Recipient-Encrypted Session Key for HDCP Key Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for protecting HDCP device key sets during the manufacturing process are costly, complex, and vulnerable to attacks, requiring large amounts of on-chip NVM and involving high circuit complexity, which increases device costs and risks of key compromise.
Innovation Solution
A method using recipient-encrypted session key cryptography, where the recipient generates and encrypts a session key with its private key, sending both encrypted and unencrypted keys to the sender, allowing secure encryption and decryption of HDCP device key sets without storing multiple keys on-chip, thus reducing NVM requirements and device costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional methods are used to protect HDCP device key sets during manufacturing, then key security is maintained, but device cost increases and circuit complexity increases
Solution Approach 1:
The patent extracts the key protection function from complex on-chip storage systems and implements it through external encryption mechanisms. The HDCP device key sets are encrypted using a content-encryption key before being stored in standard NVM, separating the security function from the storage function and reducing circuit complexity while maintaining security.
Solution Approach 2:
The patent introduces a content-encryption key as an intermediary between the key licensing authority and the HDCP device key sets. This intermediary encrypts the device key sets during manufacturing and storage, providing security without requiring complex on-chip key management circuits, thus resolving the contradiction between security and complexity.
2Reliability
If conventional methods are used to protect HDCP device key sets during manufacturing, then key security is maintained, but on-chip NVM requirements increase
Solution Approach 1:
The patent extracts the encryption function from the on-chip storage system and implements it externally during manufacturing. The content-encryption key is applied to encrypt HDCP device key sets before storage in standard NVM, providing security without requiring large on-chip NVM capacity, thus resolving the contradiction between security and storage requirements.
3Reliability
If conventional methods are used to protect HDCP device key sets, then key protection is achieved, but device cost increases
Solution Approach 1:
The patent uses a disposable content-encryption key that is applied during manufacturing and then discarded or replaced. This approach provides adequate key protection during the critical manufacturing and storage phases without requiring expensive on-chip cryptographic hardware, thus resolving the contradiction between protection and cost.
Solution Approach 2:
The patent introduces a content-encryption key as an intermediary that enables affordable key protection. This intermediary encrypts the HDCP device key sets during manufacturing using standard encryption algorithms, providing security without requiring complex or expensive on-chip key management systems, thus reducing device cost while maintaining protection.
4Adaptability or versatility
If multiple keys are stored on-chip for renewability, then key renewability is supported, but device complexity and cost increase
Solution Approach 1:
The patent applies preliminary encryption action during manufacturing by encrypting the HDCP device key sets with a content-encryption key before storage. This preliminary action enables future key renewability without requiring multiple keys to be stored on-chip, as the encrypted key sets can be replaced and re-decrypted using new content-encryption keys, thus supporting renewability without increasing circuit complexity.
Data Source
AI summary
A method for protecting secret keys, such as HDCP device key sets, during the manufacturing process is disclosed. In particular, the present invention comprises a method for securely sending and receiving data, such as HDCP device key sets, for use in a cryptosystem. In operation, a first party, referred to as a sender (107) is to send original data (106) to a second party, referred to as a recipient (100). To facilitate the secure transmission, the recipient (100) randomly generates (101) a session key (102) and encrypts it with its private key-encryption key (103). The recipient then securely sends both the encrypted and unencrypted session keys to the sender. The sender (107) then encrypts the original data (106) using the unencrypted session key (102) and includes the encrypted data (108) along with the encrypted session key (104) to the recipient (100). The recipient (100) then decrypts the encrypted session key (104) using the private key-encryption key (103) and then decrypts the original data (106).


