IP Library Granted Patent US 11,785,315
Granted Patent B2
US 11,785,315 · App. 17/958,970 · Granted Oct 10, 2023

Secure provisioning, by a client device, cryptographic keys for exploiting services provided by an operator

Inventors: Yann Bieber (Cheseaux-sur-Lausanne, CH); André Nicoulin (Cheseaux-sur-Lausanne, CH)
Assignee: NAGRAVISION SÀRL
H04N21/835H04L9/083H04L9/088H04L9/0819H04L9/0822H04L9/0825H04L9/14H04L9/16H04N7/1675H04N21/4405H04N21/63345
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,785,315
App. No.
17/958,970
Granted
Oct 10, 2023
Kind
B2
Abstract

A method for securely receiving a multimedia content by a client device operated by one or more operator(s) involving a dedicated provisioning server of a security provider managing symmetric secrets used by the client devices and operators license servers. The provisioning server provides to the client device one or more generations of operator specific unique device secrets, which are then exploited by the various operators' license servers to deliver licenses such that authorized client devices can consume protected multimedia contents.

Claims (61)

1. A method of descrambling a scrambled service, comprising:

transmitting, by a client device, a first challenge to an operator server, the first challenge including at least a certificate corresponding to the client device;

receiving, by the client device in response to the first challenge, a license from the operator server, the license including at least a service key encrypted with a unique device-derived key;

determining, by the client device, the unique device-derived key by applying a predetermined algorithm on a global operator seed and a unique device key corresponding to the client device;

decrypting, by the client device, the service key with the determined unique device-derived key;

receiving and descrambling, by the client device, the scrambled service using the service key; and

extracting, by the client device, the global operator seed from a global operator vault.

2. The method according to claim 1 , further comprising:

prior to transmitting the first challenge,

downloading, by the client device from the operator server, the global operator vault that stores the global operator seed;

transmitting a second challenge, by the client device to the operator server, the second challenge including at least a unique identifier of the client device and an identifier of the operator server; and

receiving, by the client device in response to the second challenge, the certificate corresponding to the client device.

3. The method according to claim 1 , wherein to extract the global operator seed from the global operator vault, the method further comprises decrypting the global operator vault with a global operator vault key received from the operator server by the client device with the certificate corresponding to the client device.

4. The method according to claim 2 , wherein the global operator vault is stored in non-volatile memory in the client device.

5. The method according to claim 2 , wherein the global operator vault stores a plurality of global operator seeds corresponding to a plurality of cryptographic generations.

6. The method according to claim 5 , further comprising changing a cryptographic generation (1) if a current global operator seed is compromised, or (2) periodically.

7. The method according to claim 1 , wherein the service key includes a content package key encrypted with the unique device-derived key, and a content key encrypted with the content package key.

8. The method according to claim 7 , further comprising:

decrypting, by the client device, the content package key with the unique device-derived key; and

decrypting, by the client device, the content key with the content package key after the content package key is decrypted.

9. A client device that descrambles a scrambled service, the client device comprising:

circuitry configured to

transmit a first challenge to an operator server, the first challenge including at least a certificate corresponding to the client device;

receive, in response to the first challenge, a license from the operator server, the license including at least a service key encrypted with a unique device-derived key;

determine the unique device-derived key by applying a predetermined algorithm on a global operator seed and a unique device key corresponding to the client device;

decrypt the service key with the determined unique device-derived key;

receive and descramble the scrambled service using the service key; and

extract the global operator seed from a global operator vault.

10. A method of descrambling a scrambled service, comprising:

receiving, by an operator server, a first challenge from a client device, the first challenge including at least an identifier of the client device and an identifier of the operator server;

determining entitlement of the client device to descramble the scrambled service;

when the client device is entitled to descramble the scrambled service determining, by the operator server, a device-derived key by applying a predetermined algorithm to a unique device key corresponding to the client device and a global operator seed corresponding to the operator server;

forming, by the operator server, a unique cryptogram by encrypting the device-derived key with the global operator seed;

transmitting, from the operator server to the client device, a certificate corresponding to the client device, the certificate including the unique cryptogram;

receiving, by the operator server, a second challenge from the client device, the second challenge including at least the certificate corresponding to the client device; and

providing, from the operator server to the client device in response to the second challenge, a license from the operator server, the license including at least a service key encrypted with the device-derived key,

wherein the client device uses the service key in the license to descramble the scrambled service.

11. The method according to claim 10 , further comprising:

providing, from the operator server to the client device, a global operator vault including the global operator seed.

12. The method according to claim 11 , further comprising:

providing, from the operator server to the client device, a plurality of unique cryptograms corresponding to a plurality of encryption generations,

wherein the global operator vault includes a plurality of global operator seeds corresponding to the plurality of encryption generations.

13. The method according to claim 12 , further comprising:

changing a current encryption generation (1) if a current global operator seed is compromised, or (2) periodically.

14. The method according to claim 11 , wherein the global operator vault is encrypted with a global operator vault key.

15. The method according to claim 14 , further comprising transmitting, by the operator server, the global operator vault key to the client device at a time when the certificate corresponding to the client device is transmitted.

16. The method according to claim 10 , wherein the service key includes a content package key encrypted with the device-derived key, and a content key encrypted with the content package key.

17. An operator server, comprising:

circuitry configured to

receive a first challenge from a client device, the first challenge including at least an identifier of the client device and an identifier of the operator server;

determine entitlement of the client device to descramble the scrambled service;

when the client device is entitled to descramble the scrambled service, determine a device-derived key by applying a predetermined algorithm to a unique device key corresponding to the client device and a global operator seed corresponding to the operator server;

form a unique cryptogram by encrypting the device-derived key with the global operator seed;

transmit, to the client device, a certificate corresponding to the client device, the certificate including the unique cryptogram;

receive a second challenge from the client device, the second challenge including at least the certificate corresponding to the client device; and

provide, to the client device in response to the second challenge, a license from the operator server, the license including at least a service key encrypted with the device-derived key,

wherein the client device uses the service key in the license to descramble the scrambled service.

18. An operator server according to claim 17 , wherein the circuitry is further configured to:

provide, to the client device, a plurality of unique cryptograms corresponding to a plurality of encryption generations,

wherein the global operator vault includes a plurality of global operator seeds corresponding to the plurality of encryption generations.

19. The operator server according to claim 18 , wherein the circuitry is further configured to change a current encryption generation (1) if a current global operator seed is compromised, or (2) periodically.

Assignments (2)
CHANGE OF NAME Recorded May 8, 2023
From: NAGRAVISION SA
To: NAGRAVISION SÀRL
Reel/Frame 063566/0842 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2023
From: BIEBER, YANN; NICOULIN, ANDRE
To: NAGRAVISION S.A.
Reel/Frame 063405/0385 →
Priority Claims (1)
EP 15202609 · Dec 23, 2015 · regional
Continuity (3)
Continuation 17012440 · Sep 4, 2020
Continuation 16073752
Related Publication 20230033476A1 · Feb 2, 2023