HDCP2.2 Router Transparent Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing HDCP2.2 repeaters incur significant resource overhead due to the need for decryption and re-encryption of encrypted data streams, which becomes redundant if the streams are only being routed without further manipulation.

Innovation Solution

A router design that authenticates with both the source and sink devices using the same session key and pseudo-random number, allowing encrypted data streams to be routed directly without decryption or re-encryption, thereby eliminating the need for multiple AES engines and reducing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If HDCP2.2 repeater decrypts and re-encrypts encrypted streams, then secure content protection is maintained, but computational resources and energy consumption increase significantly

Engineering Contradiction:
Improvecontent protection securityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the decryption and re-encryption operations from the repeater's functional requirements. Instead of performing these operations at the repeater, the system uses transparent routing where encrypted streams pass through the repeater unchanged, eliminating the need for AES engines in the repeater while maintaining security through authentication protocols.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication protocol as an intermediary mechanism between the source and repeater. This protocol establishes security credentials and session keys before data transmission, allowing the repeater to verify and forward encrypted streams without decrypting them, thus maintaining security without the computational overhead of decryption operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If HDCP2.2 repeater implements decryption and encryption functions, then encrypted streams can be routed securely, but device complexity increases due to multiple AES engines

Engineering Contradiction:
Improveencrypted stream securityVSAvoidnumber of AES engines
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent removes the decryption and encryption functionality from the repeater entirely. The repeater becomes a transparent router that forwards encrypted packets without processing them, eliminating the need for AES engines and significantly reducing device complexity while maintaining security through out-of-band authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the security functions from the routing functions. Authentication and key management are separated into a distinct protocol layer that operates independently from the data path, allowing the repeater to handle routing without implementing cryptographic operations.

Inventive Principle:
Principle #1Segmentation

3Reliability

If HDCP2.2 repeater processes encrypted streams through decryption and re-encryption, then content protection is maintained, but processing time and productivity decrease

Engineering Contradiction:
Improvecontent protection integrityVSAvoidstream routing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the time-consuming decryption and re-encryption operations from the data path. By implementing transparent routing where encrypted streams are forwarded without processing, the system eliminates the computational delay while maintaining security through pre-established authentication credentials.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs authentication and key exchange as preliminary actions before data transmission begins. This allows the repeater to establish security credentials in advance, enabling subsequent rapid forwarding of encrypted streams without the need for real-time decryption and re-encryption operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9509669B2Efficient routing of streams encrypted using point-to-point authentication protocol
Publication Date: 2016.11.29 UNIVERSAL CONNECTIVITY TECH INC
  • US9509669B2 patent drawing
  • US9509669B2 patent drawing
  • US9509669B2 patent drawing

AI summary

Embodiments relate to routing encrypted data from a source to a sink via a router without decrypting the data in the router. The source authenticates with the router, the result of which produces a session key and a pseudo-random number. The router authenticates with the sink using the same session key and pseudo-random number. The router passes encrypted data received from the source to the sink without decryption and re-encryption.