HDCP2.2 Router Transparent Routing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing HDCP2.2 repeaters incur significant resource overhead due to the need for decryption and re-encryption of encrypted data streams, which becomes redundant if the streams are only being routed without further manipulation.
Innovation Solution
A router design that authenticates with both the source and sink devices using the same session key and pseudo-random number, allowing encrypted data streams to be routed directly without decryption or re-encryption, thereby eliminating the need for multiple AES engines and reducing resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If HDCP2.2 repeater decrypts and re-encrypts encrypted streams, then secure content protection is maintained, but computational resources and energy consumption increase significantly
Solution Approach 1:
The patent extracts the decryption and re-encryption operations from the repeater's functional requirements. Instead of performing these operations at the repeater, the system uses transparent routing where encrypted streams pass through the repeater unchanged, eliminating the need for AES engines in the repeater while maintaining security through authentication protocols.
Solution Approach 2:
The patent introduces an authentication protocol as an intermediary mechanism between the source and repeater. This protocol establishes security credentials and session keys before data transmission, allowing the repeater to verify and forward encrypted streams without decrypting them, thus maintaining security without the computational overhead of decryption operations.
2Reliability
If HDCP2.2 repeater implements decryption and encryption functions, then encrypted streams can be routed securely, but device complexity increases due to multiple AES engines
Solution Approach 1:
The patent removes the decryption and encryption functionality from the repeater entirely. The repeater becomes a transparent router that forwards encrypted packets without processing them, eliminating the need for AES engines and significantly reducing device complexity while maintaining security through out-of-band authentication.
Solution Approach 2:
The patent segments the security functions from the routing functions. Authentication and key management are separated into a distinct protocol layer that operates independently from the data path, allowing the repeater to handle routing without implementing cryptographic operations.
3Reliability
If HDCP2.2 repeater processes encrypted streams through decryption and re-encryption, then content protection is maintained, but processing time and productivity decrease
Solution Approach 1:
The patent extracts the time-consuming decryption and re-encryption operations from the data path. By implementing transparent routing where encrypted streams are forwarded without processing, the system eliminates the computational delay while maintaining security through pre-established authentication credentials.
Solution Approach 2:
The patent performs authentication and key exchange as preliminary actions before data transmission begins. This allows the repeater to establish security credentials in advance, enabling subsequent rapid forwarding of encrypted streams without the need for real-time decryption and re-encryption operations.
Data Source
AI summary
Embodiments relate to routing encrypted data from a source to a sink via a router without decrypting the data in the router. The source authenticates with the router, the result of which produces a session key and a pseudo-random number. The router authenticates with the sink using the same session key and pseudo-random number. The router passes encrypted data received from the source to the sink without decryption and re-encryption.


