Catv communication system
35 claims: 35 independent, 0 dependent
- 1A CATV system comprising a cable network having a plurality of nodes to each of which is connected an apparatus for sending and/or receiving messages transmitted via the network and a headend apparatus to which all messages placed on the network by source nodes are sent and which is operable to re-broadcast messages for receipt by destination nodes, each network node having associated therewith a key identifying that node, characterised in that each source node apparatus comprises:means for sending a request for network access to said headend apparatus;means for receiving an encrypted access code from the headend apparatus;means for decrypting the encrypted access code with the aid of the node's key, andmeans for using the decrypted access code to generate and to insert a frame verifier code into each message frame that is sent at a point in each such message frame that precedes at least a portion thereof;and further characterised in thatsaid headend apparatus comprises:means responsive to an access request received from a source node to generate an access code,means for encrypting the access code by use of the key identifying the source node,means for placing the encrypted access code on the network for transmission to the source node,means responsive to the access code to generate therefrom a frame verifier code for each message frame received from the source node that corresponds to the frame verifier code in the received message frame,means for comparing the frame verifier code inserted in each message frame received from a source node with a corresponding frame verifier code generated in the headend apparatus, said comparison means providing an inhibit signal if the compared frame verifier codes do not match,and means operable to re-broadcast each received message frame onto the network and responsive to an inhibit signal to inhibit re- broadcasting of the portion of the message frame that followed the frame verifier code that gave rise to the inhibit signal. 1. Kabelfernsehsystem mit einem Kabelnetzwerk, das folgende Teile umfaßt: eine Vielzahl von Knotenpunkten, wobei an jedem hiervon eine Vorrichtung zum Senden und/oder Empfangen von Nachrichten, die über das NetzwerK ubermittelt werden, und eine Empfangsstellenvorrichtung, zu der alle Nachrichten, die durch Quellenknotenpunkte in das Netzwerk gespeist worden sind, gesendet werden und der dazu dienen kann, Nachrichten zum Empfang für die Ausgangsknotenpunkte zurückzusenden, wobei jedem Netzwerkknotenpunkt ein Schlüssel zugeordnet ist, der diesen Knotenpunkt identifiziert, dadurch gekennzeichnet, daß jede Quellenknotenpunktvorrichtung folgende Teile umfaßt:Vorrichtungen zum Senden einer Nachfrage bezüglich des Netzwerkanschlusses an die Empfangsstellenvorrichtung;Vorrichtungen zum Empfangen eines verschlüsselten Anschlußcodes von der Empfangsstellenvorrichtung;Vorrichtungen zum Entschlüsseln des verschlüsselten Anschlußcodes mit Hilfe des Knotenpunktschlüssels undVorrichtungen zur Anwendung des entschlüsselten Anschlußcodes zur Erzeugung und Einreihung eines Rahmenbestätigungscodes in jeden Nachrichtenrahmen, der zu einem Punkt in jeden solchen Nachrichtenrahmen gesandt wird, der zumindest einem Teil davon vorangeht und weiter dadurch gekennzeichnet, daß die Empfangsstellenvorrichtung folgende Teile umfaßt:Vorrichtungen zum Erzeugen eines Anschlußcodes entsprechend einer Anschlußnachfrage, die von einem Quellenknotenpunkt stammt,Vorrichtungen zum Verschlüsseln des Anschlußcodes unter Verwendung des Schlüssels, der den Quellenknotenpunkt kennzeichnet,Vorrichtungen zum Einspeisen des verschlüsselten Anschlußcodes in das Netzwerk zur Überspielung an den Quellenknotenpunkt,Vorrichtungen zum Erzeugen eines Rahmenbestätigungscodes entsprechend dem Anschlußcode infolge jedes Nachrichtenrahmens, der von dem Quellenknotenpunkt eingeht, der den Rahmenbestätigungscodes in den erhaltenen Nachrichtenrahmen entspricht,Vorrichtungen zum Vergleichen des Rahmenbestätigungscodes, der in jeden Nachrichtenrahmen eingefügt wird, der von einem Quellenknotenpunkt mit einem entsprechenden Rahmenbestätigungscode in der Empfangsstellenvorrichtung erzeugt wird, wobei die Vergleichsvorrichtungen ein Unterdrückungssignal erzeugen, wenn die verglichenen Rahmenbestätigungscodes nicht übereinstimmen, undVorrichtungen, die dazu dienen, jeden erhaltenen Nachrichtenrahmen in das Netzwerk zurückzusenden und auf ein Unterdrückungssignal das Zurücksenden des Teils des Nachrichtenrahmens unterdrücken, der dem Rahmenbestätigungscode folgt, der Anlaß dazu gab, das Signal zu unterdrücken. 1. Système CATV comportant un réseau câblé avec plusieurs noeuds à chacun desquels est connecté un appareil pour émettre et/ou recevoir des messages transmis par l'intermédiaire du réseau et un appareil d'extrémité vers lequel sont émis tous les messages placés sur le réseau par des noeuds source et qui a pour fonction de rediffuser les messages pour qu'ils soient reçus par des noeuds de destination, chaque noeud du réseau étant associé avec une clé qui l'identifie, caractérisé en ce que chaque appareil de noeud source comporte: un dispositif destiné à émettre une demande d'accès au réseau vers ledit appareil d'extrémité;un dispositif destiné à recevoir un code d'accès crypté provenant de l'appareil d'extrémité;un dispositif de décryptage du code d'accès crypté avec l'aide de la clé de noeud, et un dispositif pour utiliser le code d'accès décrypté afin de produire et d'introduire un code de vérification de trame dans chaque trame de message qui est émise en un point dans chacune des trames de message qui précède au moins l'une de ces parties;et caractérisé en outre en ce que ledit appareil d'extrémité comporte: un dispositif réagissant à une demande d'accès reçue d'un noeud source en produisant un code d'accès;un dispositif de cryptage du code d'accès en utilisant la clé identifiant le noeud source;un dispositif destiné à placer le code d'accès crypté sur le réseau pour sa transmission vers le noeud source;un dispositif réagissant au code d'accès en produisant à partir de ce dernier un code de vérification de trame pour chaque trame de message reçue du noeud source, qui correspond au code de vérification de trame dans la trame de message reçue un dispositif de comparaison du code de vérification de trame introduit dans chaque trame de message reçue d'un noeud source avec un code de vérification de trame produit dans l'appareil d'extrémité, ledit dispositif de comparaison produisant un signal d'inhibition si les codes de vérification de trame comparés ne se correspondent pas;et un dispositif ayant pour fonction de rediffuser chaque trame de message reçue sur le réseau et réagissant à un signal d'inhibition en inhibant la rediffusion de la partie de la trame de message qui suivait le code de vérification de trame ayant donné lieu au signal d'inhibition.
- 2A system as claimed in Claim 1 in which said means for generating frame verifier codes of said source node apparatus is operable to generate from said decrypted access code a series of frame verifier codes, andsaid means for generating frame verifier codes of said headend apparatus is operable to generate from said access code a corresponding series of frame verifier codes. 2. System nach Anspruch 1, in dem die Vorrichtungen zum Erzeugen des Rahmenbestätigungscodes der Quellenknotenpunktsvorrichtung dazu dienen können, von den entschlüsselten Anschlußcodes eine Folge von Rahmenbestätigungscodes zu erzeugen und in welcher Vorrichtungen zum Erzeugen von Rahmenbestätigungscodes der Empfangsstellenvorrichtung dazu dienen können, aus dem Anschlußcode eine entsprechende Folge von Rahmenbestätigungscodes zu erzeugen. 2. Système d'inhibition selon la revendication 1, dans lequel ledit dispositif de production des codes de vérification de trame dudit appareil de noeud source à pour fonction de produire à partir desdits codes d'accès décryptés une série de codes de vérification de trame, et ledit dispositif qui produit des codes de vérification de trame dans ledit appareil d'extrémité à pour fonction de produire à partir dudit code d'accès une série correspondante de codes de vérifications de trame.
- 3A system as claimed in Claim 2 in which said means for generating frame verifier codes of said source mode apparatus is operable to insert the next frame verifier code of the series into each next succeeding message frame, andsaid means for generating frame verifier codes of said headend apparatus is operable to provide a series of frame verifier codes corresponding to the series into the message frames. 3. System nach Anspruch 2, in welchem die Vorrichtungen zum Erzeugen des Rahmenbestätigungscodes der Quellenknotenpunktsvorrichtung dazu dienen können, den nächsten Rahmenbestätigungscode der Folge in den nächsten folgenden Nachrichtenrahmen einzufügen, und die Vorrichtungen zum Erzeugen des Rahmenbestätigungscodes der Empfangsstellenvorrichtung dazu dienen können, eine Folge von Rahmenbestätigungscodes entsprechend der Folgen in den Nachrichtenrahmen zur Verfügung zu stellen. 3. Système selon la revendication 2, dans lequel ledit dispositif produisant des codes de vérification de trame dans ledit appareil de noeud source à pourfonction d'introduire le code de vérification de trame suivant dans la série dans chaque trame de message suivant immédiatement, et ledit dispositif produisant des codes de vérification de trame dans ledit appareil d'extrémité ayant pour fonction de produire une série de codes de vérification de trame correspondant à la série dans les trames de message.
- 4A system as claimed in Claim 2 or 3 in which in the head end apparatus, said access code generating means comprises means for generating first and second code segments, the first segment constituting a network access identification code allotted to the source node requesting access to the network, and means for combining said segments to form said access code for transmission to the source node, andsaid frame verifier code generating means is responsive to said first and second code segments to encrypt the first code segment with the second to generate therefrom a sequence of a predetermined number of frame verifier codes, and means for incrementing said second code segment to a fresh value upon completion of said sequence whereby a further such sequence is generated using the fresh value of the second code segment;andin the source node apparatus,said means for generating the frame verifier codes is operable to obtain the first and second code segments from the decrypted access code and to encrypt the first code segment with the second to generate therefrom a sequence of a predetermined number of frame verifier codes corresponding to said sequence generated in said head end apparatus, and further comprising means for incrementing said second code segment to the aforesaid fresh value upon completion of said sequence whereby the aforesaid further such sequence is generated using the fresh value of the second code segment. 4. System nach Anspruch 2 oder 3, in dem in der Empfangstellenvorrichtung die Vorrichtungen zum Erzeugen des Anschlußcodes Vorrichtungen zum Erzeugen eines ersten und zweiten Codesegments umfassen, wobei das erste Segment aus einem Identifikationscode für den Netzwerkanschluß besteht, der dem Quellenknotenpunkt zugewiesen wird, der an das Netzwerk angeschlossen werden soll, und Vorrichtungen zum Kombinieren dieser Segmente enthält, um den Anschlußcode für die Zuspielung zu dem Quellenknotenpunkt zusammenzusetzen, und die Vorrichtungen zum Erzeugen des Rahmenbestätigungscodes dazu dienen, entsprechend dem ersten und zweiten Codesegment, das erste Codesegment mit dem zweiten zu verschlüsseln, um hieraus eine Folge von einer vorher bestimmten Anzahl von Rahmenbestätigungscodes zu erzeugen, und Vorrichtungen zum Inkrementieren des zweiten Codesegments zu einem neuen Wert zur Vervollständigung dieser Folge, wobei eine weitere solche Folge gebildet wird, die den neuen Wert des zweiten Codesegments zugrunde legt;undin der Quellenknotenpunktvorrichtung die Vorrichtungen zum Erzeugen des Rahmenbestätigungscodes dazu dienen, die ersten und zweiten Codesegmente aus den entschlüsselten Anschlußcodes zu erhalten und das erste Codesegment mit dem zweiten zu verschlüsseln, um daraus eine Folge von einer vorherbestimmten Zahl von Rahmenbestätigungscodes entsprechend der Folge zu erzeugen, die in der Empfangsstellenvorrichtung erzeugt wurde und weiter Vorrichtungen zum Inkrementieren der zweiten Codefolge zum zuvor genannten neuen Wert zur Vervollständigung der Folge, wobei über das zuvor Gesagte hinaus diese Folge unter Verwendung des neuen Wertes des zweiten Codesegments gebildet wird. 4. Système selon la revendication 2 ou 3, dans lequel, dans l'appareil d'extrémité, ledit dispositif générateur de codes d'accès comporte un dispositif qui produit un premier et un second segments de code, le premier segment constituant un code d'identification d'accès au réseau affecté au noeud source qui demande l'accès au réseau et un dispositif pour combiner lesdits segments afin de former ledit code d'accès pour la transmission vers le noeud source;et ledit dispositif générateur de code de trame réagissant audit premier et audit second segments de code en cryptant le premier segment de code avec le second pour produire à partir d'eux une séquence d'un nombre prédéterminé de codes de vérification de trame et un dispositif pour incrémenter ledit second segment de code jusqu'à une nouvelle valeur à la fin de ladite séquence de manière qu'une séquence soit produite en utilisant la nouvelle valeur du second segment de codes;et dans l'appareil de noeud source, ledit dispositif produisant les codes de vérification de trame ayant pour fonction d'obtenir le premier et le second segments de code à partir du code d'accès décrypté et de crypter le premier segment de code avec le second pour produire à partir d'eux une séquence d'un nombre prédéterminé de codes de vérification de trame correspondant à ladite séquence produite dans ledit appareil d'extrémité, et comportant en outre un dispositif qui incrémente ledit second segment de code jusqu'à la nouvelle valeur précitée à la fin de ladite séquence de manière que ladite autre séquence soit produite en utilisant la nouvelle valeur du second segment de code.
- 5A system as claimed in Claim 4 in which:in said headend apparatus, said means for generating said first and second code segments is operable to generate same as random numbers.6. A system as claimed in any preceding claim in whichsaid headend apparatus has associated therewith means storing a directory of node keys from which is obtained the node key pertaining to a source node from which an access request is received. 5. System nach Anspruch 4, in welchem in der Empfangsstellenvorrichtung die Vorrichtungen zum Erzeugen des ersten und zweiten Codesegments dieselben als Zufallswerte erzeugen können. 5. Système selon la revendication 4, dans lequel, dans ledit appareil d'extrémité, ledit dispositif produisant ledit premier et ledit second segments de code à pour fonction de produire ces derniers comme des nombres aléatoires.
- 6System nach einem der vorhergehenden Ansprüche, in welchem die Empfangsstellenvorrichtung mit ihr verbunden Vorrichtungen aufweist, die ein Verzeichnis von Knotenpunktschlüsseln speichern, von dem der Knotenpunktschlüssel erhalten wird, der zu einem Quellenknotenpunkt gehört, von dem eine Frage nach dem Anschluß empfangen wird. 6. Système selon l'une quelconque des revendications précédentes, dans lequel ledit appareil d'extrémité est associé avec un dispositif qui mémorise un annuaire des clés de noeud à partir duquel est obtenue la clé de noeud se rapportant à un noeud de source duquel une demande d'accès est reçue. 7. A system as claimed in any preceding claim which is arranged to provide communication from the nodes to the headend apparatus over a network up-channel and to provide communication from the headend apparatus to the nodes over a network down-channel to which each node apparatus is responsive to receive messages from the headend apparatus.
- 7System nach einem der vorangehenden Ansprüche, das derart angelegt ist, eine Nachricht von den Knotenpunkten an die Empfangsstellenvorrichtung über einen hinführenden Kanal des Netzwerks und die Nachricht von der Empfangsstellenvorrichtung zu den Knotenpunkten über einen rückführenden Kanal des Netzwerkes zu führen, an den jede Knotenpunktvorrichtung angeschlossen ist, um Nachrichten von der Empfangsstellenvorrichtung aufzunehmen. 7. Système selon l'une quelconque des revendications précédents, agencé de manière à établir une communication à partir des noeuds vers l'appareil d'extrémité sur un canal supérieur de réseau et pour établir une communication depuis l'appareil d'extrémité vers les noeuds sur un canal inférieur de réseau auquel chaque appareil de noeud réagit pour recevoir des messages provenant de l'appareil d'extrémité. 8. A system as claimed in Claim 7 in which said up-channel and down-channel are defined by respective frequency bands carried by the network.
- 8System nach Anspruch 7, in dem der hinführende und rückführende Kanal durch entsprechende Frequenzbänder festgelegt wird, die im Netzwerk vorliegen. 8. Système selon la revendication 7, dans lequel ledit canal supérieur et ledit canal inférieur sont définis par des bandes de fréquence respectives transmises par le réseau. 9. A terminal apparatus for use with a CATV system comprising a cable network having a plurality of source nodes to each of which is connectable such a terminal apparatus for sending messages transmitted via the network and a headend apparatus to which all messages placed on the network by such terminal apparatus is sent and which is operable to re-broadcast messages for receipt by destination nodes, each network source mode having associated therewith a key identifying that node, said terminal apparatus being characterised by:means for sending a request for network access to said headend apparatus;means for receiving an encrypted access code from the headend apparatus;means for decrypting the encrypted access code with the aid of the node's key,means for using the decrypted access code to generate and to insert a frame verifier code into each message frame that is sent at a point in each such message frame that precedes at least a portion thereof.
- 910. A terminal apparatus as claimed in Claim 9 in which said means for generating frame verifier codes is operable to generate from said decrypted access code a series of frame verifier codes. 9. Appareil terminal destiné à être utilisé avec un système CATV comportant un réseau câblé avec plusieurs noeuds source à chacun desquels peut être connecté un tel appareil terminal pour émettre des messages transmis par l'intermédiaire du réseau et un appareil d'extrémité vers lequel sont émis tous les messages placés par le réseau par cet appareil terminal et qui a pour fonction de rediffuser les messages pour qu'ils soient reçus par des noeuds de destination, chaque noeud source du réseau étant associé avec une clé qui l'identifie, ledit appareil terminal étant caractérisé par:un dispositif pour émettre une demande d'accès au réseau vers ledit appareil d'extrémité;un dispositif pour recevoir un code d'accès crypté dudit appareil d'extrémité;un dispositif pour décrypter le code d'accès crypté à l'aide de la clé du noeud;un dispositif pour utiliser le code d'accès décrypté de manière à produire et à introduire un code de vérification de trame dans chaque trame de message, qui est émis en un point de chaque trame de message qui précède au moins l'une de ces parties. 9. Terminal zur Verwendung in einem Kabelfernsehsystem, das ein Kabelnetzwerk enthält, welches eine Vielzahl von Quellenknotenpunkten aufweist, wobei an jeden von diesen ein solches Terminal anschließbar ist, um Nachrichten zu senden, die über das Netzwerk übermittelt werden, und eine Empfangsstellenvorrichtung, an die alle Nachrichten, die durch solche Terminals in das Netzwerk gespeist werden, gesandt werden und das dazu dient, Nachrichten zum Empfang bei den Ausgangsknotenpunkten zurückzusenden, wobei jeder Netzwerkquellenknotenpunkt mit ihm verbunden einen Schlüssel trägt, der diesen Knotenpunkt identifiziert, wobei das Terminal durch folgende Teile gekennzeichnet ist: Vorrichtungen zum Senden einer Anfrage nach dem Netzwerkanschluß an die Empfangsstellenvorrichtung;Vorrichtung zum Empfangen eines verschlüsselten Anschlußcodes von der Empfangsstellenvorrichtung;Vorrichtungen zum Entschlüsseln des verschlüsselten Anschlußcodes mit der Hilfe des Knotenpunktschlüssels;Vorrichtungen zur Anwendung des entschlüsselten Anschlußcodes, um einen Rahmenbestätigungscode zu erzeugen und in jeden Nachrichtenrahmen einzufügen, der zu einem Punkt in jeden solchen Nachrichtenrahmen gesendet wird, der zumindest einem Teil davon vorangeht.
- 10Appareil terminal selon la revendication 9, dans lequel ledit dispositif qui produit les codes de vérification de trame a pour fonction de produire, à partir dudit code d'accès décrypté, une série de codes de vérification de trame. 10. Terminal nach Anspruch 9, in dem die Vorrichtungen zum Erzeugen des Rahmenbestätigungscodes dazu verwendet werden können, aus dem entschlüsselten Anschlußcode eine Folge von Rahmenbestätigungscodes zu erzeugen. 11. A terminal apparatus as claimed in Claim 10 in which said means for generating frame verifier codes is operable to insert the next frame verifier code of the series into each next succeeding message frame.
- 11Appareil terminal selon la revendication 10, dans lequel ledit dispositif produisant des codes de vérification de trame a pour fonction d'introduire le code de vérification de trame suivant de la série dans chaque trame de message suivant immédiatement. 11. Terminal nach Anspruch 10, in welchem die Vorrichtungen zum Erzeugen des Rahmenbestätigungscodes dazu dienen, den folgenden Rahmenbestätigungscode der Folge in jeden nächstfolgenden Nachrichtenrahmen einzufügen. 12. A terminal apparatus as claimed in Claim 10 or 11 in which said means for generating the frame verifier codes is operable to obtain first and second code segments from the decrypted access code and to encrypt the first code segment with the second to generate therefrom a sequence of a predetermined number of frame verifier codes, and further comprising means for incrementing said second code segment to a fresh value upon completion of said sequence whereby a further such sequence is generated using the fresh value of the second code segment.
- 12Appareil terminal selon la revendication 10 ou 11, dans lequel ledit dispositif qui produit les codes de vérification de trame a pour fonction d'obtenir un premier et un second segments de code à partir du code d'accès décrypté et de crypter le premier segment de code avec le second pour produire à partir deux une séquence d'un nombre prédéterminé de codes de vérification de trame, et comportant en outre un dispositif pour incrémenter ledit second segment de code à une nouvelle valeur à la fin de ladite séquence de manière qu'une autre séquence soit produite en utilisant la nouvelle valeur du second segment de code. 12. Terminal nach Anspruch 10 oder 11, in welchem Vorrichtungen zum Erzeugen des Rahmenbestätigungscodes dazu dienen, erste und zweite Codesegmente von dem entschlüsselten Anschlußcode zu empfangen und das erste Codesegment mit dem zweiten zu verschlüsseln, um daraus eine Folge von einer vorherbestimmten Zahl von Rahmenbestätigungscodes zu erzeugen und sie weiterhin Vorrichtungen zum Inkrementieren des zweiten Codesegments zu einem neuen Wert zur Verfollständigung der Folge enthalten, wobei eine weitere solche Folge erzeugt wird, die die neuen Werte des zweiten Codesegments zugrundelegen. 13. A terminal apparatus as claimed in any one of Claims 9 to 12 which is arranged to provide communication to the headend apparatus over a network up-channel and to receive communication from the headend apparatus over a network down-channel.
- 13Appareil terminal selon l'une quelconque des revendications 9 à 12, agencé de manière à établir une communication vers l'appareil d'extrémité sur un canal supérieur du réseau et à recevoir une communication de l'appareil d'extrémité sur un canal inférieur du réseau. 13. Terminal nach einem der Ansprüche 9 bis 12, welches derart ausgestaltet ist, daß eine Nachricht an die Empfangsstellenvorrichtung über einen hinführenden Kanal des Netzwerkes leitet und eine Nachricht von der Empfangsstellenvorrichtungüber einen rückführenden Kanal des Netzwerks empfängt. 14. A terminal apparatus as claimed in Claim 13 in which said up-channel and down-channel are defined by respective frequency bands.
- 14Appareil selon la revendication 13, dans lequel ledit canal supérieur et ledit canal inférieur sont définis par des bandes de fréquences respectives. 14. Terminal nach Anspruch 13, in dem der hinführende und rückführende Kanal durch entsprechende Frequenzbänder festgelegt ist. 15. A headend apparatus for use in a CATV system comprising a cable network having a plurality of nodes to each of which is connected an apparatus for sending and/or receiving messages transmitted via the network and a headend apparatus to which all messages placed on the network by source nodes are sent and which is operable to re-broadcast messages for receipt by destination nodes, each network node having associated therewith a key identifying that node, and each source node apparatus comprising means for sending a request for network access to said headend apparatus; means for receiving an encrypted access code from the headend apparatus; means for decrypting the encrypted access code with the aid of the node's key, and means for using the decrypted access code to generate and to insert a frame verifier code into each message frame that is sent at a point in each such message frame that precedes at least a portion thereof; the headend apparatus comprising:means responsive to an access request received from a source node to generate an access code,means for encrypting the access code by use of the key identifying the source node,means for placing the encrypted access code on the network for transmission to the source node,means responsive to the access code to generate therefrom a frame verifier code for each message frame received from the source node that corresponds to the frame verifier code in the received message frame,means for comparing the frame verifier code inserted in each message frame received from a source node with a corresponding frame verifier code generated in the headend apparatus, said comparison means providing an inhibit signal if the compared frame verifier codes do not match, andmeans operable to re-broadcast each received message frame onto the network and responsive to an inhibit signal to inhibit re-broadcasting of the portion of the message frame that followed the frame verifier code that gave rise to the inhibit signal.
- 15Appareil d'extrémité destiné à être utilisé dans un système CATV comportant un réseau câblé avec plusieurs noeuds à chacun desquels est connecté un appareil pour émettre et/ou recevoir des messages transmis par l'intermédiaire du réseau et un appareil d'extrémité vers lequel sont émis tous les messages placés sur le réseau par des noeuds source et qui a pour fonction de rediffuser les messages pour qu'ills soient reçus par des noeuds de destination, chaque noeud du réseau étant associé avec une clé qui l'identifié et chaque appareil de noeud source comportant un dispositif pour émettre une demande d'accès au réseau vers ledit appareil d'extrémité; un dispositif destiné à recevoir un code d'accès crypté de l'appareil d'extrémité; un dispositif de décryptage du code d'accès crypté à l'aide de la clé de noeud et un dispositif utilisant le code d'accès décrypté pour produire et introduire un code de vérification de trame dans chaque trame de message, qui est émis en un point de chaque trame de message qui précède au moins l'une de ces parties; l'appareil d'extrémité comportant:un dispositif réagissant à une demande d'accès reçue d'un noeud source en produisant un code d'accès;un dispositif de cryptage du code d'accès en utilisant la clé identifiant le noeud source;un dispositif qui place le code d'accès crypté sur le réseau pour qu'il soit transmis vers le noeud source;un dispositif réagissant au code d'accès en produisant à partir de lui un code de vérification de trame pour chaque trame de message reçue d'une source qui correspond au code de vérification de trame dans la trame de message reçue;un dispositif de comparaison du code de vérification de trame introduit dans chaque trame de message reçue d'un noeud source avec un code de vérification de trame correspondant produit dans l'appareil d'extrémité, ledit dispositif de comparaison produisant un signal d'inhibition si les codes de vérification de trame comparés ne se correspondant pas;et un dispositif ayant pour fonction de rediffuser chaque trame de message reçue sur le réseau et réagissant à un signal d'inhibition en inhibant la rediffusion de la partie de la trame de message qui suivant le code de vérification de trame ayant donné lieu au signal d'inhibition. 15. Empfangsstellenvorrichtung zur Verwendung in einem Kabelfernsehsystem, die ein Kabelnetzwerk mit einer Vielzahl von Knotenpunkten umfaßt, wobei an jeden von diesen eine Vorrichtung zum Senden und/oder Empfangen von Nachrichten angeschlossen ist, die durch das Netzwerk gesendet werden, und eine Empfangsstellenvorrichtung angeschlossen ist, an die alle Nachrichten, die durch Quellenknotenpunkte in das Netzwerk gespeist werden, gesendet werden und welche dazu dient, Nachrichten zum Empfang an die Ausgangsknotenpunkte zurückzusenden, wobei jeder Netzwerkknotenpunkt mit ihm verbunden einen Identifikationsschlüssel für diesen Knotenpunkt trägt und jede Quellenknotenpunktvorrichtung Vorrichtungen zum Senden einer Anfrage für den Netzwerkanschluß an die Empfangsstellenvorrichtung umfaßt;weiterhin Vorrichtungen zum Empfang eines verschlüsselten Anschlußcodes von der Empfangsstellenvorrichtung;Vorrichtungen zum Entschlüsseln des verschlüsselten Anschlußcodes mit Hilfe des Knotenpunktschlüssels und Vorrichtungen zum Verwenden des entschlüsselten Anschlußcodes zum Erzeugen eines Rahmenbestätigungscodes und Einsetzen desselben in jeden Nachrichtenrahmen, der zu einem Punkt in jeden solchen Nachrichtenrahmen gesendet wird, der zumindest einem Teil davon vorangeht, umfaßt, wobei die Empfangsstellenvorrichtung folgende Vorrichtungen aufweist:Vorrichtungen zum Erzeugen eines Anschlußcodes entsprechend einer Anschlußnachfrage, die von einem Quellenknotenpunkt erhalten wird,Vorrichtungen zum Verschlüsseln des Anschlußcodes unter Verwendung des Identifikationsschlüssels des Quellenknotenpunkts,Vorrichtungen zum Einspeisen des verschlüsselten Anschlußcodes in das Netzwerk zur Übermittlung an den Quellenknotenpunkt,Vorrichtungen zur Erzeugung eines Rahmenbestätigungscodes infolge des Anschlußcodes für jeden Nachrichtenrahmen, der von einem Quellenknotenpunkt erhalten wird, der dem Rahmenbestätigungscode in dem empfangenen Nachrichtenrahmen entspricht,Vorrichtungen zum Vergleichen des Rahmenbestätigungscodes, der in jeden Nachrichtenrahmen eingeschoben wird, nachdem er von einem Quellenknotenpunkt empfangen wurde, mit einem entsprechenden Rahmenbesstätigungscode, der in der Empfangsstellenvorrichtung erzeugt wurde, wobei die Vergleichsvorrichtungen ein Sperrsignal aussenden, wenn die verglichenen Rahmenbestätigungscodes nicht übereinstimmen undVorrichtungen, die dazu dienen, jeden empfangenen Nachrichtenrahmen in das Netzwerk zurückzusenden und entsprechend jedem Sperrsignal zum Unterdrücken des Zurücksendens des Teils des Nachrichtenrahmens, der dem Nachrichtenbestätigungscode folgt, welcher Anlaß zu dem Sperrsignal gab, die Rücksendung zu unterbinden. 16. A headend apparatus as claimed in Claim 15 in which said means for generating frame verifier codes of said headend apparatus is operable to generate from said access code a series of frame verifier codes for comparison with a series of frame verifier codes inserted in message frames received from a source node.
- 16Appareil d'extrémité selon la revendication 15, dans lequel ledit dispositif produisant des codes de vérification de trame dudit appareil d'extrémité a pour fonction de produire à partir dudit code d'accès, une série de codes de vérification de trame destinés à être comparés avec une série de codes de vérification de trame introduits dans des trames de message reçues d'un noeud source. 16. Empfangstellenvorrichtung nach Anspruch 15, in welchem die Vorrichtungen zum Erzeugen eines Rahmenbestätigungscodes der Empfangsstellenvorrichtung dazu dient, aus dem Anschlußcode eine Folge von Rahmenbestätigungscodes zu erzeugen, um sie mit einer Folge von Rahmenbestätigungscodes zu vergleichen, die in die Nachrichtenbilder, die von einem Quellenknotenpunkt erhalten wurden, eingefügt wurden. 17. A headend apparatus as claimed in Claim 16 in which said access code generating means comprises means for generating first and second code segments, the first segment constituting a network access identification code allotted to the source node requesting access to the network, and means for combining said segments to form said access code for transmission to the source node, and said frame verifier code generating means is responsive to said first and second code segments to encrypt the first code segment with the second to generate therefrom a sequence of a predetermined number of frame verifier codes, and means for incrementing said second code segment to a fresh value upon completion of said sequence whereby a further such sequence is generated using the fresh value of the second code segment.
- 17Appareil d'extrémité selon la revendication 13, dans lequel ledit dispositif générateur de codes d'accès comporte un dispositif qui produit un premier et un second segments de code, le premier segment constituant un code d'identification d'accès au réseau affecté au noeud source demandant l'accès au réseau et un dispositif qui combine lesdits segments pour former ledit code d'accès qui doit être transmis vers le noeud source, et ledit dispositif générateur de codes de vérification de trame réagissant audit premier et audit second segments de code en cryptant le premier segment de code avec le second pour produire à partir d'eux une séquence d'un nombre prédéterminé de codes de vérification de trame et un dispositif pour incrémenter ledit second segment de code à une nouvelle valeur à la fin de ladite séquence de manière qu'une autre séquence soit produite en utilisant la nouvelle valeur du second segment de code. 17. Empfangstellenvorrichtung nach Anspruch 16, in welchem die Vorrichtungen zum Erzeugen eines Anschlußcodes Vorrichtungen zum Erzeugen von ersten und zweiten Codesegmenten umfassen, wobei das erste Segment aus einem Netzwerkanschluß identifikationscode, der dem Quellenknotenpunkt zugewiesen ist und den Anschluß an das Netzwerk erfragt besteht und Vorrichtungen zum Zusammensetzen der Segmente, um den Anschlußcode zur Übermittlung an den Quellenknotenpunkt bereitzustellen, die Vorrichtungen zum Erzeugen des Rahmenbestätigungscodes das erste Codesegment entsprechend jedem ersten und zweiten Codesegment mit dem zweiten Codesegment verschlüsseln, um daraus eine Folge von einer vorherbestimmten Zahl von Rahmenbestätigungscodes zu erzeugen undVorrichtungen zum Inkrementieren des zweiten Codesegments zu einem neuen Wert zur Vervollständigung der Folge, wobei eine weitere solche Folge unter Verwendung der neuen Werte des zweiten Codesegments erzeugt wird. 18. A headend apparatus as claimed in Claim 17 in which said means for generating said first and second code segments is operable to generate same as random numbers.
- 18Appareil d'extrémité selon la revendication 17, dans lequel ledit dispositif produisant ledit premier et ledit second segments de code produit ces derniers comme des nombres aléatoires. 18. Eine Empfangsstellenvorrichtung nach Anspruch 17, in welcher die Vorrichtungen zum Erzeugen des ersten und zweiten Codesegments dazu dienen, dieselben als Zufallszahlen zu erzeugen. 19. A headed apparatus as claimed in any one of Claims 15 to 18 in which said headend apparatus has associated therewith means storing a directory of node keys from which is obtained the node key pertaining to a source node from which an access request is received.
- 19Appareil d'extrémité selon l'une quelconque des revendications 15 à 18, dans lequel ledit appareil d'extrémité est associé avec un dispositif qui mémorise un annuaire des clés de noeud à partir duquel est obtenue la clé de noeud se rapportant à un noeud source dont a été reçue une demande d'accès. 19. Empfangsstellenvorrichtung nach einem der Ansprüche 15 bis 18, in welchem die Empfangsstellenvorrichtung mit ihr verbunden Vorrichtungen zum Speichern eines Verzeichnisses der Knotenpunktschlüssel hat, von dem der Knotenpunktschlüssel erhalten wird, der einem Quellenknotenpunkt zugehört, von welchem eine Anschlußanfrage aus empfangen wird. 20. A headend apparatus as claimed in any one of Claims 15 to 19 which is arranged to receive communication from the nodes over a network up-channel and to provide communication to the nodes over a network down-channel.
- 20Appareil d'extrémité selon l'une quelconque des revendications 15 à 19, agencé de manière à recevoir des communications des noeuds sur un canal supérieur du réseau et pour établir une communication vers les noeuds sur un canal inférieur du réseau. 20. Empfangsstellenvorrichtung nach einem der Ansprüche 15 bis 19, welche dazu vorgesehen ist, eine Mitteilung von den Knotenpunkten über einen hinführenden Kanal des Netzwerks zu erhalten und eine Mitteilung an die Knotenpunkte über einen rückführenden Kanal des Netzwerks abzugeben. 21. A headend apparatus as claimed in Claim 20 in which said up-channel and down-channel are defined by respective frequency bands carried by the network.
- 21Appareil d'extrémité selon la revendication 20, dans lequel ledit canal supérieur et ledit canal inférieur sont définis par des bandes de fréquences respectives transmises par le réseau. 21. Empfangsstellenvorrichtung nach Anspruch 20, in welcher der hinführende Kanal und der rückführend Kanal durch entsprechende Frequenzbänder, die in dem Netzwerk vorhanden sind, festgelegt werden. 22. A method of controlling access to a CATV system comprising a cable network having a plurality of nodes to each of which is connected an apparatus for sending and/or receiving messages transmitted via the network and a headend apparatus to which all messages placed on the network by source nodes are sent and which is operable to re-broadcast messages for receipt by destination nodes, each network node having associated therewith a key identifying that node, characterised in that the method of controlling access comprises the steps of:sending a request from a source node apparatus for network access to said headend apparatus;generating an access code in the headend apparatus in response to an access request received from the source node,encrypting the access code by use of the key identifying the source node,placing the encrypted access code on the network for transmission to the source node,receiving the encrypted access code from the headend apparatus at the source node apparatus and decrypting the encrypted access code with the aid of the node's key, andusing the decrypted access code to generate and to insert a frame verifier code into each message frame that is sent from the source node apparatus at a point in each such message frame that precedes at least a portion thereof;generating from the access code at the headend apparatus a frame verifier code for each message frame received from the source node that corresponds to the frame verifier code in the received message frame,comparing at the headend apparatus the frame verifier code inserted in each message frame received from a source node with a corresponding frame verifier code generated in the headend apparatus, andre-broadcasting each received message frame onto the network unless the compared frame verifier codes do not match, and in the latter case, inhibiting re-broadcasting of the portion of the message frame that followed the frame verifier code in the message that did not match that of the headend apparatus.
- 22Procédé de commande d'accès à un système CATV comportant un réseau câblé avec plusieurs noeuds à chacun desquels est connecté un appareil destiné à émettre et/ou recevoir des messages transmis par l'intermédiaire du réseau et un appareil d'extrémité vers lequel sont émis tous les messages placés sur le réseau par des noeuds source et qui a pour fonction de rediffuser les messages pour qu'ils soient reçus par des noeuds de destination, chaque noeud du réseau étant associé avec une clé qui l'identifie, procédé de commande d'accès caracterisé en ce qu'il consiste:à émettre une demande depuis un appareil de noeud source pour l'accès au réseau vers ledit appareil d'extrémité;à produire un code d'accès dans l'appareil d'extrémité en réponse à une demande d'accès reçue d'une source;à crypter le code d'accès en utilisant la clé identifiant le noeud source;à placer le code d'accès crypté sur le réseau pour qu'il soit transmis vers le noeud source;à recevoir le code d'accès crypté provenant de l'appareil d'extrémité à l'appareil de noeud source et à décrypter le code d'accès crypté à l'aide de la clé de noeud, et à utiliser le code d'accès décrypté pour produire et introduire un code de vérification de trame dans chaque trame de message qui est émise par l'appareil de noeud source en un point de chaque trame de message qui précède au moins l'une de ces parties;à produire à partir du code d'accès, à l'appareil d'extrémité, un code de vérification de trame pour chaque trame de message reçue d'une source qui correspond au code de vérification de trame dans la trame de message reçue;à comparer, à l'appareil d'extrémité, le code de vérification de trame introduit dans chaque trame de message reçue d'un noeud source avec un code de vérification de trame correspondant produit dans l'appareil d'extrémité et à rediffuser chaque trame de message reçue sur le réseau à moins que les codes de vérification de trame comparés ne se correspondent pas et, dans ce dernier cas, à inhiber la rediffusion de la partie de la trame de message qui suivait le code de vérification de trame dans le message ne correspondant pas avec celui de l'appareil d'extrémité. 22. Verfahren zur Anschlußsteuerung an ein Kabelfernsehsystem, das folgende Teile umfaßt: Ein Kabelnetzwerk, das eine Vielzahl von Knotenpunkten enthält, wobei an jeden dieser Knotenpunkt eine Vorrichtung zum Senden und/oder Empfangen von Nachrichten eingeschlossen ist, die durch das Netzwerk gesendet werden, und eine Empfangsstellenvorrichtung, an welche alle Nachrichten gesendet werden, die in das Netzwerk durch Quellenknotenpunkte eingespeist worden sind, und die dazu dient, Nachrichten zum Empfang bei den Ausgangsknotenpunkten zurückzusenden, wobei jeder Netzwerkknotenpunkt einen Identifikationsschlüssel für diesen Knotenpunkt aufweist, dadurch gekennzeichnet, daß das Verfahren zur Anschlußsteuerung folgende Schritte umfaßt:Senden einer Anfrage von einer Quellenknotenpunktvorrichtung nach einem Netzwerkanschluß an die Empfangsstellenvorrichtung;Erzeugen eines Anschlußcodes in der Empfangsstellenvorrichtung entsprechend einer Anschlußnachfrage, die von dem Quellenknotenpunkt erhalten wurde,Verschlüsse des Anschlußcodes unter Verwendung des Schlüssels, der den Quellenknotenpunkt identifiziert,Einspeisen des verschlüsselten Anschlußcodes in das Netzwerk um diesen an den Quellenknotenpunkt zu übertragen,Empfangen des verschlüsselten Anschlußcodes von der Empfangsstellenvorrichtung an der Quellenknotenpunktvorrichtung und Entschlüsseln des verschlüsselten Anschlußcodes mit Hilfe des Knotenpunktschlüssels undVerwenden des entschlüsselten Anschlußcodes um einen Rahmenbestätigungscode zu erzeugen und diesen in jeden Nachrichtenrahmen einzufügen, der von der Quellenknotenpunktvorrichtung zu einem Punkt in jeden derartigen Nachrichtenrahmen gesendet wird, der zumindest einem Teil davon vorangeht;Erzeugen eines Rahmenbestätigungscodes aus dem Anschlußcode in der Empfangsstellenvorrichtung für jeden Nachrichtenrahmen, der von dem Quellenknotenpunkt erhalten wurde, der dem Nachrichtenbestätigungscode in dem empfangenden Nachrichtenrahmen entspreicht, Vergleichen des Empfangsbestätigungscodes, der in jeden Nachrichtenrahmen, der von einem Quellenknotenpunkt erhalten wurde, eingefügt wurde, mit einem entsprechenden Rahmenbestätigungscode der in der Empfangsstellenvorrichtung erzeugt worden ist, in der Empfangsstellenvorrichtung undZurücksenden jedes empfangenen Nachrichtenrahmens in das Netzwerk, falls die verglichenen Rahmenbestätigungscodes nicht übereinstimmen und im letzteren Fall Unterdrücken des Zurücksendens des Teils des Nachrichtenrahmens, der dem Rahmenbestätigungscode in der Nachricht folgt, der nicht mit demjenigen von der Empfangsstellenvorrichtung übereinstimmt. 23. A method as claimed in Claim 22 in which the source node apparatus a series of frame verifier codes is generated from the decrypted access code and in the headend apparatus a corresponding series of frame verifier codes is generated from the access code.
- 23Procédé selon la revendication 22, dans lequel, dans l'appareil de noeud source, une série de codes de vérification de trame est produite à partir du code d'accès décrypté et, dans l'appareil d'extrémité, une série correspondant de codes de vérification de trame est produite à partir du code d'accès. 23. Verfahren nach Anspruch 22, in welchem die Quellenknotenpunktvorrichtung eine Folge von Rahmenbestätigungscodes aus den entschlüsselten Anschlußcodes erzeugt und in der Empfangsstellenvorrichtung eine entsprechende Folge von Rahmenbestätigungscodes aus dem Anschlußcode erzeugt wird. 24. A method as claimed in Claim 23 in which the insertion of a frame verifier code into each message frame in the source node apparatus is done by inserting the next frame verifier code of said series into each next succeeding message frame;and in which the headend apparatus the series of frame verifier codes provided for the aforesaid comparison corresponds to the series inserted into the message frame.
- 24Procédé selon la revendication 23, dans lequel l'insertion d'un code de vérification de trame dans chaque trame de message dans l'appareil de noeud source se fait en introduisant le code de vérification de trame suivant ladite série dans chaque trame de message suivant immédiatement;et dans lequel, dans l'appareil d'extrémité, la série des codes de vérification de trame produit pour la comparaison précitée correspond à la série introduite dans la trame de message. 24. Verfahren nach Anspruch 23, in welchem die Einfügung eines Rahmenbestätigungscodes in jeden Nachrichtenrahmen in der Quellenknotenpunktvorrichtung dadurch durchgeführt wird, daß der folgende Rahmenbestätigungscode der Folge in jeden nächstfolgenden Nachrichtenrahmen eingefügt wird und in welchem in der Empfangsstellenvorrichtung die Folge der Rahmenbestätigungscodes, welche für den vorher erwähnten Vergleich zur Verfügung gestellt wird, der Folge, welche in den Nachrichtenrahmen eingefügt wird, entspricht. 25. A method as claimed in Claim 23 or 24 in which, the generating of the access code in the headend apparatus comprises generating first and second code segments, the first segment constituting a network access identification code allotted to the source node requesting access to the network, and combining said segments to form said access code for transmission to the source node, andthe generating of frame verifier codes in the headend apparatus comprises encrypting the first code segment with the second to generate therefrom a sequence of a predetermined number of frame verifier codes, and incrementing said second code segment to a fresh value upon completion of said sequence whereby a further such sequence is generated using the fresh value of the second code segment;and in whichthe generating of the frame verifier codes in the source node apparatus comprises obtaining the first and second code segments from the decrypted access code and encrypting the first code segment with the second to generate therefrom a sequence of a predetermined number of frame verifier codes corresponding to said sequence generated in said headend apparatus, and further comprising incrementing said second code segment to the aforesaid fresh value upon completion of said sequence whereby the aforesaid further such sequence is generated using the fresh value of the second code segment.
- 25Procédé selon la revendication 23 ou 24, dans lequel la production du code d'accès dans l'appareil d'extrémité consiste à produire un premier et un second segments de code, le premier segment constituant un code d'identification d'accès au réseau affecté au noeud source demandant l'accès au réseau et à combiner les segments pourformer ledit code d'accès afin qu'il soit transmis vers le noeud source, et la production dec codes de vérification de trame dans l'appareil d'extrémité consistant à crypter le premier segment de code avec le second pour produire à partir d'eux une séquence d'un nombre prédéterminée de codes de vérification de trame et à incrémenter ledit second segment de code jusqu'à une nouvelle valeur à la fin de ladite séquence de manière qu'une autre séquence soit produite en utilisant la nouvelle valeur du second segment de code; et dans lequel la production des codes de vérification de trame dans l'appareil de noeud source consiste à obtenir le premier et le second segments de code à partir du code d'accès décrypté et à crypter le premier segment de code avec le second pour produire à partir d'eux une séquence d'un nombre prédéterminé de code de vérification de trame correspondant à ladite séquence produite dans ledit appareil d'extrémité, et consistant en outre à incrémenter ledit second segment de code jusqu'à la nouvelle valeur précitée à la fin de ladite séquence de manière que la nouvelle séquence précitée soit produite en utilisant la nouvelle valeur du second segment de code. 25. Verfahren nach den Ansprüchen 23 oder 24, in welchem die Erzeugung des Anschlußcodes in der Empfangsstellenvorrichtung folgendes umfaßt:Erzeugen eines ersten und zweiten Codesegments, wobei das erste Codesegment einen Netzwerkanschlußidentifikationscode zur Verfügung stellt, der dem Quellenknotenpunkt zugewiesen wird, welcher den Anschluß an das Netzwerk erfragt, und ein Zusammensetzen der Segmente, um den Anschlußcode zur Übermittlung an den Quellenknotenpunkt zu bilden, unddie Erzeugung von Rahmenbestätigungscodes in der Empfangsstellenvorrichtung folgende Schritte umfaßt:Verschlüsseln des ersten Codesegments mit dem zweiten Codesegment, um daraus eine Folge von einer vorherbestimmten Anzahl von Rahmenbestätigungscodes zu erhalten, und Inkrementieren des zweiten Codesegments zu einem neuen Wert zur Vervollständigung der Folge, wobei eine weitere solche Folge unter Verwendung der neuen Werte des zweiten Codesegments erzeugt wird;und in welcherdie Erzeugung des Rahmenbestätigungscodes in der Quellenknotenpunktvorrichtung folgendes umfaßt:Empfangen des ersten und zweiten Codesegments von dem entschlüsselten Anschlußcode und Verschlüsseln des ersten Codesegments mit dem zweiten, um daraus eine Folge von einer vorherbestimmten Zahl von Rahmenbestätigungscodes zu erzeugen, die der Folge entsprechen, die in der Empfangsstellenvorrichtung erzeugt worden sind, und weiterhin Inkrementieren des zweiten Codesegments zu dem genannten neuen Wert zur Vervollständigung der Folge, wobei eine weitere derartige zuvor genannte Folge unter Verwendung des neuen Wertes des zweiten Codesegments erzeugt wird. 26. A method as claimed in Claim 25 in which: the first and second code segments are generated as random numbers.
- 26Procédé selon la revendication 25, dans lequel le premier et le second segments de code sont produits comme des nombres aléatoires. 26. Verfahren nach Anspruch 25, in dem das erste und zweite Codesegment als Zufallszahlen erzeugt wird. 27. A method as claimed in any one of Claims 22 to 26 further comprising, storing a directory of node keys for access by the headend apparatus from which is obtained the node key pertaining to a source node from which an access request is received.
- 27Procédé selon l'une quelconque des revendications 22 à 26, consistant en outre à mémoriser un annuaire des clés de noeud pour l'accès par l'appareil d'extrémité, à partir duquel est obtenue la clé de noeud se se rapportant à un noeud source dont une demande d'accès est reçue. 27. Verfahren nach einem der Ansprüche 22 bis 26, das weiterhin folgende Schritte umfaßt:Speichern eines Verzeichnisses von Knotenpunktschlüsseln zum Anschluß bei der Empfangsstellenvorrichtung, von der der Knotenpunktschlüssel erhalten wird, der einem Quellenknotenpunkt zugehört, von welchem eine Anschlußanfrage empfangen wird. 28. A method as claimed in any one of Claims 22 to 27 in which communication from the nodes to the headend apparatus is provided over a network up-channel and communication from the headend apparatus to the nodes is provided over a network down-channel to which each node apparatus is responsive to receive messages from the headend apparatus.
- 28Procédé selon l'une quelconque des revendications 22 à 27, dans lequel une communication depuis les noeuds vers l'appareil d'extrémité est établie sur un canal supérieur du réseau et une communication depuis l'appreil d'extrémité vers les noeuds est établie sur un canal inférieur du réseau auquel chaque appareil de noeud réagit en recevant des messages de l'appareil d'extrémité. 28. Verfahren nach einem der Ansprüche 22 bis 27, in welchem die Mitteilung von den Knotenpunkten an die Empfangsstellenvorrichtung über einen hinführenden Kanal des Netzwerkes geführt wird und die Nachricht von der Empfangstellenvorrichtung zu den Knoten über einen rückführenden Kanal des Netzwerkes gesendet wird, an welchen jede Knotenpunktvorrichtung entsprechend dem Empfang von Nachrichten von der Empfangsstellenvorrichtung angeschlossen ist. 29. A method as claimed in Claim 28 in which said up-channel and down-channel are defined by respective frequency bands carried by the network.
- 29Procédé selon la revendication 28, dans lequel ledit canal supérieur et ledit canal inférieurs sont définis par des bandes de fréquences respectives transmises par le réseau. 29. Verfahren nach Anspruch 28, in welchem der hinführende Kanal und der rückführende Kanal durch entsprechende Frequenzbänder, die im Netzwerk vorhanden sind, festgelegt werden. 30. A method of controlling the access to a CATV system of a terminal apparatus for use with the system, the system comprising a cable network having a plurality of source nodes to each of which is connectable such a terminal apparatus for sending messages transmitted via the network and a headend apparatus to which all messages placed on the network by such terminal apparatus is sent and which is operable to re-broadcast messages for receipt by destination nodes, each network source node having associated therewith a key a identifying that node, the access control method comprising:sending a request for network access from the terminal apparatus to said headend apparatus;receiving at the terminal apparatus an encrypted access code from the headend apparatus and decrypting the encrypted access code with the aid of the node's key, andusing the decrypted access code to generate and to insert a frame verifier code into each message frame that is sent from the terminal apparatus at a point in each such message frame that precedes at least a portion thereof.
- 30Procédé de commande de l'accès à un système CATV d'un appareil terminal destiné à ce système, le système comportant un réseau câble avec plusieurs noeuds source à chacun desquels peut être connecté un appareil terminal pour émettre des messages transmis par le réseau et un appareil d'extrémité vers lequel sont émis tous les messages placés sur le réseau par cet appareil terminal, et qui a pour fonction de rediffuser des messages pour qu'ils soient reçus par des noeuds de destination, chaque noeud source du réseau étant associé avec une clé qui l'identifie, le procédé de commande d'accès consistant:à émettre une demande d'accès au réseau par l'appareil vers ledit appareil d'extrémité;à recevoir à l'appareil terminal un code d'accès crypté provenant de l'appareil d'extrémité et à décrypter le code d'accès crypté à l'aide de la clé de noeud, et à utiliser le code d'accès décrypté pour produire et introduire un code de vérification de trame dans chaque trame de message qui est émise par l'appareil terminal en un point de chaque trame de message qui précède au moins l'une de ces parties. 30. Verfahren zum Steuern des Anschlusses an ein Kabelfernsehsystem eines Terminals zur Verwendung mit einem System, das ein Kabelnetzwerk umfaßt, welches eine Vielzahl von Knotenpunkten aufweist, wobei an jeden dieser Knotenpunkte ein Terminal anschließbar ist, um Nachrichten zu senden, die durch das Netzwerk übertragen werden, und eine Empfangsstellenvorrichtung, an welche alle Nachrichten gesendet werden, die in das Netzwerk durch derartige Terminals eingespeist werden, und welche dazu dienen, Nachrichten zum Empfang für die Empfangsknotenpunkte zurückzusenden, wobei jeder Netzwerkquellennotenpunkt einen ihm eigenen Identifikationsschlüssel aufweist, wobei das Verfahren zur Anschlußsteuerung folgende Schritte umfaßt: Senden einer Anfrage für den Netzwerkanschluß von dem Terminal an die Empfangsstellenvorrichtung;Empfangen eines verschlüsselten Anschlußcodes von der Empfangsstellenvorrichtung in dem Terminal und Entschlüsseln des verschlüsselten Anschlußcodes mit der Hilfe des Knotenpunktschlüssels, undVerwendung des entschlüsselten Anschlußcodes, um einen Rahmenbestätigungscode zu erzeugen und in jeden Nachrichtenrahmen einzusetzen, der von dem Terminal an den Punkt jedes solchen Nachrichtenrahmens gesendet ist, der zumindest einem Teil davon vorausgeht. 31. A method of controlling the access of a terminal apparatus as claimed in Claim 30 in which a series of frame verifier codes is generated from said decrypted access code.
- 31Procédé de commande de l'accès d'un appareil terminal selon la revendication 30, dans lequel une série de codes de vérification de trame est produite à partir dudit code d'accès décrypté. 31. Verfahren zur Steuerung des Anschlusses eines Terminals nach Anspruch 30, in welchem eine Folge von Rahmenbestätigungscodes aus den entschlüsselten Anschlußcodes erzeugt wird. 32. A method of controlling the access of a terminal apparatus as claimed in Claim 31 in which the next frame verifier code of the series is inserted into each next succeedcng message frame.
- 32Procédé de commande de l'accès d'un appareil terminal selon la revendication 32, dans lequel le code de vérification de trame suivant dans la série est introduit dans chaque trame de message suivant immédiatement. 32. Verfahren zur Steuerung des Anschlusses eines Terminals nach Anspruch 32, in welchem der folgende Rahmenbestätigungscode der Folge in jeden nächstfolgenden Nachrichtenrahmen eingesetzt wird, 33. A method of controlling the access of a terminal apparatus as claimed in Claim 31 or 32 in which first and second code segments are obtained from the decrypted access code and the first code segment is encrypted with the second to generate therefrom a sequence of a predetermined number of frame verifier codes, and further comprising incrementing said second code segment to a fresh value upon completion of said sequence whereby a further such sequence is generated using the fresh value of the second code segment.
- 33Procédé de commande de l'accès d'un appareil terminal selon la revendication 31 ou 32, dans lequel un premier et un second segments de code sont obtenus à partir du code d'accès décrypté, et le premier segment de code est crypté avec le second pour produire à partir d'eux une séquence d'un nombre prédéterminé de codes de vérification de trame, et consistant en outre à incrémenter ledit second segment de code à une nouvelle valeur à la fin de ladite séquence de manière qu'une autre séquence soit produite en utilisant la nouvelle valeur du second segment de code. 33. Vorrichtung zum Steuern des Anschlusses eines Terminals nach Anspruch 31 oder 32, in welchem erste und zweite Codeteile von den entschlüsselten Anschlußcode erhalten werden und das erste Codesegment mit dem zweiten verschlüsselt wird, um daraus eine Folge von einer vorherbestimmten Anzahl von Rahmenbestätigungscodes zu erhalten und wobei weiterhin des zweite Codesegment zu einem neuen Wert inkrementiert wird zur Vervollständigung der Folge, wobei eine weitere solche Folge unter Verwendung des neuen Werts des zweiten Codesegments erzeugt wird. 34. A method of controlling the access of a terminal apparatus as claimed in any one of Claims 30 to 33 in which communication to the headend apparatus is made over a network up-channel and communication from the headend apparatus is received over a network down-channel.
- 34Procédé de commande de l'accès d'un appareil terminal selon l'une quelconque des revendications 30 à 33 dans lequel une communication vers l'appareil d'extrémité est établie sur un canal supérieur du réseau et une communication depuis l'appareil d'extrémité est reçue sur un canal inférieur du réseau. 34. Verfahren zur Steuerung des Anschlusses eines Terminals nach einem der Ansprüche 30 bis 33, in welchem Nachrichten an die Empfangsstellenvorrichtung über einen hinführenden Kanal des Netzwerkes zugeführt werden und Nachrichten von der Empfangsstellenvorrichtung über einen rückführenden Kanal des Netzwerkes empfangen werden. 35. A method of controlling the access of a terminal apparatus as claimed in Claim 34 in which said up-channel and down-channel are defined by respective frequency bands.
- 35Procédé de commande de l'accès d'un appareil terminal selon la revendication 34, dans lequel ledit canal supérieur et ledit canal inférieur sont définis par des bandes de fréquences respectives. 35. Vorrichtung zum Steuern des Anschlusses eines Terminals nach Anspruch 34, in welchem der hinführende Kanal und der rückführende Kanal durch entsprechende Frequenzbänder festgelegt sind.
Independent claims35
87 paragraphs, as filed
This invention is concerned with digital communication utilizing a two way cable television (CATV) network. The invention relates to a CATV system of the kind comprising a cable network having a plurality of nodes to each of which is connected an apparatus for sending and/or receiving messages transmitted via the network, and a headend apparatus to which all messages placed on the network are sent and which is operable to re-broadcast messages for receipt by destination nodes, each network node having associated therewith a key identifying that node. The invention also relates to a terminal apparatus for use at a node in a CATV system and to a headend apparatus for use in a CATV system.
Two way CATV systems are well known. Techniques for utilizing the bidirectional nature of such networks for digital data transmission have been developed. For example, see U.S. Patent 3,803,491 to Osborn and U.S. Patent 4,245,245 to Matsumato et al. A wide variety of consumer services such as home banking, electronic mail and newspapers, shop at home, and the like, are envisioned to become commonplace.
However, the systems developed to date have failed to achieve widespread use. One of the reasons for the lack of general acceptance is that prior art systems centralize digital communication at the headend of the CATV system. That is digital messages are exchanged between the headend and the user nodes. Such concentration of network intelligence at the headend node has several disadvantages.
Firstly, a centralized network design requires that many participants, particularly the cable operator, the service provider, and the equipment manufacturer, undertake coordinate activities simultaneously to assure that equipment and data formats are compatible. The reluctance of each individual party to act until a settled system architecture emerges has been an important factor in the delayed development of two way CATV data services. Also, a centralized network architecture results in complex and cumbersome headend equipment. The headend software in such prior art systems is typically multi-tasking in order to process different data services simultaneously. Therefore, adding new services to existing services can be difficult. Furthermore, as entirely new services are added to the system, the capability of a centralized system may be exceeded, requiring that the entire headend architecture be redesigned to accommodate all of the desired services.
Furthermore, system reliability is compromised when system intelligence is centralized. A single failure at the headend can disable all of the two way CATV services.
Finally, in a centralized system, the cable system operator is closely involved with the service providers and is burdened with such problems as information privacy, data integrity and disputes over rights of access to consumers by competing service providers. Such designs require many participants to undertake coordinated activities simultaneously.
A CATV system of the kind set out above is described in U.S. Patent 3,688,307. However, the system of this patent does not meet the requirements set out above, and in particular does not include adequate measures to ensure that an unauthorized user cannot gain access to the system. One facet of preventing unauthorized access lies in preventing such a user obtaining identification codes from information being transmitted over the network by authorized users and thereby using such information to falsely identify himself as an authorized user. This problem is not addressed by U.S. Patent 3,688,307.
The use of data encryption to prevent unauthorized tapping of terminals communicating with computers is well established. An example is found in U.S. Patent 3,798,605 which encrypts data from a terminal with the aid of a user password. However, this system is not concerned with the control of access to the computer even less the control of access to a network on which a variety of services may be provided. U.S. Patent 4,310,270 is another example of terminal-to-computer communication which inherently assumes the establishment of the communication link between the two user nodes, namely the terminal and the computer. It cannot be compared with the provision of a CATV system network. This specification describes access control with the use of a password and randomly generated codes. The user terminal has the same password at all times.
The system assumes that the terminal and computer generate the same pseudorandom number on each access. If that should fail, the whole system becomes unusable. The system does not prevent the gaining of access to the communication link itself such that an unauthorized user would be prevented from gaining entry to the computer at all.
Reverting to the particular requirements of two way CATV systems, there is a need for a CATV system in which the degree of coordination mentioned above is obviated. The aim is that the CATV system operator can provide transparent data transport service, which data transport service can in turn be utilized by individual entrepreneurs, or the CATV operator, to provide specific value added services.
There will be described hereinafter a CATV system embodying the present invention that provides for decentralized system intelligence. System growth at the headend or at the nodes is modular, allowing either rapid or slow development of the overall system. In other words, the CATV system operator can establish a communication system offering defined interfaces for transparent data transport service at the user nodes. The channel capacity of the headend may be expanded, but its architecture (both hardware and software) remains the same as the overall system develops. The further development of various consumer services and information appliances, both of known types, and of those yet to be invented, can continue at the node interfaces, and without further architectural changes at the headend.
Decentralized network intelligence results in less complex headend equipment. The headend can be initially equipped with a few data channels. Additional data channel capacity can be easily added as the communication data traffic load increases.
New services are readily accommodated in the system to be described by adding equipment at the server nodes which may be located anywhere in the network. For example, a new server node for electronic funds transfer can be located at the bank providing such service.
Although the complexity of each server node depends on the complexity of the specific service, server node software will generally be simplified (compared to a centralized system) due to the single task nature of a single service.
System reliability is enhanced in the system of the invention described below because equipment failure at one server node affects only that service and does not interrupt the services provided by the remaining server nodes. Similarly, a heavy data traffic load for one service does not substantially effect the service response time of the other server nodes.
Finally, a decentralized intelligence communication system tends to disassociate the CATV operator from the service provider. Issues involving information privacy and data integrity become the responsibility of the service vendor. The CATV operator simply offers transparent data transport service to be used as desired by the service provider.
Broadly stated the present invention provides in one aspect a CATV system comprising a cable network having a plurality of nodes to each of which is connected an apparatus for sending and/ or receiving messages transmitted via the network and a headend apparatus to which all messages placed on the network by source nodes are sent and which is operable to re-broadcast messages for receipt by destination nodes, each network node having associated therewith a key identifying that node, characterised in that each source node apparatus comprises: means for sending a request for network access to said headend apparatus; <ul id="ul0001" list-style="none"><li>means for receiving an encrypted access code from the headend apparatus;</li><li>means for decrypting the encrypted access code with the aid of the node's key, and</li><li>means for using the decrypted access code to generate and to insert a frame verifier code into each message frame that is sent at a point in each such message frame that precedes at least a portion thereof;</li><li>and further characterised in that</li><li>said headend apparatus comprises:</li><li>means responsive to an access request received from a source node to generate an access code,</li><li>means for encrypting the access code by use of the key identifying the source node,</li><li>means for placing the encrypted access code on the network for transmission to the source node,</li><li>means responsive to the access code to generate therefrom a frame verifier code for each message frame received from the source node that corresponds to the frame verifier code in the received message frame,</li><li>means for comparing the frame verifier code inserted in each message frame received from a source node with a corresponding frame verifier code generated in the headend apparatus, said comparison means providing an inhibit signal if the compared frame verifier codes do not match, and</li><li>means operable to re-broadcast each received message frame onto the network and responsive to an inhibit signal to inhibit re-broadcasting of the portion of the message frame that followed the frame verifier code that gave rise to the inhibit signal.</li></ul>
Preferably the respective means for generating frame verifier codes of the source node apparatus and the headend apparatus is operable to generate, from the decrypted access code, a series of frame verifier codes, the frame verifier codes generated in the headend apparatus corresponding to those generated in the source node apparatus. More preferably the means for generating the series of frame verifier codes in the source node apparatus is operable to insert the next frame verifier code of the series into each next succeeding message frame. In the headend apparatus, its means for generating frame verifier codes is operable to provide a series of such codes corresponding to that inserted into the message frames.
The system of the invention as implemented in the embodiment described below, provides transmission of each message frame through the headend apparatus unless the message frame verifier code fails to match that generated at the headend apparatus. In this latter instance transmission of the message frame is inhibited. The network with its headend apparent is thus transparent to the service being provided or used subject to the checking of authorized use. The system also does not require the identification key to be transmitted over the network other than in encrypted form.
More particularly the system to be described has the following additional features for generating the frame verifier codes. In the headend apparatus, <ul id="ul0002" list-style="none"><li>the access code generating means comprises means for generating first and second code segments, the first segment constituting a network access identification code allotted to the source node requesting access to the network, and means for combining the two code segments to form the access code for transmission to the source node. The frame verifier code generating means is responsive to the first and second code segments to encrypt the first code segment with the second to generate therefrom a sequence of a predetermined number of frame verifier codes, and includes means for incrementing the second code segmentto a fresh value upon completion of said sequence whereby a further such sequence is generated using the fresh value of the second code segment. In the source node apparatus,</li><li>the means for generating the frame verifier codes is operable to obtain the first and second code segments from the decrypted access code and to encrypt the first code segment with the second to generate therefrom a sequence of a predetermined number of frame verifier codes corresponding to the sequence generated in said headend apparatus. It further comprises means for incrementing said second code segment to the aforesaid fresh value upon completion of said sequence whereby the aforesaid further such sequence is generated using the fresh value of the second code segment.</li><li>More preferably, the first and second code segments are generated as random numbers. As will be described below, the headend apparatus has associated with it a directory of node keys from which is obtained the node key pertaining to a source node from which an access request is received. It will be realised that such a system provides a considerable security against unauthorized access. As already stated the node key is not itself transmitted. The encrypted access code which it aids in encrypting relies on numbers (code segments) generated at the headend apparatus and these can be random since the numbers need not be separately generated at a source node but are obtained by decryption at the source node. This allied to the preferred practice of changing the frame verifier code for each message frame makes unauthorized entry into the system by monitoring message frames extremely difficult.</li><li>In the system to be described, there is extensive use of computers for performing system functions which are under the control of appropriate software routines.</li></ul>
In another aspect of the invention there is provided a terminal apparatus for use with a CATV system comprising a cable network having a plurality of source nodes to each of which is connectable such a terminal apparatus for sending messages transmitted via the network and a headend apparatus to which all messages placed on the network by such terminal apparatus is sent and which is operable to re-broadcast messages for receipt by destination nodes, each network source node having associated therewith a key identifying that node, said terminal apparatus being characterised by: <ul id="ul0003" list-style="none"><li>means for sensing a request for network access to said headend apparatus;</li><li>means for receiving an encrypted access code from the headend apparatus;</li><li>means for decrypting the encrypted access code with the aid of the node's key,</li><li>means for using the decrypted access code to generate and to insert a frame verifier code into each message frame that is sent at a point in each such message frame that precedes at least a portion thereof.</li></ul>
In yet another aspect of the invention there is provided a headend apparatus for use in a CATV system comprising a cable network having a plurality of nodes to each of which is connected an apparatus for sending and/or receiving messages transmitted via the network and a headend apparatus to which all messages placed on the network by source nodes are sent and which is operable to re-broadcast messages for receipt by destination nodes, each network node having associated therewith a key identifying that node, and each source node apparatus comprising means for sending a request for network access to said headend apparatus; means for receiving an encrypted access code from the headend apparatus; means for decrypting the encrypted access code with the aid of the node's key, and means for using the decrypted access code to generate and to insert a frame verifier code into each message frame that is sent at a point in each such message frame that precedes at least a portion thereof; <ul id="ul0004" list-style="none"><li>the headend apparatus comprising:</li><li>means responsive to an access request received from a source node to generate an access code,</li><li>means for encrypting the access code by use of the key identifying the source node,</li><li>means for placing the encrypted access code on the network for transmission to the source node,</li><li>means responsive to the access code to generate therefrom a frame verifier code for each message frame received from the source node that corresponds to the frame verifier code in the received message frame,</li><li>means for comparing the frame verifier code inserted in each message frame received from a source node with a corresponding frame verifier code generated in the headend apparatus, said comparison means providing an inhibit signal if the compared frame verifier codes do not match, and</li><li>means operable to re-broadcast each received message frame onto the network and responsive to an inhibit signal to inhibit re-broadcasting of the portion of the message frame that followed the frame verifier code that gave rise to the inhibit signal.</li><li>Further aspects of the invention are concerned with methods of controlling access to a CATV system.</li></ul>
In one such further aspect of the invention there is provided a method of controlling access to a CATV system comprising a cable network having a plurality of nodes to each of which is connected an apparatus for sending and/or receiving messages transmitted via the network and a headend apparatus to which all messages placed on the network by source nodes are sent and which is operable to re-broadcast messages for receipt by destination nodes, each network node having associated therewith a key identifying that node, characterised in that the method of controlling access comprises the steps of: <ul id="ul0005" list-style="none"><li>sending a request from a source node apparatus for network access to said headend apparatus;</li><li>generating an access code in the headend apparatus in response to an access request received from the source node,</li><li>encrypting the access code by use of the key identifying the source node,</li><li>placing the encrypted access code on the network for transmission to the source node,</li><li>receiving the encrypted access code from the headend apparatus at the source node apparatus and decrypting the encrypted access code with the aid of the node's key, and</li><li>using the decrypted access code to generate and to insert a frame verifier code into each message frame that is sent from the source node apparatus at a point in each such message frame that precedes at least a portion thereof;</li><li>generating from the access code at the headend apparatus a frame verifier code for each message frame received from the source node that corresponds to the frame verifier code in the received message frame,</li><li>comparing at the headend apparatus the frame verifier code inserted in each message frame received from a source node with a corresponding frame verifier code generated in the headend apparatus, and</li><li>re-broadcasting each received message frame onto the network unless the compared frame verifier codes do not match, and in the latter case inhibiting re-broadcasting of the portion of the message frame that followed the frame verifier code in the message that did not match that of the headend apparatus.</li></ul>
In yet another such further aspect of the invention there is provided a method of controlling the access to a CATV system of a terminal apparatus for use with the system, the system comprising a cable network having a plurality of source nodes to each of which is connectable such a terminal apparatus for sending messages transmitted via the network and a headend apparatus to which all messages placed on the network by such terminal apparatus is sent and which is operable to re- broadcast messages for receipt by destination nodes, each network source node having associated therewith a key identifying that node, the access control method comprising: <ul id="ul0006" list-style="none"><li>sending a request for network access from the terminal apparatus to said headend apparatus;</li><li>receiving at the terminal apparatus an encrypted access code from the headend apparatus and decrypting the encrypted access code with the aid of the node's key, and</li><li>using the decrypted access code to generate and to insert a frame verifier code into each message frame that is sent from the terminal apparatus at a point in each such message frame that precedes at least a portion thereof.</li><li>In order that the invention and its practice may be better understood the CATV system outlines above and methods of operating same in accord with the invention will now be further described with reference to the accompanying drawings, in which:</li><li>Figure 1 is a graphical representation of bandwidth allocation in a two way CATC system;</li><li>Figure 2 is a block diagram of headend apparatus embodying the present invention;</li><li>Figure 2a is a block diagram of the modem portion of a subscriber terminal unit including a network access unit;</li><li>Figure 3 is a block diagram illustrating a CATV communication system embodying the present invention;</li><li>Figure 4 is a block diagram illustrating two CATV systems linked together in a CATV communication system embodying the present invention;</li><li>Figure 5 is a representation of a data encryption and decryption process used in the system;</li><li>Figure 6 is a flow chart representing a program for generating channel access codes in the network access controller;</li><li>Figure 7 is a flow chart representing a program for generating frame verifier codes in a terminal at a network user node embodying the present invention;</li><li>Figure 8 is a flow chart representing a program for checking a frame verifier code in the data channel access monitor at the headend of a CATV communications system embodying the present invention;</li><li>Figure 9 is a representation of a generalized protocol architecture for use in conjunction with the present invention;</li><li>Figure 10 illustrates the message format used in conjunction with the system described; and</li><li>Figures 11 a through 11f illustrate the sequence of messages exchanged in order to initiate and terminate a communication session between a source node and a destination node in a CATV system embodying the present invention.</li></ul>
Description of an embodiment of the invention A typical CATV system is capable of propagating a range of signal frequencies, for example, from 5 MHZ to 400 MHZ. Signal frequencies above 50 MHZ are reserved for distributing signals from the headend to the subscriber terminals (i.e. in the downstream or forward direction). Signal frequencies below 50 MHZ are reserved for propagating signals from individual subscriber terminals to the headend (i.e. in the upstream or return direction).
A bandwidth allocation for use in conjunction with the present invention is graphically illustrated in Figure 1. The upstream band 2 is 25 MHZ wide and extends from 5 MHZ to 30 MHZ. The downstream band 4 is also 25 MHZ wide and may be selected from any convenient band of frequencies in the downstream portion of the frequency spectrum.
The topology of a typical CATV system is that of an inverted tree. The headend is at the top of the inverted tree and the subscriber terminals are located throughout the trunk and branches. A signal from the headend in the forward direction is heard by all subscriber terminals. However, a signal transmitted from an individual subscriber terminal in the return direction is heard only by that portion of the other subscriber terminals that are in the signal propagation path from the transmitting subscriber terminal to the headend. Therefore, the signal transmitted from a particular subscriber terminal is heard by only a portion of the other subscriber terminals.
Each signal frequency in the return band 2 is paired with a corresponding signal frequency in the forward band 4. The headend includes apparatus for receiving the return signal in the upstream band, and selectively rebroadcasting the signal at a higher corresponding frequency in the forward band. In such manner, a signal from an individual subscriber terminal (in the return band) is heard by all the other subscriber terminals (in the forward band) thereby permitting any individual subscriber terminal to transmit a message to any other subscriber terminal within the CATV system.
Digital signals are transmitted in the present system by the use of frequency shift keyed (FSK) modulation. A digital signal has one of two binary logic states, i.e. 1 or 0. When the digital signal is at a logical 1, an FSK modulator transmits a signal of first frequency and when the binary signal is at a logical 0, an FSK modulator transmits a signal at a second frequency. Similarly an FSK demodulator is responsive to an FSK signal to reproduce the original digital signal.
A headend apparatus is shown in Figure 2. A data channel access monitor (DCAM) 10 comprises individual data channel access monitor modules 11a, 11b, etc., a network access controller interface processor 18 and a modem 20. An individual data channel access monitor module 11a comprises FSK demodulator 12, frame verifier logic 14, and FSK modulator 16. The FSK demodulator 12 is tuned to a particular frequency in the return band. The FSK modulator 16 is tuned to a corresponding paired frequency in the forward band. The frame verifier logic 14 examines the received data and selectively connects the output of the FSK demodulator 12 to the input of the FSK modulator 16. The FSK modulator 16 rebroadcasts the received signal in real time at a corresponding higher frequency in the forward portion of the cable spectrum. The frame verifier logic 14 also interfaces with the network access controller interface processor 18 which provides two way communication to the network access controller via modem 20. The operation of the frame verifier logic 14 will be described in more detail in conjunction with the description of Figure 8.
The modem portion of a subscriber terminal apparatus is shown in Figure 2a. A network access unit modem 13 comprises an FSK modulator 19, an FSK demodulator 15, carrier sense and collision detection circuitry 3, frequency control 17 and a microprocessor 21.
In operation, a digital signal from a source 23 is received by microprocessor 21. Microprocessor 21 formats the digital data into a frame message and includes a frame verifier (FV) code (described in conjunction with the detailed description of Figure 7) as part of the frame message format. The frame message is applied to FSK modulator 19 which transmits the frame message as an FSK signal on cable 25 in the upstream direction to the headend.
At the headend 10 (Figure 2), FSK demodulator 12 receives the encoded frame message. The frame message is examined in frame verifier logic 14. If the received frame verifier (FV) code indicates that the user is unauthorized, the frame verifier logic 14 blocks the further transmission of the frame message. However, if the frame verifier code indicates that the user is authorized, then the frame verifier logic continues to apply the frame message to FSK modulator 16 which transmits (rebroadcasts) the frame message in real time as an FSK signal in the downstream direction from the headend 10 to all subscription terminals.
The frame message is received by a network access unit (NAU) modem similar to the NAU modem 13 in Figure 2a. FSK demodulator 15 receives the rebroadcast frame message (FV) and forwards the received data to microprocessor 21. Note that the FSK demodulator 15 permits the NAU modem to monitor its own transmission as well as receive data from other network access units.
In order to share CATV communication resources among many users, the allocated return spectrum space is divided in 80 FSK data channels, each capable of transmitting 128 Kb/s. The forward spectrum space is similarly divided into 80 FSK data channels, forming 80 channel pairs in the system. However, a CATV system may have as little as one DCAM module 11 a (Figure 2). As the data traffic load increases, the CATV system operator may increase capacity by adding additional modules 11b, etc. Thus, communication capacity is increased without architectural changes at the headend.
Each subscriber terminal NAU is assigned a home channel. Naturally, for two subscriber units to communicate they must both be on the same data channel. Therefore, each NAU modem is frequency agile, i.e. able to change its upstream transmitting frequency (and its corresponding downstream receiving frequency) upon command from a system control computer called a network resource manager.
Furthermore, the present system permits many users to share the same data channel. Channel sharing is achieved by a technique known to those skilled in the art as carrier sense multiple access with collision detection (CSMA/CD).
Briefly, CSMA/CD is a contention mechanism by which many users share a common data channel. All users monitor the data channel to sense a carrier signal. A user node that desires to transmit a message waits until the channel is clear, and then transmits its message on the data channel. In the event that two users attempt to transmit at the same time, a collision occurs. The collision is detected by the users that have attempted to transmit. Each user then waits a random length of time before attempting to retransmit its respective message.
A CATV system embodying the present invention is shown in Figure 3. Such system comprises a headend including conventional one way CATV broadcasting equipment 22 which provides regular video programming material to all subscribers. The signal distribution path includes trunk cables 24, distribution amplifiers 26, feeder lines 28, and ultimately drop lines 29 to individual system nodes 31.
There are several types of individual system nodes. User nodes are nodes where access to CATV communication resources is provided. Of the user nodes, there are two types: server nodes 46 (for service providers) and subscriber nodes 48 (for service consumers). Another type of system node is a control node, where control over the CATV communication system (e.g. network access control, billing for communication service, etc) is provided. Finally, there are network nodes including a link node 50 for communication between CATV networks, and a gateway node 52 for communication between the CATV network and foreign networks, such as the switched public telephone network.
A server node 40 communicates with a subscriber node 44 through respective network access units (NAU) 38 and 42. In such cases, the CATV system provides basic data transport service so that the CATV system appears transparent to the server 40 and subscriber 44. For example, the service provider can provide an asynchronous RS-232 server node apparatus 40 and a compatible asynchronous RS-232 subscriber node apparatus 44.
A server node 46 and a subscriber node 48 may incorporate (in addition to a respective NAU) a higher level of communication service such as a full videotex implementation including graphics capability. In such case, the server node 46 need only provide a videotex compatible application service. The subscriber node 48 hardware (and software) can thus be utilized by many different service providers.
System control nodes comprise a data channel access monitor (DCAM) 10 at the headend, a network access controller (NAC) 34, a network resource manager (NRM) 36, and a network traffic monitor (NTM) 32. System control nodes communicate over the CATV system in the same manner as subscriber and server nodes. In addition there is a two way, out of band data channel 30 between the NAC 34 and the DCAM 10. Messages on the out of band channel 30 between the NAC 34 and the DCAM 10 are not generally broadcast on the CATV network. Also, system control nodes 32, 34, and 36 may be located anywhere within the CATV system, except for the DCAM 10 which is located at the headend.
The network access controller (NAC) 34 is a specially programmed computer. The primary function of the NAC 34 is to grant or deny network access to user nodes. When network access is granted, a channel access code (CAC) is provided to the user node. When network access is denied, a reason is provided (eg, channel busy, etc.) to the user node. The generation and transmission of channel access codes is described in conjunction with the description of Figure 6.
The network resource manager (NRM) 36 is another specially programmed computer. An important function of the NRM 36 is to allocate communication resources among the various users. One way this is achieved is by load leveling, ie by returning the individual user modems (FSK modulator and FSK demodulator) so that the data traffic load is more evenly distributed among the available data channels.
A second important function of the NRM 36 is to provide a directory look up service for user nodes. That is, the NRM 36 maintains a listing of currently assigned data channel frequencies (i.e. the original home channel frequency or a reassigned channel frequency) of each user node, as well as the address and symbolic name of that node. Thus, as will be further detailed in following descriptions, a user node can obtain the address and data channel frequency of a desired destination node by opening a communication session with the NRM 36.
The network traffic monitor (NTM) 32 is a third specially programmed computer. The NTM 32 is a passive information collector that listens on all data channels and collects information of usage of CATV communication resources. The information collected has two primary uses: (1) Billings for data communication service are generated during non-peak traffic hours, and (2) channel traffic statistics are provided to the NRM 36 for purposes of traffic management in allocating CATV bandwidth, i.e. load leveling.
A link node 50 provides intra-network communication between two CATV networks to form a single address space for CATV digital communication. As shown in Figure 4, two CATV networks 54 and 56 are interconnected by link nodes 50a and 50b. One CATV system 54 includes DCAM 10a, NRM36, NTM 32 and NAC 34. The other CATV system includes DCAM 10b.
In its simplest form, links 50a and 50b perform one to one mapping of specific messages between CATV system 54 and 56. Link 50a receives downstream data. The received data is applied to link 50b which in turn retransmits the data in the upstream direction in CATV system 56. Thus, by the use of link nodes 50a and 50b the CATV system 54 and the CATV system 56 form a single data network having a common address space in which any node from either system may communicate with any other node.
Within a single CATV data network, each node is assigned a unique 24 bit address. Messages that are intended for reception by a particular destination node, contain the address of the destination node. All nodes monitor at least one data channel. When the address of the destination node is recognized, the whole message is received for further processing.
In addition to the address of a particular node, each node is assigned a secret 56 bit number called a node key. The node key is a security measure designed to prevent unauthorized users from obtaining access to CATV communication resources. Unlike the node address, the node key is never transmitted on the CATV system. Furthermore, the number of possible node keys, 2<sup>56</sup>, is very large and sparsely populated so that the probability of guessing a valid node key is very small.
As a brief overview of system operation (Figure 3), consider the typical situation, wherein a source node 44 is to communicate with a destination node 40 (Figure 3).
The source node first obtains channel access by the following process: <ul id="ul0007" list-style="none"><li>1. The source node signals the headend (DCAM) with a network access request (no FV code attached).</li><li>2. The DCAM 10 forwards the network access request to the NAC 34, on the out of band channel 30 (no FV code required).</li><li>3. The NAC 34 transmits an encrypted channel access code (CAC) to the source node. A valid FV code relative to the NAC 34 is transmitted with the NAC message so that it can pass through the DCAM at the headend.</li></ul>
The source node decrypts the CAC, which is used by the source node to generate its own FV codes. The source node has thus obtained permission to utilize the requested data channel.
After the source node 44 obtains channel access, it can then establish a signal path connection with a desired destination node 40 by the following routing process: <ul id="ul0008" list-style="none"><li>1. The source node signals the NRM 36 (now with FV code attached). The message to the NRM 36 includes the symbolic name of the desired destination node.</li><li>2. The NRM 36 looks up the destination node name in its directory and responds with the channel frequency and address of the desired destination node. A valid FV, code, relative to the NRM 36 is transmitted with the NRM message so that it can pass through the DCAM at the headend.</li><li>3. If the channel frequency of the destination node 40 is different than that of the source node 44, the source node 40 changes its frequency to that of the destination node and repeats the above process for network access on the destination channel frequency.</li><li>4. The source node 44 then signals the destination node 40 with a session open request.</li><li>5. The destination node 40 receives the session open request, and, if necessary, obtains a channel access code by the above stated process for obtaining channel access. The destination node can then respond with a session open acknowledgement message.</li></ul>
At the end of this process, the source node 44 and the destination node 40 are on the same data channel thereby establishing a signal path connection between them. The two nodes 40 and 44 can continue a communication exchange until the session is terminated by appropriate messages.
In order to protect the security of channel access codes, and prevent eavesdroppers from discovering valid FV codes, a double data encryp- tion/decryption scheme is provided. The basic data encryption used is the Data Encryption Standard (DES) adopted by the National Bureau of Standards, Washington D.C. Briefly, as illustrated in Figure 5, the DES scheme permits a 64 bit input 104 to be either encrypted or decrypted into a 64 bit output 106 by use of a 56 bit key 102. Control line 108 determines whether an encryption or a decryption process is taking place.
To encrypt a 64 bit input 104, the control line 108 is set for an encryption. A 56 bit key 102 is loaded into the logic 100. Then, a 64 bit input 104 is loaded into the logic, and a 64 bit output 106 of encrypted data thereafter becomes available. For decryption, the control line 108 is set for a decryption, a 56 bit key 102 is loaded into the logic 100, a 64 bit encrypted input is loaded into the logic 100, and the 64 bit output 106 is thereafter available. Standard integrated circuits are commercially available for implementing DES in hardware. However, it is anticipated that the DES encryption and decryption will be carried out in software.
A flow chart representing the program in the NAC 34 (Figure 3) for generating channel access codes (CAC) is illustrated in Figure 6. First, a 56 bit random number called an access key is generated at step 60. Next, a 64 bit random number is generated as an initial value (IV) at step 62. The access key and the IV together form the 120 bit channel access code (CAC), as shown in step 64. The CAC is transmitted via the out of band channel to the DCAM at the headend at step 66. Furthermore, the CAC is encrypted by the NAC 34 using the user's secret node key, and transmitted to the user node at step 68.
A flow chart representing the program in a user network access unit (eg NAU 42 in Figure 3) for generating frame verifier (FV) codes is illustrated in Figure 7. First, the user NAU node that desires to obtain channel access transmits a channel access request at step 70. The channel access request is processed by the NAC which generates an encrypted CAC in accordance with the program flow chart of Figure 6, previously described. The encrypted CAC is received at the user NAU at step 72. The user NAU decrypts the 120 bit CAC using its own secret node key as the decryption key, which provides a 56 bit access key and a 64 bit initial value (IV), at step 74. The 64 bits of IV are encrypted using the 56 bit access key to produce a 64 bit output at step 76. The latter 64 bits provide eight frame verifier codes (FV) of 8 bits each. The user NAU transmits one of these eight FV codes in each of its next eight transmitted frame messages. Each frame message also includes a frame sequence (FS) number which is incremented once for each message transmitted. After eight FV codes have been transmitted for the next eight messages, the IV code is incremented and re-encrypted using the access key to produce an additional eight FV codes to be used for the next eight consecutive frame messages.
The intended purpose of the present arrangement using FV codes based in part on frame sequence, random numbers, and a secrete node key to prevent unauthorized users from obtaining CATV communication resources, or from otherwise tampering with the network control. The FV code changes for each successive frame message. Therefore, an eavesdropper cannot reuse as FS number and an FV code known to be valid. Furthermore, the FS number is included to assure synchronization of FV codes between the transmitting node and the DCAM.
A flow chart representing the program in the frame verifier logic 14 (Figure 2) for checking FV codes at the headend DCAM is shown in Figure 8. A channel access request is received at the headend at step 80. The channel access request is forwarded out of band to the NAC at step 82. The NAC responds by transmitting an unencrypted CAC out of band which is received at the DCAM at step 84. The CAC is used to encrypt the IV code with the access key (as previously described) to generate eight FV codes at step 86. A frame sequence (FS) number is associated with each of the eight FV codes.
In operation, messages are received by the DCAM at the headend which compares the received FS and FV codes with that previously calculated for the particular NAU address, at step 88. If the FS and FV codes are not equal to the previously computed FS and FV codes, the frame verifier logic 14 (Figure 3) prevents the upstream signal from being rebroadcast downstream to the system at step 90. If the FS and FV codes are equal to the previously computed FS and FV codes, the upstream message is rebroadcast on the corresponding downstream channel frequency at step 92. After the last of the computed eight FV codes has been utilized at step 94, the IV code is incremented at step 96. The incremented value of IV is encrypted using the access key to produce a new table of eight additional FV codes at step 86.
The system operation described thus far relates to establishing the basic two way signal path connection between two nodes in a CATV communication system. Figure 9 illustrates a layered protocol architecture which also includes higher level system functions. The layered architecture of Figure 9 closely conforms to the reference model for Open Systems Interconnection (OSI) developed by the Internation Standards Organization, Geneva, Switzerland.
In Figure 9, a basic frame message 120 is transmitted through the physical medium (the CATV system) from a source node to a destination node. The frame message 120 is arranged in nested layers. Specifically, the ultimate "data to be transferred" is in the application layer 132. The application layer 132 is nested within the presentation layer 130. The presentation layer 130 is nested within the session layer 128, which is nested within the transport layer 126 and so on through the network layer 124 and the link layer 122. In general, each layer includes a header such as header 130a (which precedes the application data 132) and a trailer such as trailer 130b (which follows the application data 132). However, at any given layer, the respective header may be minimal and the respective trailer may be nonexistant.
The transmitting node (source) assembles the frame message 120 before transmission through the physical medium.
The receiving node (destination) disassembles the frame message 120 one layer at a time. First, the destination node strips the link layer from the message. The "data" of the link layer is the network layer 124. The "data" of the network layer is the transport layer 126, and so on up to the application layer. Each layer of the protocol is assigned specific system communication functions as briefly outlined below.
The link layer performs basic communication functions such as CSMA/CD control, generation and checking of error detection codes, source and destination node addressing within the same CATV system, and generation of frame verifier codes.
The network layer specifies routing instructions between the source and destination nodes located in different CATV systems. The network layer information is roughly analogous to a telephone number that informs the communication network control nodes how to route the message from the source to the ultimate destination.
The transport layer governs the data flow between the source and destination nodes once a signal path connection has been established. Typical functions of the transport layer include acknowledgement of received packets, instruction as to the maximum number of packets to be transfered, and the controlled reliable transmission of packets.
The session layer is used to initiate a communication session. In this sense, the network resource manager (NRM 36 in Figure 3), previously discussed, is a specialized session layer entity. The functions controlled by the session layer include symbolic addressing, and determination of data channel routes from source to destination nodes.
The presentation layer controls the formatting of data for presentation to the user. For example, the source may interrogate the destination node to inquire as to whether the destination terminal has graphic display capability or only alphanumeric capability. A presentation level protocol suitable for use in conjunction with the present invention is disclosed in "Videotex Standard Presentation Level Protocol" published by the AT&T Press, May 1981.
The application layer includes the programs and information that is of service to the user. For example, in an electronic banking application, the application layer would contain the specific instructions for an electronic funds transfer.
Figure 10 shows the frame format of the link layer protocol. A frame consists of an 8 bit flag 134, a 24 bit destination address 136, a 24 bit source address 138, an 8 bit control field 140, a link level message 142, a 16 bit cyclic redundancy code (CRC) 144, and an 8 bit flag 146. A CRC 144 is an error detecting code. A specific CRC suitable for use in the present system is the CCITT standard adopted by the International Telegraph and Telephone Consultive Committee, Geneva, Switzerland. The flag 134 is a synchronizing code (01111110) to indicate the start of a frame message. The destination address 136 indicates the address of the destination node. In this regard, the source and destination nodes are defined in relation to the transmitting and receiving nodes respectively.
The code in the control field 140 defines the content of the following link level message 142 which contains other defined fields. For example, the control field may specify that data is to follow. In such case, the link level message 142 would contain a frame sequence (FS) number, a frame verifier (FV) code, and data which would be used in the higher layers of the protocol architecture. The control field 140 may indicate a channel (access) request to the NAC 34 (Figure 3), in which case the link level message 142 would contain no additional fields. The control field 140 may indicate channel relinquish command, in which case an FS number and an FV code would follow. The control field 140 may indicate a channel grant message, in which case an FS number, an FV code and an encrypted channel access code (CAC) would follow. The control field 140 may indicate that the message is a channel denial command, in which case the link level message 142 would include an FS number, an FV code, and a reason for denial of channel access. A user may be denied channel access because that user is not authorized to access CATV communication resources, or that the channel is busy due to heavy traffic.
As previously stated, the frame verifier logic 14 in the DCAM 10 (Figure 2) checks the FV code in the frame message while rebroadcasting the frame message in real time. Thus, the FV code must be checked before the entire message is rebroadcast. The worst case timing therefore occurs when the link level message contains no data. The frame verifier logic in the DCAM has 47 bit times (the 8 bit control field plus the 8 bit FS number, plus the 8 bit FV code, plus the 16 bit CRC, plus the 8 bit flat, minus 1 bit) to compare the received FV code with the previously computed FV code. At 128 kb/s this is about 400 microseconds.
Figures 11 a through 11f illustrate the sequence of messages exchanged between a source and destination node in order to initiate a communication session. For clarity, the message formats illustrated in Figures 11a a through 11f illustrate only those portions of the link layer and session layer protocol necessary for the conceptual understanding of the sequence of events.
Assume that source node 150 (Figure 11a) is to establish a communication session with destination node 152 (Figure 11f). First, the source node transmits a network transport request message 160 to the DCAM 10 at the headend on the source home channel frequency. The message 160 consists of a flag followed by the source node address followed by a code for a network transport request. No FV code is attached. The DCAM 10 acknowledges the transport request with a message 162 consisting of a series of flags.
The source node obtains a CAC as shown in Figure 11b. The DCAM 10 forwards the network transport request in message 164 on an out of band channel to the network access controller (NAC) 34. The NAC 34, after checking the traffic loading on the source home channel, may or may not grant access. Assuming that the NAC 34 will grant channel access to the source node 150, a message 166 is transmitted out of band back to the DCAM 10 at the headend. The latter message 166 consists of the source node address, and the unencrypted channel access code (CAC) for the source node. Also. the NAC 34 transmits to the source node 150, through the DCAM 10 on the source home channel, a message 168. The message 168 consists of a flag followed in sequence by: the source node 150 address, the NAC 34 address, the FS number for the NAC, the FV code for the NAC, an acknowledgement, and a CAC encrypted using the secret node key of the source node as the encryption key. Message 168 is rebroadcast by the DCAM 10 to the source node 150 after checking the respective FS number and FV code.
The source node 150 then opens a session with the NRM 36 as shown in Figure 11c. First, the source node 150 transmits a message 170 consisting of a flag followed in sequence by: the address of the NRM 36, the source address, the FS number for the source node, the FV code for the source node, and a session open request. This message 170 is checked in the DCAM 10 for proper FS number and FV code and rebroadcast downstream to the NRM 36. The NRM 36 responds with an acknowledgement message 172 consisting of in sequence: a flag, the source node address, the NRM address, the FS number for the NRM 36, the FV code for the NRM 36, and a session opened acknowledgement.
After the session is opened, the source node 150 obtains the address of the desired destination node and the appropriate destination channel frequency as shown in Figure 11d. The source node 150 transmits message 174 consisting of in sequence; a flag, the NRM 36 address, the source node address, the FS number for the source node, the FV code for the source node, the session request code, and the destination name or destination address. The NRM 36 responds (still on the source home channel) with message 176. The response message 176 consists of in sequence: a flag, the source node address, the NRM 36 address, FS number for the NRM 36, FV code for the NRM 36, the destination address, the destination channel frequency, a session done code, and an acknowledgement. A source node 150 closes the session with the NRM 36 by transmitting message 178. This latter message 178 consists of in sequence: a flag, the NRM 36 address, the source node 150 address, the FS number for the source node, the FV code for the source node, and a code for session closing. The response by the NRM 36 is message 180 consisting of in sequence: a flag, a source node address, the NRM 36 address, the FS number for the NRM 36, the FV code for the NRM 36, and a code for session closed.
The source node 150 then retunes to the frequency of the destination channel and obtains channel access authorization on the destination channel from the NAC 34 as shown in Figure 11 e. The sequence of messages in Figure 11e is analogous to the previously described message sequence in Figures 11 a and 11 b in which channel access was obtained by the source node 150 on the source home channel. Messages 182 and 186 in Figure 11e are analogous to messages 160 and 162 respectively in Figure 11 a. Messages 184, 188, and 190 are analogous to messages 164,166, and 168 respectively in Figure 11b.
The source node 150 now has channel access on the frequency of the destination node 152. The source node 150 opens a session with the destination node 152 as shown in Figure 11f. Message 192 consists of in sequence: a flag, the destination node address, the source node address, the FS number for the source node 150, the FV code for the source node 150, and a session open request.
Assuming that the destination node 152 has previously obtained channel access, on the destination channel frequency, (by a message sequence similar to that shown in Figure 11 a, 11 b or Figure 11 e) node 152 responds with a session open acknowledgement message 194. The message 194 comprises in sequence: a flag, the source node address, the destination node address, the FV number for the destination node 152, the FV code for the destination node 152, and a code for session open acknowledgement.
At this point, the source node 150 and the destination node 152 have both been previously granted network access and are both on the same data channel frequency. The communication session of information interchange can now proceed utilizing other layers of the protocol architecture. The CATV network provides transparent data transport service between the source node 150 and the destination node 152.
After the session of information exchange is completed, the source and destination nodes 150, 152 close the session with appropriate session closed messages similar to the session closing messages 178 and 180 between the source node 150 and the NRM 36 shown in Figure 11d.
Note that the secret node key of a respective node is never transmitted over the CATV network or the out of band data channel. Thus, an eavesdropper cannot discover the node key directly. The closest derivative of the node key that is transmitted over the CATV networks is the encrypted CAC and the following re-encrypted CAC into an FV code. The present double encryption arrangement provides security against the discovery and unauthorized use of the node key.
12 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12
34 members in 14 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 373765 | United States of America | – | |
| 37376582 | United States of America | A | |
| 37376582 | United States of America | A | |
| 373765 | – | – | – |
| US19820373765 | – | – | – |
Members34
| Document | Office | Kind | |
|---|---|---|---|
| FI831397A0 | Finland | A0 | |
| DK192083D0 | Denmark | D0 | |
| IE830985L | Ireland | L | |
| DK192083A | Denmark | A | |
| FI831397L | Finland | L | |
| NO831527L | Norway | L | |
| AU1406983A | Australia | A | |
| EP0093549A2 | European Patent Office (EPO) | A2 | |
| EP0093549A3 | European Patent Office (EPO) | A3 | |
| JPS5940786A | Japan | A | |
| ES521927A0 | Spain | A0 | |
| ES8403685A1 | Spain | A1 | |
| GR78536B | Greece | B | |
| ES528492A0 | Spain | A0 | |
| ES8407639A1 | Spain | A1 | |
| US4533948A | United States of America | A | |
| AU550086B2 | Australia | B2 | |
| NZ204038A | New Zealand | A | |
| NZ214189A | New Zealand | A | |
| CA1214865A | Canada | A | |
| CA1219332A | Canada | A | |
| EP0093549B1This record | European Patent Office (EPO) | B1 | |
| AT28018T | Austria | T | |
| ATE28018T1 | Austria | T1 | |
| DE3372250D1 | Germany | D1 | |
| FI76469B | Finland | B | |
| FI76469C | Finland | C | |
| NO160110B | Norway | B | |
| NO160110C | Norway | C | |
| IE54316B1 | Ireland | B1 | |
| JPH0473353B2 | Japan | B2 | |
| DK170388B1 | Denmark | B1 | |
| JPH0818946A | Japan | A | |
| JP2728342B2 | Japan | B2 |
36 legal events, as 3 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Opt-out of the competence of the unified patent court (upc) registeredP01 | P01 | EP | |
| Patent expired after termination of 20 yearsExpiredPE20 | PE20 | GB | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| European patent in force as of 2002-01-01IF02 | IF02 | GB | |
| Se: european patent has lapsedLapsedEUG | EUG | EP | |
| Be: lapsedLapsedBERE | BERE | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| AssignmentPUE | PUE | CH | |
| Amendments to the register in respect of changes of name or changes affecting rights (sect. 32/1977)732E | 732E | GB | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Se: european patent in force in swedenEAL | EAL | EP | |
| It: last paid annual feeITTA | ITTA | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Fr: translation filedET | ET | EP | |
| Corresponds to:REF | REF | EP | |
| Designated contracting statesAK | AK | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0093549
- Publication, DOCDB
- 0093549
- Publication, EPODOC
- EP0093549
- Application
- 83302286
- Application, DOCDB
- 83302286
- Application, EPODOC
- EP19830302286
Titles3
- English
- CATV communication system
- German
- Kabelfernsehensystem
- French
- Système de télévision câblé
Classification
- CPC, 4
- H04L9/3215
- H04L12/2801
- H04L9/3226
- H04L2209/60
- IPC, 11
- H04N7 173
- H04B3 52
- H04K1 00
- H04L9 00
- H04L9 06
- H04L9 08
- H04L9 10
- H04L9 12
- H04L9 32
- H04L12 28
- H04N7 10
Designated states9
- Contracting states, 9
- Austria
- Belgium
- Switzerland
- Germany
- France
- United Kingdom
- Italy
- Liechtenstein
- Sweden
