Security Module Key Management for Conditional Access Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In conditional access systems for digital television and radio, the existing methods for managing access control messages are inefficient in handling multiple content decryption keys, requiring frequent verification and transmission processes, which can lead to delays and increased computational load.

Innovation Solution

A method for processing access control messages that allows for the verification and storage of multiple decryption keys within a security module, enabling the transmission of one key to an external terminal while storing another locally, with the option to determine the type of key for efficient discrimination and reuse.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the security module processes each access control message separately for each content, then the verification and transmission process is simple and secure, but the processing efficiency decreases and computational load increases

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidcomputational load
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The security module performs preliminary verification of user rights against access criteria when an access control message is first received, and stores the verified decryption key locally. This preliminary action eliminates the need for repeated verification of the same rights for subsequent contents using the same key, thereby improving processing efficiency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security module is designed to handle multiple types of decryption keys (first type for transmission, second type for local storage) within a single processing framework. This multi-functionality allows the module to efficiently manage different key types without requiring separate processing paths, reducing computational overhead while maintaining security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Speed

If the decryption key is transmitted to the external terminal for each content access, then the terminal can decrypt the content, but the transmission process repeats frequently causing delays

Engineering Contradiction:
Improvekey transmission speedVSAvoidverification and transmission delay
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The security module performs preliminary verification of user rights and decrypts the key in advance when the access control message is first received. The decrypted key is then stored locally for immediate reuse, eliminating the need for repeated transmission delays while maintaining security through initial verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security module creates a local copy of the decrypted key for subsequent reuse. This copying mechanism allows the terminal to access content using the stored key without requiring repeated transmission cycles, significantly reducing access time while maintaining security through controlled copying.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If the security module stores multiple decryption keys locally, then access to multiple contents is enabled, but the security module must manage and discriminate between different key types

Engineering Contradiction:
Improveaccess to multiple contentsVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security module applies different handling rules to different types of decryption keys based on their specific characteristics. First type keys are transmitted to the terminal, while second type keys are stored locally. This localized quality approach allows efficient management of multiple key types without requiring complex uniform processing, enabling versatile content access while maintaining manageable complexity.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP2326035B1Treatment method involving a message security module for controlling access to content and associated security module
Publication Date: 2015.05.27 ORANGE SA
  • EP2326035B1 patent drawingFigure 1
  • EP2326035B1 patent drawingFigure 2A
  • EP2326035B1 patent drawingFigure 2B

AI summary

The method involves verifying whether an access criterion present in an entitlement control message utilized to control access to content, is satisfied by user rights stored in a safety module i.e. chip card, where the criterion is chosen from a group comprising valid subscriber criterion, age criterion and cost criterion. Transparent decryption keys are decrypted if the access criterion present in the control message is satisfied by the user rights. One of the decryption keys is transmitted towards an external terminal i.e. set-top box. The other decryption key is stored in the module. Independent claims are also included for the following: (1) a safety module comprising a verification unit (2) a computer program comprising instructions for performing a method for processing entitlement control messages.