US2019020933A1PendingUtilityA1

Secure provisioning, by a client device, cryptographic keys for exploiting services provided by an operator

Assignee: NAGRAVISION SAPriority: Dec 23, 2015Filed: Dec 20, 2016Published: Jan 17, 2019
Est. expiryDec 23, 2035(~9.4 yrs left)· nominal 20-yr term from priority
H04L 9/16H04L 9/083H04L 9/0825H04N 21/63345H04N 7/1675H04N 21/835H04N 21/4405H04L 9/088H04L 9/0819H04L 9/14H04L 9/0822
50
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for securely receiving a multimedia content by a client device operated by one or more operator(s) involving a dedicated provisioning server of a security provider managing symmetric secrets used by the client devices and operators license servers. The provisioning server provides to the client device one or more generations of operator specific unique device secrets, which are then exploited by the various operators' license servers to deliver licenses such that authorized client devices can consume protected multimedia contents.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for exploiting, by a client device (DEV), a scrambled service ([S Op ]SK) provided by an operator (Op), the client device (DEV) owning a unique device key ( U DK) provisioning unique cryptographic key material specific to the operator (Op) and to the client device (DEV), the provisioned unique cryptographic key material being configured to obtain a service key (SK) for descrambling the scrambled service ([S Op ]SK), the method is characterized in that it comprises:
 in an initialization phase carried out by the client device (DEV):
 downloading from a remote server a global operator vault ( GO OpVault Gen ), containing at least an operator specific global seed ( GO OpSeed Gen ), 
 transmitting a pre-provisioning challenge (REQp) for the operator (Op) to a provisioning server (PVS), the provisioning challenge (REQp) comprising at least a unique identifier (DEV-ID) of the client device (DEV) and an identifier of the operator (Op), 
   the provisioning server (PVS) carrying out steps of:
 checking entitlement of the client device (DEV) in a database (DB) coupled to the provisioning server (PVS), 
 when the entitlement checking operation is successful, retrieving from the database (DB), the unique device key ( U DK), the operator specific global seed ( GO OpSeed Gen ) and a global operator license server key ( GO K LS Gen ) by using the unique identifier (DEV-ID) of the client device (DEV) and the identifier of the operator (Op), 
 calculating a device derived key ( UO K DER Gen ) by applying a cryptographic algorithm on the unique device key ( U DK) and the global operator seed ( GO OpSeed Gen ), 
 forming a unique cryptogram ([ UO K DER Gen ] GO K LS Gen ) by encrypting the unique device derived key ( UO K DER Gen ) with the global operator license server key ( GO K LS Gen ), 
 receiving by the client device (DEV) from the provisioning server (PVS), in response to the pre-provisioning challenge (REQp), at least one device instance certificate ( UO DIC) comprising the unique cryptogram ([ UO K DER Gen ] GO K LS Gen ) specific to the operator (Op) and to the client device (DEV). 
   in an exploitation phase carried out by the client device (DEV),
 transmitting a post-provisioning challenge (REQl) to an operator license server (OpLS), the post-provisioning challenge (REQl) comprising at least the device instance certificate ( UO DIC), the operator license server (OpLS) decrypting the unique cryptogram ([ UO K DER Gen ] GO K LS Gen ) of the device instance certificate ( UO DIC) with the global operator license server key ( GO K LS Gen ) for retrieving the unique device derived key ( UO K DER Gen ) specific to the operator (Op) and to the client device (DEV), 
 receiving from the operator license server (OpLS), in response to the post-provisioning challenge (REQI), a license (L) comprising at least a service key (SK) encrypted with the unique device derived key ( UO K DER Gen ), 
 extracting the operator specific global seed ( GO OpSeed Gen ) from the global operator vault ( GO OpVault Gen ) previously downloaded, 
 calculating the unique device derived key ( UO K DER Gen ) by applying a cryptographic algorithm on the extracted global operator seed ( GO OpSeed Gen ) and the unique device key ( U DK), 
 decrypting the service key (SK) with the calculated unique device derived key ( UO K DER Gen ), 
 receiving and descrambling the scrambled service ([S Op ]SK) with the obtained service key (SK). 
   
     
     
         2 . The method according to  claim 1  characterized in that the global operator vault ( GO OpVault Gen ) is downloaded by the client device (DEV) from the provisioning server (PVS), or from a server of the operator (Op) or from an application server (APPS), and stored in a non-volatile memory of the client device (DEV). 
     
     
         3 . The method according to  claim 1  characterized in that the service key SK includes a content package key (Kp), the license (L) comprising the content package key (Kp) encrypted with the unique device derived key ( UO K DER Gen ) and a content key (CK) encrypted with the content package key (Kp), the client device (DEV) decrypting the content package key (Kp) with the calculated unique device derived key ( UO K DER Gen ), and the content key (CK) with the content package key (Kp) previously decrypted. 
     
     
         4 . The method according to  claim 2 , characterized in that the global operator vault ( GO OpVault Gen ) is encrypted by a global operator vault key ( GO K Opvault ), said global operator vault key ( GO K Opvault ) being provided to the client device (DEV) by the provisioning server (PVS) in addition to the device instance certificate ( UO DIC). 
     
     
         5 . The method according to  claim 1 , characterized in that the provisioning server (PVS) provides to the client device (DEV) several generations of unique cryptograms ([ UO K DER Gen ] GO K LS Gen ) within the device instance certificate ( UO DIC) to be stored in a memory of the client device (DEV), said unique cryptograms ([ UO K DER Gen ] GO K LS Gen ) being available for transmitting to the operator license sever (OpLS) without re-provisioning at the provisioning server (PVS), the generation currently in use being indicated by an index contained in the global operator vault ( GO OpVault Gen ). 
     
     
         6 . The method according to  claim 5 , characterized in that the global operator vault ( GO OpVault Gen ) of a given generation contains global operator seeds of the preceding generation (s). 
     
     
         7 . The method according to  claim 5 , characterized in that a generation is changed in case a vault, seed or key is compromised or after a predetermined expiry time period. 
     
     
         8 . The method according to  claim 1 , characterized in that the pre-provisioning challenge (REQp) and the post-provisioning challenge (REQl) transmitted by the client device (DEV) and the answer to the pre-provisioning challenge (REQp) transmitted by the provisioning server (PVS) and the answer to the post-provisioning challenge (REQl) transmitted by the license server (OpLS) are cryptographically signed. 
     
     
         9 . A client device (DEV) configured to exploit a scrambled service ([S Op ]SK) provided by an operator (Op), the client device (DEV), owning a unique device key ( U DK), being further configured to provision unique cryptographic key material specific to the operator (Op) and to the client device (DEV), the provisioned unique cryptographic key material being configured to obtain a service key (SK) capable to descramble the scrambled service ([S Op ]SK), the client device (DEV) is characterized in that it is further configured to:
 download and store in a non-volatile memory an operator global vault ( GO OpVault Gen ), containing at least a global operator seed ( GO OpSeed Gen ),   transmit a pre-provisioning challenge (REQp) for the operator (Op) to a provisioning server (PVS), the provisioning challenge (REQp) comprising at least a unique identifier (DEV-ID) of the client device (DEV) and an identifier of the operator (Op), the provisioning server (PVS) being configured to check entitlement of the client device (DEV) in a database (DB) coupled to the provisioning server (PVS), when the entitlement checking operation is successful, retrieve from the database (DB), the unique device key ( U DK), the operator specific global seed ( GO OpSeed Gen ) and a global operator license server key ( GO K LS Gen ) by using the unique identifier (DEV-ID) of the client device (DEV) and the identifier of the operator (Op), calculate a device derived key ( UO K DER Gen ) by applying a cryptographic algorithm on the unique device key ( U DK) and the global operator seed ( GO OpSeed Gen ), and form a unique cryptogram ([ UO K DER Gen ] GO K LS Gen ) by encrypting the unique device derived key ( UO K DER Gen ) with the global operator license server key ( GO K LS Gen ),   receive from the provisioning server (PVS), in response to pre-provisioning challenge (REQp), at least one device instance certificate ( UO DIC) comprising the unique cryptogram ([ UO K DER Gen ] GO K LS Gen ) specific to the operator (Op) and to the client device (DEV),   transmit a post-provisioning challenge (REQl) to an operator license server (OpLS), the post-provisioning challenge (REQl) comprising at least the device instance certificate ( UO DIC), the operator license server (OpLS) being configured to decrypt the unique cryptogram ([ UO K DER Gen ] GO K LS Gen ) of the device instance certificate ( UO DIC) with the global operator license server key ( GO K LS Gen ) for retrieving a unique device derived key ( UO K DER Gen ) specific to the operator (Op) and to the client device (DEV),   receive from the operator license server (OpLS), in response to post-provisioning challenge (REQI), a license (L) comprising at least a service key (SK) encrypted with the unique device derived key ( UO K DER Gen ),   calculate the unique device derived key ( UO K DER Gen ) by applying a cryptographic algorithm on the global operator seed ( GO OpSeed Gen ) and the unique device key ( U DK),   decrypt the service key (SK) with the calculated unique device derived key ( UO K DER Gen ),   receive and descramble the scrambled service ([S Op ]SK) with the obtained service key (SK).   
     
     
         10 . The client device according to  claim 9  characterized in that it is configured to download the operator global vault ( GO OpVault Gen ) from the provisioning server (PVS), or from a server of the operator (Op) or from an application server (APPS). 
     
     
         11 . The client device according to  claim 9  characterized in that the service key (SK) includes a content package key (Kp), the license (L) comprising the content package key (Kp) encrypted with the unique device derived key ( UO K DER Gen ) and a content key (CK) encrypted with the content package key (Kp), the client device (DEV) being configured to decrypt the content package key (Kp) with the calculated unique device derived key ( UO K DER Gen ), and the content key (CK) with the content package key (Kp) previously decrypted.

Join the waitlist — get patent alerts

Track US2019020933A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.