Selective Control Word Delivery for Conditional Access Traceability
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy receivers lack the capability to selectively use multiple control words for decryption, and existing fingerprinting schemes are not effectively implemented in these devices, making it difficult to trace the source of illicit distribution of control words or product keys.
Innovation Solution
A method is introduced to securely deliver two or more different control words to subsets of receivers, using primary and secondary product keys, where each receiver or group receives a unique combination of primary product keys, enabling selective decryption and fingerprinting without requiring special functionality in the receivers. This involves generating sets of primary product keys, providing primary and secondary entitlement control messages, and encrypting content portions to ensure only the correct control words can decrypt them.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple control words are delivered to receivers for fingerprinting schemes, then security and traceability are improved, but device complexity increases as receivers must handle multiple decryption keys
Solution Approach 1:
The patent segments the control word delivery system by creating multiple ECM streams (first ECM stream and second ECM stream) that are associated with the same content stream. Each ECM stream contains control words that can be used to decrypt the content, but different receivers are configured to access different ECM streams based on their entitlements. This segmentation allows multiple control words to be delivered without requiring receivers to handle all possible control words, thus maintaining security while limiting receiver complexity.
Solution Approach 2:
The patent applies local quality by providing different subsets of control words to different receivers or receiver groups. Each receiver is configured with specific entitlements that determine which ECM streams it can access. For example, premium receivers may access both first and second ECM streams while standard receivers only access the first ECM stream. This localized differentiation achieves fingerprinting and traceability goals while keeping each receiver's complexity manageable by only requiring it to handle the control words relevant to its service level.
2Adaptability or versatility
If multiple ECM streams are associated with the same content stream, then selective control word access is enabled, but transport stream complexity increases
Solution Approach 1:
The patent uses universality by creating a reusable template structure for ECM streams that can be applied to multiple content streams. The first and second ECM streams follow the same structural pattern (containing control words, synchronization information, and entitlement data), which allows the system to efficiently manage multiple streams without proportionally increasing complexity. This standardized multi-functionality enables selective access capability while keeping the transport stream structure manageable through repetition of proven patterns.
3Reliability
If fingerprinting is implemented using watermark symbols in encrypted content, then illicit distribution tracing is improved, but manufacturing precision requirements increase for accurate watermark embedding
Solution Approach 1:
The patent applies partial action by implementing fingerprinting only for specific content streams or service levels rather than universally across all content. The watermark symbols are embedded in content streams that are encrypted with control words from specific ECM streams. This selective approach provides traceability for the most valuable or sensitive content while avoiding the need for precise watermark embedding in all content, thus reducing overall manufacturing precision requirements while maintaining traceability where it matters most.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
There are disclosed methods and apparatus enabling selected use of control words distributed to each of a plurality of receivers or groups of receivers, for example as part of an MPEG-2 transport stream. A plurality of sets of primary product keys is established or generated, each set containing at least two different primary product keys. One primary product key of each set is made available to each receiver or group of receivers, such that each receiver or group of receivers is provided with a different combination of said primary product keys. For each set of primary product keys, the plurality of receivers or groups of receivers is provided with a different primary entitlement control message corresponding to each primary product key of said set, each such primary entitlement control message distributing a primary control word for recovery through decryption using the corresponding primary product key. The primary control words can then be used for purposes such as tracing compromise of the conditional access system, or arranging for differently fingerprinted content to be decoded at different receivers or groups of receivers.