IP Library Granted Patent US 9,104,882
Granted Patent B2
US 9,104,882 · App. 12/961,899 · Granted Aug 11, 2015

Reconfigurable access network encryption architecture

Inventors: Jorge Daniel Salinger (Littleton, CO); Kevin Taylor (Parker, CO); James William Fahrny (Parker, CO)
Assignee: Comcast Cable Communications, LLC
G06F21/602G06F21/10H04L63/0457H04N21/226H04N21/26606H04N21/631G06F21/604
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,104,882
App. No.
12/961,899
Granted
Aug 11, 2015
Kind
B2
Abstract

An access platform or other network elements can include multiple line cards configured to encrypt data. The platform and/or each of the line cards may receive encryption management data that conforms to a predefined encryption management data interface. The encryption management data received by a particular line card may be generated by a conditional access system device and converted to conform to the encryption management data interface by an encryption manager. Line cards may alternatively be configured for connection to separate encryption hardware components. Line cards may include a block of field programmable gate arrays or other type of programmable hardware that can be configured to execute an encryption module.

Claims (45)

1. A method comprising:

receiving, at a computing device via an encryption management data interface, a first set of encryption management data corresponding to a first conditional access device and a second set of encryption management data corresponding to a second conditional access device;

configuring, by the computing device, a first encryption module and a second encryption module respectively based on the first set of encryption management data and the second set of encryption management data;

receiving, at the computing device via one or more interfaces different from the encryption management data interface, a first set of encryption control data and a second set of encryption control data; and

encrypting, by the configured first encryption module and the configured second encryption module, a first set of content data based on the first set of encryption control data to produce an encrypted first set of content data and a second set of content data based on the second set of encryption control data to produce an encrypted second set of content data, respectively.

2. The method of claim 1 , wherein the first set of encryption management data comprises one or more of encryption settings or encryption parameters, and wherein the first set of encryption control data comprises one or more of control words or entitlement control messages (ECMs).

3. The method of claim 2 , wherein the receiving the first set of encryption management data is from an encryption manager configured to convert the first set of encryption management data from a format associated with the first conditional access device to a format associated with the encryption management data interface.

4. The method of claim 1 , wherein the computing device is a line card, wherein receiving the first set of encryption management data and the second set of encryption management data comprises:

receiving the first set of encryption management data in a standard format associated with the encryption management data interface, the standard format being different from a first format associated with the first conditional access device; and

receiving the second set of encryption management data in the standard format, the standard format being different from a second format associated with the second conditional access device, wherein the first format is different from the second format.

5. The method of claim 4 , wherein the line card is one of a plurality of line cards of an access network platform over which content data is forwarded to one or more end devices in an access network.

6. The method of claim 1 , wherein the computing device is a line card, the method further comprising:

removing, from the line card, the first encryption module; and

installing, at the line card, a third encryption module.

7. The method of claim 1 , further comprising:

modulating the encrypted first set of content data and the encrypted second set of content data with one or more downstream transmission signals.

8. The method of claim 1 , further comprising:

converting the first set of encryption management data from a format associated with the encryption management data interface to another format.

9. A method comprising:

receiving, at a computing device via an encryption management data interface, a first set of encryption management data associated with a first conditional access device and a second set of encryption management data associated with a second conditional access device;

converting the first set of encryption management data from a format associated with the encryption management data interface to a first format and the second set of encryption management data from the format associated with the encryption management data interface to a second format different from the first format;

configuring a first encryption module of the computing device based on the first set of encryption management data in the first format and a second encryption module of the computing device based on the second set of encryption management data in the second format; and

encrypting, by the configured first encryption module and the configured second encryption module, a first set of content data based on a first set of encryption control data to produce an encrypted first set of content data and a second set of content data based on a second set of encryption control data to produce an encrypted second set of content data, respectively.

10. The method of claim 9 , wherein the first set of encryption management data comprises one or more encryption settings or encryption parameters, and wherein the first set of encryption control data comprises one or more of control words or entitlement control messages (ECMs).

11. The method of claim 10 , further comprising,

receiving, at the computing device via one or more interfaces different from the encryption management data interface, the first set of encryption control data and the second set of encryption control data.

12. The method of claim 9 , further comprising:

modulating the encrypted first set of content data with one or more signals.

13. The method of claim 9 , wherein the computing device is a line card, the method further comprising:

removing, from the line card, the first encryption module; and

installing, at the line card, a third encryption module.

14. The method of claim 9 , further comprising:

receiving, at the computing device from a source via one or more interfaces different from the encryption management data interface, the first set of content data.

15. A method comprising:

receiving, at a computing device, a plurality of sets of encryption settings corresponding to a plurality of conditional access devices;

configuring, by the computing device, a plurality of encryption modules respectively based on the plurality of sets of encryption settings;

receiving, at the computing device, a plurality of sets of control words or entitlement control messages (ECMs); and

encrypting, by the configured plurality of encryption modules, a plurality of sets of content data respectively based on the plurality of sets of control words or ECMs to produce an encrypted plurality of sets of content data.

16. The method of claim 15 , wherein:

receiving the plurality of sets of encryption settings is via an encryption settings interface, and

receiving the plurality of sets of controls words or ECMs is via one or more interfaces different from the encryption settings interface.

17. The method of claim 16 , wherein the receiving the plurality sets of encryption settings is respectively from a plurality of encryption managers respectively configured to convert the plurality of sets of encryption settings from a plurality of different formats corresponding to the plurality of conditional access devices to a format associated with the encryption settings interface.

18. The method of claim 15 , further comprising:

modulating the encrypted plurality of sets of content data with one or more signals.

19. The method of claim 15 , wherein the computing device is a line card of a plurality of line cards connected to an access platform.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 7, 2010
From: SALINGER, JORGE DANIEL; TAYLOR, KEVIN; FAHRNY, JAMES WILLIAM
To: COMCAST CABLE COMMUNICATIONS, LLC
Reel/Frame 025462/0012 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 10, 1997
From: LIGHT SOURCE COMPUTER IMAGES, INC.
To: LIGHT SOURCE ACQUISITION COMPANY
Reel/Frame 008595/0318 →
Continuity (1)
Related Publication 20140108782A1 · Apr 17, 2014