Conditional Access Counter for Anti-Piracy Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing DVB conditional access architecture is vulnerable to piracy, as control words can be easily decrypted and shared, allowing unauthorized access to protected content, particularly through Internet Key Sharing Servers that exploit legitimate smart cards by submitting multiple ECM decryption requests for various channels, exceeding the legitimate usage patterns.

Innovation Solution

Implementing a counter mechanism in devices such as set-top-boxes and smart cards that increments or decrements a counter based on the type of ECM requests received, with a threshold check for management messages, ensuring that if the counter exceeds the threshold, subsequent management messages are disregarded, preventing access to protected content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If control words are made available to legitimate subscribers through management messages, then authorized access to protected content is enabled, but pirate users can commandeer legitimate systems and share keys with other pirated users

Engineering Contradiction:
Improvesecurity of content distributionVSAvoidaccess to protected content
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary verification by checking the counter value before granting access to management messages containing decryption keys. This preliminary action prevents pirate systems from obtaining keys that could be shared with other unauthorized users, while still allowing legitimate subscribers to access content normally.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The counter mechanism provides feedback about the number of ECM decryption requests received for different channels. This feedback allows the system to detect abnormal access patterns characteristic of pirate systems and respond by denying management message access when the counter exceeds the threshold.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If multiple ECM decryption requests are processed for various channels, then pirate systems can extract control words for sharing, but legitimate subscribers need access to multiple channels

Engineering Contradiction:
Improveaccess to multiple channelsVSAvoidpirate activity detection
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies different access rules based on the local condition of the counter value. When the counter is below the threshold, normal access to management messages is permitted. When the counter exceeds the threshold, access is denied. This localized quality control allows legitimate multi-channel access while blocking pirate key extraction.

Inventive Principle:
Principle #3Local quality

3Reliability

If a counter mechanism is implemented to detect pirate activity, then unauthorized key sharing is prevented, but the system complexity increases

Engineering Contradiction:
Improveprevention of unauthorized accessVSAvoidcounter verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The counter mechanism is self-contained within the subscriber device, using local resources to track and verify ECM decryption requests. The device independently maintains the counter and performs threshold comparisons without requiring external verification infrastructure, minimizing added system complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9503785B2Anti-splitter violation conditional key change
Publication Date: 2016.11.22 NAGRASTAR LLC
  • US9503785B2 patent drawing
  • US9503785B2 patent drawing
  • US9503785B2 patent drawing

AI summary

Systems and methods are disclosed for performing anti-piracy countermeasures in order to prevent unauthorized access of protected content. A conditional access system may be modified to include a counter. The counter is incremented every time the conditional access system receives a request that is a potential indication of pirate activity. The counter may also be decremented every time the conditional access system receives a request indicative of legitimate activity. If the conditional access system receives a management message containing a key required to access content keys, the conditional access system cheeks the counter. If the counter is below a threshold value, the conditional access system obtains the key. However, if the counter is above the threshold value, the conditional access system disregards the key contained in the management message, thereby losing access to protected content.