Security Module Firmware Update via Dedicated Patch Stream

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for updating firmware in security modules within the Pay-TV system are inefficient, particularly when dealing with large patches, as they require multiple EMM messages transmitted in the digital data stream, leading to prolonged update times and potential service interruptions.

Innovation Solution

The method allows the security module to 'jump' to a dedicated separate patch message stream using trigger messages, enabling the receipt of an entire patch in minimal time, with switch messages redirecting it back to the main stream upon completion, and utilizing a correspondence table to manage conditional access system identifiers for efficient firmware updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware updates are transmitted through multiple EMM messages in the digital data stream, then the security module can be updated, but the update time is prolonged and service interruptions may occur

Engineering Contradiction:
Improvefirmware update reliabilityVSAvoidupdate time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the firmware update process into two distinct channels: a dedicated patch message stream for receiving update data and the main management message stream for control commands. This segmentation allows large firmware patches to be transmitted without blocking the main stream, significantly reducing update time while maintaining reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a dedicated patch message stream as an intermediary channel between the management center and security modules. This intermediate stream handles the bulk data transmission separately from the main management message flow, enabling parallel operations and eliminating the time loss associated with sequential updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If firmware updates are performed during periods of reduced data throughput, then the security module can be updated, but the broadcasted content reception is affected

Engineering Contradiction:
Improvefirmware update reliabilityVSAvoidbroadcast content delivery efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent divides the message transmission system into separate streams: a dedicated patch message stream for firmware updates and a main stream for broadcast content and management messages. This segmentation enables simultaneous operation of both functions without interference, maintaining broadcast productivity while ensuring update reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent ensures continuous operation by allowing the main stream to continue delivering broadcast content and management messages uninterrupted while the dedicated patch stream simultaneously handles firmware updates. This continuity eliminates the need to pause broadcast services for updates.

Inventive Principle:
Principle #20Continuity of useful action

3Loss of time

If a separate dedicated stream for patch messages is created, then update time is reduced, but the system complexity increases

Engineering Contradiction:
Improveupdate timeVSAvoidmessage stream management complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The patent implements a universal management center that handles both main stream and patch stream operations through a unified architecture. The management center uses a single correspondence table to manage multiple security module types and streams, reducing the complexity increase despite having separate dedicated streams for different message types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses a correspondence table that copies and maps between different stream identifiers and security module types. This table mechanism simplifies stream management by providing a straightforward lookup system for routing messages to the appropriate security modules, reducing the operational complexity of managing multiple streams.

Inventive Principle:
Principle #26Copying

4Productivity

If trigger messages are used to redirect security modules to patch streams, then update efficiency is improved, but the message processing complexity increases

Engineering Contradiction:
Improveupdate efficiencyVSAvoidmessage processing complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by having security modules automatically detect their need for updates and trigger messages before actually receiving the patch. The module checks its firmware version against the correspondence table, identifies the appropriate patch stream, and prepares to receive updates proactively, improving efficiency while managing processing complexity through advance preparation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses feedback mechanisms where security modules report their firmware version and update status back to the management center. This feedback loop enables the management center to dynamically adjust the correspondence table and redirect modules to appropriate patch streams, improving update efficiency through intelligent routing while managing complexity through automated feedback-based control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP1980105B1Method for updating the firmware of a security module
Publication Date: 2014.05.07 NAGRAVISION SA
  • EP1980105B1 patent drawingFigure 1

AI summary

Method for updating the firmware of a security module (SM3, SM4) associated to a user unit for processing digital data broadcasted in a transport stream, said unit being connected to a conditional access system transmitting, in said transport stream, to the security module (SM3, SM4) a first stream (P0) of management messages (EMM), said method is characterized in that it comprises the following steps: - broadcasting at least a second stream (P1, P2) comprising the patch messages (EP) suitable for updating the firmware of the security module (SM3, SM4), said second stream (P1, P2) being identified by an identifier (PID) associated to a predetermined type of security module (SM3, SM4), - adding to the first stream (P0) of management messages, trigger messages (T) comprising version information allowing establishing whether said security module (SM3, SM4) is up-to-date, and an identifier indicating to said security module the suitable patch stream (P1, P2), - if the current version of the firmware of the security module (SM3, SM4) is inferior to the patch version, directing the security module (SM3, SM4) towards the stream (P1, P2) of patch messages (EP) designated by the identifier included in the trigger message (T), - updating the firmware of the concerned security module (SM3, SM4) related to the stream (P1, P2) of patch messages (EP), - directing the security module (SM3, SM4) towards the first stream (P0) of management messages (EMM) when the update of the firmware is completed.