Session Key Diversification for Instantaneous Terminal Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing the transmission of multimedia content and control words between a security processor and a terminal are vulnerable to attacks, particularly due to the potential compromise of session keys, which requires lengthy and complicated key renewal processes.

Innovation Solution

The method involves pre-recording multiple secret codes in the terminal, allowing selection of the appropriate code for decrypting multimedia content or control words based on parameters received in the same message, enabling instantaneous session key changes without a transitional period.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If session keys are encrypted and transmitted between security processor and terminal, then transmission security is improved, but key renewal becomes lengthy and complicated when keys are compromised

Engineering Contradiction:
Improvetransmission securityVSAvoidkey renewal time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The terminal pre-calculates and stores multiple future session keys (SK1, SK2, SK3, etc.) before they are needed. When a key compromise is detected, the system can immediately switch to a pre-calculated key without waiting for renewal communication, thus eliminating the lengthy key renewal process while maintaining continuous secure transmission

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a key diversification function that uses a root key and a parameter (Pc) to generate session keys. This intermediary mechanism allows the system to generate multiple valid session keys from a single root key, enabling rapid key rotation without requiring complex renewal protocols between the security processor and terminal

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple secret codes are pre-recorded in the terminal, then key renewal speed is improved, but device complexity increases

Engineering Contradiction:
Improvekey renewal speedVSAvoidterminal structure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The session key management is segmented into multiple pre-calculated keys (SK1, SK2, SK3, etc.) stored in the terminal. Each key is associated with a specific parameter value (Pc=1, Pc=2, Pc=3, etc.). This segmentation allows the terminal to quickly select the appropriate key based on the current parameter without complex real-time calculation, improving key renewal speed while keeping the terminal structure relatively simple

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses parameter changes (Pc values) to select between different pre-recorded secret codes. By changing the parameter Pc and selecting the corresponding pre-stored code, the terminal can rapidly switch between different session keys without complex operations, thus improving key renewal speed with minimal increase in device complexity

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8819436B2Protection method, decryption method, recording medium and terminal for said protection method
Publication Date: 2014.08.26 VIACCESS SA
  • US8819436B2 patent drawing
  • US8819436B2 patent drawing
  • US8819436B2 patent drawing

AI summary

Protecting data transmission, either multimedia or a control word, between a security processor and a terminal includes, at the security processor, building a current session key by root key diversification as a function of a parameter transmitted by the terminal, decrypting the data, encrypting it with the session key, and transmitting it, and at the terminal, decrypting it using a secret code to obtain plain data, recording, in advance, secret codes, each enabling decryption of only data encrypted by a corresponding session key obtained by root-key diversification with a parameter, which can be the transmitted parameter, receiving the parameter in a message that also contains the data to be decrypted by the security processor, and in response, selecting, from the secret codes, a code for decrypting the data encrypted with the session key, as a function of the parameter or another parameter in the message.