Low-latency secure segment encryption and authentication interface

    公开(公告)号:US09900289B2

    公开(公告)日:2018-02-20

    申请号:US15231161

    申请日:2016-08-08

    发明人: Alexander Giladi

    IPC分类号: H04L29/06 H04L9/08

    摘要: An apparatus comprising a memory, a processor coupled to the memory and configured to obtain a Dynamic Adaptive Streaming over Hypertext Transfer Protocol (HTTP) (DASH) Media Presentation Description (MPD) from an HTTP server, wherein the MPD describes a media presentation as at least one encrypted segment, and wherein the encrypted segment is associated with an availability time and a decryption key, and pre-fetch the decryption key associated with the encrypted segment by requesting the decryption key from a key server prior to the availability time of the encrypted segment.

    Using quality information for adaptive streaming of media content
    3.
    发明授权
    Using quality information for adaptive streaming of media content 有权
    使用媒体内容的自适应流媒体的质量信息

    公开(公告)号:US09571543B2

    公开(公告)日:2017-02-14

    申请号:US14156139

    申请日:2014-01-15

    IPC分类号: H04L29/06

    摘要: Different representations are associated with an instance of media content, and a representation can include multiple portions of media content. A respective quality value and bitrate can be associated with each of the portions. Information about the instance of content, including bitrate and quality information, can be accessed by and/or sent to a client. The quality information indicates the availability of measures of quality (e.g., quality values) and where those quality values reside or how they can be retrieved. The client can use quality as well as bitrate to make more intelligent decisions while streaming the content. For example, while the content is being downloaded over a network, the client can adapt to changes in available network bandwidth by selecting one portion of the instance of media content over another based not just on its bitrate but also based on its quality value.

    摘要翻译: 不同的表示与媒体内容的实例相关联,并且表示可以包括媒体内容的多个部分。 相应的质量值和比特率可以与每个部分相关联。 有关内容实例(包括比特率和质量信息)的信息可以由客户端访问和/或发送给客户端。 质量信息指示质量度量(例如,质量值)的可用性以及这些质量值在哪里或如何被检索的可用性。 客户端可以使用质量和比特率在流式传输内容时做出更明智的决策。 例如,当通过网络下载内容时,客户端可以通过不仅基于其比特率而且还基于其质量值,通过选择一个媒体内容的实例的一部分来适应可用网络带宽的变化。

    Authenticated Encryption Support in ISO/IEC 23009-4
    4.
    发明申请
    Authenticated Encryption Support in ISO/IEC 23009-4 审中-公开
    ISO / IEC 23009-4认证加密支持

    公开(公告)号:US20160105403A1

    公开(公告)日:2016-04-14

    申请号:US14921902

    申请日:2015-10-23

    发明人: Alexander Giladi

    IPC分类号: H04L29/06 H04L9/08

    摘要: A server apparatus supporting authenticated encryption in a network, comprising a receiver configured to receive an unencrypted segment, a processor configured to selecting an encryption key, an initialization vector, and an additional authentication data (AAD), encrypt the segment, configuring the segment for transfer in a Dynamic Adaptive Streaming over Hypertext Transfer Protocol (HTTP) (DASH) media, assign a segment number to the encrypted segment, append an authentication tag to the encrypted segment, store the encrypted segment with the appended authentication tag, and update a Media Presentation Description (MPD) associated with the encrypted segment with the appended authentication tag, wherein the MPD comprises an @aadBase attribute with an AAD base value, wherein the AAD value is the sum of the segment number and the @aadBase attribute value, and a transmitter configured to transmit the encrypted segment with the appended authentication tag to a destination.

    摘要翻译: 一种在网络中支持认证加密的服务器装置,包括被配置为接收未加密段的接收机,被配置为选择加密密钥的处理器,初始化向量和附加认证数据(AAD),加密段,为 在超文本传输​​协议(HTTP)(DASH)媒体中的动态自适应流中传输,为加密段分配段号,将认证标签附加到加密段,存储具有附加认证标签的加密段,并更新媒体 与所附加的认证标签与所述加密段相关联的表示描述(MPD),其中所述MPD包括具有AAD基本值的@aadBase属性,其中所述AAD值是所述段号和@aadBase属性值的和, 发送器被配置为将加密的段与附加的认证标签发送到目的地。

    System and method for efficient support for short cryptoperiods in template mode

    公开(公告)号:US09231761B2

    公开(公告)日:2016-01-05

    申请号:US13871889

    申请日:2013-04-26

    摘要: System and method embodiments are provided herein for efficient representation and use of initialization vectors (IVs) for encrypted segments using template mode representation in Dynamic Adaptive Streaming over Hypertext Transfer Protocol (DASH). An embodiment method includes sending in a media presentation description (MPD), from a network server to a client, a template for generating a universal resource locator (URL) to obtain an IV that is used for encrypting a segment, in absence of an IV value in the MPD, receiving from the client a URL configured according to the template, and upon receiving the URL, returning an IV corresponding to the URL to the client. Another embodiment method includes receiving in a MPD, at a client from a network server, a template for generating a URL to obtain an IV that is used for encrypting a segment, upon detecting an absence of an IV value or IV base value in the MPD, configuring a URL for the IV using the template, sending the URL for the IV, and receiving an IV.

    Authenticated encryption support in ISO/IEC 23009-4
    8.
    发明授权
    Authenticated encryption support in ISO/IEC 23009-4 有权
    ISO / IEC 23009-4认证加密支持

    公开(公告)号:US09203811B2

    公开(公告)日:2015-12-01

    申请号:US14049609

    申请日:2013-10-09

    发明人: Alexander Giladi

    摘要: A server apparatus supporting authenticated encryption in a network, comprising a receiver configured to receive an unencrypted segment, a processor configured to selecting an encryption key, an initialization vector, and an additional authentication data (AAD), encrypt the segment, configuring the segment for transfer in a Dynamic Adaptive Streaming over Hypertext Transfer Protocol (HTTP) (DASH) media, assign a segment number to the encrypted segment, append an authentication tag to the encrypted segment, store the encrypted segment with the appended authentication tag, and update a Media Presentation Description (MPD) associated with the encrypted segment with the appended authentication tag, wherein the MPD comprises an @aadBase attribute with an AAD base value, wherein the AAD value is the sum of the segment number and the @aadBase attribute value, and a transmitter configured to transmit the encrypted segment with the appended authentication tag to a destination.

    摘要翻译: 一种在网络中支持认证加密的服务器装置,包括被配置为接收未加密段的接收机,被配置为选择加密密钥的处理器,初始化向量和附加认证数据(AAD),加密段,为 在超文本传输​​协议(HTTP)(DASH)媒体中的动态自适应流中传输,为加密段分配段号,将认证标签附加到加密段,存储具有附加认证标签的加密段,并更新媒体 与所附加的认证标签与所述加密段相关联的表示描述(MPD),其中所述MPD包括具有AAD基本值的@aadBase属性,其中所述AAD值是所述段号和@aadBase属性值的和, 发送器被配置为将加密的段与附加的认证标签发送到目的地。

    Signaling and Handling Content Encryption and Rights Management in Content Transport and Delivery
    10.
    发明申请
    Signaling and Handling Content Encryption and Rights Management in Content Transport and Delivery 有权
    内容传输和传送中的信令和处理内容加密和权限管理

    公开(公告)号:US20140020111A1

    公开(公告)日:2014-01-16

    申请号:US13941408

    申请日:2013-07-12

    IPC分类号: G06F21/10

    摘要: An apparatus comprising a memory, a processor coupled to the memory and configured to obtain a protection description for media content comprising a plurality of content items, wherein the protection description comprises data signaling at least two protection mechanisms for at least two content items in a media content, wherein each of the at least two content items is protected by one or more of the at least two protection mechanisms, and wherein the protection mechanisms for the at least two content items are different, determine the protection mechanisms for the at least two content items from the data, and process the at least two content items according to their associated protection mechanisms.

    摘要翻译: 一种装置,包括存储器,处理器,其耦合到所述存储器并且被配置为获得包括多个内容项目的媒体内容的保护描述,其中所述保护描述包括数据信令,用于媒体中的至少两个内容项的至少两个保护机制 内容,其中所述至少两个内容项中的每一个由所述至少两个保护机制中的一个或多个保护,并且其中所述至少两个内容项的保护机制是不同的,确定所述至少两个内容的保护机制 来自数据的项目,并根据其相关联的保护机制处理该至少两个内容项目。