Secure Pairing of Receiving Devices via Key Derivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing content delivery to receiving devices, such as in pay-TV systems, require large amounts of data to be transmitted for personalization, posing logistical challenges and security risks, especially when devices need to be paired with operators during production or initialization.

Innovation Solution

A method involving an authority server and cryptographic functions allows receiving devices to generate a secret key using identifiers exchanged with the content provider system, reducing the need for massive key packages and enabling remote personalization without exposing sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If receiving devices are personalized during production with operator-specific secret data, then security of content delivery is improved, but data transmission volume and logistical complexity increase significantly

Engineering Contradiction:
Improvesecurity of content deliveryVSAvoiddata transmission volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the operator-specific secret data from the personalization process. Instead of embedding operator keys directly in devices during manufacturing, the system uses generic device identifiers that are processed remotely by the operator to generate device-specific keys on-demand, eliminating the need to transmit large volumes of secret data during production

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary mechanism where a trusted authority or operator system acts as a mediator. The authority server receives generic device identifiers, processes them with operator-specific secret data securely, and returns derived keys to the operator without exposing the operator's secret data. This intermediary approach enables secure key generation without direct transmission of sensitive information

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If operator-specific secret data is transmitted to manufacturers for device personalization, then device security is improved, but security risks increase due to exposure of sensitive data

Engineering Contradiction:
Improvedevice securityVSAvoidsecurity risks from data exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent removes operator-specific secret data from the manufacturing environment entirely. Instead of providing keys to manufacturers, the system keeps operator secrets confined to the operator's secure systems and only transmits or processes generic, non-sensitive device identifiers during device production and activation

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary processing of device identifiers in a secure environment controlled by the operator or trusted authority. Device-specific security parameters are pre-computed from generic identifiers using operator secrets in a protected setting, then the resulting keys are delivered without exposing the underlying secret data

Inventive Principle:
Principle #10Preliminary action

3Quantity of substance

If receiving devices are paired with operators during initialization at user premises, then data transmission during production is reduced, but the operator still requires access to secret data for personalization

Engineering Contradiction:
Improvedata transmission during productionVSAvoidcomplexity of key management system
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent enables receiving devices to self-configure during initialization by autonomously obtaining their unique identifiers and using them to request and receive device-specific security keys from the operator system. The device performs self-personalization without requiring manual intervention or complex key distribution infrastructure

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal personalization mechanism that works for both production-line and field initialization scenarios. The same identifier-based key derivation process serves both contexts, eliminating the need for separate key management systems for different personalization scenarios

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240372716A1Method for pairing a content provider system and a receiving device, corresponding computer program product and devices
Publication Date: 2024.11.07 NAGRAVISION SA
  • US20240372716A1 patent drawing
  • US20240372716A1 patent drawing
  • US20240372716A1 patent drawing

AI summary

A method for pairing a content provider system and a receiving device, a cryptographic function and a receiving device unique identifier being populated in the receiving device. According to such method, the receiving device executes: obtaining a first key which is a result of a first function taking as arguments an Identity Based Encryption scheme master key owned by an authority server and an output of the cryptographic function applied to the receiving device unique identifier; receiving, from the content provider system, a content provider unique identifier; and computing a secret key which is a result of a second function taking as operands the first key and an output of the cryptographic function applied to the content provider unique identifier, the secret key being known from the content provider system.