Local Area Network Security via Master and User Modules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for secure local area networks connected to conditional access data streams face challenges such as network key vulnerability, difficulty in extending the network, and potential disruption due to loss or damage of the parent security module.

Innovation Solution

A method for creating and managing a local area network involving a master security module that establishes and securely transmits a network key to user modules, ensuring encrypted data processing within the network, with features like session key generation and re-encryption, and a converter module for decrypting and re-encrypting data based on access rights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single parent module is used to manage network key distribution, then network security is maintained through centralized control, but the system becomes vulnerable to disruption if the parent module is lost or damaged

Engineering Contradiction:
Improvenetwork securityVSAvoidnetwork extension
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the parent module functionality into two separate components: a secure element that stores the network key and a processor that handles key distribution operations. This segmentation allows the network to maintain security while enabling flexible extension, as the secure element can remain stationary while multiple processors can be added or removed without compromising the stored network key.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure element as an intermediary between the network key storage and the key distribution process. This secure element acts as a protected mediator that stores the network key in a tamper-resistant manner while allowing authorized processors to request and receive key distribution capabilities, thereby maintaining security while enabling network extension.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the network key is stored in a removable smart card, then security is improved through physical protection, but the network can be interrupted if the card is lost or separated

Engineering Contradiction:
ImprovesecurityVSAvoidnetwork extension
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a nested structure where the network key is stored within a secure element that is embedded within the set-top box or receiver device. This nesting provides physical protection similar to a removable card while eliminating the risk of loss or separation, as the secure element remains permanently integrated within the device housing.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent combines the secure element with the processor in a single integrated security module, merging the key storage and processing functions into one protected unit. This integration maintains the security benefits of physical protection while ensuring the network key remains continuously available for network extension operations without risk of separation.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If multiple modules share the same network key, then network accessibility is improved, but security is weakened due to potential unauthorized access from neighboring networks

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by encrypting data with unique session keys that are specific to each local network instance. While multiple modules within the same network share the network key for accessibility, each data transmission is protected by a locally-generated session key, providing localized security that maintains both network accessibility and data protection.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the encryption parameter from a static network key to dynamic session keys that are generated and distributed within the network. This parameter change allows multiple modules to access the network using the same network key while maintaining security through unique, time-limited session keys for each data transmission, preventing unauthorized access from neighboring networks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7725720B2Method for generating and managing a local area network
Publication Date: 2010.05.25 NAGRAVISION SA
  • US7725720B2 patent drawing
  • US7725720B2 patent drawing

AI summary

The present invention relates to a method for creating and managing a local area network including at least one device for reproducing an encrypted data flow and a device for transmitting and re-encrypting all or part of said encrypted data, which devices include security modules. The method includes the steps of connecting a so-called master security module in one of the devices connected to the local area network, causing the master security module to generate a network key, securely transmitting the network key to one or more so-called user security modules, decrypting the data encrypted by the transmission and re-encryption device, re-encrypting the data with said device by means of a local key, transmitting the re-encrypted data to the reproduction device, and holding the reproduction device to perform decryption using the user security module associated therewith and provided with means for locating the local key.