Method and a communication device for enabling interaction with media content

The method and device enable interaction with protected media content by decrypting and monitoring within the TEE, transmitting action codes to the REE for execution, addressing the access limitations of assistant applications and enhancing user interaction.

WO2026114492A1PCT designated stage Publication Date: 2026-06-04TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
Filing Date
2024-11-28
Publication Date
2026-06-04

AI Technical Summary

Technical Problem

Existing assistant applications, such as voice assistants, are unable to interact with protected media content within a Trusted Execution Environment (TEE) due to restricted access, limiting their functionality with DRM-protected content.

Method used

A method and communication device that decrypts protected media content within the TEE, monitors for trigger conditions, and transmits action codes to the Rich Execution Environment (REE) for execution, enabling interaction with the media content while maintaining security.

Benefits of technology

Facilitates flexible and secure interaction with protected media content by allowing trigger-based actions outside the TEE, enhancing user interaction capabilities without compromising data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000021_0000
    Figure 00000021_0000
  • Figure 00000021_0001
    Figure 00000021_0001
  • Figure 00000022_0000
    Figure 00000022_0000
Patent Text Reader

Abstract

A method at a communication device comprising a Trusted Execution Environment (TEE), for enabling interaction with protected media content, available at the TEE, the method comprising: decrypting protected media content, received at the TEE; monitoring, at the TEE, at least one object of the decrypted media content, for at least one trigger condition, applicable at the TEE, and transmitting, from the TEE to outside the TEE, in response to detecting realisation of the at least one trigger condition during the monitoring, at least one action code, associated with the detected trigger condition and indicating at least one action, executable outside the TEE, on the basis of the at least one action code.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] METHOD AND A COMMUNICATION DEVICE FOR ENABLING INTERACTION WITH MEDIA CONTENT

[0002] Technical field

[0003] The present disclosure refers to a method for enabling interaction with protected media content, and a communication device, adapted for such interaction.

[0004] Background

[0005] Assistant applications, sometimes called voice assistant programs or artificial intelligence (Al) assistants, such as e.g., Microsoft CoPilot, Google Assistant, Siri and Alexa, are becoming commonplace in consumer devices, and most customer devices now have at least one rudimentary program which can perform tasks on behalf of the user of the device.

[0006] Many consumer devices are also capable of accessing and interacting with protected data content, such as e.g. DRM protected data content, such as e.g. DRM protected video or audio content, which is received at a TEE of the consumer device, where this encrypted content is decrypted before it can be processed within the TEE.

[0007] A TEE is a secure area of processing circuitry, comprising one or more processors, such as e.g. a central processing unit (CPU). The TEE protects the code and data loaded in the processor both from a confidentiality and integrity perspective. Data confidentiality prevents unauthorized entities from outside the TEE from reading data, while code integrity prevents code stored in the TEE from being replaced or modified by unauthorized entities, which may also be done by the owner of the processing circuitry itself, e.g. when applying a certain DRM scheme. However, DRM protections, applied in solutions, such as e.g. Widevine, protects content from illegal copying, but in addition, it also places restrictions on what may be performed on a communication device.

[0008] As an isolated execution environment a TEE provides security features, such as e.g. isolated execution, integrity of applications executing with the TEE, and confidentiality of their assets to a user. In general terms, the TEE offers an execution space which provides a higher level of security for trusted applications running on the device than what is the case in a rich execution environment (REE).

[0009] The REE and TEE typically have their own respective operating system (OS), where the TEE has a limited, trusted, OS, such as e.g., OP-TEE or Trusty, whereas the REE has a rich, but less trusted, OS such as e.g., Android or Windows.

[0010] New advances in machine learning (ML) model-powered assistants, such as e.g., Microsoft Recall and Supercharged Siri , are capable of assisting a user of a device by understanding what content the user is interacting with, e.g., by taking screenshots which can be analyzed for the purpose of aiding the user in future interactions. These assistants are not able to support the user in tasks involving protected content, as they normally only have access to the screen buffer available to the REE OS, whereas the REE OS is not allowed to access the TEE buffer, since this buffer is configured to protect against e.g. copying of media content, e.g. if the content is DRM protected content.

[0011] US11736764B2 refers to a solution for performing inference on content protected in a media TEE.

[0012] US9668002B1 refers to a method for determining the components of a content stream.

[0013] However, it can currently be practically impossible or at least very limiting for assistant applications, such as the ones mentioned above, to perform tasks involving protected material on content available in the TEE, from the REE, since the content is not accessible to such a software program in the REE.

[0014] Summary

[0015] It is an object of the present disclosure to address at least the issues mentioned above.

[0016] According to one aspect, a method at a communication device comprising a TEE, for enabling interaction with protected media content, available at the TEE, is suggested, where the method comprise decrypting protected media content, received at the TEE; monitoring, at the TEE, at least one object of the decrypted media content, for at least one trigger condition, applicable at the TEE, and transmitting, from the TEE to outside the TEE, in response to detecting realisation of the at least one trigger condition during the monitoring, at least one action code, associated with the detected trigger condition and indicating at least one action, executable outside the TEE, on the basis of the at least one action code.

[0017] According to another aspect, a communication device, comprising a TEE, for enabling interaction with protected media content, available at the TEE, is suggested, where the communication device comprise processing circuitry and a memory, comprising code, which when executed by the processing circuitry, causes the communication device to: decrypt protected media content, received at the TEE; monitor, at the TEE, at least one object of the decrypted media content, for at least one trigger condition, applicable at the TEE, and transmit, from the TEE to outside the TEE, in response to detecting realisation of the at least one trigger condition during the monitoring, at least one action code, associated with the detected trigger condition and indicating at least one action, executable outside the TEE on the basis of the at least one action code.

[0018] According to yet another aspect, a computer program is suggested, where the computer program comprises instructions, which when executed by processing circuitry causes the processing circuitry to: decrypt protected media content, received at the TEE; monitor, at the TEE, at least one object of the decrypted media content, for at least one trigger condition, applicable at the TEE, and transmit, from the TEE to outside the TEE, in response to detecting realisation of the at least one trigger condition during the monitoring, at least one action code, associated with the detected trigger condition and indicating at least one action, executable outside the TEE on the basis of the at least one action code.

[0019] According to another aspect, a computer program product comprising a computer program as described above is suggested. Brief description of drawings

[0020] Embodiments will now be described in more detail in relation to the accompanying drawings, in which:

[0021] Figure 1 is a block scheme, illustrating a monitoring communication device, according to one aspect.

[0022] Figure 2 is a block scheme, illustrating a media component of Fig. 1 , according to one aspect.

[0023] Figure 3 is another block scheme, illustrating a monitoring communication device, according to another aspect.

[0024] Figure 4 is a flow chart, illustrating a method for monitoring media content, according to one aspect.

[0025] Figure 5 is a signalling scheme, illustrating a procedure for monitoring media content, according to one aspect.

[0026] Detailed description

[0027] A mechanism is suggested and described herein which enables access to searchable content, which is kept in a TEE, even when rendering of the data content is done from outside the TEE. Thereby, extended access capabilities, i.e. what can be done to the data content by an application or human being, providing executable instructions to the TEE, can be provided.

[0028] In order to enhance capabilities of interacting with data content, made available in a TEE from outside the TEE, typically from an REE, a mechanism executable on a communication device, comprising a TEE, will now be described in further detail, where the method is adapted so that a high level of flexibility is provided to a user, located outside the TEE, but having access to data content, available within the TEE. This real time process can be achieved by allowing protected data content, available at the TEE, to be monitored within the TEE, such that when it is determined that certain pre-defined trigger conditions have been realized, the user is provided with one or more specific action codes, allowing one or more specific, pre-defined action to be executed outside or within the TEE, while, at the same time, leakage of the protected data content from outside the TEE is prohibited. Although the mentioned data content typically refers to some kind of media content, such as e.g. a video sequence, which will from hereinafter be referred to below, also other types of data content than media content may be handled and processed in a similar manner.

[0029] A simplified communication device, capable of monitoring media content, as suggested above, is illustrated in Fig. 1 , where the communication device 100 comprises functionality, arranged in a TEE 110, whereas other functionality is arranged outside the TEE. Typically, the functionality outside the TEE is in the present context presented as being arranged in a REE 120 of the communication device, as indicated in Figure 1 , but alternatively this functionality may instead be arranged on a device other than the communication device, but capable of interacting with the communication device.

[0030] Within the REE 120, code is executable, resulting in execution of an application 130, where this application 130 can interact with a monitoring unit 180 of the TEE 110 whenever the application 130 is having a demand for some kind of monitoring of data content, such as e.g. media content, which is accessible from within the TEE 110. The REE 120 also comprises a media driver 140, capable of rendering or consuming media content outside the TEE, typically via a shared memory 190. For the application 130 and media driver 140 to be able to communicate with the TEE 110 in a secure way, the REE 120 comprises a REE communication agent 150, whereas the TEE 110 comprises a corresponding TEE communication agent 160, where the two agents are capable of communicating via a protected communication path (not shown). I.e. the two agents enable secure communication between the REE and the TEE. The TEE 110 also comprise a media component 170, capable of handling media content, received in the TEE, so that the content can be monitored by the monitoring unit 180.

[0031] As indicated in Fig. 2, where a media component 170 is described in more detail, the media component 170 of Fig. 1 comprise at least a receiving unit 200, capable of receiving media content, provided to the TEE 110; at least one buffering unit 210, capable of buffering received media content and a decrypting unit 220, capable of decrypting received media content, according to any known decryption mechanism. An optional execution unit 230 may be configured to execute any actions according to action codes, received from outside the TEE, is execution is wanted in the TEE. Alternatively, an execution unit 230 may form part of the monitoring unit 180. Typically, the media component 170 also comprises a decoding unit (not shown) for decompressing the media. Alternatively, decoding can be executed in the REE upon rendering content. The media component 170 will also typically be configured to apply any type of key provisioning system, such as a key provisioning process, applicable in DRM protection solutions. Key provisioning systems may be available in e.g. Widevine, Playready or Apple FairPlay, allowing media content to be provided to, and buffered in the TEE in a secure way.

[0032] A communication device, comprising a TEE and possibly also an REE, and configured to execute a monitoring mechanism, as suggested above, will now be described in further detail, with reference to figure 3. The communication device 100, here referred to as communication device 100a, comprises processing circuitry 320, and a memory 330, where the memory 330 comprises a computer program 350, or computer readable instructions, which when executed by the processing circuitry 320, causes the communication device 110a to decrypt protected media content, received at the TEE.

[0033] The communication device 110a is also configured to monitor, at the TEE, at least one object of the decrypted media content, for at least one trigger condition, applicable at the TEE, after which the processing circuitry 320 is configured to transmit at least one action code, associated with the detected trigger condition and to indicate at least one action, executable outside the TEE, on the basis of the at least one action code, provided from the TEE to outside the TEE, in response to detecting realisation of the at least one trigger condition during the monitoring.

[0034] Figure 3 also comprises a computer program 350, comprising code or instructions which when executed by processing circuitry causes the processing circuitry to perform the method described herein. The communication device 100a also may comprise a computer program product 340, comprising the computer program, as described above. The computer program product may be any of e.g. an optical disc, such as a Compact Disc (CD), a Digital Versatile Disc (DVD) or a Blu-Ray disc. Alternatively, the processing circuitry 320 and the memory 340, may be separated into a TEE and a REE part. The memory 330 can be any combination of random access memory (RAM) and / or read only memory (ROM). The memory 330 also typically comprises persistent storage, which, e.g. can be any single one or combination of magnetic memory, optical memory, solid-state memory or even remotely mounted memory. The processing circuitry 320 may comprise e.g. one or more central processing unit (CPU), multiprocessor or digital signal processor (DSP).

[0035] The communication device 100a may be configured to both acquire trigger condition instructions and to generate at least one trigger condition, based on the received instructions, wherein the acquiring and generating are executed outside the TEE. Alternatively, or in combination, trigger conditions may be pre-stored at the communication device 100a. The communication device 100a may be configured to apply trigger conditions configured e.g. to detect a specific sequence or object in the media content.

[0036] For flexibility purposes the communication device 100a may be adapted to execute a wide variety of actions, allowing a user to initiate a search for media content and for interacting with media content, found in the search. Therefore, the communication device 100a may be configured to execute actions, capable of performing various tasks, such as e.g. one or more of affecting monitoring of the media content; affecting the user interface of the communication device; affecting metadata linked to triggered trigger conditions; affecting the media content, or affecting rendering of the media content.

[0037] With respect to the trigger condition instructions, the communication device 100a may be configured to acquire and interpret trigger condition instructions e.g. in the form of orally, gesture or written instructions, or in any form in which the communication device 100a is capable of receiving instructions from a user. By interpreting the acquired instructions, e.g. by speech recognition, image analysis or text analysis, respectively, certain instructions will be interpreted to certain trigger conditions which will later trigger certain associated one or more actions. Thereby certain allowable actions can be launched in a predicted way. For being able to monitor different types of media content efficiently, the communication device 100a may be configured to perform the monitoring of one or more objects of the protected media content which have been detected during scanning of at least one frame of the decrypted, protected media content. Typically, the communication device 100a is also configured to initiate such scanning from outside the TEE, e.g. from an REE, although the actual scanning is executed inside the TEE.

[0038] The protected media content may be provided in the form of DRM protected content, or content protected in any other way which the communication device 100a has been configured to handle.

[0039] The communication device 100a may be configured to receive at least one action code from the TEE, for executed from outside the TEE, e.g. in an REE of the communication device 100a.

[0040] Typically, the communication device 100a is configured to run an application outside the TEE, such as e.g. in a REE of the communication device 100a, where this application is capable of executing an action code, upon receiving such a code from the TEE.

[0041] In order to enable secure communication between an REE and a TEE of the communication device 100a, the communication device may be configured to perform such communication via a protected communication path, typically via respective communication agents of the REE and the TEE.

[0042] For the monitoring process, the communication device 100a may rely on one or more ML models, adapted for the one or more trigger conditions, applied during the monitoring, and provided to the TEE from outside the TEE or stored at the TEE.

[0043] Some content providers may have a desire to control what can be done to their media content when accessed from a TEE. For such a reason, the communication device 100a may be configured to restrict the monitoring according to rules and / or polices, applicable within the TEE for their media content in general or only some of their media content. Thereby, some trigger conditions may not be applicable on some specific media content. A method, executable in a communication device, such as the one described above, with reference to Fig. 1 and 2, or 3, will now be described in further detail with reference to Fig. 4.

[0044] As indicated with step 4:40, protected media content, such as e.g. streamed video, is being decrypted at the TEE, once the media content has been received at the TEE, according to preceding step 4:30. The received media content may have been received in response to a request from a user of the communication device, comprising the TEE, or in response to a request from an application, running in the TEE or outside the TEE, but capable of communicating with the TEE.

[0045] As indicated with another step 4:50, the media content is then being monitored, where the monitoring is executed in the TEE. The monitoring is configured to monitor for trigger conditions, available at the TEE, where such trigger conditions may be configured to detect a specific sequence or change of sequence in the media content, where a sequence may refer e.g. to a certain event in a video stream. By way of example, such an event may be a certain football team, scoring a goal in a video stream. Alternatively, a specific sequence may refer to a specific, identifiable change of content between pictures in a video stream. Trigger conditions may alternatively be configured to detect a specific object, or object change, such as e.g. a specific person, movie character, pet or car in the received media content. In some situations the trigger conditions may instead be configured to trigger on a specific change of appearance, such as e.g. a change of color, brightness or shape of an object in a video scene.

[0046] The monitoring may comprise an object detection component, capable of scanning media content, where frames of the decrypted, protected media content are being scanned for relevant objects of the media content. Once one or more objects, considered relevant according to relevant trigger conditions, have been detected, an analyzing component may analyze the relevant objects for further determination of whether the relevant trigger conditions have actually been fulfilled. Such an analyzing functionality may be based on a suitable ML model, adapted for performing one or both of object detection or labeling of media content. Such a ML model may e.g. be arranged as a Convolutional Neural Network (CNN), configured for performing object detection, or a Multi-layer Perception (MLP), configured for io performing labelling. Different ML models may be trained depending on the respective trigger conditions applied during monitoring or a specific ML model may be adapted according to the trigger conditions applied. One ML model may e.g. be trained to detect certain sports media events, whereas another model may instead be trained to detect specific characters in movies or series.

[0047] Corresponding to instructions, provided outside the TEE, being mapped to specific trigger conditions, each trigger condition is also being mapped to corresponding action codes at the monitoring unit. Thereby, only trigger conditions mapping to corresponding one or more action codes will be applied in the monitoring process. It is also to be understood that trigger conditions may be applied conditionally by the monitoring unit, such that certain trigger conditions will only be applicable e.g. at certain weekdays, at certain times of the day and / or for certain categories of media content, or according to any other condition, policies and / or rules. Such conditions may e.g. have been predefined by the content provider of certain media content, thereby allowing the content provided to maintain some control of what can be done to their provided media content when accessible from a TEE.

[0048] The trigger conditions, applied during the monitoring procedure may have been configured in advance and automatically activated e.g. by an application, when required by the application. In such a scenario, the trigger conditions may be stored in storage within the TEE. Alternatively, the communication device may acquire trigger condition instructions via a user interface (Ul), as indicated with optional step 4:10. Such instructions may be provided in any type of format, such as e.g. in written form, orally, which the Ul is capable of capturing. The application may be configured to transform the instructions to corresponding trigger conditions, or the instructions may already have been given in the format of trigger conditions, which can be understood by the monitoring unit of the TEE. If instructions for trigger conditions are acquired from outside the TEE, according to step 4:10, relevant trigger conditions, according to the acquired instructions, are provided to the TEE in another optional step 4:20. By applying steps 4:10 and 4:20, a user may be provided with a personalized monitoring mechanism, where monitoring of media content can be executed in a flexible and personalized way. Irrespective of if trigger condition instructions are provided in association with initiation of a monitoring procedure, or have been provided in advance, it is to be understood that a mapping between a trigger condition and corresponding action code / s is known to the application, executable outside the TEE. Such a mapping may e.g. be included in an interpretation process, where instructions are interpreted by the application e.g. by applying an Artificial Intelligence (Al) mechanism, such as e.g. a Large Language Model (LLM), or any other mechanism which has been adapted for the required search purpose. Alternatively, the instructions may have been provided in a form for which there are corresponding, mapping trigger conditions already stored at the REE and accessible to the application.

[0049] Once the monitoring unit has started to monitor media content, such monitoring can continue, as indicated with the “Yes” branch of step 4:90, as long as media content is fed to the TEE, or as long as monitoring has not been terminated e.g. from the application or based on instructions to terminate monitoring, entered by a user of the communication device. When monitoring is to be terminated, this is executed according to the “No” branch of step 4:90.

[0050] When it is determined, during monitoring, that one or more trigger conditions has been fulfilled, as indicated with the “Yes” branch of step 4:60, one or more action codes, corresponding or mapping to a required, associated action is acquired and transmitted to outside the TEE, as indicated in step 4:70.

[0051] An action code may initiate different actions by having effect on different data and one or more functions. According to one embodiment, an action code may affect the monitoring executed on media content at the TEE, such that e.g. an ongoing monitoring process may change from one monitoring strategy to another strategy. Alternatively, a monitoring process may be temporary or permanently interrupted.

[0052] According to another embodiment, an action code may affect the user interface of the communication device, such that e.g. the user interface changes appearance, e.g. via a notification or via the appearance or change of an icon.

[0053] According to yet another embodiment an action code may affect metadata, linked to certain triggered trigger conditions, such that e.g. certain informative data is provided and rendered to a user, together with a respective action code. According to another embodiment, monitored media content may be affected in a certain way, such that e.g. monitored media content is provided and rendered with a specific annotation.

[0054] According to yet another embodiment an action code may affect rendering of media content, such that e.g. a specific zooming in of rendered media content is executed.

[0055] Once a transmitted action code is received outside the TEE, e.g. in the REE, as indicated with step 4:80, this action code activates a corresponding action at the receiving end. The actual execution of the action may be preceded by the user of the communication device being alerted of the received action code, thereby requiring a consent from the user before the action can be executed. Alternatively, an action code initiates a series of actions, which may include also a dialogue with the user, for determining e.g. if further consent from the user is identified, or if an action code is initiating a specific option from different alternative, available options.

[0056] An action may result in that an ongoing monitoring is affected in a certain way, such that e.g. the ongoing monitoring is stopped, temporarily or permanently. Another action may result in that the user interface of the communication device is affected, e.g. by alerting the user of the communication device in a certain way. Yet another action may result in that metadata linked to trigger conditions is affected in a certain way. One action may result in that the monitored media content is affected, e.g. such that a certain episode of media content is provided with a specific notification. In another scenario data indicating how many times a certain trigger condition has been triggered may be provided. Alternatively, an action may affect the rendering of media content at a media driver located outside the TEE.

[0057] A signaling scheme, illustrating how media content may be handled on a communication device, comprising a TEE and a REE, will now be described in further detail, with reference to Fig. 5, assuming that an application is executed in the REE.

[0058] As indicated in step 5:3, protected media content, which has been requested to be sent to the TEE is received by a media component of the TEE, and in another step 5:4, the received media content is decrypted, after which the media content is acquired by the monitoring unit, as indicated in step 5:5. At this stage, the monitoring unit, now having access to both triggering conditions and media content for monitoring, initiates a monitoring process on the content, as indicated in step 5:6. Alternatively, the monitoring of step 5:6 is not initiated until this is required by an application or a user. Once a trigger condition realisation is detected, as indicated in step 5:7, one or more action codes, corresponding to the one or more realised trigger condition, is / are generated by the monitoring unit, as indicated with step 5:8. Once one or more action codes have been generated, these one or more codes is / are transmitted to the application, as indicated in step 5:9. It is here to be understood that steps 5:6- 5:9, as well as steps 5:3-5:5 may be repeated as long as no action has been taken to terminate the ongoing monitoring, or until new trigger conditions have been provided to the monitoring unit.

[0059] Each action code received by the application will result in a potential execution of one or more actions, corresponding to the received action code, as indicated with step 5:10a. While step 5:10a indicates that an action code is resulting in execution of one or more actions at the REE, an action code may also, or alternatively, be used for instructing a media component of the TEE to execute an action within the TEE. In the latter scenario, one or more action codes may be transmitted from the application to the media component, where the codes are executed, as indicated in optional steps 5:10b, and 5:10c, respectively. One or more codes, provided to the TEE may result in rendering of media content outside the TEE, as indicated with step 5:10d. REE, as indicated with optional step 5:10c.

[0060] Trigger conditions may be pre-stored at the TEE, for use during monitoring of media content. Alternatively, trigger conditions may be acquired by an application, as indicated with a first optional step 5:1 , where either trigger conditions or trigger condition instructions are acquired at the REE, e.g. by being directly provided by a user of the communication device. In the latter case, acquired trigger condition instructions are interpreted into corresponding, acceptable trigger conditions. Such instructions may be provided e.g. orally, in written form or by making detectable gestures, expressing a specific wish for certain trigger conditions to be activated. Once the instructions have been interpreted, if required, using any type of known interpretation mechanism, the one or more trigger conditions can be transmitted to the monitoring unit, as indicated with optional step 5:2. Alternatively, trigger conditions are already available at the monitoring unit, e.g. due to that trigger conditions have been pre-stored at a memory of the TEE. In the latter situation, trigger conditions may, e.g. have been provided at purchase of the communication device. According to one embodiment, the received trigger conditions may initiate monitoring of media content, available at the monitoring unit. Alternatively, initiation of monitoring requires some further input from the user, the application or from both. In the latter scenario, initiation of the monitoring may be conditioned with the user requesting certain media content to the TEE.

[0061] The actions to be executed on protected media content may, according to one example, include automatic monitoring unseen events of media content, on behalf of a user, such that e.g. a user can use an application to filter out relevant episodes from a large amount of media content, and only be alerted when relevant content has been found by the monitoring function. According to another example, a user may have certain relevant sections of media content marked-up, for easier later retrieval. According to yet another example, parents may use the suggested monitoring functionality for performing parental guidance, e.g. by blocking or filtering certain media content from being rendered to their children.

[0062] It should be noted that the above-mentioned examples illustrate rather than limit the disclosure, and that those skilled in the art will be able to design also other alternative embodiments without departing from the scope of the appended items. The word “comprising” does not exclude the presence of elements or steps other than those listed in an item, “a” or “an” does not exclude a plurality, and a single processor or other unit may fulfil the functions of several units recited in the items. Any reference signs in the items shall not be construed so as to limit their scope.

Claims

CLAIMS1 .A method at a communication device, comprising a Trusted Execution Environment (TEE), for enabling interaction with protected media content, available at the TEE, the method comprising:-decrypting (4:40) protected media content, received at the TEE;-monitoring (4:50), at the TEE, at least one object of the decrypted media content, for at least one trigger condition, applicable at the TEE, and -transmitting (4:70), from the TEE to outside the TEE, in response to detecting (4:60) realisation of the at least one trigger condition during the monitoring, at least one action code, associated with the detected trigger condition, and indicating at least one action, executable outside the TEE, on the basis of the at least one action code.

2. The method according to claim 1 , further comprising:- activating (4:80), outside the TEE, at least one indicated action, based on the at least one associated action code.

3. The method according to claim 1 or 2, further comprising:- acquiring, outside the TEE, trigger condition instructions, and- generating, outside the TEE, the at least one trigger conditions, based on the received instructions.

4. The method according to claim 3, wherein the at least one trigger condition is configured to detect (4:60) at least:- a specific sequence in the media content;- a specific sequence change in the media content;- a specific object in the media content, or- a specific object change in the media content.

5. The method according to any of claims 3 or 4, wherein the instructions are provided in the form of any of orally, gesture or written instructions.

6. The method according to any of the preceding claims, wherein the at least one action comprises affecting at least one of:- monitoring of the media content;- the user interface of the communication device;- metadata linked to triggered trigger conditions;- the media content, or- rendering of the media content;7. The method according to any of the preceding claims, wherein the monitoring (4:50) is done on one or more objects of the protected media content, which one or more objects has been detected during scanning of at least one frame of the decrypted, protected media content.

8. The method according to claim 7, wherein the scanning is initiated from outside the TEE.

9. The method according to any of the preceding claims, wherein the protected media content is protected Digital Rights Management, DRM, content.

10. The method according to any of the preceding claims, wherein the receiving at least one action code outside the TEE is executed in a Rich Execution Environment, REE.11 . The method according to any of the preceding claims, wherein the receiving at least one action code is executed by an application executing outside the TEE.

12. The method according to any of the preceding claims, wherein the communication between the TEE and outside the TEE is executed via a protected communication path.

13. The method according to any of the preceding claims, wherein the monitoring (4:50) is executed, using at least one ML model adapted for the at least one trigger condition.

14. The method according to claim 13, wherein the at least one ML model is provided to the TEE from outside the TEE.

15. The method according to any of the preceding claims, wherein the monitoring (4:50) is restricted, according to rules and / or polices, applicable within the TEE.

16. A communication device (100a), comprising a Trusted Execution Environment (TEE), for enabling interaction with protected media content, available at the TEE, the communication device (100a) comprising processing circuitry (320) and a memory (330), comprising code, which when executed by the processing circuitry (320), causes the communication device (100a) to:-decrypt protected media content, received at the TEE;-monitor, at the TEE, at least one object of the decrypted media content, for at least one trigger condition, applicable at the TEE, and-transmit, from the TEE to outside the TEE, in response to detecting realisation of the at least one trigger condition during the monitoring, at least one action code, associated with the detected trigger condition and indicating at least one action, executable outside the TEE on the basis of the at least one action code.

17. The communication device (100a), according to claim 16, further configured to execute, outside the TEE, at least one indicated action, based on the at least one associated action code.

18. The communication device (100a), according to claim 16 or 17, further configured to acquire, outside the TEE, trigger condition instructions, and- generate, outside the TEE, the at least one trigger conditions, based on the received instructions.1819. The communication device (100a) according to claim 18, wherein the at least one trigger condition is configured to detect at least:- a specific sequence in the media content;-a specific sequence change in the media content;- a specific object in the media content, or-a specific change of object in the media content.

20. The communication device (100a) according to any of claims 16 to 19, wherein the at least one action is configured to affect at least one of:- monitoring of the media content;- the user interface of the communication device;- metadata linked to triggered trigger conditions;- the media content, or- rendering of the media content;21 .The communication device (100a) according to any of claims 19 or 20, further configured to acquire and interpret trigger condition instructions, acquired in the form of any of orally, gesture or written instructions.

22. The communication device (100a) according to any of claims 16 to 21 , further configured to perform the monitoring on one or more objects of the protected media content which has been detected during scanning of at least one frame of the decrypted, protected media content.

23. The communication device (100a) according to claim 22, further configured to initiate the scanning from outside the TEE.

24. The communication device (100a) according to any of claims 16-23, further configured to protect media content provided in the form of Digital Rights Management, DRM, content.

25. The communication device (100a) according to any of claims 16-24, further configured to receive at least one action code which is executed in a Rich Execution Environment, REE.1926. The communication device (100a) according to any of claims 16-25, further configured to run an application, outside the TEE, wherein the application is capable of executing the received at least one action code, outside the TEE.

27. The communication device (100a) according to any of claims 16-26, further configured to execute the communication between the TEE and outside the TEE via a protected communication path.

28. The communication device (100a) according to any of claims 16-27, further configured to execute the monitoring, using at least one machine learning model, adapted for the at least one trigger condition.

29. The communication device (100a) according to claim 28, further configured to provide the at least one ML model to the TEE from outside the TEE.

30. The communication device (100a) according to any of claims 16-29, further configured to restrict the monitoring according to rules and / or polices, applicable within the TEE.31 . A computer program (350) comprising instructions, which when executed by processing circuitry (320) causes the processing circuitry (320) to:-decrypt protected media content, received at the TEE;-monitor, at the TEE, at least one object of the decrypted media content, for at least one trigger condition, applicable at the TEE, and-transmit, from the TEE to outside the TEE, in response to detecting realisation of the at least one trigger condition during the monitoring, at least one action code, associated with the detected trigger condition and indicating at least one action, executable outside the TEE on the basis of the at least one action code.2032. A computer program product (340) comprising a computer program (350) according to claim 31 .