DCAS Personalization Servers UKL Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In a Downloadable Conditional Access System (DCAS) architecture, personalization servers risk assigning the same unique key to multiple client devices and face unauthorized access to the entire unit key list (UKL), leading to network instability and security breaches.

Innovation Solution

The UKL is segmented into blocks, each encrypted with a unique transmission key, and assigned to specific personalization servers, ensuring that each server can only access its designated block of unique keys for client device personalization, preventing access to other blocks and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the same encrypted UKL is given to all personalization servers, then each server can access any unique key for personalization, but duplicate key assignments occur and security is compromised

Engineering Contradiction:
Improvekey assignment capabilityVSAvoidunique key assignment guarantee
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the UKL into multiple encrypted blocks, with each block assigned to a specific personalization server. This segmentation ensures that each server only has access to its designated block, preventing duplicate key assignments while maintaining operational capability for key distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each personalization server is given a unique portion of the UKL (specific encrypted block) rather than the entire list. This local quality approach allows servers to perform their function with limited, specific access rights, ensuring both operational efficiency and security constraints.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If personalization servers have access to the entire UKL, then they can personalize any client device, but unauthorized access to the entire UKL causes network-wide security breaches

Engineering Contradiction:
Improveclient device personalization capabilityVSAvoidnetwork security risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The UKL is segmented into multiple encrypted blocks distributed to different personalization servers. This segmentation limits the scope of potential security breaches to individual blocks rather than the entire key list, reducing network-wide risk while preserving personalization capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer of encryption (transport layer encryption) between the UKL blocks and personalization servers. This intermediary protection mechanism ensures that even if a server is compromised, the actual unique keys remain protected until the final decryption stage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If multiple personalization servers are deployed to serve more client devices, then network capacity increases, but the risk of duplicate key assignment and security breaches increases

Engineering Contradiction:
Improveclient device service capacityVSAvoidkey assignment uniqueness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent enables deployment of multiple personalization servers by segmenting the UKL into separate encrypted blocks for each server. This allows linear scaling of server capacity while maintaining unique key assignment through controlled access to specific blocks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2197172B1Content delivery network having downloadable conditional access system with personalization servers for personalizing client devices
Publication Date: 2020.03.25 COMBINED CONDITIONAL ACCESS DEV & SUPPORT
  • EP2197172B1 patent drawingFigure 1~3
  • EP2197172B1 patent drawingFigure 2

AI summary

A content delivery network and method employing a Downloadable Conditional Access System ("DCAS") includes first and second personalization servers. A unit key list having unique keys is segmented into different blocks. Each block is encrypted with a separate transmission key corresponding to that block such that first and second blocks are respectively encrypted with first and second transmission keys. The encrypted blocks are communicated to the personalization servers. The first transmission key is communicated to the first personalization server without being communicated to another personalization server such that the first server can decrypt the first block using the first transmission key to access the keys of the first block. The second transmission key is communicated to the second personalization server without being communicated to another personalization server such that the second server can decrypt the second block using the second transmission key to access the keys of the second block.