Dynamic Key Distribution in Transport Stream Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Conditional Access Systems (CAS) face issues where embedded CAS keys in digital broadcast receivers are difficult to update or replace if damaged or stolen, leading to high replacement costs and security breaches.
Innovation Solution
A method and system where a server encrypts a device key and sends it to a client device within a transport stream, allowing the device key to be updated and changed periodically, enabling secure decryption of scrambled broadcasting content using known encryption keys.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If CAS keys are embedded in DRM IC or storage medium during manufacturing, then the receiving device can initially decrypt broadcasts, but the keys cannot be updated or replaced if damaged or stolen
Solution Approach 1:
The system segments the key management function from the receiving device by introducing a separate key distribution server. The CAS key is divided into two parts: a static embedded key in the DRM IC for initial authentication, and a dynamic key distributed through the transport stream for updates. This segmentation allows the receiving device to maintain both embedded and received keys simultaneously, enabling key renewal without replacing the entire device.
Solution Approach 2:
The patent introduces a key distribution server as an intermediary between the content source and the receiving device. This server manages the CAS key lifecycle by generating, distributing, and updating keys through the transport stream. The intermediary enables secure key delivery and facilitates key updates without requiring direct interaction between the content source and end-user devices.
2Ease of manufacture
If embedded CAS keys are used in receiving devices, then initial broadcast decryption is enabled, but device replacement costs increase when keys are compromised
Solution Approach 1:
The system performs preliminary key distribution by embedding a static CAS key in the DRM IC during manufacturing for initial authentication. This preliminary action enables the receiving device to initially decrypt broadcasts and establish communication with the key distribution server. The embedded key serves as a bootstrap mechanism that facilitates subsequent dynamic key updates without requiring device replacement.
Solution Approach 2:
The patent changes the parameter of key lifetime from static (embedded permanently in DRM IC) to dynamic (renewable through transport stream). By introducing time-varying keys that can be updated periodically or on-demand through the transport stream, the system extends the effective lifetime of receiving devices and eliminates the need for replacement when keys are compromised.
3Ease of operation
If CAS keys are embedded in receiving devices during manufacturing, then initial access is provided, but key theft prevents future security updates
Solution Approach 1:
The system transitions from static key embedding to dynamic key distribution. The CAS key becomes a dynamic parameter that can be updated through the transport stream based on security requirements. The receiving device maintains both the embedded static key for initial access and receives dynamic keys from the server, allowing continuous security updates and key rotation even after initial deployment.
Solution Approach 2:
The patent implements periodic key distribution where the key distribution server sends updated CAS keys through the transport stream at regular intervals or on-demand. This periodic action ensures that even if a key is stolen, the system can issue new keys periodically, maintaining ongoing security without requiring device replacement. The embedded key enables initial access, while periodic key updates ensure continuous security.
Data Source
AI summary
A method for generating a transport stream of a server is provided. The method for generating a transport stream of a server which sends broadcasting content to a client device comprises: scrambling broadcasting content by using a specific key; adding at least one content-encryption message which includes the specific key and a device key for obtaining the specific key from the at least one content-encryption message to the broadcasting content so as to generate a transport stream; and sending the generated transport stream to the client device.


