PUF Circuit Key Offset for Secure Media Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In subscription-based media systems, the interface between the smartcard and decoder box is vulnerable to attacks, and updating service keys for multiple subscribers requires significant bandwidth, posing challenges in secure content delivery.

Innovation Solution

Implementing a physically unclonable function (PUF) circuit that generates a unique manufacturing-based signature, used to create a key offset for decryption, which is stored temporarily and used to facilitate media content decryption, thereby enhancing security and reducing bandwidth requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual packets are sent to every subscriber when service keys are updated, then key distribution is achieved, but transmission bandwidth required becomes prohibitive

Engineering Contradiction:
Improvekey distributionVSAvoidtransmission bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent combines multiple subscriber-specific key distribution operations into a single broadcast transmission. By merging the key distribution function with regular program content transmission and using a common Service Key for multiple subscribers, the system achieves efficient key distribution without requiring individual packet transmissions to each subscriber.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The Service Key is designed to serve multiple functions simultaneously: it encrypts program content for multiple subscribers and distributes update keys to all entitled subscribers through a single broadcast channel. This multi-functional approach eliminates the need for separate key distribution channels for each subscriber.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If the interface between smartcard and decoder box is used for key delivery, then conditional access is enabled, but vulnerability to attacks increases

Engineering Contradiction:
Improveconditional accessVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements control words with extremely short lifetimes (e.g., 10 seconds) that are continuously renewed. This disposable approach ensures that even if the smartcard-decoder interface is compromised, attackers can only access keys for very limited time windows, rendering long-term exploitation impractical.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system employs periodic renewal of control words and service keys through regular broadcast transmissions. This periodic key rotation creates multiple short-lived access windows, reducing the effectiveness of any single point of compromise at the smartcard-decoder interface.

Inventive Principle:
Principle #19Periodic action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The PUF-based approach makes smartcards resistant to cloning and reduces bandwidth needs by using short-lived keys, ensuring secure and efficient decryption of media content across multiple subscribers.

Implementation Method 1

an output is generated, the output being indicative of an unclonable characteristic of the PUF circuit

Methodology Applied
Scientific EffectManufacturing variations:

Data Source

PatentUS8983067B2Cryptographic circuit and method therefor
Publication Date: 2015.03.17 NXP BV
  • US8983067B2 patent drawing
  • US8983067B2 patent drawing
  • US8983067B2 patent drawing

AI summary

Data security is facilitated. In accordance with one or more embodiments, a target circuit is used to generate encryption information specific to the target circuit. The encryption information is used for generating data corresponding to a key, such as for decrypting media content. In some implementations, encryption information is used together with key data to generate a key offset. The key offset is subsequently used, together with newly-generated encryption information, to obtain the key.