USB Transport I/O Secure Processor Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The Digital Video Broadcasting (DVB) conditional access architecture is vulnerable to unauthorized access due to the ease with which the network control word (NCW) can be shared over the Internet, allowing non-subscribers to decrypt broadcasted content.
Innovation Solution
A Transport I/O system that maintains the network control word on a secure processor, decrypts network encrypted content, and re-encrypts it using a local control word specific to a device, preventing the network control word from being intercepted and ensuring only authorized users can access the content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the network control word is transmitted over the Internet to enable content access, then content accessibility is improved, but security deteriorates allowing unauthorized access
Solution Approach 1:
The patent extracts the network control word from the transmission path by performing decryption within the secure processor. The NCW is obtained from an encrypted form (ECM) inside the secure environment and never leaves the secure processor in decrypted form, separating the decryption function from the transmission path while maintaining content accessibility.
Solution Approach 2:
The patent introduces an intermediary encryption layer (local control word encryption) between the secure processor and the content output. The decrypted content is re-encrypted with a device-specific local control word before being made accessible, acting as a mediator that enables content access while preventing unauthorized distribution.
2Adaptability or versatility
If the network control word is shared across multiple devices, then content accessibility is improved, but security deteriorates due to interception risks
Solution Approach 1:
The patent applies local quality by making the encryption key device-specific. Each device receives content encrypted with its own unique local control word rather than a common network control word. This allows multi-device access while enhancing security, as each device's content is locally optimized and individually protected.
Solution Approach 2:
The patent segments the content distribution system into two independent encryption layers: network-level encryption (NCW) for secure transmission and device-level encryption (LCW) for local protection. This segmentation allows content to be securely distributed to multiple devices while each device maintains its own security boundary, preventing interception vulnerabilities from propagating across the network.
3Productivity
If the network control word is stored externally for easy access, then content processing efficiency is improved, but security deteriorates
Solution Approach 1:
The patent merges the functions of secure key storage, decryption, and content processing within a single secure processor. The secure processor combines the NCW storage, decryption operations, and LCW generation in one protected environment, eliminating the need to store or transmit the NCW externally while maintaining processing efficiency through integrated operations.
Solution Approach 2:
The patent performs preliminary action by obtaining and storing the network control word in encrypted form (ECM) within the secure processor before any content processing occurs. The NCW is derived from the ECM inside the secure environment and is ready for immediate use in decryption operations, eliminating the need for external storage while ensuring security through pre-established secure key management.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems and methods for implementing a Transport I/O system are described. Network encrypted content may be received by a device. The device may provide the network encrypted content to a secure processor, such as, for example, a smart card. The secure processor obtains a network control word that may be used to decrypt the network encrypted content. The secure processor may decrypt the network encrypted content to produce clear content. In embodiments, the secure processor may then use a local control word to generate locally encrypted content specific to the device. The device may then receive the locally encrypted content from the secure processor and proceed to decrypt the locally encrypted content using a shared local encryption key. The secure processor may connect to the device via a standard connection, such as via a USB 3.0 connector.