Headend Packer Encryption for Card Sharing Frustration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing conditional access systems in broadcast/multicast media environments are vulnerable to 'card sharing' schemes, where hackers distribute control words to allow non-paying users to access encrypted content, and current methods to thwart this, such as delaying control word delivery, can be circumvented by sophisticated buffering systems.

Innovation Solution

The system encrypts packet IDs in media streams, using mapping tables and encryption engines to ensure only paying users can correctly identify and filter desired channels in real-time, while non-paying users are forced to buffer all channels, increasing complexity and cost for hacking systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If control word delivery is delayed to frustrate card sharing, then security against unauthorized access is improved, but user convenience deteriorates due to additional delay in content access

Engineering Contradiction:
Improvesecurity against card sharingVSAvoiddelay in control word delivery
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the control word delivery process into two distinct phases: a preliminary phase where control words are made available to authorized devices, and a playback phase where they are activated at the precise moment needed. This segmentation allows the system to maintain security while eliminating unnecessary delays for legitimate users, as the control words are already prepared but not yet activated for unauthorized devices to utilize.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary action by pre-distributing control words to authorized end-user devices before the actual content playback occurs. This allows authorized users to have immediate access when content is transmitted, while the control words remain inactive or untransferable to unauthorized devices until the precise moment of playback, thus preventing card sharing without delaying legitimate access.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If sophisticated buffering systems are used to circumvent control word delays, then unauthorized access capability is improved, but system complexity and cost increase

Engineering Contradiction:
Improveunauthorized access capabilityVSAvoidbuffering system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary anti-action by implementing a timing mechanism that prevents the transfer of control words to unauthorized devices before the playback moment. The control words are designed to become active or transferable only at the precise moment of content playback, which prevents unauthorized devices from buffering and playing content without requiring complex buffering systems. The anti-action is built into the fundamental timing of control word activation rather than requiring additional buffering infrastructure.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If packet IDs are encrypted to prevent channel identification, then security against unauthorized access is improved, but ease of operation for legitimate users must be maintained through proper key distribution

Engineering Contradiction:
Improvechannel identification securityVSAvoidchannel filtering operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary mechanism in the form of a mapping table that translates encrypted packet IDs back to their original identifiers for authorized devices. This intermediary allows the system to maintain encrypted packet IDs for security while providing authorized users with the necessary decryption capability through the mapping table, ensuring smooth channel identification and filtering operations without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameter state of packet IDs from encrypted to decrypted form for authorized operations. By dynamically changing the encryption state of packet IDs based on user authorization status, the system maintains security for unauthorized access while ensuring ease of operation for legitimate users who can properly decrypt and filter channels using their authorized keys and mapping tables.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10205707B2Content consumption frustration
Publication Date: 2019.02.12 SYNAMEDIA LTD
  • US10205707B2 patent drawing
  • US10205707B2 patent drawing
  • US10205707B2 patent drawing

AI summary

A Headend system including a packer to pack media content into a plurality of packets including a first packet and a second packet, a packet scheduler to schedule when the packets will be broadcast/multicast to a plurality of end-user devices, and calculate a plurality of timing values including a first timing value which provides an indication of how long the second packet will arrive at the end-user devices after the arrival of the first packet at the end-user devices, and an encryption engine to: encrypt the media content of the packets and the timing values, wherein the media content of the first packet and the first timing value are encrypted by different encryption algorithms, or the same encryption algorithm with different cryptographic keys.