EP1290885A2

Secure digital content delivery system and method over a broadcast network

Abstract

This record has no abstract on file.

Term

Term ended

Projected expiry passed 22 May 2021, 5.3 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

85 claims: 36 independent, 49 dependent

  1. 1
    Claims of equivalent WO 0191465 A2 WHAT IS CLAIMED IS:1. A method for creating a secure transmission mechanism for a plurality of end user devices in a packet-based network, comprising: providing a plurality of packets;securing said plurality of packets according to security information to form secured packets;transmitting said security information to more than one end user device simultaneously through the packet-based network;and multi-casting said secured packets to the plurality of end user devices.
  2. 6
    The method of any of claims 1-5, wherein said security information includes control word information for key generation at each end user device.
  3. 11
    1 1. The method of claims 8-10, wherein the packet-based network is an IP network and said ECM is transmitted through said D? network according to at least one of a multicast IP address and an IP port, such that said end user device is notified of said at least one of said multicast EP address and said IP port through an IP notification protocol.
  4. 12
    The method of any of claims 8-11, wherein said end user device filters at least one of said ECM and said EMM according to at least one characteristic selected from the group consisting of a characteristic of said end user device and a characteristic of information stored by said end user device.
  5. 16
    The method of any of claims 8-15, wherein said EMM information includes a service identifier, and wherein said service identifier is related to a type of content of said secured packets.
  6. 19
    The method of any of claims 8- 18, wherein said EMM information includes an identifier for determining access to said secured packets according to at least one characteristic selected from the group consisting of a characteristic of an end user device and a characteristic of information stored on said end user device.
  7. 23
    The method of any of claims 8-22, wherein said ECM enables differential access to said secured packets by said end user device according to a plurality of identifiers transmitted in said EMM.
  8. 24
    The method of any of claims 8-23, wherein said end user device stores at least a content of at least one of said ECM and said EMM.
  9. 29
    The method of any of claims 7-28, wherein at least a portion of said secured packets are accessible with said ECM only, without said EMM, as a preview of said secured packets.
  10. 30
    The method of any of claims 8-29, wherein said security information is transmitted according to a standard J-P protocol.
  11. 38
    38 The method of any of claims 31-37, wherein announcement packets are encrypted.
  12. 39
    The method of any of claims 19-38, wherein said end user device is blocked from further access to said secured packets through revocation with at least one of an EMM and an ECM
  13. 42
    42 The method of any of claims 39-41, wherein said revocation causes a new service identifier to be required for accessing a content of an ECM corresponding to said secured packets.
  14. 43
    The method of any of claims 8-42, wherein said end user devices receive at least said secured packets from at least one peer end user device.
  15. 47
    47 The method of claims 44-46, wherein said EMM generated by said at least one peer end user device is mapped to a new ECM for accessing said secure packets by a central authorization entity
  16. 48
    48 The method of any of claims 44-47, wherein said packets are transmitted as part of a multi-cast session, an announcement for said session is transmitted according to a standard announcement protocol, and said announcement includes at least an SPI (security parameters index) for relating each ECM to a service identifier contained in an EMM, such that said at least one peer end user device generates at least one of said announcement and said SPI.
  17. 49
    49 The method of any of claims 37-48, wherein said central authorization entity controls at least one of said ECM, said EMM, said announcement and said SPI.
  18. 50
    50 The method of any of claims 37-49, wherein at least one of said EMM and said ECM is generated by said central authorization entity.
  19. 51
    51 The method of any of claims 37-50, wherein said end user devices are located in a cluster, and wherein each cluster is coordinated by said central authorization entity.
  20. 53
    53 The method of any of claims 7-52, wherein a pay-per-view ECM contains purchasing information for purchasing access to said secured packets and wherein EMM information is not required to access said pay-per-view ECM.
  21. 54
    54 The method of any of claims 7-52, wherein an EMM contains a credit for purchasing access to said secured packets for pay-per-view content.
  22. 55
    55 A secure transmission mechanism produced by the method of any of claims 1-54.
  23. 56
    A method for producing a conditional access (CA) system for use in a packet-switched environment (packet CA system) from a CA system for use in a broadcast environment (broadcast CA system), the method comprising:providing a broadcast CA system comprising at least one CA security characteristic;providing a packet-switched data transmission system including a security subsystem having a plurality of packet-switched security characteristics;and creating a mapping from the at least one CA security element to at least one of the plurality of packet-switched security elements, thereby producing a packet CA system.
  24. 59
    The method according to any of claims 56-58 and wherein the broadcast CA system comprises an EMM / ECM based CA system.
  25. 60
    60 A conditional access (CA) system for use in a packet-switched environment (packet CA system) produced by the method of any of claims 56-59.
  26. 61
    61 A packet-switched conditional access (CA) system for use with an end-user playback device, the CA system comprising:a protected data receiver for receiving protected data protected with at least one key;an ECM packet receiver for receiving at least one ECM packet from a packet-switching network;and an ECM-based key generator for generating said at least one key from said at least one ECM packet.
  27. 64
    The system according to any of claims 61-63 and wherein the ECM packet receiver comprises an IPSEC receiver for receiving the at least one ECM packet from the packet- switching network using an IPSEC protocol.
  28. 65
    A method for providing an entitlement control message (ECM) based conditional access (CA) system based on a packet-switching network comprising:receiving a plurality of ECMs via the packet-switching network;storing the plurality of received ECMs;and choosing, from among the plurality of stored ECMs, an ECM for providing access to CA-protected data.
  29. 69
    The method according to any of claims 65-68 and wherein the packet-switching network comprises an IP-based network.
  30. 72
    A method for creating a secure transmission mechanism for a plurality of end user devices in a packet-based network, comprising:encrypting a plurality of packets with a key to form encrypted packets, said key having associated key information for determining said key;multi-casting said associated key information to the plurality of end user devices through the packet-based network, thereby obviating the need to send said associated key information to each end user device individually;and multi-casting said encrypted packets to the plurality of end user devices to form the secure transmission mechanism.
  31. 76
    A method for creating a secure transmission mechanism for a plurality of end user devices in a packet-based network, comprising:multi-casting a plurality of secured packets and security information to the plurality of end user devices, thereby obviating the need for a one-to-one transmission of said security information to each end user device individually and thereby forming the secure transmission mechanism.
  32. 78
    A system for multi-casting secure packets to a plurality of end user devices in a packet-based network, the secure packets being secured according to security information, comprising:(a) a broadcast headend connected to the plurality of end user devices at least through the packet-based network, said broadcast headend transmitting the security information to more than one ofthe plurality of end user devices, thereby obviating the need to send the security information to each end user device individually, and said broadcast headend transmitting the secure packets to the plurality of end user devices, wherein at least one ofthe security information and the secure packets is transmitted through the packet-based network.
  33. 79
    In a system for multi-casting secure packets to a plurahty of end user devices in a packet-based network, the system comprising a broadcast headend connected to the plurality of end user devices at least through the packet-based network, providing a method for securing the packets, the method comprising:securing the secure packets according to security information;transmitting the security information by the broadcast headend to more than one end user device simultaneously according to a multi-casting protocol;and transmitting the secure packets by the broadcast headend to the plurality of end user devices;wherein at least one of the security information and the secure packets is transmitted through the packet-based network.
  34. 81
    A method for creating a secure transmission mechanism for a plurality of end user devices in an IP network, comprising:providing a plurality of data units for transport through the IP network;securing said plurality of data units according to security information to form secured data units;transmitting said security information to more than one end user device simultaneously through the IP network;and multi-casting said secured data units to the plurality of end user devices.
  35. 82
    A method for creating a secure transmission mechanism for a plurality of end user devices in a network having a characteristic of being at least one of packet-based and IP, comprising:providing a plurality of data units;securing said plurality of data units according to a control word to form secured data units, said control word being generated from security information;transmitting said security information to more than one end user device simultaneously through the network;multi-casting said data units to the plurality of end user devices;and generating said control word at each end user device with said security information.
  36. 83
    A method for creating a secure transmission mechanism for a plurality of end user devices in an IP network, comprising:providing a plurality of data units for transport through the EP network;securing said plurality of data units according to security information to form secured data units;transmitting said security information to more than one end user device simultaneously through the EP network;transmitting an announcement according to SDP (session description protocol) of EPSEC to said end user devices for indicating an association between said security information and said secured data units;and multi-casting said secured data units to the plurality of end user devices.
Independent claims36