Secure Audio Video Decryption Modules for Pay-TV Piracy Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Control word sharing piracy remains a challenge in Pay-TV systems, where unauthorized users access encrypted content by sharing control words, making it difficult to distinguish legitimate from fraudulent use without channel identifiers, and existing methods are inefficient in preventing the sharing of control words for decrypting both audio and video content.

Innovation Solution

A method and system that condition video and audio content decryption on user rights verification by primary and secondary secure devices, using non-standard encryption for audio content and watermarking, ensuring that shared control words are useless for decrypting audio content, and re-encrypting watermarked audio data with a unique key specific to the receiver.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If control words are transmitted to user units for decrypting encrypted audio/video data, then legitimate users can access the content, but unauthorized users can also intercept and share these control words to access content without paying

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the decryption process into two separate security modules: a first secure module that verifies user rights and extracts control words for video decryption, and a second secure module that verifies rights and extracts control words for audio decryption. This segmentation ensures that even if one control word is compromised, the other remains protected, preventing unauthorized access to complete content.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different encryption algorithms to video and audio content locally. Video content is decrypted using control words extracted by the first secure module, while audio content is decrypted using control words extracted by the second secure module with a different algorithm. This local differentiation in security approach makes it difficult for pirates to obtain both control words simultaneously.

Inventive Principle:
Principle #3Local quality

2Device complexity

If the same control word is used for both audio and video decryption, then the system is simpler to implement, but it becomes vulnerable to control word sharing piracy

Engineering Contradiction:
Improvesystem complexityVSAvoidanti-piracy capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the control word generation and verification process into two independent secure modules, each handling either video or audio decryption. This prevents a single control word from being used for both audio and video, thereby eliminating the vulnerability to control word sharing while maintaining manageable system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of security by using two different cryptographic algorithms (first and second algorithms) for video and audio decryption respectively. This dimensional addition in the security space ensures that compromising one algorithm does not compromise the other, enhancing anti-piracy capability without significantly increasing overall system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If control words are transmitted frequently to ensure continuous content access, then content availability is improved, but the risk of interception and sharing increases

Engineering Contradiction:
Improvecontent access continuityVSAvoidinterception risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

By segmenting the decryption into two independent secure modules with different algorithms, the patent reduces the interception risk even when control words are transmitted frequently. Pirates would need to intercept both control words simultaneously through two different security mechanisms, which is significantly more difficult than intercepting a single control word, thus maintaining content access continuity while reducing vulnerability.

Inventive Principle:
Principle #1Segmentation

4Device complexity

If a single secure module handles both audio and video decryption, then the device is less complex, but it cannot prevent control word extraction and sharing

Engineering Contradiction:
Improvemodule quantityVSAvoidcontrol word protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements segmentation by creating two separate secure modules: a first secure module for video decryption and a second secure module for audio decryption. Each module independently verifies user rights and extracts control words using different cryptographic algorithms. This segmentation prevents control word extraction and sharing because pirates would need to compromise both secure modules simultaneously, which is significantly more difficult than compromising a single module.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by using different cryptographic algorithms in different secure modules. The first secure module uses a first cryptographic algorithm for video, while the second secure module uses a second cryptographic algorithm for audio. This local differentiation in security approach ensures that even if one module is compromised, the other remains secure, thereby protecting control words without requiring an overly complex system architecture.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2802152B1Method for secure processing a stream of encrypted digital audio / video data
Publication Date: 2017.07.05 NAGRAVISION SA
  • EP2802152B1 patent drawingFigure 1
  • EP2802152B1 patent drawingFigure 2

AI summary

A method and a system is disclosed to prevent control words sharing by extracting the control words from a receiver and making them available to other users via Internet for example. The system comprises a receiver (STB) capable to process a digital data stream (ST). The receiver (STB) having a video descrambler device (VDD) is coupled to a primary and a secondary secure device (SD1, SD2). The digital data stream (ST) comprises video content data (VI) scrambled with a first algorithm using a control word (CW), audio content data (AU) encrypted with a secrete second algorithm using a system key (KS) and encrypted control messages (ECM) comprising the control word (CW). The receiver (STB) transmits the control message (ECM) to the primary secure device (SD1) which decrypts the control message (ECM) and obtains the control word (CW). The video descrambler device (VDD) uses then the control word (CW) to descramble the video content data (VI). The secondary secure device (SD2) comprises a decryption device (DEC) which decrypts, with the secrete second algorithm by using the system key (KS), the encrypted audio content data (AU)KS received from the receiver (STB) and a watermarking module (WM) configured to add a watermark to the decrypted audio content data (AU) and to return watermarked decrypted audio content data (AU'WM) to the receiver (STB). The receiver (STB) outputs to a display device (TV) the descrambled video content data (VI) and the watermarked decrypted audio content data (AU'WM) provided by the secondary secure device (SD2).