System and Method for Security Key Transmission With Strong Pairing to Destination Client
Systems and methods for security key transmission with strong pairing to a destination client are disclosed. A security key may be generated by an on-chip key generator, an off-chip device, and/or software. A rule may then be paired with the security key and an address associated with the security key. The rule may define permissible usage by a destination module, which is defined by the associated address. The rule may comprise a command word, which may be implemented using a data structure associated with a permissible algorithm type, a security key size, and/or a security key source.
1 - 34 . (canceled)
35 . An integrated circuit comprising:
a security client configured to receive a security key sequence comprising a security key and a security command; and
a key serializer configured to generate the security key sequence and transmit the security key sequence to the security client.
36 . The integrated circuit of claim 35 , further comprising:
a key generator configured to generate the security key,
wherein the key generator and the key serializer are disposed within a security boundary.
37 . The integrated circuit of claim 35 , wherein the key serializer is disposed within a security boundary, and the security client is disposed outside the security boundary.
38 . The integrated circuit of claim 35 , wherein the key serializer is disposed within a security boundary, and the security client is disposed inside the security boundary.
39 . The integrated circuit of claim 35 , wherein the security command comprises an algorithm associated with the security key, and the security client is further configured to compare the algorithm to an algorithm configuration.
40 . The integrated circuit of claim 39 , wherein the security client is further configured to produce an error message in response to the algorithm being different than the algorithm configuration.
41 . The integrated circuit of claim 35 , wherein the security key sequence further comprises an address associated with the security client.
42 . The integrated circuit of claim 35 , wherein the security client comprises a destination module, and the security key sequence further comprises an address associated with the destination module.
43 . The integrated circuit of claim 35 , wherein the security command comprises permissible usage by the security client.
44 . The integrated circuit of claim 35 , wherein the security command comprises a security key size.
45 . The integrated circuit of claim 35 , wherein the security command comprises a security key source.
46 . The integrated circuit of claim 35 , wherein the security command indicates whether the security client is authorized to use the security key.
47 . A method for security key transmission within an integrated circuit, the method comprising:
generating, by a key serializer disposed on the integrated circuit, a security key sequence comprising a security key and a security command;
transmitting, by the key serializer, the security key sequence to a security client disposed on the integrated circuit; and
receiving, by the security client, the security key sequence.
48 . The method of claim 47 , further comprising:
recovering, by a de-serializer of the security client, the security key and the security command from the security key sequence.
49 . The method of claim 47 , further comprising:
comparing, by the security client, an algorithm of the security command with an algorithm configuration; and
generating, by the security client, an error message in response to the algorithm being different than the algorithm configuration.
50 . The method of claim 47 , further comprising:
generating, by a key generator, the security key.
51 . A set-top box comprising:
an integrated circuit comprising:
a security client configured to receive a security key sequence comprising a security key and a security command; and
a key serializer configured to generate the security key sequence and transmit the security key sequence to the security client.
52 . The set-top box of claim 51 , wherein the security client is further configured to decrypt data received from a content provider.
53 . The set-top box of claim 51 , wherein the security command comprises an algorithm associated with the security key, and the security client is further configured to compare the algorithm to an algorithm configuration.
54 . The set-top box of claim 53 , wherein the security client is further configured to produce an error message in response to the algorithm being different than the algorithm configuration.