CI Plus Secure Interface for Interoperable Content Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The original CI specification allows for potential interception and copying of decrypted digital content due to insecure communication between the host and CAM, compromising security, while integrated devices offer better security but limit interoperability among different manufacturers' products.
Innovation Solution
The CI Plus specification introduces a secure interface between the host and CAM, encrypting decrypted content before transmission, authenticating both devices, and using Diffie-Hellman key exchange for secure key sharing, ensuring that only the CAM-host pair-specific keys are used for encryption, thus enhancing security without compromising interoperability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the host and CAM interact using the original CI specification with unencrypted communication, then interoperability between different manufacturers' products is achieved, but security is compromised allowing decrypted content to be intercepted and copied
Solution Approach 1:
A secure interface layer is introduced between the host and CAM that acts as an intermediary. This interface encrypts data transmissions using Diffie-Hellman key exchange and certificate-based authentication, preventing direct interception while maintaining the existing PCMCIA physical interface and protocol structure for interoperability
Solution Approach 2:
The communication parameters between host and CAM are changed from unencrypted to encrypted transmissions. Certificate hierarchy and device authentication are implemented to verify identities, and Diffie-Hellman key exchange dynamically generates secure session keys, transforming the security parameters without changing the physical interoperability interface
2Reliability
If integrated devices are used to improve security over data transfer, then content protection is enhanced, but interoperability among different manufacturers' products is limited
Solution Approach 1:
The system is segmented into separate host and CAM devices that maintain secure encrypted communication through the PCMCIA interface. The security functions (encryption, authentication, key exchange) are separated from the physical interface layer, allowing different manufacturers' devices to interoperate while each device maintains its own security implementation
Solution Approach 2:
The PCMCIA interface is made universal to support both secure and insecure communication modes. The secure interface layer provides multiple functions including encryption, decryption, authentication verification, and key management, enabling a single interface standard to serve both interoperability and security requirements across different device manufacturers
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
A method of operation of an audio/video content receiver having a content decoder capable of decoding an audio/video programme from a packetized data stream by using data packets defining decryption information comprises the steps of: receiving encoded audio/video content as a packetized data stream comprising one or more programmes having data packets identified by respective sets of one or more packet identifiers and comprising identification data mapping programmes to respective sets of the packet identifiers; selecting data packets from the packetized data stream for a required programme according to the set of packet identifiers defined by the identification data for that stream in respect of the required programme; selecting further data packets from the packetized data stream from which a programme is selected which have packet identifiers not included in the identification data for that packetized data stream; generating a composite packetized data stream from the selected packets; generating composite stream identification data indicating packet identifiers of packets included in the composite packetized data stream; and supplying the composite packetized data stream to the content decoder for decoding the programme from the composite packetized data stream according to the packet identifiers in the composite stream identification data.