Security Module Tracing Global Management Messages

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for verifying correct reception and execution of management messages by security modules in multimedia receivers are inefficient, particularly during global key changes, which can be risky and time-consuming, especially when receivers are disconnected, leading to expensive immediate updates.

Innovation Solution

A method that enforces processing of management messages by tracing and setting parameters in the security module's memory, ensuring that positive addressing management messages are only processed if global management messages have been successfully processed, thereby avoiding risky key changes and simplifying secure global updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If global key changes are performed in traditional pay-TV systems, then security updates can be applied to all receivers, but the process becomes time-consuming and risky especially when receivers are disconnected

Engineering Contradiction:
Improvesecurity update reliabilityVSAvoidkey change time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the security module pre-process and validate global management messages before executing key changes. The module traces the processing of global messages and sets parameters in memory to ensure readiness before actual key updates occur, preventing risky operations on disconnected receivers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the security module monitors and traces the processing status of global management messages. By checking whether global messages have been successfully processed before allowing positive addressing messages to execute key changes, the system ensures reliable updates while providing feedback on the security module's operational state.

Inventive Principle:
Principle #23Feedback

2Reliability

If traditional verification methods are used to check reception of management messages, then security can be maintained, but the verification process is inefficient and complex

Engineering Contradiction:
Improvemessage reception verificationVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the verification function from complex traditional methods by implementing a dedicated tracing mechanism within the security module. The module separately tracks processing of global management messages through parameter setting in memory, isolating the verification logic from the main key change process and simplifying the overall system.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If immediate updates are forced on disconnected receivers, then security can be maintained, but expensive operations are triggered and system stability is compromised

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidsystem instability and cost
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by preventing forced immediate updates on disconnected receivers. The security module checks processing status before allowing updates, and only executes key changes when global management messages have been successfully processed, thereby avoiding the harmful effects of forced updates on unstable systems.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS9961384B2Method and a security module configured to enforce processing of management messages
Publication Date: 2018.05.01 NAGRAVISION SA
  • US9961384B2 patent drawing
  • US9961384B2 patent drawing
  • US9961384B2 patent drawing

AI summary

A method and a security module configured to enforce processing of management messages. The security module is associated to a multimedia receiver configured to receive broadcast access controlled multimedia services. The management messages are transmitted by a managing center to the multimedia receiver. The method comprises steps of: receiving by the security module at least one global management message addressed to a plurality of multimedia receivers operated by the managing center, tracing processing of said global management message, receiving at least one positive addressing management message addressed to said security module, checking, by the security module, anterior processing of the global management message through the value of the parameters set during tracing processing of the global message, processing the positive addressing management message only if previous checking gives a result indicating a successful enforcement of the global management message allowing the multimedia receiver accessing the broadcast multimedia services.