Downloading data
Abstract
"DATA LOW PROCESS FOR AN MPEG RECEIVER / DECODER SET AND AN MPEG TRANSMISSION SYSTEM FOR IMPLEMENTATION OF THE SAME". In a digital television system, in which a television receives its signal via the receiver / decoder set, such as an upper positioning box, interactive applications can be downloaded and processed in the receiver / decoder set. The application code is arranged as modules and the download of the modules is preceded by the search for a directory module within a specific local address. The modules are flagged and the directory module is flagged and encrypted, so that a single encryption applies to all modules that make up the application. Multiple public encryption keys are stored in ROM in the receiver / decoder set, so that applications can be created by different sources, without the sources having to know each other's private encryption keys. A feature is provided to allow an encryption key to be temporarily stored in RAM in the receiver / decoder set, so that a manufacturer of the receiver / decoder set can test its functionality. A directory signature can be hidden in a variable position in a simulated data block in the directory module. An application to be downloaded can be tested against an application validation bitmap stored in the receiver / decoder set.

Term
Term ended
Projected expiry passed 25 April 2017, 9.4 years ago.
- Priority
- Filed
- Projected expiry
- Today
55 claims: 13 independent, 42 dependent
- 1REIVINDICAÇÕES 1. Processo de baixa de pelo menos parte de uma. aplicação para um conjunto receptor/decodificador MPEG, caracterizado pelo fato de que compreende as etapas de:divisão da aplicação em uma pluralidade de módulos;formatação de cada um dos módulos como uma respectiva tabela MPEG, as tabelas tendo a mesma identificação de tabela (TID) e outras respectivas extensões de identificação de tabela diferentes (extensões TID) do que uma extensão TID predeterminada;geração de uma tabela MPEG de diretórios para os módulos tendo a mesma dita TID e a dita extensão TID predeterminada, o diretório contendo para cada um dos módulos um nome daquele módulo e a respectiva extensão TID;transmissão cíclica da tabela MPEG de diretórios e das tabelas MPEG de módulos em um fluxo de bit MPEG;e no conjunto receptor/decodificador MPEG: recebimento do fluxo de bit MPEG;baixa daquela das tabelas MPEG tendo a extensão TID predeterminada, de modo a baixar a tabela MPEG de diretórios;determinação do conteúdo da tabela MPEG de diretórios das extensões TID das tabelas MPEG de módulos;e baixa de pelo menos uma das tabelas MPEG de módulos tendo a mesma TID que a tabela MPEG de diretórios baixada e uma extensão TID determinada da tabela MPEG de diretórios baixada. 5
- 2Processo de acordo com a reivindicação 1, caracterizado pelo fato de que compreende ainda as etapas de:inclusão na tabela MPEG de diretórios transmitida de uma identificação de versão para ela;e 10 no conjunto receptor/decodificador: determinação se a identificação de versão da tabela MPEG PMT de diretórios atualmente transmitida é mais recente do que a identificação de versão da tabela MPEG de diretórios atualmente baixada e, nesse caso, 15 repetir as etapas de baixa da tabela MPEG de diretórios, determinação das extensões TID e baixa de pelo menos uma das tabelas MPEG de módulos.
- 3Processo de acordo com a reivindicação 1 ou 2, caracterizado pelo fato de que pelo menos uma das 20 tabelas MPEG de módulos é formatada como uma pluralidade de seções MPEG, que são separadamente transmitidas no fluxo de bit MPEG, cada uma das seções MPEG contendo uma determinada parte dela uma identificação daquela seção MPEG e uma indicação do número das seções em uma tabela MPEG.
- 4Conjunto receptor/decodificador MPEG para uso na execução de parte do processo de acordo com qualquer
- 55 uma das reivindicações anteriores, caracterizado pelo fato de que compreende:um receptor para recebimento do fluxo de bit MPEG;um meio de armazenamento;e um meio de processamento que é programado para fazer 10 com que uma das tabelas MPEG recebidas, tendo a extensão TID predeterminada, seja baixada para o meio de armazenamento, para determinar do conteúdo da tabela MPEG de diretórios as extensões TID das tabelas MPEG e de módulos, e fazer com que pelo menos uma das tabelas 15 MPEG de módulos, tendo a mesma TID que aquela da tabela MPEG de diretórios baixada e uma extensão TID determinada do tabela MPEG de diretórios baixada, seja baixada para o meio de armazenamento. 5. Conjunto receptor/decodificador de acordo com a 20 reivindicação 4 para uso com o processo de acordo com a reivindicação 2, caracterizado pelo fato de que o meio de processamento é programado para determinar se uma identificação de versão da tabela MPEG de diretórios atualmente recebida é mais recente do que uma identificação de versão da tabela MPEG de diretórios baixada e, nesse caso, repetir as etapas de baixa da tabela MPEG de diretórios, determinação das extensões TID e baixa de pelo menos uma das tabelas MPEG de módulos.
- 6Conjunto receptor/decodificador de acordo com a reivindicação 4 ou 5 para uso com o processo de acordo com a reivindicação 3, caracterizado pelo fato de que o meio de processamento é programado para fazer com que as seções MPEG sejam repetidamente baixadas para o meio de armazenamento, até que o meio de processamento determine das identificações de seção e da indicação do número da seção das seções baixadas que todas as seções tenham sido baixadas.
- 7Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 4 a 6, caracterizado pelo fato de que compreende ainda uma porta paralela e/ou uma porta serial, dispostas para receber uma aplicação formatada como pelo menos uma tabela MPEG.
- 8Sistema de transmissão MPEG caracterizado pelo fato de que compreende:um meio para divisão em uma pluralidade de módulos de uma aplicação a ser baixada em um conjunto receptor/decodificador MPEG;um meio para formatar cada um dos módulos como uma tabela MPEG respectiva, as tabelas tendo a mesma TID e outras extensões TID diferentes respectivas do que uma extensão TID predeterminada;um meio para gerar uma tabela MPEG de diretórios para os modelos tendo a mesma TID e a dita extensão TID predeterminada, o diretório contendo para cada um dos módulos um nome daquele módulo e a respectiva extensão TID;e um meio para transmitir ciclicamente a tabela MPEG de diretórios e as tabelas MPEG de módulos em um fluxo de bit MPEG.
- 9Sistema de acordo com a reivindicação 8, caracterizado pelo fato de que compreende ainda um meio para gerar uma identificação de versão para a tabela MPEG de diretórios;e em que o meio gerador de tabela MPEG de diretórios é operável para incluir na tabela MPEG de diretórios a identificação de versão gerada para ela.
- 10Sistema de acordo com a reivindicação 8 ou 9, caracterizado pelo fato de que o meio de formatação de módulos é operável para formatar pelo menos uma das tabelas MPEG de módulos como uma pluralidade de seções MPEG, cada uma delas contendo em uma parte determinada dela uma identificação daquela seção MPEG naquela tabela MPEG e uma indicação do número das seções MPEG naquela tabela MPEG.
- 11Processo de baixa de dados para um conjunto 5 receptor/decodificador MPEG, caracterizado pelo fato de que compreende as etapas de:geração de uma assinatura para os dados a serem baixados;criptografação da assinatura usando uma chave privada;formatação dos dados a serem baixados, a 10 assinatura criptografada e uma identificação para a chave privada como uma tabela MPEG;transmissão da tabela MPEG;e no conjunto receptor/decodificador: recebimento da tabela MPEG;15 seleção de uma de uma pluralidade de chaves públicas de acordo com a identificação de chave na tabela MPEG recebida;decifração da assinatura criptografada na tabela MPEG recebida usando a chave pública selecionada para 20 proporcionar uma assinatura decifrada;geração de uma assinatura para os dados na tabela MPEG recebida;e comparação da assinatura decifrada e da assinatura gerada no conjunto receptor/decodificador para os dados recebidos.
- 12Processo de acordo com a reivindicação 11, caracterizado pelo fato de que compreende ainda as etapas de baixa para o conjunto receptor/decodificador de uma aplicação tendo uma assinatura criptografada usando uma chave privada tendo uma identificação de chave predeterminada;processamento da aplicação no conjunto receptor/decodificador, para fazer com que o conjunto receptor/decodificador receba uma outra chave;armazenamento da outra chave na área de memória volátil do conjunto receptor/decodificador.
- 13Processo de acordo com a reivindicação 12, caracterizado pelo fato de que durante a etapa de processamento da aplicação, a outra é fornecida localmente ao conjunto receptor/decodificador.
- 14Processo de acordo com a reivindicação 13, caracterizado pelo fato de que a outra chave é fornecida ao conjunto receptor/decodificador via uma porta paralela, uma porta serial ou uma leitora de cartão inteligente do conjunto receptor/decodificador.
- 15Processo de acordo com qualquer uma das reivindicações de 11 a 14, caracterizado pelo fato de que inclui ainda as etapas, no conjunto receptor/decodificador, de consulta, em uma área protegida de uma memória do conjunto receptor/decodificador, uma sinalização de validação para a chave pública selecionada, e inibição ou abortamento da baixa dos dados se a sinalização consultada não está posicionada.
- 16Processo de acordo com a reivindicação 15, quando dependente de qualquer uma das reivindicações de 12 a 14, caracterizado pelo fato de que, na área de memória protegida do conjunto receptor/decodificador, a chave privada tendo a identificação de chave tem uma sinalização de validação, que pode ser alterada pela dita aplicação, e uma capacidade de receber uma outra chave é determinada na dependência do estado da sinalização de validação.
- 17Processo de baixa de dados para um conjunto receptor/decodificador MPEG, caracterizado pelo fato de que compreende as etapas de:geração de uma assinatura para os dados a serem baixados;criptografação da assinatura usando uma chave privada;formatação dos dados a serem baixado, a assinatura criptografada e uma identificação para a chave privada como uma tabela MPEG;transmissão da tabela MPEG;e no conjunto receptor/decodificador: recebimento da tabela MPEG;consulta, em uma área protegida da memória do conjunto receptor/decodificador, de uma sinalização de validação para uma chave pública correspondente à chave privada identificada na tabela MPEG recebida;e se a sinalização consultada está posicionada: decifrar a assinatura criptografada na tabela MPEG recebida usando ã..... chave pública correspondente, para ser a chave privada identificada na tabela MPEG recebida, para proporcionar uma assinatura decifrada;geração de uma assinatura para os dados na tabela MPEG recebida;e comparação da assinatura decifrada e da assinatura gerada no conjunto receptor/decodificador para os dados recebidos.
- 18Processo de acordo com qualquer uma das reivindicações de 11 a 17, caracterizado pelo fato de que inclui ainda as etapas de:geração de um código de validação para os dados a serem baixados, o código de validação sendo criptografado com a assinatura na etapa de criptografação e sendo decifrado com a assinatura na etapa de decifração;consulta de um código de validação armazenado em uma área protegida da memória do conjunto receptor/decodificador;e comparação do código de validação consultado e do código de validação decifrado.
- 19Processo de baixa para um conjunto receptor/decodificador MPEG, caracterizado pelo fato de que compreende as etapas de:geração de um código de validação para os dados a serem baixados;geração de uma assinatura para os dados a serem baixados, ou uma parte deles;criptografação do código de validação e da assinatura usando uma chave privada;formatação dos dados a serem baixados e do código de validação e da assinatura criptografados como pelo menos uma tabela MPEG;transmissão da ou de cada tabela MPEG;e no conjunto receptor/decodificador: recebimento da ou de cada tabela MPEG;•« v t -· ο » - · ;i · frí w · .) · '* Ο Ο V J J ί Ο’ ».· • v «Ο » J J ·» ’ J · O o- J.T» O ) · · · Q . Q? · · Ο · - · J · AJT • KJ 4 ·0· · ' »Z-♦ ·♦ decifração do código de validação e assinatura criptografados na(s) tabela (s) MPEG usando uma chave pública correspondente à chave privada;consulta de um código de validação armazenado em uma área protegida da memória do conjunto receptor/decodificador;comparação do código de validação consultado e do código de validação decifrado;geração de uma assinatura para os dados na(s) tabela(s) MPEG recebida(s);e comparação da assinatura decifrada com a assinatura gerada no conjunto receptor/decodificador para os dados recebidos.
- 20Processo de acordo com a reivindicação 18 ou 19, caracterizado pelo fato de que inclui ainda a etapa de inibição ou abortamento da baixa de dados se, na etapa de comparação do código de validação, o código de validação consultado e o código de validação decifrado não são comparáveis entre si.
- 21Processo de acordo com qualquer uma das reivindicações de 11 a 20, caracterizado pelo fato de que a assinatura dos dados a serem baixados é criptografada em um bloco de dados incluindo outros dados, com um desvio selecionado entre o início do bloco de dados e o início da assinatura, e o bloco de dados criptografado é decifrado na etapa de decifração no conjunto receptor/decodificador, e incluindo ainda as etapas, no conjunto receptor/decodificador, de consulta de pelo menos um desvio armazenado em uma área protegida da memória do conjunto receptor/decodificador, e extração da assinatura do bloco de dados decifrado usando um desvio consultado do início do bloco de dados decifrados.
- 22Processo de baixa de dados para um conjunto receptor/decodificador MPEG, caracterizado pelo fato de que compreende as etapas de:geração de uma assinatura para os dados a serem baixados;inclusão da assinatura e de outros dados em um bloco de dados com um desvio selecionado entre o início do bloco de dados e o início da assinatura;criptografação do bloco de dados usando uma chave privada;formatação dos dados a serem baixados e do bloco de dados decifrados como uma tabela MPEG;transmissão da tabela MPEG;e no conjunto receptor/decodificador: recepção da tabela MPEG;decifração do bloco de dados criptografados na tabela MPEG recebida, usando uma chave pública correspondente à chave privada;consulta de pelo menos um desvio armazenado em uma área protegida da memória do conjunto receptor/decodificador;extração da assinatura do bloco de dados decifrados usando o dito um desvio consultado do início do bloco de dados decifrados;geração de uma assinatura para os dados na tabela MPEG recebida;e comparação da assinatura extraída do bloco de dados decifrados com a assinatura gerada no conjunto receptor/decodificador para os dados recebidos.
- 23Processo de acordo com a reivindicação 21 ou 22, caracterizado pelo fato de que a dita área protegida da memória tem pelo menos dois desses desvios armazenados, se na etapa de comparação a assinatura extraída e a assinatura gerada não são comparáveis, o processo incluindo as etapas de repetição das etapas de consulta, extração e comparação, usando outros dos desvios armazenados.
- 24Processo de acordo com qualquer uma das reivindicações de 21 a 23, caracterizado pelo fato de que pelo menos parte dos ditos outros dados no bloco de dados é dados simulados ou arbitrários.
- 25Processo de acordo com qualquer uma das reivindicações de 11 a 24, caracterizado pelo fato de 5 que os dados são baixados como uma pluralidade de módulos dos dados, e incluindo as etapas de:geração de uma assinatura de módulo para cada módulo de dados a ser baixado;formatação dos módulos de dados como as respectivas 10 tabelas MPEG de módulos;geração de um diretório incluindo uma identificação de cada tabela MPEG de módulos e da respectiva assinatura, o diretório sendo o objeto da etapa de geração de assinatura de acordo com qualquer uma das 15 reivindicações de 11 a 24;e no conjunto receptor/decodi ficador: geração de uma respectiva assinatura de módulo para cada um dos módulos nas tabelas MPEG de módulos recebidas;e 20 comparação de cada assinatura de módulo na tabela MPEG de diretórios recebida com a respectiva assinatura do módulo gerada no conjunto receptor/decodificador.
- 26Processo de baixa de uma pluralidade de módulos de dados para um conjunto receptor/decodificador MPEG, caracterizado pelo fato de que compreende as etapas de:geração de uma assinatura de módulo para cada módulo de dados a ser baixado;formatação dos módulos como as respectivas tabelas MPEG 5 de módulos;geração de um diretório incluindo uma identificação de cada tabela MPEG de módulos e da respectiva assinatura;geração de uma assinatura de diretório para o diretório;criptografação da assinatura de diretório 10 usando uma chave privada;formatação da assinatura do diretório e do diretório criptografada como uma tabela MPEG de diretórios;transmissão das tabelas MPEG de módulos e diretórios;e no conjunto receptor/decodificador: 15 recebimento das tabelas MPEG de módulos e diretórios;decifração da assinatura de diretório criptografada na tabela MPEG de diretórios recebida usando uma chave pública correspondente à chave privada;20 geração de uma assinatura de diretório para o diretório na tabela MPEG de diretórios recebida;comparação da assinatura de diretório criptografada e da assinatura de diretório gerada no conjunto receptor/decodificador;geração de uma respectiva assinatura de módulo para cada um dos módulos nas tabelas MPEG de módulos recebidas;e comparação de cada assinatura de módulo na tabela MPEG de diretórios recebida com a respectiva assinatura de módulo gerada no conjunto receptor/decodificador.
- 27Processo de acordo com a reivindicação 25 ou 26, caracterizado pelo fato de que inclui ainda a etapa de inibição ou abortamento da baixa desse módulo de dados se, na etapa de comparação da assinatura do módulo, a assinatura do módulo na tabela MPEG de diretórios recebida e a respectiva assinatura de módulo recebida gerada no conjunto receptor/decodificador para aquele módulo não são comparáveis entre si.
- 28Processo de acordo com qualquer uma das reivindicações de 11 a 27, caracterizado pelo fato de que inclui ainda a etapa de inibição ou abortamento da baixa dos dados se, na(s) etapa(s) de comparação, a ou cada assinatura decifrada e a assinatura gerada não são comparáveis entre si.
- 29Conjunto receptor/decodificador MPEG para uso na execução de parte do processo de acordo com a reivindicação 11, caracterizado pelo fato de que compreende:um meio para recebimento dessas tabelas MPEG;I 17 :·. : .·. ··:.: : :” ·*··’· ·.· : ·.: .· J :.: *··,· ! ! · ··· · · «···♦ um meio para armazenamento de uma pluralidade de chaves públicas e uma identificação para cada uma das chaves públicas;e um meio de processamento que é programado para selecionar uma das chaves públicas armazenadas de acordo com a identificação da chave na tabela MPEG recebida;decifrar a assinatura criptografada na tabela MPEG recebida usando a chave pública selecionada para proporcionar uma assinatura decifrada;gerar uma assinatura para os dados na tabela MPEG recebida;e comparar a assinatura decifrada e a assinatura gerada no conjunto receptor/decodificador para os dados recebidos.
- 30Conjunto receptor/decodificador de acordo com a reivindicação 29, caracterizado pelo fato de que o meio de armazenamento de chaves é proporcionado pela ROM.
- 31Conjunto receptor/decodificador de acordo com a reivindicação 29 ou 30, caracterizado pelo fato de que a identificação para cada uma das chaves públicas é proporcionada pelo local de armazenamento daquela chave pública no meio de armazenamento de chaves.
- 32Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 29 a 31 para uso no processo de acordo com a reivindicação 14, caracterizado pelo fato de que inclui ainda uma área de memória volátil e em que o meio de processamento é operável para baixar uma aplicação tendo uma assinatura criptografada usando uma chave privada tendo uma identificação de chave predeterminada, para processar a aplicação, para fazer com que o conjunto receptor/decodificador receba uma outra chave, e para fazer com que a outra chave seja armazenada na área de memória volátil.
- 33Conjunto receptor/decodificador de acordo com a reivindicação 32, caracterizado pelo fato de que inclui ainda um meio para receber uma outra chave, que é fornecida localmente ao conjunto receptor/decodificador.
- 3435. Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 32 a 34, caracterizado pelo fato de que a memória volátil é proporcionada pela RAM.
- 3536. Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 29 a 35 para uso no processo de acordo com a reivindicação 15, caracterizado pelo fato de que inclui ainda uma área protegida de memória para armazenamento de uma sinalização de validação para cada uma de pelo menos parte das chaves públicas, e em que o meio de processamento é programado para consultar, na área protegida de memória, a sinalização de validação para essa chave pública selecionada, e inibir ou abortar a baixa dos dados, se a sinalização consultada não está posicionada.
- 3637. Conjunto receptor/decodificador de acordo com a reivindicação 36, quando dependente de qualquer uma das reivindicações de 32 a 35, caracterizado pelo fato de que inclui ainda uma área protegida de memória para armazenamento de uma sinalização de validação para a chave privada tendo a identificação de chave predeterminada, e o meio de processamento é operável quando o processamento da dita aplicação mudar aquela sinalização de validação e é operável para permitir que outra chave seja armazenada na dependência do estado daquela sinalização.
- 3738. Conjunto receptor/decodificador MPEG para uso na execução de parte do processo de acordo com a reivindicação 17, caracterizado pelo fato de que compreende:um meio para recebimento dessas tabelas MPEG;iim meio para armazenamento de uma chave pública e uma identificação para a chave pública;e uma área protegida de memória para armazenamento de uma sinalização de validação para a chave pública;e 5 um meio de processamento, que é programado para consultar, na área protegida de memória do conjunto receptor/decodificador, uma sinalização de validação para a chave pública correspondente à chave privada identificada na tabela MPEG recebida;e, se a 10 sinalização consultada está posicionada, decifrar a assinatura criptografada na tabela MPEG recebida usando a chave pública correspondente para ser a chave privada na tabela MPEG recebida, para proporcionar uma assinatura decifrada, para gerar uma assinatura para os 15 dados na tabela MPEG recebida;e comparar a assinatura decifrada e a assinatura gerada pelo conjunto receptor/decodificador para os dados recebidos.
- 3839. Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 36 a 38, 20 caracterizado pelo fato de que a memória para armazenamento da(s) sinalização(ções) de validação de chave é proporcionada por memória não volátil rescrevivel.
- 3940. Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 36 a 39, caracterizado pelo fato de que no caso no qual uma pluralidade dessas chaves públicas é armazenada, a memória para armazenamento da(s) sinalização(ções) de validação é disposta como um mapa de bit.
- 4041. Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 29 a 40 para uso no processo de acordo com a reivindicação 17, caracterizado pelo fato de que inclui ainda uma área protegida de memória para armazenamento de um código de validação, e em que o meio de processamento é programado para decifrar o código de validação nessa tabela MPEG recebida, para consultar o código de validação armazenado, e comparar o código de validação consultado e o código de validação decifrado.
- 4142. Conjunto receptor/decodificador MPEG para uso na execução de parte do processo de acordo com a reivindicação 17, caracterizado pelo fato de que compreende:um meio para recebimento dessas tabelas MPEG;um meio para armazenamento de uma chave pública e uma identificação para a chave pública;uma área protegida de memória para armazenamento de um código de validação;e um meio de processamento, que é programado para decifrar o código de validação e a assinatura criptografados nessas tabelas MPEG recebidas usando a chave pública armazenada correspondente à chave privada;consultar o código de validação armazenado na área protegida de memória;comparar o código de validação consultado e o código de validação decifrado;gerar uma assinatura para os dados na tabela MPEG recebida ou dita parte dela;e comparar a assinatura decifrada com a assinatura gerada pelo conjunto receptor/decodificador para os dados recebidos.
- 4243. Conjunto receptor/decodificador de acordo com a reivindicação 41 ou 42, caracterizado pelo fato de que o meio de processamento é programado para inibir ou abortar a baixa dos dados, se o código de validação consultado e o código de validação decifrado não são comparáveis entre si.
- 4344. Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 41 a 44, caracterizado pelo fato de que a memória para armazenamento dos códigos de validação é disposta como um mapa de bit.
- 4445. Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 41 a 44, caracterizado pelo fato de que a memória para armazenamento dos códigos de validação é disposta como um mapa de bit.
- 4546. Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 29 a 45 para uso em um processo de acordo com a reivindicação 21, caracterizado pelo fato de que inclui ainda uma área protegida de memória para armazenamento de pelo menos um desvio, e em que o meio de processamento é programado para decifrar o bloco de dados criptografados nessa tabela MPEG recebida, consultar o dito um desvio armazenado na área protegida de memória, e extrair do bloco de dados criptografados usando o desvio consultado do início do bloco de dados decifrados.
- 4647. Conjunto receptor/decodificador para uso na execução de parte do processo de acordo com a reivindicação 22, caracterizado pelo fato de que compreende:um meio para recebimento dessas tabelas MPEG;um meio para armazenamento de uma chave pública e uma identificação para a chave pública;uma área protegida de memória para armazenamento de pelo menos um desvio;e um meio de processamento, que é programado para decifrar o bloco de dados criptografados nessa tabela 5 MPEG recebida usando a chave pública armazenada correspondente à chave privada;consultar o dito um desvio armazenado na área protegida de memória;extrair a assinatura do bloco de dados decifrados usando o desvio consultado do início do bloco de dados 10 decifrados;gerar uma assinatura para os dados na tabela MPEG recebida ou dita parte dela;e comparar a assinatura extraída do bloco de dados decifrados com a assinatura gerada pelo conjunto receptor/decodificador para os dados recebidos. 15
- 4748. Conjunto receptor/decodificador de acordo com a reivindicação 4 6 ou 47, caracterizado pelo fato de que pelo menos dois desses desvios são armazenados na área protegida da memória, e o meio de processamento é operável, se a assinatura extraída e a assinatura 20 gerada não são comparáveis, para repetir a consulta, extração e comparação, usando outro dos desvios armazenados.
- 4849. Conjunto receptor/decodificador de acordo com a reivindicação 4 6 ou 48, caracterizado pelo fato de que a memória para armazenamento dos códigos de validação é proporcionada por memória não volátil rescrevivel.
- 4950. Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 29 a 49 para uso em um processo de acordo com a reivindicação 25, caracterizado pelo fato de que o meio de processamento é programado para gerar uma respectiva assinatura de módulo para cada um dos módulos nas tabelas MPEG de módulos recebidas, e comparar cada assinatura de módulo na tabela MPEG de diretórios recebida com a respectiva assinatura de módulo gerada pelo conjunto receptor/decodificador.
- 5051. Conjunto receptor/decodificador MPEG para uso na execução de parte do processo de acordo com a reivindicação 26, caracterizado pelo fato de que compreende:um meio para recebimento dessas tabelas MPEG de módulos e diretórios;um meio para armazenamento de uma chave pública e uma identificação para a chave pública;e um meio de processamento, que é programado para decifrar a assinatura de diretório criptografada na tabela MPEG de diretórios recebida, usando a chave pública armazenada correspondente à chave privada;gerar uma assinatura de diretório para o diretório na tabela MPEG;comparar a assinatura de diretório decifrada e a assinatura de diretório gerada pelo conjunto receptor/decodificador;gerar uma respectiva assinatura de módulo para cada um dos módulos nas tabelas MPEG de módulos recebidas;e comparar cada assinatura de módulo na tabela MPEG de diretórios recebida com a respectiva assinatura de módulo gerada pelo conjunto receptor/decodificador.
- 5152. Conjunto receptor/decodificador de acordo com a reivindicação 50 ou 51, caracterizado pelo fato de que o meio de processamento é programado para inibir ou abortar a baixa desse módulo de dados, se a assinatura do módulo na tabela MPEG de diretórios recebida e a respectiva assinatura de módulo gerada no conjunto receptor/decodificador para aquele módulo não são comparáveis entre si.
- 5253. Conjunto receptor/decodificador de acordo com qualquer uma das reivindicações de 29 a 52, caracterizado pelo fato de que o meio de processamento é programado para inibir ou abortar a baixa dos dados, se a ou cada assinatura decifrada e a assinatura gerada não são comparáveis entre si.
- 5354. Processo de baixa de pelo menos parte de uma aplicação para um conjunto receptor/decodificador MPEG, caracterizado pelo fato de que é substancialmente como descrito com referência aos desenhos. 5
- 5455. Conjunto receptor/decodificador caracterizado pelo fato de que é substancialmente como descrito com referência aos desenhos.
- 5556. Sistema de transmissão MPEG caracterizado pelo fato de que é substancialmente como descrito com 10 referência aos desenhos. WO 98/43431 PCT/EP97/02111 1/9
Independent claims55
225 paragraphs, as filed
(54) Title. DATA LOW PROCESS FOR AN MPEG RECEIVER / DECODER SET AND AN MPEG TRANSMISSION SYSTEM FOR IMPLEMENTATION OF THE SAME (30) Unionist Priority: 3/21/1997 ep 97400650.4 (71) Depositor (s): Canal + Societe Anonyme Telecommunications Company ( FR) (72) Inventor (s): Jean-Claude Sarfati, Jerome Meric (74) Attorney: Di Blasi, Parente, SG & Associados S / C (86) International Order: pctep97 / 021h of 25/04/1997 (87) International Publication: wo 98/43431 of 10/01/1998 (57) Summary: DATA LOW PROCESS FOR A RECEIVER SET / MPEG DECODER AND AN MPEG TRANSMISSION SYSTEM FOR IMPLEMENTATION OF THE SAME. In a digital television system, in which a television receives its signal via the receiver / decoder set, such as an upper positioning box, interactive applications can be downloaded and processed in the receiver / decoder set. The application code is arranged as modules and the download of the modules is preceded by the search for a directory module within a specific local address. The modules are flagged and the directory module is flagged and encrypted, so that a single encryption applies to all modules that make up the application. Multiple public encryption keys are stored in ROM in the receiver / decoder set, so that applications can be created by different sources, without the sources having to know each other's private encryption keys. A feature is provided to allow an encryption key to be temporarily stored in RAM in the receiver / decoder set, so that a manufacturer of the receiver / decoder set can test its functionality. A directory signature can be hidden in a variable position in a simulated data block in the directory module. An application to be downloaded can be tested against an application validation bitmap stored in the receiver / decoder set.
<img file="BR9714592A_D0001.tif" />
--- KBTIP__ “~ ___ L ·<sup>-</sup>«Encrypted SIGNATURE
<img file="BR9714592A_D0002.tif" />
Invention Patent Descriptive Report
DATA LOW PROCESS FOR AN MPEG RECEIVER / DECODER SET AND AN MPEG TRANSMISSION SYSTEM FOR IMPLEMENTATION OF THE SAME ”.
This invention refers to:
- a data download process for an MPEG receiver / decoder set;
- the MPEG receiver / decoder set itself; and
- an MPEG transmission system.
The advent of digital transmission systems intended primarily for broadcasting television signals, in particular but not exclusively satellite television systems, opened up the possibility of using these systems for other purposes. One of these is to provide interactivity with the end user.
One way to do this is to run an application on the receiver / decoder set, through which the television signal is received. The code for the application could be permanently stored in the receiver / decoder set. However, this would be relatively limiting. Preferably, the receiver / decoder assembly should be able to download the code for a required application. In this way, more variety can be provided and applications can be updated when necessary, without any action on the part of the user.
In an MPEG system, the application code can be downloaded from the MPEG tables. However, there is a limit on the size of a piece of code that can be downloaded using a single MPEG table. Furthermore, it is necessary for an entire application to be downloaded before 10 is processed, thus providing a delay that is unacceptable for the user. Therefore, there is a desire that it is possible to download an application as a plurality of modules. However, this then creates the problem of being able to identify and extract from the MPEG 15 bit stream the modules needed for a particular application. A first aspect of the present invention is related to this problem.
According to a first aspect of the present invention, a download process for at least part of an application is provided for an MPEG receiver / decoder set, comprising the steps of: dividing the application into a plurality of modules; formatting each of the modules as a respective MPEG table, the tables having the same table identification (TID) and other respective different table identification extensions (TID extensions). that a predetermined TID extension; generation of an MPEG table of directories for the modules having the same said TID and said predetermined TID extension, the directory containing for each of the modules a name of that module and the respective TID extension; cyclic transmission of the MPEG directory table and the MPEG module tables in an MPEG bit stream; and in the MPEG receiver / decoder set: receiving the MPEG bit stream; download from that of the MPEG tables having the predetermined TID extension, in order to download the MPEG directory table; determining the content of the MPEG table of directories of the TID extensions of the MPEG module tables; and download at least one of the module's MPEG tables having the same TID as the downloaded MPEG directory table and a given TID extension from the downloaded MPEG directory table.
Consequently, an application consists of several modules, which can be downloaded and, if appropriate, processed if necessary. The directory table can be readily identified by having a particular TID extension and once it has been downloaded it allows the receiver / decoder set
<img file="BR9714592A_D0003.tif" />
identify the modules of their respective TID extensions.
The process preferably comprises the steps of: inclusion in the MPEG table of directories transmitted from a version identification to it; and in the receiver / decoder set: determining whether the version identification of the MPEG PMT directory table currently transmitted is more recent than the version identification of the MPEG directory table currently downloaded and, in this case, repeat the steps for downloading the MPEG table of directories, determination of TID extensions and download of at least one of the MPEG module tables.
Consequently, in the event that an application needs to be changed, it should be automatically detected and the updated directory and any updated modules can be downloaded.
At least one of the MPEG module tables can be formatted as a plurality of MPEG sections, which are separately transmitted in the MPEG bit stream, each of the MPEG sections containing a certain part of it an identification of that MPEG section and an indication of the number of sections in an MPEG table.
According to a second aspect of the present invention, an MPEG receiver / decoder set is provided for use in performing part of the process of the first aspect of the invention, comprising: a receiver for receiving the MPEG bit stream; a storage medium; and a processing medium that is programmed to cause one of the received MPEG tables, having the predetermined TID extension, to be downloaded to the storage medium, to determine from the MPEG directory table contents the TID extensions of the MPEG tables and modules , and make at least one of the MPEG module tables, having the same TID as that of the downloaded MPEG directory table and a given TID extension of the downloaded MPEG directory table, downloaded to the storage medium.
Preferably, the processing medium is programmed to determine whether a version ID of the MPEG directory table currently received is more recent than a version ID of the downloaded MPEG directory table, in which case, repeat the steps for downloading the table MPEG directories, determining the TID extensions and downloading at least one of the MPEG module tables.
In the case where the receiver / decoder set is arranged to receive at least one of the module tables formatted as a plurality of sections transmitted separately, the processing medium is preferably programmed to cause the MPEG sections to be repeatedly downloaded to the storage medium, until the processing medium determines from the section IDs and the indication of the section number of the downloaded sections that all sections have been downloaded.
Preferably, the receiver / decoder set further comprises a parallel port and / or a serial port, arranged to receive an application formatted as at least an MPEG table, in which case the short MPEG-2 format is preferably employed, although the long MPEG-2 format is preferably used for remote reception, for example, by satellite or cable.
This is particularly useful in the case where a manufacturer wants to test particular characteristics of the receiver / decoder set, since an application can be downloaded without having to be transmitted via the satellite television system.
In accordance with a third aspect of the present invention, an MPEG transmission system is provided comprising: a means for dividing into a plurality of application modules to be downloaded into an MPEG receiver / decoder set; a means to format each of the modules as a respective MPEG 5 table, the tables having the same TID and other respective different TID extensions than a predetermined TID extension; a means for generating an MPEG table of directories for models having the same TID and said predetermined TID extension, directory 10 containing for each of the modules a name of that module and the respective TID extension; and a means for cyclically transmitting the MPEG directory table and the MPEG module tables in an MPEG bit stream.
Preferably, the system further comprises a means 15 for generating a version identification for the table
MPEG directories; and where the table generating means
MPEG directories are operable to include in the table
MPEG directories the version ID generated for it.
The module formatting means may be operable to format at least one of the MPEG module tables as a plurality of MPEG sections, each containing a specific part of it in the MPEG section in that MPEG table and an indication of the number of sections MPEG in that MPEG table.
Desirably, the receiver / decoder set could be protected against the download of unauthorized applications that could contain, for example, a virus. Consequently, the concepts of encryption and symbolization of at least part of the application code can be contemplated.
According to a fourth aspect of the present invention, a data download process is provided for an MPEG receiver / decoder set, comprising the steps of: generating a signature for the data to be downloaded; encryption of the signature using a private key; formatting of the 15 data to be downloaded, the encrypted signature and an identification for the private key as an MPEG table; transmission of the MPEG table; and in the receiver / decoder set: receipt of the MPEG table; selecting one of a plurality of public keys according to the key identification in the received MPEG table; decryption of the encrypted signature in the MPEG table received using the selected public key to provide an encrypted signature; generation of a signature for the data in the received MPEG table; and comparing the deciphered signature and the signature generated in the receiver / decoder set for the received data.
Consequently, the receiver / decoder set can be used to download applications having encrypted signatures from more than one source, without the sources having to know each of the other private keys.
The process may further comprise the download steps for the receiver / decoder set of an application having an encrypted signature using a private key having a predetermined key identification; processing the application in the receiver / decoder set to make the receiver / decoder set receive another key; storage of the other key in the volatile memory area of the receiver / decoder set. In this case, during the application processing step, the other key can be supplied locally to the receiver / decoder set. If the receiver / decoder set has a modem connection, the receiver / decoder set is preferably arranged to prevent another key from being provided via the modem.
<img file="BR9714592A_D0004.tif" />
These features allow a manufacturer, who may want to test a receiver / decoder set, to download a key to the receiver / decoder set.
0 The process may also include the steps, in the receiver / decoder set, of consultation, in a protected area of a memory of the receiver / decoder set, a validation signal for the selected public key, and inhibition or abort of data download if the consulted signage is not positioned.
Consequently, although a plurality of public keys can be permanently provided in the memory of the receiver / decoder set, any one of them can be selectively disabled, which may be necessary in the case, for example, in which the privacy of a private key associated with a private public key is violated, or when two operators, who are using the same keys, 20 decide that they want to have separate keys.
In the case where the receiver / decoder set is arranged to download an application, having a signature encrypted using a private key having a key identification, as mentioned above, in
<img file="BR9714592A_D0005.tif" />
protected memory area of the receiver / decoder set, the private key having the key identification can have a validation signal, which can be changed by said application, and an ability to receive another key is determined depending on the signaling state validation.
These latter characteristics of validation flags for public keys can be provided regardless of the fourth aspect of the invention. Consequently, a fifth aspect of the present invention provides a data download process for an MPEG receiver / decoder set, comprising the steps of: generating a signature for the data to be downloaded; encryption of the signature using a private key; formatting of the data to be downloaded, the encrypted signature and an identification for the private key as an MPEG table; transmission of the MPEG table; and in the receiver / decoder set: receipt of the MPEG table;
consultation, in a protected area of the memory of the receiver / decoder set, of a validation signal for a public key corresponding to the private key identified in the received MPEG table; and if the consulted signage is positioned: decipher the
<img file="BR9714592A_D0006.tif" />
encrypted signature on the MPEG table received using the corresponding public key, to be the private key identified in the received MPEG table, to provide an encrypted signature; generation of a signature for the data in the received MPEG table; and comparing the decrypted signature and the signature generated in the receiver / decoder set for the received data.
The processes of the fourth and fifth aspects of the invention preferably also include the steps of: generating a validation code for the data to be downloaded, the validation code being encrypted with the signature in the encryption step and being deciphered with the signature in the deciphering stage;
consultation of a validation code stored in a protected area of the receiver / decoder memory; and comparison of the validated code consulted and the deciphered validation code.
Consequently, the receiver / decoder set can be prepared to receive only certain applications or types of applications.
These characteristics can be provided independently of the fourth and fifth aspects of
<img file="BR9714592A_D0007.tif" />
invention. Consequently, a sixth aspect of the present invention provides a data download process for an MPEG receiver / decoder set, comprising the steps of: generating a validation code for the data to be downloaded; generation of a signature for the data to be downloaded, or a part of it; encryption of the validation code and signature using a private key; formatting the data to be downloaded and the validation code and signature encrypted as at least one MPEG table; transmission of or of each MPEG table; and in the receiver / decoder set: receiving the or each MPEG table; decryption of the validation and signature code encrypted in the MPEG table (s) using a public key corresponding to the private key; consultation of a validation code stored in a protected area of the receiver / decoder memory; comparison of the consulted validation code and the deciphered validation code; generation of a signature for the data in the MPEG table (s) received; and comparing the deciphered signature with the signature generated in the receiver / decoder set for the received data.
Preferably, the process also includes the step of inhibiting or aborting the data download if, in the validation code comparison step, the consulted validation code and the deciphered validation code are not comparable with each other.
In the fourth to sixth aspects of the invention, it is possible to provide that the signature of the data to be downloaded is encrypted in a data block including other data, with a selected deviation between the beginning of the data block and the beginning of the signature, and the encrypted data block is deciphered in the decryption step in the receiver / decoder set, and also including the steps in the receiver / decoder set, querying at least one branch stored in a protected memory area of the receiver / decoder set, and extracting the signature from the deciphered data block using a branch consulted from the beginning of the deciphered data block.
Consequently, the signature can be disguised among other simulated data, making it more difficult to determine the location of the signature. Alternatively, or in addition, this feature allows data to be made available only to one or more particular groups of the receiver / decoder sets.
These features can be provided independently of the fourth to sixth aspects of the invention. Consequently, a seventh aspect of the present invention provides a data download process for an MPEG receiver / decoder set, comprising the steps of: generating a signature for the data to be downloaded; inclusion of signature 10 and other data in a data block with a deviation selected between the beginning of the data block and the beginning of the signature; encryption of the data block using a private key; formatting of the data to be downloaded and of the decrypted data block as a table
MPEG; transmission of the MPEG table; and in the receiver / decoder set: reception of the MPEG table;
decryption of the encrypted data block in the received MPEG table, using a public key corresponding to the private key; consultation of at least one diversion 20 stored in a protected area of the memory of the receiver / decoder set; extracting the signature from the decrypted data block using said consulted deviation from the beginning of the decrypted data block; generation of a signature for the data in the received MPEG table; and comparing the signature extracted from the deciphered data block with the signature generated in the receiver / decoder set for the received data.
In the case in which the said protected memory area has at least two of these deviations stored, if in the comparison step the extracted signature and the generated signature are not comparable, the process preferably includes the repetition steps of the consultation steps, extraction and comparison, using other stored deviations.
At least part of said other data in the data block can be simulated or arbitrary data, but in this case, preferably, no section of the simulated data repeats the signature.
In the fourth to seventh aspects of the invention, data can be downloaded as a plurality of data modules, and the process can include the steps of: generating a module signature for each data module to be downloaded; formatting the data modules as the respective MPEG module tables; generation of a directory including an identification of each module's MPEG table and respective signature, the directory being the object of the signature generation step;
in the receiver / decoder set:
generation of a respective module signature for each of the modules in the received module MPEG tables; and comparing each module signature in the MPEG directory table received with the respective module signature generated in the receiver / decoder set.
Consequently, although the data to be downloaded consists of a plurality of modules, only a single decryption process is required to decipher the modules, and only a single decryption process is required to allow signatures to be verified.
These features can be provided independently of the fourth to seventh aspects of the invention. Consequently, an eighth aspect of the present invention provides a process for downloading a plurality of data modules to an MPEG receiver / decoder set, comprising the steps of: generating a module signature for each data module to be downloaded; formatting the modules as the respective MPEG module tables; generation of a directory including an identification of each module's MPEG table and the respective signature; generation of a directory-to-directory signature;
encryption of the directory signature using a private key; formatting the encrypted directory and directory signature as an MPEG directory table; transmission of MPEG tables of modules and directories; and in the receiver / decoder set: receipt of MPEG tables of modules and directories; decryption of the encrypted directory signature in the MPEG directory table received using a public key corresponding to the private key; generation of a directory signature for the directory in the received MPEG directory table; comparison of the encrypted directory signature and the directory signature generated in the receiver / decoder set; generation of a respective module signature for each of the modules in the received module MPEG tables; and comparing each module signature in the MPEG directory table received with the respective module signature generated in the receiver / decoder set.
The process preferably also includes the step of inhibiting or aborting the download of that data module if, in the module signature comparison step, the module signature in the MPEG directory table received and the respective module signature received generated in the receiver / decoder set for that module are not comparable to each other.
The processes described above also preferably include the step of inhibiting or aborting the data download if, in the comparison step (s), the or each deciphered signature and the generated signature are not comparable with each other.
According to a ninth aspect of the present invention, an MPEG receiver / decoder set is provided for use in performing part of the process of the fourth aspect of the invention, comprising: a means for receiving these MPEG tables; a means for storing a plurality of public keys and an identification for each of the public keys; and a processing means that is programmed to select one of the stored public keys according to the identification of the key in the received MPEG table; decrypt the encrypted signature on the received MPEG table using the selected public key to provide an encrypted signature; generate a signature for the data in the received MPEG table; and comparing the decrypted signature and the signature generated in the receiver / decoder set for the received data.
<img file="BR9714592A_D0008.tif" />
The key storage medium is preferably provided by the ROM and the identification for each of the public keys can be provided by the storage location of that public key in the key storage medium.
The receiver / decoder assembly may further include a volatile memory area and the processing medium may be operable to download an application having an encrypted signature using a private key having a predetermined key identification, to process the application, to make the application the receiver / decoder set receives another key, and to have the other key stored in the volatile memory area.
The receiver / decoder assembly may further include a means for receiving another key, which is provided locally to the receiver / decoder assembly, such as a parallel port, a serial port and / or a smart card reader 20 of the receiver / decoder assembly. Volatile memory is preferably provided by RAM. Again, if the receiver / decoder set has a modem connection, the receiver / decoder set is preferably * ·· · * $ * · χ · · * · · preferably, arranged to prevent another key from being supplied via the modem.
The receiver / decoder set can also include a protected area of memory for storing a validation signal for each of at least part of the public keys, and the processing means can be programmed to consult, in the protected memory area, the signaling of validation for that selected public key, and inhibit or abort the data download, if the consulted signaling is not positioned.
The receiver / decoder set can also include a protected memory area for storing a validation signal for the private key having the predetermined key identification, and the processing means can be operable when the processing of said application changes that validation signal. and it is operable to allow another key to be stored depending on the state of that signal.
This latter feature can be provided regardless of the ninth aspect of the invention. Consequently, a tenth aspect of the present invention provides a receiver / decoder set
<img file="BR9714592A_D0009.tif" />
MPEG, comprising: a means of receiving these MPEG tables; a means for storing a key. public and an identification for the public key; and a protected area of memory for storing a validation signal for the public key; and a processing means, which is programmed to consult, in the protected memory area of the receiver / decoder set, a validation signal for the public key corresponding to the private key identified in the received MPEG table; and, if the consulted signaling is positioned, decrypt the encrypted signature in the received MPEG table using the corresponding public key to be the private key in the received MPEG table, to provide a decrypted signature, to generate a signature for the data in the received MPEG table; and comparing the decrypted signature and the signature generated by the receiver / decoder set for the received data.
The memory for storing the key validation signal (s) is preferably provided by rewritable non-volatile memory.
In the case where a plurality of these public keys are stored, the memory for storage
<img file="BR9714592A_D0010.tif" />
The validation signal (s) is preferably arranged as a bitmap.
The receiver / decoder set of the ninth or tenth aspect of the invention can also include a protected area of memory for storing a validation code, and the processing medium can be programmed to decipher the validation code in that received MPEG table, to consult the stored validation code, and compare the validated code consulted and the deciphered validation code.
This latter feature can be provided regardless of the ninth or tenth aspect of the invention. Accordingly, an eleventh aspect of the present invention provides an MPEG receiver / decoder assembly, comprising: a means for receiving these MPEG tables; a means for storing a public key and an identification for the public key; a protected area of memory for storing a validation code; and a processing medium, which is programmed to decipher the encrypted validation code and signature on these MPEG tables received using the stored public key corresponding to the private key; consult the validation code stored in the protected area of
<img file="BR9714592A_D0011.tif" />
memory; compare the validation code consulted and the deciphered validation code; generate a signature for the data in the MPEG table received or said part of it; and comparing the decrypted signature with the signature generated by the receiver / decoder set for the received data.
The processing medium is preferably programmed to inhibit or abort data download, if the consulted validation code and the deciphered validation code are not comparable with each other.
The memory for storing validation codes is preferably provided by non-volatile, rewritable memory and can be arranged as a bitmap.
receiver / decoder set from the new to the eleventh aspects of the invention may also include a protected memory area for storing at least one bypass, and the processing medium can be programmed to decipher the encrypted data block in that received MPEG table, see said diversion stored in the protected memory area, and extracting from the encrypted data block using the diversion consulted from the beginning of the decrypted data block.
<img file="BR9714592A_D0012.tif" />
This latter feature can be provided independently of the ninth through eleventh aspects of the invention. Accordingly, a twelfth aspect of the present invention provides an MPEG receiver / decoder set, comprising: a means for receiving these MPEG tables; a means for storing a public key and an identification for the public key; a protected memory area for storing at least one branch; and a processing medium, which is programmed to decrypt the block of encrypted data in that MPEG table received using the stored public key corresponding to the private key; consulting said diversion stored in the protected memory area; extract the signature from the decrypted data block using the deviation consulted from the beginning of the decrypted data block; generate a signature for the data in the MPEG table received or said part of it; and comparing the signature extracted from the decrypted data block with the signature generated by the receiver / decoder set for the received data.
The memory for storing validation codes is preferably provided by memory
HERE <sup>26</sup> i? i Μ. ·· '· 4:> j • * -. «» · * Non-volatile rewritable and can be arranged as a bitmap.
In the receiver / decoder set of the ninth to twelfth aspects of the invention, the processing medium can be programmed to generate a respective module signature for each of the modules in the received MPEG module tables, and compare each module signature in the table Directory MPEG received with the respective 10 module subscription generated by the receiver / decoder set.
This latter feature can be provided independently of the ninth through twelfth aspects of the invention. Consequently, a thirteenth aspect of the present invention provides an MPEG receiver / decoder set 15, comprising: a means for receiving these MPEG tables of modules and directories; a means for storing a public key and an identification for the public key; and a processing medium, which is programmed to decrypt the encrypted directory signature in the received MPEG directory table, using the stored public key corresponding to the private key; generate a directory signature for the directory in the MPEG table; compare the decrypted directory signature and the directory signature generated by the receiver / decoder set; generate a respective module signature for each of the modules in the received module MPEG tables; and comparing each module signature in the MPEG directory table received with the respective module signature generated by the receiver / decoder set.
The processing medium is preferably programmed to inhibit or abort the download of that data module, if the module signature in the received MPEG directory table and the respective module signature generated in the receiver / decoder set for that module are not comparable each other.
In the receiver / decoder set of any one of the ninth to thirteenth aspects of the invention, the processing medium is preferably programmed to inhibit or abort data download, if the or each decrypted signature and the generated signature are not comparable each other.
The preferred features of the present invention will be described below, purely by way of example, with reference to the attached drawings, in which:
Figure 1 shows the global architecture of a digital television system;
Figure 2 shows the architecture of an interactive system of the digital television system in Figure 1;
Figure 3 is a schematic diagram of interfaces of a receiver / decoder set forming part of the system of Figures 1 and 2;
Figure 4 is a schematic diagram of a remote controller used in the digital television system;
Figure 5 shows the arrangement of files within a module downloaded into the memory of an interactive receiver / decoder set;
Figure 6 illustrates an interrelationship between various components as an MPEG stream;
Figure 7 illustrates how an application can be made up of modules / tables, which, in turn, can be made up of sections;
Figure 8 illustrates the contents of a directory module;
Figure 9 illustrates, in more detail, part of the contents of the directory module; and Figure 10 illustrates various areas of memory in a television system receiver / decoder set.
t
<img file="BR9714592A_D0013.tif" />
An overview of a digital television system 1000, according to the present invention, is shown in Figure 1. The invention includes a largely conventional digital television system 2000, which uses the well-known MPEG-2 compression system, for transmit compressed digital signals. In more detail, the MPEG-2 2002 compressor in a broadcast center receives a stream of digital signals (typically, a stream of video signals). The compressor 2002 is connected to a multiplexer and heap 2004 by a connection 2006. The multiplexer 2004 receives a plurality of other input signals, assembles one or more transport currents and transmits the compressed digital signals to a 2008 transmitter in the broadcasting center, via the 2010 link, which can, of course, take a variety of forms, including telecommunications links. The transmitter 2008 transmits electromagnetic signals, via the upper link 2012, to a satellite transponder 2014, in which they are processed and broadcast electronically, via the notional lower link 2016, to the receiver on land 2018, conventionally, in the form of a satellite dish. owned by, or leased by, the end user. The signals received by the
». · - * · ι 4 ί · ° * ί ΐ ·:
:: J í ?: í.s * * ·:. · · <'* Ί .ί. · · · * · * · Receiver 2018 are transmitted to an integrated receiver / decoder set 2020, owned by, or rented by, the end user and connected to the end user's television set 2022. The receiver / decoder set 2020 decodes the signal MPEG-2 compressed into a television signal for the 2022 television set.
A conditional access system 3000 is connected to the multiplexer 2004 and the receiver / decoder set 2020 and is located partly in the diffusion center and partly in the decoder. It allows the end user to have access to digital television broadcasts from one or more broadcast providers. A smart card, capable of deciphering messages related to commercial offers (that is, one or more television programs sold by the broadcasting provider), can be inserted in the receiver / decoder set 2020. Using the decoder 2020 and the smart card, the user end can acquire events in a subscription mode or a pay-per-view mode.
An interactive system 4000, also connected to the multiplexer 2004 and the receiver / decoder set
2020, and again located partially in the broadcasting center and partially in the decoder, allows the end user to interact with various applications, via a 4002 modem return channel.
Figure 2 shows the general architecture of the interactive television system 4000 of the digital television system 1000 of the present invention.
For example, the interactive system 4000 allows an end user to purchase items from on-screen catalogs, view local news and weather maps on demand and play games via their television set.
interactive system 4000 comprises, in an overview, four basic elements:
- a 4004 authoring tool in the broadcast center (or elsewhere), to allow a broadcast provider to create, develop, debug and test applications;
- a 4006 application and data server in the broadcast center, connected to the 4004 authoring tool, to allow a broadcast provider to prepare, authenticate and format applications and data, to be sent to the multiplexer and stacker 2004, for insertion into the transport MPEG-2 (typically, your private session), to be broadcast to the end user;
- a virtual machine including a runtime engine (RTE) 4008, which is an executable code installable in the receiver / decoder set 2020 owned or rented by the end user, to allow the end user to receive, authenticate, decompress and upload applications in working memory 2024 of the receiver / decoder set 2020 for execution; the 4008 engine also runs in resident multipurpose applications; the 4008 engine is hardware and operating system independent and
- a return channel via modem 4002 between the receiver / decoder set 2020 and the application and data server 4006, to allow signals instructing the server 4006 to insert data and applications into the MPEG-2 transport stream at the end user's request.
The interactive television system operates using applications that control the functions of the receiver / decoder set and the various devices contained therein. Applications are represented in the 4008 engine as resource files. A module is a set of resource and data files. A memory volume of the receiver / decoder set is a storage space for modules. The modules can be downloaded into the 2020 receiver / decoder set of the MPEG-2 transport chain.
The physical interfaces of the receiver / decoder set 2020 are used to download data. Referring to Figure 3, the decoder 2020 contains, for example, six write-off devices; the MPEG 4028 stream tuner, the 4030 serial interface, the 4032 parallel interface, the 4034 modem and two 4036 card readers.
For the purposes of this specification, an application is a piece of computer code to control high-level functions of the preferably receiver / decoder set 2020. For example, when the end user places the focus on a 2026 remote controller (such as shown in more detail in Figure 4) on a button object seen on the screen of the 2022 television set and compressing a validation key, a sequence of instructions associated with the button is processed.
An interactive application proposes menus and executes commands at the request of the end user and provides data related to the purpose of the application. The applications can be resident applications, that is, stored in the ROM (or FLASH or other non-resident volatile memory) of the receiver / decoder set 2020, or broadcast and downloaded to the RAM (or FLASH) of the decoder 2020.
Examples of applications are:
- an initiation application - the receiver / decoder set 2020 is equipped with a resident initiation application, which is a collection of adaptable modules (this term being defined in more detail below) allowing the receiver / decoder set 2020 to be immediately operative in the MPEG-2 physical medium; the application provides core features, which can be modified by the broadcast provider, if necessary; it also provides an interface between resident applications and downloaded applications;
- a starting application - the starting application allows any application, downloaded or resident, to be processed in the receiver / decoder set 2020; this application acts as an initial charge executed when a service arrives, to start the application; the game is downloaded into RAM and can therefore be easily updated; it can be configured so that the interactive applications available on each channel can be selected and executed, immediately after download or after preload; in the case of preload, the application is loaded into memory 2024 and is activated by the start, when necessary;
- a program guide - the program guide is an interactive application that provides complete information about programming; for example, it can provide information about, say, television programs in a week provided on each channel in a bouquet of digital television; by pressing a key on the remote controller 2026, the end user has access to an additional screen, superimposed over the event shown on the screen of the 2022 television set; this additional screen is a search providing information about current events and close to each channel of the digital TV bouquet; by pressing another key on the 2026 remote controller, the end user has access to an application that presents a list of event information in one week; the end user can also have direct access to a selected channel;
- a Pay Per View application - the Pay Per View application is an interactive service available on each PPV channel of the digital TV bouquet, in conjunction with the 3000 conditional access system; the end user can access the application using a TV guide or a channel search; additionally, the application starts automatically, as soon as the PPV event is detected on the PPV channel; the end user is then able to purchase the current event via his 3020 smart card product, or via the 3022 communications server (using a modem, a phone and DTMF, MINITEL or similar codes); the application can be resident in the ROM of the receiver / decoder set 2020 or downloadable in the RAM of the decoder 2020;
- a PC download application - on request, an end user can download computer software using the PC download application;
- a magazine search application - the magazine search application comprises a cyclic video broadcast of images with end user navigation via buttons on the screen;
- a questionnaire application - the questionnaire application is preferably synchronized with a widespread questionnaire program; as an example, multiple choice questions are presented on the 2022 television screen and the end user can select an answer using the 2026 remote controller; the app
<img file="BR9714592A_D0014.tif" />
questionnaire can inform the user if the answer is correct or not and can keep a count of the user's score;
- a telecom shopping application - in an example of the telecom shopping application, offers of items for sale are transmitted to the receiver / decoder set 2020 and shown on television 2022; using the remote controller, the user can select a particular item to buy; the order for the item is sent, via the return channel via modem 4002, to the 4006 application and data server, or to a separate sales system, whose phone number has been downloaded to the receiver / decoder set, possibly with an order to charge a credit card that has been inserted into one of the 4036 card readers of the 2020 receiver / decoder set;
- a telebank application - in an example of a telebank application, the user inserts a bank card into one of the 4036 card readers of the 2020 receiver / decoder set; the receiver / decoder set 2020 dials the user's bank, using a phone number stored on the bank card or stored in the receiver / decoder set and then the application provides several features, which • · ·· · * ·· • · ·· ο ··· »· · can be selected using the 2026 remote controller, for example, to download, via a telephone line, an account balance, transfer funds between accounts, request a checkbook, etc;
- an Internet search application - in an example of the Internet search application, instructions from a user, such as a request to view a web page having a particular URL, are entered using the 2026 remote controller and these are sent by the return channel via modem 4002 to the application and data server 4006; the appropriate network page is then included in the broadcasting center transmissions, received by the receiver / decoder set 2020, via upper link 2012, transponder 2014 and lower link 2016, and shown on television 2022.
The applications are stored in memory locations in the receiver / decoder set 2020 and represented as resource files. Resource files comprise unitary graphic object description files, unitary files in variable blocks, instruction sequence files, application files and data files.
The unitary graphic object description files describe the screens, the human-machine interface; ; . ·. ··: ,ç : :·· .·. . ·. :. ·: · .:. · J:.: ··. · .:. · • 4 ·· · ··· 4 · ·· ··· of the application. Unit files in variable blocks describe the data structures treated by the application. The instruction sequence files describe the processing operations of the applications.
Application files provide entry points for applications.
The applications thus constituted can use data files, such as icon library files, image files, 10 character font files, color chart files and ASCII text files. An interactive application can also obtain data online by executing inputs and / or outputs.
The 4008 engine only carries in its memory 15 those resource files it needs at any given time. These resource files are read from unitary graphic object description files, instruction sequence files and application files; the unit files in variable blocks 20 are stored in memory following a call to a procedure for loading modules and remain locked in it, until a specific call to a procedure for downloading modules is made.
····· · · «· · · · · ··· · ·· · * X ··· · ·· · • · · · · ··· · · * 4 ·· · ··· · · · · · ···
With reference to Figure 3, a module 4001, like a telesales module, is a set of files and resource data, comprising the following:
a single application file 4012;
an indeterminate number of 4014 graphic object description files;
an undetermined number of unit files in 4016 variable blocks;
an indeterminate number of instruction sequence files 4018; and where appropriate, 4020 data files, such as icon library files, image files, character font files, color chart files and ASCII text files.
With reference to Figure 5, a module, such as a telesales module, is a set of files and resource data, comprising the following:
a single application file 4012;
an indeterminate number of 4014 graphic object description files;
an undetermined number of unit files in 4016 variable blocks;
an undetermined number of instruction string files 4018; and
<img file="BR9714592A_D0015.tif" />
where appropriate, 4020 data files, such as icon library files, image files, character font files, color chart files and ASCII text files.
The concept of 4010 modules, together with the concept of downloading small pieces of code, provides an easy evolution of applications. They can be downloaded to the permanent FLASH memory of the decoder 2020, as resident software or broadcast to be downloaded in the RAM of the decoder 2020, only when necessary by the end user.
To download a 4010 module from a carrier signal, a directory accessible on the carrier signal is first downloaded. This directory simply lists the names of the 4010 modules, which can be downloaded from the carrier signal. Once this directory has been downloaded, it is possible for the application to download one or more 4010 modules. In the case of an MPEG stream, the directory is transported in a single MPEG table. In addition, a 4010 module is transported in a single MPEG table. In the case of modules transmitted to the MPEG 4028 tuner, the long MPEG-2 format is used, with a long start record in a CRC code. This is also the case with the five other interfaces (serial interface
4030 ·· · · ··· · · ··· · · • fr »· · ···· · · ♦ · · ·« * · · · · ······ ♦ ·· · · »t · · · »· · * · · • * ·· · ··· · · ·· ♦ ·· 4032 parallel interface, 4034 modem and two 4036 card readers), except that the short MPEG-2 format with a start record more short and no CRC is used.
Referring, in particular, to Figure 6, as it is known, the MPEG-2 bit stream includes a program access table (PAT) 10 having a packet identification (PID) of 0. The PAT contains references to PIDs program map tables (PMTs) 12 for various programs. Each PMT contains a reference to the PIDs of the MPEG audio tables 14 and MPEG video tables 16 streams for that program. A packet having a PID of zero, ie program access table 10, provides the entry point for all MPEG access.
To download applications and data from it, two new flow types are defined, and the relevant PMT also contains references to the flow PIDs of the MPEG application tables 18 (or sections of them) and MPEG data tables 20 (or sections of them).
Referring to Figure 7, to download an application 22, the application is divided into modules 24, each formed by an MPEG table, part of which consists of a single section 18, and the rest can be constituted by a plurality of sections 18. One: ·. :. ·. · *:, Ι:: ··. ·. . ·. ·· «··· (* ····· · · * ·· · ♦ ♦» <· · · «· • · · · · * ···· typical section 18 has a start record 26, which includes a one-byte table ID (TID) 28, the section number 30 of that section in the table, the total number of 32 sections in that table and an extension
Two-byte TID 34. Each section also includes a data part 36 and a CRC 38. For a particular module / table 24, all sections 18 constituting that table 24 have the same TID 28 and the same TID 34 extension. particular application 22, all tables 24 constituting that application 22 have the same TID 28, but different respective TID extensions.
For each application 22, there is a single MPEG table 24, which is used as a directory, and which is shown in more detail in Figure 8. Directory table 40 includes a start record 26, a directory part 42, an ID of key 44, an encrypted signature and a CRC 38. From what was mentioned above, it will be considered that the directory table has, in its initial record 26, the same TID 28 as the other modules / tables 24 constituting the application. However, the directory table has a predetermined TID extension 34 of zero and all other modules 24 have non-zero TID extensions. The start record also includes a version number 48 for the table of · · · · · ♦ · I · · * · «·» «» ··· · »···· ·» · »··· Í tft «··· • v · · v ····· * t ·· · ··· · · ♦ ··» * directories 40. The directory part 42 includes, for each of the other modules / tables 24 constituting the application 22, the name 50 of that module, the extension TID 34 for that module and a signature 52 of that module. The directory part 42 can also include, for each of the other modules / tables 24, the length of that module and the version number of the module.
Referring back to Figure 6, in operation, PAT 10, PMTs 12 and the components of the data flow and application 18, 20 are transmitted cyclically, being updated, if necessary. Each application that is transmitted has a respective predetermined TID 28. To download an application, the MPEG table having the appropriate TID and the zero TID extension is downloaded to the receiver / decoder set 2020. This is, therefore, the table the 40 directories for the required application. The data in the directory is then processed by the receiver / decoder set 2020 to determine the TID 34 extensions of the module tables constituting the required application, and then any required module, having the same TID as the directory table and a determined TID extension of the directory, can be downloaded.
·· · · ··· is «··· V 4 ::: ::. · · Ί; . ::<sup>4</sup>:
<·> »·« »« - ·· · • * ♦ · · · '4 · · e * · · * · * · «· · ·· ♦ · *
2020 receiver / decoder set 2020 is willing to test the directory table for any update of it. It can be done by downloading the directory table again periodically, for example, every 30 seconds, or one or five minutes, and comparing the version number of the newly downloaded directory table with the version number of the previously downloaded directory table. If the newly downloaded version number is later, then the modules associated with the previous directory table, or any of those models for which there are later version numbers, are disassembled, and the later modules are downloaded and mounted. In an alternative arrangement, the incoming bit stream is filtered using a mask corresponding to the TID, TID extension and version number, with the values prepared for the application's TID, a TID extension of zero and a version number greater than the version number of the directory currently being downloaded. Consequently, an increase in the version number can be detected, and once detected, the directory is downloaded and the application is updated, as described above. Additional description of this filtration is contained in the co-pending patent application (proxy reference no. PDC / ASB / 19716). If an application is going to be ·· t- · ♦ «· ** · ί ·» · • · 9 · · k «♦ · * Λ V · ν *» *> · · · »···, an empty directory with the next version number is transmitted, but without any modules listed in the directory. In response to receiving this empty directory, the receiver / decoder set 2020 is programmed to disassemble the application.
The use of signatures and encryption for application tables will be described in detail below.
As described above, the entry for each module in the directory table 40 includes the module signature. The module signature is generated using an MD5 signature generator process known in the data in the respective module table.
Furthermore, the directory table 40 includes an encrypted signature 46, which is generated as described below with reference to Figure 9. A block of 54 or 64 bytes of data is produced. The first 56 byte is zero. The next three bytes 58 can include simulated or arbitrary data. The next eight bytes 60 provide an application validation bitmap, which will be described below. The last four 62 bytes are reserved. The remaining 32 bytes contain a 16-byte signature, which starts at a deviation between 0 and 31 bytes, after the first; ·. J. ·. · ;:<sub>t</sub> r *.
A Í · »« i * S »· byte following the application validation bitmap
60. Simulated data 66 is inserted between the map of.
application validation bit 60 and signature 64, and / or between signature 64 and reserved bytes 62. Signature 64 is produced using the MD5 signature generation process known in entries in directory 42 in directory table 40. 0 block 54 is then encrypted using a known encryption process and a private key to produce the encrypted signature and application validation bitmap 46. Data block 46 is included in directory table 40, and a 1-byte identification of the private key, which was used to encrypt the block, is included in directory table 40, as key identification 44.
To summarize the generation of an application and its transmission, the following steps are involved:
- generate the application as a plurality of modules;
- note the predetermined TID 28 for the application;
- allocate names and non-zero TID extensions 34 for the modules;
- format each module as an MPEG 24 table or sections 18 of an MPEG table;
of each module the directory;
- generate an MD5 subscription 52
- generate directory 42;
- generate an MD5 subscription 64
- select an application validation bit 60;
- select a deviation;
- generate block 54;
- encrypt block 54 using encryption with a private private key;
- generate the MPEG table of directories 40 with the TID 10 allocated 28, a TID extension of zero, the directory 42, an identification 44 of the private key and the encrypted signature 46;
- transmit directory table 40 and module tables 24 or sections 18.
The operation of the receiver / decoder set 2020 in dealing with signatures and encryption while downloading an application will be described below. Referring to Figure 10, the receiver / decoder set 2020 includes EEPROM 68, ROM 70 and
RAM 72. EEPROM 68 includes a protected region 74, which is used by the virtual machine and in which only the virtual machine (and not a normal application) can write. The protected region 74 includes a 16 or 256 bit key validation bitmap 76, a bitmap of: · · .'ο '· ί; ί. : · ...
• · · fr / '> · · ο · · · · · »♦? * J · ··· J · · e · <· · · 7 · · • V ·· 4 ··· · · ·· · ·· 64-bit application 78, and a 32-bit offset 80 bit map. ROM 7 0 includes, in one embodiment, sixteen public keys 82, in which case a 16-bit key bit map is used, and in another modality 256 public keys, in which case a validation key bit map. 256 bits is employed. Public keys are identified by their physical locations on ROM 70, or they can alternatively be included in a verification table, with which a private key identification will produce the corresponding public key. RAM 72 can be used to store a temporary key 84.
As mentioned above, when an application is going to be downloaded, first the directory table having the predetermined TID for that application and a zero TID extension is downloaded. The key identification 44 is then extracted from the directory table and a test is made of the key validation bit map 76 in protected memory 74 that the bit corresponding to the extracted key identification 44 is positioned. If not, if the appropriate key is positioned, then a public key 82 is selected from ROM 70, corresponding to the extracted key identification 44. The selected public key and a known decryption process are then used to decrypt encrypted block 46 in the directory table 40, to produce a block 54. The application validation bitmap 60 is then extracted from the deciphered block 54 and is operated on E with the application validation bitmap 78 stored in protected memory 74. If the result of operation E is zero, then the lowest of the application is aborted. However, if the result of operation E is different from zero, the offset contained in the offset bit map 80 in protected memory 74 is queried, or, if more than one offset bit is set, each offset bit is queried , in turn, and sixteen bytes of data are extracted from the deciphered block 54, starting with the deviation consulted from the first byte after the application validation bitmap 60. For the or each query queried, the 16 bytes are treated as the signature transmitted with directory table 40. The signature of entries in directory 42 of directory table 40 is calculated using the known MD5 process, and this calculated signature is compared with the signature extracted from block 54. If the two signatures for the or each deviation consulted are not comparable, then the application's lowest is aborted. However, if one of the signatures is comparable, then the download of the modules specified in directory 42 can proceed. As mentioned above, to download a particular module, the TID extension for that module is obtained from directory 42 and the MPEG table 24, or sections 18 with the same TID as the directory table and with the obtained TID extension, is downloaded. Once the MPEG table has been downloaded, the receiver / decoder set 2020 calculates the signature of the downloaded table using the known MD5 process, and then compares the signature with the signature contained in the directory entry. If the signatures are comparable, then the module is accepted, but if they are not, then the module is rejected.
All application modules can then be downloaded in the manner specified above and the application can be processed by the receiver / decoder set 2020.
The normally used characteristics of the write-off operation having been described, a description will then be made of the same characteristics used in the preparation of the receiver / decoder set 2020 and alteration of its settings.
The receiver / decoder set 2020 is programmed so that the protected memory area 74 can be changed, but only by an application that has been downloaded using a particular key ID, for example, key 15, and with a particular offset, for example, a deviation of zero 5 bytes from the first byte after the application validation bitmap 60. Protected memory 74 does not need to be changed, for example, if two operators using the same public key decide that they want to use two different public keys, or if the contents of a 10 private key have been discovered, in which case the corresponding public key can be marked as invalid in the key validation bitmap 76.
The receiver / decoder set 2020 can be arranged so that one of the keys, for example, the key 15, is always available, in which case the key does not require a bit in the key validation bit map 76. Consequently, the key bit can be used for another purpose. In particular, an application, which has been authenticated using key 15, can be arranged to position that particular bit at 1, in which case the receiver / decoder set 2020 is programmed to allow a temporary key 84 to be loaded into RAM 72 , but you could only see the serial interface 4030, parallel interface 4032 or one of the two card readers 4036. This feature can be used by, for example, a manufacturer of the receiver / decoder set 2020, which can receive an application for use, to allow a temporary key 5 to be loaded in the receiver / decoder set 2020, so that it can be tested .
The deciphering and signaling arrangement described above provides several important features.
In particular:
- an application can only be downloaded if the receiver / decoder set 2020 has the appropriate public key stored in its memory corresponding to the identification of key 44 in the downloaded 15 directory table;
- for all but one of the keys, an application can only be downloaded using a private key, if the key validation bitmap 7 8 in the memory of the receiver / decoder set 2020 is positioned, 20 to allow that key to be used;
- an application can only be downloaded if a bit positioned on the deviation bit map 80, stored in the memory of the receiver / decoder set 2020,
<img file="BR9714592A_D0016.tif" />
corresponds to the deviation used in the generation of the directory table;
- an application can only be downloaded if the application validation bitmap in the memory of the receiver / decoder set 2020 is properly positioned, to allow the application to be downloaded;
- an application can only be downloaded if the directory table has not been damaged, after its signature was originally generated;
- each module of an application can only be downloaded if the respective module table has not been damaged, after its signature was originally generated;
- only one encryption operation is required when preparing an application for download, despite the application being made up of several MPEG tables, and only one decryption operation is required in the receiver / decoder set 2020 to download the complete application;
- multiple keys can be used, so that different service providers can have different private keys;
- a temporary key can be used, for example, by a manufacturer, for testing purposes.
It is to be understood that the present invention has been described above purely by way of example and that modifications of details can be made within the scope of the invention.
Each feature mentioned in the description and (where appropriate) in the claims and drawings can be provided, independently, or in any appropriate combination.
In the preferred embodiments mentioned above, certain features of the present invention have been implemented using computer software. However, it will, of course, be clear to a person skilled in the art that any of these features can be implemented using hardware. Furthermore, it will be easily understood that the functions performed by hardware, computer software and the like are performed by them or using electrical or similar signals.
The cross-reference is made with co-pending patent applications from the same applicant, all having the same filing date and entitled Signal Generation and Broadcasting.
PC / ASB / 19707), Smartcard for use with a Receiver of Encrypted Broadcast Signals, and Receiver (Proxy Reference no. PC / ASB / 19708), Broadcast and Reception System and Conditional Access System 5 therefor (Proxy Reference no. PC / ASB / 19710),
Downloading a Computer File from a Transmitter via
Receiver / Decoder to a Computer (Power of Attorney Reference No. PC / ASB / 19711), Transmission and Reception of Television Programs and Other Data 10 (Power of Attorney Reference No. PC / ASB / 19712),
Downloading Data (Power of Attorney Reference no.
PC / ASB / 19713), Computer Memory Organization (Power of Attorney Reference no. PC / ASB / 19714),
Television or Radio Control System Development 15 (Power of Attorney Reference no. PC / ASB / 19715),
Extracting Data Sections from a Transmitted Data
Stream (Power of Attorney Reference no. PC / ASB / 19716), Access Control System (Power of Attorney Reference no.
PC / ASB / 19717), Data Processing System (Reference of 20 Power of Attorney No. PC / ASB / 19718) and Broadcast and Reception
System, and Receiver / Decoder and Remote Controller therefor (Proxy Reference no. PC / ASB / 19720). Descriptions of these documents are hereby incorporated by reference. The list of patent applications includes the present patent application.
35 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23 Sheet 24 Sheet 25 Sheet 26 Sheet 27 Sheet 28 Sheet 29 Sheet 30 Sheet 31 Sheet 32 Sheet 33 Sheet 34 Sheet 35
517 members in 27 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 97400650 | European Patent Office (EPO) | A | |
| 9702111 | European Patent Office (EPO) | W |
Members517
| Document | Office | Kind | |
|---|---|---|---|
| ZA973612B | South Africa | B | |
| ZA973607B | South Africa | B | |
| ZA973603B | South Africa | B | |
| ZA973604B | South Africa | B | |
| ZA973608B | South Africa | B | |
| ZA973610B | South Africa | B | |
| ZA973611B | South Africa | B | |
| ZA973613B | South Africa | B | |
| ZA973614B | South Africa | B | |
| ZA973609B | South Africa | B | |
| ZA973606B | South Africa | B | |
| ZA973605B | South Africa | B | |
| EP0866611A1 | European Patent Office (EPO) | A1 | |
| EP0866613A1 | European Patent Office (EPO) | A1 | |
| EP0866616A1 | European Patent Office (EPO) | A1 | |
| ZA982384B | South Africa | B | |
| ZA982385B | South Africa | B | |
| CA2284011A1 | Canada | A1 | |
| CA2284014A1 | Canada | A1 | |
| CA2284016A1 | Canada | A1 | |
| CA2284018A1 | Canada | A1 | |
| CA2284022A1 | Canada | A1 | |
| CA2284023A1 | Canada | A1 | |
| CA2284036A1 | Canada | A1 | |
| CA2284038A1 | Canada | A1 | |
| CA2284044A1 | Canada | A1 | |
| CA2284145A1 | Canada | A1 | |
| CA2284146A1 | Canada | A1 | |
| CA2284147A1 | Canada | A1 | |
| CA2284153A1 | Canada | A1 | |
| CA2284154A1 | Canada | A1 | |
| CA2284681A1 | Canada | A1 | |
| CA2284867A1 | Canada | A1 | |
| CA2499904A1 | Canada | A1 | |
| WO9843162A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843165A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843167A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843172A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO9843248A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843415A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843421A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843425A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843426A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843427A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843428A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843430A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843431A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843432A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843433A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO9843437A1 | World Intellectual Property Organization (WIPO) | A1 | |
| ZA982386B | South Africa | B | |
| AU2638597A | Australia | A | |
| AU2701397A | Australia | A | |
| AU2770297A | Australia | A | |
| AU2770397A | Australia | A | |
| AU2770497A | Australia | A | |
| AU2770597A | Australia | A | |
| AU2770697A | Australia | A | |
| AU2770797A | Australia | A | |
| AU2770897A | Australia | A | |
| AU2770997A | Australia | A | |
| AU2771097A | Australia | A | |
| AU2888097A | Australia | A | |
| AU7038098A | Australia | A | |
| AU7038198A | Australia | A | |
| AU7038298A | Australia | A | |
| AU7208298A | Australia | A | |
| EP0872798A1 | European Patent Office (EPO) | A1 | |
| ZA982387B | South Africa | B | |
| NO994529D0 | Norway | D0 | |
| NO994530D0 | Norway | D0 | |
| NO994531D0 | Norway | D0 | |
| NO994532D0 | Norway | D0 | |
| NO994533D0 | Norway | D0 | |
| NO994534D0 | Norway | D0 | |
| NO994535D0 | Norway | D0 | |
| NO994536D0 | Norway | D0 | |
| NO994537D0 | Norway | D0 | |
| NO994538D0 | Norway | D0 | |
| NO994539D0 | Norway | D0 | |
| NO994540D0 | Norway | D0 | |
| NO994541D0 | Norway | D0 | |
| NO994542D0 | Norway | D0 | |
| NO994543D0 | Norway | D0 | |
| NO994544D0 | Norway | D0 | |
| NO994529L | Norway | L | |
| NO994530L | Norway | L | |
| NO994531L | Norway | L | |
| NO994532L | Norway | L | |
| NO994533L | Norway | L | |
| NO994534L | Norway | L | |
| NO994535L | Norway | L | |
| NO994536L | Norway | L | |
| NO994537L | Norway | L | |
| NO994538L | Norway | L | |
| NO994539L | Norway | L | |
| NO994540L | Norway | L | |
| NO994541L | Norway | L | |
| NO994542L | Norway | L | |
| NO994543L | Norway | L |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Application dismissed because of non-payment of annual fees [chapter 8.6 patent gazette]REFERENTE A 6A , 7A E 8A ANUIDADES.B08F | B08F |
Numbers
- Application
- 9714592
Titles2
- Portuguese
- Processo de baixa de dados para um conjunto receptor/decodificador mpeg e um sistema de transmissão mpeg para implementação do mesmo
- English
- Data download process for a mpeg receiver / decoder set and a mpeg transmission system to implement it
Classification
- CPC, 30
- G06F9/4843
- H04N7/20
- G06F11/10
- G06F11/1435
- G06Q20/04
- G06Q20/341
- G06Q20/357
- G06Q20/40975
- G06T9/007
- G07F7/1008
- G07F17/0014
- G11C16/105
- H04B7/18526
- H04N7/163
- H04N7/1675
- H04N7/17309
- H04N7/17318
- H04N17/004
- H04N21/2351
- H04N21/258
- H04N21/4351
- H04N21/4437
- H04N21/4586
- H04N21/4622
- H04N21/4623
- H04N21/4782
- H04N21/8166
- H04N21/8402
- H04N21/426
- H04N5/44
- IPC, 58
- G06F9 445
- G06F9 06
- G06F9 46
- G06F9 48
- G06F11 00
- G06F11 08
- G06F11 10
- G06F11 14
- G06F11 26
- G06F11 28
- G06F12 00
- G06F12 02
- G06F13 00
- G06F13 10
- G06F21 10
- G06K17 00
- G06K19 00
- G06K19 07
- G06Q20 00
- G06T9 00
- G07F7 00
- G07F7 10
- G09C1 00
- G11C8 06
- G11C16 02
- H04B1 713
- H04B7 185
- H04H20 02
- H04H40 00
- H04L1 00
- H04L9 00
- H04L9 10
- H04L9 32
- H04L12 56
- H04L13 08
- H04L29 10
- H04N
- H04N5 00
- H04N5 222
- H04N5 44
- H04N5 455
- H04N7 14
- H04N7 16
- H04N7 167
- H04N7 173
- H04N7 66
- H04N17 00
- H04N17 04
- H04N21 235
- H04N21 258
- H04N21 435
- H04N21 443
- H04N21 458
- H04N21 462
- H04N21 4623
- H04N21 4782
- H04N21 81
- H04N21 84