Conditional Access System Using Constrained Control Words

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conditional access systems in content delivery networks face security vulnerabilities due to less secure decryption engines that could potentially attack more secure systems, compromising the integrity of encrypted content.

Innovation Solution

Implementing a method where less secure decryption engines use a constrained set of control words, derived by combining a locally accessible fixed control word with a variable control word, to prevent unauthorized decryption of content intended for more secure systems, thereby maintaining security and compatibility with conventional decryption engines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If standardized chip-making processes are used to reduce costs and increase flexibility, then manufacturing ease and cost reduction are improved, but security and vulnerability to attacks deteriorate

Engineering Contradiction:
Improvechip-making process standardizationVSAvoiddecryption engine security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent applies local quality by differentiating the security characteristics of different decryption engines within the same system. Less secure decryption engines are designed with specific constraints (using only even numbers as control words) that limit their attack capability, while more secure engines maintain full functionality. This allows standardized manufacturing processes to be used across the board while maintaining security through localized differentiation.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent creates asymmetry in the control word generation process by requiring that less secure decryption engines use only even numbers as control words, while more secure engines can use any number. This asymmetric constraint prevents less secure engines from attacking more secure ones, as the mathematical constraint creates a fundamental difference in their operational capabilities.

Inventive Principle:
Principle #4Asymmetry

2Adaptability or versatility

If less secure decryption engines are allowed to operate in the same system as more secure ones, then system compatibility and versatility are improved, but security vulnerability increases

Engineering Contradiction:
Improvesystem compatibilityVSAvoidattack capability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by pre-constraining less secure decryption engines to use only even numbers as control words before they can be used to attack more secure systems. This preemptive mathematical constraint ensures that even if a less secure engine obtains the control word for a more secure system, it cannot successfully decrypt the content because the control word would need to be odd, which contradicts the engine's operational constraints.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent uses the control word generation process as an intermediary mechanism that mediates between different types of decryption engines. The mathematical constraint on control word generation acts as a barrier that prevents less secure engines from interacting harmfully with more secure engines, while still allowing both types to operate within the same system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If control words are mathematically constrained to prevent brute force attacks, then security against unauthorized decryption is improved, but flexibility and adaptability of the system deteriorate

Engineering Contradiction:
Improvesecurity against brute forceVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the decryption engine population into distinct categories based on their security characteristics and control word constraints. Less secure engines are segmented to use only even numbers, while more secure engines use any numbers. This segmentation allows the system to maintain security through constrained engineering while preserving flexibility through the existence of multiple engine types that can serve different purposes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the parameter space of control words by introducing mathematical constraints (even vs. odd numbers) that fundamentally alter the search space for brute force attacks. This parameter change reduces the effective search space for unauthorized decryption while maintaining the ability of authorized systems to generate and use control words for content encryption and decryption.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8687806B2Conditional access system employing constrained encryption keys
Publication Date: 2014.04.01 GOOGLE TECHNOLOGY HOLDINGS LLC
  • US8687806B2 patent drawing
  • US8687806B2 patent drawing
  • US8687806B2 patent drawing

AI summary

A method and apparatus is provided for decrypting an encrypted transport stream, comprising. The method includes receiving the encrypted transport stream over a content delivery network. The encrypted transport stream is encrypted using a first control word that serves as an encryption/decryption key. A variable control word is received over the content delivery network. The variable control word is mathematically constrained to create a second control word. The encrypted transport stream is decrypted using the second control word if the second control word is the same as the first control word.