Management Center Broadcast Access Control via Boolean Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current broadcast encryption systems rely heavily on the security module of receiving devices to enforce access conditions, which can be vulnerable to reverse-engineering, and struggle to efficiently manage complex access policies and user characteristics.

Innovation Solution

Implementing a method where a management center uses two key materials (positive and negative) for each subscription package to encrypt product keys, allowing access only when the positive key material is present and denying access when the negative key material is absent, thus shifting the access rule enforcement from the security module to the management center.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access conditions are enforced by the security module of the receiving device, then the system can control access to broadcast content, but the security module becomes vulnerable to reverse-engineering and cannot efficiently manage complex access policies

Engineering Contradiction:
Improveaccess control securityVSAvoidreverse-engineering vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the access condition enforcement function from the receiving device's security module and relocates it to the management center. The management center now evaluates access conditions and determines whether to release product keys, while the security module retains only key storage and decryption functions. This extraction eliminates the vulnerability of having complex access control logic embedded in the receiving device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces the management center as an intermediary between the broadcast content and the receiving devices. The management center acts as a mediator that receives access condition evaluations, determines key release decisions, and communicates with both the broadcast system and the receiving devices. This intermediary structure centralizes security enforcement while simplifying the receiving device's security module.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the security module stores and enforces access conditions locally, then access control can be implemented, but the device complexity and security risks increase

Engineering Contradiction:
Improvelocal access controlVSAvoidsecurity module complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the complex access condition evaluation logic from the security module and relocates it to the management center. The security module now only stores subscription package keys and receives access decisions, significantly reducing its complexity while maintaining ease of operation through automated key release.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of having the receiving device's security module actively evaluate access conditions and make decisions, the system inverts the approach by having the management center make the access decisions based on evaluations it performs. The security module passively receives and executes key release decisions, simplifying its role while maintaining operational effectiveness.

Inventive Principle:
Principle #13The other way round (Inversion)

3Adaptability or versatility

If complex access policies are managed at the receiving device level, then fine-grained control is possible, but the system becomes less secure and harder to manage

Engineering Contradiction:
Improveaccess policy flexibilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent extracts complex access policy management from the receiving device level and consolidates it at the management center. The management center maintains a database of subscription packages and access conditions, evaluating whether releasing a product key would violate any access conditions. This centralization maintains policy flexibility while significantly improving system security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The management center serves multiple functions: it manages subscription packages, evaluates access conditions, determines key release decisions, and communicates with both the broadcast system and receiving devices. This universal approach consolidates complex access policy management in a single secure location while maintaining the ability to enforce fine-grained control across the entire system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2345246B1Method to enforce by a management center the access rules for a broadcast product
Publication Date: 2012.08.15 NAGRAVISION SA
  • EP2345246B1 patent drawingFigure 1

AI summary

The purpose of this invention is to propose a manner to rely to a lesser extent on the security means of the receivers security module to enforce the access conditions defined in the key messages on one hand and to handle complex access conditions based on the characteristic and properties of the receiving device or the user of such a device on the other hand. It is therefore proposed a method to enforce by a management center the access rules for a broadcast product received by receivers, the access to said product being released by an access key, said management center managing a plurality of Boolean positive and negative attributes on receivers, the method comprising the steps of associating one positive Boolean attribute to one receiver entitled to said attribute and loading state to it; associating one negative Boolean attribute to said receiver not entitled to said attribute and loading state to it; defining at least a second broadcast encryption scheme targeting the set of the negative Boolean attributes and associating to each negative Boolean attribute the corresponding decryption key material; expressing the access conditions on a product as a Boolean expression on attributes by combining at least one of the positive Boolean attributes and at least one of the negative Boolean attributes by means of at least one of Boolean conjunction or disjunction; generating at least one cryptogram to be broadcasted to the receiver by encrypting the access key by means of the two combined broadcast encryption schemes according to the said Boolean expression.