A system for secure delivery of on-demand content over broadband access networks
utilizes a pair of servers and security mechanisms to prevent client processes
from accessing and executing content without authorization. A plurality of encrypted
titles are stored on a content server coupled to the network. An access server
also coupled to the network contains the network addresses of the titles and various
keying and authorization data necessary to decrypt and execute a title. A client
application executing on a user's local computer system is required to retrieve
the address, keying and authorization data from the access server before retrieving
a title from the content server and enabling execution of the title on a user's
local computer system.