Access Control Device Using Time Stamp Duration Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for controlling access to encrypted data in Pay-TV systems, such as those described in European Patent Application EP 1 575 293 and US 2004/0215691, require a channel identifier for each control message, which is not feasible in configurations where control messages do not contain such identifiers, particularly when channels are grouped by class, leading to inability to prevent fraudulent use of security modules by multiple decoders.
Innovation Solution
A method and device that increment or decrement an error counter based on the time duration between consecutive control messages, allowing for detection of fraudulent use without requiring a channel identifier, by comparing time stamps and cryptoperiods to determine if control messages are sent according to conventional or fraudulent use, enabling measures like service interruption or module locking.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If channel identifiers are required for each control message to detect fraudulent use, then security against sharing is improved, but device complexity and ease of operation deteriorate due to the need for identifier management and comparison
Solution Approach 1:
The patent changes the detection parameter from channel identifiers to time intervals between control messages. Instead of comparing channel IDs, the system measures the time duration between consecutive control messages and compares it to a predefined threshold. This parameter change simplifies the detection mechanism while maintaining security effectiveness.
Solution Approach 2:
The patent extracts the time stamp information from control messages and uses it as the sole basis for detection, removing the need for channel identifier comparison. By focusing only on the time interval between messages, the system eliminates the complexity of managing and comparing channel identifiers while still detecting fraudulent sharing behavior.
2Measurement precision
If channel identifiers are used to distinguish legitimate channel changes from fraudulent sharing, then detection accuracy is improved, but ease of operation worsens due to inability to handle class-grouped channels without identifiers
Solution Approach 1:
The patent changes the detection approach from identifier-based to time-based measurement. By measuring the time interval between control messages and comparing it to the cryptoperiod duration, the system achieves detection accuracy without requiring channel identifiers. This makes the system easier to operate, especially in configurations where channels are grouped by class without individual identifiers.
Solution Approach 2:
The system uses the inherent time stamp information already present in control messages to perform self-detection of fraudulent use. The time interval between messages automatically reveals whether legitimate channel changes or fraudulent sharing is occurring, without requiring external identifier management or complex comparison logic.
3Device complexity
If time duration between control messages is monitored instead of channel identifiers, then device complexity is reduced, but reliability may worsen if time synchronization is not precise
Solution Approach 1:
The patent establishes a predefined threshold for the time interval between control messages, which is set based on the cryptoperiod duration. This preliminary configuration allows the system to reliably detect fraudulent use without requiring complex real-time synchronization mechanisms. The threshold acts as a reference that simplifies the detection process while maintaining security reliability.
Solution Approach 2:
Instead of using channel identifiers to determine if messages are legitimate, the patent inverts the approach by using the absence of expected time intervals to detect fraud. Legitimate messages naturally occur at intervals related to the cryptoperiod, while fraudulent messages disrupt this pattern. This inversion simplifies the detection logic while maintaining reliability.
Data Source
AI summary
The invention concerns a method for controlling access to encrypted data by control words (CW), said control words being received by a security module in control messages (ECM) and returned to a unit operating on (STB) the encrypted data. The method includes the following steps: receiving a first control message (ECM) comprising at least one control word (CW) and a time stamp (TS), receiving a second control message (ECM2) consecutive to the first control message (ECM1), said second message comprising at least one control word (CW) and a time stamp (TS), determining a duration corresponding to the difference between the time stamps (TS) of the two consecutive control messages (ECM1, ECM2), if said duration is less than a predefined duration (CP), incrementing an error counter (CE), and if said duration is not less than said predefined duration, decrementing said error counter (CE), returning the control word (CW) to the operating unit (STB) after a waiting time depending on the value of the error counter (CE).


