Conditional access system using messages with multiple encryption keys
13 claims: 6 independent, 7 dependent
- 1Message (MEC) for providing access conditions ( 15 ) On a by a control word (CW i ) scrambled Program, characterized That the message (MEC) includes:n items (A1, ..., An), which the different by n Encryption key K1, K2, ..., Kj, ..., Kn encrypted Control word (CW i ) Include, and n additional Elements (DX1, ..., dxj, ..., DXn), each one of the one n encryption keys Kj (J = 1, 2, ..., n) associated with the key index I (Kj) which in which n is an integer greater than 1.
- 4A method for descrambling a by a control word (CW i ) Scrambled program, characterized in that that the method comprises the steps of:Provide a message (MEC), which a user assigned access conditions, n elements represented by n different encryption keys K1, K2, ..., Kj, ..., Kn encrypted Control word (CW i ) Include, and additional n Elements (DX1, ..., dxj, DXn), each comprising a one of said n encryption keys Kj (J = 1, 2, ..., n) associated with the key index I (Kj) comprise comprises, in which n is an integer greater than 1;wherein the method further comprises the step of selecting a of n elements depending from one of the in a receiver includes the message stored encryption key, wherein the selecting step is made using a key index, of the with the encryption key in the receiver the message is stored.
- 6Smart card for providing a control word (CW i ) For descrambling a received scrambled been program, said program scrambled by the control word is characterized in that the chip card comprises:medium for receiving a first message (MEC), wherein the first message a user assigned access conditions corresponding data, n elements represented by n different encryption keys K1, K2, ..., Kj, ..., Kn encrypted control word include, and n additional Elements (DX1, ..., dxj, DXn), each comprising a one of said n encryption keys Kj (J = 1, 2, ..., n) associated with the key index I (Kj) comprise comprises, wherein n is an integer greater than 1, and Medium ( 24 ) For decrypting said control word, in which decryption means at least one of the encryption key (Kj) and the associated key index include.
- 8Chip card 6 or 7, characterized by one of the claims, that it further comprises:Means for receiving a second Message (MD), wherein the second message comprises data users the assigned permissions correspond;Medium ( 20 ) for validating said second message using a control key (KC);in which the control key (KC) of the validation key (Q) is different for validating said first message.
- 10system for conditional access for selectively providing programs for User, the system comprising:Means for providing one by a control word (CW i ), by Data, which are associated with the permissions of the user, and by additional data that access conditions are associated scrambled program;a Decoder for descrambling the scrambled program;a Smart card for receiving the authorization data and access condition data and for providing said control word to the decoder, thereby in that the Access condition data in a message (MEC) according to a of claims carries 1 to 3 to the smart card be and the chip card a card according to one of claims 6 to 9.
- 13Off-line information medium comprising:on Program by a string of N control words CW 1 , ..., CW i , ..., CW N scrambled , where N is an integer greater than 1;and a lot of messages in accordance with one of the at ?page 10? claims 1 to . 3
Independent claims6
105 paragraphs, as filed
The The present invention relates to a system for conditional Access.
On system for allows conditional access, that a service provider acquired his services only to users with permissions these services provide. This is z. B. in pay-TV systems the case.
the document <patcit><text>EP 0679029 A1</text></patcit> discloses an example of such a system for conditional Access.
As the skilled person is well known in the art, consists of by a service provider service provided by an element which is scrambled by control words. The scrambled Element can only regard this user permissions associated descrambles and thus be read by the user. The scrambled item is referred to as IE (ECG), where ECG the unscrambled item represents.
Around to descramble the item, provides the service provider for each user the control words ready for scrambling the the element served. To keep the control words secret, will they provided after using an algorithm with a key encrypts K have been. The various encrypted control words sent to the various users in messages in the following description referred to for convenience with MEC will.
Around only entitle users to grant access to its services, provides the service provider for each user a smart card and a decoder ready.
The allows smart card on the one hand, the permissions of the user for which it was provided has to be validated, and recorded and on the other hand, the encrypted control words to decipher. For this purpose, the smart card includes the key K of the algorithm encryption the control words enabled.
on the other hand allows the decoder for its part, the scrambled item on the basis of from the decrypted control words descramble existing from the smart card element.
The Permissions of each user are sent in messages referred to in the following description for convenience with MD will.
According to the state art includes a message MD, which is provided for a user, three Main elements: <ul><li>- A first element which gives the card address of the user;</li><li>- on second element describing the permissions of the user gives;</li><li>- on the third element, which enables to validate the message MD and allows to verify that the authorizations contained in the message MD the user actually for the User privileges are reserved.</li></ul>
As previously mentioned was, the encrypted control words transmitted by means of the messages MEC to users.
According to the state art, a message MEC of a header and of a main part: <ul><li>- The header are u. a. the type and size of the in the body of the message MEC contained elements;</li><li>- of the Main part consists inter alia of a member having a set of conditions for the includes access to the service provided by the supplier; from an element comprising a control word with the algorithm with the key encrypts K , and of an element, comprising a data unit, of the key K dependent and the content of the message MEC and, in particular in the message allows to validate MEC access conditions contained and check.</li></ul>
If the decoder of a user among the different by the service provider distributed addresses recognizes the address of its associated card, the message MD corresponding to the recognized address is analyzed. The Message MD analysis using an analysis algorithm executed by the encryption key of control words is controlled.
systems for conditional Access are mainly of two types.
On first system is usually an online system called. In a conditional access system of the "on-line type" is the scrambled item IE (ECG) is an item consisting of a signal of a single source simultaneously to the various customers of the service provider is distributed. This distribution can eg. As by air or practiced wired will. As is known to those skilled in the art, the News MEC in such a conditional access system by the Service Provider with a scrambled Element IE (ECG) sent.
On second system conditional access <?page 3?>is usually an offline system called. In a conditional access system from the "Offline" type are the scrambled item IE (ECG) and the messages MEC on off-line information media such as z. B. Compact Discs, digital video discs or other digital optical disks contain.
The Invention will be described in more detail in the case of off-line systems. How later apparent, the invention but refers to any type of Access control system, whether this system from offline or the online type is.
As previously mentioned was, the key is the encryption algorithm for the control words contained in each user card. It follows that the theft of a single card to knowledge of the key K can lead.
thereupon is provided by the seller service is no longer protected.
Of the Service provider must then for each user to provide a new card that includes a new key K. In the case of off-line systems now has the off-line information medium z. B. by the compact disc, the Digital Video Disc or by other digital optical disc is formed, a solid content, the not changed can be. Continuity ensure the service that he has to provide, is the Service Provider then forced not only new off-line information media distribute, reverse compatible with the new encryption key are, but also the existing pool of off-line information media, he before the change the encryption key of control words has distributed, fully to renew.
There the number of off-line information media often several hundred thousand or even can reach several millions, this is particularly in terms of cost a disadvantage.
The Invention does not have this disadvantage.
General the present invention relates to a novel system for conditional Access.
More accurate The invention also refers to a new definition of News MEC, a new user card and in the case of off-line systems a new off-line information medium.
Thus the invention relates to a message (MEC) according to claim 1.
Also refers the invention relates to a method for descrambling a by a control word scrambled Program in accordance with claim . 4
Also refers the invention relates to a chip card according to claim sixth
In the dependent claims are specific embodiments the invention set forth.
Of the key the encryption algorithm for the control words contained in each user card.
If the theft of user cards to the attention of the key of encryption algorithm for the control words leads, change the service provider according to the invention the key and the key index, contained in the user cards by one of the keys and he the key indices which are already contained in the messages MEC, a new encryption algorithm key and a new key index chooses.
in the The case of off-line systems is an advantage of the invention, for. Example, that is prevented that the change the encryption algorithm key for the control words Renewal of the entire pool of distributed before the change of the key Off-line information media conditionally.
More Features and advantages of the invention will become apparent while reading a preferred embodiment, forth, the accompanying reference to the Figures will be given in which:
<figref idrefs="S30">1</figref> on Format of a message MEC according to the state is art;
<figref idrefs="S31">2</figref> the Block diagram of a user card according to the prior art; Fig
<figref idrefs="S32">3a</figref> and <figref idrefs="S33">3b</figref> two Formats a message MEC according to the invention represent;
<figref idrefs="S34">4</figref> the Block diagram of a user card represents that with a message MEC under <figref idrefs="S32">3a</figref> is working;
<figref idrefs="S35">5</figref> the Block diagram of a user card represents that with a message MEC under <figref idrefs="S33">3b</figref> is working.
The same reference numerals in all figures, the same Elements.
<figref idrefs="S30">1</figref> provides a format of a message MEC according to the prior art.
The Message MEC consists of a main part C1 and a header <figref>6</figref>. its contents (H1) such as the type and size of the main part in the C1 Elements contained there.
<?page 4?>
Of the Main section C1 includes, inter alia, a first element <figref>1</figref>, its Content (ID) allows to identify the service provider, a second member <figref>2</figref>That the amount of access conditions includes that associated with the service provided by the supplier are a third element <figref>3</figref>Whose content (I (K)) the index the key K of the encryption algorithm for the control words are, a fourth element <figref>4</figref>Comprising a control word Cwi, that with the algorithm with key K (E (Cwi) K) encrypted , and a fifth element <figref>5</figref>That a datum HASH<sub>K</sub> includes, the content of the message MEC and, in particular in the message allows to validate MEC access conditions contained and check. The datum HASH<sub>K</sub> is the key to K encoding the control words controlled.
In <figref idrefs="S30">1</figref> represents the control word Cwi the current control word, ie one which the part of the program that is read, allows to descramble. As the skilled artisan is well-known in the art comprises the message includes MEC that Cwi, generally also a second control word. This second control word is the control word for the next descrambling period, ie the current control word of the message MEC which the message MEC will follow, including the Cwi as instantaneous control word. Around the drawings are not unnecessarily to load, this second check word is in <figref idrefs="S30">1</figref> not shown.
As the person skilled in the art is known which is in <figref idrefs="S30">1</figref> described Message Format MEC merely an MEC message format example. In particular, the order in which the sequence of the various blocks <figref>1</figref>. <figref>2</figref>. <figref>3</figref>. <figref>4</figref>. <figref>5</figref> defined from where the message MEC consists, be changed.
<figref idrefs="S31">2</figref> provides the block diagram of a user card according to the prior art.
The user card <figref>7</figref> includes five Main circuits: <ul><li>- A circuit <figref>8</figref> to the Validating the permissions of the user;</li><li>- a circuit <figref>9</figref> for storing validated permissions user;</li><li>- a circuit <figref>10</figref> for access control;</li><li>- a circuit <figref>11</figref> for validating the messages MEC;</li><li>- a circuit <figref>12</figref> for decrypting the encrypted Control words.</li></ul>
The validation circuit <figref>8</figref> allows, at the news MD the operations of user address recognition and user authorization Analysis perform. For this Purpose, the validation circuit <figref>8</figref> the key K of the Encryption algorithm. If the message MD is validated, the message in the MD permissions of the user contained in the circuit <figref>9</figref> to the Save validated permissions saved.
The circuit <figref>11</figref> for validating the messages MEC enables the access conditions contained in the messages MEC <figref>2</figref> operations execute, which are equal to those obtained by the validation circuit <figref>8</figref> at are running the permissions contained in the messages MD the user. The validation circuit <figref>11</figref> includes the key K.
The decryption circuit <figref>12</figref> allows the control words to decipher. For this purpose, the decryption circuit <figref>12</figref> also the key K of the encryption algorithm for the Control words.
The Access control circuit <figref>10</figref> compares the validated Access conditions with the validated entitlements of the user. If the validated access conditions the validated entitlements match the user, authorized a of the access control circuit <figref>10</figref> outbound and to the decryption circuit <figref>12</figref> applied Signal S decryption the control words. In the opposite case, the signal S authorized decryption not.
At the Completion of the various steps of the decryption procedure may be decryption circuit <figref>12</figref> the decrypted control words Cwi generated to the descrambling the scrambled Element IE (ECG) to allow.
<figref idrefs="S32">3a</figref> provides a first MEC message format is according to the invention.
The Message MEC consists of a body C2a and a header <figref>13</figref>. its content (H2), among other things the type and size of in the body C2a Elements contained there.
Of the Main part C2a includes among other things an element <figref>14</figref>, The contents of (Identifier) to identify the service provider, n elements A1, ..., Aj, ..., An, each of the algorithms with respective keys K1, ..., Kj, ..., Kn encrypted same control word Cwi include, n items DX1, ..., dxj, ..., DXn, the indices I (K1), ..., I (Kj), ..., I (Kn) which the various key K1, ..., Kj, ..., Kn to identify possible, an element <figref>15</figref>Which includes the set of access conditions, associated with the service provided by the service provider, and an element <figref>16</figref>That a datum HASH<sub>Q</sub> includes, the content of the message MEC and, in particular in the message MEC containing<?page 5?>allows to validate nen access requirements and to check. The datum HASH<sub>Q</sub> is a key Q controlled, preferably by any of the encryption keys K1, ..., Kj, ..., Kn are different.
According to a first embodiment the invention is the algorithm with key Kj whatever the rank j (j = 1, 2, ..., n) of the key Kj is the same. This can z. B. by the abbreviation RSA ( "Rivest Shamir ADLEMAN ") known Algorithm by the abbreviation SDE ( "Syndrome Decoding Engine ") known Algorithm or again by the abbreviation DES ( "Data Encryption Standard") known algorithm be.
According to the invention the algorithm with key Kj for all or for some the key Kj (j = 1, 2, ..., n) is equal or different.
Advantageous can the different key Kj which are successively used as following, according to a particular embodiment, the invention will be chosen with a size, with the rank j of the key Kj increases. Any thieves are then placed in a situation in the theft of several key becomes increasingly difficult.
According to <figref idrefs="S32">3a</figref> consequences the various elements according to the first format of the invention the body of the message MEC form, in a specific order successive. However, the invention relates to the formats messages MEC for the order of the elements of the in <figref idrefs="S32">3a</figref> illustrated is different.
<figref idrefs="S33">3b</figref> provides a second MEC message format is according to the invention.
The Message MEC consists of a body C2b and a header <figref>17</figref>. its content (H3) including the type and size of in the body C2b Elements contained there.
Of the Main part C2b includes: <ul><li>- P elements ID1, ID2, IDK, ..., lDp, each one of the p service providers, wherein p is an integer, to identify to enable,</li><li>- n Elements A11, ..., A1j, ..., 1 n for the provider of rank 1, wherein n is an integer,</li><li>- m Elements A21, ..., A2j, ..., A2m for the provider of rank 2, wherein m is an integer,</li><li>- v Elements k1, ..., kj, ..., Akv for the provider of rank k, wherein v is an integer,</li><li>- w Elements Ap1, ..., Apj, ..., Apw for the provider of rank p, wherein w is an integer,</li></ul> wherein each of the n + m + ... + V + ... + w elements A11, ..., kj, ..., according to the preferred Apw embodiment the invention, the same with an algorithm with respective keys K11, ..., Kkj, ..., Kpw encrypted Control word Cwi includes, <ul><li>- N elements DX11, ..., DX1j, ..., For DX1n Bookseller of rank 1,</li><li>- m Elements DX21, ..., DX2j, ..., DX2n for the provider of rank 2,</li><li>- v Elements DXk1, ..., DXkj, ..., DXkv for the provider of rank k,</li><li>- w Elements DXp1, ..., DXpj, ..., DXpw for the provider of rank p,</li></ul> in which each of the n + m + ... + v + ... + w items DX11, ..., DXkj, ..., DXpw the indices I (K11), ..., I (Kkj), ..., includes I (Kpw), which, how later is specified, the respective keys K11, ..., Kkj, ..., Kpw to identify possible, where the indices with the keys I (Kk1), ..., I (Kkj), ..., I (Kkp) of the service provider of rank k (k = 1, 2, ..., p), an encryption key index field of order k define, <ul><li>- an element <figref>18</figref>. comprising the amount of access conditions through the p deployed service provider service associated with the conditions for access the p service providers according to the preferred embodiment The invention together,</li><li>- a Amount of p data HASH<sub>Q1</sub>, ..., HASH<sub>Qk</sub>, ..., HASH<sub>qp</sub>. wherein the datum HASH<sub>Qk</sub> the content the access conditions contained in the message MEC and the Part of the message MEC which assigned to the service provider of rank k is, allows to validate and verify. The datum HASH<sub>Qk</sub> is by a key Qk controlled. The keys Q1, ..., Qj, ..., Qp are different from each other, and preferably different from the encryption keys Kkj,</li><li>- a Amount of p data I (Q1), ..., I (Qk), ..., I (Qp) that a control key index field form, with the key index I (Qk), later is specified, the datum HASH<sub>Qk</sub> to allows recognize.</li></ul>
According to the above preferred embodiment described of the invention includes each of the n + m + ... + v + ... + w items A11, ..., Akj, ..., Apw the same with an algorithm with the respective keys K11, ..., Kkj, ..., Kpw encrypted Control word Cwi.
According to this in <figref idrefs="S33">3b</figref> -described embodiment of the invention are access conditions <figref>18</figref> common to the p service providers. In other Embodiments of Invention are the conditions of access by a service provider to another or from one group of service providers to other miscellaneous.
As previously mentioned was, the rows<?page 6?>sequence in which the various elements, forming the body of the message MEC follow one another, from in <figref idrefs="S33">3b</figref> be represented differently.
According to a particular embodiment of the Invention is the encryption algorithm the key Kkj of the service provider with the rank k (k = 1, 2, ..., p) regardless of Rank j of the key Kkj same.
According to embodiments, of the above-mentioned particular embodiment, are different, the encryption algorithm with the can key Kkj according to the rank k of the key be Kkj different.
As where in <figref idrefs="S32">3a</figref> described case, the message MEC may the different key Kkj, which are used by a single service provider sequentially, advantageously have a size, with the rank j of the key Kkj increases to complicate the theft increasingly.
<figref idrefs="S34">4</figref> provides a user card, which fall under a message MEC <figref idrefs="S32">3a</figref> is working.
The Users list includes five Main circuits: <ul><li>- A circuit <figref>20</figref> to the Validating the permissions of the user;</li><li>- a circuit <figref>21</figref> for storing the validated entitlements the user;</li><li>- a circuit <figref>22</figref> for access control;</li><li>- a circuit <figref>23</figref> for validating the messages MEC;</li><li>- a circuit <figref>24</figref> for decrypting the encrypted Control words.</li></ul>
The validation circuit <figref>20</figref> allows, at the news MD the operations of user address recognition and user authorization Analysis perform.
The Analysis of the message MD is with the aid of an analysis algorithm executed of a in the validation circuit <figref>20</figref> contained key KC depends. Preferably, the key KC from any one of the encryption key Kj (J = 1, 2, ..., n) of different keys. If the message MD is validated, the authorizations contained in the message MD the user in the circuit <figref>21</figref> validated for storage Permissions saved.
The validation circuit <figref>23</figref> enables the in the news perform MEC contained access conditions validation operations like those are contained in the messages in the MD Permissions of the user are executed. validation the messages MEC, with the aid of a controlled by the key Q Validation algorithm executed. The key Q is in the circuit <figref>23</figref> contain.
If the key Kj of the Dechiffrierschaltung <figref>24</figref> Key contained is, with the aid of the key Kj of the encryption algorithm decryption the encrypted Control word E (Cwi) Kj executed.
If the key Kj in the deciphering circuit <figref>24</figref> contain is, the latter also includes the index I (Kj) which, under the Amount contained in the message MEC encrypted control words that encrypted Control word E (Cwi) Kj allows to detect. If the control word E (Cwi) Kj has been recognized, the latter of the validation circuit is <figref>23</figref> at decryption circuit <figref>24</figref> transfer. Then, find the decryption instead of.
The Access control circuit <figref>22</figref> compares the validated Access conditions with the validated entitlements of the user. If the validated access conditions the validated entitlements match the user, authorized a of the access control circuit <figref>22</figref> outbound Signal S decryption said control word. In the opposite case entitled the signal S decryption not.
As previously mentioned was the theft of a user card to the attention of in can the user card contained control words encryption key lead. If the theft is excessive, distributes the service provider new user cards. The decryption circuit for the control words the new user cards then contains a new encryption key and a new encryption key index.
According to the invention are the new encryption key as well the new key index contained in the messages MEC.
Around in the case of off-line systems to ensure the permanence of his service, provides the service provider for its new customers new off-line information media ready, where with the stolen key encrypted deleted control words are.
As previously mentioned was, the off-line information media, which before the change distributes the encryption key are, according to the invention advantageously after this change continue to be used. Thus, the use of these information media either with a card which contains a new encryption key, or <?page 7?>with an old card that is not the new encryption key includes, running will. Likewise and in reciprocal manner, the after the change distributed the encryption key Off-line information media with the user cards which comprise the old encryption key, as in stolen cards is the case in particular, advantageous no longer be read.
in the Case of online systems acquires the service provider the user card, the stolen key include, again, replacing them with new cards, the new one Encryption key as about the above-mentioned include.
Advantageous then a transition period are fixed in relation to the distribution of new user cards. While throughout the transitional period include distributed from the service provider messages MEC control words with the key, been the stolen encrypted are, and control words, which have been encrypted with the new encryption key. If all the users cards have been renewed, are the service provider Now only news from MEC, which include the new encryption key.
As non-limiting Example, the number of versions of encryption the control words, ie the number of encryption algorithm keys for the control words, between 5 and 10, respectively.
<figref idrefs="S35">5</figref> provides the block diagram represents a user card with a message MEC under <figref idrefs="S33">3b</figref> is working.
The user card <figref>25</figref> out <figref idrefs="S35">5</figref> is the Card that is associated with the service provider of rank k.
The user card <figref>25</figref> five main circuits: <ul><li>- a circuit <figref>26</figref> to validate the permissions of the user;</li><li>- a circuit <figref>27</figref> for storing the validated entitlements the user;</li><li>- a circuit <figref>28</figref> for access control;</li><li>- a circuit <figref>29</figref> for validating the messages MEC;</li><li>- a circuit <figref>30</figref> for decrypting the encrypted Control words.</li></ul>
The circuits <figref>26</figref>. <figref>27</figref> and <figref>28</figref> have the same Functions as those of the respective circuits described above <figref>20</figref>. <figref>21</figref> and <figref>22</figref>,
The Analysis of the messages MD is with the aid of an analysis algorithm executed of a in the validation circuit <figref>26</figref> Keys contained KC depends. The key KC is preferably a from that in the decryption circuit <figref>30</figref> contained Encryption key different Key.
The circuit <figref>29</figref> allows the execution of Validation of the access conditions as well as that part of the message MEC, is associated with the service provider of rank k. For this Reason, the circuit <figref>29</figref> the control key index I (Qk) the datum HASH the<sub>Qk</sub> in the message MEC to identify possible and the key Qk, the datum HASH the<sub>Qk</sub> to control allows.
The Control words decryption circuit <figref>30</figref> includes the encryption key and Kkj the encryption key index I (Kkj).
The Validation of the access conditions contained in the messages MEC is carried out with the aid of a validation algorithm which by the key Qk is checked when the control words decryption circuit <figref>30</figref> the key Kkj and includes the index I (Kkj).
Of the key Index I (Kkj) allows, encrypted under the Volume control words the encrypted Control word E (Cwi) Kkj to recognize. If the control word E (Cwi) Kkj has been recognized, the latter of the validation circuit is <figref>29</figref> at decryption circuit <figref>30</figref> transfer. thereupon with the aid of the key Kkj the encryption algorithm decryption the encrypted Control word E (Cwi) Kkj executed.
According to the preferred embodiment of Invention includes the in <figref idrefs="S32">3a</figref> described message MEC, an encryption key index field and includes in <figref idrefs="S33">3b</figref> Message MEC described p encryption keys index fields and a Control key index field. As previously mentioned was possible these key indexes Recognition of their associated data by the user card.
In other Examples that do not fall under the scope of the claims, include the news MEC no encryption keys indices and / or control keys indices. The deciphered control words and the data that enable to validate the messages MEC, are represented by the user card by their order and their Size recognized. The circuits <figref>24</figref> and <figref>30</figref> then include in a per se known fashion elements for detecting the order and the size of the decrypted control words are necessary, the circuit <figref>29</figref> comprises elements the for the detection of said rows<?page 8?>follow and the size of the data is necessary, which enable to validate the messages MEC and check.
Independent of the message MEC of the invention type, the invention relates in The case of off-line systems to an off-line information medium includes a scrambled by a string of N control words element, characterized characterized in that it encrypted p strings of from N control words includes existing elements, each string of the elements scrambled descrambling item allows wherein p is an integer greater than or is equal to 1.
The existing string of encrypted control words from the N Elements is a string of the same encrypted control words, wherein each control word is encrypted with an algorithm with a different key.
Thus include the off-line information media according to the invention messages MEC such as those described in <figref idrefs="S32">3a</figref> or <figref idrefs="S33">3b</figref> are described. According to the invention then include the information contained in the off-line information media News MEC all the elements for descrambling the entire scrambled Elements are necessary.
Thus form the <figref idrefs="S32">3a</figref> and <figref idrefs="S33">3b</figref> also one symbolic representation of two MEC message format examples, contained on the off-line information media according to the invention.
If the information medium comprises a plurality of strings of elements, which the scrambled descrambling item enable, preferably each string of elements another service provider assigned.
The introduction the messages MEC in the element contained in the offline medium can be exemplified carried out with the help of standards are known to those skilled in the art by the name "MPEG-2 System". If not compatible storage of the item on the off-line medium with the "MPEG-2 System" standard is there another way of introducing the messages MEC for. B. in storing only one or a few messages MEC, z. B. of 2 or 3 messages MEC, with the entirety of the medium on the Programs contained and in placing these messages MEC in the header of each of the programs or in any other Structure of a size sufficient to store these few News MEC.
According to a particular embodiment of the in <figref idrefs="S35">5</figref> Described system, several different service providers on the same off-line information system such as z. B. a Digital Video distribute Disc same programs.
Advantageous is then not every service provider forced its own Digital Video disc presses on. Thus, various Service providers on the same medium, all or some of their services offer to lower costs without compromising their respective key of Control words encryption algorithm mutually reveal.
Of the Advantage described above in the context of an offline system concerns and the context of an online system. Several distribution of programs can then using messages MEC such as those described in <figref idrefs="S33">3b</figref> described are offering access to the same program.
In addition, the invention provides a further advantage in the context of online systems.
Thus allows the invention in the context of online systems that any copying of distributed scrambled prohibit programs in plain text that the various service providers the use of copies and / or recordings of the scrambled control programs. To the copies and / or the records the scrambled to see programs in plain text, users are then forced to request permission from the service provider. The reading of the Copies and / or the recordings is then by the presence or otherwise the appropriate permissions in the map the user edited.
Thus take advantage of all that previously the in relation to the context Invention used off-line information media mentioned are, also in respect of the copies and / or the records scrambled Programs.
6 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6
10 members in 6 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 9609501 | France | A | |
| 9609501 | France | – | |
| 9609501 | – | – | – |
| FR19960009501 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| FR2751817A1 | France | A1 | |
| EP0822720A1 | European Patent Office (EPO) | A1 | |
| CN1175142A | China | A | |
| JPH1098462A | Japan | A | |
| FR2751817B1 | France | B1 | |
| US6091818A | United States of America | A | |
| CN1145302C | China | C | |
| EP0822720B1 | European Patent Office (EPO) | B1 | |
| DE69737804D1 | Germany | D1 | |
| DE69737804T2This record | Germany | T2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| No opposition during term of oppositionOpposition8364 | 8364 |
Numbers
- Publication
- 69737804
- Publication, DOCDB
- 69737804
- Publication, EPODOC
- DE69737804T
- Application
- 69737804
- Application, DOCDB
- 69737804
- Application, EPODOC
- DE1997637804T
Titles2
- German
- System mit bedingtem Zugang unter Verwendung von Nachrichten mit mehreren Verschlüsselungsschlüsseln
- English
- Conditional access system using messages with multiple encryption keys
Classification
- CPC, 5
- H04N7/163
- H04N7/1675
- H04N21/26606
- H04N21/4181
- H04N21/4623
- IPC, 4
- H04L9 32
- G09C1 00
- H04N7 16
- H04N7 167
