USB Transport I/O Secure Processor Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Digital Video Broadcasting (DVB) conditional access architecture is vulnerable to unauthorized access due to the ease with which the network control word (NCW) can be shared over the Internet, allowing non-subscribers to decrypt broadcasted content.

Innovation Solution

A Transport I/O system that maintains the network control word on a secure processor, decrypts network encrypted content, and re-encrypts it using a local control word specific to a device, preventing the network control word from being intercepted and ensuring only authorized users can access the content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the network control word is transmitted over the Internet to enable content access, then content accessibility is improved, but security deteriorates allowing unauthorized access

Engineering Contradiction:
Improvecontent accessibilityVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the network control word from the transmission path by performing decryption within the secure processor. The NCW is obtained from an encrypted form (ECM) inside the secure environment and never leaves the secure processor in decrypted form, separating the decryption function from the transmission path while maintaining content accessibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary encryption layer (local control word encryption) between the secure processor and the content output. The decrypted content is re-encrypted with a device-specific local control word before being made accessible, acting as a mediator that enables content access while preventing unauthorized distribution.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the network control word is shared across multiple devices, then content accessibility is improved, but security deteriorates due to interception risks

Engineering Contradiction:
Improvemulti-device content accessVSAvoidinterception vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by making the encryption key device-specific. Each device receives content encrypted with its own unique local control word rather than a common network control word. This allows multi-device access while enhancing security, as each device's content is locally optimized and individually protected.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the content distribution system into two independent encryption layers: network-level encryption (NCW) for secure transmission and device-level encryption (LCW) for local protection. This segmentation allows content to be securely distributed to multiple devices while each device maintains its own security boundary, preventing interception vulnerabilities from propagating across the network.

Inventive Principle:
Principle #1Segmentation

3Productivity

If the network control word is stored externally for easy access, then content processing efficiency is improved, but security deteriorates

Engineering Contradiction:
Improvecontent processing efficiencyVSAvoidtheft risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent merges the functions of secure key storage, decryption, and content processing within a single secure processor. The secure processor combines the NCW storage, decryption operations, and LCW generation in one protected environment, eliminating the need to store or transmit the NCW externally while maintaining processing efficiency through integrated operations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary action by obtaining and storing the network control word in encrypted form (ECM) within the secure processor before any content processing occurs. The NCW is derived from the ECM inside the secure environment and is ready for immediate use in decryption operations, eliminating the need for external storage while ensuring security through pre-established secure key management.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3002950B1USB interface for performing transport I/O
Publication Date: 2021.03.17 NAGRASTAR LLC
  • EP3002950B1 patent drawingFigure 1
  • EP3002950B1 patent drawingFigure 2
  • EP3002950B1 patent drawingFigure 3

AI summary

Systems and methods for implementing a Transport I/O system are described. Network encrypted content may be received by a device. The device may provide the network encrypted content to a secure processor, such as, for example, a smart card. The secure processor obtains a network control word that may be used to decrypt the network encrypted content. The secure processor may decrypt the network encrypted content to produce clear content. In embodiments, the secure processor may then use a local control word to generate locally encrypted content specific to the device. The device may then receive the locally encrypted content from the secure processor and proceed to decrypt the locally encrypted content using a shared local encryption key. The secure processor may connect to the device via a standard connection, such as via a USB 3.0 connector.