Cryptographic Entity Group Segmentation for Secure Key Diversification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing multimedia signal reception systems struggle to restrict a first cryptographic entity to only work with a specific group of second entities, while maintaining security and adaptability across different protection modes.

Innovation Solution

Implementing a method where only a group of N second entities, chosen from a larger set of P entities, use a session key derived from a common root key, ensuring the first entity is usable only within this group by rendering the diversification module unusable after connection, and using security integrated circuits to store and decrypt session keys securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a first cryptographic entity is designed to work with any second entity using a common root key, then universality and ease of operation are improved, but security is worsened because the first entity cannot be restricted to a specific group of second entities

Engineering Contradiction:
Improveuniversality of first entityVSAvoidsecurity restriction
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the set of second entities into multiple groups, each group associated with a specific root key. The first cryptographic entity is configured to work only with second entities from its assigned group, creating segmented access control that maintains security while preserving universality within the designated group.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each first cryptographic entity is assigned specific local qualities through configuration parameters that identify its authorized group of second entities. This local quality approach allows the entity to maintain universality within its designated scope while being restricted from other groups, resolving the contradiction between broad adaptability and security constraints.

Inventive Principle:
Principle #3Local quality

2Reliability

If a first cryptographic entity is restricted to work only with a specific group of N second entities, then security is improved, but adaptability is worsened because the entity cannot be used with other second entities

Engineering Contradiction:
Improvesecurity restrictionVSAvoiduniversality of first entity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The first cryptographic entity maintains multi-functionality by being able to work with any second entity within its designated group of N entities. While restricted from other groups, it achieves universality within its scope, allowing it to serve multiple purposes and compatible devices without requiring multiple specialized entities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses parameter changes in the form of group identification parameters and root key selections to enable the first entity to adapt its operation to different second entities within its authorized group. This parameter-based approach maintains security restrictions while providing flexibility and adaptability within the permitted scope.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If session keys are obtained by diversifying root keys using the same identifier, then ease of operation is improved through automatic key matching, but security is worsened because the diversification module remains usable for creating new session keys

Engineering Contradiction:
Improveautomatic key matchingVSAvoidkey security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary action by rendering the diversification module unusable immediately after the first and second entities are connected and have established their session key. This preliminary security measure prevents any subsequent unauthorized key generation while maintaining the ease of automatic key matching during the legitimate connection process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system extracts the diversification capability from the first cryptographic entity after use, effectively removing the ability to create new session keys once the connection is established. This extraction of the key generation function maintains security by preventing unauthorized key creation while preserving the automatic matching functionality during the legitimate pairing process.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8666072B2Method and a system for receiving a multimedia signal, a cryptograophic entity for said reception method and system, and a method and a black box for producing said cryptographic entity
Publication Date: 2014.03.04 VIACCESS SA
  • US8666072B2 patent drawing
  • US8666072B2 patent drawing
  • US8666072B2 patent drawing

AI summary

This method of receiving a multimedia signal scrambled by means of a control word uses a first cryptographic entity that can be connected to any one of P second cryptographic entities to form part of a device for receiving the scrambled multimedia signal. Only second cryptographic entities of a group of N second cryptographic entities selected from a wider set of P second cryptographic entities use a session key obtained by diversifying a root key identical to the root key used to obtain the session key of the first cryptographic entity.