A system and method for retrieval and transfer of encrypted content from a
failed set-top box. When content is recorded to the storage device of a
set-top box, the content is encrypted with a content instance key. This
content instance key is encrypted with the public key of the set-top box
and a duplicate of the content instance key is encrypted by another
public key other than the public key of the set-top. In the event the
set-top fails, the encrypted content on the storage device may be
retrieved from the storage device by decrypting the duplicate content
instance key with the private key that corresponds with the public key
that encrypted the duplicate of the content instance key.