Secure Storage Method for Encrypted Digital Recorder Content

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing conditional access receivers struggle to ensure access to stored encrypted content when system keys change, particularly during the storage process, and existing solutions do not account for scenarios where rights are acquired after storage or when decryption conditions vary over time, leading to supplementary charges and access issues.

Innovation Solution

A storage method where encrypted events, control messages, and system keys are stored in a receiver/decoder unit, with system keys encrypted by a predefined local key, ensuring access even if keys change, using a unique key that remains unchanged, such as a session key generated randomly, and stored alongside active and future keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If system keys are changed regularly for security reasons, then security is improved, but access to stored content becomes unreliable when keys change

Engineering Contradiction:
Improveaccess reliabilityVSAvoidkey change impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by encrypting the event with multiple control words before storage, where each control word is associated with a different time period. This allows the content to be decrypted at any future time using the control word corresponding to that time period, even if system keys have changed since the original encryption.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If control words are decrypted and re-encrypted in the security unit during recording, then key lifetime issues are solved, but the security unit is heavily charged and rights may not yet be acquired

Engineering Contradiction:
Improvedecryption accessVSAvoidsecurity unit burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the decryption and re-encryption operation from the security unit by performing these operations in the user unit instead. The security unit only needs to verify rights and return control words, while the actual decryption and re-encryption with time-associated control words is done locally, reducing the burden on the security unit.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If encrypted content is stored without specific protection, then storage flexibility is improved, but authors' royalties cannot be collected if disk is duplicated

Engineering Contradiction:
Improvestorage flexibilityVSAvoidcontent protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the protection mechanism by associating different control words with different time periods. The content is encrypted with multiple control words (CW1, CW2, CW3) corresponding to different time windows. This allows flexible storage while maintaining protection, as each time period has its own encryption key, preventing unauthorized duplication across different time periods.

Inventive Principle:
Principle #1Segmentation

4Reliability

If rights are verified before control word return, then security is improved, but access fails when rights are acquired after storage

Engineering Contradiction:
Improvesecurity controlVSAvoidlate rights acquisition
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies dynamics by making the control word verification dynamic rather than static. Instead of verifying rights only at the moment of storage, the system verifies rights at the moment of playback using the time-associated control word. This allows users to acquire rights after storage, as long as they have the appropriate right for the time period when they want to access the content.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8082588B2Secured storage method of encrypted data on a personal digital recorder
Publication Date: 2011.12.20 NAGRAVISION SA
  • US8082588B2 patent drawing
  • US8082588B2 patent drawing

AI summary

The objective of the present invention is a storage method in a decoder of an event encrypted by control words that guarantees the access to this event at whichever moment, even if certain keys of the system have changed for security reasons. This objective is achieved by a storage method of an event encrypted by control words in a reception and decryption unit connected to a security unit, said control words and the necessary rights being contained in management messages encrypted by system keys, comprising storing the encrypted event as well as the control messages in the storage unit, and storing in the storage unit the system keys encrypted by a predefined local key stored in the security unit.