Secure Tunnel Server for CAS Head-End Cloud Migration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conditional Access Systems (CAS) face security risks when transitioning to public cloud services, particularly in small and medium-sized environments, as they struggle to ensure secure data transmission and compatibility with existing DVB simulcrypt standards.

Innovation Solution

Implementing a server with a communicator and processor that generates and transmits encrypted information, decrypts received information, and uses secure tunnel services to ensure secure communication between the CAS head-end and external servers, maintaining compatibility with DVB simulcrypt standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If CAS head-end configurations are serviced through public cloud, then cost and management burden are reduced, but security risk increases due to unencrypted data transmission

Engineering Contradiction:
Improvemanagement burdenVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A secure tunnel server is introduced as an intermediary between the cloud-based CAS head-end and the external server. The secure tunnel client in the electronic apparatus connects to this mediator, which then communicates with the cloud service. This intermediary layer encrypts all data transmissions, allowing the system to benefit from cloud-based management while maintaining security through the encrypted communication channel provided by the tunnel server.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If data is transmitted as unencrypted clear text according to DVB simulcrypt standards, then compatibility with existing apparatuses is maintained, but security is compromised in public cloud environments

Engineering Contradiction:
ImprovecompatibilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The secure tunnel server acts as a mediator that translates between the unencrypted DVB simulcrypt format required by existing apparatuses and the encrypted format needed for secure cloud communication. The tunnel server receives unencrypted data from the cloud-based CAS head-end, encrypts it, and forwards it to the electronic apparatus through the secure tunnel. This allows existing DVB-compatible devices to operate while security is maintained through the encryption layer provided by the tunnel server.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the encryption parameter of data transmission dynamically based on the communication context. Within the secure tunnel, data is transmitted in encrypted form to protect security. However, when interfacing with DVB simulcrypt components, the data is in unencrypted clear text format to maintain compatibility. The secure tunnel server performs the parameter change from encrypted to unencrypted format as needed, allowing both security and compatibility requirements to be satisfied.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11272234B2Electronic apparatus, server and method of controlling the same
Publication Date: 2022.03.08 SAMSUNG ELECTRONICS CO LTD
  • US11272234B2 patent drawing
  • US11272234B2 patent drawing
  • US11272234B2 patent drawing

AI summary

Disclosed are an electronic apparatus, a server, and a method of controlling the same, the server including: a communicator configured to connect with an electronic apparatus and an external server; and a processor configured to: generate first encrypted information by encrypting first decryption information received from the electronic apparatus, the first decryption information for reproducing content, control the communicator to transmit, to the external server, the generated first encrypted information, generate second decryption information by decrypting second encrypted information received from the external server, the second encrypted information generated based on the first decryption information, and control the communicator transmit the generated second decryption information to the electronic apparatus to scramble the content by a scrambler of the electronic apparatus.