Nested Control Message Structure for Secure Audio Video Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for secure processing of access-controlled digital audio/video data are inefficient and slow due to lengthy rights verification and large control messages, which increase bandwidth requirements and calculation time, especially when the index value of control messages is high.
Innovation Solution
The method involves structuring a control message as a first part with access conditions and a second part encapsulating another control message, with both conditional access devices verifying access conditions sequentially before releasing the control word, using unique pairing keys for secure connection and cryptographic authentication to enhance security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If control messages are structured with high index values to enhance security, then security of control words is improved, but calculation time and bandwidth requirements increase
Solution Approach 1:
The control message is segmented into multiple parts (first part with access conditions, second part encapsulating another control message) with sequential verification by different conditional access devices. This segmentation allows the system to maintain high security through multiple verification layers while optimizing processing efficiency by distributing verification tasks across multiple devices rather than requiring sequential processing within a single device.
Solution Approach 2:
A control message is structured to encapsulate another control message within it, creating a nested structure where the second part of the first control message contains a complete second control message. This nesting reduces the overall bandwidth requirement by efficiently packing verification data while maintaining the security benefits of multiple verification stages.
2Reliability
If control messages are structured with high index values to enhance security, then security of control words is improved, but bandwidth requirements increase
Solution Approach 1:
The control message is segmented into multiple parts (first part with access conditions, second part encapsulating another control message) with sequential verification by different conditional access devices. This segmentation allows the system to maintain high security through multiple verification layers while optimizing processing efficiency by distributing verification tasks across multiple devices rather than requiring sequential processing within a single device.
Solution Approach 2:
A control message is structured to encapsulate another control message within it, creating a nested structure where the second part of the first control message contains a complete second control message. This nesting reduces the overall bandwidth requirement by efficiently packing verification data while maintaining the security benefits of multiple verification stages.
3Reliability
If multiple conditional access devices verify access conditions sequentially, then security of control words is reinforced, but device complexity increases
Solution Approach 1:
The control message is segmented into multiple parts (first part with access conditions, second part encapsulating another control message) with sequential verification by different conditional access devices. This segmentation allows the system to maintain high security through multiple verification layers while optimizing processing efficiency by distributing verification tasks across multiple devices rather than requiring sequential processing within a single device.
Data Source
Figure 1~2
Figure 3
AI summary
A method based on access conditions verification performed by two conditional access devices consecutively on a control message before releasing a control word and forwarding it to a descrambler. The control message is structured so that it encapsulates another control message. The processing unit for carrying out the method comprises a first conditional access device connected to a second conditional access device provided with a descrambler and a secured processor or secured hardware logic. The processing unit is configured for receiving control messages comprising at least a first part containing first access conditions and a second part structured as a control message containing second access conditions and a control word. The control message and the second part are each encrypted and accompanied by respectively first and second authentication data. The first conditional access device decrypts and verifies integrity of the control message, verifies the first access conditions and transmits the second part of the control message to the second access control device when the verification of the first access conditions is successful. The second conditional access device decrypts and verifies integrity of the second part and further verifies the second access conditions, releases and loads the control word into the descrambler when the verification of the second access conditions is successful. The descrambler descrambles the audio/video data with the control word and forwards said data in clear to an appropriate output of the processing unit.