Secure Authentication Channel for CI+ Decryption Bandwidth

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Common Interface Plus (CI+) interface requires significant bandwidth to send two complete transport streams between the set-top box and the Conditional Access Module (CICAM), making it inconvenient for decryption with multiple tuners.

Innovation Solution

A secure authentication channel (SAC) is generated between the CICAM and the set-top box, allowing only the control word and usage rules to be transmitted, reducing the data passed over the interface, and enabling efficient decryption of multiple transport streams.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two complete transport streams are sent over the interface between the set-top box and the CICAM, then decryption can be performed, but the bandwidth required becomes excessively large

Engineering Contradiction:
Improvedecryption capabilityVSAvoidbandwidth
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential decryption elements (control words and usage rules) from the complete transport stream and transmits them separately over the interface. This separates the bulk encrypted content (processed locally) from the critical access control data (transmitted over interface), thereby reducing interface bandwidth requirements while maintaining decryption capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the transport stream processing into two parts: encrypted content processing (done locally in the set-top box) and control word generation (done in the CICAM). By dividing the decryption process into these segments and transmitting only the control words over the interface, the bandwidth burden is significantly reduced.

Inventive Principle:
Principle #1Segmentation

2Productivity

If the interface bandwidth is reduced to enable multiple tuner decryption, then the amount of data transmitted decreases, but ensuring security and access control becomes more challenging

Engineering Contradiction:
Improvemultiple tuner supportVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a secure authentication channel as an intermediary mechanism between the set-top box and CICAM. This dedicated secure channel transmits control words and usage rules with enhanced protection, ensuring that even with reduced data transmission, security and access control are maintained through specialized security protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Quantity of substance

If only control words and usage rules are transmitted over the interface, then bandwidth usage is reduced, but the complexity of managing secure authentication increases

Engineering Contradiction:
Improvedata transmission volumeVSAvoidauthentication channel management
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent implements a universal secure authentication channel that handles multiple functions: control word transmission, usage rule distribution, and security management. This multi-functional channel consolidates what could be multiple separate complex systems into a single standardized interface, reducing overall system complexity despite the specialized security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2612503B1Method and system for decrypting a transport stream
Publication Date: 2020.04.15 SATURN LICENSING LLC
  • EP2612503B1 patent drawingFigure 1
  • EP2612503B1 patent drawingFigure 2
  • EP2612503B1 patent drawingFigure 3

AI summary

A module configured in operation to connect to a host, the module comprising: a decryptor operable to decrypt an encrypted transport stream received from the host, the transport stream containing content data and a decryption seed; a decryption key generator operable to extract the decryption seed from the transport stream and to generate a decryption key from said decryption key seed; and a secure channel generator operable to generate a secure channel between the module and the host, whereby the secure channel generator is further operable to provide the generated decryption key to the host over the secure channel.