USB Transport I/O Secure Processor for Broadcast Content Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Digital Video Broadcasting (DVB) architecture is vulnerable to unauthorized access due to the ease with which the network control word (NCW) can be shared over the Internet, allowing non-subscribers to decrypt broadcasted content.

Innovation Solution

A Transport I/O system that employs a secure processor to decrypt network encrypted content using a network control word, which remains within the secure processor, and then re-encrypts the content using a local control word specific to each device, ensuring that the network control word is never exposed and providing unique encryption for each device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the network control word is shared over the Internet for content decryption, then content accessibility is improved, but security is worsened due to unauthorized access

Engineering Contradiction:
Improvecontent accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A secure processor acts as an intermediary between the network control word and the content decryption process. The secure processor receives the network control word, performs decryption internally, and outputs decrypted content without exposing the control word. This mediator approach allows content accessibility while preventing unauthorized access to the control word.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The network control word is extracted from the general system and isolated within a dedicated secure processor. By separating the control word management from the content processing system, the invention prevents the control word from being exposed during transmission and processing, thus maintaining security while enabling content accessibility.

Inventive Principle:
Principle #2Taking out (Extraction)

2Device complexity

If the network control word is stored externally for easy access, then device complexity is reduced, but security is worsened due to interception risk

Engineering Contradiction:
Improvesystem simplicityVSAvoidinterception risk
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The network control word is nested within the secure processor, which is itself nested within the content processing system. This nested structure allows the control word to be protected within a secure enclave while still being accessible for decryption operations. The secure processor acts as a nested secure module that maintains simplicity at the system level while providing enhanced security for the control word.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If content is encrypted with a unique local control word for each device, then security is improved, but device complexity increases due to key management

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Each device generates and manages its own unique local control word within its secure processor. The secure processor automatically handles the generation, storage, and usage of the local control word without requiring external key management infrastructure. This self-service approach enhances security through unique encryption per device while avoiding the complexity of centralized key management systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9647997B2USB interface for performing transport I/O
Publication Date: 2017.05.09 NAGRASTAR LLC
  • US9647997B2 patent drawing
  • US9647997B2 patent drawing
  • US9647997B2 patent drawing

AI summary

Systems and methods for implementing a Transport I/O system are described. Network encrypted content may be received by a device. The device may provide the network encrypted content to a secure processor, such as, for example, a smart card. The secure processor obtains a network control word that may be used to decrypt the network encrypted content. The secure processor may decrypt the network encrypted content to produce clear content. In embodiments, the secure processor may then use a local control word to generate locally encrypted content specific to the device. The device may then receive the locally encrypted content from the secure processor and proceed to decrypt the locally encrypted content using a shared local encryption key. The secure processor may connect to the device via a standard connection, such as via a USB 3.0 connector.