If I understand what you describe correctly, Samsung are using a DRM key to ensure you only use ringtones downloaded (and paid for) from a supplier they approve (and from whom they presumably get a cut).
If that's the case, you would need an approved key with which to sign the packages yourself, and obviously Samsung and its business partners will not give you that for commercial reasons.
I would be wary of using any application (especially Windows) which claimed to be able to circumvent this, as it would either contain an unlawfully obtained copy of the key (and therefore put you on the wrong side of the law), or be a trojan which installed malware on your computer while pretending to do the job.