A
distribution system and method for distributing digital information is provided, which has high recoverability from a security breach. The
distribution system comprises a
server (200) and a computing device (110). During an enrollment phase, the computing device obtains a first response from an integrated physically unclonable function (150) integrated in the computing device. The
system comprises an enrollment module (130) for determining helper data from a decryption key and the first response to enable later reconstruction of the decryption key from the helper data and a second response obtained from the physically unclonable function. During a reconstruction phase, which occurs after the enrollment phase and typically after a security breach has occurred that revealed data and / or
programming code of the computing device, the
server may encrypt digital information using an
encryption module (220) with a cryptographic
encryption key corresponding to the decryption key. The computing device comprises a decryption module (120) for decrypting the encrypted digital information with the decryption key. The digital information may be used to send an update message to the computing device. Since, the decryption key need only be available at the computing device after the breach, it can recover even if data, such as a cryptographic key, or
programming code of the computing device was revealed, and even if an attacker could eavesdrop on the encrypted digital information.