Nova Patents
CA2498684C

Apparatus for encryption key management

Abstract

An apparatus (102) and a receiver (110), which are in a broadband communication system (100), includes the logic (232) necessary for encrypting content (254) through the use of encryption keys. This content is received by the receivers (110). The receiver (110) validates the keys and denies the use of the content (254) if the keys become invalid.

CA2498684C, drawing sheet 1
Sheet 1 of 14

Term

Term ended

Expired 17 September 2022, 4 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

71 claims: 6 independent, 65 dependent

  1. 1
    CA 02498684 2010-04-13 CLAIMS 1. A method of controlling access to an encrypted instance of service, which was encrypted by a first key, the method implemented in a receiver in a subscriber television system, the method comprising the steps of :(a) encrypting the first key using a public key of a private key-public key pair belonging to the receiver, thereby converting the first key into an encrypted first key;(b) associating a key validator with the encrypted first key, wherein the key validator includes a time indicator that indicates whether the encrypted first key is valid;(c) determining whether the encrypted first key is valid;(d) responsive to the encrypted first key being valid, decrypting the encrypted first key thereby recovering the first key;and (e) responsive to the encrypted first key being valid, decrypting the encrypted service instance using the recovered first key.
  2. 23
    A receiver in a digital subscriber network, the receiver receiving content provided by an entitlement agent through a first communication link, the receiver comprising:a first key validator including a validation token having a time specifier for which the first key is validated;an encryptor adapted to encrypt a first key using a public key of a public key-private key pair associated with the receiver;and a decryptor adapted to decrypt the first key using the private key of the public key-private CA 02498684 2010-04-13 key pair.
  3. 34
    In a receiver coupled to a subscriber television network, a method of controlling access to an encrypted instance of service provided to the receiver by a headend of the subscriber television network, the method comprising the steps of :receiving at the receiver a service instance ;encrypting the service instance with a first key;generating a key validator having a time indicator included therein;encrypting the first key with a second key, thereby converting the first key into an encrypted first key;associating the encrypted first key with the key validator;storing the encrypted service instance, the encrypted first key and the key validator in a storage device;responsive to receiving a request for the stored encrypted service, retrieving the encrypted first key and the key validator from the storage device;responsive to retrieving the encrypted key validator, determining whether the encrypted first key is valid using the key validator;responsive to the encrypted first key being valid, decrypting the encrypted first key with a CA 02498684 2010-04-13 third key, thereby recovering the first key;and responsive to recovering first key, decrypting the encrypted service instance.
  4. 45
    In a subscriber television system having a head-end and a receiver that receives a service instance from the head-end, the receiver, the receiver comprising:a first processor adapted to encrypt a service instance with a first key and adapted to encrypt the first key with a public key of a public key-private key pair belonging to the receiver, thereby converting the first key into an encrypted first key, the first processor further adapted to generate a key validator having a time indicator included therein;storage means in communication with the first processor, the storage means adapted to store the encrypted first key, the encrypted service instance and a key authenticator;a secure element in communication with the first processor, the secure element having a second processor and a memory, the memory having the private key belonging to the receiver stored therein, the second processor adapted to generate a key authenticator using at least a portion of the key validator and the public key belonging to the receiver, wherein the memory of the secure element is not accessible to the first processor;and an input port in communication with the first processor adapted to receiver commands from a subscriber input device, wherein responsive to a command from the subscriber input device received at the input port, the first processor determines whether the encrypted first key is valid using the key validator, the second processor decrypts the encrypted first key using the private key, thereby recovering the first key, and determines whether the key validator is authentic using the private key and the key validator, and responsive to both the first key being valid and the key validator being authentic, the first processor decrypts the service instance using the recovered first key.
  5. 57
    In a subscriber network system having a head-end and a receiver that receives a service instance from the head-end, the receiver, which is located remotely from the head-end, stores the service instance at the remote location and restricts access to the stored service instance, the receiver comprising:a port adapted to receive the service instance;a storage device at the remote location, the storage device having an encrypted first key, a key validator, and key authenticator stored therein, and wherein the first key is used for decrypting the service instance when the first key is valid;a memory having a private key-public key pair for the receiver stored therein;and a processor in communication with the memory, the processor adapted to use the public key of the receiver to encrypt the first key and generate the key validator and the key authenticator, wherein the key validator includes a time indicator used for determining whether the first key is valid or has expired, the key authenticator includes a hash digest signed by the private key of the receiver, and the hash digest is the output of a hash function having as inputs at least a portion of the key validator and at least a portion of the first key.
  6. 65
    In a subscriber television system having a head-end and a receiver that receives a service instance from the head-end, the receiver, which is located remotely from the head-end at a subscriber's premises restricts access to the stored service instance, a method of accessing the restricted service instance, the method implemented at the receiver and comprising the steps of :receiving the service instance;encrypting the service instance with a first key;storing the encrypted service instance in a storage device at the premises of the subscriber;encrypting the first key with a second key, thereby converting the first key to an encrypted first key, wherein the second key is a public key of a private key-public key pair belonging to the receiver;associating a key validator with the encrypted first key, wherein the key validator includes a time indicator that indicates whether the encrypted first key is valid;associating a key authenticator with the encrypted first key, wherein the key authenticator includes a digest signed by the private key and indicates whether the key validator is authentic;storing the encrypted first key, the key validator, and the key authenticator;determining whether the encrypted first key is valid using the key validator ;responsive to the encrypted first key being valid, decrypting the encrypted first key with the private key of the receiver, thereby recovering the first key;responsive to the encrypted first key being valid, authenticating the key validator using the key authenticator;responsive to both the encrypted first key being valid and the key validator being authentic, decrypting the encrypted service instance.