Information enciphering method
Abstract
In an encryption method, an encryption apparatus, a recording method, a decoding method, a decoding apparatus and a recording medium, encryption keys (K0 - Kn) can be managed with ease by hierarchizing encryption keys using a one-way function (F). <IMAGE>

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
5 claims: 2 independent, 3 dependent
- 1Patent claims Zastrzeżenia patentowe 1. A method of encrypting information, in particular software or data, using a predetermined encryption key, characterized in that the encryption key is arranged hierarchically by means of a sequentially encrypting version of the encryption key from a direct previously encrypted version of the encryption key using a one-way function and specific information is decoded by using a hierarchy of encryption key, only the later version, by excluding the first version of the primary encryption key, it has the ability to decode specific information of the previous version of the encryption key. 1. Sposób szyfrowania informacji, w szczególności oprogramowania lub danych przy użyciu z góry ustalonego klucza szyfrowania, znamienny tym, że hierarchicznie układa się klucz szyfrowania za pomocą sekwencyjnie szyfrującej wersji klucza szyfrowania z bezpośredniej uprzednio zaszyfrowanej wersji klucza szyfrowania z zastosowaniem funkcji jednokierunkowej i dekoduje się określoną informację za pomocą ułożonego hierarchicznie klucza szyfrowania, przy czym tylko późniejsza wersja, wyłączając pierwszą wersję głównego klucza szyfrowania, ma zdolność dekodowania określonej informacji uprzedniej wersji klucza szyfrowania.
- 4A method of encrypting information, in particular software or data, using a predetermined encryption key, characterized in that the encryption key is arranged hierarchically by means of a sequentially encrypting version of the encryption key from a direct previously encrypted version of the encryption key using a one-way function and specific encrypted information is recorded on the recording medium, only the later version, by excluding the first version of the primary encryption key, it has the ability to decode specific information of the previous version of the encryption key. 4. Sposób szyfrowania informacji, w szczególności oprogramowania lub danych przy użyciu z góry ustalonego klucza szyfrowania, znamienny tym, że hierarchicznie układa się klucz szyfrowania za pomocą sekwencyjnie szyfrującej wersji klucza szyfrowania z bezpośredniej uprzednio zaszyfrowanej wersji klucza szyfrowania z zastosowaniem funkcji jednokierunkowej i zapisuje się określoną zaszyfrowaną informację na nośniku zapisu, przy czym tylko późniejsza wersja, wyłączając pierwszą wersję głównego klucza szyfrowania, ma zdolność dekodowania określonej informacji uprzedniej wersji klucza szyfrowania.
Independent claims2
138 paragraphs in 23 sections, as filed
The subject of the invention is a method of information encryption.
In particular, the present invention relates to the field of data encryption or software, saving encrypted data or programs on a medium, and then decoding encrypted software or data, which is associated with protection against unauthorized use of programs or data recorded on such media as a digital video disc, or programs and data available on the network.
To protect against the unauthorized use of programs or data, an encryption method is used, which consists in using adopted code keys and recording encrypted data to a digital video entry board, hereinafter referred to as a CPW disc (DVD), or entering them on the network. Encrypted software or data distributed over the network or recorded to a CPW disc can be decoded using the encryption keys provided separately.
A hierarchical key management system containing numerous secured terminals is known from US Pat. No. 4,888,801. These terminals provide secure access to the appropriate number of users. The user enters the activation and security device or key into a secured terminal for access to a secured connection through a fixed telecommunications network. A group of secured wireless terminals is connected to a key certification certificate. There may be many groups of key certification certificates and corresponding secure user terminals. At the highest level, the key certification certificate center secures connections through key certification certificates. In turn, the key certification certificate authorizes secure connections between users. As a result, if one key management level is random, the other levels and users are not at risk.
182 259
From US 4888796 a device is reproducing program material, by means of which a user of a device receiving a program signal, such as a telephone, television, radio, cassette recorder, or the like, can automatically and selectively secure the reception and response by the receiving device , against unwanted transmissions. The display device is capable of recognizing the non-interfering material content signals transmitted together with the program signals received by the receiving device and is capable of automatically shutting down the receiving device in response to recognition of the material content signal.
A known method and apparatus for encrypting a signal is described in US Pat. No. 5,115467. In this known solution, a shared key and a separate key are generated from the same common secret generating key. The key generator is combined with common parameter data to provide a common intermediate key. The common intermediate key is used to create the shared key. The generating key is also combined with separate parameter data to provide a separate intermediate key. A separate intermediate key is used to create a separate key. The system is particularly useful for providing category keys and programs for use in an encrypted satellite television system. The generating key is used to create the same category key for all uplinks and different program keys for each uplink.
In addition, the publication No. WO 95/27354 discloses a method and apparatus for electronic distribution of licenses that can be used in a network or non-network environment for the convenience of licensing and delivery. In addition, these solutions include the use of product distribution of the compact disc CD ROM. This known method and device exhibit the ability to immobilize electronically distributed material and the ability to license certain material to users in the distribution chain. This method and device protects many electronic licenses by decommissioning those licenses in which the access key is required to make the license available for use. This method and device reduce the cost of electronic dissemination by the ability to distribute many products, product versions and licenses that are useless before performing the authorization procedure.
The known method of encrypting and decoding information will be briefly explained on the basis of Figure 1, which shows the principle of encrypting and decoding information.
The transmitter 101 encrypts plain text M (transmitted information) using the encryption key K1 to obtain the encrypted text C (in practice, transmitted data). The encrypted text C is transmitted to the receiver 102, in which it is decoded using the decoding key K2, to obtain the explicit M text. In this way, the plain text is transmitted from the transmitter to the receiver. Often, people who do not have a decoding key intercept and decode the encrypted C text using cipher breaker 103. The way in which people who legally possess the key obtain the explicit M text from the encrypted C text is generally referred to as decoding, while an analogous act performed by people who do not have a key and intercept encrypted text are referred to as decryption.
Once disclosed, the encryption key used in the method described above becomes useless and does not prevent the unauthorized use of data. Therefore, the disclosed keys are exchanged for new ones, which are further used to encrypt the software or data, preventing their unauthorized use.
In practice, it often happens that despite the exchange of a key for a new one, some of the software or data is still encrypted using the old key, which must therefore be kept. Consequently, each encryption key update increases the number of stored keys, and thus creates software and hardware problems related to the need to use stored encryption keys. On the other hand, updating encryption hardware keys is sometimes associated with great difficulties.
182 259
The method of encrypting information, in particular software or data using a predetermined encryption key, according to the invention is characterized in that the encryption key is arranged hierarchically by means of a sequentially encrypting version of the encryption key from a direct previously encrypted version of the encryption key using a one-way function and is decoded specific information using a hierarchy of encryption key, only the later version, excluding the first version of the master encryption key, has the ability to decode the specific information of the previous version of the encryption key.
It is beneficial that the first of the hierarchically arranged encryption keys is the primary key.
It is advantageous that the special information is also encrypted using the hierarchical encryption key.
In a different solution, the method of encrypting information according to the invention is characterized in that the encryption key is arranged hierarchically by means of a sequentially encrypting version of the encryption key from a direct previously encrypted version of the encryption key using a one-way function and the specified encrypted information is recorded on the recording medium, only later version, excluding the first version of the master encryption key, has the ability to decode specific information of a previous version of the encryption key.
It is preferred that together with the specific encrypted information, special information encrypted with the encryption key is recorded on the recording medium.
According to the solution of the invention, easy to use hierarchical encrypted keys are used to encrypt data or software, encrypted data or programs are saved on a carrier for later decoding of encrypted information.
The subject of the invention is explained in the embodiments in the drawing, in which Fig. 1 is a block diagram illustrating the principle of encrypting and decoding encrypted software or data, Fig. 2 is a schematic diagram illustrating an exemplary hierarchical structure of cipher keys, Fig. 3 is a flowchart explaining the method making a CPW digital video board. on which the encrypted information is saved, fig. 4 - schematically a CPW disc on which a secret number and encrypted information was recorded, Fig. 5 - block diagram of the encryption device, Fig. 6 - block structure of the integrated circuit for decoding information recorded on the CPW disc shown in Fig. 4, Fig. 7 - flowchart referring to the integrated circuit shown in Fig. 6, Fig. 8 - a detailed flowchart referring to the working key preparation step shown in Fig. 7, Fig. 9 - a second, detailed flowchart relating to the working key preparation step, shown in Fig. 7, Fig. 10 - a diagram illustrating how the cipher keys are recorded on CPW discs and distributed, Fig. 11 - a diagram illustrating the way in which what cipher key is placed in the decoding and distributed software, and Fig. 12 is a diagram illustrating how the cipher key is placed in the integrated circuit and distributed;
A schematic diagram illustrating how the encryption keys are arranged in a hierarchical structure is shown in Fig. 2. The encryption key K1, the next in the hierarchy n, is formed relative to the main encryption key KO, the first in the hierarchy, using the so-called one-way function F. The task of the one-way function F, one of the so-called one-way functions, is to carry out irreversible calculations, as a result of which the K1 encryption key can be easily calculated from the main encryption key Ko, while making reverse calculations is practically impossible, i.e. the main KO encryption key is practically not it can be calculated from the next encryption key K1 in the hierarchy.
Encryption algorithms, such as DES Data Encryption Standard (publication FIPS 46,1977, National Bureau of Standards), Fast FEAL Encryption Algorithm (S. Miyaguschi, "FEAL Cipher Family", Lecture Notes in Computer Science, 537 (1001), pp. 627 to 638, (Advances in Cryptology - CRYPTO '90)), or a message shortening algorithm such as Message Digest algorithm (MD4; RL Rivest, 537 (1001), p. 303 to 311, Advances in Cryptology - CRYPTO '90)) or Standard Displacement
182 259
Security SHS (Secure Hash Standard, publication FIPS 180,1993, National Bureau of Standards). DES and FEAL algorithms are described in detail in "Cipher and Information Security by Tsujii and Kasahara, July 1993".
The one-way function will be described in detail, including examples, below.
When using the DES algorithm, the one-way function and the algorithm are bound by an equation
F9k) = DES (IV, k) (1) in which IV (Initial Vector) is any starting vector, and k is a key.
In addition, the following algorithms can be used in the unidirectional function:
- block (resulting) encryption algorithm
- arithmetic algorithm.
Using a block (result) algorithm, encrypted text is obtained by encrypting plain text using a key, as described in the equation
C = Enc (P, k), (2) in which C is an encrypted text, P is plain text, and is a key.
In particular, a set of bits of a fixed length is obtained by irreversible key transformation by some type of displacement function in each block.
The plain text is then, in several circuits, processed in the permutation or replacement module to replace the data or perform a similar operation. In each circulation, plain text is subjected to some transformations using a bit string obtained from the key, for example, a logical symmetrical difference operation (exclusive OR).
The arithmetic algorithm is used in issues related to discrete algorithms, as expressed in the equation
F (k) <=> ak mod p, (3) in which a is the accepted constant, k is the key, and ap is the prime number. In equation (3), the symbol '<=>' means 'by definition'.
In particular, the function F (k) is defined as "the remainder of dividing the product of k by p". In this case, the function F (k) can easily be obtained from the key k, but it is very difficult to recover the key k from the function F (k).
As mentioned, after obtaining the next encryption key KI in the hierarchy, from the master key KO, using the one-way function F (k), the encryption keys K2, K3 ..., Kn-1, Kn are sequentially calculated according to equation (4) . As a result of calculations that use the one-way function F, encryption keys are hierarchically arranged from level 1 to n:
Ki = F (Ki-1), (4) where i = 1,2,3, ..., n
The value of n is equal to the number of hierarchy levels (number of generations).
And indeed, although the new encryption keys can be easily calculated using the one-way F function in the way described, it is practically impossible to perform reverse calculations, i.e. the original encryption key cannot practically be calculated from the encryption keys using the one-way F function.
We will now describe how to encrypt information, such as software or data, and provide encrypted information to the user. When information, such as software or data, is encrypted and delivered to the user as shown in Fig. 2, it is first encrypted using a level 1 encryption key Kn, which encryption key Kn is provided to the user either together with the encrypted information,
182 259 or separately. The user can decode the encrypted information using the supplied encryption key Kn.
After disclosure of the Kn encryption key provided, information, such as software or data, is encrypted using a Kn-1 encryption key higher in the hierarchy (level 2), which Kn-1 encryption key is provided to the user. Similarly, after each disclosure of the encryption key, the information is encrypted using the encryption key higher in the hierarchy and the encryption key is provided to the user.
The lowest encryption key Kn (level 1) is calculated on the basis of a higher-level Kn-1 key, using the function F. In particular, the encryption key Kn is easily calculated using the function F, and the information encrypted using the encryption key Kn is decoded using the encryption key Kn, calculated on the basis of the key Kn-1. Accordingly, each subsequent encryption key can be calculated using the F function in any generation, since a higher hierarchy encryption key is used for the calculation. Thanks to this, by storing the last, undisclosed encryption key, the user can decode information encrypted not only with the last key, but also information encoded with the previous key. Furthermore, all encryption keys are sequentially generated from the KO master key using the F function. Thus, if the user stores the KO master key instead of the last, unrevealed encryption key, he can decode the encrypted information with all encryption keys. This makes using encryption keys easy.
A flowchart illustrating how information (plain text) such as moving images, sounds, data or software is encrypted and recorded on a recording medium, such as a CPW digital video disc (DVD), for example using the keys shown in Fig. 2 is shown in fig. 3.
After the operation has started, in the SI step, the key of the right generation (hierarchy level) is selected from the hierarchically arranged keys shown in Fig. 2, and the selected key becomes the working key. Then, the second step S2 is performed, in which the specified string of alphanumeric characters becomes a secret number, encrypted with the working key obtained in step SI, and the secret number encrypted in the above way is recorded on a specific part of the CPW board 1, as exemplified in Fig. 4 .
Then, step S3 is performed, in which the data, e.g. plain text, is encrypted with a working key and the encrypted data (secret text) is saved on a specific section of the CPW 1 board, as exemplified in Fig. 4.
An embodiment of the encryption device using the encryption method presented is shown in Fig. 5.
As discussed in Figure 5, unencrypted data and a secret number are provided to the associated input terminals 60 and 70 and beyond, to the corresponding encryption circuits 51 and 52. The secret number is a chain of alphanumeric characters, as already mentioned. The working key generating circuit 53 selects the encryption key of the corresponding generation (hierarchy) from the hierarchically arranged keys shown in Fig. 2, and passes the selected key to encryption circuits 51 and 52 as a working key. The encryption circuit 52 encrypts the supplied secret number using a working key obtained from the working key generating circuit 53. Then, the encrypted secret number is delivered to the recording device 54. The encryption circuit 51 encrypts the provided, explicit data using the working key and provides the encrypted information to the recording device 54. The recording device 54 records the encrypted information and the encrypted secret number on specific portions of the CPW 1, as exemplified in Fig. 4.
If the recording device 54 is used to prepare the mother disc, the resulting stamp can be used to make a large number of discs.
An example of a block diagram of an integrated circuit designed to decode information recorded on a CPW 1 disc and played back on a digital video disc player is shown in Fig. 6. Secret number, encrypted secret number and encrypted information are
182 259 brought to integrated circuit 11. The encrypted secret number is from the CPW 1 disc, and the unencrypted secret number is provided from the CPW disc player's own memory (not shown). The secret number is a specific string of alphanumeric characters, the same as that used on the encryption side.
Memory 12 includes the encrypted KO key shown in Fig. 2, preferably a master key. Register 13 contains an encryption key of a particular generation obtained by using the already mentioned function F relative to the master key, for example a working key as will be described. The decoding circuit 14 generates a working key based on the secret number entered, the encrypted secret number and the master key read from memory 12 and the key thus prepared provides to register 13 as will be described. The decoding system 14 decodes the entered, encrypted information (encrypted text) using a working key and prepares the explicit information (plain text).
A flowchart illustrating how the chip 11 decodes encrypted data from the CPW board 1 is shown in Figure 7.
After starting the operation, in step S11, the encrypted secret number is read from a specific section of the CPW 1 board. Then, the second step S12 is performed, in which the working key is prepared, based on the encrypted secret number read in step S11 and the secret number provided from its own memory a CPW player (not shown) as will be described, with reference to Fig. 8.
The details of the procedure when performing step S12 of Figure 7 are represented in the flow chart shown in Figure 8.
After the operation has started, in step S21, the control key is read from the memory 12 of integrated circuit 11 and established as the current key k. Then the current key k is transferred to the decoder circuit 14. The current key k is the key currently used for decoding.
In the next decision-making step S22, as shown in Fig. 8, the secret number and the encrypted secret number are transferred to the decoding system 14, in which the encrypted secret number is decoded using the current key k. The choice of the further path depends on the result of comparing the unencrypted secret number with secret number subjected to encryption and decoded using the current key k. If both forms of the number do not match, which corresponds to the branch NIE in the decision fork, then it is assumed that the current key is not the encryption key used on the encryption side. In this case, step S23 is performed, in which the next generation encryption key is calculated, based on the current key k, using the one-way function F, and sets as the current current key k, as expressed by the equation k = F (K) (5)
Then step S22 is performed again and the same procedure is repeated again. However, if the comparison of the unencrypted secret number with the secret number subjected to the encryption operation and decoded using the current key k results in a match, which corresponds to the YES branch in the decision fork, it is assumed that the current key is the encryption key used to encrypt the secret number. In this case, step S24 is performed, in which the decoding circuit 14 assumes that the current key k is a working key and passes it to the register 13, where it is stored. Then the operations in the network shown in Fig. 8 end and the procedure returns to step S13 in the activities network shown in Fig. 7. Then the decoding system 14 reads from the register 13 the working key obtained as a result of the actions of step S12 (steps S21 to S24 shown in Fig. 8). It then decodes, using the working key, the encrypted information entered (encrypted text) and passes the decoded information as explicit data (plain text).
As already described, if the user stores the KO master key, he can decode the encrypted information using an encryption key of any hierarchy, since the integrated circuit 11 obtains a working key, corresponding to the encrypted information, from the KO master key.
182 259
In the case of using a computer or software to perform the above-described activities, the procedure during the execution of step S12 in Fig. 7 is replaced by the steps shown in the flowchart shown in Fig. 9. The flowchart shown in Fig. 9 shows how the functions of the system of Fig. 6 can be filled by a computer decoding encrypted information in a software way. In this case, the computer replaces the decoder plate corresponding to the system of Fig. 6, as well as the software contained in the memory of such a board. In this case, the control key that was previously stored is not used now, although it can be used. Instead, the latest distributed version of the encryption key is used.
As will be described in the explanation of Fig. 10, the user enters, from the keyboard, an encryption key Ki (where i = n, n-1, ... 1), with a certain hierarchy level, distributed as a record on the CPW disc. This encryption key is stored in the computer's internal memory. Alternatively, the computer may receive the latest version of the key distributed over the telephone or computer network and store it in a specific memory, for example random access memory (RAM).
After the operation has started, in the first step S31, the entered Ki key is read from the memory and established as the current key k. The current key k is the key currently used for decoding, similar to the previously described.
In the next decision step S32, the secret number is retrieved from memory, and the encrypted secret number is read from the CPW disc. The encrypted secret number is decoded using the current k key. The choice of further route depends on the result of comparing the unencrypted secret number with the secret number subjected to the encryption operation and decoded using the current key k. If both forms of the number do not match, which corresponds to the branch NIE in the decision fork, then it is assumed that the current key is not the encryption key used on the encryption side. In this case, step S33 is performed, in which the next generation encryption key is calculated based on the current key k, using the two-way function F, and sets as the current current key k. Then, step S32 is again performed and the same procedure is repeated again.
However, if the comparison of the unencrypted secret number with the secret number subjected to the encryption operation and decoded using the current key k results in matching, which corresponds to the TAK branch in the decision fork of S32, then it is assumed that the current key k is the encryption key used to encrypt the secret number. In this case, step S34 is performed, in which the current key k is assumed to be a working key and stores it in a specific memory, e.g. in a register. Then the operations in the network shown in Fig. 9 end and the procedure returns to the activities network shown in Fig. 7.
Then, step S13 is performed in the flowchart shown in Fig. 7, where the encrypted information is decoded using a working key obtained as a result of the actions of step S12 (steps S31 to S34 shown in Fig. 9) and provided as explicit data (plain text ).
As already described, in the case of decoding encrypted information by a computer program based on a distributed encryption key of any hierarchy level, it is possible to decode encrypted information using at least the Ki encryption key or Ki-1 to K1 encryption keys with a hierarchy level lower than level of the Ki encryption key.
As already mentioned, in the decoding device it is enough to remember the last encryption key, because the information encrypted using previous versions of the key can be decoded with the last encryption key (master key or key of any hierarchy level). Thanks to this, unlike the known solutions, there is no need to store subsequent versions of the encryption keys each time the encryption key is changed after the previous version is revealed. This facilitates the use of encryption keys.
Disclosure of the encryption key used in the solution shown in Fig. 6 can be difficult, because the encryption key (KO main key) is placed in memory 12 inside integrated circuit 11, and the encryption key of the specified hierarchy is calculated
182 259 through integrated circuit 11, which protects the key against leaks and disclosure. In addition, in the discussed solution, the processes of decoding information and calculating the encryption keys occur in the same decoding system 14, which allows it to be protected.
An exemplary method of distributing encryption keys is shown in Figs. 10 to 12.
The method of writing the encryption keys on the CPW envelope or on the disc itself is shown in Fig. 10.
An alphanumeric character, bar code, hologram or similar element corresponding to an encryption key of a certain hierarchy is printed on the envelope of the CPW 21 plate with the title A or on the very surface of the CPW 21 plate, as illustrated in Fig. 10. Similarly, an alphanumeric character, the bar code , a hologram or similar element corresponding to the encryption key of the specified hierarchy B is printed on the envelope of the CPW 22 disc with the title B written or on the very surface of the CPW 22 disc. In this way, the A key can be distributed to users together with CPW 21 boards, and the B encryption key can be distributed to users together with CPW 22 boards. Alternatively, the data specifying the encryption key A may be recorded on a medium such as a chip with integrated circuit and distributed to users together with CPW 21 boards, or the data specifying the encryption key B may be recorded on a medium such as a chip with integrated circuit and distributed to users together with boards CPW 22.
The user playing the CPW 21 disc enters the encryption key A printed on the CPW 21 disc into the computer 23 using an external device such as a keyboard. As described with reference to the flowchart shown in Fig. 9, the computer 23 performs the same functions as the integrated circuit 11 shown in Fig. 6, i.e. it decodes the encrypted information according to the specific application program.
Thus, when the CPW 21 disc is in the digital video disc player (not shown), the computer 23 reads the encrypted information from the CPW 21 disc via the CPW disc player and decodes the encrypted information read from the CPW 21 disc using the previously entered encryption key A. Of course, encrypted information recorded on a CPW 22 disc can be decoded just like on a CPW 21 disc.
Accordingly, this form is advantageous for distributing different encryption keys for each title of a digital video disc. For example, encryption keys calculated from different primary keys using a one-way function can be assigned to each title of a digital video disc.
Even if the encryption key A associated with the title A is revealed, then it is updated and replaced with the encryption key A2, i.e. the old encryption key A can be easily calculated, in a certain way, from the encryption key A2, analogously to the method described in the explanation Fig. 9. This allows the user to decode the title A, encrypted using the old encryption key, using only the latest key version (in this case the A2 encryption key).
The method of entering the encryption key code into the software to decode the key and pass it on to the user is shown in Fig. 11.
The code specifying the encryption key is entered into the decoding software used by the decoder board 33 to decode the encrypted information, as illustrated in Fig. 11. Then the decoder board 33 is placed in the computer 23, so that the computer 23 can decode, through the decoder board 33, encrypted information recorded on CPW 31 and 32 discs, reproducing moving and still images and sound corresponding to the decoded information.
This example is beneficial for distributing the same key to users.
In this case, the computer 23 is connected to the telephone or computer network by means of which the current versions of the encryption key are provided. Computer 23
182 259 remembers the last encryption key version received, using the decoding software and the 33 decoder board.
In this way, the computer 23 can decode encrypted information recorded on CPW 31i 32 discs, using the encryption key in a manner analogous to that described in the explanation of Fig. 7 and Fig. 9.
Information encrypted using an encryption key can be delivered to computer 23 via a telephone network or a computer. In this case, the computer 23 decodes the information provided, using an encryption key previously distributed over the telephone or computer network.
As described in the explanation of Fig. 2, the encryption keys of all hierarchy levels can be formed from the first KO encryption key in the hierarchy, using the so-called one-way function F, and this first KO encryption key is used as the master key. So if the encryption key serving as the master key is placed in a device such as an integrated circuit, then the encryption key of all hierarchy levels can be created from the first KIO encryption key in the hierarchy, and the information, encrypted using any of these keys K1 to Kn, can be decoded. Because users find it very difficult to reveal data in a device such as an integrated circuit, unauthorized use of the encryption key can be eliminated.
The method of entering the encryption key into the integrated circuit and dissemination is shown in Fig. 12. The manufacturer obliged to keep secret produces the integrated circuit 41 in which the encryption key is stored. The structure of the integrated circuit 41 is preferably the same as that of the integrated circuit 11 of Fig. 6. In this case, the integrated circuit 41 is supplied to the manufacturer A. Then, after mounting the CPW 43 in the player, the integrated circuit 41 goes to the user. The secret number, encrypted using the encryption key of a certain hierarchy stored in integrated circuit 41 and the specified information, encrypted using the same encryption key are stored on the CPW 42 board.
When playing a CPW 42 disc by a user using a CPW 43 disc player, the control encryption key is read from the integrated circuit 41, and the working key is obtained in the same way as described in the explanation of Fig. 7 and Fig. 8, so that it can decode encrypted information recorded on a CPW 42 disc, reproducing moving and still images and sound corresponding to the decoded information.
If the main encryption key is saved in the integrated circuit, as already described, the CPW 43 disc player is able to decode and play back the encrypted information recorded on the CPW 42 disc regardless of the level of the key hierarchy used to encrypt the information recorded on the CPW 42 disc.
In integrated circuit 41, instead of the primary encryption key, a key with a certain hierarchy level can be stored, one of the one calculated from the primary encryption key using a one-way function. In this case, the CPW 43 disc player decodes and plays back the encrypted information recorded on the CPW 42 disc if the same encryption key or a lower hierarchy key was used to encrypt the information recorded on the CPW 42 disc.
The way in which a particular cipher key is remembered in a specific chip mounted on a CPW 43 disc player is advantageous when distributing the same encryption key, regardless of the CPW disc title.
As already described, due to the fact that the encryption keys are arranged hierarchically using a one-way function, the information is decoded using the encryption key of any hierarchy level, and this key is provided to the user who can decode the encryption information using the previous encryption key, retaining only the last key. This makes using encryption keys easy.
The embodiment illustrated in Fig. 12 can be used more efficiently if the encryption keys cannot be easily exchanged over the network. In particular, when information such as software or moving images is encrypted using an encryption key of any hierarchy level and stored on a disc
182 259
CPW 42, and the main key is contained inside the integrated circuit 41, so that an encryption key of any hierarchy level can be created from this master key using a one-way function F. This allows you to decode information encrypted with the encryption key of any hierarchy level recorded on a disc CPW 42. So even when the encryption key has been updated due to the disclosure of the previous encryption key, and the information recorded on CPW 42 was encrypted using the encryption key of the new hierarchy level, the user can normally decode and restore the saved information in the usual way.
The scope of information use is appropriately limited, because digital video disc players that do not contain an integrated circuit 41 with an encryption key are not able to correctly play CPW 42 discs with information encrypted using the encryption key. In addition, the scope of information use is also appropriately limited in the case of computers, because computers that do not contain a decoder board with a memorized encryption key are not able to correctly restore the medium with the information encrypted using the encryption key.
The cipher keys are distributed in the form of alphanumeric characters, bar codes or halograms printed on a recording medium, such as a digital video disc, or on a digital video disc envelope, data corresponding to the encryption key stored in the card with the integrated circuit, data corresponding to the encryption key stored in the layout integrated, difficult to use, data corresponding to the encryption key entered into the software, or data corresponding to the encryption key transmitted over the telephone or computer network in a particularly simplified manner.
Although in the above description the recording medium is a CPW digital video disc, the use of the invention is not limited to this medium only. Other recording media such as CD-ROM memory, MD mini disk, optical disk, magneto-optical disk, and diskette can also be used.
The invention can be used when providing information over a computer network such as the Internet.
Although the digital video disc player itself stores a secret number in a specific memory, as previously mentioned, the present invention is not limited in this respect and the secret number can, for example, be recorded on a specific part of the digital video disc, read later and fed to the decoding circuit 14 ( Fig. 6). In this case, as shown in Fig. 5, a secret number is given to the recording device 54 and recorded to disc 1.
Although the computer itself decodes encrypted information, the following variant is also possible. This solution does not use software, and the integrated circuit can be turned on to the computer and decode encrypted information. The scope of information use is appropriately limited, because computers that do not contain an integrated circuit 41 with an encryption key are not able to correctly restore the encrypted information.
In the encryption method and decoding method presented, the decoding side, while retaining the last encryption key, can decode the information encrypted using the previous encryption key, due to the fact that the encryption keys are hierarchically arranged using a one-way function. That is why it is easy to use generations (hierarchy) of keys during upgrades.
In addition, using the encryption device and the decoding device provided, the decoding party, having a primary encryption key, can decode the encrypted information using the encryption key calculated from the primary key, due to the fact that the encryption keys are calculated using a one-way function based on the stored primary key in the first memory and the decoding device decodes information based on the encryption key contained in the second memory. Therefore, it is easy to use the generation (hierarchy) of keys during the upgrade. What's more, the level of encryption key security can be significantly increased due to the placement of individual components inside the integrated circuit, which reduces possible leaks.
182 259
FIG. 3 (start)
SELECTING THE KEY FROM THE RIGHT HIERARCHIA DEGREE
AND ENCRYPTING THE SECRET NUMBER BY MEANS WORKING KEY AND SECRET L SECRET AT CPW '
CIPHER. DISCLOSED TEXT USING A WORKING KEY / SAVING CODE DATA AT CPW
S2 (end)
FIG. 4
<img file="PL182259B1_D0001.tif" />
182 259
FIG. 5
<img file="PL182259B1_D0002.tif" />
182 259
F / G. 6
ENCRYPTED SECRET NUMBER
SECRET NUMBER
encrypted
INFORMATION
FIG. 7
<img file="PL182259B1_D0003.tif" />
<img file="PL182259B1_D0004.tif" />
182 259
FIG. 8
<img file="PL182259B1_D0005.tif" />
YES
Working key - k
S24 v
<img file="PL182259B1_D0006.tif" />
182 259
FIG. 9
<img file="PL182259B1_D0007.tif" />
RETURN
182 259
FIG. 10
<img file="PL182259B1_D0008.tif" />
<img file="PL182259B1_D0009.tif" />
<img file="PL182259B1_D0010.tif" />
USER'S PAGE
182 259
<img file="PL182259B1_D0011.tif" />
TITLE Β
USER'S PAGE
182 259
FIG. 12
<img file="PL182259B1_D0012.tif" />
USER'S PAGE
TITLE
182 259
FIG. 1
<img file="PL182259B1_D0013.tif" />
CODE BREAKER
FIG. 2
<img file="PL182259B1_D0014.tif" />
LEAD n-1
HIERARCHY LEVEL
F: One-way function
UP Department of Publications. Circulation of 60 copies
Price PLN 4.00
Contents23
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
9 members in 6 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 26725095 | Japan | A | |
| 267250 | – | – | – |
| JP19950267250 | – | – | – |
Members9
| Document | Office | Kind | |
|---|---|---|---|
| EP0768774A2 | European Patent Office (EPO) | A2 | |
| PL316552A1 | Poland | A1 | |
| KR970024712A | Republic of Korea | A | |
| CN1159112A | China | A | |
| JPH103256A | Japan | A | |
| US5796839A | United States of America | A | |
| EP0768774A3 | European Patent Office (EPO) | A3 | |
| PL182122B1 | Poland | B1 | |
| PL182259B1This record | Poland | B1 |
Numbers
- Publication, DOCDB
- 182259
- Publication, EPODOC
- PL182259B
- Application
- 96345832
- Application, DOCDB
- 34583296
- Application, EPODOC
- PL19960345832
Titles
- English
- INFORMATION ENCIPHERING METHOD
Classification
- CPC, 3
- G11B20/0021
- G11B20/00086
- H04L9/088