Shared HDCP Engine for Multi-Channel Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing High-bandwidth Digital Content Protection (HDCP) protocol requires multiple authentication engines and stream cipher engines for each channel, leading to large and expensive HDCP engine chips, especially as the number of channels in a media streaming system increases.

Innovation Solution

A receiving device is configured with a single authentication engine and stream cipher engine that can authenticate and decrypt multiple content channels by generating session keys sequentially, using an initial session key and a session key indicator to decrypt encrypted media content across multiple channels, including HDMI and MHL3 channels, without the need for separate engines for each channel.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication engines and stream cipher engines are implemented for each channel, then content protection reliability is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improvecontent protection reliabilityVSAvoidHDCP engine chip complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple authentication engines and stream cipher engines into a single shared HDCP engine that can sequentially serve multiple content channels. The authentication engine authenticates multiple transmitting devices and generates session keys for different channels, while a single stream cipher engine decrypts content from any active channel using the appropriate session key, thereby reducing chip complexity while maintaining security

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The HDCP engine is designed with multi-functionality to handle multiple content channels through a single authentication engine and single stream cipher engine. The authentication engine can authenticate different transmitting devices on different channels, and the stream cipher engine can decrypt content from any active channel by selecting the appropriate session key, making the engine universal across multiple channels

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If separate authentication engines and stream cipher engines are implemented for each channel, then decryption efficiency is improved, but manufacturing cost increases

Engineering Contradiction:
Improvedecryption efficiencyVSAvoidmanufacturing cost
Core Design Contradiction:
ProductivityVSEase of manufacture

Solution Approach 1:

The patent implements a dynamic session key generation mechanism where the authentication engine generates session keys sequentially for different channels based on authentication results. The stream cipher engine dynamically selects and uses the appropriate session key based on which channel is currently active, allowing efficient decryption without requiring separate dedicated engines for each channel

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication engine performs preliminary authentication of transmitting devices and generates session keys for multiple channels in advance, before content decryption is needed. This preliminary action allows the stream cipher engine to efficiently decrypt content from any active channel by simply selecting the pre-generated session key, maintaining decryption efficiency while reducing hardware requirements

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9432345B2Authentication engine and stream cipher engine sharing in digital content protection architectures
Publication Date: 2016.08.30 LATTICE SEMICON CORP
  • US9432345B2 patent drawing
  • US9432345B2 patent drawing
  • US9432345B2 patent drawing

AI summary

A system for receiving and decrypting media content encrypted according to the HDCP protocol is described herein. A receiving device coupled to a plurality of content channels includes an authentication engine to authenticate each content channel and to generate an initial session key associated with each authenticated content channel. The content channels can be, for example, an HDMI channel or an MHL3 channel. A session key indicator indicating a session key used to encrypt media content is received, and an updated session key is generated. The receiving device also includes a stream cipher engine configured to decrypt received encrypted media content using the updated session key. Decrypted media content can then be displayed, for instance on a display of the receiving device.