Secure sidecar container
US-2024330031-A1 · Oct 3, 2024 · US
US9436812B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9436812-B2 |
| Application number | US-201514641986-A |
| Country | US |
| Kind code | B2 |
| Filing date | Mar 9, 2015 |
| Priority date | Dec 19, 2012 |
| Publication date | Sep 6, 2016 |
| Grant date | Sep 6, 2016 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Embodiments of an invention for platform-hardened digital rights management key provisioning are disclosed. In one embodiment, a processor includes an execution unit to execute one or more instructions to create a secure enclave in which to run an application to receive digital rights management information from a provisioning server in response to authentication of the application by a verification server.
Opening claim text (preview).
What is claimed is: 1. A processor comprising: a hardware access control unit to restrict access to the memory space of a secure enclave; and an instruction decoder circuit to decode a first instruction, wherein the first instruction is a secure-enclave-create instruction to be executed to create the secure enclave in which to run an application to request digital rights management (DRM) provisioning information from a provisioning server, to receive a first key component from the provisioning server, to request authentication from a verification server, to generate a second key component, to provide proof of authentication to the provisioning server, to send the second key component to the provisioning server, to generate a shared secret key, to receive the DRM provisioning information from the provisioning server, to decrypt the DRM provisioning information using the shared secret key, to seal the DRM provisioning information to the secure enclave, to store the sealed DRM provisioning information in a non-volatile memory, to unseal the DRM provisioning information in the secure enclave, and to use the content from a content server without repeating the requesting of DRM provisioning information from the provisioning server, wherein the seal is to be performed using a second instruction of the processor, wherein the second instruction is a secure-enclave-seal instruction. 2. The processor of claim 1 , wherein the digital rights management (DRM) provisioning information includes a Digital Transmission Content Protection key. 3. The processor of claim 1 , wherein the authentication involves an Enhanced Protection ID algorithm. 4. The processor of claim 1 , wherein the application in the secure enclave is also to generate an identity report. 5. The processor of claim 4 , wherein the application in the secure enclave is to use an Enhanced Protection ID (EPID) private key, the identity report. 6. The processor of claim 5 , wherein requesting authentication includes sending the signed identity report to the verification server. 7. The processor of claim 6 , wherein the application in the secure enclave is also to receive, from the verification server, the proof of authentication, wherein the authentication involves verifying the signed identity report. 8. The processor of claim 7 , wherein verifying the signed identity report uses an EPID public key corresponding to the EPID private key. 9. A system comprising: a non-volatile memory; and a processor including a hardware access control unit to restrict access to the memory space of a secure enclave, wherein the processor is to execute a secure-enclave-create instruction to create the secure enclave in which to run an application to request digital rights management (DRM) provisioning information from a provisioning server, to receive a first key component from the provisioning server, to request authentication from a verification server, to generate a second key component, to provide proof of authentication to the provisioning server, to send the second key component to the provisioning server, to generate a shared secret key, to receive the DRM provisioning information from the provisioning server, to decrypt the DRM provisioning information using the shared secret key, to seal the DRM provisioning information to the secure enclave, to store the sealed DRM provisioning information in the non-volatile memory, to unseal the DRM provisioning information in the secure enclave, and to use the content from a content server without repeating the requesting of DRM provisioning information from the provisioning server, wherein the seal is to be performed using a secure-enclave-seal instruction of the processor. 10. The system of claim 9 wherein the DRM provisioning information includes a Digital Transmission Content Protection key.
including means for verifying the identity or authority of a user of the system {or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials} · CPC title
for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title
Protecting distributed programs or content, e.g. vending or licensing of copyrighted material (protection in video systems or pay television H04N7/16) {; Digital rights management [DRM]} · CPC title
using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.