Bridge Device Partial Authentication for HDCP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current High-Bandwidth Digital Content Protection (HDCP) systems require bridge devices to have both encryption and decryption engines, which are costly and power-intensive, as they need to decrypt and re-encrypt entire data streams, exposing protected content during the process.
Innovation Solution
Implementing a partial authentication mechanism that allows a bridge device to access and modify encrypted data streams without complete decryption, using a single encryption/decryption engine and XOR masking techniques to analyze and re-encrypt content within the bridge device's chip, independent of the source and sink devices' authentications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a bridge device employs complete encryption and decryption engines to process HDCP-protected data streams, then the device can decrypt and re-encrypt the entire data stream for measurement and processing, but the cost in terms of power consumption, die space, and component requirements increases significantly
Solution Approach 1:
The patent extracts only the essential authentication functionality from the complete encryption/decryption engine. The bridge device performs partial authentication using authentication engines that verify content protection status without requiring full decryption capabilities, thereby reducing power consumption and die space while maintaining content processing capability
Solution Approach 2:
The patent implements partial authentication where the bridge device performs only the necessary authentication steps to verify content protection status rather than complete decryption and re-encryption. This partial action approach reduces the computational burden and resource requirements while still enabling content measurement and processing
2Productivity
If a bridge device employs complete encryption and decryption engines, then the device can process and measure encrypted content, but the die space and manufacturing cost increase due to requiring two complete key sets and additional testing
Solution Approach 1:
The patent extracts only the authentication functionality needed for content protection verification, removing the requirement for complete decryption engines. The bridge device uses authentication engines that work with encrypted data directly, eliminating the need for two complete key sets and reducing die space while maintaining content measurement capability
Solution Approach 2:
The patent segments the authentication and processing functions into separate components. The authentication engine handles content protection verification independently from the measurement and processing functions, allowing the bridge device to perform content analysis without requiring full decryption capabilities
3Ease of operation
If a bridge device performs complete decryption of encrypted data streams, then the device can access and process the content, but the protected content is exposed outside the chip during the decryption process
Solution Approach 1:
The patent introduces an intermediary authentication mechanism that allows the bridge device to verify content protection status and perform measurements without exposing the actual content. The authentication engine acts as a mediator that provides controlled access to content metadata and measurement data while keeping the encrypted content confined within the chip
Solution Approach 2:
The patent implements partial authentication that provides just enough access for content measurement and processing without full decryption. This approach allows the bridge device to access necessary content information for processing while maintaining content protection and preventing exposure outside the chip
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach reduces the need for dual engines in bridge devices, saving power and costs while maintaining data integrity and security, allowing for efficient processing and analysis of encrypted content without exposing it outside the chip.
Implementation Method 1
using a single encryption/decryption engine and XOR masking techniques to analyze and re-encrypt content within the bridge device's chip
Data Source
AI summary
Embodiments of the invention are generally directed to performing processing of content through partial authentication of secondary channel. An embodiment of a method includes performing a first authentication between a source transmitting device and a sink receiving device for communication of data streams, and performing a second authentication between the source transmitting device and a bridge device such that the second authentication is independent of the first authentication and the sink receiving device remains uninfluenced by the second authentication. The bridge device includes an intermediate carrier device coupled to the source transmitting device and the sink receiving device. The method further includes transmitting a data stream having encrypted content from the source transmitting device to the bridge device.


