MX349246B

Method for protecting decryption keys in a decoder and decoder for implementing said method.

Abstract

A method for securing control words (CW) within a decoder (10) in charge of deciphering the digital content protected by these control words, comprising the following steps: - for each decryption unit (14) of this decoder, uploading in a directory (22) a parity key (PK) referenced by means of an identifier (ID) associating said key to a decryption unit, - receiving at least one encrypted control word referenced by means of an indication (D) ) that allows identifying the decryption unit for which it is intended, - decrypting the control word using a first shared key with a security module (30), - identifying in the directory the parity key whose identifier (ID) corresponds to the destination indication (D) associated with the control word,- encrypt this control word using this parity key, - store in a register (15) the control word in a chronological and referenced manner.

MX349246B, drawing sheet 1
Sheet 1 of 17

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Granted
  4. Today

13 claims: 3 independent, 10 dependent

  1. 1
    A method of securing control words (CW) within a decoder (10) in charge of deciphering at least one digital content protected by said control words, said decoder (10) comprising a connected key processor (20), via a secure channel (25), to a security module (30) responsible for transmitting said control words (CW) to said decoder (10) in encrypted form, at least one decryption unit (14) responsible for decrypting the digital content, and a control word register (15) administered by means of said processor (20), the method comprising the following steps:1. Un método para asegurar pala-hras de control (CW) dentro de un decodificador (10) a cargo de descifrar al menos un contenido digital protegido por dichas palabras de control, comprendiendo dicho decodificador (10) un procesador de claves conectado (20), a través de un canal seguro (25), a un módulo de seguridad (30) a cargo de emitir dichas palabras de control (CW) hacia dicho decodificador (10) de forma encriptada, al menos una unidad de descifrado (14) a cargo de desencriptar el contenido digital, y un registro de palabras de control (15) administrado por medio de dicho procesador (20), comprendiendo el método las siguientes etapas: - cargar, para cada unidad de descifrado (14) en un directorio de claves (22) administrado por dicho procesador (20), una clave de paridad (PK) que por una parte se encuentra referenciada por medio de un identificador (ID) que la asocia con la unidad de descifrado (14) para la cual se destina únicamente y, por otra parte, es conocida por esta unidad de descifrado, - loading, for each decryption unit (14) in a key directory (22) managed by said processor (20), a parity key (PK) which on the one hand is referenced by means of an identifier (ID) which associates it with the decryption unit (14) for which it is intended solely and, on the other hand, is known from this decryption unit, - receiving, by means of said key processor (20), at least one control word (CW) encrypted by the security module (30), said control word (CW) being further referenced by an indication (D) that allows to identify the decryption unit (14) for which it is intended, - recibir, por medio de dicho procesador de claves (20), al menos una palabra de control (CW) encriptada por el módulo de seguridad (30), siendo dicha palabra de control (CW) referenciada además por una indicación (D) que permite identificar la unidad de descifrado (14) para la cual está destinada, - decrypt, by means of the key processor (20), said control word (CW) by means of a decryption key (SK) specific for said secure channel (25), - desencriptar, por medio del procesador de claves (20), dicha palabra de control (CW) por medio de una clave de desencriptación (SK) específica para dicho canal seguro (25) , -37 ,... ..... -37 ,... ..... - identificar, en dicho directjoikfe * - - * - (2 ^) 1 ^ 5 ^ 3 ^^ tNSTiTUTC MEXICANO - identificar, en dicho directjoikfe*- -*-( 2^ )1^5^3^^ tNSTiTUTC MEXICANO D £ THE PROPERTY parity key (PK) whose identifier (ID) cd ^^ S ^ onSte ^ to the destination indication (D) associated with. said word of _ control (CW), then D£ LA PROPIEDAD clave de paridad (PK) cuyo identif icador (ID) cd^^S^onSte^a la indicación de destino (D) asociada con . dicha palabra de _ control (CW), después - encrypt this control word (CW) using the parity key (PK) identified in this way, and - eñcriptar esta palabra de control (CW) utilizando la clave de paridad (PK) identificada de esta manera, y - almacenar, en dicho registro (15) de manera cronológica y referenciada, la palabra de control (CW) así encriptada utilizando la clave de paridad (PK), de manera que cualquier palabra de control específica requerida por la unidad de descifrado (14) pueda retirarse de dicho registro (15) a fin de desencriptarse y utilizarse por esta unidad de descifrado para descifrar una parte de dicho contenido digital. - store, in said register (15) in a chronological and referenced manner, the control word (CW) thus encrypted using the parity key (PK), so that any specific control word required by the decryption unit (14) can be removed from said register (15) in order to be decrypted and used by this decryption unit to decrypt a part of said digital content.
  2. 4
    The method according to any one of the preceding claims, characterized in that said control word register (15) is made accessible to any decoding unit (14) of the decoder (10). 4 . El método de acuerdo con cualquiera de las reivindicaciones precedentes, caracterizado en que dicho registro de palabras de control (15) se hace accesible para cualquier unidad de descifrado (14) del decodificador (10).
  3. 8
    The method according to the claim 6 o 8. El método de acuerdo con la roivíndícación 6 o 7, caracterizado en que la transmisión de dicha clave de paridad (PK) entre el procesador de claves (20) y dicha unidad de descifrado (14) se lleva a cabo utilizando un segundo canal seguro. 7, characterized in that the transmission of said parity key (PK) between the key processor (20) and said decryption unit (14) is carried out using a second secure channel.