Encryption Key Generation Using Unique Device and IC Card Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for encrypting and decrypting copyrighted content struggle to limit copying to a specific area and ensure secure transmission, as they often allow unauthorized access and reproduction across different devices.
Innovation Solution
The development of an apparatus that generates unique encryption keys for each device, allowing only authorized machines to decrypt and reproduce content by using a master key stored on a removable medium, ensuring high security and restricting access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a certification key is prestored in an IC card for authentication, then user legitimacy can be confirmed before content download, but the key for encrypted contents may be eavesdropped on during transmission from the contents server to the IC card
Solution Approach 1:
The encryption key management is segmented into multiple components: a certification key for authentication, a machine-unique key generated by the encrypting apparatus, and a final encryption key derived from both. This segmentation allows authentication and encryption functions to be separated, reducing the risk that eavesdropping on one key compromises the entire system.
Solution Approach 2:
The certification key is prestored in the IC card before any content transmission occurs. This preliminary authentication mechanism ensures that only legitimate users can initiate content downloads, and the key transmission happens only after authentication is complete, minimizing exposure time.
2Adaptability or versatility
If DVD recorder/players have common encrypting and decrypting functions for compatibility, then contents information can be reproduced across different machines, but it becomes difficult to limit copying to only one specific home
Solution Approach 1:
Each encrypting apparatus is assigned a unique machine key that is local to that specific device. This local quality ensures that while the apparatus can decrypt content encrypted by other machines (maintaining compatibility), the encryption itself is tailored to the specific machine, preventing unauthorized copying outside the designated home.
Solution Approach 2:
The system uses asymmetric key relationships where the encrypting apparatus generates a machine-unique key that differs from the certification key in the IC card. This asymmetry allows the apparatus to verify authenticity without having direct access to the certification key, and enables controlled distribution of decryption capability within the authorized home.
3Ease of operation
If encryption key information is transmitted from the contents server to the IC card over a network, then the key can be delivered to authorized devices, but the transmission channel is vulnerable to eavesdropping
Solution Approach 1:
The IC card acts as an intermediary that holds the certification key and participates in the key generation process. Instead of directly transmitting the final encryption key from the server to the apparatus, the system uses the IC card as a mediator to authenticate the apparatus and contribute to generating the encryption key, adding a security layer against eavesdropping.
Solution Approach 2:
The encryption key is not transmitted as a static value but is dynamically generated by combining the machine-unique key from the apparatus with information from the IC card. This parameter change approach ensures that even if transmission is intercepted, the key cannot be reused or predicted, as it is specific to each apparatus-IC card pairing.
Data Source
AI summary
In an apparatus for encrypting an information signal into an encryption-resultant signal, a first encryption key peculiar to the present apparatus is generated. Key information is read out from a replaceable recording medium. A decision is made as to whether or not the read-out key information has been generated by an apparatus different from the present apparatus. A second encryption key is generated in response to the read-out key information when it is decided that the read-out key information has been generated by an apparatus different from the present apparatus. One is selected from the first encryption key and the second encryption key as a final encryption key. An information signal is encrypted in response to the final encryption key.


