Multiport Content Encryption Engine for Shared Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing content protection systems in multimedia devices require complex processing for each port or channel independently, leading to inefficiencies as content protection standards evolve, necessitating a method to share processing across multiple ports.
Innovation Solution
A method involving authentication to create shared key and initialization vector pairs for ciphering protected content across multiple channels, using an Advanced Encryption Standard process to generate key streams, and maintaining buffers for each channel to efficiently cipher data, allowing for the combination of processing across multiple ports.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If independent content protection processing is performed for each port or channel, then content security is maintained, but processing complexity and computational overhead increase significantly
Solution Approach 1:
The patent combines multiple independent content protection processing units into a single shared processing unit. Multiple ports/channels share the same encryption engine, key management system, and processing resources. This merging approach maintains security by implementing authentication and key exchange for each channel while reducing overall system complexity and computational overhead through resource sharing.
Solution Approach 2:
The patent creates a universal content protection processing unit that can serve multiple different ports and channels simultaneously. The single processing unit is designed to handle authentication, key management, and encryption/decryption operations for various channels, making the system more efficient while maintaining the security requirements for each individual channel.
2Reliability
If separate authentication and key exchange processes are performed for each channel, then security is ensured, but processing time and computational resources increase
Solution Approach 1:
The patent performs authentication and key exchange processes in advance during system initialization or connection setup. Once authenticated, the security parameters and key streams are pre-generated and stored in buffers for each channel. This preliminary action ensures that when actual content protection is needed, the processing time is minimized while security requirements are fully met.
Solution Approach 2:
The patent maintains continuous key streams in buffers for each channel, prepared in advance through authentication processes. This allows the encryption/decryption operations to proceed continuously without repeated authentication overhead, reducing processing time while maintaining security through the pre-established cryptographic parameters.
3Reliability
If multiple independent encryption engines are deployed for multiple ports, then channel-specific security is maintained, but system resource consumption and device complexity increase
Solution Approach 1:
The patent merges multiple independent encryption engines into a single shared encryption unit that serves multiple ports and channels. This unified approach reduces the total computational resources required while maintaining channel-specific security through separate authentication and key management for each channel. The shared engine efficiently processes encryption/decryption operations for multiple channels without requiring duplicate hardware or software instances.
Data Source
AI summary
A method for ciphering protected content communicated between a first device and a plurality of devices over a plurality of channels comprises performing authentication between the first device and each of the plurality of devices to create two or more shared key and initialization vector pairs allowing the ciphering of the protected content; generating a key stream for each of the channels based on a selected one of the two or more of shared key and initialization vector pairs; maintaining a buffer for each channel, each of the buffer containing the key stream generated for the corresponding channel; and ciphering data incoming on a selected channel using the selected key stream from the buffer corresponding to the selected channel.


