Independent external security module for a digitally upgradeable television signal decoder
Abstract
Upgrade circuitry (1390) is provided so as to adapt a reception system (1306) for analog signals to accept both analog and digital signals. The upgrade circuitry (1390) selects (1392) a predetermined digital signal from a number of received digital signals, and decompresses (1393) the selected digital signal. The reception system (1306) includes a switch (1367) for selectively coupling to a decoder (1368) either an analog signal processing demodulator (1366) or the upgrade circuitry (1390).

Term
Term ended
Expired 27 March 2012, 14.5 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
39 claims: 39 independent, 0 dependent
- 1A decoder for receiving and descrambling a signal which has been scrambled using a key, the key having been selectively encrypted using at least one of a first confidential serial number and a second confidential serial number, said decoder comprising:first key decryptor means (713) operative when the selectively encrypted key has been encrypted using the first confidential serial number;second key decryptor means (718) operative when the selectively encrypted key has been encrypted using the second confidential serial number, one of the first and second key decryptor means being incorporated in a replaceable security module [714] removably attached to the decoder while the other is incorporated in a fixed security element [719] of the decoder;andcontrol means (708) for operating at least one of the first and second key decryptor means to generate a decrypted key, the decrypted key being the key used to descramble the signal. Dekoder für den Empfang und die Entwürfelung eines Signals, das auf der Grundlage der Verwendung eines Codes verwürfelt worden ist, wobei der Code selektiv verschlüsselt wurde, und dies unter Verwendung von zumindest einer ersten vertraulichen Seriennummer und einer zweiten vertraulichen Seriennummer;der besagte Dekoder umfaßt dabei: erste Code-Entschlüsselungsvorrichtungen (713), die dann aktiviert werden, wenn der selektiv verschlüsselte Code über die Verwendung der ersten vertraulichen Seriennummer verschlüsselt worden ist;zweite Code-Entschlüsselungsvorrichtungen (718), die dann aktiviert werden, wenn der selektiv verschlüsselte Code unter Verwendung der zweiten vertraulichen Seriennummer verschlüsselt wurde, wobei eine der ersten und zweiten Code-Entschlüsselungsvorrichtungen in einem austauschbaren Sicherheitsmodul (714) eingebaut ist, das an dem Dekoder abnehmbar befestigt ist, während die andere in einem stationären Sicherheitselement (719) des Dekoders enthalten ist;undSteuervorrichtungen (708) für den Betrieb von mindestens einem der ersten und zweiten Code-Entschlüsselungsvorrichtungen, um einen entschlüsselten Code zu generieren, wobei der entschlüsselte Code jener ist, der für die Entwürfelung des Signals verwendet wird. Décodeur pour recevoir et débrouiller un signal qui a été brouillé par utilisation d'une clef, la clef ayant été sélectivement chiffrée par utilisation d'au moins un premier numéro de série confidentiel ou un deuxième numéro de série confidentiel, ledit décodeur comprenant : des premiers moyens décrypteurs de clef (713), actifs quand la clef sélectivement chiffrée a été chiffrée par utilisation du premier numéro de série confidentiel ;des deuxièmes moyens décrypteurs de clef (718), actifs quand la clef sélectivement chiffrée a été chiffrée par utilisation du deuxième numéro de série confidentiel, les premiers ou les deuxièmes moyens décrypteurs de clef étant incorporés dans un module de sécurité remplaçable (714), fixé d'une manière amovible au décodeur, tandis que les autres sont incorporés dans un élément de sécurité fixe (719) du décodeur ;etdes moyens de commande (708), pour agir sur au moins les premiers ou les deuxièmes moyens décrypteurs de clef, pour produire une clef décryptée, la clef décryptée étant la clef utilisée pour débrouiller le signal.
- 2A decoder according to claim 1, wherein the control means operates the first key decryptor means to decrypt the selectively encrypted key and generate the decrypted key. Dekoder gemäß Anspruch 1, dadurch gekennzeichnet, daß die Steuervorrichtung die erste Code-Entschlüsselungsvorrichtung steuert, um den selektiv verschlüsselten Code zu entschlüsseln und den entschlüsselten Code zu generieren. Décodeur selon la revendication 1, dans lequel les moyens de commande agissent sur les premiers moyens décrypteurs de clef pour décrypter la clef sélectivement chiffrée et générer la clef décryptée.
- 3A decoder according to claim 1 or claim 2, wherein the control means operates the second key decryptor means to decrypt the selectively encrypted key and generate the decrypted key. Dekoder gemäß Anspruch 1 oder Anspruch 2, dadurch gekennzeichnet, daß die Steuervorrichtung die zweite Code-Entschlüsselungsvorrichtung steuert, um den selektiv verschlüsselten Code zu entschlüsseln und den entschlüsselten Code zu generieren. Décodeur selon la revendication 1 ou la revendication 2, dans lequel les moyens de commande agissent sur les deuxièmes moyens décrypteurs de clef, pour décrypter la clef sélectivement chiffrée et générer la clef décryptée.
- 4A decoder according to any of claims 1, 2 or 3, wherein the control means operates the first key decryptor means to decrypt the selectively encrypted key and generate a partially decrypted key and then operates the second key decryptor means to decrypt the partially decrypted key and generate the decrypted key. Dekoder gemäß irgendeinem der Ansprüche 1, 2 oder 3, dadurch gekennzeichnet, daß die Steuervorrichtung die erste Code-Entschlüsselungsvorrichtung steuert, um den selektiv verschlüsselten Code zu entschlüsseln und einen partiell entschlüsselten Code zu generieren, und dann die zweite Code-Entschlüsselungsvorrichtung steuert, um den partiell entschlüsselten Code zu entschlüsseln und den entschlüsselten Code zu generieren. Décodeur selon l'une quelconque des revendications 1, 2 ou 3, dans lequel les moyens de commande agissent sur les premiers moyens décrypteurs de clef pour décrypter la clef sélectivement chiffrée et générer une clef partiellement décryptée, puis agit sur les deuxièmes moyens décrypteurs de clef pour décrypter la clef partiellement décryptée et générer la clef décryptée.
- 5A decoder according to any preceding claim, wherein:the control means operates in one of a first mode, a second mode mode, and a third modewhile operating in the first mode, the control means operates the first key decryptor means to decrypt the selectively encrypted key and generate the decrypted key;while operating in the second mode, the control means operates the second key decryptor means to decrypt the selectively encrypted key and generate the decrypted key;andwhile operating in the third mode, the control means operates the first key decryptor means to decrypt the selectively encrypted key and generate a partially decrypted key and then operates the second key decryptor means to decrypt the partially decrypted key and generate the decrypted key. Dekoder gemäß irgendeinem der vorausgegangenen Ansprüche, dadurch gekennzeichnet, daß: die Steuervorrichtung in entweder einer ersten Betriebsart, einer zweiten Betriebsart oder einer dritten Betriebsart operiert;bei einem Betrieb in der ersten Betriebsart, die Steuervorrichtung die erste Code-Entschlüsselungsvorrichtung steuert, um den selektiv verschlüsselten Code zu entschlüsseln und den entschlüsselten Code zu generieren;in der zweiten Betriebsart die Steuervorrichtung die zweite Code-Entschlüsselungsvorrichtung steuert, um den selektiv verschlüsselten Code zu entschlüsseln und den entschlüsselten Code zu generieren;undin der dritten Betriebsart die Steuervorrichtung die erste Code-Entschlüsselungsvorrichtung steuert, um den selektiv verschlüsselten Code zu entschlüsseln und einen partiell entschlüsselten Code zu generieren, und dann die zweite Code-Entschlüsselungsvorrichtung steuert, um den partiell entschlüsselten Code zu entschlüsseln und den entschlüsselten Code zu generieren. Décodeur selon l'une quelconque des revendications précédentes, dans lequel : les moyens de commande agissent selon un premier mode, un deuxième mode ou un troisième mode :quand ils agissent selon le premier mode, les moyens de commande agissent sur les premiers moyens décrypteurs de clef, pour décrypter la clef sélectivement chiffrée et générer la clef décryptée ;quand ils agissent selon le deuxième mode, les moyens de commande agissent sur les deuxièmes moyens décrypteurs de clef, pour décrypter la clef sélectivement chiffrée et générer la clef décryptée ;etquand ils agissent selon le troisième mode, les moyens de commande agissent sur les premiers moyens décrypteurs de clef pour décrypter la clef sélectivement chiffrée et générer une clef partiellement décryptée, puis agissent sur les deuxièmes moyens décrypteurs de clef pour décrypter la clef partiellement décryptée et générer la clef décryptée.
- 6A decoder according to any preceding claim, wherein the decoder further includes signal descrambling means (708) for descrambling signal using the decrypted key. Dekoder gemäß irgendeinem der vorausgegangenen Ansprüche, dadurch gekennzeichnet, daß der Dekoder zusätzlich eine Signal-Entwürfelungsvorrichtung (708) aufweist, um das Signal über den entschlüsselten Code zu entwürfeln. Décodeur selon l'une quelconque des revendications précédentes, dans lequel le décodeur comprend en outre des moyens débrouilleurs de signaux (708), pour débrouiller le signal en utilisant la clef décryptée.
- 7A decoder according to any preceding claim, further comprising first and second key memory means (707, 720) respectively coupled to said first and second key decryptor means (713, 718), for storing said decrypted key. Dekoder gemäß irgendeinem der vorausgegangenen Ansprüche, der darüber hinaus erste und zweite Code-Speichervorrichtungen (707, 720) aufweist, die jeweils mit der besagten ersten und zweiten Entschlüsselungs-Vorrichtung (713, 718) gekoppelt sind, um den besagten entschlüsselten Code zu speichern. Décodeur selon l'une quelconque des revendications précédentes, qui comprend en outre des premiers et des deuxièmes moyens de mémoire de clef (707, 720), qui sont couplés respectivement auxdits premiers et deuxièmes moyens décrypteurs de clef (713, 718) pour stocker ladite clef décryptée.
- 8A decoder according to any preceding claim, further comprising first and second confidential serial number memory means (712, 717) respectively coupled to said first and second key decryptor means (713, 718), for storing first and second confidential serial numbers. Dekoder gemäß irgendeinem der vorausgegangenen Ansprüche, der darüber hinaus erste und zweite vertrauliche Seriennummer-Speichervorrichtungen (712, 717) besitzt, die jeweils an der besagten ersten und zweiten Code-Entschlüsselungsvorrichtung (713, 718) gekoppelt sind, um erste und zweite vertrauliche Seriennummern zu speichern. Décodeur selon l'une quelconque des revendications précédentes, qui comprend en outre des premiers et des deuxièmes moyens de mémoire de numéro de série confidentiel (712, 717), couplés respectivement auxdits premiers et deuxièmes moyens décrypteurs de clef (713, 718), pour stocker le premier et le deuxième numéros de série confidentiels.
- 9A decoder according to claim 8, wherein in the replaceable security module (714) and in the fixed security element (719), said first and second confidential serial number memory means further comprise security means for allowing the contents of said first and second confidential serial number memory means (712, 717) to be read only by said respective first and second key decryptor means (713, 718). Dekoder gemäß Anspruch 8, dadurch gekennzeichnet, daß in dem austauschbaren Sicherheitsmodul (714) und in dem stationären Sicherheitselement (719) die besagten ersten und zweiten vertraulichen Seriennummer-Speichervorrichtungen ferner Sicherheitselemente umfassen, damit der Inhalt der besagten ersten und zweiten vertraulichen Seriennummer-Speichervorrichtungen (712, 717) nur über die besagte entsprechende erste und zweite Code-Entschlüsselungsvorrichtung (713, 718) gelesen werden kann. Décodeur selon la revendication 8, dans lequel, dans le module de sécurité remplaçable (714) et dans le module de sécurité fixe (719), lesdits premiers et deuxièmes moyens de mémoire de numéros de série confidentiels comprennent des moyens de sécurité, pour que le contenu desdits premiers et deuxièmes moyens de mémoire de numéros de série confidentiels (712, 717) ne puissent être lus que par lesdits premiers et deuxièmes moyens décrypteurs de clef (713, 718) respectifs.
- 10A decoder according to any preceding claim, wherein said signal is a television signal. Dekoder gemäß irgendeinem der vorausgegangenen Patentansprüche, bei dem es sich bei dem besagten Signal um ein Fernsehsignal handelt. Décodeur selon l'une quelconque des revendications précédentes, dans lequel ledit signal est un signal de télévision.
- 11A decoder according to claim 10, wherein said signal is a B-MAC type television signal. Dekoder gemäß Patentanspruch 10, bei dem es sich bei dem besagten Signal um ein Fernsehsignal des Typs B-MAC handelt. Décodeur selon la revendication 10, dans lequel ledit signal est un signal de télévision de type B-MAC.
- 12A decoder according to any preceding claim, further comprising telephone interface means (875) for transmitting and receiving data to and from a television signal provider. Dekoder gemäß irgendeinem der vorausgegangenen Patentansprüche, der ferner eine Telefon-Schnittstellenvorrichtung (875) umfaßt, um Daten auf den Betreiber eines Fernsehsignals zu übertragen und Daten von diesem zu empfangen. Décodeur selon l'une quelconque des revendications précédentes, qui comprend en outre des moyens d'interface téléphonique (875) pour transmettre des données à un fournisseur de signaux de télévision et les en recevoir.
- 13A decoder according to claim 12, in which subscriber input data is transmitted by the replaceable security module (714) via said telephone interface means (875). Dekoder gemäß Patentanspruch 12, dadurch gekennzeichnet, daß die Input-Daten des Teilnehmers durch das austauschbare Sicherheitsmodul (714) über die besagte Telefon-Schnittstellenvorrichtung (875) übertragen werden. Décodeur selon la revendication 12, dans lequel les données d'entrée de l'abonné sont transmises par le module de sécurité remplaçable (714) par l'intermédiaire desdits moyens d'interface téléphonique (875).
- 14A decoder according to any preceding claim, wherein said first confidential serial number is assigned to the fixed security element (719) of said decoder (706). Dekoder gemäß irgendeinem der vorausgegangenen Patentansprüche, dadurch gekennzeichnet, daß die besagte erste vertrauliche Seriennummer dem festen Sicherheitselement (719) des besagten Dekoders (706) zugeordnet ist. Décodeur selon l'une quelconque des revendications précédentes, dans lequel ledit premier numéro de série confidentiel est attribué à l'élément de sécurité fixe (719) dudit décodeur (706).
- 15A decoder according to any preceding claim, wherein said second confidential serial number is assigned to said replaceable security module (714). Dekoder gemäß irgendeinem der vorausgegangenen Patentansprüche, dadurch gekennzeichnet, daß die besagte zweite vertrauliche Seriennummer dem besagten austauschbaren Sicherheitsmodul (714) zugeordnet ist. Décodeur selon l'une quelconque des revendications précédentes, dans lequel ledit deuxième numéro de série confidentiel est attribué audit module de sécurité remplaçable (714).
- 16A decoder according to any preceding claim, wherein:the selectively encrypted key has been encrypted under either a first confidential serial number, a second confidential serial number, or both;andthe decoder further comprises means for actively switching (708), in response to a detected signal, between the fixed security element (719) and the replaceable security module (714) so as to effectively decrypt the selectively encrypted key to generate the decrypted key. Dekoder gemäß irgendeinem der vorausgegangenen Patentansprüche, dadurch gekennzeichnet, daß: der selektiv verschlüsselte Code entweder unter einer ersten vertraulichen Seriennummer oder einer zweiten vertraulichen Seriennummer oder beiden verschlüsselt worden ist;undder Dekoder ferner Vorrichtungen umfaßt, um, in Reaktion auf ein erfaßtes Signal, aktiv zwischen dem stationären Sicherheitselement (719) und dem austauschbaren Sicherheitsmodul (714) umzuschalten (708), um auf diese Art und Weise wirksam den selektiv verschlüsselten Code zu entschlüsseln und damit den entschlüsselten Code zu generieren. Décodeur selon l'une quelconque des revendications précédentes, dans lequel : la clef sélectivement chiffrée a été chiffrée par utilisation d'un premier numéro de série confidentiel, d'un deuxième numéro de série confidentiel, ou des deux ;etle décodeur comprend en outre des moyens de commutation active (708), en réponse à un signal détecté, entre l'élément de sécurité fixe (719) et le module de sécurité remplaçable (714), de façon à décrypter efficacement la clef sélectivement chiffrée, pour générer la clef décryptée.
- 17A decoder according to any preceding claim, wherein:the selectively encrypted key has been encrypted under either a first confidential serial number, a second confidential serial number, or both;andthe decoder further comprises means for actively switching (708), in response to a received signal, between first and second key decryptor means (713, 718) so as to effectively decrypt the key. Dekoder gemäß irgendeinem der vorausgegangenen Ansprüche, dadurch gekennzeichnet, daß: der selektiv verschlüsselte Code entweder unter einer ersten vertraulichen Seriennummer oder einer zweiten vertraulichen Seriennummer oder beiden verschlüsselt worden ist;undder Dekoder darüber hinaus Vorrichtungen umfaßt, um aktiv in Reaktion auf ein empfangenes Signal zwischen ersten und zweiten Code-Entschlüsselungs-Vorrichtungen (713, 718) umzuschalten (708), um auf diese Art und Weise den Code wirksam zu entschlüsseln. Décodeur selon l'une quelconque des revendications précédentes, dans lequel : la clef sélectivement chiffrée a été chiffrée par utilisation d'un premier numéro de série confidentiel, d'un deuxième numéro de série confidentiel, ou des deux ;etle décodeur comprend en outre des moyens de commutation active (708), en réponse à un signal reçu, entre les premiers et les deuxièmes moyens décrypteurs de clef (713, 718), de façon à décrypter efficacement la clef.
- 18A decoder according to any preceding claim operative to receive a composite data packet addressed to a single decoder or group of decoders, the composite data packet comprising:a first data packet (9a) containing unencrypted data for addressing the individual or group of decoders;a second data packet (9c) containing unencrypted data for determining whether at least one of first and second key decryptor means (714, 719) in the decoder are to be enabled;and,a third data packet (9d) containing encrypted data for use by the decoder. Dekoder entsprechend irgendeinem der vorausgegangenen Patentansprüche, der so arbeitet, daß er ein zusammengesetztes Datenpaket empfängt, das an einen einzelnen Dekoder oder eine Gruppe von Dekodern adressiert ist, wobei dieses zusammengesetzte Datenpaket folgendes umfaßt: ein erstes Datenpaket (9a), das nicht-verschlüsselte Daten für die Adressierung des individuellen oder der Gruppe von Dekodern enthält;ein zweites Datenpaket (9c), das nicht-verschlüsselte Daten für die Bestimmung darüber enthält, ob mindestens eine der ersten und zweiten Code-Entschlüsselungsvorrichtungen (714, 719) in dem Dekoder aktiviert werden sollen;undein drittes Datenpaket (9d), das verschlüsselte Daten zur Verwendung durch den Dekoder enthält. Décodeur selon l'une quelconque des revendications précédentes, actif pour recevoir un paquet de données composite adressé à un décodeur unique ou à un groupe de décodeurs, le paquet de données composite comprenant : un premier paquet de données (9a), contenant des données non chiffrées, pour adressage du décodeur individuel ou du groupe de décodeurs ;un deuxième paquet de données (9c) contenant des données non chiffrées, pour déterminer si au moins les premiers ou les deuxièmes moyens décrypteurs de clef (714, 719) se trouvant dans le décodeur doivent être validés ;etun troisième paquet de données (9d), contenant des données chiffrées, pour utilisation par le décodeur.
- 19A decoder according to claim 18, in which the composite data packet further comprises a fourth data packet (9b) containing unencrypted data for determining the order of decrypting the third data packet by the first and second key decryptor means (714, 719) if the third data packet had been twice encrypted. Dekoder gemäß Anspruch 18, bei dem das zusammengesetzte Datenpaket darüber hinaus ein viertes Datenpaket (9b) umfaßt, das nicht-verschlüsselte Daten für die Bestimmung der Reihenfolge der Entschlüsselung des dritten Datenpakets über die erste und zweite Code-Entschlüsselungsvorrichtung (714, 719) enthält, wenn das dritte Datenpaket zweimal verschlüsselt worden ist. Décodeur selon la revendication 18, dans lequel le paquet de données composite comprend en outre un quatrième paquet de données (9b) contenant des données non chiffrées, pour déterminer l'ordre de décryptage du troisième paquet de données par les premiers et les deuxièmes moyens décrypteurs de clef (714, 719) si le troisième paquet de données a été deux fois chiffré.
- 20Der Dekoder gemäß irgendeinem der vorausgegangenen Patentansprüche, der darüber hinaus folgende Elemente umfaßt:einen Dekoder-Schaltkreis (1368), wobei die erste und zweite Code-Entschlüsselungsvorrichtung (1314, 1319 darin enthalten sind;einen Demodulator (1366);Vorrichtungen für den Empfang (1391) einer Vielzahl komprimierter Digitalsignale mit einer Vielzahl von Adressen, wobei jede Adresse einem speziellen Digitalsignal zugeordnet ist;Vorrichtungen zur Auswahl (1392) eines speziellen Digitalsignals durch Identifizierung der betreffenden Adresse;Vorrichtungen zur Dekomprimierung (1393) des ausgewählten Digitalsignals;undVorrichtungen für die selektive Kopplung (1397) einer der Vorrichtungen für die Dekomprimierung (1393) und des Demodulators (1366) an den Dekoder-Schaltkreis (1368). Décodeur selon l'une quelconque des revendications précédentes, qui comprend en outre : un circuit décodeur (1368), les premiers et les deuxièmes moyens décrypteurs de clef (1314, 1319) y étant incorporés ;un démodulateur (1366) ;des moyens (1391) pour recevoir une pluralité de signaux numériques comprimés ayant une pluralité d'adresses, chaque adresse correspondant à un signal numérique particulier ;des moyens (1392) pour sélectionner un signal numérique particulier par identification de l'adresse particulière ;des moyens (1393) pour décomprimer le signal numérique sélectionné ;etdes moyens (1397) pour coupler d'une manière sélective au circuit décodeur (1368) les moyens de décompression (1393) ou le démodulateur (1366). The decoder according to any preceding claim, further comprising: decoder circuitry (1368), the first and second key decryptor means (1314, 1319) being incorporated therein;a demodulator (1366);means for receiving (1391) a plurality of compressed digital signals with a plurality of addresses, each address corresponding to a particular digital signal;means for selecting (1392) a particular digital signal by identifying the particular address;means for decompressing (1393) the selected digital signal;andmeans for selectively coupling (1397) to the decoder circuity (1368) one of the means for decompressing (1393) and the demodulator (1366).
- 21A decoder according to claim 20, further comprising means, coupled between the means for selecting (1392) and the means for decompressing (1393), for decrypting (1399) the digital signal. Dekoder gemäß Patentanspruch 20, der darüber hinaus Vorrichtungen umfaßt, die zwischen den Vorrichtungen für die Auswahl (1392) und die Vorrichtungen für die Dekomprimierung (1393) gekoppelt sind, um das digitale Signal zu entschlüsseln (1399). Décodeur selon la revendication 1, qui comprend en outre des moyens (1399), couplés entre les moyens de sélection (1392) et les moyens de décompression (1393), pour décrypter le signal numérique.
- 22A decoder according to any preceding claim wherein the replaceable security module includes:the second key decryptor means;means, coupled to the second key decryptor means, for generating decoder control information from the decrypted key, the decoder control information useable for descrambling the scrambled signal;andsecurity means to ensure that the decrypted key generated by the second key decryptor means is only useable by the means for generating the decoder control information. Dekoder gemäß irgendeinem der vorausgegangenen Patentansprüche, dadurch gekennzeichnet, daß das austauschbare Sicherheitsmodul folgende Elemente umfaßt: die zweiten Code-Entschlüsselungsvorrichtung;Vorrichtungen, die mit der zweiten Code-Entschlüsselungsvorrichtung gekoppelt sind, um Dekoder-Steuerdaten von dem entschlüsselten Code zu generieren, wobei die Dekoder-Steuerdaten für die Entwürfelung des verwürfelten Signals verwendbar sind;undSicherheitsvorrichtungen, um sicherzustellen, daß der entschlüsselte Code, der über die zweite Code-Entschlüsselungsvorrichtung generiert worden ist, nur über die Vorrichtung zur Generierung der Dekoder-Steuerdaten verwendbar ist. Décodeur selon l'une quelconque des revendications précédentes, dans lequel le module de sécurité remplaçable comprend : les deuxièmes moyens décrypteurs de clef ;des moyens, couplés aux deuxièmes moyens décrypteurs de clef, pour générer une information de commande de décodeur à partir de la clef décryptée, l'information de commande de décodeur pouvant être utilisée pour débrouiller le signal brouillé ;etdes moyens de sécurité, pour garantir que la clef décryptée générée par les deuxièmes moyens décrypteurs de clef ne peuvent être utilisés que par les moyens destinés à générer l'information de commande de décodeur.
- 23A method for decoding a signal in a decoder comprising first and second key decryptor means, one of the first and second key decryptor means being incorporated in a replaceable security module while the other is incorporated in a fixed security element, the method comprising steps of:selectively operating the first key decryptor means to process a selectively encrypted key based on a first confidential serial number when the selectively encrypted key has been encrypted under the first confidential serial number;selectively operating the second key decryptor means to process the selectively encrypted key based on a second confidential serial number when the selectively encrypted key has been encrypted under the second confidential serial number;andcontrolling the operation of at least one of the first and second key decryptor means to generate a decrypted key. Ein Verfahren zur Decodierung eines Signals in einem Dekoder, der erste und zweite Code-Entschlüsselungsvorrichtungen umfaßt, wobei eine der ersten und zweiten Code-Entschlüsselungsvorrichtungen in einem austauschbaren Sicherheitsmodul eingebettet ist, während die andere in einem stationären Sicherheitselement fixiert ist;die Methode umfaßt dabei folgende Stufen: die selektive Steuerung der ersten Code-Entschlüsselungsvorrichtung zur Verarbeitung eines selektiv verschlüsselten Codes, ausgehend von der ersten vertraulichen Seriennummer, wenn der selektiv verschlüsselte Code unter der ersten vertraulichen Seriennummer verschlüsselt worden ist;die selektive Steuerung der zweiten Code-Entschlüsselungsvorrichtung, um den selektiv verschlüsselten Code zu verarbeiten, ausgehend von einer zweiten vertraulichen Seriennummer, wenn der selektiv verschlüsselte Code unter der zweiten vertraulichen Seriennummer verschlüsselt worden ist;unddie Steuerung der Betriebsfunktion von mindestens einer der ersten und zweiten Code-Entschlüsselungsvorrichtungen zur Generierung eines entschlüsselten Codes. Procédé pour décoder un signal dans un décodeur comprenant des premiers et des deuxièmes moyens décrypteurs de clef, les premiers ou les deuxièmes moyens décrypteurs de clef étant incorporés dans un module de sécurité remplaçable, tandis que les autres sont incorporés dans un élément de sécurité fixe, le procédé comprenant les étapes consistant : à agir sélectivement sur les premiers moyens décrypteurs de clef pour traiter une clef sélectivement chiffrée sur la base d'un premier numéro de série confidentiel quand la clef sélectivement chiffrée a été chiffrée par utilisation du premier numéro de série confidentiel ;à agir sélectivement sur les deuxièmes moyens décrypteurs de clef pour traiter la clef sélectivement chiffrée sur la base d'un deuxième numéro de série confidentiel quand la clef sélectivement chiffrée a été chiffrée par utilisation du deuxième numéro de série confidentiel ;età commander le fonctionnement d'au moins les premiers ou les deuxièmes moyens décrypteurs de clef, pour générer une clef décryptée.
- 24A method according to claim 23, wherein the step of controlling controls the decoder to operate in one of a first mode, a second mode and a third mode, the step of controlling including a step of:while the decoder is operating in the first mode, operating the first key decryptor means to decrypt the selectively encrypted key and generate the decrypted key;while the decoder is operating in the second mode, operating the second key decryptor means to decrypt the selectively encrypted key and generate the decrypted key;andwhile the decoder is operating in the third mode, operating the first key decryptor means to decrypt the selectively encrypted key and generate a partially decrypted key and then operating the second key decryptor means to decrypt the partially decrypted key and generate the decrypted key. Procédé selon la revendication 23, dans lequel l'étape de commande commande le décodeur, pour qu'il agisse selon un premier mode, un deuxième mode ou un troisième mode, l'étape de commande comprenant une étape consistant : quand le décodeur agit selon le premier mode, à agir sur les premiers moyens décrypteurs de clef pour décrypter la clef sélectivement chiffrée et générer la clef décryptée ;quand le décodeur agit selon le deuxième mode, à agir sur les deuxièmes moyens décrypteurs de clef pour décrypter la clef sélectivement chiffrée et générer la clef décryptée ;etquand le décodeur agit selon le troisième mode, à agir sur les premiers moyens décrypteurs de clef pour décrypter la clef sélectivement chiffrée et générer une clef partiellement décryptée, puis à agir sur les deuxièmes moyens décrypteurs de clef pour décrypter la clef partiellement décryptée et générer la clef décryptée. Verfahren gemäß Patentanspruch 23, dadurch gekennzeichnet, daß die Steuerungsstufe den Dekoder so steuert, daß er entweder in einer ersten Betriebsart, einer zweiten Betriebsart oder einer dritten Betriebsart operiert, wobei die Stufe der Steuerung folgende Stufe umfaßt: während der Dekoder in der ersten Betriebsart operiert, Steuerung der ersten Code-Entschlüsselungsvorrichtung zur Entschlüsselung des selektiv verschlüsselten Codes und zur Generierung des entschlüsselten Codes;während der Dekoder in der zweiten Betriebsart arbeitet, Steuerung der zweiten Code-Entschlüsselungsvorrichtung zur Entschlüsselung des selektiv verschlüsselten Codes und zur Generierung des entschlüsselten Codes;undwährend der Dekoder in der dritten Betriebsart arbeitet, Steuerung der ersten Code-Entschlüsselungsvorrichtung zur Entschlüsselung des selektiv verschlüsselten Codes und Generierung eines partiell entschlüsselten Codes, mit anschließender Steuerung der zweiten Code-Entschlüsselungsvorrichtung, um den partiell entschlüsselten Code zu entschlüsseln und den entschlüsselten Code zu generieren.
- 25A method according to claim 23 or claim 24, further comprising a step of generating decoder control information based on the decrypted key, the decoder control information useable for descrambling scrambled signals. Procédé selon la revendication 23 ou 24, qui comprend en outre une étape consistant à générer une information de commande de décodeur sur la base de la clef décryptée, l'information de commande de décodeur pouvant être utilisée pour débrouiller des signaux brouillés. Verfahren gemäß Anspruch 23 oder Anspruch 24, mit einer zusätzlichen Stufe der Generierung von Dekoder-Steuerungsdaten, ausgehend von dem entschlüsselten Code, wobei die Dekoder-Steuerdaten für die Entwürfelung von verwürfelten Signalen nutzbar sind.
- 26A method according to any of claims 23 to 25, further comprising a step of securing data access to at least one (1) ensure that the first confidential serial numbers is readable only by the first key decryptor means, and (2) ensure that the second confidential serial numbers is readable only by the second key decryptor means. Procédé selon l'une quelconque des revendications 23 à 25, qui comprend en outre une étape consistant à assurer l'accès de données, au moins pour (1) garantir que les premiers numéros de série confidentiels ne peuvent être lus que par les premiers moyens décrypteurs de clef, ou (2) garantir que les deuxièmes numéros de série confidentiels ne peuvent être lus que par les deuxièmes moyens décrypteurs de clef. Verfahren gemäß irgendeinem der Patentansprüche 23 bis 25, das darüberhinaus eine Stufe der Sicherstellung des Datenzugangs umfaßt, um zumindest sicherzustellen, (1) daß die ersten vertraulichen Seriennummern nur über die erste Code-Entschlüsselungsvorrichtung lesbar sind und (2) daß die zweiten vertraulichen Seriennummern nur über die zweite Code-Entschlüsselungsvorrichtung lesbar sind.
- 27A method according to any of claims 23 to 26, wherein said signal is a television signal. Procédé selon l'une quelconque des revendications 23 à 26, dans lequel ledit signal est un signal de télévision. Verfahren gemäß irgendeinem der Patentansprüche 23 bis 26, dadurch gekennzeichnet, daß es sich bei dem besagten Signal um ein Fernsehsignal handelt.
- 28A method according to claim 27, wherein said signal is a B-MAC type television signal. Procédé selon la revendication 27, dans lequel ledit signal est un signal de télévision de type B-MAC. Verfahren gemäß Patentanspruch 27, dadurch gekennzeichnet, daß es sich bei dem besagten Signal um ein B-MAC-Fernsehsignal handelt.
- 29A method according to any of claims 23 to 28, further comprising a step of transmitting, via telephone interface means (875), data to and from a television signal provider. Procédé selon l'une quelconque des revendications 23 à 28, qui comprend en outre une étape consistant à transmettre, par l'intermédiaire de moyens d'interface téléphonique (875), des données à un fournisseur de signaux de télévision et à partir de ce dernier. Verfahren gemäß irgendeinem der Patentansprüche 23 bis 28, das darüberhinaus eine Stufe der Übermittlung von Daten zu und von einem Fernsehsignal-Lieferanten über eine Telefon-Schnittstellenvorrichtung (875) umfaßt.
- 30A method according to claim 29, further comprising the step of:preparing subscriber input data in the replaceable security module (714) to be transmitted via the telephone interface means. Procédé selon la revendication 29, qui comprend en outre l'étape consistant : à préparer des données d'entrée d'abonnés dans le module de sécurité remplaçable (714), destinées à être transmises par l'intermédiaire des moyens d'interface téléphonique. Verfahren gemäß Patentanspruch 29, das zusätzlich die Stufe der Aufbereitung von Teilnehmer-Inputdaten in dem austauschbaren Sicherheitsmodul (714) umfaßt, zwecks Übertragung über die Telefon-Schnittstellenvorrichtung.
- 31A method according to any of claims 23 to 30, further comprising a step of actively switching (708), in response to a detected signal, between the fixed security element (719) and the replaceable security module (714) so as to effectively decrypt the selectively encrypted key to generate the decrypted key. Procédé selon l'une quelconque des revendications 23 à 30, qui comprend en outre une étape de commutation active (708), en réponse à un signal détecté, entre l'élément de sécurité fixe (719) et le module de sécurité remplaçable (714), de façon à décrypter efficacement la clef sélectivement chiffrée, pour produire la clef décryptée. Verfahren gemäß irgendeinem der Patentansprüche 23 bis 30, das darüberhinaus eine Stufe der aktiven Schaltung (708), in Reaktion auf ein erfaßtes Signal, zwischen dem stationären Sicherheitselement (719) und dem austauschbaren Sicherheitsmodul (714) umfaßt, um auf diese Art und Weise wirksam den selektiv verschlüsselten Code zu entschlüsseln und damit den entschlüsselten Code zu generieren.
- 32A method according to any of claims 23 to 31, further comprising a step of actively switching (708), in response to a detected signal, between the first and second key decryptor means (713, 718) so as to effectively decrypt the selectively encrypted key to generate the decrypted key. Procédé selon l'une quelconque des revendications 23 à 31, qui comprend en outre une étape de commutation active (708), en réponse à un signal détecté, entre les premiers et les deuxièmes moyens décrypteurs de clef (713, 718), de façon à décrypter efficacement la clef sélectivement chiffrée et générer la clef décryptée. Verfahren gemäß irgendeinem der Patentansprüche 23 bis 31, das darüberhinaus eine Stufe der aktiven Schaltung (708), in Reaktion auf ein erfaßtes Signal, zwischen der ersten und zweiten Code-Entschlüsselungsvorrichtung (713, 718) umfaßt, um somit den selektiv verschlüsselten Code wirksam zu entschlüsseln und damit den entschlüsselten Code zu generieren.
- 33A method according to any of claims 23 to 32, further comprising steps of:providing subscriber information including said selectively encrypted key and said first and second confidential serial numbers at a first source;providing a plurality of program signals at a plurality of second sources;transmitting the subscriber information to the second sources;combining the subscriber information with the program signals to produce combined signals;and,transmitting the combined signals to said decoder. Procédé selon l'une quelconque des revendications 23 à 32, qui comprend en outre les étapes consistant : à mettre à disposition des informations d'abonnés, comprenant ladite clef sélectivement chiffrée et lesdits premiers et deuxièmes numéros de série confidentiels, au niveau d'une première source ;à mettre à disposition une pluralité de signaux de programme au niveau d'une pluralité de deuxièmes sources ;à transmettre les informations d'abonnés aux deuxièmes sources ;à combiner les informations d'abonnés aux signaux de programme pour produire des signaux combinés ;età transmettre les signaux combinés audit décodeur. Verfahren gemäß irgendeinem der Patentansprüche 23 bis 32, das darüberhinaus folgende Stufen umfaßt: Bereitstellung von Teilnehmerdaten, einschließlich des besagten selektiv verschlüsselten Codes und der besagten ersten und zweiten vertraulichen Seriennummer für eine erste Quelle;die Bereitstellung einer Vielzahl von Programmsignalen für eine Vielzahl von zweiten Quellen;die Übermittlung der Teilnehmer-Information auf die zweiten Quellen;die Kombination der Teilnehmerdaten mit den Programmsignalen zur Erzeugung kombinierter Signale;unddie Übertragung der kombinierten Signale auf den besagten Dekoder.
- 34A method according to any of claims 23 to 33 further comprising a step of receiving a composite data packet, the composite data packet comprising:a first data packet (9a) containing unencrypted data for addressing the individual or group of decoders;a second data packet (9c) containing unencrypted data for determining whether at least one of first and second key decryptor means (714, 719) in the decoder are to be enabled;and,a third data packet (9d) containing encrypted data for use by the decoder. Procédé selon l'une quelconque des revendications 23 à 33, qui comprend en outre une étape consistant à recevoir un paquet de données composite, le paquet de données composite comprenant : un premier paquet de données (9a) contenant des données non chiffrées, pour adressage du décodeur individuel ou du groupe de décodeurs ;un deuxième paquet de données (9c) contenant des données non chiffrées pour déterminer si au moins les premiers ou les deuxièmes moyens décrypteurs de clef (714, 719) se trouvant dans le décodeur doivent être validés ;etun troisième paquet de données (9d), contenant des données chiffrées, pour utilisation par le décodeur. Verfahren gemäß irgendeinem der Patentansprüche 23 bis 33, das darüber hinaus eine Stufe des Empfangs eines zusammengesetzten Datenpakets umfaßt, wobei dieses zusammengesetzte Datenpaket folgendes umfaßt: ein erstes Datenpaket (9a), das nicht-verschlüsselte Daten für die Adressierung des einzelnen Dekoders oder einer Gruppe von Dedekodern enthält;ein zweites Datenpaket (9c), das nicht-verschlüsselte Daten für die Bestimmung darüber enthält, ob mindestens eine der ersten und zweiten Code-Entschlüsselungsvorrichtungen (714, 719) in dem Dekoder aktiviert werden sollen;undein drittes Datenpaket (9d), das entschlüsselte Daten für die Verwendung durch den Dekoder enthält.
- 35A method according to claim 34, wherein the composite data packet further comprises a fourth data packet (9b) containing unencrypted data for determining the order of decrypting the third data packet by the first and second key decryptor means (714, 719) if the third data packet had been twice encrypted. Procédé selon la revendication 34, dans lequel le paquet de données composite comprend en outre un quatrième paquet de données (9b) contenant des données non chiffrées, pour déterminer l'ordre de décryptage du troisième paquet de données par les premiers et les deuxièmes moyens décrypteurs de clef (714, 719) si le troisième paquet de données a été deux fois chiffré. Verfahren gemäß Patentanspruch 34, dadurch gekennzeichnet, daß das zusammengesetzte Datenpaket darüber hinaus ein viertes Datenpaket (9b) umfaßt, das nicht-verschlüsselte Daten enthält, um die Reihenfolge der Entschlüsselung des dritten Datenpakets über die erste und zweite Code-Entschlüsselungsvorrichtung (714, 719) zu bestimmen, wenn das dritte Datenpaket zweimal verschlüsselt worden ist.
- 36A method according to any of claims 23 to 35, wherein the decoder further includes decoder circuitry (1368), the first and second key decryptor means being incorporated therein, the method further comprising steps of:receiving (1391) a plurality of compressed digital signals with a plurality of addresses, each address corresponding to a particular digital signal;selecting (1392) a particular digital signal by identifying the particular address;decompressing (1393) the selected digital signal;andselectively coupling (1367) to decoder circuity (1368) one of the decompressed signal (1393) and a demodulated signal (1366). Procédé selon l'une quelconque des revendications 23 à 35, dans lequel le décodeur comprend en outre un circuit décodeur (1368), les premiers et les deuxièmes moyens décrypteurs de clef y étant incorporés, le procédé comprenant en outre les étapes consistant : à recevoir (1391) une pluralité de signaux numériques comprimés, avec une pluralité d'adresse, chaque adresse correspondant à un signal numérique particulier ;à sélectionner (1392) un signal numérique particulier par identification de l'adresse particulière ;à décomprimer (1393) le signal numérique sélectionné ;età coupler sélectivement (1367) au circuit décodeur (1368) le signal décomprimé (1393) ou un signal démodulé (1366). Verfahren gemäß irgendeinem der Patentansprüche 23 bis 35, dadurch gekennzeichnet, daß der Dekoder darüber hinaus einen Dekoder-Schaltkreis (1368) umfaßt, wobei die erste und zweite Code-Entschlüsselungsvorrichtung in diesen eingebettet sind;da Verfahren umfaßt darüber hinaus folgende Stufen: den Empfang (1391) einer Vielzahl komprimierter Digitalsignale mit einer Vielzahl von Adressen, wobei jede Adresse einem speziellen Digitalsignal entspricht;die Auswahl (1392) eines speziellen Digitalsignals durch Identifizierung der spezifischen Adresse;die Dekomprimierung (1393) des gewählten digitalen Signals;unddie selektive Kopplung (1367) entweder des dekomprimierten Signals (1393) oder des demodulierten Signals (1366) an den Dekoder-Schaltkreis (1368).
- 37A method according to claim 36, further comprising a step of decrypting (1399) the selected digital signal. Procédé selon la revendication 36, qui comprend en outre une étape consistant à décrypter (1399) le signal numérique sélectionné. Verfahren gemäß Patentanspruch 36, das darüberhinaus die Stufe der Entschlüsselung (1399) des ausgewählten Digitalsignals umfaßt.
- 38A method according to any of claims 23 to 37, further comprising steps of:generating decoder control information from the decrypted key, the decoder control information useable for descrambling the scrambled signal;andensuring that the decrypted key generated by the second key decryptor means is only useable for generating the decoder control information. Procédé selon l'une quelconque des revendications 23 à 37, qui comprend en outre les étapes consistant : à générer une information de commande de décodeur à partir de la clef décryptée, l'information de commande de décodeur pouvant être utilisée pour débrouiller le signal brouillé ;età faire en sorte que la clef décryptée générée par les deuxièmes moyens décrypteurs de clef ne puisse être utilisée que pour générer l'information de commande de décodeur. Verfahren gemäß irgendeinem der Patentansprüche 23 bis 37, das darüberhinaus folgende Stufen umfaßt: die Generierung von Dekoder-Steuerdaten aus dem entschlüsselten Code, wobei die Dekoder-Steuerdaten, die für die Entwürfelung des verwürfelten Signals nutzbar ist;unddie Sicherstellung dahingehend, daß der entschlüsselte Code, der über die zweite Code-Entschlüsselungsvorrichtung generiert worden ist, nur für die Generierung der Dekoder-Steuerdaten verwendbar ist.
- 39A method according to any claims 23 to 38, wherein the second key decryptor means is incorporated in the replaceable security module, and initially the step of controlling operates only the first key decryptor means, and a headend encrypts a new key under an alternate first confidential serial number and then under the second confidential serial number to produce a new selectively encrypted key, and the method further includes steps of:decrypting the new selectively encrypted key in the first key decryptor means using the alternate first confidential serial number to produce a partially decrypted key;anddecrypting the partially decrypted key in the second key decryptor means using the second confidential serial number to recover the new key, each subsequent new key being encrypted under only the second confidential serial number thereafter, the step of controlling operating only the second key decryptor means when a subsequent new key is encrypted under only the second confidential serial number. Procédé selon l'une quelconque des revendications 23 à 38, dans lequel les deuxièmes moyens décrypteurs de clef sont incorporés dans le module de sécurité remplaçable, et, initialement, l'étape de commande n'agit que sur les premiers moyens décrypteurs de clef, et une tête de réseau chiffre une nouvelle clef, en utilisant un autre premier numéro de série confidentiel, puis en utilisant le deuxième numéro de série confidentiel pour produire une nouvelle clef sélectivement chiffrée, et le procédé comprend en outre les étapes consistant : à décrypter la nouvelle clef sélectivement chiffrée dans les premiers moyens décrypteurs de clef, par utilisation de l'autre premier numéro de série confidentiel pour produire une clef partiellement décryptée ;età décrypter la clef partiellement décryptée dans les deuxièmes moyens décrypteurs de clef, par utilisation du deuxième numéro de série confidentiel pour récupérer la nouvelle clef, chaque nouvelle clef ultérieure étant chiffrée uniquement par utilisation du deuxième numéro de série confidentiel, puis l'étape de commande n'agissant que sur les deuxièmes moyens décrypteurs de clef quand une nouvelle clef ultérieure est chiffrée uniquement par utilisation du deuxième numéro de série confidentiel. Verfahren gemäß irgendeinem der Patentansprüche 23 bis 38, dadurch gekennzeichnet, daß die zweite Code-Entschlüsselungsvorrichtung in dem austauschbaren Sicherheitsmodul eingebettet ist, und zunächst die Steuerungsstufe nur die erste Code-Entschlüsselungsvorrichtung betreibt und eine Kopfstelle einen neuen Code unter einer alternativen ersten vertraulichen Seriennummer verschlüsselt, um dann unter der zweiten vertraulichen Seriennummer einen neuen selektiv verschlüsselten Code zu generieren;das Verfahren umfaßt darüber hinaus folgende Stufen: die Entschlüsselung des neu selektiv verschlüsselten Codes in der ersten Code-Entschlüsselungsvorrichtung unter Verwendung der alternativen ersten vertraulichen Seriennummer zur Erzeugung eines partiell entschlüsselten Codes;unddie Entschlüsselung des teilweise entschlüsselten Codes in der zweiten Code-Entschlüsselungsvorrichtung unter Einsatz der zweiten vertraulichen Seriennummer, um den neuen Code zurückzugewinnen, wobei jeder nachfolgende neue Code nur unter der zweiten vertraulichen nachfolgenden Seriennummer verschlüsselt wird, wobei die Steuerungsstufe die zweite Code-Entschlüsselungsvorrichtung nur dann betreibt, wenn ein neuer nachfolgender Code nur unter der zweiten vertraulichen Seriennummer verschlüsselt wird.
Independent claims39
138 paragraphs, as filed
<u>BACKGROUND OF THE INVENTION</u>
1. <u>Field of the Invention</u>
The present invention relates generally to the field of scrambling and transmission systems and more specifically, to an external security module for a television signal decoder of a broadcast, satellite, or cable television transmission system. Additionally, the present invention is more specifically directed to a method of transmitting subscriber information to subscription television signal distributors and methods for converting a television signal decoder to accept digital television signals. The present invention has particular application for B-type Multiplexed Analog Component (B-MAC) satellite transmission, but may also be used for NTSC (National Television Standards Committee), PAL, SECAM, or proposed high definition television formats. In addition, the scrambling system of the present invention can be used in applications in related fields such as electronic banking networks, telephone switching systems, cellular telephone networks, computer networks, etc. The system has particular application to so-called " conditional-access " multichannel television systems, where the viewer may have access to several "basic" channels, one or more "premium" or extra-cost channels as well as "pay-per-view" or "impulse pay-per-view" programs.
2. <u>Description of the Relevant Art</u>
In a pay television system, a pay television service provider typically protects the signal from unauthorized subscribers and pirates through scrambling.
For the purposes of the following discussion and this invention, the term "subscriber" means one who is paying for the television service. The "subscriber" could thus be an individual consumer with a decoder in his own home, or could be a system operator such as a local cable TV operator, or a small network operator such as a Hotel/Motel operator with a central decoder for all televisions in the Hotel or Motel. In addition, the "subscriber" could be an industrial user, as described in U.S. Patent 4,866,770 assigned to the same assignee as the present application and incorporated herein by reference.
For the purposes of this invention, a network is defined as a program source, (such as a pay television provider), an encoder, (sometimes called a "headend "), a transmission means (satellite, cable, radio wave, etc.) and a series of decoders used by the subscribers as described above. A system is defined as a program source, an encoder, a transmission means, and a single receiving decoder. The system model is used to describe how an individual decoder in a network interacts with the encoder
The scrambling process is accomplished via a key which may itself be encrypted. Each subscriber wishing to receive the signal is provided with a decoder having an identification number which is unique to the decoder. The decoder may be individually authorized with a key to descramble the scrambled signal, provided appropriate payments are made for service. Authorization is accomplished by distributing descrambling algorithms which work in combination with the key (and other information) to paying subscribers, and by denying that information to non-subscribers and to all would-be pirates.
The key may be transmitted as a data signal embedded in the normal television transmission associated with the identification number of the decoder. In a typical television signal, there are so-called "vertical blanking intervals" (VBI) occurring in each field and "horizontal blanking intervals" (HBI) occurring in each line between the chrominance and luminance signals. Various other signals can be sent "in-band" in the vertical and horizontal blanking intervals including additional audio channels, data, and teletext messages. The key can be embedded in these "blanking intervals" as is well known in the art. Attention is drawn to U.S. Patent No. 4,829,569 assigned to the same assignee as the present application and incorporated herein by reference, showing how such data can be embedded in a B-MAC signal. Alternatively, the key may be sent "out-of-band" over a separate data channel or even over a telephone line.
Maintaining security in a conditional-access television network depends on the following requirements: <ul id="ul0001" list-style="none" compact="compact"><li>(i) The signal scrambling techniques must be sufficiently complex to insure that direct encryptographic attack is not practical.</li><li>(ii) keys distributed to an authorized decoder cannot be read out and transferred to other decoders.</li></ul>
The first condition can be satisfied by practical scrambling algorithms now available such as the DES (Data Encryption Standard) or related algorithms.
The second condition requires the physical security of certain devices within the television signal decoder and is much more difficult to satisfy. Such a device must prevent observation of both the key decryption process and the partially decrypted key signals.
Figure 1 shows a prior art conditional-access system for satellite transmission. In encoder <b>101</b>, the source program information <b>102</b> which comprises video signals, audio signals, and data is scrambled in program scrambler <b>103</b> using a key from key memory <b>104</b>. The scrambling techniques used may be any such techniques which are well known in the art. The key can be a signal or code number used in the scrambling process which is also required to "unlock" or descramble the program in program descrambler <b>108</b> in decoder <b>106</b>. In practice, one key can be used (single layer encryption) or more than one key (not shown). The key is usually changed with time (i.e. - monthly) to discourage piracy. The scrambled programs and the key are transmitted through satellite link <b>105</b>, and received by conditional-access decoder <b>106</b>. Decoder <b>106</b> recovers the key from the received signal, stores it in key memory <b>107</b> and applies it to program descrambler <b>108</b> which descrambles the scrambled program received over satellite link <b>105</b>, and outputs unscrambled program <b>109</b>. The system is not totally secure, as the key is transmitted in the clear through the channel and is available for recovery by pirates.
To overcome this difficulty and referring to prior art Figure 2, a method of protecting the key during distribution is introduced into the system of Figure 1. Prior to transmission, the key used to scramble source program <b>202</b> in program scrambler <b>203</b> is recovered from key memory <b>204</b> and itself encrypted in key encryptor <b>210</b> using a secret serial number (SSN) from secret serial number database <b>211</b> which contains a list of the secret serial numbers of all legitimate subscribers. These secret serial numbers may relate to the unique identification numbers mentioned above for each decoder of a network of such decoders. The source program has now been scrambled using the key, and the key itself has been encrypted using a secret serial number. Thus, the key is not subject to compromise or recovery during transmission in comparison with the system of Figure 1. In order to descramble the program, the pirate must first obtain the secret serial number of a legitimate decoder, match it with the appropriately encrypted key, decrypt the key, and then descramble the program. The secret serial number is installed in decoder <b>206</b>, for example, during manufacture in SSN memory <b>212</b> resident in decoder <b>206</b>. The secret serial number is therefore unavailable to pirates provided that decoder <b>206</b> remains physically secure.
Each secret serial number is unique to an individual decoder or, at least, unique to a group of decoders in order to be reasonably secure. The encrypted key may therefore be transmitted to each decoder individually by cycling through a database <b>211</b>, containing all the secret serial numbers of the network in encoder <b>201</b> and forming a separate key distribution message in an addressed data packet individually addressed to each authorized decoder in the network. An individual decoder recognizes when its encrypted key has been received by reading the key distribution message attached to the encrypted key. A typical address data packet is depicted in Figure 9 and described more fully below.
In known B-MAC systems, the key is distributed in an addressed data packet individually addressed to a particular subscriber's decoder by means of its unique identification number. The addressed data packet is typically inserted in lines 4 through 8 of the vertical blanking interval. Each addressed data packet is typically addressed to one individual decoder. As there are sixty fields generated per second (30 frames of 2 interlaced fields each) in a B-MAC or NTSC television signal, at the rate of one addressed data packet per field, a possible sixty different decoders (or groups of decoders) can be addressed each second, or 3600 per minute, 215,000 per hour, and over 5 million per day. Since each decoder need only be addressed when the service level or encryption level changes, there are sufficient frames available to individually address each decoder even in large systems. The address rate of the decoders may be increased by transmitting more than one addressed data packet per field. Additional data packets may be inserted in the vertical blanking interval or in the horizontal blanking intervals of each frame. The total number of possible addressable decoders is a function of the number on data bits available for decoder addresses. The B-MAC format typically uses 28 bits for decoder addresses, allowing for over 268 million possible decoder addresses. Attention is drawn to the United States Advanced Television Systems Committee Report T2/62, "MULTIPLEXED ANALOG COMPONENT TELEVISION BROADCAST SYSTEM PARAMETER SPECIFICATIONS,"incorporated herein by reference, which describes the data format in a B-MAC signal.
After receiving the addressed data packet, key decryptor <b>213</b> then decrypts the key using the secret serial number stored in SSN memory <b>212</b>. If service to any decoder <b>206</b> in the network is to be terminated, the secret serial number for that decoder is simply deleted from SSN database <b>211</b>, and decoder <b>206</b> is deauthorized at the beginning of the next key period.
In a decoder such as the one shown in Figure 2, the pay television provider has to rely on the physical security of the decoder box itself to prevent a pirate from reading or modifying the secret serial number and key memories in the decoder or observing the key decryption process. In order to provide the necessary physical security, decoder boxes can be equipped with tamper-proof seals, specially headed screws and fasteners, or other tamper resistant packaging to make physical compromise of the decoder difficult. The subscriber is aware that tampering with the decoder could alter the tamper-proof seals or damage the decoder and subsequent examination could lead to discovery.
There are several disadvantages of relying on the physical security of the decoder to maintain system security. First, the pay television provider has to maintain ownership and control over all of the decoders of the network and then rent or lease the decoders to subscribers. The pay television provider is thus responsible for maintenance of all decoders and must maintain an expensive parts inventory and maintenance staff. In addition, in order to initiate service, a serviceperson must make a personal visit to the subscriber's location to install the decoder. In a pay television satellite system, such installation and service calls could be quite costly for remote installations which could be located anywhere in the world. Further, the physical security of a decoder could be breached without fear of discovery if a pirate could obtain a decoder that had been stolen either during the distribution process or from an individual subscriber's home.
Hence, the system of Figure 2 can be secure only under the following conditions: <ul id="ul0002" list-style="none" compact="compact"><li>(i) It must be impossible to read or modify the SSN and key memories in the decoder.</li><li>(ii) It must be impossible to observe the key decryption process, or the links between the four elements (<b>207, 208, 212,</b> and <b>213</b>) of the decoder.</li></ul>
One way to achieve both of these goals is by the use of a so-called " secure microprocessor".
<u>Decryption Microprocessors</u>
Figure 3 shows a block diagram of a typical prior art microprocessor <b>320</b> with processor <b>321</b>, program memory <b>322</b>, memory address bus <b>328</b>, memory data <b>326</b> and memory data bus <b>327</b>. In such a device, input data <b>323</b> is processed according to a program stored in program memory <b>322</b>, producing output data <b>324</b>. Program memory <b>322</b> can be "read out" through memory data bus <b>327</b>. That is, the memory can be stepped through by sequentially incrementing memory address <b>325</b> through memory address bus <b>328</b> into program memory <b>322</b>. Output memory data <b>326</b> from memory data bus <b>327</b> will reveal the entire program contents of microprocessor <b>320</b>, including any stored descrambling algorithm and secret serial number. With such data, a pirate can easily decrypt a key transmitted through satellite link <b>205</b> of Figure 2.
Figure 4 shows a block diagram of an ideal secure microprocessor <b>420</b> adapted for securing an algorithm and secret serial number according to one aspect of the present invention. The major difference between secure microprocessor <b>420</b> of Figure 4 and microprocessor <b>320</b> of Figure 3 is that both memory address bus <b>328</b> and memory data bus <b>327</b> are absent, so there is no way to step through program memory <b>422</b> for the purpose of reading or writing. Memory references are executed only by processor <b>421</b> according to its mask-programmed code which cannot be changed. All input data <b>423</b> is treated as data for processing, and all output data <b>424</b> is the result of processing input data <b>423</b>. There is no mechanism for reading or modifying the contents of program memory <b>422</b> via the data inputs.
Modern devices are a close approximation to this ideal secure microprocessor. There is, however, one requirement which causes a variation from the ideal. Following manufacture, there must be a mechanism available to write into memory <b>422</b> the decoder specific secret serial number <b>430</b>, as well as decryption algorithm <b>434</b>. If this facility were available to a pirate, he could modify the secret serial number for the purpose of cloning. Therefore, this facility must be permanently disabled after the secret serial number has been entered.
A variety of techniques may be used to disable the facility for writing into the memory. Secure microprocessor <b>420</b> could be provided with on-chip fusible data links <b>431</b>, a software lock, or similar means for enabling the secret serial number <b>430</b> and descrambling algorithm <b>434</b> to be loaded into memory <b>422</b> at manufacture. Then, for example, the fusible links shown in dashed lines are destroyed so that a pirate has no access to descrambling algorithm <b>434</b> or secret serial number <b>430</b> stored in program memory <b>422</b>.
In an alternative embodiment, the microprocessor of Figure 4 can be secured with an "E<sup>2</sup> bit." The "E<sup>2</sup> bit", a form of software lock, will cause the entire memory (typically EEPROM) to be erased if an attempt is made to read out the contents of the memory. The "E<sup>2</sup> bit" provides two advantages; first, the memory is secured from would-be pirates, and second, the memory erasure will indicate that tampering has occurred.
A pirate would have to have access to extensive micro-chip facilities and a significant budget to compromise such a secure microprocessor. The physical security of the processor would have to be breached, destroying the processor and contents. However, integrated circuit technology continuously improves, and unexpected developments could occur which might enable attacks to be made at the microscopic level which are more economic than those available today. Further, the worldwide market for pirate decoders for satellite transmissions would provide the economic incentive to the increasingly sophisticated pirate electronics industry to compromise such a unit.
Copying a single decoder comprising a microprocessor according to Figure 4 could lead to decoder clones based on the single secret serial number in that single decoder. Discovery would result in the termination of that secret serial number, and thus termination of all of the clones. However, a pirate would also have the option of using the single compromised unit to recover the key. The pirate could then develop a decoder design which would accept the key as a direct input. These pirate units could then be illegally distributed to subscribers, who would pay the pirate for a monthly update of the key. The consequence of a security breach could become extremely damaging to the pay television provider.
<u>Replaceable Security Module</u>
Pay television providers are therefore at risk if security depends exclusively on the physical defenses of the secure microprocessor. Figure 5 shows a device which attempts to overcome the disadvantages of the devices of Figures 1 and 2 by providing a security device in a replaceable security module <b>514</b>. Replaceable security module <b>514</b> comprises key decryptor <b>513</b>, secret serial number memory <b>512</b> and key memory <b>507</b>. As in Figure 2, encoder <b>501</b> scrambles source program <b>502</b> comprising video signals, audio signals and data in program scrambler <b>503</b> using a key from key memory <b>504</b>. The key is encrypted in key encryptor <b>510</b> using a secret serial number (SSN) from secret serial number database <b>511</b> which contains a list of the secret serial numbers of all legitimate subscribers.
The same SSN is installed in secret serial number memory <b>512</b> in replaceable security module <b>514</b> which is removably attachable to decoder <b>506</b>. Key decryptor <b>513</b> of replaceable security module <b>514</b> decrypts the key using the secret serial number stored in secret serial number memory <b>512</b>. The decrypted key is then stored in key memory <b>507</b>. Unlike Figure 2, the entire replaceable security module is removably attached to decoder <b>506</b>. Program descrambler <b>508</b> reads the decrypted key from key memory <b>507</b> in replaceable security module <b>514</b> and uses the key to descramble and output descrambled program <b>509</b>. Removable security module <b>514</b> is designed to be replaced by the subscriber, preferably without any special tools and, thus, most conventionally may comprise a plug-in module.
The use of a plug-in external module gives the pay television provider the ability to upgrade the technology in the security device by swapping it out at very low cost. In the event of a security breach, a new replaceable security module containing the program scrambling algorithm and SSN could be mailed out to authorized subscribers. The authorized subscribers could then remove the old replaceable security module from their decoder and insert the new replaceable security module themselves. System security is thus recovered without the expense of replacing the entire decoder or the expense of sending a service person to replace the replaceable security modules in each decoder. In addition, it is not necessary for the pay television provider to own the decoder itself. The decoder can be a generic commercially available unit purchased by the subscriber, or even integrated into the television itself. To initiate service, the pay television provider need only mail the replaceable security module to the subscriber and no service call is necessary.
Although the replaceable security module has the advantages of providing a guarantee that network security is recoverable following a breach, it also has some disadvantages. All the security resides in replaceable security module <b>514</b>, and decoder <b>506</b> itself is a generic unit. The key signal which is generated by replaceable security module <b>514</b> is observable at its transfer point to decoder <b>506</b>. The key can, however, be changed sufficiently often to ensure that it has no value to a potential pirate.
The problem with this approach is that a given removable security module <b>514</b> will operate with any decoder <b>506</b>, and that tampering with replaceable security module <b>514</b> does not involve damage to decoder <b>506</b>. Consequently, if replaceable security module <b>514</b> were to be compromised, piracy would become widespread very rapidly.
<u>Multiple Encryption Layers</u>
Although the devices as described above show a single key to scramble the program signal (so-called "single layer encryption") any of the prior art devices could also be practiced using a multiple key ("two layer", "three layer", etc.) scrambling system. A multiple key encryption system with particular applications to a cable television environment is described in U.S. Patent No. 4,890,319, to Seth-Smith, issued December 26, 1989, incorporated herein by reference. Figure 6 shows an example of a prior art two layer encryption encoder <b>601</b>. Encoder <b>601</b> contains secret serial number database <b>611</b> which contains a list of secret serial numbers for all authorized subscribers, these serial numbers preferably being 56 bits in length. Key memory <b>604</b> stores the "Key of the Month" (KOM) which in this embodiment can be either an "even" key for even months (February, April, June, etc.) or an "odd" key for odd months (January, March, May, etc.). The key could also be different for each month of the year, or could be made even more unique, depending on the available data bits for such a key. In addition, the key could be changed more frequently or less frequently than the monthly basis shown here. These KOM's are preferably 56 bits in length.
Key encryptor <b>610</b> encrypts the key selected from key memory <b>604</b> and outputs a series of encrypted keys E<sub>SSN</sub>[KOM] each encrypted with a secret serial number from secret serial number database <b>611</b>, to data multiplexor <b>635</b>. Seed memory <b>636</b> contains a "seed" which is used for scrambling the audio and video signals. The "seed" can also be a data code or a signal similar to the key described above. Preferably, the seed changes every 1/4 second. Seed encryptor <b>637</b> encrypts the seed with the key of the month and outputs the encrypted seed E<sub>KOM</sub>[SEED] to data multiplexor <b>635</b>. Thus the key has been encrypted with the secret serial number, and the seed encrypted with the key. Neither the key nor the seed can be easily recovered during transmission.
In this embodiment, source program <b>602</b> comprises a Multiplexed Analog Video (MAC) signal <b>639</b> with the typical chrominance and luminance signals described previously, along with multiplexed audio data <b>638</b> which may comprise several different audio and non-audio (data) signals. For example, there may be at least two channels of audio (stereo) and additional channels of teletext for the hearing impaired. In addition, there may be additional channels of audio related to the video signal such as foreign language translations, unrelated audio signals such as radio programs or data signals such as subscriber messages, computer data, etc. All of these signals are digitized and multiplexed together, as is well known in the art, and the resulting multiplexed analog components, data <b>638</b> is then ready to be scrambled.
The seed passes through pseudo-random bit sequencer (PRBS) <b>643</b> and then is added to multiplexed audio data <b>638</b> in adder <b>644</b>. Together, pseudo-random bit sequencer (PRBS) <b>643</b> and adder <b>644</b> comprise a bit-by-bit encryptor <b>645</b> as is well known in the art. The resulting scrambled multiplexed audio data is then passed to data multiplexor <b>635</b> and is multiplexed with the encrypted seed and key.
MAC video signal <b>639</b> is scrambled in line translation scrambler <b>603</b> which scrambles the lines of the MAC signal using the "seed" from seed memory <b>636</b> for the scrambling algorithm. The resulting scrambled MAC signal is then sent to multiplexor <b>632</b> which multiplexes the scrambled MAC signal with the output from data multiplexor <b>635</b>. The multiplexed data output of data multiplexer <b>635</b> is modulated into pulse amplitude modulation (PAM) format by P.A.M. modulator <b>645</b>. The output B-MAC signal <b>646</b> contains MAC video signal <b>639</b> and multiplexed PAM audio data <b>638</b>, both scrambled with the seed, along with the seed encrypted with the key of the month, and a series of keys of the month which have been encrypted with the secret serial numbers of the subscriber's decoders, all multiplexed together.
In order to descramble the B-MAC signal <b>646</b>, a pirate must be able to decrypt one of the encrypted keys, and use that key to decrypt the seed. However, as in the single layer encryption device described in Figure 2, the pirate only needs to compromise one of the decoders in order to obtain a secret serial number, and thus decrypt the key. With the key, a pirate can then decrypt the seed, and with the seed, descramble the program signal. Additional "layers" of encryption (i.e. - more seeds and keys) make pirating more cumbersome, as the pirate must decrypt more seeds and keys, however, once the first key has been decrypted, the subsequent keys and seeds can be decrypted as well. In the embodiment shown in Figure 6, keys need be decrypted every month for the pirate to be able to descramble the program signal all year. The secret serial numbers, seed, and key, as used in Figure 6, can be used effectively by the pay television provider to terminate a particular decoder by secret serial number and generally discourage piracy by amateurs. However, while this system has not yet been compromised, a determined pirate may compromise such a multi-layered encryption system with the aid of a compromised decoder, the heart of such piracy being the gaining of access to a secret serial number
A particular problem involves the transmission of the encrypted seeds and/or encrypted KOM's with the encrypted program signal to individual subscribers who may have their own antenna, commonly a backyard reception dish. Referring to Figure 11, prior systems used a central control <b>1181</b> to insert addressed data packets or other subscriber related information into the program signals to authorize those individual receivers who receive encrypted signals directly, not through a local distributor. Central control <b>1181</b> would transmit addressed data packets, via dedicated lines <b>1185</b>, to uplink broadcaster <b>1183</b> (e.g., Home Box Office, Cinemax, etc. ) who would in turn multiplex the addressed data packets with their program signals, usually encrypted. The signals would be transmitted to satellite <b>1105</b> and then back to an individual receiver <b>1189</b> typically through backyard reception antenna <b>1187</b>. If a individual desired to receive certain programs, they would place a call through phone line <b>1188</b> to central control <b>1181</b>. Central control in turn would relay the individual's authorization request through dedicated lines <b>1185</b> to uplink broadcasters <b>1183</b>. Uplink broadcasters then would multiplex the individual's new authorization code with their particular encrypted program signals. The signals would then relay through satellite transponder <b>1105</b> to the individual's antenna <b>1187</b> and into their decoder box where the new authorization request would permit them to decrypt the new program signals. Such a system is currently used by General Instrument's Video Cypher II∼ TM system. Importantly, due to the transmission limitations of dedicated lines <b>1185</b>, typically telephone lines, a broadcaster could not rapidly address all subscribers.
An additional problem with the prior art involve the upgrading of current television decoders to accept digital television signals. Previously, local cable television distributors would have to replace all existing converting boxes in subscriber homes with new converter boxes which could accommodate digital television signals. This was costly because new decoder boxes would have to be distributed and the old boxes collected and often times destroyed. Alternatively, a local cable television distributor could distribute new decoder boxes which would only accept digital television signals. Thus, subscribers would have their original decoder box which would accept analog signals while the new box would accept digital signals. This too was costly as many circuits within the two boxes would be redundant, additional spliters would have to be added at a subscriber's home to provide for two coaxial inputs to the boxes, in addition to other annoyances previously mentioned.
In view of the deficiencies of the above prior art devices, it still remains a requirement in the art to provide a scrambling system for pay television systems which does not reply solely on the physical security of the decoder components to maintain system integrity.
<b>SUMMARY OF THE INVENTION</b>
The invention is defined in the claims to which reference should now be made.
It is an object of the present invention to provide a decoder with a data interface for a removable security module.
It is a further object of the present invention to provide a replaceable security module capable of performing all the functions performed by the internal security module.
It is further object of the present invention to provide a system of double-encrypting the key using two different secret serial numbers respectively assigned to a subscriber's decoder and removable security module.
It is a further object of the present invention to provide a replaceable security module for a television signal decoder where the replaceable security module will work with only one decoder and cannot be used with another decoder.
It is still a further object of the present invention to provide a decoder where external security modules may be replaced without any disruption in a subscriber's reception of authorization signals.
It is yet a further object of the present invention to provide a method of transmitting the same authorization signals on multiple channels, to individual subscription television receivers.
It is yet a further object of the present invention to provide a low cost method of easily converting a decoder box to accept both analog and digital television signals without redundant circuitry.
Many of the above-stated problems and related problems of the prior art encryption devices have been solved by the principles of the present invention which is able to twice-encrypt the key prior to transmission, first with a first secret serial number (SSN<sub>0</sub>) of the subscriber's replaceable external security module, and again with a second secret serial number (SSN<sub>1</sub>) of the subscriber's decoder. The double-encryption technique discourages copying the replaceable external security module, as each replaceable security module will work only with its mating decoder. The system also allows the replaceable security module to be replaced following a system breach, thus allowing for recovery of system security. Furthermore, the present invention allows for uninterrupted transmission of decrypted signals upon replacement of the external security module by providing three steps of decryption. First, incoming signals are decrypted using the second secret serial numbers of the subscriber's decoder, before a new replaceable external security module is inserted into the decoder. Second, a valid key of the month (KOM) is delivered to the internal security module where it is decrypted using an alternate secret serial number (SSN). The packet is then forwarded to the new external security module where it is further decrypted and the valid KOM is stored. Finally, decryption of incoming signals are then routed to the external security module which becomes the active security element.
The system comprises an encoder for encoding a signal, the encoder further comprising a signal scrambler and a first and second key encrypters. The signal scrambler scrambles the signal and outputs a scrambled signal and a key for descrambling the scrambled signal. The first key encryptor is coupled to the signal scrambler and performs a first encyrption on the key using a first secret serial number and outputs a once-encrypted key. The second key encryptor is coupled to the first key encryptor and performs a further encryption on the once-encrypted key using a second secret serial number and outputs a twice-encrypted key.
The system further comprises a transmitter coupled to the signal scrambler and the second key encryptor for transmitting the scrambled signal and twice-encrypted key.
The system further comprises a routing manager/decoder coupled to the transmitter for receiving and descrambling the scrambled signal. The decoder comprises first and second key decryptors and a descrambler. In the twice encrypted mode, the first key decryptor is coupled to the transmitter and performs a first key decryption on the twice-encrypted key using the second secret serial number and outputs a partially decrypted key. The second key decryptor is coupled to the first key decryptor and perform a second key decryption on the partially decrypted key using the first secret serial number and outputs the decrypted key. The descrambler is coupled to the second key decryptor and the transmitter and descrambles the scrambled signal using the decrypted key and outputs the descrambled signal. The decoder may function without the use of a replaceable security module. In the event of a system breach or a service level change, a replaceable security module may then be inserted into the decoder to "upgrade" the decoder.
In another embodiment of the present invention, authorization signals are transmitted from a master uplink through a satellite transponder into a loop-back uplink. At the loop-back uplink, program audio and video signals are combined with the authorization signals and sent back to the satellite transponder then to an individual subscription television signal receiver
In a further embodiment of the present invention, an easily connectable module or "side-car" is described which permits a standard decoder box to accept both analog and digital television signals. This digital side-car is capable of upgrading existing converter boxes without the duplication of non-video components.
These and other objects and advantages of the invention, as well as the details of an illustrative embodiment, will be more fully understood from the following specification and drawings in which similar elements in different figures are assigned the same last two digits to their reference numeral (i.e., decoder 7<u>06</u> of Figure 7 and decoder 8<u>06</u> of Figure 8).
<u>BRIEF DESCRIPTION OF THE DRAWINGS</u>
FIG. 1 shows an example of a prior art conditional-access system for satellite transmission with a key signal sent in the clear to the decoder.
FIG. 2 shows an example of a prior art conditional-access system for satellite transmission using a single key encryption technique.
FIG. 3 shows an example of a prior art microprocessor without a secure memory.
FIG. 4 shows a secure microprocessor with a secure memory and fusible data links adapted for storing an algorithm and secret serial number according to the present invention.
FIG. 5 shows an example of a conditional-access system for satellite transmission with a replaceable security module containing a first secret serial number.
FIG. 6 shows another prior art conditional-access system for satellite transmission using an additional layer of encryption,
FIG. 7 shows one exemplary embodiment of the conditional-access system of the present invention with an encoder encrypting the key with both a first and second secret serial number, a satellite transmission system, and a decoder containing a first secret serial number and a replaceable security module containing a second secret serial number.
FIG. 8 shows an expanded view of the decoder of FIG. 7
FIG. 9 shows a frame format for an addressed data packet.
FIG. 9A shows a frame format for a system data packet.
FIG. 10 shows communications between a secure microprocessor, either internal or external, and the routing manager.
FIG. 11 shows a prior art system of transmitting authorization signals and addressed data packets between a central control and an individual television subscriber.
FIG. 12 shows another embodiment of the present invention for transmitting the same authorization signals on multiple channels from a central control to an individual television subscriber.
FIG. 13 shows another embodiment of the present invention where the decoder depicted in FIGS. 7 and 8 may be easily upgraded to accept both analog and digital television signals.
<u>DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENT</u>
Figure 7 shows the encryption system of the present invention comprising an encoder <b>701</b> for encoding a source program <b>702</b> for transmission over a satellite link <b>705</b> to at least one decoder <b>706</b>. According to Figure 7, the key is encrypted and addressed to individual decoders, similar to the device in Figure 5. However, in this case, the key may be encrypted twice.
Encoder <b>701</b> has an active security selection memory <b>721</b> containing the active security selection. The active security selection selects the fixed security element <b>719</b> or the replaceable security element <b>714</b> as the active security element. Only the active security element will received B-MAC signals and supply the seed to the program scrambler <b>703</b>. A key memory <b>704</b> contains the active security selection <b>721</b> and the seed used to scramble program <b>702</b> in program scrambler <b>703</b>. Alternatively, as in FIG. 6, key memory <b>604</b> could contain keys of the month (KOMs) which are used to encrypt a seed. This seed is used to encrypt the source program <b>702</b>. In this double encryption technique, the KOM is first encrypted in first key encryptor <b>710</b> with a first secret serial number (SSN<sub>0</sub>) stored in SSN<sub>0</sub> database <b>711</b>. The KOM is further encrypted in second key encryptor <b>715</b> with a second secret serial number (SSN<sub>1</sub>) from SSN<sub>1</sub> database <b>716</b>. This process continues for each SSN so as to produce a series of encrypted keys which are then multiplexed with the scrambled program via multiplexer <b>732</b> and transmitted via satellite link <b>705</b>.
Decoder <b>706</b> receives and demultiplexes the encrypted program and encrypted keys via demultiplexer 733 and performs a first key decryption in internal security module <b>719</b> which is an integral part of the decoder <b>706</b>. A second decryption takes place in a replaceable external security element <b>714</b> which is mounted on the exterior of the decoder <b>706</b>, for example, as a plug-in module. Alternatively, the encrypted key could be sent separate from the encrypted program over two separate channels as described in copending application serial number 473,442, incorporated herein by reference.
Internal fixed security module <b>719</b> is the default security element when the replaceable external security module <b>714</b> is not installed. Internal security module <b>719</b> will receive system data routed from routing manager <b>708</b>. The authorization and control data will preferably comprise or include addressed data packets as depicted in FIG. 9 and system data packets depicted in 9A. Addressed data packets 9e include preferably a 28 bit user identification number or address 9a which is sent unencrypted. This user address corresponds to a user address contained in both internal and external security modules <b>719</b> and <b>714</b>. The routing manager <b>708</b> senses the unique user address of only internal security module <b>719</b> and correspondingly routes the entire addressed data packet 9e to the specified security module. Following the user address are two unencrypted bits 9b and 9c. The first bit 9b determines whether the addressed data packet is to be ultimately routed to the internal security module <b>719</b> or to the external security module <b>714</b>. The second bit 9c determines whether the information which follows, encrypted information 9d, is encrypted either once or twice. If bit 9c indicates double encryption, then both the internal security module <b>719</b> and the external security module <b>714</b> are required to decrypt it. The bits of encrypted data 9d would include authorization and control data, e.g., the key of the month, subscriber authorization data such as user tier information, pay-per-view information, or other subscriber specific or decoder specific data. Generally, authorization data determines whether a particular subscriber or decoder is authorized to receive and decrypt a particular program or view pay-per-view programs, etc. Control data may include signals to determine where data packets are routed, energy management data, burglar alarm data, or other decoder component enabling signals.
Table 1 shows how addressed data packets 9e are routed depending upon the value of bits 9b and 9c. <tables id="tabl0001" num="0001"><table frame="all"><title>TABLE 1</title><tgroup cols="3" colsep="1" rowsep="1"><colspec colnum="1" colname="col1" colwidth="52.50mm" /><colspec colnum="2" colname="col2" colwidth="52.50mm" /><colspec colnum="3" colname="col3" colwidth="52.50mm" /><thead valign="top"><row><entry namest="col1" nameend="col1" align="left"><b>Destination Bit 9b</b></entry><entry namest="col2" nameend="col2" align="left"><b>Encryption Bit 9c</b></entry><entry namest="col3" nameend="col3" align="left"><b>Routing of Address Data Packet (ADP) Result</b></entry></row></thead><tbody valign="top"><row><entry namest="col1" nameend="col1" align="left">internal</entry><entry namest="col2" nameend="col2" align="left">single</entry><entry namest="col3" nameend="col3" align="left">ADP to internal security module only</entry></row><row><entry namest="col1" nameend="col1" align="left">internal</entry><entry namest="col2" nameend="col2" align="left">double</entry><entry namest="col3" nameend="col3" align="left">ADP to external module first, then to internal</entry></row><row><entry namest="col1" nameend="col1" align="left">external</entry><entry namest="col2" nameend="col2" align="left">single</entry><entry namest="col3" nameend="col3" align="left">ADP to external security module only</entry></row><row rowsep="1"><entry namest="col1" nameend="col1" align="left">external</entry><entry namest="col2" nameend="col2" align="left">double</entry><entry namest="col3" nameend="col3" align="left">ADP to internal module first, then to external</entry></row></tbody></tgroup></table></tables>
The system data packet shown in Figure 9A contains program specific information and is sent and processed by all decoders. The system data packet 9h includes an internal/external destination bit 9f similar to bit 9b in addressed data packet 9e. Bit 9f determines where the system data packet is routed by routing manager <b>708</b>, specifically, whether packet 9h is routed to the internal or the external security module. The information following, 9g, is encrypted data including the encryption seed, program tier information which determines in which tier the particular program is located, the cost of the program for pay-per-view purposes, checksum bits, and any additional information which is specific to the program or channel in which system data packet 9h is transmitted. Restating, system data packets 9h are specific to a particular program or channel, and are preferably inserted by program broadcasters (shown as <b>1183</b> in Figure 11 and <b>1286</b> in Figure 12). Each program is preferably encrypted with its unique seed.
As discussed earlier with reference to Figure 6, the internal and external security modules must first receive and decrypt their unique addressed data packets to recover the key of the month. Using this key of the month then, the internal and external security modules would use this key of the month to decrypt the seed from system data packets 9h. Finally, the seed is sent from the security module through routing manager to video descrambler <b>873</b> or audio/data decryptor <b>874</b> so as to decrypt a program video or audio.
All data contained in addressed data packet 9e and system data packet 9h may be processed by the internal security module <b>719</b>. Similarly, the external security module <b>714</b> may replace the functionality of the internal security module <b>719</b> when it is installed. External security module <b>714</b> will be used as the active security element when directed by unencrypted data bit 9f of system data packet 9h. This allows external security module <b>714</b> to be deployed, inserted and authorized with addressed data packet information (particularly, KOM's) before the system switches the active security element from the internal security module <b>719</b> to the external security module <b>714</b>. This process will be described more fully below. As previously mentioned, addressed data packets 9e contain user addresses 9a which is unencrypted and unique to each internal security module <b>719</b>. The external security module <b>714</b> also has a unique user address which is used to track location of external modules. Once the external security module <b>714</b> is inserted, it may customize itself to the user address of the internal security module <b>719</b> by having the user address of internal security module <b>719</b> route its address to external security module <b>714</b> which may store this address in secure memory <b>720</b>.
The addressed data packets 9e are used to deliver decoder specific information to a single decoder, preferably using the loop-back method described below with respect to Figure 12. In a B-MAC television signal, the addressed data packets are preferably transmitted during the vertical blanking interval of each frame as discussed in the background of the invention. Each subscriber would have a unique address data packet corresponding to their decoder <b>706</b>. Each decoder is assigned a single unique user address and a corresponding secret serial number (SSN). The user address and corresponding secret serial number are not identical, nor or they related. Preferably, the secret serial numbers are generated using a random number generator. When an address data packet with a corresponding user address is received, the packet can be decrypted thus revealing the KOM and data. All decrypted data (e.g., KOM's, tier data, PPV, etc.) is held within a secure memory within the module (<b>707</b> or <b>720</b>). The packets preferably contain a checksum which is used to verify both correct reception and decryption of the data. All addressed data packets are received by the routing manager <b>708</b>, and, depending upon the value of bit 9b, sent to the indicated security module for decryption. The decrypted and stored data is used by the conditional access software or program authorization software contained within the security modules to determine whether a particular program is to be decrypted depending upon a subscriber's tier, pay-per-view account, etc. Security modules <b>714</b> and <b>719</b> also determine whether a particular piece of encrypted data is to be placed within its secure memory module. For example, the call back telephone number used by modem <b>875</b> need not be stored in the secure memory, and thus, is passed to the modem.
Both replaceable security module <b>714</b> and an internal security element <b>719</b> of decoder <b>706</b> may be constructed according to the principles of Figure 4. For example, the second secret serial number SSN<sub>1</sub> may be loaded into SSN<sub>1</sub> memory <b>717</b> of module <b>714</b> via fusible links, and then these links destroyed during manufacture. Similarly, SSN<sub>0</sub> memory <b>712</b> of internal security element <b>719</b> may be loaded during manufacture over a fusible link and then the link destroyed. Also over a fusible link, algorithms may be loaded into key decryptors <b>718</b>, <b>713</b> during manufacture and the fusible links subsequently destroyed
The replaceable security module provides the pay television provider with the option of replacing system security by mailing out new replaceable security modules to all authorized subscribers. Returned replaceable security modules <b>714</b> could be re-used for a different decoder if the links were not destroyed by reprogramming the SSN<sub>0</sub> and SSN<sub>1</sub> databases <b>711</b> and <b>716</b> to correspond to the combination of the first secret serial number of decoder <b>706</b> with the second secret serial number of security module <b>714</b>. Preferably, the returned replaceable security modules <b>714</b> are destroyed, and a new replaceable security module <b>714</b> sent to a subscriber, incorporating changes and improvements in the security technology to thwart potential pirates. In the event of a security breach, it is only necessary to replace the replaceable security module and not the complete decoder in order to restore system security. Most advantageously, the subscriber replaces the external security module without special assistance, and returns the old module to the service provider.
Referring to Figure 8, an enlarged picture of encoder <b>706</b> is shown, particularly, program descrambler/routing manager <b>708</b> is more fully depicted. Incoming television signals, preferably B-MAC television signals, are input into demultiplexer <b>833</b>. The demultiplexer separates video, digital audio, teletext, and authorization and control data. The authorization and control data, particularly addressed data packets 9e and system data packets 9h, are input into display and communication processor <b>870</b>. Demultiplexer <b>833</b> also provides error correcting and data recovery for the incoming signal. Furthermore, the incoming signal is formatted into a form which is more easily usable by the display and communications processor <b>870</b>.
The authorization and control data, particularly addressed data packets 9e are input into the user interface logic <b>871</b> and the security routing manager <b>872</b> of the display and communication processor <b>870</b>. Specifically, the incoming data rate is usually too fast for processor <b>870</b> to handle, therefore demultiplexer <b>833</b> stores and formats the data, and inputs it as a parallel stream into user interface logic <b>871</b> and security routing manager <b>872</b>. If the addressed data packet 9e contains the unique user address 9a of this particular decoder <b>806</b> and the decryption bit 9c is set to single encryption, user interface logic <b>871</b> commands security routing manager <b>872</b> to pass the addressed data packet into internal security module (inboard security element or ISE) <b>819</b>, if destination bit 9b is so set. Alternatively, if destination bit 9b is set for the external security module <b>814</b>, security routing manager <b>872</b> forwards the address data packet through coupler <b>879</b> to the external security module (outboard security element or OSE) <b>814</b>. <u>See</u> Table 1.
If encryption bit 9c is set for single encryption, then depending upon destination bit 9b, either the internal or external security module decrypts the encrypted address data packet information 9d. Once the KOM is decrypted, it is stored in secure memory <b>720</b> and <b>707</b>, then used to decrypt the seed. This seed, preferably changing very frequently compared with the KOM, for example, every 1/4 second, is then routed from either the internal or external security module through routing manager <b>872</b> to video descrambler <b>873</b> or audio/data decryptor <b>874</b>. The seeds are used in video descrambler <b>873</b> and audio/data decryptor <b>874</b> to decrypt the video and audio/data respectively. Since the seed changes so frequently, every 1/4 second, it is not critical that the seed is sent unencrypted to video descrambler <b>873</b> and audio/data decryptor <b>874</b>.
If encryption bit 9c is set for doubling encryption and destination bit 9b is set to external, then an incoming addressed data packet 9e is partially decrypted first in the internal security module using a first secret/confidential serial number, and then finally decrypted in the external security module using a second secret/confidential serial number. The KOM is once again stored in secure memory <b>720</b> and is used to decrypt the seed.
Coupler <b>879</b> is also connected to audio/data decryptor <b>874</b> to allow for the audio/data decryptor to be upgraded by an external security module <b>814</b> which could contain additional decrypting algorithms directed to audio/data only. This would provide for increasing security of encrypted audio if current encryption of the audio had been compromised.
Telephone modem <b>875</b> may include a microprocessor to allow either the internal or external security modules <b>819</b> and <b>814</b> to communicate to encoder <b>701</b> or other facilities via telephone lines. This feature will be discussed more fully below.
Also shown in Figure 8 are front panel display <b>878</b> which includes input buttons for a subscriber and a display preferably on the front of decoder box <b>806</b>. On-screen displays/teletext <b>877</b> provides for on-screen messages or teletext to be either overlayed or displayed on a subscriber's television screen.
<u>Transferring Security Functions Between Modules</u>
The process of transferring the security functions from the internal security module to the external security module will be described now. Initially, all security functions are performed by internal security module <b>719</b>. If a security breach occurs, it may be defended against by manufacturing and distributing external security modules with instructions for installation into decoder <b>706</b>. At this point, the external security element does not have a valid key of the month in its secure memory <b>720</b> nor any appropriate tier and event numbers for the particular subscriber. Therefore, the external security element <b>714</b> cannot yet perform any independent security functions.
The KOM is delivered to the internal and external security modules using encrypted addressed data packets 9e. Because the external security element is installed to upgrade security, the addressed data packets for the internal security module and the external security module are encrypted differently using KOM's unique to each internal and each external security module. Therefore, the non-encrypted bit 9b determines the destination of the address data packet 9e, as shown in Table 1 above.
During this transition stage, addressed data packets carrying the next KOM are transmitted with destination bit 9b set to the external security module, with encryption bit 9c set to double encryption. The routing manager <b>708</b> still delivers the address data packet 9e to the internal security module first, but now the internal security module decrypts the address data packet 9d using an alternate secret serial number contained within its secret serial number memory <b>712</b>. This alternate secret serial number is not the one which is normally used by the internal security module for decrypting addressed data packets 9d. The result of this decryption using the alternate secret serial number is passed back to the routing manager <b>872</b> and forwarded to the external security module <b>814</b> for final decryption using the secret serial number of the external security module. Thus, the key of the month is twice encrypted, first with the alternate secret serial number and second with the external security module's secret serial number. This twice encryption prevents casual migration of external security modules between decoders <b>706</b> since both decoder-specific decryptions must be successful. Restating, the KOM is twice encrypted during the transition stage with a secret serial number stored in the secure memory of the internal security module, and a secret serial number stored in the secure memory of the external security module for each internal and external security module in existence.
If the KOM was not twice encrypted with an alternate SSN, then a pirate could alter destination and encryption bits 9b and 9c to transmit a decrypted KOM between security modules, and thus intercept is during transmission. By using the alternate SSN, if tampering of destination and encryption bits occur, the internal security module would believe the encrypted KOM were encrypted using the regular SSN, and thus could not decrypt the KOM. Only partially decrypted KOM's are passed between modules and only in the double encryption state. The present system prohibits the use of exchanging external security modules between decoders since both SSNs must correspond with a twice encrypted KOM.
When the next KOM has been transmitted to and stored in all decoders <b>706</b>, then the encoder <b>701</b> preferably changes the system data packet destination bit 9f to the external security module and encryption bit 9c to double encryption. The external security module <b>714</b> now becomes the active security element and assumes all security functions. Thus, the decrypting seeds are now decrypted with the KOM and released from the external security module <b>714</b> through security routing manager <b>872</b> to the video descrambler <b>873</b> and audio/data decryptor <b>874</b>. Since the external security module now also contains the subscriber's authorization data such as program and service tiers, and pay-per-view event authorization in its secure non-volatile memory, it may conditionally release seeds to decrypt specific programs independent from the internal security module. Similarly, being an independent security module, the external security module may record impulse pay-per-view event purchases from the user interface logic <b>871</b> and upload this information to a phone manager via telephone modem <b>875</b> using encrypted communications as described below. Encryption bit 9c may be changed to single encryption if so desired. The reason for adding an external security module is to recover security after the internal security module had been comprised. Thus, in the preferred embodiment, double encryption is used and the external security module becomes the active security element upon compromise of the internal security module.
Once external security modules have been deployed, new security functions (including new secret serial numbers, encrypting algorithms, software or physical security) may be incorporated into the internal security module so that an external security module is not required in new decoder boxes which are distributed after external security modules have been distributed. Still, an empty coupler <b>879</b> is provided for future external security modules. To provide for compatible transmission to future external security modules, the internal security module in these new decoder boxes must functionally emulate the previous-generation internal security module, as well as perform the same function as the internal-external security module combination, and it must respond to both address data packet destination bit 9b and encryption bit 9c.
If a previously distributed external security module is compromised, a new external security module is deployed, with the subscriber removing the old and inserting the new. The new external security module will not have the key of the month, or the subscriber's authorization and control data such as tiers or event numbers. Therefore, to maintain continuity of service, all security and authorization functions are temporarily returned to the internal security module. Prior to distribution/mailing of the new external security modules, addressed data packets are transmitted with the destination bit 9b set to the internal security module and encryption bit 9c set to single encryption. Thereafter, the previously described steps are performed with encryption bit 9c changing to double encryption to allow the new KOM to be twice decrypted and stored in the new external security module. Finally, security, authorization and control functions are switched to the external security module with encryption bits set for either or double.
Summarizing, if a system breach occurs, the pay television provider then mails out replaceable external security modules to subscribers, switches decryption to the internal security module until all decoders have the new KOM, then uses decryption through the external security module only or uses the double encryption technique, and thus recovers system security. The optional usage of the replaceable external security module has other attractive benefits as well. Subscribers who do not pay for any premium channels may not be sent a replaceable security module, as the "basic" channels may only use a once-encrypted key or may even be sent in the clear. If the subscriber wishes to upgrade to a premium channel or channels, the pay television provider may then mail that subscriber the appropriate replaceable security module.
In addition, the replaceable security module may be used to add other additional features. Many cable television systems offer optional services such as IPPV (Impulse-Pay-Per-View) which require two-way communication between the decoder <b>706</b> and the headend. In the past, if a subscriber wished to upgrade to IPPV service, a subscriber's decoder would have to be altered by inserting a IPPV module internally or by adding an IPPV "side car" externally. Alternatively, the entire decoder would have to be replaced. All three options would necessitate a service call, causing inconvenience to the subscriber, and expense to the pay television provider. Similarly, when a pay television provider wishes to upgrade its entire encoder/decoder <u>system</u>, it must provide a new decoder to each subscriber which will work in the interim with both the old and new encoding techniques, as it is nearly impossible to replace all subscriber decoders simultaneously. Thus a decoder manufacturer is faced with the added expense of providing his state-of-the-art decoder with extra circuitry in order to function with the pay television provider's old encoder for the few months during the change over period.
In all of the above instances of upgrading existing service, the replaceable security module <b>714</b> may be used to upgrade the decoder <b>706</b> without the expense and inconvenience of a service call. The replaceable security module <b>714</b> may be mailed to the subscriber and the subscriber can then insert the replaceable security module <b>714</b> and instantly upgrade the decoder or add additional features (such as IPPV), alter the decoding technique, or provide an additional level of security. Preferably, IPPV is incorporated within the decoder <b>706</b>. Notably, the replaceable security module <b>714</b> may add additional software features to the decoder.
The replaceable security module <b>714</b> may take one of several forms. In the preferred embodiment, the module may comprise a "smart card", a plastic "credit card" with a built-in microprocessor (such as a 68HC11 microprocessor), such as described by the International Standards Organization in standard ISO 7816/1 and ISO7816/2. Attention is drawn to U.S. Patent No. 4,841,133 issued June 20, 1989 and incorporated herein by reference, describing such a "smart card. " The "smart card" may be equipped with a series of electrical contacts which connect to contacts in coupler <b>879</b>. Preferably 16 contacts are provided so as to allow for plenty of expansion room if additional features are included in the future, since only 6 to 8 of the contacts would be used by the present invention. The contacts may provide power to the card, along with clock signals and data transmission. Additional contacts may be provided to allow connection between coupler <b>879</b> to audio/data decryptor <b>874</b>. These additional contacts would allow for additional decrypting algorithms to be applied in conjunction with or independent from those decrypting algorithms contained in decryptor <b>874</b> or for some other purpose.
<u>Use of Telephone Controller/Modem</u>
Pay-per-view programming is defined here as any programming where the subscriber can request authorization to watch a particular program. In many pay television systems, pay-per-view programming is used for sporting events (boxing, wrestling, etc.) which are not transmitted on a regular basis. A subscriber wishing to view the event must receive authorization in the form of a special descrambler mechanism, or in the form of a special code transmitted or input to the subscriber's decoder. Some pay-per-view television systems allow the subscriber to request a pay-per-view program (i.e. - movies) to watch. The pay television provider then transmits the requested program and authorizes that subscriber's decoder to receive the signal.
Impulse pay-per-view (IPPV) programming is defined here as any programming where the subscriber has a pre-authorized number of "credits" saved in his individual decoder. If a subscriber wishes to view a particular program, the subscriber merely actuates the decoder, the appropriate number of credits are subtracted from the subscriber's remaining credits, and the subscriber is immediately able to view the program. Pay television systems are disclosed, for example, in U.S. Patent No. 4,484,217 and 4,163,254 to Block, incorporated herein by reference.
In a pay-per-view embodiment of the present invention, the decoder may send a signal to the headend via the telephone controller/modem <b>875</b> with a request for authorization to decode a pay-per-view program. Preferably however, secure memories <b>720</b> and <b>707</b> store authorization information (i.e. -credits) for pay-per-view programming, and the security modules forward actual pay-per-view data via the telephone controller/modem <b>875</b> at a later time.
The telephone controller <b>940</b> could be a computer modem type device, or could work using touch-tone signals to communicate with the headend. Preferably, the telephone controller is a modem type device, communicating with the headend using a frequency shift keying or FSK protocol. Attention is drawn to U.S. Patent No. 4,926,444, issued May 15, 1990, describing FSK operation and incorporated herein by reference. The pay television provider can thus send appropriate authorization information (TEL) to the subscriber, encrypted with a subscriber's secret telephone number (STN). The secret telephone number is not a telephone number in the ordinary sense, but rather another type of secret serial number, which could be assigned to a given telephone controller/modem <b>875</b> or series of telephone controllers. Once received by processor <b>870</b> of decoder <b>906</b>, the authorization information may be routed and used to enable descrambling of a particular pay-per-view program or programs.
In another embodiment, which could be used in conjunction with the pay-per-view embodiment described above, the telephone controller/modem can be used to receive the KOM encrypted with the secret telephone number. The encrypted program signal is input to decoder <b>806</b> through modem <b>875</b> into processor <b>870</b>. Modem <b>875</b> must be capable of providing the functions of demultiplexer <b>833</b> so as to separate the addressed data packets 9e, input them into processor <b>870</b> which will then route them to the prescribed security module.
The telephone controller <b>875</b> can be programmed to call the headend at a predetermined time or at a predetermined time interval, or upon receiving a signal from the headend preferably when phone usage is at a minimum (i.e. - early morning hours). The telephone controller can call the headend via a toll free 1-800 number, a so-called "watts" line, or via a local call to a commercial data link such as TYMNET or TELENET. Preferably, the present invention would use the data return system described in application entitled DATA RETURN FOR A TELEVISION TRANSMISSION SYSTEM, having serial number , incorporated herein by reference. Once the call is connected and communications established, the decoder <b>806</b> uploads to the headend a record of pay-per-view usage encrypted with the secret telephone STN<sub>1</sub>. The headend may then download data similarly encrypted to the decoder <b>806</b> including new keys, secret serial numbers, or decryption algorithms. The encrypted key or other encrypted data may be sent to either internal security element <b>819</b>, or the replaceable security module <b>814</b>. The information transmitted from the headend may come via the telephone line through modem <b>875</b> into processor <b>870</b> or preferably through the satellite TV input into box <b>833</b> and on into processor <b>870</b>.
As discussed above, a new secret serial number or decryption algorithm, encrypted with the secret telephone number, may be sent from the headend to a decoder through telephone controller <b>875</b>. The encrypted secret serial number or decryption algorithm is then decrypted and stored in the selected security modules. This downloading of decryption algorithms and secret serial numbers via the telephone controller <b>875</b> is sometimes called an "E<sup>2</sup> patch", and allows the pay television provider to maintain or recover system security by loading new information into a decoder's EEPROM. An E<sup>2</sup> patch does not necessarily entail changing the entire decryption algorithm in the decoder <b>806</b>. The secret serial number or merely a portion of the decryption algorithm, such as a particular byte or data table need only be changed in order to sufficiently alter the decryption algorithm. The E<sup>2</sup> patch allows the pay television provider or upgrade the encryption system to fix "bugs" and recover system security.
After receiving a signal through the telephone controller <b>875</b>, the headend will send an acknowledgment signal to the decoder, indicating that information has been received. Similarly, after data has been downloaded from the headend to the decoder through the telephone controller/modem, the decoder will return an acknowledgment signal through modem <b>875</b> to the headend that data has been received. Hereto, the present invention would preferably use the data return system described in application entitled DATA RETURN FOR A TELEVISION TRANSMISSION SYSTEM, having serial number <b> </b> , incorporated herein by reference.
In addition to pay-per-view requests or records, telephone controller <b>875</b> can also be used to upload other signals from the decoder. For example, tamper protection information such as described in connection with Figure 4 can be sent indicating whether or not the decoder has been tampered with. Further, program viewing information can be uploaded to the pay television provider for television rating purposes (i.e., - Nielson ratings).
In general, any data that can be delivered via the B-MAC input of Figure 9 (or NTSC, PAL, SECAM, etc.) can also be downloaded through the telephone controller <b>875</b>. Such information includes, but is not limited to, blackout codes, tiering information, personal messages, number of available credits, group identification numbers, and other system data. Generally, the telephone controller <b>875</b> is used for infrequent communications, such as periodic security level changes and IPPV requests, due to the limited bandwidth of telephone lines and the increased cost of sending information via telephone versus the B-MAC input.
The telephone information (TEL) encrypted with the secret telephone number (STN) remains encrypted throughout the decoder <b>806</b> and may only be decrypted in the security modules. The decrypted telephone information does not pass out of the security modules, in order to prevent observation by a pirate. For decoder <b>806</b> to descramble a scrambled program, both the telephone information and the addressed data packet received through the B-MAC input must be present. By relying on both information sources, piracy is virtually impossible, as the potential pirate must break into the pay television provider's telephone system as well as decrypt a twice-encrypted key.
Figure 10 shows communications between a secure microprocessor, either internal or external, and the routing manager. Decoder <b>1006</b> comprises secure microprocessor <b>1050</b> with secure memory <b>1052</b>. Secure memory <b>1052</b> contains a set of secret serial numbers SSN<sub>0</sub>, a secret telephone number STN<sub>0</sub> unique to that decoder or a series of decoders loaded during manufacture and secured with an "E<sup>2</sup> bit" as discussed in connection with Figure 4 or other security, the encryption algorithm <b>E</b>, and other authorization information. Encrypted program signal E<sub>KOM0</sub>(SYS) <b>1053</b> and once-encrypted key-of-the-month E<sub>SSN0</sub>(KOM0) <b>1054</b> are input to decoder <b>1006</b> along with optional encrypted telephone data E<sub>STN0</sub>(TEL) <b>1055</b>.
Secure microprocessor <b>1050</b> decrypts encrypted telephone data E<sub>STN0</sub>(TEL) <b>1055</b> using the secret telephone number STN<sub>0</sub> stored in secure memory <b>1052</b>. The decrypted telephone data (TEL) is also stored in secure memory <b>1052</b> to prevent observation by pirates. The telephone data (TEL) may provide authorization information to decoder <b>1006</b> as to whether decoder <b>1006</b> is presently authorized to decrypt some or all of the received encrypted programs. In addition, other information may be transferred between the decoder and the headend as discussed in connection with Figure 9.
<u>Transmission of Addressed Data Packets</u>
Regarding the transmission of the encrypted signal with the addressed data packets 9e, previous systems incorporated a central control at the broadcasting uplink. As previously discussed and referring to Figure 11, prior systems used a central control <b>1181</b> to insert addressed data packets or other subscriber related information into the program signals to authorize those individual receivers who receive encrypted signals directly, not through a local distributor. Central control <b>1181</b> would transmit addressed data packets, via dedicated lines <b>1185</b>, to uplink broadcaster <b>1183</b> (e.g., Home Box Office, Cinemax, etc.) who would in turn multiplex the addressed data packets with their program signals, usually encrypted.
Under the new system and referring to Figure 12, a subscriber authorization computer <b>1282</b> and supervisory control computer <b>1280</b> are provided which input the same subscriber and system data via addressed and system data packets 9e and 9h to master uplink <b>1284</b>. The subscriber authorization computer <b>1282</b> and the supervisory control computer <b>1280</b> are both current products manufactured and sold by Scientific-Atlanta. Subscriber authorization computer <b>1282</b> contains all subscriber or decoder specific data in a large database. This subscriber specific data is then formatted into addressed data packets 9e for multiplexing with audio and video in master uplink <b>1284</b>. Similarly, subscriber authorization computer <b>1282</b> contains system wide information specific to particular programs in a large database and is formatted into system data packets 9h for transmission. Master uplink <b>1284</b> multiplexes the system and addressed data packets with audio and video to produce a typical B-MAC signal. This signal may be received by any subscriber who may use the data packets to decrypt the program. The addressed and system data packets 9e and 9h are then transmitted on a channel with the audio and video to satellite transponder <b>1205</b> via satellite uplink <b>1283</b>.
The signal is reflected from satellite transponder <b>1205</b> to satellite receiver and uplink <b>1283</b>. The addressed and system data packets are received by loop-back uplink <b>1286</b> where they are stripped away from the audio and video program signals inserted at master uplink <b>1284</b>. The packets are then multiplexed with different audio and video program signals and retransmitted to satellite transponder <b>1205</b>. The combined signals are then transmitted to the individual receiver <b>1289</b> via receiver <b>1283</b> where they are decrypted. With this system, addressed data packets may be received by several loop-back uplink broadcasters who may multiplex these packets with their scrambled program signals. They may also take selected portions from the system data packet 9h, for example, tier information, pay-per-view cost data, etc. In this way, all loop-back uplink broadcasters preferably send broadcasted B-MAC program signals with data packets to all subscribers. A subscriber may tune to any channel to receive both the scrambled program and data packets to decrypt the program. The system wide data which may be combined at loop-back uplink <b>1286</b> preferably includes the call-back data described in application having serial number entitled DATA RETURN FOR TELEVISION TRANSMISSION SYSTEM, incorporated herein by reference.
In this system, the need for dedicated lines <b>1185</b> to each broadcaster is obviated since the addressed data packets may be transmitted from master uplink <b>1284</b> to a variety of loop-back uplinks <b>1286</b> for the various program distributors (e.g., HBO, Cinemax, etc. ). The addressed and system data packets are in the form depicted in FIGS. 9 and 9A respectively, and preferably placed in a B-MAC format. Thus, loop-back uplink <b>1286</b> must decode the B-MAC signals to remove the loop-back formatting so as to extract each individual encrypted address data packet 9e to be multiplexed with their particular encrypted program signal.
Additionally, the present invention may operate in a full field KOM mode which would be able to rapidly address all decoders <b>706</b> in the network. In a B-MAC television signal, the addressed data packets are preferably transmitted during the vertical blanking interval of each frame as discussed in the background of the invention. Typically, KOMs and addressed data packets are sent during five lines of the vertical blanking interval for each field. This produces roughly 6,000 bytes per second of data. This amount of data may be transmitted over dedicated lines <b>1185</b> of the prior art. However, if a broadcaster wanted to rapidly address all subscribers they were limited by the transmission capabilities of the dedicated lines <b>1185</b> typically telephone lines by a telephone company. Under the present invention, roughly 500 kilobytes per second of data may be sent in the full field mode. 204 video lines plus the 5 vertical blanking interval lines are available in this mode, per field, for transmitting addressed data packets. Consequently, if a broadcaster wanted to rapidly authorize PPV or IPPV viewing for a recently upcoming program (e.g., a boxing match), the broadcaster may do so with the present system. A text screen may appear on all subscriber's television sets which may indicate what was occurring.
With this system, an individual subscriber with a satellite receiving dish may receiver program signals and data packets from all satellites, regardless of which channel he is tuned. If he is authorized to decrypt a particular program signal, the signal will contain his unique address data packet which is routed by processor <b>870</b> and decrypted by the particular security module.
<u>Digitally Upgrading the Decoder</u>
Referring to Figure 13, a method of converting the analog decoder box depicted in Figure 7 as <b>706</b> and Figure 8 as <b>806</b> from an analog configuration to also accept digital television signals is shown. The original analog decoder box is depicted as <b>1306</b> where incoming signals are down converted in down converter <b>1365</b>. Preferably incoming signals are in the L band region, having frequencies between 0.95 and 1.45 gigahertz, however, any other frequencies may be used. These frequencies are down converted to a fixed frequency more manageable by the decoder, preferably to a 612 megahertz intermediate frequency. The signals are then demodulated in FM demodulator <b>1366</b> and transmitted to decoder <b>1368</b> through switch <b>1367</b>. Preferably, the signals are in a B-MAC form and therefore decoder <b>1368</b> decodes and decrypts the B-MAC signal to its audio, NTSC video and channel 3 signals to be input into a standard television receiver.
To upgrade the system to accept digital signals, a "digital side-car" <b>1390</b> may be added by using a simple four lead connection. Tap <b>1397</b> allows the down converted signals to be input into the quadrature phase shift key demodulator <b>1391</b> of side-car <b>1390</b>. Preferably a 40 megabytes per second demodulator is used. The demodulated signals are then input into error correcting and demultiplexer <b>1392</b>. Block <b>1392</b> also provides correct timing for the signals in side-car <b>1390</b>.
Switch <b>1367</b> would be placed in a second position to receive digital signals whereby analog signals from digital to analog (D/A) converter <b>1396</b> are input into decoder card <b>1368</b>. Tuning microprocessor <b>1367</b>, coupled to decoder <b>1368</b> is used to control the physical transponder tuning function. Additionally, tuning microprocessor <b>1376</b> could also control volume, and display data on the front panel of decoder box <b>1390</b>. Importantly, tuning microprocessor <b>1376</b> provides tuning information to box <b>1392</b> via decoder <b>1368</b> to allow demultiplexer <b>1392</b> to select a particular digital subchannel from all incoming signals contained within a particular channel. Specifically, the display and communication's processor <b>870</b> receives unencrypted channel location bits which allow it to locate and select a particular transponder number (or channel number) and sub-transponder (or subchannel number). This channel map is more fully described in application entitled VIRTUAL CHANNELS FOR A MULTIPLEXED ANALOG COMPONENT (MAC) TELEVISION SYSTEM, having serial number , incorporated herein by reference. Additionally, the video decryption seed from the security modules is also transmitted to box <b>1392</b> to allow the selected subchannel to be decrypted.
Box <b>1392</b> corrects error in the signal using a forward error correction method (FEC) with checksum or parity bits. The signal is demultiplexed with the selected subchannel input to video decompressor <b>1393</b>. Typical digital video decompression would be discrete cosine transform (DCT) or other digital high compression technique known by those skilled in the art.
The decompressed/expanded digital video signals are then decrypted in decryptor <b>1399</b>. If video signals are to be transmitted digitally, digital encryption using a key number rather than the previously described scrambling of analog signals using a seed is preferred. Consequently, external and internal security modules <b>1314</b> and <b>1319</b> respectively, of decoder <b>1368</b> provide decryption keys to decryptor <b>1399</b>. Functioning of security modules <b>1314</b> and <b>1319</b> are identical to that previously described above.
The decrypted decompressed/expanded digital video signals are then processed for reformation to a B-MAC signal using techniques known by those skilled in the art. The expanded digital video signals are input into YUV store <b>1395</b> where the luminance signal Y is stored for each line or frame. Similarly, chrominance signals U and V are also stored on a frame basis. Box <b>1392</b> also inputs B-MAC data to store control <b>1394</b> which outputs the stored luminance and chrominance stores at correctly timed intervals through D/A converter <b>1396</b> to decoder <b>1368</b>. Signals coming out of converter <b>1396</b> are typical B-MAC signals having video, audio and other data. From decoder <b>1368</b>, the standard analog signals are then input into a television receiver.
This embodiment allows the digital side-car to decompress and expand the low bit rate signal into a full B-MAC video signal. The system data, system and addressed data packets 9e and 9h, teletext and digital audio are uncompressed and are passed out to decoder <b>1368</b> without decompression in side-car <b>1390</b>.
Switch <b>1376</b> could be microprocessor controlled so that a "compression-enable" bit in the system data or address data packet is read and causes switch <b>1367</b> to enable the decompression digital side-car <b>1390</b> to be enabled. Thus, the decoder <b>1306</b> with digital side-car <b>1390</b> may be able to receive and descramble both analog and digital video signals. Furthermore, tap <b>1397</b> is provided in Figure 13 as a loop. This loop could be a single lead, however, the loop provides for additional flexibility of expansion.
While the present invention has been disclosed with respect to a preferred embodiment and modifications thereto, further modifications will be apparent to those of ordinary skill in the art within the scope of the claims that follow. It is not intended that the invention be limited by the disclosure, but instead that its scope be determined entirely by the claims which follow.
12 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12
56 members in 16 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 677460 | United States of America | – | |
| 67746091 | United States of America | A | |
| 67746091 | United States of America | A | |
| 677460 | – | – | – |
| US19910677460 | – | – | – |
Members56
| Document | Office | Kind | |
|---|---|---|---|
| US5029207A | United States of America | A | |
| CA2049310A1 | Canada | A1 | |
| WO9111884A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU7340291A | Australia | A | |
| EP0466916A1 | European Patent Office (EPO) | A1 | |
| BR9104261A | Brazil | A | |
| KR920702158A | Republic of Korea | A | |
| EP0506435A2 | European Patent Office (EPO) | A2 | |
| AU1384092A | Australia | A | |
| JPH04506736A | Japan | A | |
| BR9201106A | Brazil | A | |
| EP0506435A3 | European Patent Office (EPO) | A3 | |
| CN1066950A | China | A | |
| AU635180B2 | Australia | B2 | |
| JPH05145923A | Japan | A | |
| US5237610A | United States of America | A | |
| MX172416B | Mexico | B | |
| AR246145A1 | Argentina | A1 | |
| AU650958B2 | Australia | B2 | |
| EP0679029A1 | European Patent Office (EPO) | A1 | |
| EP0683614A1 | European Patent Office (EPO) | A1 | |
| CN1030955C | China | C | |
| EP0506435B1This record | European Patent Office (EPO) | B1 | |
| AT144670T | Austria | T | |
| ATE144670T1 | Austria | T1 | |
| DE69214698D1 | Germany | D1 | |
| DE69214698T2 | Germany | T2 | |
| EP0809402A1 | European Patent Office (EPO) | A1 | |
| SG44801A1 | Singapore | A1 | |
| PH31140A | Philippines | A | |
| EP0683614B1 | European Patent Office (EPO) | B1 | |
| EP0466916B1 | European Patent Office (EPO) | B1 | |
| EP0679029B1 | European Patent Office (EPO) | B1 | |
| AT180373T | Austria | T | |
| AT180936T | Austria | T | |
| AT181196T | Austria | T | |
| ATE180373T1 | Austria | T1 | |
| ATE180936T1 | Austria | T1 | |
| ATE181196T1 | Austria | T1 | |
| KR100193542B1 | Republic of Korea | B1 | |
| DE69229235D1 | Germany | D1 | |
| DE69131285D1 | Germany | D1 | |
| DE69229408D1 | Germany | D1 | |
| DE69229235T2 | Germany | T2 | |
| DE69131285T2 | Germany | T2 | |
| DE69229408T2 | Germany | T2 | |
| EP0809402B1 | European Patent Office (EPO) | B1 | |
| AT192891T | Austria | T | |
| ATE192891T1 | Austria | T1 | |
| DE69132198D1 | Germany | D1 | |
| DE69132198T2 | Germany | T2 | |
| CA2049310C | Canada | C | |
| JP3304084B2 | Japan | B2 | |
| JP3476481B2 | Japan | B2 | |
| USRE39166E | United States of America | E | |
| MY131301A | Malaysia | A |
49 legal events, as 4 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notification of lapseLapsedST | ST | FR | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Nl: lapsed or anulled due to non-payment of the annual feeLapsedNLV4 | NLV4 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| European patent in force as of 2002-01-01IF02 | IF02 | GB | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Patent ceasedCeasedPL | PL | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| No opposition filedOpposition26N | 26N | EP | |
| No opposition filed within time limitOppositionORIGINAL CODE: 0009261PLBE | PLBE | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: NO OPPOSITION FILED WITHIN TIME LIMITSTAA | STAA | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| It: translation for a ep patent filedITF | ITF | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Fr: translation filedET | ET | EP | |
| Corresponds to:REF | REF | EP | |
| New agentNV | NV | CH | |
| Designated contracting statesAK | AK | EP | |
| Miscellaneous (deleted)DX | DX | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Corresponds to:REF | REF | EP | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOS IGRAGRAH | GRAH | EP | |
| Despatch of communication of intention to grantORIGINAL CODE: EPIDOS AGRAGRAG | GRAG | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for examination filed17P | 17P | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Designated contracting statesAK | AK | EP | |
| Search report despatchedORIGINAL CODE: 0009013PUAL | PUAL | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 0506435
- Publication, DOCDB
- 0506435
- Publication, EPODOC
- EP0506435
- Application
- 92302675
- Application, DOCDB
- 92302675
- Application, EPODOC
- EP19920302675
Titles3
- German
- Unabhängiges externes Sicherheitsmodul für einen digital-erweiterbaren Fernsehsignaldekoder
- English
- Independent external security module for a digitally upgradeable television signal decoder
- French
- Module de sécurité indépendant et externe pour un décodeur de signaux de télévision qui est extensible numériquement
Classification
- CPC, 8
- H04N21/4405
- H04N5/46
- H04N7/162
- H04N7/163
- H04N7/1675
- H04N7/20
- H04N21/4623
- H04N21/426
- IPC, 10
- H04K1 02
- H04L9 10
- H04N5 00
- H04N5 44
- H04N5 46
- H04N7 16
- H04N7 167
- H04N7 20
- H04N21 4405
- H04N21 4623
Designated states13
- Contracting states, 13
- Austria
- Belgium
- Switzerland
- Germany
- Denmark
- Spain
- France
- United Kingdom
- Italy
- Liechtenstein
- Luxembourg
- Netherlands (Kingdom of the)
- Sweden