Local Area Network Security via Master and User Modules
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for secure local area networks connected to conditional access data streams face challenges such as network key vulnerability, difficulty in extending the network, and potential disruption due to loss or damage of the parent security module.
Innovation Solution
A method for creating and managing a local area network involving a master security module that establishes and securely transmits a network key to user modules, ensuring encrypted data processing within the network, with features like session key generation and re-encryption, and a converter module for decrypting and re-encrypting data based on access rights.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single parent module is used to manage network key distribution, then network security is maintained through centralized control, but the system becomes vulnerable to disruption if the parent module is lost or damaged
Solution Approach 1:
The patent segments the parent module functionality into two separate components: a secure element that stores the network key and a processor that handles key distribution operations. This segmentation allows the network to maintain security while enabling flexible extension, as the secure element can remain stationary while multiple processors can be added or removed without compromising the stored network key.
Solution Approach 2:
The patent introduces a secure element as an intermediary between the network key storage and the key distribution process. This secure element acts as a protected mediator that stores the network key in a tamper-resistant manner while allowing authorized processors to request and receive key distribution capabilities, thereby maintaining security while enabling network extension.
2Reliability
If the network key is stored in a removable smart card, then security is improved through physical protection, but the network can be interrupted if the card is lost or separated
Solution Approach 1:
The patent implements a nested structure where the network key is stored within a secure element that is embedded within the set-top box or receiver device. This nesting provides physical protection similar to a removable card while eliminating the risk of loss or separation, as the secure element remains permanently integrated within the device housing.
Solution Approach 2:
The patent combines the secure element with the processor in a single integrated security module, merging the key storage and processing functions into one protected unit. This integration maintains the security benefits of physical protection while ensuring the network key remains continuously available for network extension operations without risk of separation.
3Adaptability or versatility
If multiple modules share the same network key, then network accessibility is improved, but security is weakened due to potential unauthorized access from neighboring networks
Solution Approach 1:
The patent applies local quality by encrypting data with unique session keys that are specific to each local network instance. While multiple modules within the same network share the network key for accessibility, each data transmission is protected by a locally-generated session key, providing localized security that maintains both network accessibility and data protection.
Solution Approach 2:
The patent changes the encryption parameter from a static network key to dynamic session keys that are generated and distributed within the network. This parameter change allows multiple modules to access the network using the same network key while maintaining security through unique, time-limited session keys for each data transmission, preventing unauthorized access from neighboring networks.
Data Source
AI summary
The present invention relates to a method for creating and managing a local area network including at least one device for reproducing an encrypted data flow and a device for transmitting and re-encrypting all or part of said encrypted data, which devices include security modules. The method includes the steps of connecting a so-called master security module in one of the devices connected to the local area network, causing the master security module to generate a network key, securely transmitting the network key to one or more so-called user security modules, decrypting the data encrypted by the transmission and re-encryption device, re-encrypting the data with said device by means of a local key, transmitting the re-encrypted data to the reproduction device, and holding the reproduction device to perform decryption using the user security module associated therewith and provided with means for locating the local key.

