Conditional Access System for Intelligent Operating Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing downloadable conditional access system technology is limited in adapting to intelligent operating systems, particularly for smart TVs, and fails to provide seamless interconnection of nationwide cable TV networks, which is essential for the transition from traditional digital TV to smart TV platforms.
Innovation Solution
A conditional access method and system for intelligent operating systems that includes a smart device equipped with a live broadcasting application module, a digital TV module, a media play module, a conditional access module, a trusted execution environment (TEE), and a high-security chip, which acquires and processes channel program information, entitlement control messages, and descrambles video and audio streams using encryption keys, enabling secure and adaptable conditional access across multiple manufacturers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional downloadable conditional access system technology is used, then set-top boxes can be customized for wired networks with security protection, but the system cannot adapt to intelligent operating systems and cannot realize seamless interconnection of nationwide cable TV networks
Solution Approach 1:
The system is divided into multiple independent modules including conditional access module, media playback module, application module, and trusted execution environment module. Each module operates independently with defined interfaces, allowing the system to adapt to different operating systems while maintaining security through modular architecture.
Solution Approach 2:
A conditional access module is introduced as an intermediary layer between the secure hardware (high-security chip) and the application layer. This intermediary manages entitlement control messages and entitlement management messages, enabling conditional access functionality to be implemented in intelligent operating systems while maintaining the security guarantees of the underlying hardware.
2Adaptability or versatility
If conditional access functionality is integrated into intelligent operating systems, then multi-manufacturer switching and system openness are improved, but system security and protection of entitlement control mechanisms may be compromised
Solution Approach 1:
The high-security chip with trusted execution environment is embedded within the intelligent operating system architecture. The secure hardware contains the conditional access module, which in turn manages multiple conditional access application modules from different manufacturers. This nested structure allows multi-vendor support while maintaining security boundaries.
Solution Approach 2:
The system uses entitlement control messages and entitlement management messages that contain parameters such as conditional access application identifiers, video stream identifiers, and audio stream identifiers. These parameters are dynamically managed to enable switching between different conditional access systems while maintaining security through encrypted message exchanges.
3Device complexity
If a unified conditional access system is designed for intelligent operating systems, then device complexity is reduced, but it becomes difficult to support multiple conditional access application modules from different manufacturers
Solution Approach 1:
The conditional access module is designed with universal interfaces that can work with multiple conditional access application modules from different manufacturers. The module uses standardized message formats (entitlement control messages and entitlement management messages) and identifies different conditional access systems through conditional access application identifiers, enabling a single unified architecture to support multiple vendors.
Data Source
AI summary
The present invention provides a conditional access method for an intelligent operating system that comprises a trusted execution environment. A digital TV module acquires all channel messages and a control management message. A media play module distributes a DescramblerId and sends the acquired videoPid, audioPid, casId, ecmPid and emmPid and the descrambler message DescramblerId to a conditional access module. The conditional access module selects a registered conditional access application module according to the casId. The conditional access application module acquires corresponding ecm Data and emm Data from the digital TV module, and sends the ecm Data and emm Data to the conditional access module. The conditional access module sends the messages to a trusted application module. The trusted application module performs parse to acquire EK1, EK2 and ECW. The security chip controls a descrambler corresponding to the DescramblerId to perform descrambling according to the acquired messages.


