Data Recording Device Secure Key Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing content data distribution systems face challenges in protecting digital content from unauthorized activities, as encryption methods like double key schemes can be compromised, leading to the creation of clone storage media and unauthorized use of content data.
Innovation Solution
A data recording device and method that employs a memory unit with a controller for secure data communication, using a controller unique key and identification information to encrypt and decrypt a medium device key, and perform authentication/key exchange processes to establish a secure channel for data access, preventing unauthorized access and clone card diffusion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If double key encryption scheme is used to protect content data, then content security is improved, but vulnerability to clone media creation increases
Solution Approach 1:
The encryption system is segmented into multiple independent components: a first encryption key stored securely in the storage medium, a second encryption key stored in the authentication unit, and a certificate authority structure. This segmentation ensures that no single component contains all encryption capabilities, preventing clone media creation even if one component is compromised.
Solution Approach 2:
A certificate authority acts as an intermediary between the storage medium and the reproduction device. The certificate authority issues certificates that bind the first key and second key together in a trusted manner, enabling secure content distribution without requiring direct access to both keys simultaneously, thus preventing unauthorized cloning.
2Ease of operation
If encryption keys are stored in storage medium to enable content access, then content accessibility is improved, but risk of unauthorized access increases
Solution Approach 1:
Encryption keys are segmented and stored in separate secure locations: the first key is stored in the storage medium's authentication unit in a protected manner, while the second key is stored in the reproduction device's authentication unit. This segmentation allows legitimate access while preventing unauthorized access, as both keys are required together for decryption.
Solution Approach 2:
Authentication and key verification are performed preliminarily before content access is granted. The reproduction device's authentication unit verifies the first key and second key relationship through certificate validation before enabling content reproduction, ensuring that only authorized devices can access the content.
3Reliability
If authentication mechanisms are implemented to prevent clone cards, then security against clone media is improved, but device complexity increases
Solution Approach 1:
Instead of storing sensitive key material directly, the system uses certificate copies that contain only the necessary verification information. The authentication unit stores and verifies certificate copies that prove the relationship between keys without exposing the keys themselves, simplifying the authentication mechanism while maintaining security against clone cards.
Data Source
AI summary
A controller is provided with a controller key and a first controller identification information unique to the controller. The controller generates a controller unique key unique to a respective controller based on the controller key and the first controller identification information, and a second controller identification information based on the first controller identification information. A decryptor decrypts the encrypted medium device key using the controller unique key to obtain a medium device key. An authentication/key exchange process unit performs authentication/key exchange process with the host device through an interface unit using the medium device key, the medium device key certificate and the second controller identification information to establish a secure channel.


