Elementary stream partial encryption
Abstract
An encryption arrangement used for multiple encryption of TV programs. The system of the embodiment of the present invention performs multiple encryption on only a part of the data required to fully present the TV program, so as to allow multiple conditional access encryption systems related to set-top boxes of multiple manufacturers to coexist in a single system. In one embodiment, only the audio data is encrypted, and the video remains in plaintext. By encrypting only a part of the program, compared with other multiple encryptions for all TV programs, it consumes much less bandwidth, so that more programs can be transmitted on the same bandwidth, and at the same time, there are more programs in a single cable TV system. Two conditional access systems coexist.

Term
Term ended
Expired 13 December 2022, 3.8 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
15 claims: 3 independent, 12 dependent
- 1一种对数字电视信号进行多重加密的方法,包括: 根据第一加密方法对数字电视信号的所选定基本流加密,以形成第一加密基本流; 根据第二加密方法对数字电视信号的所选定基本流加密,以形成第二加密基本流;以 及 将第一加密基本流和第二加密基本流与数字电视信号的至少一个未加密的基本流组 合起来,以形成部分多重加密的电视信号。
- 2如权利要求1的方法,其中,用分组标识符(PID)或业务流标识符(SSID)标识出所 述选定的基本流分组以便进行加密。
- 3如权利要求1或2的方法,还包括在有线电视系统、地面广播系统和卫星系统之一中 发布所述部分多重加密的电视信号。
- 4如权利要求1的方法,其中,所述多重加密包括对被标识为音频基本流分组、视频基 本流分组和系统信息基本流分组之一的分组进行多重加密。
- 5如权利要求1的方法,其中,所述选定的基本流是分组化的,并且,所述分组由分组 标识符(PID)来标识,并且在节目映射表(PMT)中引用所述分组标识符。
- 6一种电视信号接收设备,包括: 接收器,接收双重部分加密的电视信号,该信号包括用第一加密算法和第二加密算法 加密的基本分组流以及未加密的分组; 解密器,从所述接收器接收用第一加密算法加密的基本流分组,并用第一解密算法对 所述加密的基本流分组进行解密;以及 解码器,对所述解密的基本流分组和未加密的分组进行接收和解码,以便形成适于在 电视接收器上播放的电视信号。
- 7如权利要求6的设备,其中,所述接收器还丢弃用第二加密算法加密的基本流分组。 如权利要求6或7的设备,其中,用分组标识符(PID)或业务流标识符(SSID)标识 出选定的基本流分组以便进行加密。
- 89. 如权利要求6的设备,其中,所述多重加密包括对被标识为音频基本流分组、视频基 本流分组和系统信息基本流分组之一的分组进行多重加密。
- 910. 如权利要求6的设备,其中,选定的基本流分组由分组标识符(PID)来标识,并且在 节目映射表(PMT)中引用所述分组标识符。
- 1011. 如权利要求6的设备,其中,从地面广播系统、卫星系统和有线电视系统之一中接 收所述双重部分加密的电视信号。
- 1112. 一种对多重部分加密的电视信号进行解码的方法,包括: 接收具有多重加密基本流和未加密部分的电视信号,其中,所述多重加密的基本流包 括用第一加密方法加密的第一加密基本流部分和用第二加密方法加密的所述基本流部分 的一个复制品; 对第一加密的基本流进行解密,以形成解密的基本流; 对解密的基本流和未加密部分进行解码,以形成解码的电视信号。
- 1213. 如权利要求12的方法,其中,所述解码的信号适于在电视机上播放。
- 1314. 如权利要求12或13的方法,其中,所述第一加密基本流是由与用来对第一加密基 本流进行解密的第一解密算法相关联的第一分组标识符(PID)来标识的,而由第二加密算 CN 1633809 Β 法加密的基本流部分的复制是由用于对基本流部分的复制品解密的第二解密算法相关联 的第二分组标识符(PID)来标识的。
- 1415. 如权利要求14的方法,还包括通过PID过滤丢弃所述第二加密算法加密的音频部 分。
- 1516. 如权利要求12的方法,它是在集成电路、电视接收器设备、电视和电视机顶盒之一 中执行的。 CN 1633809 Β
Independent claims15
359 paragraphs, as filed
Elementary stream partial encryption
[0001] Cross-reference of related documents
[0002] This application relates to Candelore et al.'s US provisional patent application No. 60/296,673, Unger et al.'s provisional patent application No. 60/304,241, Candelore et al.'s provisional patent application No. 60/304,131 No. and US Provisional Patent Application No. 60/____ by Candelore et al. Among them, the provisional US provisional patent application
No. 60/296, 673 was submitted on June 6, 2001, entitled "Methods for multiple CA providers to interoperate by sending the video of certain content in the content delivery system through clear text, and the dual transmission and use of audio Dual transmission of video and audio of other content (Method for Allowing MultipleCA Providers to Interoperate in a Content Delivery System by Sending Video in the Clear for Some Content, and Dual Carriage of Andio and Dual Carriage of Video and Audio for Other Content); Provisional Patent Application No. No. 60/304, 241 was filed on July 10, 2001, entitled "Independent Selective Encryption of Program Content for Dual Carriage (Independent Selective Encryption of Program Content for Dual Carriage); Provisional Patent Application No. 60/304, No. 131 was submitted on July 10, 2001, entitled "Method for Allowing Multiple CA Providers to Interoperate in a Content Delivery System by disrupting the content according to the time slice part" (Method for Allowing Multiple CA Providers to Interoperate in a Content Delivery System by Partial Scrambling Content ona Time Slice Basis); US Provisional Patent Application No. 60/______ was filed on October 26, 2001, entitled Television Encryption Systems (Television Encryption Systems), document number SNY-R4646P. These patents are cited in this article Apply for reference.
[0003] This application is submitted at the same time with the following documents: Unger et al.'s document number is SNY-R4646. 01 patent application, entitled Critical Packet Partial Encryption (Critical Packet Partial Encryption), the serial number is _____;
The document number of Candelore et al. is the patent application of SNY-R4646. 02, entitled "Time DivisionPartial Encryption (Time DivisionPartial Encryption), the serial number is ______; the document number of Unger et al. is the patent application of SNY-R4646.04, The title is Partial Encryption and PID Mapping (Partial Encryption and PID Mapping), the serial number is ____; and, the patent application of Unger et al.'s document number is SNY-R4646. 05, titled "Decoding and Decrypting Partially Encrypted Information (Decoding and Decrypting of Partially Encryptedlnformation), the serial number is ___. These concurrently filed patent applications are cited in this article for reference.
[0004] Copyright Statement
[0005] A part of the disclosure of this patent document includes copyrighted material. The copyright owner has no objection to photocopying the patent documents or patent disclosures in the patent documents or records of the patent and trademark office, but reserves all copyrights under any circumstances.
Invention field
[0006] The present invention relates generally to the field of encryption systems. Specifically, the present invention relates to a system, method, and device for partially encrypting and decrypting the numbers of television signals.
[0007] Background of the invention
[0008] Television is used to deliver entertainment and educational information to viewers. Source materials (audio, video, etc.) are multiplexed into a combined signal, which is used to modulate the carrier. The carrier is generally called a frequency channel. (A typical channel can
CN 1633809 Β
Carry one analog program, one or two high-definition (HD) digital programs or several (for example, nine) standard-definition digital programs). In the terrestrial system, these channels correspond to the frequencies arranged by the government and are broadcast in the air. The program is transmitted to a receiver with a tuner. The tuner receives the signal from the air and transmits it to the demodulator. The demodulator provides the video to the display and the audio to the speaker. In a cable television system, the modulated channel is transmitted on the cable. It is also possible to feed a program guide within or outside the band to indicate what programs are available and to indicate related tuning information. The number of cable channels is limited and limited by the bandwidth of the device/cable. The wired release system requires huge capital investment and is expensive to upgrade.
[0009] A large amount of TV content is valuable to its producers, so copyright holders must control access and restrict copying. Examples of typical protected materials include feature films, sporting events, and adult programming. Conditional access (CA) systems are used to control the availability of programs in content delivery systems such as cable television systems. The CA system is a matched set of equipment. One part is integrated in the front-end equipment of the cable TV system and the payload is encrypted, and the other part is decrypted and embedded in the set-top box (STB) installed in the user's home. A variety of CA systems are used in the cable television industry, including those provided by NDS (Newport Beach, California), Motorola (Schaumberg, Illinois), and Scientific Atlanta (Atlanta, Georgia). This matching device of the CA system has the effect that "traditional" vendors are locked as suppliers of additional STBs. Since the multiple technologies used for conditional access are not compatible with each other (usually proprietary), any new potential suppliers are forced to authorize traditional CAs. Therefore, cable TV operators will find themselves unable to obtain newer or competitive technologies from other set-top box manufacturers. This is because technology owners are usually unwilling to cooperate or charge reasonable licensing fees. when This inflexibility is particularly troublesome when some cable companies with completely different CA systems merge. Service providers like to have more than one program source for STB for many reasons.
[0010] Once a cable TV operator selects an encryption scheme, it is difficult to change or upgrade the content encryption scheme without introducing backward compatible decoding equipment (such as a set-top box). Even if the technology is available to STB vendors so that they can provide multiple decryption capabilities, providing multi-mode capabilities for processing multiple encryption systems in a new set-top box will significantly increase the cost of any new set-top box.
[0011] The only known current option to avoid the domination of traditional vendors (without a large number of replacements) is to use "full dual transmission. Full dual transmission means repeated transmission of every encrypted program-every Each transmission uses one type of CA encryption. In order to provide full double transmission, the headend must be enhanced to provide various forms of CA at the same time. Traditional STB should not be affected, and they should continue to be implemented regardless of any changes. Functionality. However, full dual transmission usually has a higher price due to bandwidth effects, which will reduce the number of featured programs available. Generally speaking, the lack of the number of higher-paid channels will limit the number of options available to viewers , The value that cable operators can provide will also be limited.
[0012] The traditional cable TV system arrangement is shown in Figure 1. In this system, the cable TV operator uses the CA technology from manufacturer A (system A) at the front-end equipment 22 of the cable TV system to process the audio/video (A/V) content with the CA encryption equipment 18 compatible with system A. 14. The encrypted A/V content is multiplexed together with system information (SI) 26 and program specific information (PSI) and transmitted to the user via the cable TV system 32. STB36. STB36 includes the data from system A (manufacturer A) A decryption CA device that decrypts A/V content. The decrypted A/V content can then be provided to the television 44 for viewing by the user.
[0013] In a cable television system such as that in FIG. 1, the digital program stream is divided into packets for transmission. The grouping (video, audio, auxiliary data, etc.) of each component of the program is marked with a group identifier or PID. In-channel
CN 1633809 Β
These packet streams for the various components of all programs are aggregated into a composite stream. Additional packets are also included to provide decryption keys and other overhead information. In addition, unused bandwidth is filled with empty packets. The bandwidth budget is usually adjusted to utilize about 95% of the available channel bandwidth.
[0014] Overhead information usually includes guide data, which explains what programs are available and how to determine the location of related channels and components. This kind of guide data is also called system information or SI: SI can be transmitted to the STB within the band (part of the data encoded in the channel) or outside the band (with a special channel dedicated to this purpose). SI transmitted electronically can be partially copied in a more traditional form (ie, grids published in newspapers and magazines).
[0015] In order for viewers to have a satisfactory TV experience, it is generally necessary for viewers to have clear access to audio and video content. Some analog cable television systems have used multiple filtering techniques to obscure the video, thereby preventing unauthorized viewers from receiving unpaid programs. In such systems, analog audio is sometimes sent in the clear. In the Motorola VideoCipher2Plus system used in C-band satellite transmission, strong digital audio encryption and weaker analog video protection (using synchronous inversion) are used. In the airline's aircraft movie system, audio can only be used by renting headphones, so that only paying customers can provide complete audio and video.
[0016] Brief description of the drawings
[0017] The appended claims specify the features of the invention that are considered novel. However, by referring to the following detailed description of the present invention, the present invention itself can be better understood in terms of organization and operation methods and its purposes and advantages. The following content together with the accompanying drawings illustrate certain exemplary embodiments of the present invention. In the picture:
[0018] FIG. 1 is a block diagram of a traditional conditional access cable television system;
[0019] FIG. 2 is a block diagram of a system consistent with an embodiment of the present invention, in which double-encrypted audio is transmitted together with plaintext video;
[0020] FIG. 3 is a block diagram of a system consistent with an embodiment of the present invention, in which part of the program is double-encrypted according to the time slice mechanism;
[0021] FIG. 4 is a flowchart of a double encryption process consistent with some embodiments of the present invention;
[0022] FIG. 5 is a flowchart of a decryption process consistent with some embodiments of the present invention;
[0023] FIG. 6 is a block diagram of a system consistent with an embodiment of the present invention, in which part of the program is double-encrypted on a packet basis;
[0024] FIG. 7 is a flowchart of a double encryption process consistent with some embodiments of the present invention;
[0025] FIG. 8 is a flowchart of a decryption process consistent with some embodiments of the present invention;
[0026] FIG. 9 is a block diagram of a system consistent with an embodiment of the present invention, in which system information is encrypted and programs are sent in plain text;
[0027] FIG. 10 is a block diagram of a general system consistent with various embodiments of the present invention;
[0028] FIG. 11 is a block diagram of the first embodiment of the implementation form of the encryption system consistent with the embodiment of the present invention in the front-end equipment of the cable TV system;
[0029] FIG. 12 is a block diagram of the second embodiment of the implementation form of the encryption system consistent with the embodiment of the present invention in the front-end equipment of the cable TV system;
[0030] FIG. 13 is a flowchart of the entire encryption process used to implement certain embodiments of the present invention in the front-end equipment of a cable TV system;
[0031] FIG. 14 is a block diagram of a first embodiment of a set-top box implementation form of a decoding system consistent with an embodiment of the present invention;
CN 1633809 Β
[0032] FIG. 15 is a block diagram of a second embodiment of the implementation form of the decoding system consistent with the embodiment of the present invention in the cable television system STB;
[0033] FIG. 16 is a block diagram of a third embodiment of the implementation form of the decoding system consistent with the embodiment of the present invention in the cable television system STB;
[0034] FIG. 17 illustrates a PID remapping process implemented in an embodiment of a set-top box PID remapper; [0035] FIG. 18 is a block diagram of an exemplary decoder chip that can be used in a TV set-top box according to the present invention.
[0036] Detailed description of the invention
[0037] Although there are many different forms of embodiments of the present invention, specific embodiments are shown and described in detail in the accompanying drawings. It should be recognized that the present disclosure should be regarded as an example of the principles of the present invention, rather than The invention is to be limited to the specific embodiments shown and described. In the following description, the same reference numerals are used to describe the same, similar or corresponding parts in multiple figures. The terms "scrambling" and "encryption" and their variations are synonymous in this article. Also, the term "television program" and similar terms can be interpreted in the usual traditional sense. The term also refers to any segment of A/V content that can be displayed on a television or similar monitor device.
[0038] Overview
[0039] Modern digital cable television networks generally use CA systems that can fully encrypt digital audio and video, so that no one other than those who have properly ordered can access the program. This encryption is designed to prevent hackers and non-subscribers from receiving unpaid programs. However, because cable TV operators want to provide their subscribers with set-top boxes from different manufacturers, they will need to transmit multiple copies of a single program encrypted with multiple encryption technologies compatible with the CA system of each STB manufacturer. And disappointed.
[0040] This need to transmit multiple copies of the program (referred to as "full dual transmission") consumes valuable bandwidth, and this valuable bandwidth can be used to provide viewers with additional program content. Certain embodiments of the present invention can solve this problem, in which the bandwidth requirement for providing the same content to multiple transmissions can be minimized. The result can be called "virtual dual transmission" because it provides the benefits of full dual transmission without the cost of full bandwidth. Several embodiments of the invention presented herein can be used to achieve effective partial scrambling. These embodiments vary with the criteria used to select the part to be encrypted. The selected part will affect the additional bandwidth requirements and the effect of encryption. One encryption process or a combination of several encryption processes should be used in a manner consistent with the embodiment of the present invention.
[0041] Some implementations of the partial double encryption described herein use additional (secondary) PIDs for each copied component<sub>O</sub>These secondary PIDs are used to mark packets carrying duplicate content with additional encryption methods. The PSI is enhanced to transmit information about the existence of the new PID in the following way: the inserted PID is ignored by the traditional STB, but can be easily extracted by the new STB.
[0042] Some implementations of partial double encryption include copying only specific packets marked with a given PID. The method used to select which packets to encrypt is detailed below. The original (ie, traditional) PID continues to mark packets encrypted with traditional encryption and other packets that are transmitted in plaintext. The new PID is used to mark packets encrypted with the second encryption method. The packet with the secondary PID masks the encrypted packet marked with the primary PID. The packets forming the encryption pair can appear in two orders, but in a preferred implementation form, the order can be maintained in the plaintext part of the PID stream. As can be seen from the following description, by using the primary and secondary PIDs, the decoder located in the set-top box can easily determine which packets can be decrypted by the decryption method associated with the set-top box. The processing procedure for operating the PID will be described in more detail later.
[0043] (According to a classification method) The encryption technology described in this article can be roughly divided into three basic variations: only the main part (ie audio), only the SI, and only the selected packet. Generally speaking, the embodiments disclosed herein
CN 1633809 Β
Each encryption technique used in the A/V signal attempts to encrypt a part of the A/V signal or related information, while keeping the other part of the A/V signal as plaintext in order to save bandwidth. Since the same plaintext part can be sent to all different set-top boxes, bandwidth can be saved. Use a variety of methods to select the part of the information to be encrypted. In this way, the various embodiments of the present invention can eliminate the traditional "brute force" technique of encrypting the entire content in a specific scrambling scheme, which means redundant use of bandwidth when other scrambling schemes are desired. In addition, each of the partial double encryption schemes described herein can be used as a single partial encryption scheme without departing from the embodiments of the present invention.
[0044] Various embodiments of the present invention use a variety of processing procedures individually or in combination to transmit the main part of the content in plaintext, while only encrypting a small amount of information required for correct reproduction of the content. Therefore, as opposed to completely copying every desired program stream, the amount of transmitted information that is uniquely encrypted according to a specific scrambling scheme occupies only a small part of the content. As far as the exemplary system in this document is concerned, the encryption system A has always been considered a traditional system. The following is a detailed description of each of the above-mentioned encryption technologies.
[0045] Various embodiments of the present invention allow independent operation of each participating CA system. Each CA system is not related to other CA systems. There is no need for the keys in the front-end equipment to work together, because each system encrypts its own packets. Each CA system can use a different key appearance time. For example, a packet encrypted with Motorola's proprietary encryption method can use an embedded security ASIC to use a fast-changing encryption key, while a packet encrypted with a smart card-based system of NDS can use a slower-changing key. For Scientific Atlanta and Motorola's traditional encryption, the above embodiments can work equally well.
[0046] Encrypted elementary stream
[0047] Referring now to FIG. 2, an embodiment of a system that can reduce the need for additional bandwidth and provide multiple transmissions is illustrated as system 100. In this embodiment, the system makes use of the fact that it is generally undesirable to Watch TV shows in the case of audio. Although there are exceptions (such as adult programs, certain sports events, etc.), it is impossible for ordinary viewers to accept daily watching of TV programs without hearing the sound. Therefore, at the front-end equipment 122, the video signal 104 is provided in a plaintext (unencrypted) manner, and the plaintext audio 106 is provided to multiple CA systems for broadcasting on the cable television network. In the exemplary system 100, the plaintext audio 106 is provided to the encryption system 118, and the system 118 encrypts the audio data with the encryption system A (the encryption system A is regarded as a traditional system in the entire file). At the same time, the plaintext audio 106 is provided to the encryption system 124, and the system 124 uses the encryption system B to encrypt the audio data. The clear text video is multiplexed with encrypted audio from 118 (audio A), encrypted audio from 124 (audio B), system information 128, and program-specific information 129.
[0048] After being released via the cable television system 32, the video, system information, program-specific information, audio A and audio B are all transmitted to the set-top boxes 36 and 136. At the conventional STB 36, the video is displayed and the encrypted audio is decrypted in the CA system A40 for playback on the TV 44. Similarly, in the new STB 136, the video is displayed and the encrypted audio is decrypted in the CA system B for playback on the TV 144.
[0049] Compared with a complete A/V program (or even just a video part), audio has a lower bandwidth requirement. The current maximum bit rate of 384Kb/sec stereo audio is about 10% of that of a 3.8Mb/sec TV program. Therefore, for the double transmission of encrypted audio (video is transmitted in plaintext) in a system with 10 channels transmitted by 256QAM (Quadrature Amplitude Modulation), only about one channel of bandwidth will be lost. Therefore, about nine channels can be transmitted. This is a significant improvement to the requirement of double encryption for all channels. Double encryption for all channels reduces the number of available channels from ten to five. If deemed necessary, for example, sports events, paid viewing, adult programs, etc., both audio and video can still be double-encrypted if necessary.
CN 1633809 Β
[0050] Traditional and new set-top boxes can function in a conventional manner, namely receiving plaintext video and decrypting the audio in the same way as used to fully decrypt the encrypted A/V content. If the user does not subscribe to the program encrypted according to the above scheme, the user can only see the video at most, but not the audio. As far as the enhanced security of the video is concerned, it is also possible to use other embodiments of the present invention (which will be described later). (For example, the SI can be disrupted to make it more difficult for unauthorized set-top boxes to tune to the video portion of the program). Unauthorized set-top boxes that have not been modified by hackers will blank the video because they receive encrypted audio.
[0051] The authorized set-top box receives an authorization control message (ECM), which is used to obtain an access standard and a descrambling key. The set-top box attempts to apply the key to video and audio. Since the video is not disturbed, the video will pass through the descrambler of the set-top box unaffected. The set-top box does not matter whether the video is in plaintext. For disturbed audio and plain text video, unmodified and unsubscribed set-top boxes appear to be unauthorized. The video and the actually disturbed audio will be blanked. An on-screen display will appear on the TV to indicate that the viewer needs to subscribe to the program. This ideally prohibits casual viewers from hearing or seeing the content at all.
[0052] In one embodiment of the present invention, the encrypted audio is transmitted as a digital packet on the A/V channel. Transmit two (or more) audio streams encrypted according to the two (or more) encryption systems used by the system's set-top box. In order to enable two (or more) STBs to correctly decrypt and decode their respective audio streams, SI (system information) data is transmitted from the front-end device 122 of the cable TV system, and the front-end device 122 uses the transmitted data to determine the audio The service identifier of the location to identify the specific channel where audio can be found. This is achieved by assigning a first packet identifier (PID) to system A audio and a second packet identifier (PID) to system B audio. For example (but not for limitation), program specific information (PSI) can be sent to identify the location of audio for two systems, one of which uses NDS conditional access and the other uses Motorola conditional access. Those skilled in the art should be able to understand how to adapt this information to other embodiments of partial encryption described later herein.
[0053] SI can be independently transmitted to traditional and non-traditional set-top boxes. SI information can be sent, so that traditional and non-traditional set-top boxes can operate without conflict. In the SI sent to the traditional set-top box, the VCT (Virtual Channel Table) will indicate that the desired program (for example, HB0 marked as program number 1) is on the service ID "1" and the VCT access control bit is set. The network information table (NIT) sent to the first STB will indicate that the service ID "1" is at frequency=1234. In the SI sent to the non-traditional set-top box, the VCT indicates that the desired program (for example, HB0 marked as program number 1001) is on the service ID "1001" and the VCT access control bit is set. The network information table sent to the non-traditional STB will indicate that the service ID "1001" is at frequency 1234. The following exemplary program association table PSI data is sent to traditional and non-traditional set-top boxes (according to MPEG data structure format):
[0054]
PAT PATOxOOOO sent on PID = 0x0000
-Transport stream ID
-PAT version
-Program number 1
-ΡΜΤΟχΟΟΙΟ
-Program number 2
-PMT0x0020
-Program number 3
-PMT0x0030
-Program number 4
-PMT0x0040
-Program number 5
-PMT0x0050
-Program number 6
-ΡΜΤ0χ0060
-Program number 7
-ΡΜΤ0χ0070
-Program number 8
-ΡΜΤ0Χ0080
-Program number 9
-ΡΜΤ0χ0090
-Program number 1001
-PMTOxlOlO
-Program number 1002
-PMT0xl020
-Program number 1003
-PMT0xl030
-Program number 1004
-PMT0xl040
-Program number 1005
-ΡΜΤΟχΙΟδΟ -program number 1006 -ΡΜΤΟχΙΟβΟ -program number 1007 -PMT0xl070 -program number 1008 -MT0xl080 -program number 1009 -PMT0xl090
[0055] Traditional and non-traditional set-top boxes selectively receive the following exemplary program map table PSI data (according to MPEG data
CN 1633809 Β
According to structure format):
[0056] PMT sent on PID=0x0010
ΡΜΤΟχΟΟΙΟ
-PMT program number 1
-PMT segment version 10
-PCRPIDOxOOll
-Elementary flow
-Stream type (video 0x02 or 0x80)
-Basic PID (0x0011)
-Descriptor
-CA Descriptor (ECM) for CA Vendor #1-Elementary Stream
-Stream type (audio 0x81)
-Basic PID (0x0012)
-Descriptor
-CA Descriptor (ECM) for CA supplier #1 PMT sent on PID = 0x1010
PMTOxlOlO
-PMT program number 1010 -PMT segment version 10 -PCRPIDOxOOll
-Elementary flow
-Stream type (Video 0x02 or 0x80) -Basic PID (0x0011)
-Descriptor
-CA Descriptor (ECM) for CA Vendor #2-Elementary Stream
-Stream type (audio 0x81) -Basic PID (0x0013)
-Descriptor
-CA Descriptor (ECM) for CA Vendor #2
[0057] Consider an example in which programs are expected to be sent in a system using Motorola or Scientific Atlanta and NDS CA. The above communication is consistent with the PSI sent by Motorola and Scientific Atlanta in their CA system, with only minor changes. Change the program association table (PAT) to index an additional program map table (PMT) for each program. Each program in this embodiment has two program numbers in the PAT. In the above table, program number 1 and program number 1001 are the same program except for the audio PID and CA descriptor that index different. In order to create multiple PMTs and multiplex the new PAT and PMT information with the data stream, the system can be changed, so that the front-end equipment of the cable TV system can be modified appropriately. Furthermore, those skilled in the art should recognize how to make these messages suitable for other partial encryption schemes described in this article. The advantage of this method is that, for front-end equipment or traditional and non-traditional set-top boxes, no special hardware or software is required to transmit the audio that is encrypted by the program.
CN 1633809 Β
[0058] This technology can make unpaid paid programs inaudible and prevent users from using the program, but hackers may try to tune into the video. To prevent this, if necessary, the mechanisms used in other encryption techniques according to the present invention (as described later) can be used at the same time. Since closed captions are generally transmitted as part of video data, users can still obtain readable audio information and plaintext video. Therefore, although it is suitable for some applications, the technology itself cannot provide adequate protection for all situations. In another embodiment, video packets containing closed caption information as part of the payload can also be additionally scrambled.
[0059] In an alternative embodiment, the independent PID assigned to each group of encrypted videos can be used to only double or multiple encrypt the video. Although this will provide more secure encryption for general programs (because video may be more important than audio), the bandwidth savings compared to full dual transmission is only about 10%, because only audio can be shared among all set-top boxes. However, this method can be used for specific content (such as adult and sports programs) and helps reduce the bandwidth overhead for that content, while the audio encryption method can be used for other types of content. In the digital satellite service (DSS) transmission standard for DirecTVTM service, the service channel identifier (SCID), which is considered equivalent, can be used to identify audio packets for adding tt I ο
[0060] Time Slicing
[0061] Another embodiment according to the present invention is referred to herein as timeslicing, and is illustrated as system 200 in FIG. 3. In this embodiment, a part of each program is encrypted on a time-correlated basis in a way that interferes with watching the program, unless the user has paid for the program. This embodiment of the present invention can be implemented as: partially encrypted video and plaintext audio, plaintext video and partially encrypted audio, or partially encrypted video and audio. The duration of the encrypted time slice is a certain percentage of the entire time, and the duration can be selected so as to satisfy any suitable desired balance between bandwidth usage and anti-hacking security. Generally speaking, in any of the embodiments described herein, less than 100% of the content is encrypted in order to generate the desired partial encryption. The following example details partially encrypted video and audio.
[0062] For example (but not for limitation), consider a system with nine programs, all of which are subject to double partial encryption in accordance with an exemplary embodiment of the present invention. These nine channels are fed to the cable head-end equipment as a multiplexed packet stream and digitally encoded with a packet identifier (PID) to identify the packet associated with a specific one of the nine programs. In this example, assume that these nine programs have video PIDs numbered 101-109 and audio PIDs numbered 201-209. Partial encryption according to this embodiment is time multiplexing between programs, so at any given time, only packets from a single program are encrypted. This method does not need to know what the content is.
[0063] With reference to Table 1 below, an exemplary embodiment of a time slice double encryption scheme consistent with an embodiment of the present invention is illustrated. Regarding program 1 with main video PID101 and main audio PID201, in the first time period, encryption system A is used to encrypt packets with PID101 and PID201 for encryption, and other packets representing other programs are sent in plaintext. In this embodiment, the secondary PID is also assigned to video and audio. For program 1, the secondary PID is PID111 for video and PID21L for audio. In the first time period, use encryption system B to encrypt the packet with secondary PID, and send it in plaintext. Of eight time periods. For time period 10, the packet with any one of the above four PIDs is encrypted again, and then the next eight time periods are sent in plaintext. In a similar way, in the second time period, use the encryption system A to encrypt the program 2 with the main video PID102 and the main audio PID202, and use the encryption system B to encrypt the packet with the relevant secondary PID, and in the next It is sent in clear text in the eight time periods, and so on. By examining the first nine rows, this pattern can be clearly seen in Table 1. Without departing from this
CN 1633809 Β
In the case of the invention, both audio and video packets or only audio or video can be encrypted according to this technology. Also, audio and video can have their own separate encryption sequences. In Table 1, PI represents time period number 1, P2 represents time period number 2, and so on. EA means using CA system A to encrypt information, and EB means using CA system B to encrypt information.
[0064]
<td>program</td><td>Video PID</td><td>Audio PID</td><td>P1</td><td>P2</td><td>P3</td><td>P4</td><td>P5</td><td>P6</td><td>P7</td><td>P8</td><td>P9</td><td>P10</td><td>P11</td><td>P12</td><td></td>
<td>1</td><td>PID101</td><td>PID201</td><td>EA</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>EA</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>2</td><td>PID102</td><td>PID202</td><td>Plaintext</td><td>EA</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>EA</td><td>Plaintext</td><td></td>
<td>3</td><td>PID103</td><td>PID203</td><td>Plaintext</td><td>Plaintext</td><td>EA</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>EA</td><td></td>
<td>4</td><td>PID104</td><td>PID204</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>EA</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>5</td><td>PID105</td><td>PID205</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>EA</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>6</td><td>PID106</td><td>PID206</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>EA</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>7</td><td>PID107</td><td>PID207</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>EA</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>8</td><td>PID108</td><td>PID208</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>EA</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>9</td><td>PID109</td><td>PID209</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>EA</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>1</td><td>PID111</td><td>PID211</td><td>EB</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td>EB</td><td></td><td></td><td></td>
<td>2</td><td>PID112</td><td>PID212</td><td></td><td>EB</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td>EB</td><td></td><td></td>
<td>3</td><td>PID113</td><td>PID213</td><td></td><td></td><td>EB</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td>EB</td><td></td>
<td>4</td><td>PID114</td><td>PID214</td><td></td><td></td><td></td><td>EB</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td>
<td>5</td><td>PID115</td><td>PID215</td><td></td><td></td><td></td><td></td><td>EB</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td>
<td>6</td><td>PID116</td><td>PID216</td><td></td><td></td><td></td><td></td><td></td><td>EB</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td>
<td>7</td><td>PID117</td><td>PID217</td><td></td><td></td><td></td><td></td><td></td><td></td><td>EB</td><td></td><td></td><td></td><td></td><td></td><td></td>
<td>8</td><td>PID118</td><td>PID218</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td>EB</td><td></td><td></td><td></td><td></td><td></td>
<td>9</td><td>PID119</td><td>PID219</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td>EB</td><td></td><td></td><td></td><td></td>
[0065] Table 1
[0066] In order to maintain compatibility with the established conventional encryption system (encryption system A), encryption system A is used to encrypt the encryption period for each of programs 1 to 9. Traditional STB equipment will accept this partially encrypted A/V data stream, transparently transmit unencrypted packets and decrypt encrypted packets. However, it is desirable to use both the encryption system A and the encryption system B to obtain double encryption. In order to do this, assign the main PID to the specified program (for example, assign the program 1
CN 1633809 Β
Video PID101 and audio PID201) and secondary PID (for example, video PID111 and audio PID211 are assigned to program 1) to carry the basic data stream for a given premium channel.
3, the system 200 generally illustrates the function of the front-end equipment 222 of the cable TV system, wherein the clear text video 208 of the N channels at the front-end equipment 222 is provided to the smart switch 216 (in a programming processor Work under the control of ), the switch can choose to transmit the packet that will be assigned the primary PID at 220 to be transmitted in clear text. The packet to be encrypted is selected to be passed to the encryptor 218 of the conditional access system A and the encryptor 224 of the conditional access system B. Once encrypted, these encrypted packets from 218 and 224 are assigned primary or secondary PIDs at 220, respectively. The system information from 228 and the PSI from 229 are multiplexed or combined with plaintext packets, system A-encrypted packets, and system B-encrypted packets and broadcast on the cable television system 32.
[0068] For the purpose of discussion, if the time slice period is 100 milliseconds, as shown in Table 1, for all nine programs, there is a multi-encryption period totaling 111 milliseconds per second on average. If the time slice period is 50 milliseconds, there are two multiple encryption periods totaling 111 milliseconds. If an unsubscribed set-top box trying to tune the video can maintain any kind of image lock, it will get very poor images, and the audio will be messy.
[0069] The PSI for the partially scrambled stream is processed in a slightly different manner from the above double audio encryption example. The same SI and PAT PSI information can essentially be sent to traditional and non-traditional set-top boxes. The difference lies in the PMT PSI information. The traditional set-top box parses the PMT PSI and obtains the main video and audio PID as before. The non-traditional set-top box obtains the main PID like the traditional set-top box, but the CA descriptor in the PMT PSI must be checked to check whether the stream is partially disturbed. For a specific CA supplier, the secondary PID is disturbed. Therefore, it makes sense to use a CA descriptor dedicated to the specific CA supplier to send the PID signal. The present invention allows more than two CA providers to coexist by allowing more than one secondary PID. The secondary PID should be unique to a specific CA provider. The set-top box knows the CA ID for the CA it has and can check all the CA descriptors to find the one related to it.
[0070] Although the secondary PID data can be sent as private data in the same CA descriptor used for ECM, the preferred embodiment uses a separate CA descriptor. The secondary PID is placed in the CA PID field. This allows the front-end processing device to "see" the PIDo without having to parse the private data field of the CA descriptor. In order to distinguish the difference between the ECM and the secondary PID CA descriptor, it can send a pseudo-private data value.
[0071]
CN 1633809 Β
PMT sent on PID = 0x0010
ΡΜΤΟχΟΟΙΟ
-PΜΤ program number 1 -PΜΤ segment version 10
-PCRPIDOxOOll
-Elementary flow
-Stream type (video 0x02 or 0x80)
-Basic PID (OxOOll)
-Descriptor
-CA Descriptor (ECM) for CA vendor #1
-CA Descriptor (ECM) for CA Vendor #2
-CA Descriptor (Secondary PID) for CA Vendor #2-Elementary Stream
-Stream type (audio 0x81)
-Basic PID (0x0012)
-Descriptor
-CA Descriptor (ECM) for CA vendor #1
-CA Descriptor (ECM) for CA Vendor #2
-CA Descriptor (Secondary PID) for CA Vendor #2 [0072] CA Descriptor (ECM) for CA Vendor #2
[0073] Descriptor
-Mark: Conditional access (0x09)
-Length: 4 bytes
-data
-CA system ID: 0x0942 (second CA supplier) -CAPID (0x0015)
[0074] CA Descriptor (Secondary PID) for CA Provider #2
[0075] Descriptor
-Mark: Conditional access (0x09)
-Length: 5 bytes
-data
-CA system ID: 0xl234 (second CA supplier) -CAPID (0x0016)
-Private data
[0076] The traditional STB36 working under the CA system A receives data, ignores the secondary PID, decrypts the packets encrypted under the CA system A, and provides the program to the television 44. The new or non-traditional STB236 receives SI228. It receives
CN 1633809 Β
PSI229 also uses PMT to identify the primary and secondary PIDs related to the program being watched called out in the second CA descriptor. The packets encrypted under the CA system A are discarded, and the packets with the secondary PID encrypted under the CA system B are decrypted by the CA system B240 and inserted into the plaintext data stream so as to be decoded and displayed on the TV 224.
[0077] FIG. 4 illustrates a processing procedure for encoding at the front-end equipment of a cable TV system, which can be used to implement an embodiment of the present invention, where CA system A is a traditional system, and CA system B is The new system introduced. When a clear text packet for a given program is received at 250, if the packet (or frame) is not encrypted (that is, it is not the current time slice used for encryption for the program), then the clear text packet (C) is transmitted for Insert the output stream at 254. If the current packet is encrypted because the current packet is part of the encryption time slice, the packet is passed to the packet encryption process A258 and the packet encryption process B262 for encryption. The Encrypted Packet (EA) from Encryption Process A at 258 is passed to 254 for insertion into the output stream. The encrypted packet (EB) from encryption process B at 262 is assigned a secondary PID at 264 for insertion into the output stream at 254. Repeat the above process for all groups in the program.
[0078] FIG. 5 illustrates the processing procedure used in STB236. STB236 has a newly introduced CA system B to decrypt and decode the received data stream, and the received data stream contains the main , C, EA and EB grouping of the secondary PID. When a packet is received at 272, it is checked whether it has the primary PID of interest. If not, it is checked at 274 whether the packet has the secondary PID of interest. If the packet has neither a primary PID nor a secondary PID, then at 278 the packet is ignored or discarded. Any inserted packets between EA and EB packets that are not primary or secondary PID are discarded. Whether the decoder can receive multiple consecutive EAs or EBs before receiving the matched EA or EB packets is a matter of implementation form and mainly a buffering issue. In addition, it is easy to detect secondary packets that come before the main packet instead of after the main packet. It is also possible to design such a circuit in which two situations can occur, namely: the secondary grouping is before the main grouping or after the main grouping. If the packet has the primary PID of interest, then the packet is checked at 284 to determine if it is encrypted. If not, then at 288 the packet (C) is passed directly to the decoder for decoding. If the packet is determined to be encrypted at 284, it is considered an EA packet and discarded or ignored at 278. In some implementation forms, At 284, the encryption of the main packet is not checked. Instead, only check its position relative to the secondary group at 284 to identify it for replacement.
[0079] If the packet is determined to have a secondary PID at 274, then at 292 the PID is remapped to the primary PID (or equivalently the primary PID is remapped to the secondary PID value). The packet is then decrypted at 296 and sent to the decoder at 288 for decoding. Of course, those skilled in the art should recognize that there can be many variations without departing from the present invention, for example, the order of 292 and 296 or the order of 272 and 274 can be reversed. As mentioned earlier, 284 can be replaced by checking the position of the primary packet relative to the secondary packet. Those skilled in the art can think of other variations.
[0080] The traditional STB36 working under the encryption system A completely ignores the secondary PID packet. If necessary, decrypt the packets with the main PID and pass them to the decoder without decryption if they are plaintext. Therefore, the so-called "traditional" STB working under the encryption system A will properly decrypt and decode the partially encrypted data stream related to the primary PID and ignore the secondary PIDo pair work under the encryption system B without modification. The STB is programmed to ignore all encrypted packets related to the primary PID and use the transmitted encrypted packets with the secondary PID related to the specific channel.
[0081] Therefore, each double partially encrypted program has two sets of PIDs associated with it. In the case of the system shown with appropriate time slice intervals, if the encryption is performed cycle by cycle as described, the image is basically unviewable on the STB that does not have either type of decryption.
[0082] In order to implement such a system in the front-end equipment 322 of FIG. 6, the SI and PSI can be modified to include the second group of CAs.
CN 1633809 Β
Descriptor information. Traditional set-top boxes may not be able to tolerate unknown CA descriptors. Therefore, in the set-top box, alternatively, the content PID and/or SI/PSI and ECM PID can be "hard-coded" offset from the traditional CA PID. Or you can send parallel PSI. For example, for non-traditional set-top boxes, the auxiliary PAT can be sent at PID1000 instead of PID0±. It can index auxiliary PMT not found in traditional PAT. The auxiliary PMT may include non-traditional CA descriptors. Since the auxiliary PMT is unknown to the traditional set-top box, there is no interoperability problem.
[0083] In a system in which System A corresponds to a traditional set-top box manufactured by Motorola or Scientific Atlanta, there is no need to modify the STB. For the STB compatible with System B, for the dual transmission of partially encrypted programs described in this article, the video and audio decoder is suitable for monitoring two PIDs (primary PID and secondary PID) instead of monitoring only one PID. Depending on the number of non-traditional CA systems used, there may be one or more shadow PIDs. However, suitable for the CA method used by a specific STB, the specific set-top box only monitors one of the secondary PIDs. In addition, it is ideal to ignore encrypted packets from PIDs that carry video or audio that is mainly plaintext. Since ignoring "bad packets" (packets that cannot be easily decoded as they are) may already be a function performed by many decoders, no modification is required. For systems with decoders that do not ignore bad packets, filtering functions can be used. It should be recognized that time slice encryption technology can be applied only to video or audio. Also, the video can be time-slice-encrypted, while the audio is double-encrypted as in the previous embodiment. Time slice technology can be applied to multiple programs at the same time. The number of encrypted programs in a period of time is mainly a problem of bandwidth allocation. Although the above example discusses disturbing a single program each time, the present invention is not limited to this. For those skilled in the art, other combinations of encryption techniques described in this document can also be conceived.
[0084] Encryption of the Mth and Nth packets
[0085] Another embodiment according to the present invention is referred to herein as encryption of the Mth and Nth packets. This is a variation of the embodiment illustrated as system 200 in FIG. 3. In this embodiment, the grouping of each PID representing the program is encrypted in a way that can interfere with watching the program, unless the user has paid for the program. In this embodiment, M represents the number of packets between the start of encryption events, and N represents the number of packets that are continuously encrypted once encryption starts. Ν is less than Μ. If M = 9 and N = 1, then there is an encryption event lasting one packet for every nine packets. If M = 16 and N = 2, then every sixteen packets will have an encryption event lasting two packets. As in the previous embodiment, the CA system A218 and the CA system B224 are used to copy and process each packet to be double-partially encrypted. The operational difference between this embodiment and the previous time slicing technique is that the switch 216 selects packets for the encryption operation under the control of the programmed processor.
[0086] As an example (but not for limitation), consider a system with nine program channels that are to be double-encrypted according to this exemplary embodiment. These nine channels are digitally coded with a group identifier (PID) to identify the group related to a specific one of the nine programs. In this example, it is assumed that these nine programs have video PIDs with numbers 101-109 and audios with numbers 201-209. According to this embodiment, encryption is performed randomly on a program-by-program basis, and therefore, packets from other programs can be encrypted at the same time. This is illustrated in Table 2 below, where M = 6, N = 2 and only the video is encrypted, but this should not be considered restrictive. This method does not need to know what the content is. In Table 2, PK1 represents group number 1, PK2 represents group number 2, and so on.
[0087]
<td>program</td><td>video</td><td>PK1</td><td>PK2</td><td>PK3</td><td>PK4</td><td>PK5</td><td>PK6</td><td>PK7</td><td>PK8</td><td>PK9</td><td>PK10</td><td>PK11</td><td>PK12</td><td></td>
<td>1</td><td>PID101</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
CN 1633809 Β
<td>program</td><td>video</td><td>PK1</td><td>PK2</td><td>PK3</td><td>PK4</td><td>PK5</td><td>PK6</td><td>PK7</td><td>PK8</td><td>PK9</td><td>PK10</td><td>PK11</td><td>PK12</td><td></td>
<td>2</td><td>PID102</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td></td>
<td>3</td><td>PID103</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>4</td><td>PID104</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td></td>
<td>5</td><td>PID105</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>6</td><td>PID106</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td></td>
<td>7</td><td>PID107</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>8</td><td>PID108</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>9</td><td>PID109</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td></td>
<td>1</td><td>PID111</td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td></td>
<td>2</td><td>PID112</td><td></td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td>
<td>3</td><td>PID113</td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td>
<td>4</td><td>PID114</td><td></td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td>
<td>5</td><td>PID115</td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td>
<td>6</td><td>PID116</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td></td>
<td>7</td><td>PID117</td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td></td>
<td>8</td><td>PID118</td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td>
<td>9</td><td>PID19</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td></td>
[0088] Table 2
[0089] In the example of Table 2, each program is encrypted with an encryption scheme of M=6 and N=2 completely independently of each other. Furthermore, the described example only encrypts the video, but the audio can also be encrypted according to the above or another arrangement. If it is only applied to video, the audio can be double scrambled or time sliced encrypted as in the previous embodiment. Or, if it is only applied to audio, the video can be time-sliced as in the previous embodiment.
[0090] Those skilled in the art should realize that many variations of the above-mentioned technology can be designed in accordance with the partial perturbation concept disclosed herein. For example, five plaintexts, two encrypted, followed by two plaintexts, and then an encrypted mode (CCCCCEECCE CCCCCEECCE...) conforms to the variation of this part of the encryption concept, while the randomness of M and N Values, pseudo-random values, and semi-random values can be used to select packets for encryption. Random, pseudo-random, or
Semi-random (collectively referred to as "random" in this article) selection will make it difficult for hackers to algorithmically reconstruct groups in the post-processing process of trying to recover the recorded content that was disrupted. Those skilled in the art should recognize how to adapt the above information to other embodiments of partial encryption described later in this document. Certain embodiments can be used in combination to more effectively keep the content confidential.
[0091] Data structure encryption
[0092] Another partial encryption method in the embodiment of the present invention performs encryption on the basis of a data structure. By way of example but not for limitation, one common data structure used for encryption is MPEG video frames. The following Table 3 illustrates this point (again only for video), where encryption is performed every nine video frames. In this embodiment, the ten-frame encryption period of each program is different from each other for each channel, but this should not be considered restrictive. This idea can be seen as a variation of time slices or encryption arrangements (or other modes) of the M and N parts based on video or audio frames (or other data structures). In the exemplary embodiment, M = 10 , Ν = Ε Of course, other values of M and N can be used in similar embodiments. In Table 3, F1 represents frame number 1, F2 represents frame number 2, and so on.
[0093]
<td>program</td><td>video</td><td>F1</td><td>F2</td><td>F3</td><td>F4</td><td>F5</td><td>F6</td><td>F7</td><td>F8</td><td>F9</td><td>F10</td><td>F11</td><td>F12</td><td></td>
<td>1</td><td>PID101</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>Plaintext</td><td></td>
<td>2</td><td>PID102</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>3</td><td>PID103</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>4</td><td>PID104</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>5</td><td>PID105</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td></td>
<td>6</td><td>PID106</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>Plaintext</td><td></td>
<td>7</td><td>PID107</td><td>Plaintext</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td></td>
<td>8</td><td>PID108</td><td>Plaintext</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td></td>
<td>9</td><td>PID109</td><td>ΕΑ</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>Plaintext</td><td>ΕΑ</td><td>Plaintext</td><td></td>
<td>1</td><td>PID111</td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td></td><td></td>
<td>2</td><td>PID112</td><td></td><td></td><td></td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td>
<td>3</td><td>PID113</td><td></td><td></td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td>
<td>4</td><td>PID114</td><td></td><td></td><td></td><td></td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td>
<td>5</td><td>PID115</td><td></td><td></td><td></td><td>ΕΒ</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td>
CN 1633809 Β
<td>program</td><td>video</td><td>F1</td><td>F2</td><td>F3</td><td>F4</td><td>F5</td><td>F6</td><td>F7</td><td>F8</td><td>F9</td><td>F10</td><td>F11</td><td>F12</td><td></td>
<td>6</td><td>PID116</td><td>EB</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td>EB</td><td></td><td></td>
<td>7</td><td>PID117</td><td></td><td>EB</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td>EB</td><td></td>
<td>8</td><td>PID118</td><td></td><td>EB</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td>EB</td><td></td>
<td>9</td><td>PID119</td><td>EB</td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td></td><td>EB</td><td></td><td></td>
[0094] Table 3
[0095] Therefore, equally each encrypted program has two sets of PIDs associated with it. If the encryption is performed cycle by cycle as described above, the image is basically unviewable for the system shown. For the nine-program system shown at 30 frames per second, about three frames are encrypted per second. For viewers who are not authorized to watch the program, their STB can at most occasionally capture still frames because the STB constantly tries to synchronize and recover. Viewers who have already subscribed to the program can easily watch the program. The bandwidth cost for this encryption arrangement depends on the frequency of encryption. In the above example, an extra 1/9 of the data is transmitted for each program. In this example, the bandwidth of about one program is used. In the case of a larger number of programs, fewer packets are encrypted for each program, and the security of the encryption system will be slightly reduced. As in the randomized M and N methods, random frames can be selected. As far as video is concerned, choosing a random frame will help ensure that all types of frames are affected-intra-coded frames (I frames), predicted frames (P frames), bidirectional coding (B frames) and DC frames.
[0096] In a variation of the present invention, fewer packets can be encrypted in order to obtain an acceptable level of security. In other words, perhaps in the nine-program system, only one frame per second needs to be encrypted to obtain an acceptable level of security. In this system, the total cost is one encryption cycle per second per program or about 1/30 of the data transmitted in the total cost. This total cost level is compared with the full double transmission encryption under the two encryption systems. The associated 50% bandwidth loss is a significant improvement. In another variation of the present invention, only specific video frames can be encrypted to obtain an acceptable level of security. For example, for MPEG content, only The intra-coded frame (I frame) is scrambled to further reduce the total bandwidth overhead and still maintain an acceptable level of security. This provides a significant improvement over the bandwidth required for full dual transmission.
[0097] Critical block encryption
[0098] The use of selective block-by-block double encryption technology can achieve high efficiency in bandwidth usage. In this embodiment, the packets are selected for encryption according to their importance to the correct decoding of the audio and/or video of the program content.
[0099] Compared with the full dual transmission of encrypted content, this embodiment can reduce bandwidth requirements by disrupting only a small portion of packets. The plaintext packet is shared between two (or more) dual transmission PIDs. In a preferred embodiment, as will be disclosed, less than about one percent of the total content bandwidth is used. In a system using traditional encryption schemes, clear text program content packets can be received by traditional and new set-top boxes. As mentioned above, the encrypted packet is double-transmitted and processed by the corresponding set-top box with the appropriate CA. Each CA system is not related to each other. No key sharing is required, and the standby CA system can use different key appearance times. For example, a system with a Motorola-specific encryption method can generate a fast-changing encryption key with an embedded security ASIC, while a system based on an NDS smart card can generate a key with a slower change. For Scientific Atlanta and Motorola's traditional encryption, this embodiment can work equally well.
CN 1633809 Β
[0100] Referring to FIG. 6, a block diagram of a system according to an embodiment of the present invention is illustrated as a system 300, in which part of a program is double-encrypted on a packet-by-packet basis. In this system, for example, the traditional CA system A and the new CA system B are used to double-encrypt the packets of the backup program. The encrypted packet is selected according to the importance of the packet to the correct decoding of the video and/or audio stream.
[0101] In the system shown in FIG. 6, the front-end equipment 322 of the cable television system selects the packet of the A/V content 304 at the packet selector 316 for encryption. The packets selected for encryption are selected so that unreceived (via an unpaid decoder) these packets will seriously affect the real-time decoding of the program and will affect the post-processing of the recorded content. In other words, only key packets are encrypted. For video and audio, this can be achieved by encrypting the "start of frame" transport stream packet that contains the PES (Packetized Elementary Stream) header and other headers as part of the payload, because there are no such The information STB decoder cannot decompress MPEG compressed data. MPEG2 stream uses the "packet unit start indicator" in the transmission header to identify the "frame start" packet. Generally speaking, a packet carrying a payload containing a set of image headers or video sequence headers can be used to implement the scrambling technique of the present invention.
[0102] MPEG (Moving Picture Experts Group) compatible compressed video can regroup the elementary data stream into a transport stream in the form of a slightly arbitrary payload with 188 bytes of data. Therefore, the transport stream packets containing the PES header can be selected at the selector 136 for encryption, and these packets can be double-encrypted by the CA system A encryptor 318 and the CA system B encryptor 324. The packet to be double partially encrypted may be copied, and as in the previous embodiment, the PID of the copied packet encrypted by the encryptor 324 may be remapped to the secondary PID at 330. Transmit the remaining packets in clear text. The clear text packet, the system A encrypted packet, the system B encrypted packet, and the system information 328 and PSI from 329 are multiplexed together to be broadcast on the cable television system 32.
[0103] Like the previous system, the traditional STB36 receives the plaintext data and the data encrypted under the CA encryption system A and transparently transmits the unencrypted data combined with the data decrypted by the CA decryption A40 to the decoder. In the new STB336, programs are assigned to primary and secondary PIDs. Receive the plaintext packet with the main PID and pass it to the decoder. Discard the encrypted packet with the primary PID. Decrypt the encrypted packet with the secondary PID, and then recombine it with the data stream (for example, by remapping the packet to the primary PID) for decoding.
[0104] Taking video as an example, each sample is called a frame, and the sampling rate is generally 30 frames per second. If the samples are encoded to be suitable for 3.8 Mbps, each frame will occupy a bandwidth of 127K bits. For MPEG transmission, this data is divided into 188-byte packets, and the first or first few packets of each frame contain a header indicating the processing of the main body of the frame data. Double encryption of only the first header packet (1504 extra bits) requires only 1.2% (1504/127K) of extra bandwidth. For high-definition (19Mbps) streams, this percentage is even less.
[0105] As mentioned above, according to this embodiment, the transport stream packet containing the PES header is the preferred encryption target. These packets contain sequence header, sequence extension header, image header, quantization and other decoding tables (they are also in the same packet). If these packets cannot be decoded (that is, a hacker tries to watch an unauthorized program without paying the subscription fee), even a small part of the program cannot be watched. In short, any attempt to tune to the program is likely to encounter a black screen and no audio, because known decoder integrated circuits use PES headers to synchronize elementary streams such as video and audio in real time. By encrypting the PES header, the decoding engine in an unauthorized set-top box cannot even be started. The key information that dynamically changes in the packet containing the PES header can prevent, for example, post-processing attacks on the stored content. Those skilled in the art will notice that for the implementation of this embodiment of the present invention, it can also be identified Without departing from the present invention, unauthorized viewing of other critical or important packets or content units can be strictly prevented for encryption. For example, MPEG intra-encoding or I-frame image packets can be encrypted to prevent the program
CN 1633809 Β
To watch the video part. The embodiments of the present invention can be used in combination with any other embodiments, for example, can be used in combination with random, M and N or data structure encryption that scrambles packets containing PES headers and other packets. Critical packet encryption can be applied to video encryption, while using different methods for audio. For example, the audio can be double-encrypted. For those skilled in the art, other variations within the scope of the present invention can be conceived.
[0106] FIG. 7 is a flowchart illustrating an exemplary encoding process such as can be used at the front-end device of FIG. 6. When a transport stream packet is received at 350, the packet is checked to determine whether it meets the selection criteria for encryption. In this preferred embodiment, the selection criterion is the presence of a PES header as part of the packet payload. If the standard is not met, the packet is transmitted as a plaintext unencrypted packet (C) so as to be inserted into the output data stream at 354. If the packet meets the above criteria, it is encrypted with the CA encryption system A at 358 to generate an encrypted packet EA. At 362, the packet is copied and encrypted with CA encryption system B to generate an encrypted packet. This encrypted packet is mapped to the secondary PID at 366 to generate an encrypted packet. EBo inserts the encrypted packets EA and EB together with the plaintext packet C into the output data stream at 354. Preferably, the EA and EB packets are inserted in the data stream where the single original packet for encryption was originally obtained, so that the ordering of the data remains substantially the same.
[0107] When an output data stream from 354 is received at an STB compatible with CA encryption system B, such as 336 in FIG. 6, a processing procedure such as that of FIG. 8 (similar to the processing procedure of FIG. 5) can be used. ) And the like to decrypt and decode the program. When a packet with primary or secondary PID is received at 370, it is judged at 370 whether the packet is in plaintext (C) or encrypted with system A (EA), or at 374 it is judged whether the packet is with system B (EB) To encrypt. If the packet is in plaintext, it is passed directly to the decoder 378. In some embodiments, the relative position of the primary packet before or after the secondary packet may be used to signal the replacement of the primary packet in the stream. It is not particularly necessary to check the jamming status of the main packet. If the packet is an EA packet, it is discarded at 380. If the packet is an EB packet, it is decrypted at 384. At this time, at 388 the secondary PID packet and/or the primary PID packet are remapped to the same PID. At 378, the decrypted packet and the plaintext packet are decoded.
[0108] Relative to the requirement of full dual transmission, the above-mentioned dual partial encryption arrangement can greatly reduce bandwidth requirements. Encrypting PES header information can effectively protect video and audio content, while allowing two or more CA systems to independently "coexist" in the same cable television system. The set-top box of the traditional system A is not affected, and the set-top box of the system B only needs less hardware, firmware or software enhancements to monitor the two PIDs for video and audio respectively. Each type of STB (traditional and non-traditional) can maintain its inherent CA method. The modification of the front-end equipment is limited to selecting content for encryption, introducing a second encryptor, and providing means to mix their combination into a composite output stream.
[0109] In one embodiment, the front-end equipment is configured to randomly disrupt as much content as the bandwidth allows, not just the key PES header. These extra scrambled packets can be located in the PES payload, or can be located in other packets in the entire video/audio frame, thereby making the content more secure.
[0110] SI encryption
[0111] Referring now to FIG. 9, one embodiment of a system that has a minimum requirement for any additional bandwidth is illustrated as system 400. In this embodiment, the system takes advantage of the fact that for the set-top box, system information (SI) 428 is required to tune the program. In a cable television system, SI is sent outside the band (that is, at a frequency outside the normal viewing channel). It can also be sent within the band. If sending in the band, copy SI428 and send SI428 in each stream. For discussion purposes, it is assumed that the SI sent to a "legacy" set-top box from the previous manufacturer is independent of the SI sent to a set-top box such as STB436 from the new manufacturer. Therefore, each version of SI can be disturbed independently with the conditional access system A418 and the conditional access system B424 as described earlier. Clear text video 404 and clear text audio 406 in a clear text manner
CN 1633809 Β
Transmit, but in order to understand how to find them, SI information 428 is required.
[0112] The SI transmits information related to channel names and program guide information such as program names and start times, and frequency tuning information for each channel. Digital channels are multiplexed together and transmitted on a specific frequency. In the embodiment of the present invention, the SI information is encrypted, and the information can only be used by authorized set-top boxes. If the SI information used to understand the position of all A/ν frequencies in the device is not received, tuning cannot be performed.
[0113] To prevent a hacker from programming a set-top box to track or scan the frequency, the frequency of the channel may deviate from the standard frequency. Also, the frequency can be dynamically changed on a daily, weekly, or other period or randomly. A typical wired front-end device can have about 30 frequencies in use. The various frequencies are generally selected to specifically avoid interference with each other and with the frequencies used by terrestrial broadcast signals and receiving equipment clocks. Each channel has at least one independent alternative channel, which, if used, will not cause interference or cause the frequency of adjacent channels to change. Therefore, the actual possible frequency mapping is 2 or 1.07x109. However, a hacker can quickly try both frequencies when trying to tune each of about 30 channels. If the frequency with content is successfully determined, the hacker's set-top box can parse PSI429 to know the various PIDs that make up the program. It would be difficult for a hacker to know that "Program 1" is "CNN", "Program 5" is "ΤΝΝ", and so on. This information is sent along with the SI. As mentioned earlier, the SI is disrupted and cannot be used by unauthorized set-top boxes. However, stubborn hackers may infer these by selecting individual channels and checking the content delivered. Therefore, in order to prevent the channel from being recognized, the layout of the programs in a single stream can be changed frequently. For example, in the above example, program 2 and program 5 are exchanged. Therefore, "program 1" is "TΝΝ", "Program 5" is "CNN". Also, it is possible to move a program to a completely different stream with a completely new program group. A typical digital cable data converter can transmit 250 programs including music. Each program can be tuned uniquely. The possible combination of reordering is 250! (factorial). Without the content mapping provided by the transmitted SI or the hacker, the user is faced with randomly selecting each program in the stream to check whether it is the one of interest.
[0114] Therefore, in the data converter 422, the video signal 404 and the audio signal 406 are provided in plaintext (unencrypted), and the SI428 is provided to multiple CA systems for transmission on the cable television network. Therefore, in the exemplary system 400, the plain text SI428 is provided to the encryption system 418, which encrypts the SI data with the encryption system A. At the same time, the plain text SI428 is provided to the encryption system 424, which uses the encryption system B to encrypt the SI data. Then, the plaintext video 404, audio 406, and PSI 429 are multiplexed with the encrypted SI (SIA) from 418 and the encrypted SI (SIB) from 424 to replace the out-of-band system information 428.
[0115] After being released through the cable television system 32, the video, audio, PSI, system information A, and system information B are all transmitted to the set-top boxes 36 and 436. At STB36, the encrypted SI is decrypted at CA system A40 to provide tuning information to the set-top box. The set-top box tunes out a specific program so that it can be displayed on the television 44. Similarly, at STB436, the encrypted SI is decrypted at CA system B440 to provide tuning information to the set-top box, so as to tune out a specific program and display it on the TV 444.
[0116] The advantage of this method is that in a content delivery system (such as a cable TV system), no additional A/V bandwidth is required. Only double transmission of SI is required. No special hardware is required. Most tuners can easily adapt to any frequency that deviates from the standard frequency. Software can be used for SI decryption, or hardware can be used to assist SI decryption. For example, a traditional Motorola set-top box can use a hardware decryptor built into the decoder IC chip to de-disturb the SI transmitted in Motorola's out-of-band mode.
[0117] A stubborn hacker may use a spectrum analyzer on the coaxial cable to understand where the A/V channel is located. Also, the hacker may program the set-top box to automatically scan the frequency band to understand the location of the A/V channel (this is a relatively
CN 1633809 Β
Slow process). If the frequency of the A/V channel changes dynamically, hackers can be prevented because they need to continuously analyze or scan the band. Furthermore, the program number and the assigned PID can also be changed. However, dynamically changing frequencies, program numbers, and PIDs may cause operational difficulties for service providers (such as cable TV operators).
[0118] General introduction
[0119] The system 500 of FIG. 10 can generally represent various of the aforementioned technologies. The system 500 has a front-end equipment 522 of a cable television system, the front-end equipment has a clear text video 504, a clear text audio 506, SI528 and PSI529, any of them can be selectively switched through a switch 518 controlled by an intelligent processor, The switch 518 is also used to assign the PID (in an embodiment that requires PID allocation or redistribution) to the conditional access system A520 or the conditional access system B524 or to transmit it to the cable television system 32 in a clear text. As mentioned above, the STB36 can correctly decode the programs or SI encrypted according to the traditional CA system A. As mentioned earlier, the information encrypted by CA system B is understood by STB536 and decrypted and decoded accordingly.
[0120] PID mapping considerations
[0121] When necessary, the above-mentioned PID mapping idea can be applied to the double partial encryption technology described herein as a whole. In wired front-end equipment, this general idea is to process a data stream composed of packets to copy the packets selected for encryption. These packets are copied and encrypted with two different encryption methods. The copied packets are assigned to independent PIDs (one of which matches the traditional CA PID for plaintext content) and reinserted in the data stream at the location of the originally selected packets for transmission in the cable television system. At the output end of the front-end equipment of the cable TV system, the packet stream that appears has traditional encrypted packets and plaintext packets with the same PID. The secondary PID identifies the packet encrypted with the new encryption system. In addition to the PID remapping performed at the front-end equipment, MPEG packets also use a continuous count to maintain the proper order of the packets. In order to ensure correct decoding, this continuous count should be properly maintained during the creation of the packetized data stream at the front-end equipment. This is achieved by ensuring that consecutive count values are sequentially assigned to packets with PIDs in the usual way. Therefore, a packet with a secondary PID will carry a continuous count independent of the primary PID. The following description is made in a simplified form, where PID025 is the primary PID, PID125 is the secondary PID, E is the encrypted packet, C is the plaintext packet, and the end number is the continuous count.
[0122]
<td>025C04</td><td>025E05</td><td>125E11</td><td>025C06</td><td>025C07</td><td>025C08</td><td>025C09</td><td>025E10</td><td>125E12</td>
[0123] In the exemplary segment of the above grouping, the groups with PID025 are considered to have their own consecutive counting order (04, 05, 06, 07, 08, 09,...). Similarly, packets with secondary PID125 also have their own continuous counting order (11, 12....).
[0124] At the STB, the PID can be processed in a variety of ways so that the encrypted packet with the secondary PID is correctly associated with the correct program. In one implementation form, the packet header of the input stream segment is as follows:
[0125]
<td colspan="2"></td><td>025C04</td><td>025E05</td><td>125E11</td><td>025C06</td><td>025C07</td><td>025C08</td><td>025C09</td><td>025E10</td><td>125E12</td>
<td>[0126][0127]</td><td colspan="7">Process the above header to create the following output stream fragment</td><td>:</td><td></td><td></td>
<td></td><td></td><td>125C04</td><td>025E11</td><td>125E05</td><td>125C06</td><td>125C07</td><td>125C08</td><td>125C09</td><td>025E12</td><td>125E10</td>
[0128] The primary PID (025) in the input stream is replaced by the secondary PID for the plaintext packet (C). To the encrypted packet
CN 1633809 Β
Say, keep the primary PID and secondary PID, but exchange consecutive counts. Therefore, in the absence of errors caused by continuity loss, the secondary PID can be used to correctly decrypt and decode the packet stream. Other PID processing methods and continuous counting, such as mapping the PID (125) on the scrambled traditional packet to NOP PID (all) or other undecoded PID values, can also be used in embodiments according to the present invention.
[0129] The primary and secondary PIDs are transmitted to the STBo in the program map table (PMT) transmitted as part of the program specific information (PSI) data stream. The STB running under CA encryption system A ("traditional" system) can be ignored The secondary PID exists, but the new STB running under CA encryption system B is programmed to recognize that the secondary PID is used to transmit the encrypted part of the program related to the primary PID. The set-top box is warned of the fact that this encryption scheme is used due to the presence of a CA descriptor in the basic PID of the "loop" used for PMT. Generally, there are CA descriptors used in the video basic PID "loop" and another CA descriptor in the audio basic PID "loop". The CA descriptor uses private data bytes to identify CA_PID as an ECM PID or as a secondary PID for partial scrambling, so that the STB running under system B can find the primary and secondary PIDs related to a single program. Since the PID field in the transmission header has a length of thirteen bits, there are 213 or 8192 PIDs available, and any excess PID can be used for the secondary PID as needed.
[0130] In addition to assigning PIDs to each program component or selected parts, a new PID can also be assigned to mark the ECM data used in the second encryption technique. Each assigned PID number can be marked as a user-defined stream type to prevent interference operation of traditional STB. MPEG defines this reserved block for the number of user-defined data stream types.
[0131] Although the PID mapping at the cable TV head-end equipment is conceptually a simple operation, in fact the cable TV head-end equipment is usually established, so it is necessary to comply with the established cable TV system with the least interference. Modify it in a cost-effective way to achieve this task. Therefore, the details of the actual implementation form in the front-end equipment of the cable TV system depend to some extent on the actual traditional hardware existing in the front-end equipment, and examples thereof will be described in detail below.
[0132] Implementation form of front-end equipment
[0133] Those skilled in the art should understand that the above descriptions related to FIGS. 2, 3, 6, 9 and 10 are somewhat conceptual in nature and are used to illustrate the overall ideas related to the various embodiments of the present invention. And concepts. When realizing the practical realization of the present invention, those skilled in the art should realize that the important practical problem they face is the cost-effectiveness of providing various partial encryption methods in the existing traditional front-end equipment of the existing cable TV suppliers. The form of realization. Taking two main traditional cable TV systems as examples, the following explains how to implement the above-mentioned technologies in cable TV front-end equipment.
[0134] First, consider the use of Motorola brand conditional access system cable TV system front-end equipment. In such a system, the modification shown in Figure 11 can be made to provide a cost-effective mechanism for partial double encryption implementations. In a typical Motorola system, HITS (Front End Equipment in the Air) or similar data feed is provided from the satellite. This feed can provide aggregated digital content, which is provided to cable TV providers and used by receivers such as Motorola Integrated Receiver Transponder (IRT) IRTIOOO and IRT2000 and Motorola Modular Processing System (MPS). /Descrambler/Scrambler system 604 received. The plaintext stream of digitized television data can be obtained from the satellite descrambler function block 606 of the receiver/descrambler/scrambler system 604. This plaintext stream can be processed by a new functional block shown as the packet selector/duplicator 610. The new function block 610 may be implemented as a programmed processor or implemented by hardware, software, or a combination thereof.
[0135] The packet selector/duplicator 610 selects the packets to be double-encrypted using any of the above-mentioned partial double-encryption methods.
CN 1633809 Β
group. These packets are then copied with the new PID so that they can be identified for encryption later. For example, if the packet associated with a particular program at the input of 610 has PID A, the packet selector/duplicator 610 will identify the packets to be encrypted and copy these packets and remap them to PIDs B and C, respectively, So that they can be identified in the two different systems for encryption. It is preferable that the copied packets are inserted into the data stream next to each other at the position of the original copied packets with PIDs B and C, so they will maintain the same order of the original presentation (except for the original resident in the data stream). Where there is one group, there are now two groups). For the time being, assume that the new CA system to be added is NDS encryption. In this case, PID A represents a plaintext packet, PID B represents an NDS encrypted packet, and PID C represents a Motorola encrypted packet. The packet with PID B can be encrypted with NDS encryption in 610 at this time or tt I can be added later.
[0136] The packets with PIDs B and C are then returned to the system 604. In this system, according to the instructions of the control system 614 related to Motorola equipment, the cable scrambler 612 uses Motorola encryption to encrypt the packets with PID C's packet is encrypted. Then, the output stream from the cable TV scrambler 612 goes to another new device, a PID remapper and scrambler 620, which receives the output stream from 612 and remaps the rest of the packets with PID A to PID C, and in the control system Under the control of 624, the PID B packet is encrypted with the NDS encryption algorithm. The output stream at 626 has clear text unencrypted packets with PID C and selected packets with PIDC (the selected packets have been copied and encrypted with Motorola encryption system) and NDS encrypted with PID B The system has been encrypted grouping. This stream is then modulated at 628 (for example, quadrature amplitude modulation and RF modulation) for distribution on the cable television system. The above preferred embodiment maps the unencrypted packets to PID A to match the scrambled packets on PID C, because in this way the audio and video PIDs taken out in the traditional program specific information (PSI) are correct. Control computer, scrambler and traditional set-top box only know PID Co or, the scrambled packet on PID C can be mapped back to PID A, but this may mean editing the automatically generated PSI to map the PID number from PID C back to PID Ao in the PID remapper and scrambler 620
[0137] In the above example, the PID remapper and scrambler 620 can also be used to demultiplex the PSI information, modify it to reflect the addition of NDS encryption (by using the CA descriptor in the PMT), and modify it. The subsequent PSI information is multiplexed back into the data stream. An ECM supporting NDS encryption can also be inserted into the data stream at the PID remapper and scrambler 620 (or can be inserted by the packet selector/duplicator 610).
[0138] Therefore, in order to add NDS encryption (or another encryption system) to the front-end equipment of a cable TV system using Motorola equipment, the packet must be copied and the PID remapped by PIDo remapped in the data stream from the satellite descrambler and then used In order to identify the grouping to be disturbed by each CA system. Once the traditional system encryption is performed, the plaintext PID is remapped, so that the plaintext and encrypted packets in the traditional system share the same PIDo. It can be programmed with a processor or with a combination such as an application specific integrated circuit or a programmable logic device or a field programmable gate array. A class of custom or semi-custom integrated circuits to achieve PID remapping as in 620 and packet selection and copying as in 610. Without departing from the present invention, there may be other implementation forms.
[0139] FIG. 12 illustrates a similar device configuration such as that used when implementing partial double encryption of the present invention in a cable head-end device based on Scientific Atlanta. In this embodiment, an HTITS feed or similar feed is received at IRD704, which includes satellite descrambler 706. It can be a Motorola IRT or an MPS with only a satellite descrambler function. The output of the satellite descrambler 706 also provides a plaintext data stream, which can be processed by the new packet selector/duplicator 710. The new packet selector/duplicator 710 can select the packets to be encrypted, copy them, and copy the packets The PID is mapped to the new PID. Similarly, for example, assign PID A to the group reserved in plain text, and use the new system
CN 1633809 Β
Packets encrypted by the system (such as NDS) are allocated with PID B, and packets encrypted with the Scientific Atlanta encryption system are allocated with PID Co. Packets with PID B can be encrypted with the NDS encryption system at this time.
[0140] The packet stream is then sent to the multiplexer 712 (for example, Scientific Atlanta multiplexer), where it is used at 714 under the control of the control system 718 associated with the multiplexer 712. The Scientific Atlanta encryption system encrypts packets with PID C. Then, the data stream is provided to the QAM modulator 720 inside the multiplexer 712. In order to correctly remap the packet, the QAM modulated signal at the output of the multiplexer 712 is provided to the new processor system 724, in which the QAM modulated signal at the QAM demodulator 730 The signal is demodulated, and the plaintext PID A packet is remapped to the PID Co at the PID remapper 734 controlled by the control system 738. It is also possible to implement encryption with the NDS encryption algorithm here instead of in 710. Then, QAM and RF modulation are performed on the remapped PID and the double partially encrypted data stream at 742 for distribution on the cable television system.
[0141] In the above example, the PID remapper and scrambler 734 can also be used to demultiplex the PSI information, modify it to reflect the addition of NDS encryption (add CA descriptor to the PMT) and change the modified PSI The information is multiplexed back into the data stream. An ECM supporting NDS encryption can also be inserted into the data stream at the PID remapper and scrambler 734 (or can be inserted by the packet selector/duplicator 710). Programmable processors or custom or semi-custom integrated circuits such as application specific integrated circuits or programmable logic devices or field programmable gate arrays can be used to implement PID remapping and/or scrambling as in 734 and respectively as in QAM demodulation and QAM modulation in 730 and 724, and packet selection and copying as in 710. There may be other implementation forms without departing from the present invention.
[0142] The above-mentioned embodiments of the present invention enable the conventional scrambling device to scramble only the desired packets in the elementary stream instead of the entire elementary stream. The PID numbers of packets that are not intended to be scrambled (for example, PID A) can be used to scramble specific packets of the elementary stream. Place the packet to be disturbed on PID C. The disturbing device will disturb the packet on PID C (the packet that has been selected to be disturbed). After being scrambled, the unscrambled packet has a PID number that is mapped to the same PID number as the scrambled packet-PID A becomes PID C. Traditional set-top boxes will receive elementary streams with scrambled and undisturbed packets.
[0143] The packets in these embodiments are processed in the form of streams. The entire stream is sent to the traditional scrambling device for scrambling. This will keep all packets in a precise time synchronization sequence. If the packet is extracted from the stream and sent to a traditional jamming device, time jitter may be introduced. This embodiment avoids this problem by keeping all packets in the stream. This embodiment does not require cooperation from vendors of traditional scrambling equipment, because the device does not involve remapping packets from PID A to PID Co. This remapping is preferred because the PID extracted from the PSI generated by the traditional scrambling system No need to change. The traditional system knows PID C, but does not know that PID Ao can find all the elementary streams to be disturbed by the traditional disturbing equipment in a single PID± that the disturbing system has instructed to disturb it.
[0144] In the above example, the use of NDS as the second encryption system should not be seen as restrictive. Moreover, although the two widely used systems Motorola and Scientific Atlanta are illustrated by way of example, similar modifications to the traditional system can also be used to allow PID remapping and double partial encryption. Generally speaking, the above-mentioned technique involves the overall process as described in 800 in FIG. 13. A feed is received at 806, which is descrambled when received at 810, resulting in a packetized plaintext data stream. At 814, a packet is selected according to the desired partial double encryption technique (for example, only audio encryption, encryption of the packet containing the PES header, etc.). At 818, the selected group is copied, and each copy pair is remapped to two new PIDs (for example, PID B and PID C). Then, at 822, the copied packet is encrypted according to PID (that is, PID C is encrypted according to traditional encryption, and PID C is encrypted according to the new encryption system.
CN 1633809 Β
Β to encrypt). Then at 826, the plaintext packet (eg PID A) is remapped to the same PID as the traditional encrypted PID (PID C).
[0145] The order in which certain units of the process of FIG. 13 are executed may vary depending on the specific conventional system that is modified to adapt to the specific double encryption arrangement used. For example, the new encryption system can be used for encryption during copying or later when remapping traditional packets, as shown in Figures 11 and 12. In addition, a variety of demodulation and remodulation operations can be performed as needed to adapt to the existing specific traditional system (not shown in Figure 13).
[0146] Implementation form of set-top box
[0147] There may be several set-top box implementation forms within the scope of the present invention. The method used in the front-end equipment to select packets for encryption has nothing to do with STB.
[0148] FIG. 14 illustrates one such implementation form. In this embodiment, the packet from the tuner and demodulator 904 is provided to the demultiplexer 910 of the decoder circuit 908. The packets are cached in the memory 912 (for example, using a unified memory architecture) and processed by the main CPU 916 of the STB with software stored in the ROM memory 920.
[0149] The selected PID can be stripped from the input transmission through the PID filter of the STB, decrypted and cached into the synchronous dynamic random access memory (SDRAM), which is the same as the personal video recorder (PVR) application in preparation for transmission The initial processing required for the hard disk drive (HDD) is similar. Then, the main CPU 916 can "manually" filter the data cached in the SDRAM in order to eliminate packets containing unwanted PIDs. This process has some obvious side effects.
[0150] The host overhead is estimated to be about 1% of the CPU bandwidth. In the worst case, for a 15Mbit/s video stream, this is equivalent to 40K bytes/sec. This reduction is possible because only 4 bytes at most are evaluated for each packet, and its position is at the 188-byte interval, so there is no need to consider the centered data. Therefore, each packet header in the SDRAM can be directly accessed through simple memory pointer processing. In addition, packets are cached in blocks and evaluated together to reduce task switching of the host. This will eliminate interference with other tasks when each new packet is received. When the channel changes, this may result in an increased waiting time to start decoding the stream to allow time to fill the cache. This can be ignored according to the allocated SDRAM cache buffer size.
[0151] Then, the packet filtered by the host in the SDRAM cache is transferred to the A/V queue through an existing hardware DMA for processing and simulating the implementation of the PVR. The filtered packets are then provided to the decoder 922 for decoding. [0152] FIG. 15 illustrates the second technology implemented in the set-top box. Since the A/V decoder module 934 of the RISC processor in the decoder circuit 930 processes part of the transmission PID and strips/connects for decoding, the firmware in the decoder IC930 can be changed to exclude according to the standard in each packet header Part of the individual packets within the transport stream. Alternatively, the demultiplexer 910 can be designed to exclude said packets. The traditionally scrambled packets are still encrypted after passing through the CA module. Use the decoder IC930 to perform the removal of traditionally disturbed packets and assume that the packets encrypted with the new encryption algorithm (such as NDS) are directly adjacent to the traditionally encrypted packets (or at least before the next mainstream video packet), so the removal of traditional packets is actually completed In order to merge a single plaintext stream into the header area and the video queue.
[0153] FIG. 16 illustrates a third technique used to implement partial encryption in a set-top box. In this embodiment, a circuit such as an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or a programmable logic device (PLD) 938 is placed in the tuner and demodulator 904 and decoder PID remapping in other custom-designed circuits between IC908. In a variation of this embodiment, the decoder IC 908 can be modified to implement PID remapping in the demultiplexer 940. In both cases, the traditionally encrypted packets are discarded, and the non-traditional packets are remapped in circuit 938 or demultiplexer 940.
[0154] In one embodiment, the PLD shown in FIG. 17 may be used to implement the third technique described above. This form of realization assumes
CN 1633809 Β
There is no more than one encrypted packet of a specific PID that appears continuously. Therefore, this implementation form can be modified to adapt to, for example, the packet string encrypted by the above-mentioned M and Nth encryption arrangements (which will be described later). The input stream passes through the PID recognizer 950, which is used to demultiplex the input stream according to the PID. In 958, the main PID packet continuity is checked. If a continuity error is detected, the error is noted and the count is reset at 960.
[0155] The original input packet stream contains packets tagged with multiple PIDs. The PID identifier 950 separates the packet with the two PIDs of interest (primary and secondary PID) from all other packets. This capability can be extended to handle multiple PID pairs. Other packets are routed directly to the modified output stream. This process can cause clock delays of three or four bytes.
[0156] The PID recognizer 950 routes the packet with the secondary PID to the continuous count checker 945, which verifies the sequence integrity of the PID. Any errors are noted at 956, but the special handling of errors has nothing to do with the understanding of the present invention. The consecutive values of the group are reserved for use when checking the order of subsequent groups. Use an independent master count to perform a corresponding continuity check 958 for the packets with the master PID, and record any errors at 960 as well.
[0157] Check the secondary flag of the secondary packet at 962. Use this boolean indicator to remember whether a sub-packet has been processed since the last plaintext packet. More than one sub-packet between the plaintext packets is an error in this embodiment, and is marked at 964. Remember the existence of the secondary group by setting the secondary flag at 966.
[0158] The consecutive count of sub-packets is changed at 968 to accommodate the plaintext packet sequence. The data used for this replacement comes from the value used to check the continuity of the mainstream at 958. The modified packet is sent from 968 and merged into the modified stream that constitutes the output stream.
[0159] After the continuity check of the packets with the main PID at 958, they are distinguished by the scramble flag in the header at 970. If it is a scrambled packet, the main flag is queried at 974. The main flag Boolean indicator is used to remember whether the encrypted main packet has been processed since the last plaintext packet. More than one primary encrypted packet between the plaintext packets is an error in this embodiment, and it is marked at 976 before the packet is discarded at 978. The existence of the encrypted main packet is remembered by setting the main flag at 980. If there are no downstream consumers for the encrypted main packet, it can be discarded at 978. In some cases, the packet may have to continue (in this case, its consecutive count may use the discarded second consecutive value).
[0160] If the primary PID scramble test at 970 detects a plaintext packet, then at 984 the status of the primary and secondary flags are tested. The valid condition is that neither is set at the same time and both are set at the same time, because the encrypted packet should appear in a matching pair. A sequence with only one and no other should be marked as an error at 988. However, in this embodiment, the order of appearance is irrelevant. It should be noted that in addition to the scramble bit (for example, transport_priority) bit in the transport header, there may be other ways to mark the main packet to be deleted. In addition, it is not necessary to use any bit, such as simple position information of the primary packet before or after the secondary packet, as an indicator for replacement.
[0161] Before being output in the modified output stream, the PID value of the plaintext packet with the primary PID is changed to the secondary PID at 922. Alternatively, the secondary PID packet can be remapped to the primary PID value. The content can be decoded when the correct PID (primary or secondary PID) is provided to the decoder to decode the insider. The existence of plaintext grouping will also clear the primary and secondary Boolean flags.
[0162] In all the proposed embodiments, even when a series of primary packets are marked for replacement, secondary packets can still be inserted at positions adjacent to the primary packets to be replaced. However, in some cases, if multiple encrypted packets can be inserted into the stream without a centered packet, it may facilitate partial disruption of the front-end equipment. In order to adapt to multiple consecutive encrypted packets (such as the same as the M and N part encryption methods), the count matching test function can be used instead of using the main and auxiliary flags. Therefore, instead of the units 962, 964, and 966, the count of sub-encrypted packets can be increased. Replace unit 970,974,
CN 1633809 Β
976 and 980, can increase the main encryption packet count. The unit 984 can be replaced by comparing the primary and secondary encrypted packet counts to ensure that the same number of encrypted packets are received on the primary and secondary paths. Instead of clearing the flag at 992, the count can be cleared. With this variation, multiple encrypted packets can be received continuously, and the received numbers can be compared in order to monitor the integrity of the data stream. Those skilled in the art will think of other variations.
[0163] The functions described above in conjunction with FIG. 17 can be integrated into an A/V decoder chip whose functions are similar to the commercially available Broadcom series 70xx or 71xx decoders used in commercial set-top boxes. Figure 18 illustrates a block diagram for such a decoder chip, in which the functions already provided in the commercial chip are basically unchanged. Generally speaking, commercial decoder chips expect a one-to-one correspondence between PID and program components (such as audio or video).
[0164] The decoder described in FIG. 18 can be connected to the STB central processing unit to allow multiple PIDs to be programmed into the decoder, so that it can be used for main audio, main video and picture-in-picture (PiP) functions. Secondary video processing primary and secondary PID. In this embodiment, the original data stream is received by the packet classifier 1002, which can provide the function of demultiplexing the packet stream based on PID similar to that described above in conjunction with FIG. 17. Preferably, the decoder of FIG. 18 uses hard-wired logic circuits instead of programmed software to implement the PID classification function of 1002. For example, the program guide and stream navigation information are output for use by the main processor of the STB. The packets related to the main audio program are buffered in FIF01006, decrypted in the decryptor 1010, and then buffered at 1014 for the MPEG audio decoder 1018 to obtain when needed. Subsequently, the decoded MPEG audio is provided as an output from the decoder.
[0165] In a similar manner, packets related to the main video program are cached in FIF01024, decrypted in the decryptor 1028, and then cached at 1032 for the MPEG video decoder 1036 to obtain when needed. Then, the decoded MPEG video for the main channel is provided to the synthesizer 1040, and thereafter provided as an output from the decoder. Similarly, packets associated with the PIP video is buffered within FIF01044, decrypted in a decrypter 1048 and then buffered in 1052, in order for the MPEG video decoder 1056 acquires when needed. The decoded MPEG video for the picture-in-picture channel is then provided to the synthesizer 1040, where the above-mentioned video is combined with the main channel video, and thereafter provided as a decoded video output from the decoder. Discard other packets that are not related to the main channel or the picture-in-picture channel. Of course, without departing from the embodiments of the present invention, other functions may also be included in or deleted from the decoder chip.
[0166] Conclusion
[0167] As mentioned above, in order to prevent the persistent threat of hackers, several of the above partial encryption arrangements can be combined to further enhance security. For example, key packet encryption can be used in any combination with SI encryption, M and N, random encryption, time slicing, and other technologies to further enhance security. In one embodiment, as many packets as possible can be encrypted within the available bandwidth. The amount of encryption may depend on whether the content is a regular program or paid content (such as paid viewing or VOD), whether it is an adult program or a regular movie, and the level of security that different cable operators are satisfied with. Those skilled in the art should understand that, without departing from the present invention, there can be many other combinations to further enhance the security of encryption.
[0168] The present invention has been described in the above-mentioned multiple embodiments of the digital A/V system using MPEG2 encoding. Therefore, the multiple packet names and protocols specified are related to MPEG2 encoding and decoding. However, those skilled in the art should realize that the ideas disclosed and claimed in this article should not be regarded as restrictive. The same or similar technology can be used in any digital cable television system without being limited to the MPEG2 protocol. Moreover, the technology of the present invention can be used in any other appropriate content delivery occasions, including (but not limited to) terrestrial broadcast-based content delivery systems, Internet-based content delivery, such as, for example, the Digital Satellite Service (DSS) used in the DirecTVTM system. ) Satellite-based content delivery systems and packet media (such as CDs and DVDs). These multiple alternatives are considered in this document as
CN 1633809 Β
Equivalently, the exemplary MPEG2 cable television embodiment should be regarded as an illustrative exemplary embodiment.
[0169] In addition, the present invention has been described in terms of using a TV set-top box to decode partially encrypted TV programs. However, this decoding mechanism can also be implemented in a TV receiver that does not require STB or in a music player such as an MP3 player. These embodiments are considered equivalent.
[0170] Furthermore, although the present invention has been described in terms of using the above encryption technology to provide a double partial encryption mechanism for TV programs, these partial encryption technologies can also be used as a single encryption technology or used in more than two encryption technologies. Multi-encryption under the encryption system without limitation. More than two types of encryption systems can be used for the additional copy packets to be encrypted. Alternatively, the encryption key used to copy one of the packets may be shared among multiple encryption systems. Furthermore, although only the encryption of TV programs is specifically disclosed, the present invention can also be used for single or double encryption of other content, including (but not limited to) content downloaded from the Internet or other networks, and music content. , Packet media content and other types of information content. Without departing from the present invention, this content can be played on a variety of playback devices, including (but not limited to) personal digital assistants (PDAs), personal computers, personal music players, audio systems, audio /Video system and so on.
[0171] Those skilled in the art should recognize that the present invention has been described in terms of exemplary embodiments that can be implemented with a programmed processor. However, the present invention should not be so limited, because the present invention can be implemented by hardware equivalent components such as dedicated hardware and/or a dedicated processor equivalent to the described and claimed invention. Similarly, general-purpose computers, microprocessor-based computers, microcontrollers, optical computers, analog computers, dedicated processors, and/or dedicated hard-wired logic can be used to construct alternative equivalent embodiments of the present invention.
[0172] Those skilled in the art should recognize that, without departing from the present invention, the program steps and related data used to implement the above-mentioned embodiments can be used with disk memory and, for example, read only memory (ROM), random access memory (RAM) devices, optical memory elements, magnetic memory elements, magneto-optical memory elements, flash memory, magnetic core memory and other forms of memory and/or other equivalent storage technologies. These alternative forms of memory devices can be considered equivalent.
[0173] The present invention, as described in the embodiments herein, can be implemented by a programming processor that executes programming instructions, which are outlined in the above flowchart and can be stored on any appropriate electronic storage medium or in Transmission on any appropriate electronic communication medium. However, those skilled in the art should realize that without departing from the present invention, the above-mentioned processing can be implemented in a variety of variations and a variety of appropriate programming languages. For example, the order of certain operations performed is usually variable, and additional operations or deletion operations can be added without departing from the present invention. Error capture can be increased and/or enhanced, and the user interface and information presentation mode can be changed without departing from the present invention. These variations are considered equivalent.
[0174] Although the present invention has been described with specific embodiments, it is obvious that those skilled in the art can see various substitutions, improvements, alterations and changes from the above description. Therefore, the present invention intends to include all these substitutions, improvements and changes falling within the scope of the appended claims.
23 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17 Sheet 18 Sheet 19 Sheet 20 Sheet 21 Sheet 22 Sheet 23
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US6229895B1 | Cites | United States of America | Search report |
| US5915018A | Cites | United States of America | Search report |
369 members in 12 offices
Priority claims14
| Document | Office | Kind | Date |
|---|---|---|---|
| 10037914 | United States of America | – | |
| 3791402 | United States of America | A | |
| 3791402 | United States of America | A | |
| 2405865 | Canada | – | |
| 2405865 | Canada | A | |
| 2405865 | Canada | A | |
| 0240051 | United States of America | W | |
| 0240051 | United States of America | W | |
| 10037914 | – | – | – |
| 2405865 | – | – | – |
| CA20022405865 | – | – | – |
| PCTUS2002040051 | – | – | – |
| US20020037914 | – | – | – |
| WO2002US40051 | – | – | – |
Members369
| Document | Office | Kind | |
|---|---|---|---|
| WO0059222A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU3505700A | Australia | A | |
| KR20010110715A | Republic of Korea | A | |
| EP1163798A1 | European Patent Office (EPO) | A1 | |
| CN1353909A | China | A | |
| JP2002540736A | Japan | A | |
| US6490081B1 | United States of America | B1 | |
| US2002194613A1 | United States of America | A1 | |
| US2002196939A1 | United States of America | A1 | |
| US2003021412A1 | United States of America | A1 | |
| US2003026423A1 | United States of America | A1 | |
| US2003046686A1 | United States of America | A1 | |
| CA2405865A1 | Canada | A1 | |
| CA2405899A1 | Canada | A1 | |
| CA2405901A1 | Canada | A1 | |
| CA2405902A1 | Canada | A1 | |
| CA2406329A1 | Canada | A1 | |
| US2003081776A1 | United States of America | A1 | |
| US2003086154A1 | United States of America | A1 | |
| US2003112499A1 | United States of America | A1 | |
| CA2413807A1 | Canada | A1 | |
| CA2413880A1 | Canada | A1 | |
| CA2413881A1 | Canada | A1 | |
| CA2413905A1 | Canada | A1 | |
| CA2413955A1 | Canada | A1 | |
| CA2413980A1 | Canada | A1 | |
| CA2709393A1 | Canada | A1 | |
| CA2709394A1 | Canada | A1 | |
| CA2746401A1 | Canada | A1 | |
| CA2746510A1 | Canada | A1 | |
| CA2746621A1 | Canada | A1 | |
| CA2746625A1 | Canada | A1 | |
| CA2746782A1 | Canada | A1 | |
| CA2748412A1 | Canada | A1 | |
| CA2748417A1 | Canada | A1 | |
| CA2748539A1 | Canada | A1 | |
| US2003123664A1 | United States of America | A1 | |
| US2003133570A1 | United States of America | A1 | |
| WO03059039A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO03061173A2 | World Intellectual Property Organization (WIPO) | A2 | |
| WO03061288A1 | World Intellectual Property Organization (WIPO) | A1 | |
| WO03061289A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2002357213A1 | Australia | A1 | |
| AU2002357846A1 | Australia | A1 | |
| AU2002357846A8 | Australia | A8 | |
| AU2002360604A1 | Australia | A1 | |
| AU2002360605A1 | Australia | A1 | |
| AU2002360605A8 | Australia | A8 | |
| US2003145329A1 | United States of America | A1 | |
| WO03065724A1 | World Intellectual Property Organization (WIPO) | A1 | |
| US2003152224A1 | United States of America | A1 | |
| US2003152226A1 | United States of America | A1 | |
| US2003156718A1 | United States of America | A1 | |
| US2003159139A1 | United States of America | A1 | |
| US2003159140A1 | United States of America | A1 | |
| US2003174837A1 | United States of America | A1 | |
| US2003174844A1 | United States of America | A1 | |
| CA2480964A1 | Canada | A1 | |
| WO03090401A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU2003234690A1 | Australia | A1 | |
| WO03059039A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US6697489B1 | United States of America | B1 | |
| CA2437014A1 | Canada | A1 | |
| CA2437018A1 | Canada | A1 | |
| CA2437025A1 | Canada | A1 | |
| CA2437086A1 | Canada | A1 | |
| US2004047470A1 | United States of America | A1 | |
| US2004049688A1 | United States of America | A1 | |
| US2004049690A1 | United States of America | A1 | |
| US2004049691A1 | United States of America | A1 | |
| US2004049694A1 | United States of America | A1 | |
| CA2498326A1 | Canada | A1 | |
| WO2004023717A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003268468A1 | Australia | A1 | |
| US6721093B2 | United States of America | B2 | |
| US2004073917A1 | United States of America | A1 | |
| CA2498346A1 | Canada | A1 | |
| WO2004036892A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003296903A1 | Australia | A1 | |
| AU2003296903A8 | Australia | A8 | |
| EP1163798B1 | European Patent Office (EPO) | B1 | |
| AT268973T | Austria | T | |
| ATE268973T1 | Austria | T1 | |
| DE60011405D1 | Germany | D1 | |
| KR20040068994A | Republic of Korea | A | |
| KR20040069353A | Republic of Korea | A | |
| US2004151314A1 | United States of America | A1 | |
| KR20040070296A | Republic of Korea | A | |
| KR20040070299A | Republic of Korea | A | |
| KR20040070300A | Republic of Korea | A | |
| US2004158721A1 | United States of America | A1 | |
| US6781750B2 | United States of America | B2 | |
| US2004181666A1 | United States of America | A1 | |
| WO03061173A3 | World Intellectual Property Organization (WIPO) | A3 | |
| WO2004082147A2 | World Intellectual Property Organization (WIPO) | A2 | |
| MXPA04006248A | Mexico | A | |
| MXPA04006249A | Mexico | A | |
| EP1461950A1 | European Patent Office (EPO) | A1 | |
| EP1461952A1 | European Patent Office (EPO) | A1 | |
| MXPA04006400A | Mexico | A |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Expiry of patent termCX01 | CX01 | |
| Grant of patent or utility modelGrantedC14 | C14 | |
| Entry into substantive examinationC10 | C10 | |
| PublicationC06 | C06 |
Numbers
- Publication
- 1633809
- Publication, DOCDB
- 1633809
- Publication, EPODOC
- CN1633809B
- Application
- 28284526
- Application, DOCDB
- 02828452
- Application, EPODOC
- CN2002828452
Titles2
- Chinese
- 基本流部分加密
- English
- Elementary stream partial encryption
Classification
- CPC, 10
- H04N21/44055
- H04N21/2347
- H04N7/1675
- H04N21/23476
- H04N21/2362
- H04N21/26606
- H04N21/4345
- H04N21/4623
- H04N21/835
- H04N7/10
- IPC, 9
- H04N7 167
- H04L9 18
- H04N21 2347
- H04N21 2362
- H04N21 266
- H04N21 434
- H04N21 4405
- H04N21 4623
- H04N21 835