EP0872077B1

Method and apparatus for providing conditional access in connection-oriented, interactive networks with a multiplicity of service providers

Abstract

This record has no abstract on file.

EP0872077B1, drawing sheet 1
Sheet 1 of 17

Term

Term ended

Expired 22 August 2016, 10.1 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

5 claims: 2 independent, 3 dependent

  1. 1
    An apparatus. (20,30) for use in an interactive information services system for providing at least one of video, audio, and data, program, requested by a customer (130) from a service provider, SP, and for transmitting the requested program in program bearing packets to a set top unit, STU, associated with the customer, the apparatus being positioned between the SP and the STU for ensuring that only the customer has access to said program, said apparatus comprising:means (20) for receiving program bearing packets in a first network protocol from a first data link (40) and removing said packets from said first network protocol means (20) for applying conditional access to said program bearing packets;and means (20) for re-encapsulating said program bearing packets in a second network protocol and outputting said program bearing packets over a second data link (50), characterized in that said means for applying conditional access comprises: means (30) for selecting program bearing packets comprising a program requested by the customer;means (20,30) for encrypting said selected program bearing packets according to a first encryption algorithm using a first key;means (20,30) for encrypting said first key according to a second encryption algorithm using a second key;means (20,30) for hashing a concatenation of said first key and said second key according to a hushing function to produce an authentication code from which the STU can determine the authenticity of said firs key;means (20,30) for providing the encrypted said first key and the hash of said first key concatenated with said second key to the customer;means (30) for encrypting said second key according to a third encryption algorithm using a third key corresponding to a private key stored within the STU associated with the customer, said third encryption algorithm comprising a public-key encryption algorithm and said third key comprising a public-key corresponding to said private key;means (30) for providing a digital signature based on said second key, the STU using the digital signature to verify the source of said second key;and means (300) for providing the encrypted said second key and the digital signature to the customer.
  2. 4
    A method for providing conditional access to a service provider, SP, connected to a network in a digital video delivery system in which a plurality of programs are stored at the service provider in a transport packet format and delivered in a first protocol format to the network for delivery to a subscriber, and applying conditional access to the transport packets, said method comprising the steps of:selecting program bearing packets comprising a program requested by the customer;encrypting said selected program bearing packets according to a first encryption algorithm using a first key;encrypting said first key according to a second encryption algorithm using a second key;and providing the encrypted said first key to the customer, characterized in that it further comprises the steps of: encrypting said second key according to a public-key encryption algorithm using a public key corresponding to a private key stored within a set top unit, STU, associated with the customer;providing the encrypted said second key to the customer;hashing a concatenation of said first key and said second key according to a hashing function to produce an authentication code;and providing the authentication code to the customer, whereby the STU can determine the authenticity of said first key with said authentication code.