Set-Top Box Key Revocation via Hardware Parser Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems for fee-based video broadcasting are vulnerable to revocation denial of service attacks, where unauthorized entities can cause the receiving system to fail by revoking all security keys, leading to a loss of access control.

Innovation Solution

A method and system that utilize a hidden key for secure key revocation, where the key revocation command is encrypted and signed with a unique key ID, and verified through a hardware parser to ensure authenticity, preventing unauthorized revocation and maintaining access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security systems allow key revocation commands to be processed, then access control can be updated, but the system becomes vulnerable to revocation denial of service attacks where unauthorized entities can revoke all security keys

Engineering Contradiction:
Improveaccess control integrityVSAvoidrevocation denial of service attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification of the revocation command signature and key ID match before processing the revocation. This preliminary action prevents unauthorized revocation attempts from succeeding, as the system checks authenticity and legitimacy before executing the key revocation operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism that mediates between the received revocation command and the actual key revocation operation. The signature verification and key ID matching act as an intermediary layer that filters out malicious commands before they can cause harm.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system verifies signatures and key IDs for each revocation command, then unauthorized revocation is prevented, but the processing complexity and time increase

Engineering Contradiction:
Improverevocation command authenticityVSAvoidrevocation command processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary checks of the signature and key ID match before proceeding with full revocation processing. By verifying critical authenticity indicators first, the system avoids lengthy processing of obviously invalid commands, reducing average processing time while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If the system stores and compares key IDs in one-time programmable memory, then precise key identification is achieved, but the device complexity increases

Engineering Contradiction:
Improvekey ID matching accuracyVSAvoidmemory comparison mechanism
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent uses a simplified copying approach where the received key ID is directly compared against the stored key ID in OTP memory. This direct comparison method achieves precise key identification without requiring complex verification algorithms, balancing accuracy with simplicity.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9461825B2Method and system for preventing revocation denial of service attacks
Publication Date: 2016.10.04 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US9461825B2 patent drawing
  • US9461825B2 patent drawing
  • US9461825B2 patent drawing

AI summary

Methods and systems for preventing revocation denial of service attacks are disclosed and may include receiving and decrypting a command for revoking a secure key utilizing a hidden key, and revoking the secure key upon successful verification of a signature. The command may comprise a key ID that is unique to a specific set-top box. A key corresponding to the command for revoking the secure key may be stored in a one-time programmable memory, compared to a reference, and the security key may be revoked based on the comparison. The command for revoking the secure key may be parsed from a transport stream utilizing a hardware parser. The method and system may also comprise generating a command for revoking a secure key. The command may be encrypted and signed utilizing a hidden key and may comprise a key ID that is unique to a specific set-top box.