EP1126355A1

Method and system for distributing programs using tamper resistant processor

Abstract

A scheme for distributing executable programs through a network from a program distribution device to a client device having a tamper resistant processor which is provided with a unique secret key and a unique public key corresponding to the unique secret key in advance is disclosed. In this scheme, a first communication path is set up between the program distribution device and the client device, and a second communication path directly connecting the program distribution device and the tamper resistant processor is set up on the first communication path. Then, the encrypted program is transmitted from the program distribution device to the tamper resistant processor through the second communication path.

EP1126355A1, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Projected expiry passed 14 February 2021, 5.6 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

19 claims: 7 independent, 12 dependent

  1. 1
    A program distribution device for distributing executable programs through a network to a client device having a tamper resistant processor which is provided with a unique secret key and a unique public key corresponding to the unique secret key in advance, the program distribution device comprising:a first communication path set up unit configured to set up a first communication path between the program distribution device and the client device;a second communication path set up unit configured to set up a second communication path directly connecting the program distribution device and the tamper resistant processor, on the first communication path;an encryption processing unit configured to produce an encrypted program by encrypting an executable program to be distributed to the client device;anda transmission unit configured to transmit the encrypted program to the tamper resistant processor through the second communication path.
  2. 6
    The program distribution device according to any one of claims 1-5, wherein communications through the second communication path are cipher communications.
  3. 7
    A client device for receiving programs distributed from a program distribution device through a network, the client device comprising:a tamper resistant processor which is provided with a unique secret key and a unique public key corresponding to the unique secret key in advance;a first communication path set up unit configured to set up a first communication path between the program distribution device and the client device;a second communication path set up unit configured to set up a second communication path directly connecting the program distribution device and the tamper resistant processor, on the first communication path;anda program receiving unit configured to receive an encrypted program from the program distribution device through the second communication path.
  4. 12
    The client device of any one of claims 7-11, wherein communications through the second communication path are cipher communications.
  5. 13
    A program distribution system, comprising:a program distribution device connected to a network, for distributing executable programs through the network;anda client device connected to the network, for receiving the executable programs distributed from the program distribution device through the network;wherein the client device has: a tamper resistant processor which is provided with a unique secret key and a unique public key corresponding to the unique secret key in advance;a client side first communication path set up unit configured to set up a first communication path between the program distribution device and the client device;a client side second communication path set up unit configured to set up a second communication path directly connecting the program distribution device and the tamper resistant processor, on the first communication path;anda program receiving unit configured to receive an encrypted program from the program distribution device through the second communication path;and the program distribution device has: a server side first communication path set up unit configured to set up the first communication path between the program distribution device and the client device;a server side second communication path set up unit configured to set up the second communication path directly connecting the program distribution device and the tamper resistant processor, on the first communication path;an encryption processing unit configured to produce the encrypted program by encrypting an executable program to be distributed to the client device;anda transmission unit configured to transmit the encrypted program to the tamper resistant processor through the second communication path.
  6. 14
    A method for distributing executable programs through a network from a program distribution device to a client device having a tamper resistant processor which is provided with a unique secret key and a unique public key corresponding to the unique secret key in advance, the method comprising the steps of:setting up a first communication path between the program distribution device and the client device;setting up a second communication path directly connecting the program distribution device and the tamper resistant processor, on the first communication path;producing an encrypted program by encrypting an executable program to be distributed to the client device, at the program distribution device;andtransmitting the encrypted program from the program distribution device to the tamper resistant processor through the second communication path.
  7. 19
    The method of any one of claims 14-18, wherein communications through the second communication path are cipher communications.