Trusted Domain Content Security via Intermediary Key Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cable TV systems face challenges in preventing unauthorized copying and distribution of programming content, especially with the increasing use of home networking, where subscribers need to perform authorized copying while restricting access to protect content from unauthorized parties.

Innovation Solution

A 'trusted domain' is defined within the cable TV system, using cryptographic elements like encryption keys to control access to content stored on user devices, ensuring that content remains secure and cannot be distributed over the Internet or copied multiple times, by encrypting content with a secret key and using public key algorithms to manage access across devices within the domain.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If programming content is encrypted using DES key for secure delivery, then content security is improved, but key management complexity increases

Engineering Contradiction:
Improvecontent securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary key (content key) that mediates between the symmetric DES encryption and asymmetric RSA encryption. The content key is used to encrypt the programming content, while the RSA key pair manages the secure distribution and protection of this content key. This intermediary approach separates the content encryption from the key management, reducing the complexity of directly managing DES keys across multiple devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If content is stored on user devices for DVR functions, then user convenience is improved, but unauthorized copying risk increases

Engineering Contradiction:
Improveuser convenienceVSAvoidunauthorized copying risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies different encryption qualities to different locations and uses. The programming content is encrypted with a content key for storage on user devices, enabling convenient access. However, the content key itself is protected by RSA encryption specific to each authorized device. This local quality approach ensures that while content is accessible locally for DVR functions, unauthorized copying is prevented because each device has its own unique RSA key pair for verifying the content key's authenticity.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If multiple devices are authorized to access content, then adaptability is improved, but access control complexity increases

Engineering Contradiction:
Improvemulti-device accessVSAvoidaccess control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal access control mechanism using RSA asymmetric encryption that works across multiple devices. Each device receives a content key encrypted with its own public key, allowing the same content to be securely accessed on multiple authorized devices without requiring separate access control mechanisms for each device. The headend system can distribute content to multiple devices using the same encryption approach, providing universality and reducing access control complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8266429B2Technique for securely communicating and storing programming material in a trusted domain
Publication Date: 2012.09.11 TIME WARNER CABLE ENTERPRISES LLC
  • US8266429B2 patent drawing
  • US8266429B2 patent drawing
  • US8266429B2 patent drawing

AI summary

A “trusted domain” is established within which content received from a communications network, e.g., a cable TV network, is protected from unauthorized copying thereof, in accordance with the invention. In an illustrative embodiment, the trusted domain includes a device associated with a user which receives content from the cable TV network. The content may be encrypted using a content key in accordance, e.g., with a 3DES encryption algorithm before it is stored in the device. In addition, a first encrypted content key version and a second encrypted content key version are generated by respectively encrypting the content key with a public key associated with the device and another public key associated with the user, in accordance with public key cryptography. The first and second encrypted content key versions are stored in association with the encrypted content in the device storage. The encrypted content can be migrated from a first device to a second device, and can be decrypted in the second device if the second device is associated with the same user, and also provided with the second encrypted content key version.