Drm protected video streaming on game console with secret-less application
Abstract
Techniques are disclosed for secure playback of protected multimedia content on a game console using a secret-less application. An SSO model can be used for client authentication at a key server, which eliminates the need of storing or using any secret information in the client application. Further, an encrypted content key generated by a content packager using a public key can be deployed in the key URI of a playlist file, which is sent to the key server. The key server can be configured to decrypt the content key using a corresponding private key. Further, the content key and unencrypted samples are protected in the game console client application from debugging and replay attacks by using additional security checks at both the client and key server. By storing secret information remotely from the game console and using the SSO model, DRM policies can be enforced on an untrusted client application.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer-implemented method comprising:
receiving, from a client computing device via a communications network using a secure communications protocol, an access control credential and an encrypted content key associated with protected multimedia content; determining that the client computing device is authenticated based on the access control credential; in response to the determination, decrypting the encrypted content key using a private cryptographic key; and sending the decrypted content key to the client computing device via the communications network using the secure communications protocol, the decrypted content key being configured for use by the client computing device for accessing the protected multimedia content.
2 . The method of claim 1 , wherein the encrypted content key is encoded within a security token signed by a multimedia content server associated with the protected multimedia content.
3 . The method of claim 2 , further comprising receiving, from the client computing device via the communications network using the secure communications protocol, policy information associated with the protected multimedia content.
4 . The method of claim 3 , further comprising obtaining output control information from the policy information.
5 . The method of claim 3 , further comprising determining that the encrypted content key is valid based on expiry information encoded in the policy information.
6 . The method of claim 3 , wherein the policy information is encoded with the security token.
7 . The method of claim 1 , wherein the access control credential includes a single sign on token, and wherein the determining is performed according to a single sign on authentication model.
8 . The method of claim 1 , wherein the secure communications protocol includes Hypertext Transfer Protocol Secure (HTTPS).
9 . The method of claim 1 , wherein the client computing device includes a Microsoft Xbox® device.
10 . A computer-implemented method comprising:
receiving an access control credential from a security token service via a communications network; receiving, from a multimedia content server via the communications network, a playlist file having encoded therein a uniform resource identifier (URI) associated with a key server and a security token signed by the multimedia content server, the security token having encoded therein an encrypted content key associated with protected multimedia content; sending the access control credential and the encrypted content key to the key server via the communications network using a secure communications protocol; receiving a decrypted content key from the key server via the communications network using the secure communications protocol, the decrypted content key being configured for accessing the protected multimedia content; and playing back the protected multimedia content using the decrypted content key.
11 . The method of claim 10 , further comprising receiving the protected multimedia content from the multimedia content server via the communications network.
12 . The method of claim 11 , wherein the protected multimedia content is encrypted, and wherein the method further comprises decrypting the protected multimedia content using the decrypted content key.
13 . The method of claim 10 , wherein the URI is encoded in a format comprising “https://remote-keyserver/key?token=XboxSecurityToken”, where “remote-keyserver” represents a uniform resource locator (URL) of the key server, and “XboxSecurityToken” represents the security token.
14 . The method of claim 10 , wherein the secure communications protocol includes Hypertext Transfer Protocol Secure (HTTPS).
15 . The method of claim 10 , wherein the access control credential includes a single sign on token.
16 . The method of claim 10 , wherein the playing is performed using a HTTP Live Streaming (HLS) player.
17 . A computer-implemented method comprising:
generating a playlist file associated with protected multimedia content, the playlist file having encoded therein a uniform resource identifier (URI) associated with a key server and a signed security token having encoded therein an encrypted content key associated with the protected multimedia content; encrypting the protected multimedia content using the content key; and sending the playlist file and the protected multimedia content to a client computing system via a communication network using a secure communications protocol.
18 . The method of claim 17 , further comprising encoding the URI in a format comprising “https://remote-keyserver/key?token=XboxSecurityToken”, where “remote-keyserver” represents a uniform resource locator (URL) of the key server, and “XboxSecurityToken” represents the security token.
19 . The method of claim 17 , further comprising encoding policy information associated with the protected multimedia content in the playlist file.
20 . The method of claim 17 , wherein the secure communications protocol includes Hypertext Transfer Protocol Secure (HTTPS).Join the waitlist — get patent alerts
Track US2015235011A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.