Nova Patents
EP2225848A2

Key distribution system

Abstract

This record has no abstract on file.

Term

2.4 yearsto projected expiry

Projected expiry 3 March 2029, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

37 claims: 22 independent, 15 dependent

  1. 1
    Claims of equivalent WO 2009112966 A2 What is claimed is:CLAIMS 1. A key distribution system for controlling access to content by a plurality of rendering devices, comprising: an epoch module to provide a plurality of epochs, each of the epochs including a plurality of service key periods;a service key module to provide a plurality of service keys so that, for each one of the epochs, a batch of the service keys is provided for employment in decryption of the content across the service key periods of the one epoch;a group module to provide a plurality of group keys for each of the epochs such that: for each of the epochs, each of the rendering devices is assigned one of the group keys such that more than one of the rendering devices may be assigned a same one of the group keys;for each of the epochs, the assignment of the group keys groups together the rendering devices having the same one group key, thereby defining a plurality of groups;each of the service keys is valid across all the groups;and in different ones of the epochs, the rendering devices are grouped differently;an encryption module to encrypt, for each of the epochs, each of the service keys, in the batch of the service keys with each of the group keys, such that each of the service keys is individually encrypted with a different one of the group keys yielding a plurality of group-key-encrypted service keys from each of the service keys;and a delivery module to distribute to the rendering devices, for each one of the epochs, the group-key-encrypted service keys for the batch of the service keys and the group keys of the one epoch.
  2. 6
    The system according to any of claims 3-5, wherein the epoch module is operative to provide, for each one of the epochs, an epoch key, the encryption module being operative to encrypt, for each one of the groups, the at least one key package of the one group using the epoch key of the one epoch.
  3. 7
    The system according to any of claims 3-6, wherein the delivery module is operative to include an identification in the at least one key package of the one group, the identification identifying the at least one key package of the one group as being associated with the one group.
  4. 8
    The system according to any of claims 1-7, wherein the group module is operative to assign the group keys to the rendering devices randomly/pseudo-randomly.
  5. 9
    The system according to any of claims 1-7, wherein:the rendering devices are operative to determine to which of the groups the rendering devices belong by employing a function having parameters;and the delivery module is operative to distribute the function and/or the parameters to the rendering devices.
  6. 12
    The system according to any of claims 1-11, further comprising a traitor identifier to identify a traitor device of the rendering devices based on the traitor device distributing, at least one of the group-key-encrypted service keys and/or at least one of the group keys.
  7. 13
    The system according to any of claims 2-12, further comprising a period master key module to provide for each one of the service key periods in the one epoch a different period master key, the encryption module being operative to further encrypt each one of the group-key-encrypted service keys using the period master key of the one service key period of the one group-key encrypted service key being encrypted.
  8. 16
    The system according to any of claims 13-15, wherein the period master key module is operative to provide the period master key for each one of the service key periods such that the period master key for the one service key period is the same across all of the groups and across all of the services.
  9. 17
    The system according to any of claims 1-16, wherein:each of the rendering devices is associated with a different user key;the user key of each of the rendering devices is associated with one of the group keys;the encryption module is operative to encrypt, for each one of the rendering devices, the one group key of the one rendering device using the user key of the one rendering device, yielding a user-key-encrypted group key for each of the rendering devices;and the delivery module is operative to distribute to the rendering devices the user-key- encrypted group key of each of the rendering devices.
  10. 21
    The system according to any of claims 1-20, wherein:the group module is operative to create a plurality of supergroups, one of the supergroups including the plurality of groups for the rendering devices, another one of the supergroups including a plurality of other groups for a plurality of other rendering devices;the group module is operative to provide a plurality of other group keys for each of the epochs thereby defining the other groups, in different ones of the epochs the other rendering devices are grouped differently;the encryption module is operative to encrypt, for each of the epochs, each of the service keys in the batch of the service keys with each of the other group keys, such that each one of the service keys is individually encrypted with a different one of the other group keys yielding a plurality of other-group- key-encrypted service keys from each one of the service keys;and the delivery module is operative to distribute the other-group-key- encrypted service keys for the batch of the service keys and the other group keys of the one epoch to the other rendering devices according to a first delivery schedule.
  11. 24
    The system according to any of claims 1-20, wherein:the group module is operative to create a plurality of supergroups, one of the supergroups including the plurality of groups for the rendering devices, another one of the supergroups including a plurality of other groups for a plurality of other rendering devices;the epoch module is operative to provide a plurality of other epochs, each of the other epochs including a number of the service key periods, the epochs commencing according to a plurality of first start dates, the other epochs commencing according to a plurality of second start dates, the first start dates being different from the second start dates;the service key module is operative to provide, for each of the other epochs, another batch of the service keys;the group module is operative to provide a plurality of other group keys for each of the other epochs thereby defining the other groups, in different ones of the other epochs the other rendering devices are grouped differently;the encryption module is operative to encrypt, for each of the other epochs, each of the service keys in the other batch of the service keys with each of the other group keys, such that each of the service keys of the other batch is individually encrypted with a different one of the other group keys yielding a plurality of other-group-key-encrypted service keys from each one of the service keys of the other batch;and the delivery module is operative to distribute, for each one of the other epochs, the other-group-key-encrypted service keys for the other batch of the service keys and the other group keys of the one epoch to the other rendering devices.
  12. 25
    A key distribution system for controlling access to content by a plurality of rendering devices, each of the rendering devices having a user with at least one user characteristic, the system comprising:a service key module to provide a batch of service keys for employment in decryption of the content by the rendering devices;a group module to group together the rendering devices into a plurality of groups according to the at least one user characteristic of the user of each of the rendering devices;and a delivery module to distribute the batch of service keys periodically to the rendering devices according to a different schedule for different ones of the groups.
  13. 26
    A key distribution system for controlling access to content by a plurality of rendering devices, the system comprising:a service key module to provide a batch of service keys for employment in decryption of the content by the rendering devices;a group module to group together the rendering devices into a plurality of groups;and a delivery module to distribute the batch of service keys periodically to the rendering devices with a different frequency for different ones of the groups.
  14. 27
    A key distribution system for controlling access to content by a plurality of rendering devices, the system comprising:a group module to group together the rendering devices into a plurality of groups;an epoch module is operative to provide a plurality of epochs, the epochs commencing on a different start date for different ones of the groups;a service key module to provide a batch of service keys for employment in decryption of the content by the rendering devices in each of the epochs;and a delivery module to distribute the batch of the service keys in each of the epochs to the rendering devices.
  15. 28
    The system according to any of claims 25-27 ', wherein the groups are supergroups, each of the supergroups including a plurality of subgroups, each of the subgroups of each of the supergroups in each of the epochs being associated with a different subgroup key.
  16. 29
    The system according to any of claims 25-28, wherein one of the rendering devices is transferred from one of the groups to another one of the groups.
  17. 30
    A method performed by a first rendering device, the method comprising:receiving a plurality of group keys in a plurality of key packages, the group keys being associated with a plurality of groups of rendering devices, each of the key packages including a group indication to identify the groups of the group keys in the key packages;receiving at least one of: a function having at least one parameter;and the at least one parameter;employing the function to determine which of the groups the first rendering device belongs to.
  18. 32
    A method performed by a first rendering device, the method comprising:receiving a plurality of user-key-encrypted group keys associated with a plurality of rendering devices, each of the rendering devices is associated with a different user key, the user key of each of the rendering devices is associated with one of a plurality of group keys, the user-key- encrypted group keys are produced by encrypting, for each one of the rendering devices, the one group key of the one rendering device using the user key of the one rendering device;and identifying which one of the user-key-encrypted group keys is associated with the first rendering device by trial and error decryption of the user- key-encrypted group keys.
  19. 34
    A key distribution method for controlling access to content by a plurality of rendering devices, comprising:providing a plurality of epochs, each of the epochs including a plurality of service key periods ;providing a plurality of service keys so that, for each one of the epochs, a batch of the service keys is provided for employment in decryption of the content across the service key periods of the one epoch;providing a plurality of group keys for each of the epochs such that: for each of the epochs, each of the rendering devices is assigned one of the group keys such that more than one of the rendering devices may be assigned a same one of the group keys;for each of the epochs, the assignment of the group keys groups together the rendering devices having the same one group key, thereby defining a plurality of groups;each of the service keys is valid across all the groups;and in different ones of the epochs, the rendering devices are grouped differently;encrypting, for each of the epochs, each of the service keys, in the batch of the service keys with each of the group keys, such that each of the service keys is individually encrypted with a different one of the group keys yielding a plurality of group-key-encrypted service keys from each of the service keys;and distributing to the rendering devices, for each one of the epochs, the group-key-encrypted service keys for the batch of the service keys and the group keys of the one epoch.
  20. 35
    A key distribution method for controlling access to content by a plurality of rendering devices, each of the rendering devices having a user with at least one user characteristic, the method comprising:providing a batch of service keys for employment in decryption of the content by the rendering devices;grouping together the rendering devices into a plurality of groups according to the at least one user characteristic of the user of each of the rendering devices;and distributing the batch of service keys periodically to the rendering devices according to a different schedule for different ones of the groups.
  21. 36
    A key distribution method for controlling access to content by a plurality of rendering devices, the method comprising:providing a batch of service keys for employment in decryption of the content by the rendering devices;grouping together the rendering devices into a plurality of groups;and distributing the batch of service keys periodically to the rendering devices with a different frequency for different ones of the groups.
  22. 37
    A key distribution method for controlling access to content by a plurality of rendering devices, the method comprising:grouping together the rendering devices into a plurality of groups;providing a plurality of epochs, the epochs commencing on a different start date for different ones of the groups;providing a batch of service keys for employment in decryption of the content by the rendering devices in each of the epochs;and distributing the batch of the service keys in each of the epochs to the rendering devices.
Independent claims22