A method for use in a distribution system having a key management center,
a distribution station and a reception terminal. The method updates a
pair of distribution keys unique to the reception terminal, where the
distribution public key is used to encrypt distribution data, and the
distribution secret key is used to decrypt encrypted data. In the key
updating method, the reception terminal acquires an update secret key
prior to data distribution, and the key management center acquires an
update public key making a pair with the update secret key, generates a
new pair of distribution keys, encrypts a new distribution secret key by
using the update public key, transmits an encrypted secret key to the
reception terminal and updates to the new distribution public key. The
reception terminal receives the encrypted secret key and restores the new
distribution secret key by decrypting it using the update secret key and
updates to the new distribution secret key.