CA2804427C

Technique for transferring encrypted content from first device to second device associated with same user

Abstract

A "trusted domain" is established within which content received from a communications network, e.g., a cable TV network, is protected from unauthorized copying thereof, in accordance with the invention. In an illustrative embodiment, the trusted domain includes a device associated with a user which receives content from the cable TV network. The content may be encrypted using a content key in accordance, e.g., with a 3DES encryption algorithm before it is stored in the device. In addition, a first encrypted content key version and a second encrypted content key version are generated by respectively encrypting the content key with a public key associated with the device and another public key associated with the user, in accordance with public key cryptography. The first and second encrypted content key versions are stored in association with the encrypted content in the device storage. The encrypted content can be migrated from a first device to a second device, and can be decrypted in the second device if the second device is associated with the same user, and also provided with the second encrypted content key version.

CA2804427C, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Expired 15 July 2025, 1.2 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

22 claims: 3 independent, 19 dependent

  1. 1
    CA 02804427 2013-12-05 What is claimed is:1. A system configured to enable decryption of encrypted content in a first device, said encrypted content in said first device being decrypted using a content key, said system comprising: a second device configured to transmit a first encrypted content key to said first device;an apparatus configured to receive said first encrypted content key from said first device;and a database configured to supply a first cryptographic element associated with a user of said first device;wherein said apparatus is further configured to: recover said content key via decryption of said first encrypted content key with said first cryptographic element;generate a second encrypted content key via encryption of said recovered content key with a second cryptographic element associated with said first device;and provide at least said second encrypted content key to said first device, said content key being recoverable at said first device based at least in part on said second encrypted content key.
  2. 8
    A method for use in a first client device of a content distribution network, said network comprising at least a network entity and a plurality of client devices, said method comprising:CA 02804427 2013-12-05 receiving encrypted content at said first device;receiving a first encrypted version of a cryptographic element;receiving a second encrypted version of said cryptographic element from said network entity;deriving said cryptographic element using at least one of said first and second encrypted versions of said cryptographic element;and decrypting said encrypted content using said cryptographic element.
  3. 16
    A method for use in an apparatus for decrypting encrypted content, said encrypted content being stored in a first device remote from said apparatus, and said encrypted content being decrypted using a content key, said method comprising:receiving a first encrypted content key from said first device, said first encrypted content key associated with said second device;obtaining a first cryptographic element associated with a user of said first device;using said first cryptographic element to decrypt said first encrypted content key, thereby recovering said content key;using a second cryptographic element associated with said firstdevice to encrypt said recovered content key, thereby generating a second encrypted content key;and providing said second encrypted content key to said first device, said content key being recoverable by said first device based on at least in part on said second encrypted content key.