. The token indicates that the communication device 300 is allowed to access the media content. In this way, the communication device 300 is provide with a media placeholder object for media content that is to be rendered inside the TEE. The placeholder object might for this purpose specify properties that describe the position of the layer for rendering the media content, how the media content is to be presented, e.g., crop, scale, rotate, flip; composition information of how the media content is to be composited with other layers, etc.
[0048] It is understood that the placeholder media object needs to be created in order for the media server device 100 to provide the placeholder media object to the communication device 300. In this respect, the media server device 100 could create the placeholder media object as a reaction to the media storage device 200 informing the media server device 100 that the media content is accessible. In other alternatives, the placeholder media object is created by the media storage device 200 and received by the media server device 100 from the media storage device 200 together with the information of the availability of the media content for the first group of users.
[0049] Embodiments relating to further details of handling media content as performed by the media server device 100 will now be disclosed with continued reference to Fig. 2.
[0050] In some embodiments, the information received by the media storage device 200 comprises a link to the media content. This link can then be provided together with the placeholder media object to the communication device 300 in step S106. The communication device 300 could then request the media content by following the link. In some non-limiting examples, the link is a hyperlink.
[0051] In some aspects, the media server device 100 verifies that the TEE has been set up correctly in the communication device 300 before providing the placeholder media object to the communication device 300 in step S106. That is, in some embodiments, the media server device 100 is configured to perform (optional) step S104.
[0052] S104: The media server device 100 obtains information of attested setup of the TEE in the communication device 300 before providing the placeholder media object to the communication device 300. In some embodiments, the information indicates that a private key of an asymmetric key pair is accessible to the TEE but not outside the TEE. Further, the attestation might be performed by the media server device 100 itself or by an attestation device that is trusted by the media server device 100 and the TEE.
[0053] In other aspects, the media server device loo abstains from verifying that the TEE has been set up correctly in the communication device 300. Then, in case the TEE has not been set up correctly in the communication device 300, the communication device 300 would not be able to access the media content in clear-text form since, as will be disclosed below, the media content is sent to the communication device 300 in encrypted form, where the key material needed to decrypt the media content to cleartext form only is available inside the TEE.
[0054] In some aspects, the media server device 100 communicates an identifier (ID) of the placeholder media object to the media storage device 200. Therefore, in some embodiments, the media server device 100 is configured to perform (optional) step S108.
[0055] S108: The media server device 100 provides an identifier (e.g., an alphanumeric string) of the placeholder media object to the media storage device 200.
[0056] This simplifies further communication between the media server device 100 and the media storage device 200 with respect to both the placeholder media object itself and the media content.
[0057] As will be further disclosed below, once the communication device 300 has gained access to the media content, the communication device 300 might, for example, display, or otherwise play out, the media content to the user of the communication device 300. In response thereto, the user of the communication device 300 might provide different types of feedback to the communication device 300 about the media content. Any such information (e.g., that the media content has been displayed or played-out, as well as the aforementioned feedback) might be collected by the communication device 300. This information as received by the media server 100 will hereinafter be referred to as engagement patterns. In some non-limiting examples, the engagement patterns comprise details pertaining to any, or any combination of number of views of the media content, total viewing time of the media content, feedback information from the first group of users with respect to the media content. The engagement patterns can be provided to the media server 100, either upon request from the media server or pushed by the communication device 300. In particular, in some embodiments, the media server device 100 is configured to perform (optional) step S110.
[0058] S110: The media server device 100 obtains information of engagement patterns of the first group of users with respect to the media content. The engagement patterns may be transmitted from one or more communication devices 300 to the media server device 100 using any communication protocol setup for the control signaling inbetween the media server device 100 and the one or more communication devices 300 .
[0059] Further, the media server device 100 might provide this information to the media storage device 200. Thus, in some embodiments, the media server device 100 is configured to perform (optional) step S112.
[0060] S112: The media server device 100 forwards the information of the engagement patterns to the media storage device 200.
[0061] Actions taken by the media storage device 200 upon having obtained the information of the engagement patterns from the media server device 100 will be disclosed below.
[0062] Further, the media server device 100 might itself use the engagement patterns to update the placeholder media object. Therefore, in some embodiments, the media server device 100 is configured to perform (optional) step S114.
[0063] S114: The media server device 100 updates the placeholder media object to comprise information of the engagement patterns of the media content.
[0064] In this way, when the placeholder media object is sent to another communication device, this communication device will gain access to the engagement patterns. Details of the engagement patterns can then be displayed, or other ways provided, on a user interface of this communication device.
[0065] In some aspects, and as will be disclosed in further detail below, the media storage device 200 determines that the media content is to be made available also to a second group of users (in addition to the first group of users). Hence, in some embodiments, the media server device 100 is configured to perform (optional) step Sn6.
[0066] Sn6: The media server device 100 receives the media content from the media storage device 200 for the media content to be made available to the first group of users as well as a second group of users.
[0067] In this respect, the second group of users might be either explicit or implicit. For example, the second group of users might comprise all users of a certain media platform that the media server device 100 hosts. For example, the second group of users might be defined by information received from the media storage device 200 and / or from the media content providing device 400.
[0068] The media server device 100 could then populate the placeholder media object with the media content and expose the placeholder media object to the communication devices 300 associated with the first group of users as well as to communication devices 500 associated with a second group of users, as in step S118. Populating the placeholder media object with the media content could comprise, e.g., removing the hyperlink to the media storage device 200 and replacing the hyperlink with the actual media content. Alternatively, the hyperlink may be replaced by a link pointing to the address of the media content stored on the media storage device 100.
[0069] S118: The media server device 100 publishes the media content to the communication device 300 associated with the first group of users as well as to a communication device 500 associated with the second group of users.
[0070] Here, the media server device 100 could make the media content part of its database of media content that is available to all users of the first group of users and the second group of users. Hence, in this way, the media content is made available to the first group of users via the media server device 100. This is in contrast to step S106 according to the media content was made available to the first group of users via the media storage device 200.
[0071] In other aspects, and as will be disclosed in further detail below, the media storage device 200 determines that the media content is not to be made available any longer. As a consequence of this, the placeholder media object of the media content should no longer be available to the first group of users. In particular in some embodiments, the media server device 100 is configured to perform (optional) steps S120 and S122.
[0072] S120: The media server device 100 receives instructions from the media storage device 200 to stop distributing the placeholder media object of the media content.
[0073] S122: The media server device 100 removes the placeholder media object in response thereto (i. e. , in response to having received the instructions).
[0074] In some examples, the media server 100 could further instruct any communication device 300 having received the placeholder media object to remove the placeholder media object from its storage and TEE.
[0075] Reference is now made to Fig. 3 illustrating a method for secure handling of media content as performed by the media storage device 200 according to an embodiment.
[0076] It is assumed that the media storage device 200 receives information a media content providing device 400 that media content is to be published for a first group of users, as in steps S202 and S206.
[0077] S202: The media storage device 200 receives media content from a media content providing device 400.
[0078] The media storage device 200 then uses the media server device 100 as a proxy for notifying the first group of users that the media content is available, as in step S206.
[0079] S206: The media storage device 200 provides information to the media server device 100 of availability of the media content for a first group of users of a media service provided by the media server device 100.
[0080] It is further assumed that the communication device 300 belonging to a user in the first group of users requests access to the media content, as in step S210.
[0081] S210: The media storage device 200 receives a request for accessing the media content from a communication device 300. The request comprises a token. In general terms, the token is a proof that the communication device 300 (or more precisely: a TEE in the communication device 300) is allowed to access the media content, further aspects of the token will be disclosed below. As previously disclosed, the token was issued to the communication device 300 by the media server device 100.
[0082] S218-2: The media storage device 200 provides the media content in encrypted form to a TEE in the communication device 300 upon having verified the token and that the communication device 300 is associated with the first group of users.
[0083] Embodiments relating to further details of handling media content as performed by the media storage device 200 will now be disclosed with continued reference to Fig.
[0084] 3-
[0085] As disclosed above, in some embodiments, the information received by the media storage device 200 comprises a link to request the media content. As further disclosed above, the link can then be provided together with the placeholder media object to the communication device 300 in step S106. The communication device 300 could then request the media content by following the link. In some non-limiting examples, the link is a hyperlink.
[0086] As disclosed in step S218-2, the media content is provided in encrypted form to the TEE in the communication device 300. In this respect the media content is only to be available in clear-text form inside the TEE. In general terms, this requires the communication device 300 to be able to decrypt (thus encrypted) media content only inside the TEE. In turn, this requires key material for the decryption to be provided to the TEE in a secure manner. One embodiment to achieve this involves the media storage device 200 to perform (optional) steps S212. S214, S216, S218-4 upon having received the request in step S210.
[0087] S212: The media storage device 200 creates at least one content encryption key to protect the media content.
[0088] S214: The media storage device 200 protects the at least one content encryption key with a public key of an asymmetric key pair where the corresponding private key is accessible by the TEE.
[0089] S216: The media storage device 200 encrypts the media content with the at least one content encryption key. S218-4: The media storage device 200 provides the at least one protected content encryption key to the TEE.
[0090] In some embodiments, the at least one content encryption key is created upon the media storage device 200 having verified that the token indicates existence of a TEE in the communication device 300.
[0091] As disclosed above, the media server device 100 might communicate an ID of the placeholder media object to the media storage device 200. Therefore, in some embodiments, the media storage device 200 is configured to perform (optional) step S208.
[0092] S208: The media storage device 200 receives an identifier of a placeholder media object of the media content from the media server device 100.
[0093] One purpose of the media content being published for the first group of users is for the media storage device 200 to obtain engagement patterns of the first group of users with respect to the media content. These engagement patterns could then be compared to one or more publishing criterion with respect to whether the media content is to be published also for a second group of users. The media storage device 200 might therefore receive, be configured with, or otherwise obtain at least one such publishing criterion. Hence, in some embodiments, the media storage device 200 is configured to perform (optional) step S204.
[0094] S204: The media storage device 200 obtains a publishing criterion for publishing the media content for a second group of users.
[0095] The publishing criterion might pertain to different types of thresholds and / or timers. In some non-limiting examples, the publishing criterion to any, or any combination of a time limit for availability of the media content, a number of views limit of the media content, a threshold total viewing time of the media content, feedback information from the first group of users with respect to the media content.
[0096] As already mentioned, the media storage device 200 might check whether the publishing criterion is fulfilled for engagement patterns of the first group of users with respect to the media content. Therefore, in some embodiments, the media storage device 200 is configured to perform (optional) step S220. S220: The media storage device 200 receives information of engagement patterns of the first group of users with respect to the media content from the media server device 100.
[0097] Then, based on the engagement patterns, the media storage device 200 can determine whether the media content is to be exposed to the media server device 100 or not. In particular, in some embodiments, the media storage device 200 is configured to perform (optional) step S222.
[0098] S222: The media storage device 200 determines, based on whether the engagement patterns fulfil the publishing criterion or not, whether to provide the media content to the media server device 100 or not.
[0099] In this respect, when a positive threshold is met (i.e., the publishing criterion is fulfilled), the media content is provided to the media server device 100. That is, in some embodiments, the media storage device 200 is configured to perform (optional) step S224.
[0100] S224: The media storage device 200 provides, when the engagement patterns fulfil the publishing criterion, the media content to the media server device 100 for the media content to be made available to a second group of users.
[0101] Conversely, when a negative threshold is met (i.e., the publishing criterion is not fulfilled), the media server device 100 is instructed to stop distributing the placeholder media object. That is, in some embodiments, the media storage device 200 is configured to perform (optional) step S226.
[0102] S226: The media storage device 200 provides, when the engagement patterns fail to fulfil the publishing criterion, instructions to the media server device 100 to stop distributing a placeholder media object of the media content.
[0103] Still further, in some embodiments, the media storage device 200 retain the finegrained control over at least part of the media content over time (e.g., only exposing the media content to a limited group of users). In such embodiments there is no need for a publishing criterion (or, conversely, the publishing criterion will never be fulfilled). Reference is now made to Fig. 4 illustrating a method for secure handling of media content as performed by the communication device 300 according to an embodiment.
[0104] As disclosed above, the media server device 100 provides a placeholder media object of the media content for accessing the media content and a token to a communication device 300 associated with the first group of users. Hence, the communication device 300 is configured to perform step S304.
[0105] S304: The communication device 300 receives a placeholder media object of media content for accessing the media content and a token from a media server device 100 providing a media service to a user of the communication device 300. The token indicates that the communication device 300 is allowed to access the media content.
[0106] S306: The communication device 300 stores at least part of the placeholder media object in the TEE.
[0107] S308: The communication device 300 provides a request and the token to the media storage device 200 for the communication device 300 to access the media content.
[0108] S310: The communication device 300, in response thereto (i.e., in response to having provided the request to the media storage device 200), receives the media content in encrypted form from the media storage device 200.
[0109] S312: The communication device 300 fills the placeholder media object with the media content in encrypted form in the TEE.
[0110] Embodiments relating to further details of handling media content as performed by the communication device 300 will now be disclosed with continued reference to Fig.
[0111] 4-
[0112] As disclosed above, a link can be provided together with the placeholder media object to the communication device 300 in step S106. This link can thus be received in step S304. The communication device 300 could then access the media content by following the link. That is, the link can be utilized in step S308 for the communication device 300 to send the request to the correct media storage device 200. In some non-limiting examples, the link is a hyperlink. As further disclosed above, the media server device too verifies that the TEE has been set up correctly in the communication device 300 before providing the placeholder media object to the communication device 300 in step S106. Therefore, in some embodiments, the communication device 300 is configured to perform step S302 before receiving the placeholder media object in step S304.
[0113] S302: The communication device 300 attests setup of the TEE before receiving the placeholder media object by providing an attestation result for the setup of the TEE and at least one application running inside the TEE for accessing the media content.
[0114] As further disclosed above, the media content is only accessible in clear-text form inside the TEE. Therefore, in some embodiments, the communication device 300 is configured to perform step S314.
[0115] S314: The communication device 300 decrypts the media content only inside the TEE using a private key of an asymmetric key pair that is accessible to the TEE but not outside the TEE. For this purpose, the TEE might receive at least one protected content encryption key from the media server device 100. The content encryption key can then then be used to decrypt the media content inside the TEE.
[0116] In some examples, the content encryption key is protected by a key encapsulation using a key provided by the media server device 100. In other examples, other procedures are used to provide the key to communication device 300, e.g., establishing a symmetric key between the TEE in the communication device 300 and the media storage device 200 using a key exchange protocol, such as Diffie-Hellman.
[0117] In some examples, there is a limit on the number of times a certain media content can be accessed by the communication device 300. This can e.g., be achieved by incorporating a policy framework into the TEE application and keeping track of the user’s consumption of the content; alternatively, the content key being replaced by a seed which is to be used by the communication device 300 to create the content key. A key derivation function (KDF) may additionally take content metadata as input, e.g., a binary value indicating “first view”, “received less than 10 minutes ago”, etc. An incorrect binary value would generate an incorrect key and therefore prevent access to the media content. In some examples, the communication device 300 receives, from the media server 100, a request to remove the placeholder content, after which the communication device 300 performs deletion of any media content related to the placeholder media object.
[0118] One particular embodiment for secure handling of media content based on at least some of the above disclosed embodiments will now be disclosed in detail with reference to the signaling diagram of Fig. 5.
[0119] In this embodiment, a media content providing device 400 intends to publish some media content to a limited group of users (here denoted a first group of users). Based on the engagement patterns of these users, it is then determined whether the media content is to be published to a larger group of users (the first group of users and a second group of users) or not.
[0120] S401: The media content providing device 400 creates content comprising e.g., video, audio, sensory inputs, etc. that defines media content.
[0121] S402: The media content providing device 400 specifies a publishing criterion for the media content. Alternatively, it is the media storage device 200 that specifies the publishing criterion for the media content.
[0122] S403: The media content providing device 400 uploads the media content to the media storage device 200.
[0123] S404: The media storage device 200 informs the media server device 100 that new media content is available for a first group of users. The media storage device 200 further informs the media server device 100 on what resource (e.g., in terms of a uniform resource locator, URL), address, port, etc. the media content is available for request and optionally supplies a hash of the media content.
[0124] S405: The media server device 100 creates a placeholder media object with a link to request the media content according to the received information. The placeholder media object may further contain the hash of the media content. The media server device 100 makes the placeholder media object available for communication device(s) 300 belonging to the first group of users. The media server device 100 might further communicate an ID of the placeholder media object to the media storage device 200, to be used as a reference if several placeholder media objects are active for the same media content providing device 400.
[0125] S406: At least one communication device 300 is presented with the placeholder media object, e.g., by running a media application belonging to the media server device 100 on the communication device 300.
[0126] Either prior to, or after receiving the placeholder media object, the media server device 100 instructs the communication device 300 to setup, or verify that it has previously setup, a TEE for processing the media content.
[0127] The TEE may be equipped with a private key from a trusted third party, e.g., the communication device manufacturer. Alternatively, the private key may be provisioned by the media server device 100. The intent of the private key is to provision the content encryption key into the TEE of the communication device 300.
[0128] The media server device 100 or a trusted third party attests the setup of the TEE according to known protocols, e.g., such as any of the Internet Engineering Taskforce (IETF) Remote Attestation Procedures (RATSs). If the TEE setup cannot be attested, the communication device 300 is removed from the first group of users and the procedure is halted.
[0129] S407: The communication device 300 receives a token from the media server device 100, indicating that the communication device 300 is allowed to access the media content.
[0130] In some examples, the token comprises an ID and / or content hash of the media object. In some examples, the token further comprises a report from the attestation of the TEE.
[0131] S408: The communication device 300 connects to the URL, address, port, etc. of the media storage device 200 and supplies the token to the media storage device 200.
[0132] S409: The media storage device 200 validates that the communication device 300 is part of the first group of users and has presented a valid token. In some examples, the check of the communication device 300 is omitted as it is checked as a part of the communication device 300 receiving the token from the media server device 100.
[0133] S410: The media storage device 200 then, in case of successful validation, supplies the media content as encrypted with the content key to the communication device 300, and the content key, where the content key is encrypted with the public key of the TEE in the communication device 300.
[0134] S411: The placeholder media object, as received by the communication device 300 from the media server device 100, is populated and rendered with the decrypted media content via secure output on the at least one communication device 300. The media content is decrypted within the TEE, either the whole media content at once, or part by part of the media content as for streamed media content, leading to the user of the communication device 300 being able to consume the content locally.
[0135] S412: Viewing patterns, interactions, and reactions from the one or more communication device(s) 300 are communicated as engagement patterns to the media server device 100. The media server device 100 uses the engagement patterns to update the original, placeholder media object.
[0136] S413: The engagement patterns, or at least a distilled version of the engagement patterns, are propagated to the media storage device 200 for analysis.
[0137] Optionally, any communication device 300 receiving the media object at a later point may access the interactions and reactions from previous viewers.
[0138] Optionally, any communication device 300 that has already received the media object may receive an update to the engagement patterns when new viewing patterns, interactions, and reactions are recorded.
[0139] S414: The media storage device 200 evaluates the engagement patterns by comparing the engagement patterns to the publishing criterion.
[0140] If a positive threshold is met after a certain number of communication devices 300 having received the media content or a certain amount of time has passed, e.g., exceeding a baseline of percentage of positive reactions, step S415 is entered. If a negative threshold is met after a certain number of communication devices 300 having received the content or a certain amount of time has passed, e.g., exceeding a maximum percentage of negative reactions, the media storage device 200 stops sharing the media object with the communication device(s) 300 and instructs the media server device 100 to stop distributing the placeholder media object. Optionally, the placeholder media object may also be removed from the media server device 100. Optionally, the communication device 300 may also be instructed to remove the key material for accessing the media object and / or any media content linked to the placeholder media object stored in the TEE.
[0141] S415: The media storage device 200 provides the media content to the media server device 100.
[0142] S416: The media server device 100 populates the placeholder media object with the media content. In this way, all communication devices 300, 500 which are presented with the media object after this point will be able to access the media content directly from the media server device 100.
[0143] 8417a: At least one communication device 300 belonging to the first group of users is presented with the media object.
[0144] 8417b: At least one communication device 500 belonging to a second group of users is presented with the media object.
[0145] Fig. 6 schematically illustrates, in terms of a number of structural units, the components of a media server device 100 according to an embodiment. Processing circuitry 110 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 910a (as in Fig. 9), e.g., in the form of a storage medium 130. The processing circuitry 110 may further be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA).
[0146] Particularly, the processing circuitry 110 is configured to cause the media server device 100 to perform a set of operations, or steps, as disclosed above. For example, the storage medium 130 may store the set of operations, and the processing circuitry no may be configured to retrieve the set of operations from the storage medium 130 to cause the media server device 100 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus, the processing circuitry 110 is thereby arranged to execute methods as herein disclosed.
[0147] The storage medium 130 may also comprise persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory.
[0148] The media server device 100 may further comprise a communications (comm.) interface 120 for communications with other entities, functions, nodes, and devices, as in Fig. 1. As such the communications interface 120 may comprise one or more transmitters and receivers, comprising analogue and digital components.
[0149] The processing circuitry 110 controls the general operation of the media server device 100 e.g., by sending data and control signals to the communications interface 120 and the storage medium 130, by receiving data and reports from the communications interface 120, and by retrieving data and instructions from the storage medium 130. Other components, as well as the related functionality, of the media server device 100 are omitted in order not to obscure the concepts presented herein.
[0150] Fig. 7 schematically illustrates, in terms of a number of structural units, the components of a media storage device 200 according to an embodiment. Processing circuitry 210 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 910b (as in Fig. 9), e.g., in the form of a storage medium 230. The processing circuitry 210 may further be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA).
[0151] Particularly, the processing circuitry 210 is configured to cause the media storage device 200 to perform a set of operations, or steps, as disclosed above. For example, the storage medium 230 may store the set of operations, and the processing circuitry 210 may be configured to retrieve the set of operations from the storage medium 230 to cause the media storage device 200 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus, the processing circuitry 210 is thereby arranged to execute methods as herein disclosed.
[0152] The storage medium 230 may also comprise persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory.
[0153] The media storage device 200 may further comprise a communications interface 220 for communications with other entities, functions, nodes, and devices, as in Fig. 1. As such the communications interface 220 may comprise one or more transmitters and receivers, comprising analogue and digital components.
[0154] The processing circuitry 210 controls the general operation of the media storage device 200 e.g., by sending data and control signals to the communications interface 220 and the storage medium 230, by receiving data and reports from the communications interface 220, and by retrieving data and instructions from the storage medium 230. Other components, as well as the related functionality, of the media storage device 200 are omitted in order not to obscure the concepts presented herein.
[0155] The media server device 100 and / or media storage device 200 may be provided as respective standalone devices or as a part of at least one further device. Thus, a first portion of the instructions performed by the media server device 100 and / or media storage device 200 may be executed in a respective first device, and a second portion of the of the instructions performed by the media server device 100 and / or media storage device 200 may be executed in a respective second device; the herein disclosed embodiments are not limited to any particular number of devices on which the instructions performed by the media server device 100 and / or media storage device 200 may be executed. Hence, the methods according to the herein disclosed embodiments are suitable to be performed by a media server device 100 and / or media storage device 200 residing in a cloud computational environment. Therefore, although a single processing circuitry 110, 210 is illustrated in Figs. 6 and 7 the processing circuitry 110, 210 may be distributed among a plurality of devices, or nodes. The same applies to the computer programs 920a, 920b of Fig. 9. "2-1
[0156] Fig. 8 schematically illustrates, in terms of a number of structural units, the components of a communication device 300 according to an embodiment. Processing circuitry 310 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 910c (as in Fig. 9), e.g., in the form of a storage medium 330. The processing circuitry 310 may further be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA).
[0157] Particularly, the processing circuitry 310 is configured to cause the communication device 300 to perform a set of operations, or steps, as disclosed above. For example, the storage medium 330 may store the set of operations, and the processing circuitry 310 may be configured to retrieve the set of operations from the storage medium 330 to cause the communication device 300 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus, the processing circuitry 310 is thereby arranged to execute methods as herein disclosed.
[0158] The storage medium 330 may also comprise persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory.
[0159] The communication device 300 may further comprise a communications interface 320 for communications with other entities, functions, nodes, and devices, as in Fig.
[0160] 1. As such the communications interface 320 may comprise one or more transmitters and receivers, comprising analogue and digital components.
[0161] The processing circuitry 310 controls the general operation of the communication device 300 e.g., by sending data and control signals to the communications interface 320 and the storage medium 330, by receiving data and reports from the communications interface 320, and by retrieving data and instructions from the storage medium 330. Part of the processing circuitry 310 and part of the storage medium 330 is implemented in a TEE 340 of the communication device 300. Other components, as well as the related functionality, of the communication device 300 are omitted in order not to obscure the concepts presented herein. Fig. 9 shows one example of a computer program product 910a, 910b, 910c comprising computer readable means 930. On this computer readable means 930, a computer program 920a can be stored, which computer program 920a can cause the processing circuitry 110 and thereto operatively coupled entities and devices, such as the communications interface 120 and the storage medium 130, to execute methods according to embodiments described herein. The computer program 920a and / or computer program product 910a may thus provide means for performing any steps of the media server device 100 as herein disclosed. On this computer readable means 930, a computer program 920b can be stored, which computer program 920b can cause the processing circuitry 210 and thereto operatively coupled entities and devices, such as the communications interface 220 and the storage medium 230, to execute methods according to embodiments described herein. The computer program 920b and / or computer program product 910b may thus provide means for performing any steps of the media storage device 200 as herein disclosed. On this computer readable means 930, a computer program 920c can be stored, which computer program 920c can cause the processing circuitry 310 and thereto operatively coupled entities and devices, such as the communications interface 320 and the storage medium 330, to execute methods according to embodiments described herein. The computer program 920c and / or computer program product 910c may thus provide means for performing any steps of the communication device 300 as herein disclosed.
[0162] In the example of Fig. 9, the computer program product 910a, 910b, 910c is illustrated as an optical disc, such as a CD (compact disc) or a DVD (digital versatile disc) or a Blu-Ray disc. The computer program product 910a, 910b, 910c could also be embodied as a memory, such as a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), or an electrically erasable programmable read-only memory (EEPROM) and more particularly as a non-volatile storage medium of a device in an external memory such as a USB (Universal Serial Bus) memory or a Flash memory, such as a compact Flash memory. Thus, while the computer program 920a, 920b, 920c is here schematically shown as a track on the depicted optical disk, the computer program 920a, 920b, 920c can be stored in any way which is suitable for the computer program product 910a, 910b, 910c. The inventive concept has mainly been described above with reference to a few embodiments. However, as is readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the inventive concept, as defined by the appended patent claims.
Claims
CLAIMS1. A method for secure handling of media content, wherein the method is performed by a media server device (too), and wherein the method comprises: receiving (S102) information from a media storage device (200) of availability of media content for a first group of users of a media service provided by the media server device (100); and providing (S106) a placeholder media object of the media content for accessing the media content and a token to a communication device (300) associated with the first group of users upon having verified that the communication device (300) comprises a trusted execution environment for processing the media content, wherein the token indicates that the communication device (300) is allowed to access the media content.
2. The method according to claim 1, wherein the information received by the media storage device (200) comprises a link to the media content, and wherein the link is provided together with the placeholder media object to the communication device (300).
3. The method according to claim 1 or 2, wherein the method further comprises: providing (S108) an identifier of the placeholder media object to the media storage device (200).
4. The method according to any preceding claim, wherein the method further comprises: obtaining (S104) information of attested setup of the trusted execution environment in the communication device (300) before providing the placeholder media object to the communication device (300).
5. The method according to claim 4, wherein the information indicates that a private key of an asymmetric key pair is accessible to the trusted execution environment but not outside the trusted execution environment.
6. The method according to any preceding claim, wherein the method further comprises: obtaining (Siio) information of engagement patterns of the first group of users with respect to the media content; and forwarding (S112) the information of the engagement patterns to the media storage device (200).
7. The method according to claim 6, wherein the method further comprises: updating (S114) the placeholder media object to comprise information of the engagement patterns of the media content.
8. The method according to claim 6 or 7, wherein the engagement patterns comprise details pertaining to any, or any combination of: number of views of the media content, total viewing time of the media content, feedback information from the first group of users with respect to the media content.
9. The method according to any preceding claim, wherein the method further comprises: receiving (S116) the media content from the media storage device (200) for the media content to be made available to the first group of users as well as a second group of users; and publishing (S118) the media content to the communication device (300) associated with the first group of users as well as to a communication device (500) associated with the second group of users.
10. The method according to any of claims 1 to 8, wherein the method further comprises: receiving (S120) instructions from the media storage device (200) to stop distributing the placeholder media object of the media content; and in response thereto: removing (S122) the placeholder media object.
11. A method for secure handling of media content, wherein the method is performed by a media storage device (200), and wherein the method comprises: receiving (S202) media content from a media content providing device (400); providing (S206) information to a media server device (100) of availability of the media content for a first group of users of a media service provided by the media server device (100); receiving (S210) a request for accessing the media content from a communication device (300), wherein the request comprises a token; and providing (S218-2) the media content in encrypted form to a trusted execution environment in the communication device (300) upon having verified the token and that the communication device (300) is associated with the first group of users.
12. The method according to claim 11, wherein the information provided to the media server device (100) comprises a link to the media content.
13. The method according to claim 11 or 12, further comprising, upon having received the request: creating (S212) at least one content encryption key to protect the media content; protecting (S214) the at least one content encryption key with a public key of an asymmetric key pair accessible by the trusted execution environment; encrypting (S216) the media content with the at least one content encryption key; and providing (S218-4) the at least one protected content encryption key to the trusted execution environment.
14. The method according to claim 13, wherein the at least one content encryption key is created upon having verified that the token indicates existence of a trusted execution environment in the communication device (300).
15. The method according to any of claims 11 to 14, wherein the method further comprises:receiving (S208) an identifier of a placeholder media object of the media content from the media server device (100).
16. The method according to any of claims claim 11 to 15, wherein the method further comprises: obtaining (S204) a publishing criterion for publishing the media content for a second group of users.
17. The method according to claim 16, wherein the publishing criterion to any, or any combination of: a time limit for availability of the media content, a number of views limit of the media content, a threshold total viewing time of the media content, feedback information from the first group of users with respect to the media content.
18. The method according to any of claims 11 to 17, wherein the method further comprises: receiving (S220) information of engagement patterns of the first group of users with respect to the media content from the media server device (100).
19. The method according to a combination of claims 16 and 18 or a combination of claims 17 and 18, wherein the method further comprises: determining (S222), based on whether the engagement patterns fulfil the publishing criterion or not, whether to provide the media content to the media server device (100) or not.
20. The method according to claim 19, wherein the method further comprises: providing (S224), when the engagement patterns fulfil the publishing criterion, the media content to the media server device (100) for the media content to be made available to a second group of users.
21. The method according to claim 19, wherein the method further comprises: providing (S226), when the engagement patterns fail to fulfil the publishing criterion, instructions to the media server device (100) to stop distributing a placeholder media object of the media content.
22. A method for secure handling of media content, wherein the method is performed by a communication device (300), wherein the communication device (300) comprises a trusted execution environment, and wherein the method comprises: receiving (S304) a placeholder media object of media content for accessing the media content and a token from a media server device (100) providing a media service to a user of the communication device (300), wherein the token indicates that the communication device (300) is allowed to access the media content; storing (S306) at least part of the placeholder media object in the trusted execution environment; providing (S308) a request and the token to a media storage device (200) for the communication device (300) to access the media content; and in response thereto: receiving (S310) the media content in encrypted form from the media storage device (200); and filling (S312) the placeholder media object with the media content in encrypted form in the trusted execution environment.
23. The method according to claim 22, wherein the placeholder media object is received together with a link to the media content, and wherein the link is used for providing the request to the media storage device (200).
24. The method according to claim 22 or 23, wherein the method further comprises: attesting (S302) setup of the trusted execution environment before receiving the placeholder media object by providing an attestation result for the setup of the trusted execution environment and at least one application running inside the trusted execution environment for accessing the media content.
25. The method according to claim 22, 23 or 24, wherein the method further comprises:decrypting (S314) the media content only inside the trusted execution environment using a private key of an asymmetric key pair that is accessible to the trusted execution environment but not outside the trusted execution environment.
26. A media server device (100) for secure handling of media content, the media server device (100) comprising processing circuitry (110), the processing circuitry being configured to cause the media server device (100) to: receive information from a media storage device (200) of availability of media content for a first group of users of a media service provided by the media server device (100); and provide a placeholder media object of the media content for accessing the media content and a token to a communication device (300) associated with the first group of users upon having verified that the communication device (300) comprises a trusted execution environment for processing the media content, wherein the token indicates that the communication device (300) is allowed to access the media content.
27. A media storage device (200) for secure handling of media content, the media storage device (200) comprising processing circuitry (210), the processing circuitry being configured to cause the media storage device (200) to: receive media content from a media content providing device (400); provide information to a media server device (100) of availability of the media content for a first group of users of a media service provided by the media server device (100); receive a request for accessing the media content from a communication device (300), wherein the request comprises a token; and provide the media content in encrypted form to a trusted execution environment in the communication device (300) upon having verified the token and that the communication device (300) is associated with the first group of users.
28. A communication device (300) for secure handling of media content, the communication device (300) comprising a trusted execution environment andprocessing circuitry (310), the processing circuitry being configured to cause the communication device (300) to: receive a placeholder media object of media content for accessing the media content and a token from a media server device (100) providing a media service to a user of the communication device (300), wherein the token indicates that the communication device (300) is allowed to access the media content; store at least part of the placeholder media object in the trusted execution environment; provide a request and the token to a media storage device (200) for the communication device (300) to access the media content; and in response thereto: receive the media content in encrypted form from the media storage device (200); and fill the placeholder media object with the media content in encrypted form in the trusted execution environment.
29. A computer program (920a) for secure handling of media content, the computer program comprising computer code which, when run on processing circuitry (110) of a media server device (100), causes the media server device (100) to: receive (S102) information from a media storage device (200) of availability of media content for a first group of users of a media service provided by the media server device (100); and provide (S106) a placeholder media object of the media content for accessing the media content and a token to a communication device (300) associated with the first group of users upon having verified that the communication device (300) comprises a trusted execution environment for processing the media content, wherein the token indicates that the communication device (300) is allowed to access the media content.
30. A computer program (920b) for secure handling of media content, the computer program comprising computer code which, when run on processing circuitry (210) of a media storage device (200), causes the media storage device (200) to:receive (S202) media content from a media content providing device (400); provide (S206) information to a media server device (100) of availability of the media content for a first group of users of a media service provided by the media server device (100); receive (S210) a request for accessing the media content from a communication device (300), wherein the request comprises a token; and provide (S218-2) the media content in encrypted form to a trusted execution environment in the communication device (300) upon having verified the token and that the communication device (300) is associated with the first group of users.
31. A computer program (920c) for secure handling of media content, the computer program comprising computer code which, when run on processing circuitry (310) of a communication device (300) comprising a trusted execution environment, causes the communication device (300) to: receive (S304) a placeholder media object of media content for accessing the media content and a token from a media server device (100) providing a media service to a user of the communication device (300), wherein the token indicates that the communication device (300) is allowed to access the media content; store (S306) at least part of the placeholder media object in the trusted execution environment; provide (S308) a request and the token to a media storage device (200) for the communication device (300) to access the media content; and in response thereto: receive (S310) the media content in encrypted form from the media storage device (200); and fill (S312) the placeholder media object with the media content in encrypted form in the trusted execution environment.
32. A computer program product (910a, 910b, 910c) comprising a computer program (920a, 920b, 920c) according to at least one of claims 29, 30 and 31, and a computer readable storage medium (930) on which the computer program is stored.
Citation Information
Patent Citations
Method, system, and device of provisioning cryptographic data to electronic devices
US9866376B2
System, Apparatus And Method For Providing Protected Content In An Internet Of Things (IOT) Network
US20160364553A1
Data owner restricted secure key distribution
US20180234403A1
Cryptographically secure request verification
US20230050222A1