Yes, Liski is correct about the key changes.

This is one of the features that makes Irdeto 2 so secure. Irdeto has two models of CA system, MCrypt and PiSys. MCrypt is good for about 100k subs and changes keys monthly, but is inexpensive to diploy and maintain. PiSys is good for more than 1m subs, has multiple key changes per day and can support Simulcypt (and cost about 5x as much as MCrypt to deploy and support) - we use this.

We also use the Epsilon card which has card sharing countermeasures and the ability to download new code to the card. We have done pour best to make a secure CA environment.

So.... no, sorry, but we will continue to cycle keys muultiple times per day - given the gold cards and MDS hacks of the past, we will not compromise on security.

One of our primary assumptions is that your IRD will continue to process ECMs during standby (the SelecTV STB does this) - this is typical of newer IRDs - there is even a feature in the CA to start a download when the STB goes to standby. In your case, your will need to keep your IRD powerd up to avoid the authorisation delay.

I'm always interested to hear of potential failures - we have one or two people working in the teleport - they can't see every problem - some of our best informaton about problems comes from the field.