Security Module Key Management for Conditional Access Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In conditional access systems for digital television and radio, the existing methods for managing access control messages are inefficient in handling multiple content decryption keys, requiring frequent verification and transmission processes, which can lead to delays and increased computational load.
Innovation Solution
A method for processing access control messages that allows for the verification and storage of multiple decryption keys within a security module, enabling the transmission of one key to an external terminal while storing another locally, with the option to determine the type of key for efficient discrimination and reuse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the security module processes each access control message separately for each content, then the verification and transmission process is simple and secure, but the processing efficiency decreases and computational load increases
Solution Approach 1:
The security module performs preliminary verification of user rights against access criteria when an access control message is first received, and stores the verified decryption key locally. This preliminary action eliminates the need for repeated verification of the same rights for subsequent contents using the same key, thereby improving processing efficiency while maintaining security.
Solution Approach 2:
The security module is designed to handle multiple types of decryption keys (first type for transmission, second type for local storage) within a single processing framework. This multi-functionality allows the module to efficiently manage different key types without requiring separate processing paths, reducing computational overhead while maintaining security requirements.
2Speed
If the decryption key is transmitted to the external terminal for each content access, then the terminal can decrypt the content, but the transmission process repeats frequently causing delays
Solution Approach 1:
The security module performs preliminary verification of user rights and decrypts the key in advance when the access control message is first received. The decrypted key is then stored locally for immediate reuse, eliminating the need for repeated transmission delays while maintaining security through initial verification.
Solution Approach 2:
The security module creates a local copy of the decrypted key for subsequent reuse. This copying mechanism allows the terminal to access content using the stored key without requiring repeated transmission cycles, significantly reducing access time while maintaining security through controlled copying.
3Adaptability or versatility
If the security module stores multiple decryption keys locally, then access to multiple contents is enabled, but the security module must manage and discriminate between different key types
Solution Approach 1:
The security module applies different handling rules to different types of decryption keys based on their specific characteristics. First type keys are transmitted to the terminal, while second type keys are stored locally. This localized quality approach allows efficient management of multiple key types without requiring complex uniform processing, enabling versatile content access while maintaining manageable complexity.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
The method involves verifying whether an access criterion present in an entitlement control message utilized to control access to content, is satisfied by user rights stored in a safety module i.e. chip card, where the criterion is chosen from a group comprising valid subscriber criterion, age criterion and cost criterion. Transparent decryption keys are decrypted if the access criterion present in the control message is satisfied by the user rights. One of the decryption keys is transmitted towards an external terminal i.e. set-top box. The other decryption key is stored in the module. Independent claims are also included for the following: (1) a safety module comprising a verification unit (2) a computer program comprising instructions for performing a method for processing entitlement control messages.