Secured Digital Broadcasting Key Management via HSM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secured broadcasting systems for digital data flows are vulnerable to key theft and unauthorized access due to the exposure and storage of ciphering/deciphering keys, which can be stolen or shared using cryptanalysis methods.
Innovation Solution
The method involves regenerating a secret key during the ciphering process and storing it in a secured memory area of the terminal, using a cryptographic mechanism to securely generate and manage keys, with a Hardware Security Module (HSM) handling key management and storage to prevent key exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If ciphering/deciphering keys are stored in the decoder box memory, then the system can function as a stand-alone device, but the keys become vulnerable to theft through memory bus reading and key sharing attacks
Solution Approach 1:
The patent extracts the key management function from the decoder box by introducing a separate key management server that handles key generation, storage, and distribution. This separates the cryptographic operations from the storage operations, preventing attackers from accessing stored keys through memory bus reading while maintaining stand-alone device operation capability.
Solution Approach 2:
The patent introduces a key management server as an intermediary between the content distribution system and the decoder box. This intermediary handles all key-related operations securely, acting as a mediator that prevents direct exposure of keys in the decoder box memory while enabling the stand-alone device to function properly.
2Adaptability or versatility
If keys are transmitted to the decoder box for deciphering, then the device can access authorized content, but logistical costs and security risks increase due to key storage and transfer requirements
Solution Approach 1:
The patent implements self-service by enabling the decoder box to autonomously request and receive keys from the key management server based on its identifier and authorization status. The system performs key management operations automatically without requiring manual intervention, reducing logistical complexity while maintaining content access capability.
Solution Approach 2:
The key management server provides universal service to multiple decoder boxes, handling key generation, storage, and distribution for all authorized devices. This multi-functional approach consolidates key management operations into a single system that serves multiple clients, reducing overall system complexity and logistical overhead.
Data Source
AI summary
A method and system for secured broadcasting of a digital data flow between a technical platform (1) and at least one terminal (2), characterized in that it comprises the following steps:transmitting a scrambled and multiplexed digital data flow with at least one message (ECM) including a control key (CW) encrypted by a channel key (CC);descrambling in a secured memory area of the terminal (2) the scrambled digital data flow from the control key (CW) obtained according to the following substeps;sending to the technical platform (1) a request including the identifier (IUi) of the terminal (2);generating a secret key (CSk) from a cryptographic mechanism (A) using a single ciphering key (BSKn) and the identifier (IUi) of the terminal (2) with view to ciphering said channel key (CC) and obtaining a message (eCCk);deciphering the message (eCCk) received by a terminal (2) from the key (CSk) initially stored in the terminal (2) so as to obtain the channel key (CC), andobtaining the control key (CW) resulting from the deciphering of the message (ECM) from the channel key (CC).


