In a multimedia recording and playback network for receiving from a
content server a service package of multimedia content, the network
including a media server in communication with the content server, a
method of securely transmitting a master encryption key from the content
server to the media server, including the steps downloading a service
package certificate from the content server to the media server,
authenticating, in the media server, the received service package
certificate, the content server providing to the media server a key
server certificate, a public key of the content server, and a client
certificate request, the media server authenticating the key server
certificate, providing to the content server, upon authentication of the
key server certificate by the media server, a client certificate
including a challenge signature, and a public key of the media server,
the content server authenticating the client certificate including the
challenge signature received from the media server, the media server
requesting the master encryption key from the content server, and the
content server responding by transmitting the master encryption key to
media server.