Network Security System
Claim Score by NHIP
Abstract
A system for restricting access to encrypted content stored in a consuming device (12) which is part of a network (10) including other devices (14), the system including a content storage medium to store the encrypted content, a secret-share distribution module to distribute secret-shares to the other devices (14), a secret-share receive module to receive the secret-shares from the other devices (14), a secret reconstruction module to form a content decryption input from the secret-shares received by the secret-share receive module, a content decryption module to receive the encrypted content from the content storage medium and the content decryption input from the secret reconstruction module and decrypt the encrypted content using the content decryption input thereby rendering decrypted content, and a content consumer to use the decrypted content, wherein the secret shares distributed to the other devices (14) are in an encrypted format for decryption by the consuming device (12) or the other devices (14).

Term
Projected expiry 14 August 2028.
- Priority
- Filed
- Published
- Today
- Projected expiry
24 claims: 6 independent, 18 dependent
- 1A system for restricting access to encrypted content stored in a consuming device which is part of a network including other devices, the system comprising a plurality of operationally connected elements including:a content storage medium to store the encrypted content therein;a decryption input disseminator including: a secret share distribution module to distribute a plurality of secret shares to the other devices;a decryption input accumulator including: a secret share receive module to receive at least some of the secret shares from the other devices;and a secret reconstruction module to form a content decryption input from the at least some secret shares received by the secret share receive module;a content decryption module to: receive the encrypted content from the content storage medium and the content decryption input from the secret reconstruction module;and decrypt the encrypted content using the content decryption input thereby rendering decrypted content;and a content consumer to use the decrypted content decrypted by the content decryption module, wherein the secret shares distributed to the other devices are in an encrypted format for at least one of decryption by the consuming device and the other devices.
- 16A system for restricting access to encrypted content stored in a consuming device which is part of a network including other devices, the system comprising a plurality of operationally connected elements including:a secret share splitting module to split a content decryption input into a plurality of secret shares;a secret share encryption module to encrypt the secret shares thereby rendering encrypted secret shares;and a broadcast module to broadcast: the encrypted content to the consuming device;and the encrypted secret shares to at least one of the consuming device and the other devices.
- 21A method for restricting access to encrypted content stored in a consuming device which is part of a network including other devices, the method comprising:storing the encrypted content therein;distributing a plurality of secret shares to the other devices;receiving at least some of the secret shares from the other devices;forming a content decryption input from the at least some secret shares;decrypting the encrypted content using the content decryption input thereby rendering decrypted content;and using the decrypted content decrypted, wherein the secret shares distributed to the other devices are in an encrypted format for at least one of decryption by the consuming device and the other devices.
- 22Broadest claimClaim Score 80, broad(NHIP)A method for restricting access to encrypted content stored in a consuming device which is part of a network including other devices, the method comprising:splitting a content decryption input into a plurality of secret shares;encrypting the secret shares thereby rendering encrypted secret shares;and broadcasting the encrypted secret shares to at least one of the consuming device and the other devices.
- 23A system for restricting access to encrypted content stored in a consuming device which is part of a network including other devices, the system comprising a plurality of operationally connected elements including:means for storing the encrypted content therein;means for distributing a plurality of secret shares to the other devices;means for receiving at least some of the secret shares from the other devices;means for forming a content decryption input from the at least some secret shares received by the secret share receive module;means for receiving the encrypted content from the content storage medium and the content decryption input from the secret reconstruction module;means for decrypting the encrypted content using the content decryption input thereby rendering decrypted content;and means for using the decrypted content decrypted by the content decryption module, wherein the secret shares distributed to the other devices are in an encrypted format for at least one of decryption by the consuming device and the other devices.
- 24A system for restricting access to encrypted content stored in a consuming device which is part of a network including other devices, the system comprising a plurality of operationally connected elements including:means for splitting a content decryption input into a plurality of secret shares;means for encrypting the secret shares thereby rendering encrypted secret shares;and means for broadcasting: the encrypted content to the consuming device;and the encrypted secret shares to at least one of the consuming device and the other devices.
Independent claims6
135 paragraphs in 5 sections, as filed
FIELD OF THE INVENTION
p-0002The present invention relates to security of content stored in a consuming device which is part of a network including other devices.
BACKGROUND OF THE INVENTION
p-0003By way of introduction, personal video recorders (PVRs) typically record broadcast media content thereon. The media content is preferably stored in an encrypted format. Entitlement control messages (ECMs) (or similar decryption inputs), which are generally used to decrypt the content are also typically stored in the PVR. A security device, for example, but not limited to, a smart card is typically used to convert the ECMs into keys for decrypting the media content stored in the PVR. Therefore, if the PVR is stolen along with the accompanying smart card there is nothing stopping the thief from accessing the content stored in the PVR. Even if the PVR is stolen without the smart card, the thief may be able to hack the device thereby gaining access to the content, leading to unauthorized distribution and/or viewing.
p-0004Additionally, there is a problem of computer, storage device and/or file theft in a home and/or corporate environment.
p-0005The following references are believed to represent the state of the art:
p-0006U.S. Pat. No. 5,764,767 to Beimel, et al.;
p-0007U.S. Pat. No. 6,367,019 to Ansell, et al.;
p-0008U.S. Pat. No. 6,748,084 to Gau, et al.;
p-0009US Published Patent Application No. 2002/0157002 of Messerges, et al.;
p-0010US Published Patent Application No. 2003/0026432 of Woodward;
p-0011PCT Published Patent Application No. WO04/051920 of Matsushita Electric Industrial Co., Ltd.;
p-0012PCT Published Patent Application No. WO03/067809 of Surety, Inc.; and
p-0013PCT Published Patent Application No. WO00/058963 of Liquid Audio, Inc.
p-0014The disclosures of all references mentioned above and throughout the present specification, as well as the disclosures of all references mentioned in those references, are hereby incorporated herein by reference.
SUMMARY OF THE INVENTION
p-0015The present invention seeks to provide an improved system and method for restricting access to encrypted content stored in a consuming device which is part of a network including other devices.
p-0016The system of the present invention, in preferred embodiments thereof, makes content readable only when the content storage is on an authorized network. Content decryption input for decrypting the encrypted content is stored among the other devices (for example, but not limited to, security servers or other static devices) in the network in the form of secret shares. The term “content decryption input” as used in the specification and claims is defined as: (i) an input used directly to decrypt content, the input being for example, but not limited to, a decryption key; or (ii) an input used indirectly to decrypt content, the input being for example, but not limited to an entitlement control message, whereby the input is used to form a key for directly decrypting content. The secret shares are sent to the other devices while encrypted. In order to decrypt the encrypted content, the secret shares are recovered from the other devices and the content decryption input is formed from the secret shares. Therefore, if the device is removed from the authorized network prior to recovery of the secret shares then the content decryption input cannot be formed from the secret shares.
p-0017By way of example, in a Pay-TV environment, an attacker is forced to break multiple devices in order to get the ECMs. The ECMs are not placed on the same physical device as the media content, but instead preferably distributed among a number of devices within the network.
p-0018It is possible to create enough secret shares from each content decryption input for more than one authorized network, so that a device, for example, but not limited to, a portable computer can be moved from one authorized network to another (for example, from a corporate network to a home network) and access secured files in both authorized networks.
p-0019In accordance with a preferred embodiment of the present invention the consuming device preferably encrypts the secret shares prior to sending the secret shares to the other devices such that only the consuming device can decrypt the secret shares. In the preferred embodiment, the other devices are thereby prevented from reconstructing the content decryption input for use by the other devices.
p-0020In accordance with a first alternative preferred embodiment of the present invention, the consuming device is treated as a “non-trusted party”. Devices are typically defined as “non-trusted” if they are not trusted to distribute the secret shares and/or delete the content decryption input after the secret shares have been formed. Therefore, in the “non-trusted party” mode, a content provider provides the content with already encrypted secret shares. In order for the consuming device to decrypt the secret shares, the secret shares need to be sent to the other devices for decryption first. When the consuming device wants to access the encrypted content, the other devices decrypt the encrypted secret shares. The other devices then send the decrypted secret shares to the consuming device. The consuming device then forms the content decryption input from the decrypted secret shares. In the first alternative preferred embodiment, the consuming device does not receive the content decryption input from the content provider and the consuming device is forced to distribute the secret shares to the other devices in the network.
p-0021In accordance with a second alternative preferred embodiment of the present invention, the secret shares are doubly encrypted by the content provider so that the secret shares first need to be decrypted by the other devices and then decrypted by the consuming device.
p-0022In the above embodiments, the formation of the content decryption input from the secret shares does not typically require all the distributed secret shares to be used, but only a fraction thereof. This is typically performed using a secret sharing threshold scheme, for example, but not limited to, the Shamir Secret Sharing Scheme, published in 1979.
p-0023The system and method of the present invention, in preferred embodiments thereof, is useful for a variety of content for example, but not limited to, media content, data and files.
p-0024There is thus provided in accordance with a preferred embodiment of the present invention a system for restricting access to encrypted content stored in a consuming device which is part of a network including other devices, the system including a plurality of operationally connected elements including a content storage medium to store the encrypted content therein, a decryption input disseminator including a secret share distribution module to distribute a plurality of secret shares to the other devices, a decryption input accumulator including a secret share receive module to receive at least some of the secret shares from the other devices, and a secret reconstruction module to form a content decryption input from the at least some secret shares received by the secret share receive module, a content decryption module to receive the encrypted content from the content storage medium and the content decryption input from the secret reconstruction module, and decrypt the encrypted content using the content decryption input thereby rendering decrypted content, and a content consumer to use the decrypted content decrypted by the content decryption module, wherein the secret shares distributed to the other devices are in an encrypted format for at least one of decryption by the consuming device and the other devices.
p-0025Further in accordance with a preferred embodiment of the present invention the elements also include a content and secret receive module to receive the encrypted content and the content decryption input for forwarding to the content storage medium and the decryption input disseminator, respectively, the decryption input disseminator also includes a secret share splitting module to split the content decryption input into the secret shares, and erase the content decryption input from the consuming device, and a secret share encryption module to encrypt the secret shares created by the secret share splitting module, and the decryption input accumulator also includes a secret share decryption module to decrypt the at least some secret shares received by the secret share receive module, and forward the decrypted secret shares to the secret reconstruction module.
p-0026Still further in accordance with a preferred embodiment of the present invention the secret shares are encrypted by the secret share encryption module only for decryption by the consuming device.
p-0027Additionally in accordance with a preferred embodiment of the present invention the secret share splitting module is operative to split the content decryption input into the secret shares in accordance with a threshold scheme such that the secret reconstruction module only needs a predetermined number of any of the secret shares in order to form the content decryption input, the predetermined number being greater than one but less thank the number of the other devices.
p-0028Moreover in accordance with a preferred embodiment of the present invention the threshold scheme is based on the Shamir secret-sharing method.
p-0029Further in accordance with a preferred embodiment of the present invention the elements also include a content and secret receive module to receive the encrypted content and the secret shares, the secret shares being received encrypted such that each of the secret shares is uniquely encrypted for decryption by a corresponding one of the other devices, and forward the encrypted content to the content storage medium and the encrypted secret shares to the secret share distribution module.
p-0030Still further in accordance with a preferred embodiment of the present invention the elements also include a content and secret receive module to receive the encrypted content and the secret shares, the secret shares being received doubly encrypted by an inner encryption and then an outer encryption such that the outer encryption needs to be decrypted before the inner encryption, the outer encryption being uniquely encrypted for decryption by a corresponding one of the other devices, the inner encryption being for decryption only by the consuming device, and forward the encrypted content to the content storage medium and the encrypted secret shares to the secret share distribution module, and the decryption input accumulator also includes a secret share decryption module to decrypt the at least some secret shares received by the secret share receive module, and forward the decrypted secret shares to the secret reconstruction module.
p-0031Additionally in accordance with a preferred embodiment of the present invention the secret shares are formed in accordance with a threshold scheme such that the secret reconstruction module only needs a predetermined number of any of the secret shares in order to form the content decryption input, the predetermined number being greater than one but less than the number of the other devices.
p-0032Moreover in accordance with a preferred embodiment of the present invention the threshold scheme is based on the Shamir secret-sharing method.
p-0033Further in accordance with a preferred embodiment of the present invention the content consumer is a media player, and the decrypted content includes a video frame.
p-0034Still further in accordance with a preferred embodiment of the present invention the content decryption input is an entitlement control message.
p-0035Additionally in accordance with a preferred embodiment of the present invention the content consumer is a computer processor, and the decrypted content includes at least part of a data file.
p-0036Moreover in accordance with a preferred embodiment of the present invention the content decryption input is a decryption key.
p-0037Further in accordance with a preferred embodiment of the present invention the secret share distribution module is operative to distribute each of the secret shares to the other devices with a message authentication code of a corresponding one of the secret shares, the secret share decryption module being operative to verify the message authentication code of each of the at least some secret shares received by the secret share receive module.
p-0038Still further in accordance with a preferred embodiment of the present invention the secret share distribution module is operative to distribute each of the secret shares to the other devices with a message authentication code of the content decryption input, the secret share reconstruction module being operative to verify the message authentication code of the content decryption input.
p-0039There is also provided in accordance with still another preferred embodiment of the present invention a system for restricting access to encrypted content stored in a consuming device which is part of a network including other devices, the system including a plurality of operationally connected elements including a secret share splitting module to split a content decryption input into a plurality of secret shares, a secret share encryption module to encrypt the secret shares thereby rendering encrypted secret shares, and a broadcast module to broadcast the encrypted content to the consuming device, and the encrypted secret shares to at least one of the consuming device and the other devices.
p-0040Additionally in accordance with a preferred embodiment of the present invention the secret share splitting module is operative to split the content decryption input into the secret shares in accordance with a threshold scheme such that only a predetermined number of any of the secret shares is needed in order to re-form the content decryption input, the predetermined number being greater than one but less than the number of the other devices.
p-0041Moreover in accordance with a preferred embodiment of the present invention the threshold scheme is based on the Shamir secret-sharing method.
p-0042Further in accordance with a preferred embodiment of the present invention the secret share encryption module is operative to encrypt the secret shares, such that each of the encrypted secret shares is uniquely encrypted for decryption by a corresponding one of the other devices.
p-0043Still further in accordance with a preferred embodiment of the present invention the secret share encryption module is operative to encrypt the secret shares, such that each of the encrypted secret shares is doubly encrypted by an inner encryption and then an outer encryption such that the outer encryption needs to be decrypted before the inner encryption, the outer encryption being uniquely encrypted for decryption by a corresponding one of the other devices, the inner encryption being for decryption only by the consuming device.
p-0044There is also provided in accordance with still another preferred embodiment of the present invention a method for restricting access to encrypted content stored in a consuming device which is part of a network including other devices, the method including storing the encrypted content therein, distributing a plurality of secret shares to the other devices, receiving at least some of the secret shares from the other devices, forming a content decryption input from the at least some secret shares, decrypting the encrypted content using the content decryption input thereby rendering decrypted content, and using the decrypted content decrypted, wherein the secret shares distributed to the other devices are in an encrypted format for at least one of decryption by the consuming device and the other devices.
p-0045There is also provided in accordance with still another preferred embodiment of the present invention a method for restricting access to encrypted content stored in a consuming device which is part of a network including other devices, the method including splitting a content decryption input into a plurality of secret shares, encrypting the secret shares thereby rendering encrypted secret shares, and broadcasting the encrypted secret shares to at least one of the consuming device and the other devices.
BRIEF DESCRIPTION OF THE DRAWINGS
p-0046The present invention will be understood and appreciated more fully from the following detailed description, taken in conjunction with the drawings in which:
p-0047<figref idrefs="DRAWINGS">FIG. 1</figref> is a simplified block diagram view of a network including a consuming device and other devices constructed and operative in accordance with a preferred embodiment of the present invention;
p-0048<figref idrefs="DRAWINGS">FIG. 2</figref> is a simplified block diagram view of the consuming device of <figref idrefs="DRAWINGS">FIG. 1</figref>;
p-0049<figref idrefs="DRAWINGS">FIG. 3</figref> is a simplified block diagram view of a network including a consuming device and other devices constructed and operative in accordance with a first alternative preferred embodiment of the present invention;
p-0050<figref idrefs="DRAWINGS">FIG. 4</figref> is a simplified block diagram of a content provider of <figref idrefs="DRAWINGS">FIG. 3</figref>;
p-0051<figref idrefs="DRAWINGS">FIG. 5</figref> is a simplified block diagram view of the consuming device of <figref idrefs="DRAWINGS">FIG. 3</figref>;
p-0052<figref idrefs="DRAWINGS">FIG. 6</figref> is a simplified block diagram view of a network including a consuming device and other devices constructed and operative in accordance with a second alternative preferred embodiment of the present invention;
p-0053<figref idrefs="DRAWINGS">FIG. 7</figref> is a simplified block diagram of a content provider of <figref idrefs="DRAWINGS">FIG. 6</figref>;
p-0054<figref idrefs="DRAWINGS">FIG. 8</figref> is a simplified block diagram view of the consuming device of <figref idrefs="DRAWINGS">FIG. 6</figref>;
p-0055<figref idrefs="DRAWINGS">FIG. 9</figref> is a graph showing a polynomial to illustrate the Shamir secret sharing scheme; and
p-0056<figref idrefs="DRAWINGS">FIG. 10</figref> is a simplified block diagram view illustrating content decryption input restoration for use by the devices of <figref idrefs="DRAWINGS">FIGS. 1</figref>, <b>3</b> and <b>6</b> according to the Shamir secret sharing scheme.
DETAILED DESCRIPTION OF A PREFERRED EMBODIMENT
p-0057Reference is now made to <figref idrefs="DRAWINGS">FIG. 1</figref>, which is a simplified block diagram view of a network <b>10</b> including a plurality of interconnected devices including a consuming device <b>12</b> (denoted Device D) and other devices <b>14</b> (denoted devices <b>1</b> to <b>5</b>) constructed and operative in accordance with a preferred embodiment of the present invention.
p-0058In a Pay-TV environment, for example, when the consuming device <b>12</b>, typically a PVR in the network <b>10</b>, purchases and records content <b>16</b> from a content provider <b>20</b>, the content provider <b>20</b> sends the content <b>16</b>, encrypted by a plurality of content decryption inputs CDIs <b>18</b>. The content provider <b>20</b> also sends the CDIs <b>18</b> along with the content <b>16</b>. The CDIs <b>18</b> are denoted by K<sub>j </sub>in <figref idrefs="DRAWINGS">FIG. 1</figref> (for example, K<sub>1</sub>, K<sub>2 </sub>. . . K<sub>t</sub>), where j is a value between 1 and t. Similarly, the content <b>16</b> typically includes portions of the content <b>16</b>, C<sub>j </sub>(denoted C<sub>1</sub>, C<sub>2 </sub>. . . C<sub>t </sub>in <figref idrefs="DRAWINGS">FIG. 1</figref>). Therefore, each content portion C<sub>j </sub>preferably has a corresponding content decryption input, K<sub>j</sub>. Each CDI <b>18</b> is preferably split into encrypted secret shares (ESSs) <b>24</b> using a secret sharing method (for example, but not limited to, the Shamir secret-sharing method) by the consuming device <b>12</b>. The ESSs <b>24</b> are then typically distributed by the consuming device <b>12</b> to the other devices <b>14</b> in the network <b>10</b>.
p-0059For playback, the consuming device <b>12</b> preferably establishes a viewing session with a number of the other devices <b>14</b> in the network <b>10</b>. The consuming device <b>12</b> receives the ESSs <b>24</b> and then the consuming device <b>12</b> decrypts the ESSs <b>24</b>. The consuming device <b>12</b> then computes the original CDIs <b>18</b> from the decrypted ESSs <b>24</b>. The CDIs <b>18</b> are then used to decrypt the content <b>16</b> for playing by consuming device <b>12</b>.
p-0060The above example described a preferred embodiment of the present invention with reference to pay-TV. However, it will be appreciated by those ordinarily skilled in the art that the preferred embodiment of the present invention can similarly be applied to other security scenarios, for example, but not limited to, file and disk security, wherein there is typically one portion of content C<sub>1 </sub>encrypted using one content decryption input, K<sub>1</sub>. Therefore, when encrypting sensitive files or file systems (for example, but not limited to, PGP disks), the content decryption input, K<sub>1</sub>, is preferably split into secret shares using a suitable secret sharing method, for example, but not limited to, the Shamir secret-sharing method. The secret shares are then encrypted forming the ESSs <b>24</b>. The consuming device <b>12</b> then distributes the ESSs <b>24</b> to the other devices <b>14</b> (for example, but not limited to, secure static devices) in the network <b>10</b>. The file can be viewed/file system can be mounted, only on the same network <b>10</b>, or a network explicitly provided with the ESSs <b>24</b>.
p-0061In all cases, including Pay-TV and file and disk security, the original CDI <b>18</b> is preferably erased after the CDI <b>18</b> is split into the secret shares, as well as after the CDI <b>18</b> has been restored and used. Stealing the CDI(s) <b>18</b> then typically requires an intrusive attack on the consuming device <b>12</b> when the consuming device <b>12</b> is live, online and on the network <b>10</b>, in other words, while the CDI <b>18</b> is in the memory of the consuming device <b>12</b> during the decryption process.
p-0062The other devices <b>14</b> may be any suitable device which has communication capabilities and a memory for storing the ESSs <b>24</b>.
p-0063It is possible to split and distribute the content <b>16</b> as well as the CDI(s) <b>18</b>, in which case the C<sub>j </sub>is omitted and K<sub>j </sub>denotes the content <b>16</b> and the CDIs <b>18</b>. However, splitting and distributing the content <b>16</b> as well as the CDIs <b>18</b> implies greater computation cost and network load.
p-0064The preferred embodiment described above is an example of a trusted device model whereby the consuming device <b>12</b> computes the secret shares for each of the CDI(s) <b>18</b> (K<sub>1</sub>, K<sub>2</sub>, . . . , K<sub>t</sub>) for distribution, after encryption, to the other devices <b>14</b>. However, in certain scenarios, it is desirable to adopt a non-trusted device model, which may be useful, for example, in Pay-TV and other broadcast scenarios. In the non-trusted device model, the content provider <b>20</b> computes the ESSs <b>24</b> for each CDI <b>18</b>. In the non-trusted device model the CDIs <b>18</b> are not broadcast to the consuming device <b>12</b>. The consuming device <b>12</b> receives the ESSs <b>24</b> from the content provider <b>20</b>. The ESSs <b>24</b> cannot be decrypted by the consuming device <b>12</b>. The ESSs <b>24</b> are distributed by the consuming device <b>12</b> to the other devices <b>14</b>. The other devices <b>14</b> are able to decrypt the ESSs <b>24</b> for use by the consuming device <b>12</b>. The non-trusted device model is described in more detail with reference to <figref idrefs="DRAWINGS">FIGS. 3-8</figref>.
p-0065The choice of trusted/non-trusted model depends on the level of trust of the consuming device <b>12</b>, considerations of computational load on the content provider <b>20</b>, and the knowledge of the network membership by the content provider <b>20</b>. The final factor can be established by explicit enrollment or periodic updates through an upstream channel (Internet Protocol (IP), cable report-back or phone-based callback).
p-0066The trusted model is now described in more detail.
p-0067Reference is now made to <figref idrefs="DRAWINGS">FIG. 2</figref>, which is a simplified block diagram view of the consuming device <b>12</b> of <figref idrefs="DRAWINGS">FIG. 1</figref>. Consuming device <b>12</b> preferably implements a system for restricting access to the encrypted content <b>16</b> stored in the consuming device <b>12</b>. The system preferably includes a plurality of operationally connected elements typically including a content and secret receive module <b>26</b>, a content storage medium <b>28</b>, a decryption input disseminator <b>30</b>, a decryption input accumulator <b>32</b>, a content decryption module <b>34</b> and a content consumer <b>36</b>.
p-0068The content and secret receive module <b>26</b> is preferably operative to receive the encrypted content <b>16</b> and CDIs <b>18</b> for forwarding to content storage medium <b>28</b> and the decryption input disseminator <b>30</b>, respectively.
p-0069The content storage medium <b>28</b> is preferably operative to store the encrypted content <b>16</b> therein.
p-0070The decryption input disseminator <b>30</b> typically includes a secret share splitting module <b>38</b>, a secret share encryption module <b>40</b> and a secret share distribution module <b>42</b>. The secret share splitting module <b>38</b> preferably receives the CDIs <b>18</b> from the content and secret receive module <b>26</b>. The secret share splitting module <b>38</b> is generally operative to split each CDI <b>18</b> into a plurality of secret shares <b>44</b>. Additionally, the secret share splitting module <b>38</b> is preferably operative to erase each CDI <b>18</b> from the consuming device <b>12</b> after the secret shares <b>44</b> are created.
p-0071The secret share encryption module <b>40</b> is preferably operative to encrypt the secret shares <b>44</b> created by the secret share splitting module <b>38</b> resulting in a plurality of encrypted secret shares <b>46</b>. The secret shares <b>44</b> are preferably encrypted by the secret share encryption module <b>40</b> only for decryption by the secret share decryption module <b>50</b> of the consuming device <b>12</b>. The term “only for decryption” as used in the specification and claims is defined as the encryption is performed for decryption by a particular decryption method and/or decryption key without having to resort to hacking methods in order to decrypt the encrypted secret shares <b>46</b>. The encrypted secret shares <b>46</b> are typically encrypted with the same key, Known only to the consuming device <b>12</b>. Therefore, the secret shares <b>44</b> cannot be used by any other device to restore the original CDI(s) <b>18</b> without employing hacking methods.
p-0072The secret share distribution module <b>42</b> is preferably operative to distribute the encrypted secret shares <b>46</b> to the other devices <b>14</b> (<figref idrefs="DRAWINGS">FIG. 1</figref>).
p-0073The encrypted secret shares <b>46</b> are typically held by the other devices <b>14</b> until the consuming device <b>12</b> needs the encrypted secret shares <b>46</b> for decrypting the content <b>16</b>.
p-0074The decryption input accumulator <b>32</b> preferably includes a secret share receive module <b>48</b>, a secret share decryption module <b>50</b> and a secret reconstruction module <b>52</b>.
p-0075The secret share receive module <b>48</b> is generally operative to receive at least some of the encrypted secret shares <b>46</b> from the other devices <b>14</b> for forwarding to the secret share decryption module <b>50</b>.
p-0076The secret share decryption module <b>50</b> is typically operative to decrypt the encrypted secret shares <b>46</b> received by the secret share receive module <b>48</b> thereby yielding the decrypted secret shares <b>44</b>. The secret share decryption module <b>50</b> preferably forwards the decrypted secret shares <b>44</b> to the secret reconstruction module <b>52</b>.
p-0077The secret reconstruction module <b>52</b> is preferably operative to form each CDI <b>18</b> from the secret shares <b>44</b>.
p-0078The content decryption module <b>34</b> is generally operative to receive the encrypted content <b>16</b> from the content storage medium <b>28</b> and to receive the CDI(s) <b>18</b> from the secret reconstruction module <b>52</b>. The content decryption module <b>34</b> is also generally operative to decrypt the encrypted content <b>16</b> using the CDI(s) <b>18</b> thereby rendering decrypted content <b>54</b>. After the content <b>16</b> is decrypted, the CDI(s) <b>18</b> are erased, preferably immediately. Additionally, the CDIs <b>18</b> are preferably never stored in non-volatile storage.
p-0079The content consumer <b>36</b> is preferably operative to use the decrypted content <b>54</b> decrypted by the content decryption module <b>34</b>. It will be appreciated by those ordinarily skilled in the art that the content consumer <b>36</b> may be any suitable device for playing/using content. For example, in a media environment, the decrypted content <b>54</b> typically includes video and/or audio frames, the content consumer <b>36</b> typically being a media player, for example, but not limited to, a Television set-top box, a mobile telephone or any other suitable media player, the CDIs <b>18</b> typically being entitlement control messages or other suitable key stream components.
p-0080By way of another example, in a data security environment, the decrypted content <b>54</b> typically includes at least part of a data file, the content consumer <b>36</b> typically being a computer processor and the CDI <b>18</b> being a decryption key.
p-0081The secret share splitting module <b>38</b> is preferably operative to split the CDI(s) <b>18</b> into the secret shares <b>44</b> in accordance with a threshold scheme such that the secret reconstruction module <b>52</b> only needs a predetermined number, r, of any of the secret shares <b>44</b> in order to form any one CDI <b>18</b>. The predetermined number, r, is typically greater than one but less than, or equal to, the number of the other devices <b>14</b>. The predetermined number is preferably less than the number of the other devices <b>14</b>.
p-0082The predetermined number, r, of secret share owners required to participate in recreating each CDI <b>18</b> from the ESSs <b>24</b>, is optionally defined by the content provider, or the device distributing the shares, and/or by network properties (for example, but not limited to, the number of secure trusted devices). The predetermined number, r, is preferably based on the desired content security level and/or on the number of devices forming the home network.
p-0083In accordance with a most preferred embodiment of the present invention, the threshold scheme is based on the Shamir secret-sharing method. It will be appreciated by those ordinarily skilled in the art that other suitable threshold schemes as well as other suitable non-threshold schemes may used.
p-0084The following security schemes are optionally implemented to enhance security.
p-0085First, secret share distribution module <b>42</b> is preferably operative to distribute each of the encrypted secret shares <b>46</b> to the other devices <b>14</b> with a message authentication code (MAC) <b>56</b> of a corresponding one of the encrypted secret shares <b>46</b>. The secret share decryption module <b>50</b> is operative to verify the message authentication code <b>56</b> of each of the decrypted secret shares <b>44</b>. The message authentication code <b>56</b> is therefore verified before accepting any secret share <b>44</b> for use in reconstructing any of the CDIs <b>18</b>.
p-0086Second, the secret share distribution module <b>42</b> is preferably operative to distribute each of the encrypted secret shares <b>46</b> to the other devices <b>14</b> with a message authentication code <b>58</b> of a corresponding one of the CDIs <b>18</b>. The secret reconstruction module <b>52</b> is operative to verify the message authentication code <b>58</b> of each of the reconstructed CDIs <b>18</b>. The message authentication code <b>58</b> is verified after recomputing the original secret, and serves as proof of the correctness of the original secret.
p-0087It will be appreciated by those ordinarily skilled in the art that MACs may be used with the other embodiments of the present invention. Additionally, it will be appreciated by those ordinarily skilled in the art that the content provider <b>20</b> may also be able to attach MACs to the CDIs <b>18</b>. In the embodiments of the invention where the content provider <b>20</b> distributes secret shares, the content provider <b>20</b> may also distribute MACs with the secret shares.
p-0088The non-trusted model is now described in more detail with reference to <figref idrefs="DRAWINGS">FIGS. 3-8</figref>.
p-0089Reference is now made to <figref idrefs="DRAWINGS">FIG. 3</figref>, which is a simplified block diagram view of a network including a consuming device <b>60</b> and other devices <b>62</b> constructed and operative in accordance with a first alternative preferred embodiment of the present invention. In the first alternative preferred embodiment, the content provider <b>20</b> does not send the CDIs <b>18</b> with the content <b>16</b>. Instead, the content provider <b>20</b> prepares secret shares. The content provider <b>20</b> then encrypts the secret shares resulting in encrypted secret shares <b>64</b>. The secret shares are encrypted for decryption by the other devices <b>62</b> only and not for decryption by the consuming device <b>60</b>. Therefore, the consuming device <b>60</b> is forced to distribute the encrypted secret shares <b>64</b> to the other devices <b>62</b> for decryption before the secret shares can be used to recreate the CDIs <b>18</b>. Additionally, as the consuming device <b>60</b> does not receive the CDIs <b>18</b> from the content provider <b>20</b>, there is no doubt as to the CDIs <b>18</b> not being erased before the secret shares are distributed to the other devices <b>62</b>.
p-0090Each of the encrypted secret shares <b>64</b> sent by the content provider <b>20</b> for receipt by the consuming device <b>60</b> is preferably encrypted such that each encrypted secret share <b>64</b> is uniquely encrypted for decryption by a corresponding other device <b>62</b>. In other words, each encrypted share <b>64</b> can only be decrypted (using non-hacking methods) by one of the other devices <b>62</b> which has the unique key and/or method for decrypting the encrypted secret share <b>64</b>. Therefore, the consuming device <b>60</b> is forced to distribute the secret shares to the other devices <b>62</b> determined by the content provider <b>20</b>.
p-0091When the consuming device <b>60</b> wants to play/use the content <b>16</b>, the other devices <b>62</b> preferably decrypt the encrypted secret shares <b>64</b> thereby yielding decrypted secret shares <b>66</b>. The decrypted secret shares <b>66</b> are sent to the consuming device <b>60</b> for reconstructing the CDI(s) <b>18</b>.
p-0092Reference is now made to <figref idrefs="DRAWINGS">FIG. 4</figref>, which is a simplified block diagram of the content provider <b>20</b> of <figref idrefs="DRAWINGS">FIG. 3</figref>. The content provider <b>20</b> preferably includes a secret share splitting module <b>61</b>, a secret share encryption module <b>63</b> and a broadcast module <b>65</b>.
p-0093The secret share splitting module <b>61</b> receives the CDIs <b>18</b> and splits each of the CDIs <b>18</b> into the secret shares <b>66</b> preferably in accordance with a threshold scheme such that only a predetermined number of any of the secret shares is needed in order to re-form each CDI <b>18</b>. The predetermined number is greater than one but less or equal to the number of the other devices <b>62</b> (<figref idrefs="DRAWINGS">FIG. 3</figref>). The predetermined number is preferably less than the number of the other devices <b>62</b> (<figref idrefs="DRAWINGS">FIG. 3</figref>).
p-0094The threshold scheme is preferably based on the Shamir secret-sharing method. However, it will be appreciated by those ordinarily skilled in the art that other suitable threshold schemes and non-threshold schemes may be used.
p-0095The secret share encryption module <b>63</b> encrypts the secret shares <b>66</b> thereby rendering the encrypted secret shares <b>64</b>, such that each of the encrypted secret shares <b>64</b> is uniquely encrypted for decryption by a corresponding one of the other devices <b>62</b> (<figref idrefs="DRAWINGS">FIG. 3</figref>).
p-0096The broadcast module <b>65</b> broadcasts the encrypted secret shares <b>64</b> and the content <b>16</b> to the consuming device <b>20</b>. It will be appreciated by those ordinarily skilled in the art that the encrypted secret shares <b>64</b> may be broadcast directly to the other devices <b>62</b> (<figref idrefs="DRAWINGS">FIG. 3</figref>).
p-0097Reference is now made to <figref idrefs="DRAWINGS">FIG. 5</figref>, which is a simplified block diagram view of the consuming device <b>60</b> of <figref idrefs="DRAWINGS">FIG. 3</figref>. The consuming device <b>60</b> is substantially the same as the consuming device <b>12</b> except for the following differences. Due the functionality described with reference to <figref idrefs="DRAWINGS">FIGS. 3 and 4</figref>, the consuming device <b>60</b> does not require the secret share splitting module <b>38</b>, the secret share encryption module <b>40</b> nor secret share decryption module <b>50</b>. The content and secret receive module <b>26</b> preferably receives the content <b>16</b> and the encrypted secret shares <b>64</b>. The content and secret receive module <b>26</b> preferably forwards the content <b>16</b> to the content storage medium <b>28</b> and the encrypted secret shares <b>64</b> to the secret share distribution module <b>42</b>. The secret share distribution module <b>42</b> preferably distributes the encrypted secret shares <b>64</b> to the other devices <b>62</b> (<figref idrefs="DRAWINGS">FIG. 3</figref>). The other devices <b>62</b> generally decrypt the encrypted secret shares <b>64</b> yielding the decrypted secret shares <b>66</b>.
p-0098For playback/use of the content <b>16</b>, the decrypted secret shares <b>66</b> are preferably received by the secret share receive module <b>48</b>. The decrypted secret shares <b>66</b> are preferably passed by the secret share receive module <b>48</b> to the secret reconstruction module <b>52</b> in order to form the CDI(s) <b>18</b> from the decrypted secret shares <b>66</b>. The content <b>16</b> is then preferably decrypted by the content decryption module <b>34</b> yielding the decrypted content <b>54</b>. The decrypted content <b>54</b> is then generally available for play/use by the content consumer <b>36</b>.
p-0099As described above with reference to <figref idrefs="DRAWINGS">FIG. 4</figref>, the encrypted secret shares <b>64</b> are preferably formed in accordance with a threshold scheme. Therefore, the secret reconstruction module <b>52</b> only needs a predetermined number of any of the secret shares <b>66</b> in order to form the CDI(s) <b>18</b>. The predetermined number is typically greater than one but less than, or equal to the number of the other devices. The predetermined number is preferably less than the number of the other devices. The threshold scheme is preferably based on the Shamir secret-sharing method. However, it will be appreciated by those ordinarily skilled in the art that other suitable threshold schemes and non-threshold schemes may be used.
p-0100It will be appreciated by those ordinarily skilled in the art that the encrypted secret shares <b>64</b> can be distributed directly by the content provider <b>20</b> (<figref idrefs="DRAWINGS">FIG. 3</figref>) to the other devices <b>62</b> (<figref idrefs="DRAWINGS">FIG. 3</figref>) if an appropriate communication link exists between the content provider <b>20</b> and the other devices <b>62</b>. Where the content provider <b>20</b> distributes the encrypted secret shares <b>64</b> directly to the other devices <b>62</b>, the secret share distribution module <b>42</b> is not required.
p-0101Reference is now made to <figref idrefs="DRAWINGS">FIG. 6</figref>, which is a simplified block diagram view of a network including a consuming device <b>68</b> and other devices <b>70</b> constructed and operative in accordance with a second alternative preferred embodiment of the present invention. In the second alternative preferred embodiment, the content provider <b>20</b> does not send the CDIs <b>18</b> with the content <b>16</b>. Instead, the content provider <b>20</b> prepares secret shares.
p-0102The content provider <b>20</b> then preferably encrypts the secret shares twice, resulting in doubly encrypted secret shares (DESSs) <b>72</b> for sending to the consuming device <b>68</b>. The DESSs <b>72</b> are preferably doubly encrypted by an inner encryption and then an outer encryption such that the outer encryption needs to be decrypted before the inner encryption. The outer encryption is preferably uniquely encrypted for decryption, by non-hacking methods, by a corresponding one of the other devices <b>70</b>, similar to the encryption of the encrypted secret shares <b>64</b> (<figref idrefs="DRAWINGS">FIG. 3</figref>). The inner encryption is preferably encrypted for decryption, by non-hacking methods, only by the consuming device <b>68</b>, similar to the encryption of the ESSs <b>24</b> (<figref idrefs="DRAWINGS">FIG. 1</figref>).
p-0103Therefore, the consuming device <b>68</b> is forced to distribute the DESSs <b>72</b> to the other devices <b>70</b> for decrypting the outer encryption. Additionally, the other devices <b>70</b> cannot use the DESSs <b>72</b> as the inner encryption is only for decryption by the consuming device <b>68</b>.
p-0104When the consuming device <b>68</b> wants to play/use the content <b>16</b>, the other devices <b>70</b> preferably decrypt the DESSs <b>72</b> thereby yielding encrypted secret shares <b>74</b> still encrypted by the inner encryption. The encrypted secret shares <b>74</b> are preferably sent to the consuming device <b>68</b> for decryption and reconstructing the CDI(s) <b>18</b>.
p-0105Reference is now made to <figref idrefs="DRAWINGS">FIG. 7</figref>, which is a simplified block diagram of the content provider <b>20</b> of <figref idrefs="DRAWINGS">FIG. 6</figref>. The content provider <b>20</b> preferably includes a secret share splitting module <b>71</b>, a secret share encryption module <b>73</b> and a broadcast module <b>75</b>.
p-0106The secret share splitting module <b>71</b> receives the CDIs <b>18</b> and splits each of the CDIs <b>18</b> into the secret shares <b>76</b> preferably in accordance with a threshold scheme such that only a predetermined number of any of the secret shares is needed in order to re-form each CDI <b>18</b>. The predetermined number is greater than one but less or equal to the number of the other devices <b>70</b> (<figref idrefs="DRAWINGS">FIG. 6</figref>). The predetermined number is preferably less than the number of the other devices <b>70</b> (<figref idrefs="DRAWINGS">FIG. 6</figref>).
p-0107The threshold scheme is preferably based on the Shamir secret-sharing method. However, it will be appreciated by those ordinarily skilled in the art that other suitable threshold schemes and non-threshold schemes may be used.
p-0108The secret share encryption module <b>73</b> doubly encrypts the secret shares <b>76</b> thereby rendering the DESSs <b>72</b>.
p-0109The broadcast module <b>75</b> broadcasts the DESSs <b>72</b> and the content <b>16</b> to the consuming device <b>20</b>. It will be appreciated by those ordinarily skilled in the art that the DESSs <b>72</b> may be broadcast directly to the other devices <b>70</b> (<figref idrefs="DRAWINGS">FIG. 6</figref>).
p-0110Reference is now made to <figref idrefs="DRAWINGS">FIG. 8</figref>, which is a simplified block diagram view of the consuming device <b>68</b> of <figref idrefs="DRAWINGS">FIG. 6</figref>. The consuming device <b>68</b> is substantially the same as the consuming device <b>60</b> (<figref idrefs="DRAWINGS">FIG. 5</figref>) except for the following differences. The content and secret receive module <b>26</b> preferably receives the content <b>16</b> and the DESSs <b>72</b>. The content and secret receive module <b>26</b> preferably forwards: the content <b>16</b> to the content storage medium <b>28</b>; and the DESSs <b>72</b> to the secret share distribution module <b>42</b> for forwarding to the other devices <b>70</b> (<figref idrefs="DRAWINGS">FIG. 6</figref>). The other devices <b>70</b> typically decrypt the DESSs <b>72</b> yielding the encrypted secret shares <b>74</b>. For play/use of the content <b>16</b>, the encrypted secret shares <b>74</b> are preferably received by the secret share receive module <b>48</b>. The secret share receive module <b>48</b> typically forwards the encrypted secret shares <b>74</b> to the secret share decryption module <b>50</b> for decryption, thereby yielding decrypted secret shares <b>76</b>. The secret share decryption module <b>50</b> generally forwards the decrypted secret shares <b>76</b> to the secret reconstruction module <b>52</b>. The decrypted secret shares <b>76</b> are preferably reconstructed by the secret reconstruction module <b>52</b> to form the CDI(s) <b>18</b> for use in decrypting the content <b>16</b>.
p-0111Reference is now made to <figref idrefs="DRAWINGS">FIG. 9</figref>, which is a graph <b>78</b> showing a polynomial <b>80</b> to illustrate the Shamir secret sharing scheme. The secret sharing method is now described in more detail with reference to the Shamir secret sharing scheme. However, it will be appreciated by those ordinarily skilled in the art that other suitable threshold and non-threshold secret sharing schemes can be used to implement the system and method of the present invention. By way of introduction the Shamir secret sharing method uses polynomial interpolation. Each device on the network preferably receives a serial number, z; z is a small integer between 1 and N. L=|K| denotes the maximum number of bits in one CDI <b>18</b> (<figref idrefs="DRAWINGS">FIG. 1</figref>). M denotes the modulus, a large number that is close enough to 2<sup>L</sup>, so that M is greater than the binary representation of any CDI <b>18</b>. It is preferably required that M should not have any divisors less than or equal to the device numbers of the network <b>10</b> (<figref idrefs="DRAWINGS">FIG. 1</figref>); for simplicity, we generally require that M be prime. M should preferably be greater than N.
p-0112As described above with reference to <figref idrefs="DRAWINGS">FIG. 2</figref>, r is the predetermined number of secret share owners required to participate in the CDI <b>18</b> re-generation. Therefore, the polynomial needs r coefficients.
p-0113As described above with reference to <figref idrefs="DRAWINGS">FIG. 1</figref>, K<sub>1</sub>, K<sub>2</sub>, . . . , K<sub>t </sub>denotes the sequence of the CDIs <b>18</b> for the content <b>16</b>. For each CDI <b>18</b> (K<sub>j</sub>) that we want to split into secret shares, we preferably take the binary representation of the CDI <b>18</b> (K<sub>j</sub>) padded to L bits. We then preferably take the binary representation as the free coefficient of the polynomial.
p-0114For the other r−1 coefficients, we need r−1 arbitrary L-bit secret numbers such that no strict subset of the coefficients reveals K<sub>j</sub>. The coefficients are denoted N<sub>1 </sub>. . . N<sub>r−1</sub>. Optionally, the coefficients may be obtained by using at least some of the other CDIs <b>18</b> (K<sub>j+1</sub>, K<sub>j+2</sub>, . . . ) thereby allowing the distribution of r CDIs <b>18</b> at a time. However, the first method of determining the r−1 coefficients is more secure.
p-0115Alternate methods of generating the L*(r−1) bits include the following secure methods. First, use a secure random or pseudo-random number generator to determine the r−1 coefficients. Second, use a well-known hash function (for example, but not limited to, SHA-1 or MD5) with K<sub>j </sub>as the original input. The r−1 coefficients are obtained by repeatedly hashing K<sub>j </sub>and concatenating the results.
p-0116For a device z and CDI <b>18</b> (K<sub>j</sub>), the secret share of z, namely, A<sub>j</sub>(z) is preferably as follows:
p-0117<br /><i>Aj</i>(<i>z</i>)=<i>Kj+N</i><sub>1</sub><i>*z+N</i><sub>2</sub><i>*z</i><sup>2</sup><i>+ . . . +N</i><sub>r−1</sub><i>*z</i><sup>r−1</sup>(mod <i>M</i>) (Equation 1),
p-0118which can also be written in the form,
p-0119<maths id="MATH-US-00001" num="00001"><math overflow="scroll"><mtable><mtr><mtd><mrow><mrow><msub><mi>A</mi><mi>j</mi></msub><mo></mo><mrow><mo>(</mo><mi>z</mi><mo>)</mo></mrow></mrow><mo>=</mo><mrow><msub><mi>K</mi><mi>j</mi></msub><mo>+</mo><mrow><munderover><mo>∑</mo><mrow><mi>i</mi><mo>=</mo><mn>1</mn></mrow><mrow><mi>r</mi><mo>-</mo><mn>1</mn></mrow></munderover><mo></mo><mstyle><mspace width="0.3em" height="0.3ex" /></mstyle><mo></mo><mrow><mrow><mo>(</mo><mrow><msub><mi>N</mi><mi>i</mi></msub><mo>*</mo><msup><mi>z</mi><mi>i</mi></msup></mrow><mo>)</mo></mrow><mo></mo><mrow><mrow><mo>(</mo><mrow><mi>mod</mi><mo></mo><mrow><mstyle><mspace width="0.3em" height="0.3ex" /></mstyle><mo></mo><mstyle><mspace width="0.3em" height="0.3ex" /></mstyle></mrow><mo></mo><mi>M</mi></mrow><mo>)</mo></mrow><mo>.</mo></mrow></mrow></mrow></mrow></mrow></mtd><mtd><mrow><mo>(</mo><mrow><mi>Equation</mi><mo></mo><mstyle><mspace width="0.8em" height="0.8ex" /></mstyle><mo></mo><mn>2</mn></mrow><mo>)</mo></mrow></mtd></mtr></mtable></math></maths>
p-0120Equations 1 and 2 describe a polynomial; for example, the polynomial <b>80</b>. The number of the device is given on the axis labeled z of the graph <b>78</b>. The value of the secret share is given on the axis labeled y of the graph <b>78</b>. So for example, the device z receives secret shares A<sub>1</sub>(z), A<sub>2</sub>(z), . . . , A<sub>t</sub>(z).
p-0121Since the Shamir secret sharing scheme is a threshold scheme, it is possible for a device to hold more than one secret share. Such a device would be privileged, as the privileged device would effectively replace several devices. It is also possible to pass the extra secret shares to other devices when new devices become available. This is generally useful in enrollment and disenrollment, discussed below.
p-0122Reference is now made to <figref idrefs="DRAWINGS">FIG. 10</figref>, which is a simplified block diagram view illustrating content decryption input restoration for use by the devices of <figref idrefs="DRAWINGS">FIGS. 1</figref>, <b>3</b> and <b>6</b> according to the Shamir secret sharing scheme. The consuming device <b>12</b> (Device D) chooses at least r network peers, namely the other devices <b>14</b>, holding a plurality of secret shares <b>82</b> for the content <b>16</b> that consuming device <b>12</b> wants to decrypt. To decrypt portion j of the encrypted content <b>16</b> (C<sub>j</sub>), the consuming device <b>12</b> requests the secret share A<sub>j</sub>(z) from the other devices <b>14</b>. The consuming device <b>12</b> then restores the CDI <b>18</b> (K<sub>j</sub>). K<sub>j </sub>is then used by consuming device <b>82</b> to decrypt C<sub>j</sub>.
p-0123The preferable mathematical treatment involved in determining K<sub>j </sub>from the secret shares <b>82</b> is described below.
p-0124The participating devices indices (including the index of device D) are generally denoted V<sub>1</sub>, V<sub>2</sub>, V<sub>2</sub>, . . . , V<sub>r</sub>.
p-0125To restore K<sub>j</sub>, the consuming device <b>12</b> (device D) preferably gathers the secret shares A<sub>j</sub>(V<sub>1</sub>), A<sub>j</sub>(V<sub>2</sub>), . . . , A<sub>j</sub>(V<sub>r</sub>) and solves a linear equation system modulo M, defined by the Vandermonde matrix:
p-0126<maths id="MATH-US-00002" num="00002"><math overflow="scroll"><mrow><mrow><mrow><mo>(</mo><mtable><mtr><mtd><mn>1</mn></mtd><mtd><msub><mi>v</mi><mn>1</mn></msub></mtd><mtd><msubsup><mi>v</mi><mn>1</mn><mn>2</mn></msubsup></mtd><mtd><mi>…</mi></mtd><mtd><msubsup><mi>v</mi><mn>1</mn><mrow><mi>r</mi><mo>-</mo><mn>1</mn></mrow></msubsup></mtd></mtr><mtr><mtd><mn>1</mn></mtd><mtd><msub><mi>v</mi><mn>2</mn></msub></mtd><mtd><msubsup><mi>v</mi><mn>2</mn><mn>2</mn></msubsup></mtd><mtd><mi>…</mi></mtd><mtd><msubsup><mi>v</mi><mn>2</mn><mrow><mi>r</mi><mo>-</mo><mn>1</mn></mrow></msubsup></mtd></mtr><mtr><mtd><mi>…</mi></mtd><mtd><mi>…</mi></mtd><mtd><mi>…</mi></mtd><mtd><mi>…</mi></mtd><mtd><mi>…</mi></mtd></mtr><mtr><mtd><mn>1</mn></mtd><mtd><msub><mi>v</mi><mi>r</mi></msub></mtd><mtd><msubsup><mi>v</mi><mi>r</mi><mn>2</mn></msubsup></mtd><mtd><mi>…</mi></mtd><mtd><msubsup><mi>v</mi><mi>r</mi><mrow><mi>r</mi><mo>-</mo><mn>1</mn></mrow></msubsup></mtd></mtr></mtable><mo>)</mo></mrow><mo></mo><msub><mrow><mo>(</mo><mtable><mtr><mtd><msub><mi>K</mi><mi>j</mi></msub></mtd></mtr><mtr><mtd><msub><mi>N</mi><mn>1</mn></msub></mtd></mtr><mtr><mtd><mi>…</mi></mtd></mtr><mtr><mtd><msub><mi>N</mi><mrow><mi>r</mi><mo>-</mo><mn>1</mn></mrow></msub></mtd></mtr></mtable><mo>)</mo></mrow><mi>u</mi></msub></mrow><mo>=</mo><mrow><mo>(</mo><mtable><mtr><mtd><mrow><msub><mi>A</mi><mi>j</mi></msub><mo></mo><mrow><mo>(</mo><msub><mi>V</mi><mn>1</mn></msub><mo>)</mo></mrow></mrow></mtd></mtr><mtr><mtd><mrow><msub><mi>A</mi><mi>j</mi></msub><mo></mo><mrow><mo>(</mo><msub><mi>V</mi><mn>2</mn></msub><mo>)</mo></mrow></mrow></mtd></mtr><mtr><mtd><mi>…</mi></mtd></mtr><mtr><mtd><mrow><msub><mi>A</mi><mi>j</mi></msub><mo></mo><mrow><mo>(</mo><msub><mi>V</mi><mi>r</mi></msub><mo>)</mo></mrow></mrow></mtd></mtr></mtable><mo>)</mo></mrow></mrow></math></maths>
p-0127The determinant of the matrix is Π (V<sub>j</sub>−V<sub>i</sub>|1<=i<j<=r).
p-0128According to the definition of M, the value of the determinant is co-prime to M, and therefore co-prime to invertible mod M. Therefore, the matrix is also invertible. In other words, the values N<sub>1</sub>, . . . , N<sub>r−1 </sub>and K<sub>j </sub>are recoverable, but only by someone who has a set of at least r secret shares A<sub>j</sub>.
p-0129Enrollment and disenrollment are now described below.
p-0130The peer set V1, V2, . . . , Vr may be altered during a playback/use session or between playback/use sessions. Any device that suffers a malfunction or wishes to discontinue participation may be replaced by another device that has secret shares for the content as long as the security level r is preserved.
p-0131Any new device joining the network, and wishing to serve as a share holder, can be given a set of secret shares Aj(z) corresponding to its index z. Depending on the trust model (trusted or non-trusted), the consuming device <b>12</b> or the content provider <b>20</b> (<figref idrefs="DRAWINGS">FIG. 1</figref>) preferably compute and provide the new secret shares for the new device z. Note that with the trusted model case, the consuming device <b>12</b> generally needs to gather r secret shares and restore the original CDIs <b>18</b> first (<figref idrefs="DRAWINGS">FIG. 1</figref>).
p-0132It is sensible to increase the security level r upon the enrollment of new devices. If the security level r is increased, all the participating devices must receive newly computed secret shares based on the new value of r.
p-0133Error recovery is now described below.
p-0134It is possible to strengthen the system against erroneous secret shares provided by cheating or malfunctioning participants. In order to detect bad secret shares, three subsets of r participants are used, instead of one subset. The subsets may overlap. In there are bad secret shares present, the sender of the bad secret shares may be detected by comparing the results from the three different subsets; the subsets where the sender of the bad secret shares does not participate will agree on the correct result. It may be necessary to change the participation of the subsets more than once to identify the sender of the bad secret shares.
p-0135It is appreciated that software components of the present invention may, if desired, be implemented in ROM (read only memory) form. The software components may, generally, be implemented in hardware, if desired, using conventional techniques.
p-0136It will be appreciated that various features of the invention which are, for clarity, described in the contexts of separate embodiments may also be provided in combination in a single embodiment. Conversely, various features of the invention which are, for brevity, described in the context of a single embodiment may also be provided separately or in any suitable sub-combination. It will also be appreciated by persons skilled in the art that the present invention is not limited by what has been particularly shown and described hereinabove. Rather the scope of the invention is defined only by the claims which follow.
Contents5
13 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13
Every citation, both waysCites: the store holds 14 of 15
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2009254750A1 | Cited by | United States of America | Pre-grant |
| US10091000B2 | Cited by | United States of America | Applicant |
| WO2020112949A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US2010054470A1 | Cited by | United States of America | Pre-grant |
| US9392319B2 | Cited by | United States of America | Applicant |
| US2014250303A1 | Cited by | United States of America | Pre-grant |
| US2014198911A1 | Cited by | United States of America | Pre-grant |
| US8595507B2 | Cited by | United States of America | Applicant |
| US2007160198A1 | Cited by | United States of America | Pre-grant |
| US10284367B1 | Cited by | United States of America | Search report |
| US8918897B2 | Cited by | United States of America | Search report |
| US10887091B2 | Cited by | United States of America | Applicant |
| US2011202755A1 | Cited by | United States of America | Pre-grant |
| US9516016B2 | Cited by | United States of America | Applicant |
| US9231943B2 | Cited by | United States of America | Applicant |
| US2020127817A1 | Cited by | United States of America | Search report |
| US2010232604A1 | Cited by | United States of America | Pre-grant |
| WO2016048515A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US9774449B2 | Cited by | United States of America | Applicant |
| US10623386B1 | Cited by | United States of America | Search report |
| US9992170B2 | Cited by | United States of America | Applicant |
| US2008183992A1 | Cited by | United States of America | Pre-grant |
| US8009830B2 | Cited by | United States of America | Applicant |
| US2009097661A1 | Cited by | United States of America | Pre-grant |
| US2011126295A1 | Cited by | United States of America | Pre-grant |
| US2017187523A1 | Cited by | United States of America | Search report |
| US2016099933A1 | Cited by | United States of America | Pre-grant |
| US10402573B1 | Cited by | United States of America | Search report |
| US9613220B2 | Cited by | United States of America | Applicant |
| US8364958B2 | Cited by | United States of America | Search report |
| US2017187523A1 | Cited by | United States of America | Pre-grant |
| US2006177061A1 | Cited by | United States of America | Pre-grant |
| US8787583B2 | Cited by | United States of America | Applicant |
| US9594698B2 | Cited by | United States of America | Search report |
| US2008137857A1 | Cited by | United States of America | Pre-grant |
| US2010299313A1 | Cited by | United States of America | Pre-grant |
| US10263770B2 | Cited by | United States of America | Applicant |
| US2011019822A1 | Cited by | United States of America | Pre-grant |
| US2015052369A1 | Cited by | United States of America | Pre-grant |
| US9503785B2 | Cited by | United States of America | Applicant |
| US2018097624A1 | Cited by | United States of America | Search report |
| US9940195B2 | Cited by | United States of America | Applicant |
| US2011179271A1 | Cited by | United States of America | Pre-grant |
| US9871770B2 | Cited by | United States of America | Applicant |
| US10419214B2 | Cited by | United States of America | Search report |
| US9935923B2 | Cited by | United States of America | Applicant |
| US2014310516A1 | Cited by | United States of America | Pre-grant |
| US10298562B2 | Cited by | United States of America | Applicant |
| US2014029748A1 | Cited by | United States of America | Pre-grant |
| US8675877B2 | Cited by | United States of America | Applicant |
| US10873449B2 | Cited by | United States of America | Search report |
| US9906500B2 | Cited by | United States of America | Applicant |
| US9515828B2 | Cited by | United States of America | Search report |
| CN107465505A | Cited by | China | Search report |
| WO2012177268A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8155322B2 | Cited by | United States of America | Search report |
| US10068103B2 | Cited by | United States of America | Applicant |
| US9548972B2 | Cited by | United States of America | Search report |
| US9985932B2 | Cited by | United States of America | Applicant |
| US10797865B2 | Cited by | United States of America | Search report |
| US11032259B1 | Cited by | United States of America | Search report |
| US9461821B1 | Cited by | United States of America | Search report |
| US10887086B1 | Cited by | United States of America | Applicant |
| US2010054458A1 | Cited by | United States of America | Pre-grant |
| US2008244277A1 | Cited by | United States of America | Pre-grant |
| US2009177894A1 | Cited by | United States of America | Pre-grant |
| US9407431B2 | Cited by | United States of America | Applicant |
| US9641514B2 | Cited by | United States of America | Search report |
| US9742561B2 | Cited by | United States of America | Search report |
| US2001037407A1 | Cites | United States of America | Pre-grant |
| US2002108040A1 | Cites | United States of America | Pre-grant |
| US2002157002A1 | Cites | United States of America | Pre-grant |
| US2003026432A1 | Cites | United States of America | Pre-grant |
| US2003081789A1 | Cites | United States of America | Pre-grant |
| US2003112969A1 | Cites | United States of America | Pre-grant |
| US2003115251A1 | Cites | United States of America | Pre-grant |
| US2004103276A1 | Cites | United States of America | Pre-grant |
| US2004117649A1 | Cites | United States of America | Pre-grant |
| US5764767A | Cites | United States of America | Pre-grant |
| US6367019B1 | Cites | United States of America | Pre-grant |
| US6408392B2 | Cites | United States of America | Pre-grant |
| US6748084B1 | Cites | United States of America | Pre-grant |
| US8139770B2 | Cites | United States of America | Pre-grant |
6 members in 3 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 17160105 | Israel | A | |
| 2006000519 | Israel | W | |
| 171601 | – | – | – |
| IL20050171601 | – | – | – |
| PCTIL0600519 | – | – | – |
| WO2006IL00519 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| WO2007049267A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1839405A1 | European Patent Office (EPO) | A1 | |
| US2009077379A1 | United States of America | A1 | |
| EP1839405A4 | European Patent Office (EPO) | A4 | |
| EP1839405B1 | European Patent Office (EPO) | B1 | |
| US8842835B2 | United States of America | B2 |
18 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lapsed due to failure to pay maintenance feeLapsedFP | FP | |
| Lapse for failure to pay maintenance feesLapsedPATENT EXPIRED FOR FAILURE TO PAY MAINTENANCE FEES (ORIGINAL EVENT CODE: EXP.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYLAPS | LAPS | |
| Information on status: patent discontinuationPATENT EXPIRED DUE TO NONPAYMENT OF MAINTENANCE FEES UNDER 37 CFR 1.362STCH | STCH | |
| Fee payment procedureMAINTENANCE FEE REMINDER MAILED (ORIGINAL EVENT CODE: REM.); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP | |
| Maintenance fee paymentMAFP | MAFP | |
| Certificate of correctionCC | CC | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 2009077379
- Publication, EPODOC
- US2009077379
- Application
- 11793365
- Application, DOCDB
- 79336506
- Application, EPODOC
- US20060793365
Titles
- English
- Network Security System
Classification
- CPC, 2
- H04L9/085
- H04L2209/60
- IPC, 3
- H04L9 12
- H04L9 00
- H04N7 16
- USPC, 2
- 713170000
- 380200000