Pay-TV Decoder Security Module Origin Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Pay-TV operators face challenges in tracing and preventing unauthorized redistribution of encrypted content due to control word sharing, which affects revenue and bandwidth efficiency in existing conditional access systems.

Innovation Solution

The method involves duplicating an elementary stream in a pay-TV service, encrypting it with a unique control word, and using a security module to select and transmit the appropriate control word for decryption, allowing for identification of the security module's origin and reducing bandwidth impact by only duplicating streams during suspicious activity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If multiple encodings of the same content are broadcast to identify traitor receivers, then the ability to trace unauthorized receivers is improved, but the broadcast bandwidth efficiency deteriorates

Engineering Contradiction:
Improvereceiver identification accuracyVSAvoidbroadcast bandwidth efficiency
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The system dynamically switches between single encoding and multiple encodings based on detected suspicious activities. When control word sharing is detected, the system activates multiple encodings with different identification markers for a limited period to trace the pirate receiver, then returns to single encoding to conserve bandwidth. This dynamic adaptation resolves the contradiction by applying multiple encodings only when necessary.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements periodic monitoring of receiver behavior and periodically evaluates whether multiple encodings are needed. Instead of continuously broadcasting multiple encodings, the system uses periodic detection cycles to identify suspicious receivers, applies multiple encodings during detected threat periods, and switches back to single encoding during normal operation, thus maintaining bandwidth efficiency while preserving traceability capability.

Inventive Principle:
Principle #19Periodic action

2Measurement precision

If stream duplication is performed continuously to enable security module identification, then the identification capability is improved, but the bandwidth consumption increases

Engineering Contradiction:
Improvesecurity module origin identificationVSAvoidbandwidth consumption
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system dynamically controls stream duplication based on real-time detection of control word sharing activities. During normal operation, only single encoding is used. When suspicious activities are detected, the system activates stream duplication with unique identifiers embedded in the duplicated streams, allowing identification of the security module origin. The duplication is deactivated after the identification period, thus achieving identification capability without continuous bandwidth overhead.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system prepares identification mechanisms in advance by embedding unique identifiers in the stream duplication structure, but only activates the duplication process when control word sharing is detected. This preliminary preparation allows rapid response to piracy attempts while avoiding the bandwidth consumption that would result from continuous duplication, resolving the contradiction between identification capability and bandwidth usage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10419800B2Method to identify the origin of a security module in pay-TV decoder system
Publication Date: 2019.09.17 NAGRAVISION SA
  • US10419800B2 patent drawing

AI summary

A method to identify the origin of a security module in a pay-tv system comprising: receiving by the pay-tv decoder system at least a first stream, a second stream and a control word stream, the first and second streams being encrypted by a first and a second control word, respectively, extracting from the control word stream, entitlement messages containing a main control word allowing retrieval of the first and second control words and access conditions, transferring the control word stream to the security module and checking the access conditions, selecting a current control word from the first or second control word based on part of the internal parameter, transmitting the current control word to the pay-tv decoder, selecting a current stream from the first or second stream in accordance with the selection of the first or second control word, and decrypting the current stream with the current control word.