Secured Appliance Access Control via Remote Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data systems, such as satellite and cable television broadcasting, face unauthorized access due to vulnerabilities in existing security measures, like smart cards that can be hacked or cloned, leading to unpaid access to data.

Innovation Solution

A system and method that uses a secured appliance and remote control with a limited capability to cooperate until a decryption key is provided, where the remote control encrypts data frames transmitted to the appliance, establishing a one-to-one relationship and utilizing rolling codes to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If smart cards are used for storing access authorization, then access control is implemented, but the security measure is susceptible to being hacked or cloned

Engineering Contradiction:
Improveaccess control reliabilityVSAvoidvulnerability to hacking and cloning
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the security function into two separate components: an encryption key stored in the remote control and a decryption key stored in the secured appliance. This segmentation ensures that neither component alone can provide unauthorized access, as both the encryption and decryption keys are required for the system to function. The smart card vulnerability is eliminated by distributing security credentials across multiple devices rather than concentrating them in a single hackable component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs asymmetric cryptography where the encryption key and decryption key are mathematically related but distinct. The encryption key stored in the remote control cannot be easily derived from the decryption key stored in the appliance, and vice versa. This asymmetric relationship provides strong security against cloning and hacking attempts, as compromising one key does not automatically compromise the other.

Inventive Principle:
Principle #4Asymmetry

2Reliability

If encryption keys are distributed to remote control and secured appliance, then unauthorized access is prevented, but device complexity increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary key distribution and pairing during the initial setup phase. The encryption key is pre-loaded into the remote control, and the corresponding decryption key is pre-loaded into the secured appliance before the user begins normal operation. This preliminary action eliminates the need for complex key management during daily use, as the keys are already in place and automatically utilized for encryption and decryption operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements automatic key management where the remote control and secured appliance independently handle their respective encryption and decryption operations without requiring user intervention. The devices automatically use their stored keys to encrypt and decrypt communications, eliminating the need for manual key distribution, storage, or management by the user, thereby reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8254576B2System and method for limiting access to data
Publication Date: 2012.08.28 UNIVERSAL ELECTRONICS INC
  • US8254576B2 patent drawing
  • US8254576B2 patent drawing
  • US8254576B2 patent drawing

AI summary

A controlling device provides conditional access to secured content renderable by an appliance. The controlling device transmits a data frame to the appliance and encrypts at least a part of the data frame that includes data to be used by the appliance to provide access to the secured content. At the appliance a decryption key complimentary to the encryption key is used to decrypt the received the data frame. The appliance allows the secured content to be rendered only after the appliance determines that the data in the received, decrypted data frame includes the data the appliance requires to provide access to the secured content.