Master Device Verification Table for Home Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for managing revocation lists in digital data protection, particularly in broadcasting environments, face challenges such as high bandwidth consumption and inefficiency in pay-TV applications, where traditional negative lists become unmanageable due to piracy, and require more secure and efficient mechanisms to authenticate and authorize devices within a home network.

Innovation Solution

A method involving the broadcasting of a verification table containing a list of certificate identifiers, allowing the master device to activate or deactivate target devices based on content-specific verification indications, using either positive or negative lists, with the option to transmit a positive list individually to each receiver for secure authentication, reducing bandwidth usage and improving manageability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional negative lists are used to manage revoked certificates in broadcasting environments, then security against piracy is improved, but bandwidth consumption increases and manageability deteriorates when the list becomes large

Engineering Contradiction:
Improvesecurity against piracyVSAvoidbandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the revocation list management by separating the broadcast transmission of certificate validation data from the local verification process. The master device receives segmented certificate data and verification rules from the broadcast, then performs local verification against target devices. This segmentation reduces the need to continuously transmit large revocation lists over the broadcast network, thereby reducing bandwidth consumption while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by pre-distributing verification rules and reference certificate data to master devices through broadcast before actual verification is needed. The master device is pre-configured with verification capabilities and reference data, enabling it to perform local verification without requiring real-time transmission of large revocation lists, thus reducing bandwidth consumption during operation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional negative lists are used to manage revoked certificates, then security against piracy is improved, but the complexity of managing large lists deteriorates

Engineering Contradiction:
Improvesecurity against piracyVSAvoidmanageability of revocation lists
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent inverts the traditional approach by having the master device perform verification against pre-distributed reference data rather than maintaining and managing large local revocation lists. The verification burden is shifted from list management to comparison against broadcast-provided reference certificates, simplifying the master device's management tasks while maintaining security through the broadcast authority's centralized list management.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If certificate verification is performed for all content, then security is improved, but processing time and system complexity increase

Engineering Contradiction:
ImprovesecurityVSAvoidverification processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies partial action by performing verification only when necessary - specifically when the broadcast indication signals that verification is required for the current content. The master device checks the verification indication associated with each content item and only initiates verification processes when flagged, avoiding unnecessary verification overhead for content that does not require it, thus reducing processing time while maintaining security where needed.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP1946551B1Method for verifying a target device connected to a master device
Publication Date: 2010.04.14 NAGRAVISION SA
  • EP1946551B1 patent drawingFigure 1

AI summary

The invention concerns various methods for distributing and managing revocation lists associated with anti-copy protection standards, so as to facilitate processing thereof in a television broadcasting environment while guaranteeing security against piracy of the receiver equipment and equipment connected to said television broadcasting receiver within a home network. This is achieved by a method for verifying a target device connected to a master device, the latter being provided with means for receiving a content transmitted by a broadcasting center via a data stream, the master device and the target device being authenticated by exchanging a certificate including at least one certificate identifier, said method including the following steps: a) transmitting by television broadcasting at least one target device verifying table containing a list of certificate identifier, b) storing said list in the master device, c) extracting a verifying indication associated with the content, said indication including enabling or disabling the verification of the target device, d) if the verifying indication includes enabling the verification, verifying the certificate of the target device via the master device, using at least one stored list to authorize or prohibit data exchange with the target device.