Secure Conditional Access Software Download System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional media program stream delivery systems lack standardization in encryption/decryption and compression/decompression technologies, leading to high costs and difficulties in upgrading, which restricts innovation and customer satisfaction, and limits media service providers' ability to improve or add new services.

Innovation Solution

A system and method for securely downloading and reconfiguring conditional access software, Digital Rights Management software, and Gaming Security Software using a specialized entitlement management message and supervisory logon key, enabling authentication between sender and receiver security devices, and supporting multiple security systems and processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional fixed and proprietary encryption/decryption technologies are used, then vendor-specific security is maintained, but upgrading and standardization become expensive and difficult

Engineering Contradiction:
ImprovesecurityVSAvoidupgrading capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security by allowing the receiver security device to download and execute new security software updates remotely. The system transitions from static proprietary security to a dynamic architecture where security algorithms can be updated, renewed, and reconfigured without hardware replacement, enabling vendors to respond to security threats and implement standardization while maintaining reliability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security system is segmented into separate functional components: the receiver security device, the sender security server, and the download mechanism. This segmentation allows independent updates of security software without affecting the entire system, enabling standardized security protocols to be deployed while maintaining vendor-specific implementations where needed.

Inventive Principle:
Principle #1Segmentation

2Reliability

If proprietary encryption/decryption technologies are used, then vendor-specific security control is maintained, but competition and innovation are restricted

Engineering Contradiction:
Improvesecurity controlVSAvoidservice delivery flexibility
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The receiver security device is designed with universal capabilities to support multiple security systems and algorithms through remote downloads. The device can execute different security software packages from various vendors, enabling a single hardware platform to serve multiple security standards and implementations, thus enhancing competition and innovation while maintaining security control.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary download mechanism that acts as a mediator between the sender security server and the receiver security device. This intermediary layer enables standardized security updates to be distributed while allowing vendors to maintain control over their specific security implementations, balancing proprietary control with broader compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If conventional security systems are used, then individual security implementations are maintained, but switching costs and renewability costs are significant

Engineering Contradiction:
Improvesecurity implementationVSAvoidswitching cost
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring the receiver security device with the capability to download and execute new security software. Authentication credentials and download protocols are established in advance, enabling seamless security updates and renewals without significant switching costs or service interruption, thus reducing time loss while maintaining security implementation reliability.

Inventive Principle:
Principle #10Preliminary action

4Stability of the object's composition

If fixed encryption/decryption technologies are used, then system stability is maintained, but service improvement and new service addition are restricted

Engineering Contradiction:
Improvesystem stabilityVSAvoidservice improvement capability
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic service capability by enabling the receiver security device to download new security software and algorithms remotely. This dynamic architecture allows the system to maintain stability through proven security implementations while simultaneously improving services by deploying new algorithms and features without hardware changes, thus resolving the contradiction between stability and adaptability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7383438B2System and method for secure conditional access download and reconfiguration
Publication Date: 2008.06.03 COMCAST CABLE COMM LLC
  • US7383438B2 patent drawing
  • US7383438B2 patent drawing
  • US7383438B2 patent drawing

AI summary

A method of securely downloading at least one of conditional access software (CAS), Digital Rights Management software (DRMS), Trusted Domain Software (TDS), and Gaming Security Software (GSS) includes presenting a specialized entitlement management message (EMM) to initiate the download to a receiver security device using a supervisory logon key (SLK) split to logon with a second split contained inside the receiver security device, presenting a receiver digitally signed random challenge from the receiver security device to a sender security server to establish authentication of the receiver security device to the sender security server, and signing and returning the receiver random challenge from the sender security server to the receiver security device with a sender random challenge to establish authentication of the sender security server to the receiver security device.