Nova Patents
IL130963A

Key management for content protection

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority and filed
  2. Published
  3. Today

29 claims: 19 independent, 10 dependent

  1. 1
    P-048-IL Claims amended.doc P-048 BR 29NOV05 130963/2 CLAIMS 1. A method for black box analysis of a device capable of accessing protected content, the method comprising:providing a device to be analyzed;inputting to the device a data item comprising encrypted protected content and a plurality of encrypted versions of a content key for accessing the protected content, each of the plurality of encrypted versions being encrypted in accordance with a different one of a plurality of group keys;receiving, from the device, decrypted content representing a decryption of the protected content;determining whether the received content is one of the following: erroneous;and null, and producing a result;identifying a set of group keys comprising at least one group key which is known to the device based, at least in part, on the result, wherein the data item also comprises at least one invalid content key encrypted in accordance with one of the plurality of group keys.
  2. 2
    A method for black box analysis of a device capable of accessing protected content, the method comprising:providing a device to be analyzed;inputting to the device a data item comprising encrypted protected content and a plurality of encrypted versions of a content key for accessing the protected content, each of the plurality of encrypted versions being encrypted in accordance with a different one of a plurality of group keys;receiving, from the device, decrypted content representing a decryption of the protected content;determining whether the received content is one of the following: erroneous;and null, and producing a result;identifying a set of group keys comprising at least one group key which is known to the device based, at least in part, on the result, 22 130963/2 wherein the data item also comprises at least one invalid content key encrypted in accordance with one of the plurality of group keys, and the protected content is protected in accordance with the following method: providing a plurality of authorized devices;dividing the plurality of authorized devices into a plurality of groups, each of the plurality of authorized devices being comprised in at least one of the plurality of groups, no two devices of the plurality of authorized devices being comprised in exactly the same groups;determining whether at least one device of the plurality of authorized devices is to be prevented from having access to the protected content and, if at least one device is to be prevented, removing all groups comprising the at least one device from the plurality of groups, thus producing a set of remaining groups;determining an authorized set comprising groups from the set of remaining groups, such that each device of the plurality of authorized devices which was not determined, in the determining whether step, to be prevented from having access is comprised in at least one group of the authorized set;assigning, to each one of the plurality of authorized devices, a set of keys comprising one group key for each group of which the one device is a member;and utilizing at least some of the group keys for communication of a content decryption key to at least one of the plurality of authorized devices, the utilizing step comprising, for each of the plurality of authorized devices: obtaining the content decryption key, wherein the obtaining comprises performing no more than a predetermined number of decryptions.
  3. 7
    A method according to any of claims 2-6 and also comprising the step of:at at least one of the authorized devices, using the group key of the set of keys corresponding to the group of which the authorized device is a member.
  4. 8
    A method according to any of claims 2-7 and wherein each group key of the set of keys is assigned an initial value, and said initial value can not be changed.
  5. 9
    A method according to any of the above claims and wherein the authorized set comprises a plurality of maximal groups from the set of remaining groups, such that each maximal group is not a subset of any one of the set of remaining groups.
  6. 10
    A method according to any of the above claims and wherein the determining whether step comprises receiving an identification of the at least one device. 24 130963/2
  7. 11
    A method according to any of the above claims and wherein each two devices of the plurality of authorized devices have at least one group key in common.
  8. 12
    A method according to any of the above claims and wherein at least some of the authorized devices are not in communication with a central authorization facility after an initial manufacturing period.
  9. 13
    A method for black box analysis of a device capable of accessing protected content, the method comprising:providing a device to be analyzed;inputting to the device a data item comprising encrypted protected content and a plurality of encrypted versions of a content key for accessing the protected content, each of the plurality of encrypted versions being encrypted in accordance with a different one of a plurality of group keys;receiving, from the device, decrypted content representing a decryption of the protected content;determining whether the received content is one of the following: erroneous;and null, and producing a result;identifying a set of group keys comprising at least one group key which is known to the device based, at least in part, on the result, wherein the data item also comprises at least one invalid content key encrypted in accordance with one of the plurality of group keys, and the protected content is protected in accordance with the following method: distributing a protected content access key independently encrypted with each group key of a set of group keys, wherein none of a plurality of devices to be prevented from having access to protected content are members of any group associated with any of the set of group keys;and at each authorized device having access to the protected content, performing no more than a predetermined number of decryption 25 130963/2 operations, said predetermined number being the same for all authorized devices, to obtain the protected content access key from an encrypted form thereof, said encrypted form being encrypted with a group key corresponding to a group of which said authorized device is a member, and wherein each group key of the set of group keys has an initial value, and the initial value can not be changed, and said predetermined number does not depend on the number of authorized devices.
  10. 15
    A method according to any of claims 2-14 and also comprising:generating each of said group keys as a plurality of independently generated sets of group keys, wherein no group key of any one independently generated set is based, even in part, on any key of any other independently generated set.
  11. 16
    A method according to any of claims 2-14 and also comprising:generating each of said group keys as a plurality of independently generated sets of group keys, wherein each group key is based, at least in part, pseudo-randomly on a source key.
  12. 17
    A method according to any of claims 2-15 and also comprising:dividing the plurality of groups into a hierarchical set of groups, said hierarchical set of groups comprising a plurality of groups comprising at least a first group and a second group, each of said first group and said second group being associated with first and second group key generation information respectively;and generating a least one group key in each of said first group and said second group using said associated group key generation information, wherein 26 130963/2 said second group key generation information can be derived from said first group key generation information.
  13. 20
    A method according to any of claims 17-19 and wherein at least one of said first group key generation information and said second group key generation information is embedded in at least one removable security device.
  14. 23
    A method according to any of claims 1-22 and also comprising performing the following steps at least once before performing the identifying step:choosing a new plurality of encrypted versions of the content key;and performing the inputting, receiving and determining steps.
  15. 25
    A method according to any of claims 1-24 and wherein the identifying step comprises identifying a group key which is one of the plurality of group keys with which the invalid content key is encrypted.
  16. 26
    A method according to any of claims 1-25 and wherein the identifying step comprises identifying the one of the plurality of group keys with which the invalid content key is encrypted.
  17. 27
    A method according to any of claims 1 - 26 and wherein the identifying step comprises identifying a group key which is not one of the plurality of group keys with which the invalid content key is encrypted.
  18. 28
    A method according to any of claims 1-27 and substantially as described hereinabove.
  19. 29
    A method according to any of claims 1 - 27 and substantially as shown in the drawings. Respectfully submitted, Sanford T. Colb Co. Advocates Patent Attorneys C:34543 28
Independent claims19