Dual-Module Audio Video Decryption Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure processing units for access-controlled digital audio/video data lack security against counterfeited security modules, as they rely on a single key pair for decryption, which can be compromised.

Innovation Solution

A method and unit that utilize a pairing mechanism between the security module and the processing unit, where control messages contain both control words and right execution parameters, allowing two security devices to manage and verify keys independently, ensuring secure decryption of audio/video data by applying sequential control words.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single key pair is used for decryption in the calculation module, then the decryption process is simple and efficient, but the security is compromised against counterfeited security modules

Engineering Contradiction:
ImprovesecurityVSAvoiddecryption process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The decryption process is segmented into two independent paths: one using a first key from the security module to decrypt a first control word, and another using a second key from the calculation module to decrypt a second control word. Both control words are then combined to decrypt the encrypted data stream. This segmentation allows each module to independently verify keys, preventing counterfeited security modules from compromising the entire system.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a pairing mechanism with two key pairs is implemented, then security against counterfeited modules is improved, but the device complexity and key management burden increase

Engineering Contradiction:
Improvesecurity against counterfeited modulesVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The pairing between the security module and calculation module is established in advance during system initialization. Each module is pre-configured with its specific key (first key in security module, second key in calculation module) and the pairing relationship is registered beforehand. This preliminary action simplifies operational key management during normal decryption processes, as the pairing verification is already in place and does not require complex real-time negotiations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If control words are managed independently by two modules, then key renewal can be performed regularly, but the coordination and synchronization between modules becomes more complex

Engineering Contradiction:
Improvekey renewal capabilityVSAvoidmodule coordination
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Control words are renewed periodically through the independent decryption paths. The system regularly updates control words using the two independent key pairs, allowing each module to independently participate in key renewal without requiring complex real-time coordination. The periodic nature of control word updates simplifies the synchronization requirement, as each module can independently process renewals at predetermined intervals.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8549655B2Unit and method for secure processing of access controlled audio/video data
Publication Date: 2013.10.01 NAGRAVISION SA
  • US8549655B2 patent drawing
  • US8549655B2 patent drawing
  • US8549655B2 patent drawing

AI summary

Unit for secure processing access controlled audio/video data capable of receiving control messages (ECM) comprising at least one first control word (CW1) and first right execution parameters (C1), at least one second control word (CW2) and second right execution parameters (C2), said processing unit being connected to a first access control device (CA1), said processing unit is characterized in that it comprises: —means for verifying and applying the first right execution parameters (C1) in relation to the contents of a memory (M1) of said first access control device (CA1) and means for obtaining the first control word CW1, —a second access control device (CA2) integrated into the processing unit UT including means for verifying and applying the second right execution parameters (C2) in relation to the contents of a memory (M2) associated to said second access control device (CA2) and means for obtaining the second control word (CW2), —a deciphering module (MD) capable of deciphering, sequentially with the first and the second control word (CW1) and (CW2), the access controlled audio/video data, said control words (CW1) and (CW2) being provided by the first and second access control devices (CA1, CA2) and stored in said deciphering module (MD). A method for secure processing digital access controlled audio/video data carried out by said unit is also an object of the present invention.