US2006031873A1PendingUtilityA1

System and method for reduced hierarchy key management

Assignee: COMCAST CABLE HOLDINGS LLCPriority: Aug 9, 2004Filed: Aug 9, 2004Published: Feb 9, 2006
Est. expiryAug 9, 2024(expired)· nominal 20-yr term from priority
H04L 9/0897H04N 7/17309H04N 21/26613H04L 9/0836H04N 7/1675H04N 7/162H04N 21/2347H04N 21/4623H04L 2209/60H04N 21/4405H04N 21/835
49
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A controller for managing media stream decryption keys includes a media decryption engine, a table, and a content key list. The media decryption engine receives an encrypted media stream from a headend and presents a decrypted media stream to a receiving device in response to a decryption key, wherein the decryption key is a function of a content key. The table contains a content key index and a plurality of corresponding content keys. Content keys that correspond to a particular encrypted media stream are selected from the content key list using an index from the content key table, and that is referenced by an identifier received from a headend in connection with the encrypted media stream.

Claims

exact text as granted — not AI-modified
1 . A controller for managing media stream decryption keys, the controller comprising: 
 a media decryption engine that receives an encrypted media stream from a headend and presents a decrypted media stream to a receiving device in response to a decryption key, wherein the decryption key is a function of a content key;    a table containing a content key index and a plurality of corresponding content keys; and    a content key list, wherein content keys that correspond to a particular encrypted media stream are selected from the content key list using an index from a content key table that is referenced by an identifier received from a headend in connection with the encrypted media stream.    
   
   
       2 . The controller of  claim 1  wherein the decryption key is a working key that is changed periodically.  
   
   
       3 . The controller of  claim 1  wherein the list of the content keys and the key index are loaded into the controller from the headend.  
   
   
       4 . The controller of  claim 1  further comprising a combiner configured to receive the selected content key and a working key modifier, and generate the decryption key in response to the selected content key and the working key modifier.  
   
   
       5 . The controller of  claim 4  wherein the identifier is a program identifier in the media stream.  
   
   
       6 . The controller of  claim 4  wherein the combiner generates the decryption key using at least one of an exclusive OR (EXOR) and a hashing operator.  
   
   
       7 . The controller of  claim 1  wherein the identifier is a video on demand identifier and the table further contains video on demand epochs related to respective content keys, and the decryption keys are further presented in response to a respective video on demand epoch that is selected when the content key is selected.  
   
   
       8 . The controller of  claim 3  wherein entitlement management message (EMM) updates that are downloaded from the headend to the controller are used solely to deliver entitlements after a first list of the content key tables is sent, and the index table is updated in lieu of sending new keys for each new EMM.  
   
   
       9 . The controller of  claim 1  wherein the index further comprises initialization vector (IV) values and the content key list contains IVs, wherein content keys and IVs that correspond to a particular encrypted media stream are selected from the content key and IV list using the index from a content key and IV table that is referenced by the identifier that is received from the headend in connection with the encrypted media stream.  
   
   
       10 . The controller of  claim 1  further comprising at least one hash operator configured to provide a one-way hash operation to at least one of the index, the content key, and the decryption key.  
   
   
       11 . A method of managing media stream decryption keys, the method comprising: 
 receiving an encrypted media stream from a headend and presenting a decrypted media stream to a receiving device in response to a decryption key using a media decryption engine, wherein the decryption key is a function of a content key;    storing a content key index and a plurality of corresponding content keys in a table; and    selecting content keys that correspond to a particular encrypted media stream from a content key list using an index in the content key table that is referenced by an identifier received from the headend in connection with the encrypted media stream.    
   
   
       12 . The method of  claim 11  wherein the decryption key is a working key that is changed periodically.  
   
   
       13 . The method of  claim 11  further comprising loading the list of the content keys and the key index into the controller from the headend.  
   
   
       14 . The method of  claim 11  further comprising receiving the selected content key and a working key modifier, and generating the decryption key in response to the selected content key and the working key modifier using a combiner in the controller.  
   
   
       15 . The method of  claim 14  wherein the identifier is a program identifier in the media stream.  
   
   
       16 . The method of  claim 12  generating the decryption key using at least one of an exclusive OR (EXOR) and a hashing operator via the combiner.  
   
   
       15 . The method of  claim 11  wherein the identifier is a video on demand identifier and the table further contains video on demand epochs related to respective content keys, and the decryption keys are further presented in response to a respective video on demand epoch that is selected when the content key is selected.  
   
   
       17 . The method of  claim 11  further comprising downloading entitlement management message (EMM) updates from the headend to the controller solely to deliver entitlements after a first list of the content key tables is sent, and updating the index table in lieu of sending new keys for each new EMM.  
   
   
       18 . The method of  claim 11  wherein the index further comprises initialization vector (IV) values and the content key list contains IVs, wherein content keys and IVs that correspond to a particular encrypted media stream are selected from the content key and IV list using the index from a content key and IV table that is referenced by the identifier that is received from the headend in connection with the encrypted media stream when Cipher Block Chaining is used as the mode of a selected algorithm.  
   
   
       19 . The method of  claim 11  further comprising at least one hash operator configured to provide a one-way hash operation to at least one of the index, the content key, and the decryption key.  
   
   
       20 . A system for distribution, reception and display of media streams, the system comprising: 
 a headend configured to generate and present at least one encrypted media stream;    a media decryption engine that receives the at least one encrypted media stream and presents a decrypted media stream in response to a decryption key, wherein the decryption key is a function of a content key; and    a table containing a content key index and a plurality of corresponding content keys, wherein content keys that correspond to a particular encrypted media stream are selected from the content key table using an entry in the content key index that is referenced by an identifier that is received from the headend in connection with the encrypted media stream.    
   
   
       21 . The system of  claim 20  further comprising a network configured to receive the at least one encrypted media stream and present the at least one encrypted media stream to at least one of a set top box (STB) and a receiving device that include the media decryption engine and the table.

Join the waitlist — get patent alerts

Track US2006031873A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.