Bridge Device Partial Authentication for HDCP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current High-Bandwidth Digital Content Protection (HDCP) systems require bridge devices to have both encryption and decryption engines, which are costly and power-intensive, as they need to decrypt and re-encrypt entire data streams, exposing protected content during the process.

Innovation Solution

Implementing a partial authentication mechanism that allows a bridge device to access and modify encrypted data streams without complete decryption, using a single encryption/decryption engine and XOR masking techniques to analyze and re-encrypt content within the bridge device's chip, independent of the source and sink devices' authentications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a bridge device employs complete encryption and decryption engines to process HDCP-protected data streams, then the device can decrypt and re-encrypt the entire data stream for measurement and processing, but the cost in terms of power consumption, die space, and component requirements increases significantly

Engineering Contradiction:
Improvecontent processing capabilityVSAvoidpower consumption
Core Design Contradiction:
Ease of operationVSUse of energy by moving object

Solution Approach 1:

The patent extracts only the essential authentication functionality from the complete encryption/decryption engine. The bridge device performs partial authentication using authentication engines that verify content protection status without requiring full decryption capabilities, thereby reducing power consumption and die space while maintaining content processing capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements partial authentication where the bridge device performs only the necessary authentication steps to verify content protection status rather than complete decryption and re-encryption. This partial action approach reduces the computational burden and resource requirements while still enabling content measurement and processing

Inventive Principle:
Principle #16Partial or excessive action

2Productivity

If a bridge device employs complete encryption and decryption engines, then the device can process and measure encrypted content, but the die space and manufacturing cost increase due to requiring two complete key sets and additional testing

Engineering Contradiction:
Improvecontent measurement and processingVSAvoidencryption and decryption engines
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent extracts only the authentication functionality needed for content protection verification, removing the requirement for complete decryption engines. The bridge device uses authentication engines that work with encrypted data directly, eliminating the need for two complete key sets and reducing die space while maintaining content measurement capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the authentication and processing functions into separate components. The authentication engine handles content protection verification independently from the measurement and processing functions, allowing the bridge device to perform content analysis without requiring full decryption capabilities

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If a bridge device performs complete decryption of encrypted data streams, then the device can access and process the content, but the protected content is exposed outside the chip during the decryption process

Engineering Contradiction:
Improvecontent accessVSAvoidcontent exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that allows the bridge device to verify content protection status and perform measurements without exposing the actual content. The authentication engine acts as a mediator that provides controlled access to content metadata and measurement data while keeping the encrypted content confined within the chip

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements partial authentication that provides just enough access for content measurement and processing without full decryption. This approach allows the bridge device to access necessary content information for processing while maintaining content protection and preventing exposure outside the chip

Inventive Principle:
Principle #16Partial or excessive action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach reduces the need for dual engines in bridge devices, saving power and costs while maintaining data integrity and security, allowing for efficient processing and analysis of encrypted content without exposing it outside the chip.

Implementation Method 1

using a single encryption/decryption engine and XOR masking techniques to analyze and re-encrypt content within the bridge device's chip

Methodology Applied
Scientific EffectXOR masking:

Data Source

PatentUS8930692B2Mechanism for internal processing of content through partial authentication on secondary channel
Publication Date: 2015.01.06 LATTICE SEMICON CORP
  • US8930692B2 patent drawing
  • US8930692B2 patent drawing
  • US8930692B2 patent drawing

AI summary

Embodiments of the invention are generally directed to performing processing of content through partial authentication of secondary channel. An embodiment of a method includes performing a first authentication between a source transmitting device and a sink receiving device for communication of data streams, and performing a second authentication between the source transmitting device and a bridge device such that the second authentication is independent of the first authentication and the sink receiving device remains uninfluenced by the second authentication. The bridge device includes an intermediate carrier device coupled to the source transmitting device and the sink receiving device. The method further includes transmitting a data stream having encrypted content from the source transmitting device to the bridge device.