Method for pairing a content provider system and a receiving device, corresponding computer program product and devices
A method for pairing a content provider system and a receiving device, a cryptographic function and a receiving device unique identifier being populated in the receiving device. According to such method, the receiving device executes: obtaining a first key which is a result of a first function taking as arguments an Identity Based Encryption scheme master key owned by an authority server and an output of the cryptographic function applied to the receiving device unique identifier; receiving, from the content provider system, a content provider unique identifier; and computing a secret key which is a result of a second function taking as operands the first key and an output of the cryptographic function applied to the content provider unique identifier, the secret key being known from the content provider system.
1 . A method for pairing a content provider system and a receiving device intended to receive content data from said content provider system through a first communications network, an authority server being communicatively connected to the receiving device and to the content provider system through a second communications network, a cryptographic function and a receiving device unique identifier being populated in the receiving device, comprising, by processing circuitry of the receiving device:
obtaining a first key which is a result of a first function implementing a user secret key generation, the first function taking as arguments, an Identity Based Encryption scheme master key owned by the authority server and an output of the cryptographic function applied to the receiving device unique identifier;
receiving, from the content provider system, a content provider unique identifier;
computing a secret key which is a result of a second function taking as operands, the first key and an output of the cryptographic function applied to the content provider unique identifier, the secret key being known by the content provider system; and
pairing the content provider system and the receiving device based on the secret key being known by the content provider system.
2 . The method according to claim 1 , wherein the second function taking as operands:
the first key, and
an output of the cryptographic function applied to the content provider unique identifier,
delivers a same result as the second function taking as operands:
a second key which is a result of the first function taking as arguments, the master key and, an output of the cryptographic function applied to the content provider unique identifier, and
an output of the cryptographic function applied to the receiving device unique identifier.
3 . The method according to claim 1 , wherein said obtaining a first key further comprises receiving the first key from the authority server.
4 . The method according to claim 1 , wherein a public key known by the authority server is populated in the receiving device,
wherein said obtaining a first key further comprises:
generating a random number;
encrypting the random number using the authority server public key;
sending, to the authority server, the encrypted random number;
receiving, from the authority server, a partial key corresponding to a result of a third function taking as an argument:
a difference between the first key and a value which is a result of a predefined function of said random number and of said receiving device unique identifier, and
said output of the cryptographic function applied to the receiving device unique identifier, and
wherein a structure of said third function and of said predefined function is known from the receiving device.
5 . A method for pairing a content provider system and a receiving device intended to receive content data from said content provider system through a first communications network, an authority server being communicatively connected to the receiving device and to the content provider system through a second communications network, a cryptographic function and a content provider unique identifier being populated in the content provider system, comprising, by processing circuitry of the content provider system:
receiving, from the authority server, a second key which is a result of a first function implementing a user secret key generation, the first function taking as arguments, an Identity Based Encryption scheme master key owned by the authority server and an output of the cryptographic function applied to the content provider unique identifier;
receiving, from the receiving device, a receiving device unique identifier;
computing a secret key which is a result of a second function taking as operands, the second key and an output of the cryptographic function applied to the receiving device unique identifier, the secret key being known by the receiving device; and
pairing the content provider system and the receiving device based on the secret key being known by the content provider system.
6 . The method according to claim 5 , wherein the second function taking as operands:
the second key, and
an output of the cryptographic function applied to the receiving device unique identifier,
delivers a same result as the second function taking as operands:
a first key which is a result of the first function taking as arguments, the master key and, an output of the cryptographic function applied to the receiving device unique identifier, and
an output of the cryptographic function applied to the content provider unique identifier.
7 . The method according to claim 5 , further comprising, before executing said receiving from the authority server the second key by the content provider system:
sending, to the authority server, the content provider unique identifier.
8 . The method according to claim 1 , wherein said first function implements elliptic curve scalar point multiplication between said arguments, said output of said cryptographic function being a point on an elliptic curve.
9 . The method according to claim 1 , wherein said second function implements bilinear pairing between said operands.
10 . The method according to claim 1 , wherein said first communications network is a bidirectional communications network.
11 . The method according to claim 1 , wherein said first communications network and said second communications network are a same network.
12 . The method according to claim 1 , wherein said receiving the receiving device unique identifier or the content provider unique identifier further comprises receiving the receiving device unique identifier or the content provider unique identifier through a secured communication channel.
13 . A non-transitory computer readable medium having stored thereon program code instructions for implementing the method according to claim 1 .
14 . An electronic device for pairing a content provider system and a receiving device intended to receive content data from said content provider system through a first communications network, an authority server being communicatively connected to the receiving device and to the content provider system through a second communications network, a cryptographic function and a receiving device unique identifier being populated in the electronic device, the electronic device comprising:
processing circuitry or a dedicated computing machine configured to, when the electronic device is implemented in the receiving device:
obtain a first key which is a result of a first function implementing a user secret key generation, the first function taking as arguments, an Identity Based Encryption scheme master key owned by the authority server and an output of the cryptographic function applied to the receiving device unique identifier;
obtain, from the content provider system, a content provider unique identifier;
compute a secret key which is a result of a second function taking as operands, the first key and an output of the cryptographic function applied to the content provider unique identifier, the secret key being known by the content provider system; and
pair the content provider system and the receiving device based on the secret key being known by the content provider system.
15 . An electronic device for pairing a content provider system and a receiving device intended to receive content data from said content provider system through a first communications network, an authority server being communicatively connected to the receiving device and to the content provider system through a second communications network, a cryptographic function and a content provider unique identifier being populated in the electronic device, the electronic device comprising:
processing circuitry or a dedicated computing machine configured to, when the electronic device is implemented in the content provider system:
receive, from the authority server, a second key which is a result of a first function implementing a user secret key generation, the first function taking as arguments, an Identity Based Encryption scheme master key owned by the authority server and an output of the cryptographic function applied to the content provider unique identifier;
receive, from the receiving device, a receiving device unique identifier; and
compute a secret key which is a result of a second function taking as operands, the second key and an output of the cryptographic function applied to the receiving device unique identifier, the secret key being known by the receiving device; and
pair the content provider system and the receiving device based on the secret key being known by the content provider system.
16 . The method according to claim 2 , wherein said obtaining a first key further comprises receiving the first key from the authority server.
17 . The method according to claim 2 , wherein a public key known by the authority server is populated in the receiving device,
wherein said obtaining a first key further comprises:
generating a random number;
encrypting the random number using the authority server public key;
sending, to the authority server, the encrypted random number;
receiving, from the authority server, a partial key corresponding to a result of a third function taking as an argument:
a difference between the first key and a value which is a result of a predefined function of said random number and of said receiving device unique identifier, and
said output of the cryptographic function applied to the receiving device unique identifier, and
wherein a structure of said third function and of said predefined function is known from the receiving device.
18 . The method according to claim 6 , further comprising, before executing said receiving from the authority server the second key by the content provider system:
sending, to the authority server, the content provider unique identifier.
19 . The method according to claim 5 , wherein said first function implements elliptic curve scalar point multiplication between said arguments, said output of said cryptographic function being a point on an elliptic curve.