US20030194092A1

Digital rights management (DRM) encryption and data-protection for content on a relatively simple device

Claim Score by NHIP

Read claim 7, the broadest

Abstract

A device has a symmetric device key (DK) and a copy of (DK) encrypted according to a public key (PU) of an entity (PU(DK)). The device receives an object from a host computer, at least a portion of which is encrypted according to (DK). The device sends (PU(DK)) to the host computer, and the host computer sends (PU(DK)) to the entity. The entity applies a corresponding private key (PR) to (PU(DK)) to obtain (DK) and sends (DK) to the host computer. The host computer may then encrypt the object according to (DK) and download same to the device, and the device may decrypt the encrypted object based on (DK).

US20030194092A1, drawing sheet 1
Sheet 1 of 20

Term

Term ended

Projected expiry passed 14 October 2024, 1.9 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

28 claims: 5 independent, 23 dependent

  1. 1
    A method performed in combination with a host computer and a device that couples to and downloads an object from the host computer, the device having a symmetric device key (DK) and a copy of (DK) encrypted according to a public key (PU) of an entity (PU(DK)), whereby the device receives an object from the host computer at least a portion of which is encrypted according to (DK), the method for communicating (DK) from the device to the host computer and comprising:sending (PU(DK)) from the device to the host computer;sending (PU(DK)) from the host computer to the entity, the entity having a private key (PR) corresponding to (PU), applying (PR) to (PU(DK)) to obtain (DK), and sending (DK) back to the host computer;and receiving (DK) from the entity at the host computer, whereby the host computer may then encrypt the object according to (DK) and download the encrypted object to the device, and the device may then decrypt the encrypted object based on (DK).
  2. 7
    Broadest claimClaim Score 64, broad(NHIP)A method of manufacturing a device that couples to and downloads objects from a host computer, comprising:receiving a public key of an entity (PU);selecting a symmetric device key (DK) for the device;encrypting (DK) according to (PU) to produce (PU(DK));and permanently storing (PU(DK)) and (DK) on the device, whereby the device transmits (PU(DK)) to the host computer, the host computer obtains (DK) from the entity based on (PU(DK)), encrypts at least a portion of an object according to (DK), and transmits the encrypted object to the device, and the device retrieves (DK) therefrom and decrypts the encrypted object therewith.
  3. 10
    A method performed in combination with a host computer and a device that couples to and downloads an object from the host computer, the device having a symmetric device key (DK), a copy of (DK) encrypted according to a public key (PU) of an entity (PU(DK)), and a symmetric binding key (BK) encrypted according to (DK) ((DK(BK))) initially set to an initializing value, the initializing (DK(BK)) signaling to the host computer that (BK) needs to be initialized to a randomized value and thus be individualized to such device, whereby the device is to receive an object from the host computer at least a portion of which is encrypted according to (BK), the method for initializing (BK) and comprising:sending both (PU(DK)) and (DK(BK)) from the device to the host computer;realizing by the host computer that the sent (DK(BK)) is the initializing (DK(BK));sending (PU(DK)) from the host computer to the entity, the entity having a private key (PR) corresponding to (PU), applying (PR) to (PU(DK)) to obtain (DK), selecting an initialized (BK) for the device, employing the obtained (DK) to encrypt the initialized (BK) to produce an initialized (DK(BK)), and sending the initialized (DK(BK)) back to the host computer;receiving the initialized (DK(BK)) from the entity at the host computer;forwarding the initialized (DK(BK)) to the device;and storing the initialized (DK(BK)) at the device in place of the initializing (DK(BK)), whereby the device may then decrypt an object encrypted by the host computer based on (BK).
  4. 19
    A method of manufacturing a device that couples to and downloads objects from a host computer, comprising:receiving a public key of an entity (PU);selecting a symmetric device key (DK) for the device;encrypting (DK) according to (PU) to produce (PU(DK));permanently storing (PU(DK)) and (DK) on the device;and storing in a re-writable memory an initializing value for a symmetric binding key (BK) encrypted according to (DK) ((DK(BK))) that signals to the host computer that (BK) needs to be initialized to a randomized value and thus be individualized to such device, whereby the device transmits (PU(DK)) and the initializing (DK(BK)) to the host computer, the host computer realizes that the transmitted (DK(BK)) is the initializing (DK(BK)), obtains an initialized (DK(BK)) from the entity based on (PU(DK)), and transmits the initialized (DK(BK)) to the device, and the device stores the initialized (DK(BK)) in the re-writable memory in place of the initializing (DK(BK)), and whereby thereafter the device transmits (PU(DK)) and (DK(BK)) to the host computer, the host computer obtains (BK) from the entity based on (PU(DK)) and (DK(BK)), encrypts at least a portion of an object according to (BK), and transmits the encrypted object to the device, and the device retrieves (BK) therefrom and decrypts the encrypted object therewith.
  5. 22
    A method performed in combination with a host computer and a device that couples to and downloads an object from the host computer, the device having a symmetric device key (DK), a copy of (DK) encrypted according to a public key (PU) of an entity (PU(DK)), and a symmetric binding key (BK) encrypted according to (DK) ((DK(BK))), whereby the device is to receive an object from the host computer at least a portion of which is encrypted according to (BK), the method for communicating (BK) from the device to the host computer and comprising:sending both (PU(DK)) and (DK(BK)) from the device to the host computer;sending (PU(DK)) and (DK(BK)) from the host computer to the entity, the entity having a private key (PR) corresponding to (PU), applying (PR) to (PU(DK)) to obtain (DK), applying (DK) to (DK(BK)) to obtain (BK), and sending (BK) back to the host computer;and receiving (BK) from the entity at the host computer, whereby the host computer may then encrypt the object according to (BK) and download the encrypted object to the device, and the device may then decrypt the encrypted object based on (BK).