US2008028234A1PendingUtilityA1

Method and system for secure content distribution

Assignee: VIXS SYSTEMS INCPriority: Feb 17, 2004Filed: Oct 3, 2007Published: Jan 31, 2008
Est. expiryFeb 17, 2024(expired)· nominal 20-yr term from priority
G06F 21/109
51
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system on a chip (SOC) device is disclosed comprising external outputs, and external inputs. A first secure storage location is operably decoupled from all of the external outputs of the SOC device during a normal mode of operation. By being decoupled from all external outputs, representations of the data stored at the first secure device are prevented from being provided to the external outputs. The decryption engine is also included on the system on a chip, comprising a first data input, and a private key input coupled to a first portion of the first secure storage location, and an output coupled to a second secure location. The decryption engine is operable to determine decrypted data from data received at the first data input based upon a private key received at the private key input. The decryption engine is further operable to write the decrypted data only to the first secure memory location and the second secure location.

Claims

exact text as granted — not AI-modified
1 . A system on a chip (SOC) device comprising: 
 external output interfaces to provide information from the SOC device;    external input interfaces to provide information to the SOC device;    a first secure storage location operably de-coupled from all external output nodes of the SOC device during a normal mode of operation to prevent representations of data to be stored at the first secure storage location from being provided at an external output interface; and    a decryption engine comprising a first data input, a private key input coupled to a first portion of the first secure storage location, and an output coupled to a second secure storage location, the decryption engine operable to determine decrypted data from data received at the first data input based on a private key received at the private key input, and further operable to write the decrypted data only to the first secure memory location and the second secure storage location.    
     
     
         2 . The system of  claim 1 , wherein the first storage location is operably decoupled from all external devices by preventing access to the first storage location.  
     
     
         3 . The system of  claim 1 , wherein the first storage location is operably decoupled from all external devices by destroying the data at the first storage location in response to being accessed.  
     
     
         4 . The system of  claim 1 , wherein a second secure storage location coupled to the output of the decryption engine is operably de-coupled from all external output nodes of the SOC device during a normal mode of operation to prevent data stored at the second secure storage location from being provided at an external output interface.  
     
     
         5 . The method of  claim 4 , wherein a first portion of the first secure storage location is a write-once storage location.  
     
     
         6 . The method of  claim 4 , wherein the first portion of the first secure storage location is a write-many storage location.  
     
     
         7 . The system of  claim 4 , wherein a first portion of the first secure storage location comprises a non-volatile storage location for a first private key storage location.  
     
     
         8 . The system of  claim 7 , wherein the first secure storage location comprises a plurality of private key storage locations.  
     
     
         9 . The system of  claim 8 , wherein the plurality of private key storage locations are part of the first portion of the first secure storage location.  
     
     
         10 . The system of  claim 1 , wherein the decryption engine is operable to execute a decryption algorithm in parallel in hardware.  
     
     
         11 . The system of  claim 1  further comprising a unique SOC identifier.  
     
     
         12 . The system of  claim 4  further comprising: 
 a descrambler comprising a first data input, a control word input coupled to a first portion of the second secure storage location during normal operation, and an output, the descrambler operable to access a control word only from the second secured storage location, wherein the control word is used by the descrambler to descramble scrambled data.    
     
     
         13 . The system of  claim 12  further comprising a random number generator comprising an output, the random number generator operable to provide a random number at the output.  
     
     
         14 . The system of  claim 13 , wherein the output of the random number generator is coupled to the second secure storage location.  
     
     
         15 . The system of  claim 14 , wherein the output of the random number generator is operably coupled to have exclusive write access to a predefined location of the second secure storage location during normal operation.  
     
     
         16 . The system of  claim 15  further comprising: 
 an encryption engine comprising a first data input coupled to the second secure storage location, a public key input to receive a public key, and an output to provide an encrypted representation of data received at the first data input.    
     
     
         17 . The system of  claim 16 , where in the encryption engine is operable to provide the encrypted representation to an external output interface.  
     
     
         18 . The system of  claim 17 , where in the first secure storage location being operably de-coupled from all external output nodes of the SOC device further comprises the first secure storage location being de-coupled from the data input and the public key input of the encryption engine.  
     
     
         19 . The system of  claim 18  further comprising a transcoder operably coupled to the output of the descrambler to receive a first image having a first resolution and to provide a second image, based on the first image, having a second resolution, the second resolution being less than the first resolution.  
     
     
         20 . The system of  claim 18  further comprising a transcoder operably coupled to the output of the descrambler to receive a first image at a first bit rate and to provide a second image, based on the first image, having a second bit rate, the second resolution being less than the first resolution.

Join the waitlist — get patent alerts

Track US2008028234A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.