Multimedia Unit Re-encryption for Secure Network Content Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital domestic networks face issues where stored audio/video content can no longer be decrypted due to outdated rights in security modules, and there is a risk of improper copying of content between networks.

Innovation Solution

A method where encrypted content is re-encrypted with a random key and transmitted with an authorization block containing the random key encrypted with a network key, allowing decryption by members of the network independently of time elapsed and preventing unauthorized copying by using a security module with the network key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If content is stored with original encryption keys, then initial decryption works, but content becomes inaccessible after rights update

Engineering Contradiction:
Improvecontent accessibilityVSAvoidtime elapsed between storage and reading
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary re-encryption of the content with updated control words at the time of storage. When content is recorded, it is re-encoded using current control words extracted from ECM messages, and an authorization block containing these control words is generated and stored alongside the content. This preliminary action ensures that when the content is later read, the control words are already available in the authorization block, eliminating the time-related accessibility problem.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authorization block serves as an intermediary between the encrypted content and the decoder. It contains the control words and ECM messages that mediate the decryption process. Instead of relying on the decoder to obtain control words from external sources at playback time, the authorization block provides them directly, acting as a self-contained intermediary that resolves the time delay issue.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If content is re-encoded with current control words, then future accessibility is ensured, but network security is compromised

Engineering Contradiction:
Improvecontent accessibilityVSAvoidunauthorized copying
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system applies different quality levels of encryption to different parts of the content distribution system. Content transmitted over the network is encrypted with a network-specific key, while the authorization block contains control words that are specific to individual decoders or decoder groups. This local differentiation ensures that even if content is intercepted, it cannot be decoded without the specific authorization block, and the network key prevents unauthorized access to the content stream itself.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses asymmetric encryption characteristics where the network key and control words are structured differently and serve different purposes. The network key is used for content protection during transmission and storage, while control words are used for decoder-specific authorization. This asymmetry ensures that compromising one layer does not automatically compromise the other, providing layered security against unauthorized copying.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS7769171B2Method for transmitting digital data in a local network
Publication Date: 2010.08.03 NAGRAVISION SA
  • US7769171B2 patent drawing
  • US7769171B2 patent drawing
  • US7769171B2 patent drawing

AI summary

An aim to reach may be on one hand, to allow the reading of a content stored by a digital video recorder from a decoder of the local network regardless of the time elapsed between storage and reading, and on the other hand to prevent the transfer or improper copying of the content stored from one network to another. An aim may be achieved by a method of an embodiment, for transmitting digital data in a local network including members constituted by at least one first multimedia unit having a content storage device and at least one second multimedia unit intended to restore the content. The first multimedia unit may be connected, on one hand, to a broadcasting server of encrypted digital audio/video data and on the other hand to the second multimedia unit, each member possessing a security module including a network key. The first multimedia unit receives and decrypts the encrypted data forming a content broadcasted by the broadcasting server and re-encrypts the content previously decrypted. The method of an embodiment may include steps wherein the content is re-encrypted with a random key and transmitted to the second multimedia unit accompanied by an authorization block including the random key encrypted with the network key, the second multimedia unit decrypts the authorization block, and extracts the random key to be used for decrypting the content.