IP Library Granted Patent US 9,025,765
Granted Patent B2
US 9,025,765 · App. 12/600,068 · Granted May 5, 2015

Data security

Inventors: Wilhelmus Petrus Adrianus Johannus Michiels (Eindhoven, NL); Paulus Mathias Hubertus Mechtildis Antonius Gorissen (Eindhoven, NL); Boris Skoric (Eindhoven, NL)
Assignee: Irdeto B.V.
G06F21/52G06F21/10G06F2221/2107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,025,765
App. No.
12/600,068
Granted
May 5, 2015
Kind
B2
Abstract

A system 100 for increasing data security comprises predetermined system data 104 to be protected. A cryptographic unit 108 is used for cryptographic processing of respective blocks of the content data in dependence on respective keys. A key provider 106 determines the respective key used for the processing of a respective block of the content data in dependence on a respective portion 112 of the predetermined system data 104 , the portion not including all the predetermined system data, wherein different respective portions of the predetermined system data are selected for the respective blocks of content data. A server system 200 for increasing data security comprises an output 202 for providing processed content data 110 to a client system 100 , the client system comprising predetermined system data 104 to be protected. The server system 200 also comprises a cryptographic unit 208 and a key provider 206.

Claims (44)

1. A system for increasing data security by protecting system software, the system comprising:

an input for receiving content data, wherein the content data is configured to be processed;

a memory storing predetermined system data, wherein the predetermined system data is configured to be protected and comprises software code comprising computer executable instructions;

a cryptographic unit for cryptographic processing of respective blocks of the content data based on respective cryptographic keys;

a key provider for selecting a respective portion of the software code for a respective block of the content data such that different respective portions of the software code are selected for the respective blocks of the content data, and determining the respective cryptographic key used for the processing of the respective block of the content data based on the respective portion of the software code, the portion of the software code not including all the software code.

2. The system according to claim 1 , wherein the key provider selects the respective portion of the software code based on the content data outside the respective block of the content data.

3. The system according to claim 2 , wherein the key provider selects the respective portion of the software code based on a ciphertext of the content data outside the respective block of content data.

4. The system according to claim 3 , wherein the key provider selects the respective portion of the software code based on the ciphertext of a previously processed data block.

5. The system according to claim 1 , wherein the cryptographic unit applies an XOR operation involving at least part of the respective key and at least part of the respective block of the content data.

6. The system according to claim 1 , further comprising a storage for storing encrypted content data corresponding to the content data, wherein the cryptographic unit decrypts the encrypted content data.

7. The system according to claim 6 , wherein the cryptographic unit comprises an encrypter for encrypting the respective blocks of the content data based on the respective keys and a decrypter for decrypting respective blocks of the encrypted content data based on the respective keys.

8. The system according to claim 1 , wherein the cryptographic unit applies a digital watermark to the content data based on the respective key.

9. The system of claim 1 , wherein the respective cryptographic key comprises one or more of the respective portion of the software code and a pseudo-random function of the respective portion of the software code.

10. A server system for increasing data security by protecting system software, the system comprising:

an input for receiving content data, wherein the content data is configured to be processed;

an output for transmitting processed content data to a client system, the client system including a memory storing predetermined system data, wherein the predetermined system data is configured to be protected and comprises software code comprising computer executable instructions;

a cryptographic unit for cryptographic processing of respective blocks of the content data based on respective cryptographic keys;

a key provider for selecting a respective portion of the software code for a respective block of the content data such that different respective portions of the software code are selected for the respective blocks of content data, and determining the respective cryptographic key used for the processing of the respective block of the content data based on the respective portion of the software code, the portion of the software code not including all data software code.

11. The server system of claim 10 , wherein the respective cryptographic key comprises one or more of the respective portion of the software code and a pseudo-random function of the respective portion of the software code.

12. A client system for increasing data security by protecting system software, the client system comprising:

an input for receiving content data from a server system, wherein the content data is configured to be processed;

a memory storing predetermined system data, wherein the predetermined system data is configured to be protected and comprises software code comprising computer executable instructions;

a cryptographic unit for cryptographic processing of respective blocks of the content data based on respective cryptographic keys;

a key provider for selecting a respective portion of the software code for a respective block of the content data such that different respective portions of the software code are selected for the respective blocks of content data, wherein the key provider is configured to select the same portion of software code selected by a server key provider on the server system during cryptographic processing of the respective block of the content data on the server system, and determining the respective cryptographic key used for the processing of the respective block of the content data based on the respective portion of the software code, the portion of the software code not including all the software code.

13. The client system of claim 12 , wherein the respective cryptographic key comprises one or more of the respective portion of the software code and a pseudo-random function of the respective portion of the software code. NEW

14. A method executed by one or more computing devices of increasing data security by protecting system software, the method comprising:

receiving, by at least one of the one or more computing devices, content data, wherein the content data is configured to be processed;

cryptographically processing, by at least one of the one or more computing devices, respective blocks of the content data based on respective cryptographic keys;

selecting, by at least one of the one or more computing devices, in the computer a respective portion of software code for a respective block of the content data such that different respective portions of the software code are selected for the respective blocks of the content data; and

determining, by at least one of the one or more computing devices, the respective cryptographic key used for the processing of the respective block of the content data based on the respective portion of the software code, wherein the software code comprises computer executable instructions, the portion of the software code not including all the software code.

15. The method of claim 14 , wherein the respective cryptographic key comprises one or more of the respective portion of the software code and a pseudo-random function of the respective portion of the software code.

16. A method executed by one or more computing devices of increasing data security by protecting system software, the method comprising:

receiving, by at least one of the one or more computing devices, content data, wherein the content data is configured to be processed;

transmitting, by at least one of the one or more computing devices, processed content data to a client system, the client system storing predetermined system data, wherein the predetermined system data is configured to be protected and comprises software code comprising computer executable instructions;

cryptographically processing, by at least one of the one or more computing devices, respective blocks of the content data based on respective cryptographic keys;

selecting, by at least one of the one or more computing devices, a respective portion of software code for a respective block of the content data such that different respective portions of the software code are selected for the respective blocks of the content data; and

determining the respective cryptographic key used for the processing of the respective block of the content data based on the respective portion of the software code, the portion of the software code not including all the software code.

17. The method of claim 16 , wherein the respective cryptographic key comprises one or more of the respective portion of the software code and a pseudo-random function of the respective portion of the software code.

18. At least one non-transitory computer-readable medium storing computer-readable instructions that, when executed by one or more computing devices, cause at least one of the one or more computing devices to:

receive content data, wherein the content data is configured to be processed;

cryptographically process respective blocks of the content data based on respective cryptographic keys;

select a respective portion of software code for a respective block of the content data such that different respective portions of the software code are selected for the respective blocks of the content data; and

determine the respective cryptographic key used for the processing of the respective block of the content data based on the respective portion of the software code, the portion of the software code not including all the software code.

19. The at least one non-transitory computer-readable medium of claim 18 , wherein the respective cryptographic key comprises one or more of the respective portion of the software code and a pseudo-random function of the respective portion of the software code.

Assignments (4)
MERGER Recorded Dec 16, 2014
From: IRDETO CORPORATE B.V.
To: IRDETO B.V.
Reel/Frame 034512/0718 →
CHANGE OF NAME Recorded Sep 4, 2013
From: IRDETO B.V.
To: IRDETO CORPORATE B.V.
Reel/Frame 031156/0553 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2010
From: KONINKLIJKE PHILIPS ELECTRONICS N. V.
To: IRDETO B.V.
Reel/Frame 023985/0760 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 16, 2009
From: MICHIELS, WILHELMUS PETRUS ADRIANUS JOHANNUS; GORISSEN, PAULUS MATHIAS HUBERTUS MECHTILDIS ANTONIUS; SKORIC, BORIS
To: KONINKLIJKE PHILIPS ELECTRONICS N V
Reel/Frame 023520/0062 →
Priority Claims (1)
EP 07108580 · May 22, 2007 · regional
Continuity (1)
Related Publication 20100215173A1 · Aug 26, 2010