Key Provisioning Application for Home Network Content Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing content receivers face difficulties in accessing encrypted content due to fixed CA client software that is hard to update and the need for simultaneous support of multiple Digital Rights Management (DRM) and Conditional Access (CA) systems, which complicates the distribution of decryption keys and smart card upgrades.

Innovation Solution

A method involving a key provisioning application executed on a device within the home network that receives a key provisioning message to derive and provide content decryption keys to the content receiver, allowing access to encrypted content through the home network, using cryptographic keys and protocols like DLNA/UPnP for communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a fixed CA client software is used in content receivers, then the system structure is simple and easy to implement, but the software is difficult to update and cannot easily support multiple DRM and CA systems

Engineering Contradiction:
Improvesupport for multiple DRM and CA systemsVSAvoidsystem structure complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a key provisioning application as an intermediary component that runs on a separate device (such as a set-top box or server) and communicates with the content receiver. This intermediary handles the complexity of key management and provisioning for multiple DRM and CA systems, while the content receiver itself maintains a simpler structure. The key provisioning application acts as a mediator between the content receiver and the various key management systems, resolving the contradiction by centralizing complexity in the intermediary rather than in the receiver.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the key management functionality into separate components: the key provisioning application on a provisioning device and the key usage functionality on the content receiver. This segmentation allows the receiver to remain simple while the provisioning device handles the complexity of supporting multiple systems. The segmentation enables independent updates and maintenance of the provisioning logic without requiring changes to the receiver hardware or firmware.

Inventive Principle:
Principle #1Segmentation

2Reliability

If smart card upgrades are implemented in content receivers, then security can be improved, but the upgrade process is complex and difficult to distribute

Engineering Contradiction:
Improvesecurity levelVSAvoiddistribution and upgrade ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent uses copying by allowing the key provisioning application to be distributed and executed on various provisioning devices throughout the network. Instead of physically upgrading smart cards in each receiver, the key provisioning functionality is copied to multiple devices that can then provision keys to receivers. This digital copying approach makes distribution easy while maintaining security through proper key management protocols.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The key provisioning application serves as an intermediary that simplifies the upgrade process. Rather than directly modifying or replacing smart cards in receivers (which would be complex), the intermediary provisioning application handles key generation, encryption, and distribution. This intermediary layer abstracts the complexity of security upgrades and makes them easier to distribute and implement across the network.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If decryption keys are distributed through traditional CA systems, then security is maintained, but the key distribution process is complex and requires fixed infrastructure

Engineering Contradiction:
Improvekey distribution simplicityVSAvoidkey distribution infrastructure
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent introduces dynamics by allowing the key provisioning application to be flexibly deployed on various devices (set-top boxes, servers, or other provisioning devices) rather than requiring a fixed infrastructure. The system can dynamically adapt to different network configurations and device capabilities. The key provisioning application can be updated, moved, or scaled as needed, providing operational simplicity while avoiding the rigidity of fixed key distribution infrastructure.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The key provisioning application is designed to be universal, capable of supporting multiple DRM and CA systems through a single unified interface. This multi-functional application can provision keys for different content protection systems without requiring separate infrastructure for each system. The universality of the provisioning application simplifies key distribution operations while reducing the overall infrastructure complexity by consolidating multiple functions into a single versatile component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2979419B1Enabling a content receiver to access encrypted content
Publication Date: 2021.10.13 IRDETO BV
  • EP2979419B1 patent drawingFigure 1~2
  • EP2979419B1 patent drawingFigure 3
  • EP2979419B1 patent drawingFigure 4~6

AI summary

There is described a method of enabling a content receiver to access encrypted content, the content receiver forming part of a home network. The method comprises executing, on a device that also forms part of the home network, a key provisioning application. The method further comprises the key provisioning application receiving a key provisioning message and, based on the key provisioning message, providing to the content receiver via the home network one or more content decryption keys for decrypting the encrypted content. There is also described a device arranged to carry out this method. In addition, there is described a content receiver arranged to (a) receive from the aforementioned device, via a home network, one or more content decryption keys for accessing encrypted content; and (b) decrypt encrypted content using the one or more content decryption keys. Related computer programs and computer readable mediums are also described.