IP Library Granted Patent US 8,689,340
Granted Patent B2
US 8,689,340 · App. 12/084,852 · Granted Apr 1, 2014

Disk protection system

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,689,340
App. No.
12/084,852
Granted
Apr 1, 2014
Kind
B2
Abstract

A method for protecting content on a medium including a token which implements at least a portion of a keyed function, providing a first encryption method and a first encryption key, inputting each one of a plurality of token inputs to the token and converting an output of the token to a function output, and storing a plurality of ordered pairs each including a function input and the corresponding function output, encrypting the plurality of ordered pairs using the first encryption method and the first encryption key, and storing the encrypted plurality of ordered pairs on the medium. Related apparatus and methods are also described.

Claims (75)

1. A method for producing a medium, the method comprising:

providing a medium comprising a token, the token implementing at least a portion of a keyed function;

providing a secret number k;

providing a function D having an associated inverse function D −1 , such that for inputs x and y, D −1 (x,D(x,y))=y;

receiving at the medium, from externally thereto, a plurality of token inputs, each token input being suitable for input to the token;

for each one of the plurality of token inputs:

inputting the token input to the token and receiving a token output from the token;

transmitting at least the token output to a device external to the medium and performing the following in the device external to the medium:

converting the token output to a function output o, the function output o representing a result of performing the keyed function on a function input corresponding to the token input;

computing D(o,k); and

producing an ordered pair, comprising:

a function input corresponding to the token input; and

D(o,k),

thereby producing a plurality of ordered pairs at the device external to the medium;

providing a first encryption method and a first encryption key; and

the device external to the medium storing the plurality of ordered pairs on the medium, other than in the token; wherein the storing the plurality of ordered pairs on the medium comprises a subprocess selected from a group consisting of:

(a) encrypting each ordered pair at the device external to the medium using the first encryption method and the first encryption key; and the device external to the medium storing each encrypted ordered pair on the medium; and

(b) encrypting the plurality of ordered pairs at the device external to the medium using the first encryption method and the first encryption key, thereby producing an encrypted plurality of ordered pairs; and the device external to the medium storing the encrypted plurality of ordered pairs on the medium.

2. The method according to claim 1 and wherein the secret number k comprises a cryptographic decryption key.

3. The method according to claim 1 and wherein the converting comprises an identity conversion.

4. The method according to claim 1 and wherein each function input is identical to the corresponding token input.

5. The method according to claim 1 and wherein each token input is derived from a corresponding function input.

6. The method according to claim 1 and wherein the plurality of token inputs are produced by performing the following in the device external to the medium:

providing a plurality of function inputs, each function input being suitable for input to the keyed function; and

converting the plurality of function inputs to a plurality of token inputs.

7. The method according to claim 1 wherein at least one of the ordered pairs is stored in a medium content area.

8. The method according to claim 1 , wherein the storing the plurality of ordered pairs on the medium comprises:

encrypting each ordered pair at the device external to the medium using the first encryption method and the first encryption key; and

the device external to the medium storing each encrypted ordered pair on the medium.

9. The method according to claim 1 , wherein the storing the plurality of ordered pairs on the medium comprises:

encrypting the plurality of ordered pairs at the device external to the medium using the first encryption method and the first encryption key, thereby producing an encrypted plurality of ordered pairs; and

the device external to the medium storing the encrypted plurality of ordered pairs on the medium.

10. The method according to claim 9 and wherein the converting comprises an identity conversion.

11. The method according to claim 9 and wherein each function input is identical to the corresponding token input.

12. The method according to claim 9 and wherein each token input is derived from a corresponding function input.

13. The method according to claim 9 and wherein the plurality of token inputs are produced by performing the following in the device external to the medium:

providing a plurality of function inputs, each function input being suitable for input to the keyed function; and

converting the plurality of function inputs to a plurality of token inputs.

14. The method according to claim 9 and wherein the encrypted plurality of ordered pairs is stored in a medium content area.

15. The method according to claim 9 and wherein the encrypted plurality of ordered pairs is stored in a medium control area.

16. The method according to claim 1 and also comprising:

encrypting content in accordance with a second encryption method and the secret number k, thereby producing encrypted content; and

storing the encrypted content on the medium.

17. The method according to claim 16 and wherein the first encryption method and the second encryption method are identical.

18. The method according to claim 16 and wherein the first encryption method is different from the second encryption method.

19. A medium for storing content, the medium comprising a physical storage device, the medium comprising:

a content storage area;

an ordered pair storage area; and

a token, the token implementing at least a portion of a keyed function and being operative to receive, from externally to the medium, a plurality of token inputs and produce a plurality of token outputs,

wherein the ordered pair storage area stores a plurality of ordered pairs, and

the ordered pair storage area does not comprise the token, and

the ordered pairs are produced by performing the following:

providing a secret number k;

providing a function D having an associated inverse function D −1 , such that for inputs x and y, D −1 (x,D(x,y))=y;

receiving at the medium, from externally thereto, a plurality of token inputs, each token input being suitable for input to the token;

for each one of the plurality of token inputs:

inputting the token input to the token and receiving a token output from the token;

transmitting at least the token output to a device external to the medium and performing the following in the device external to the medium:

converting the token output to a function output o, the function output o representing a result of performing the keyed function on a function input corresponding to the token input;

computing D(o,k); and

producing an ordered pair, comprising:

 a function input corresponding to the token input; and

 D(o,k), and

the ordered pairs are received, from the device external to the medium, at the medium for storage thereon; wherein a first encryption method and a first encryption key are provided, and wherein the storing the plurality of ordered pairs on the medium comprises a subprocess selected from a group consisting of:

(a) encrypting each ordered pair at the device external to the medium using the first encryption method and the first encryption key; and the device external to the medium storing each encrypted ordered pair on the medium; and

(b) encrypting the plurality of ordered pairs at the device external to the medium using the first encryption method and the first encryption key, thereby producing an encrypted plurality of ordered pairs; and the device external to the medium storing the encrypted plurality of ordered pairs on the medium.

20. The medium according to claim 19 and wherein at least part of the ordered pair storage area is interleaved with the content storage area.

21. The medium according to claim 19 and wherein each ordered pair is separately encrypted.

22. The medium according to claim 19 and wherein the plurality of ordered pairs is encrypted as a unit.

23. The medium according to claim 19 and wherein the content storage area stores content.

24. The medium according to claim 23 and wherein the content is encrypted in accordance with an encryption method and the secret number k.

25. The medium according to claim 19 and wherein the token is adapted to receive an analog token input and produce an analog token output, and the medium also comprises:

a digital-to-analog input unit receiving a plurality of digital inputs and converting each of the plurality of digital inputs to an analog form suitable for input to the token; and

an analog-to-digital output unit receiving the plurality of analog outputs from the token and converting each of the plurality of analog outputs into digital form to produce a plurality of digital outputs.

26. The medium according to claim 19 and wherein the token is adapted to receive a digital input and produce a digital output.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 22, 2013
From: NDS LIMITED
To: CISCO TECHNOLOGY, INC.
Reel/Frame 030258/0465 →
RELEASE OF PATENT SECURITY INTERESTS Recorded Mar 29, 2011
From: J.P.MORGAN EUROPE LIMITED
To: NDS LIMITED; NEWS DATACOM LIMITED
Reel/Frame 026042/0124 →
RELEASE OF INTELLECTUAL PROPERTY SECURITY INTERESTS Recorded Mar 11, 2011
From: NDS HOLDCO, INC.
To: NDS LIMITED; NEWS DATACOM LIMITED
Reel/Frame 025940/0710 →
SECURITY AGREEMENT Recorded May 18, 2009
From: NDS LIMITED; NEWS DATACOM LIMITED
To: NDS HOLDCO, INC.
Reel/Frame 022703/0071 →
SECURITY AGREEMENT Recorded May 14, 2009
From: NDS LIMITED; NEWS DATACOM LIMITED
To: J.P. MORGAN EUROPE LIMITED
Reel/Frame 022678/0712 →