Configurable Secure Processor for Downloadable Conditional Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing downloadable conditional access systems require the host processor to execute CA system-specific code, leading to increased work and costs, security vulnerabilities, and the risk of unauthorized access due to the transmission of decryption keys.
Innovation Solution
Implementing a configurable secure processor that executes the DCAS software module, eliminating the need for host processor-specific code and ensuring that decryption keys are never transmitted outside the secure processor, thereby enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the host processor executes CA system-specific code to enable different CA systems, then the STB can support multiple CA systems, but the work and costs increase and security vulnerabilities arise
Solution Approach 1:
The patent segments the CA system functionality into a separate secure processor that executes downloaded CA kernels, isolating it from the host processor. This segmentation allows the host processor to remain generic while the secure processor handles CA-specific operations, reducing host processor complexity and work while maintaining multi-CA-system support.
Solution Approach 2:
The patent introduces a secure processor as an intermediary between the host processor and the CA system. This intermediary executes the downloaded CA kernel and handles all CA-specific code execution, preventing the host processor from directly executing CA system-specific code and thereby reducing its workload and associated costs.
2Adaptability or versatility
If the host processor executes CA system-specific code, then different CA systems can be supported, but security vulnerabilities and unauthorized access risks increase
Solution Approach 1:
The patent segments security-critical CA operations into a dedicated secure processor, separating them from the general-purpose host processor. This segmentation ensures that CA system-specific code executes in an isolated, secure environment, preventing security vulnerabilities from affecting the host processor while maintaining support for multiple CA systems.
Solution Approach 2:
The secure processor acts as a security intermediary that mediates all CA-related operations. It executes the downloaded CA kernel in a controlled environment, preventing direct execution of CA code on the host processor and thereby eliminating security vulnerabilities and unauthorized access risks while maintaining CA system support.
3Adaptability or versatility
If multiple DCAS kernel designs are created for different host processors, then compatibility with various STBs is achieved, but the complexity and cost of implementation increase
Solution Approach 1:
The patent makes the secure processor universal by designing it to execute downloaded CA kernels for different CA systems without requiring host processor-specific code. The secure processor can be reconfigured through software downloads to support multiple CA systems, eliminating the need to create multiple DCAS kernel designs for different host processors while maintaining broad STB compatibility.
Solution Approach 2:
The patent introduces dynamic reconfigurability to the secure processor, allowing it to load and execute different CA kernels as needed. This dynamic approach replaces static, host processor-specific kernel designs with a flexible system that can adapt to different CA systems through software downloads, reducing implementation complexity and cost while maintaining compatibility.
Data Source
AI summary
In a downloadable conditional access system (DCAS), preferably all DCAS-specific code is implemented in a configurable secure (CS) processor that is in communication with the host processor. Preferably, no DCAS-specific code is executed in the host processor. The host processor delivers commands to the CS processor, which the CS processor performs to configure itself in accordance with the particular DCAS encryption scheme used by the DCAS. Once configured, the CS processor executes a DCAS software module that has been downloaded to the CS processor, which looks for the corresponding EMMs and ECMs, processes them to obtain the CW, and then uses the CW to decrypt the content stream.


