Process for updating access rights to conditional access data
Abstract
La présente invention concerne un procédé de mise à jour de droits d'accès à des données à accès conditionnel. Dans ce procédé, on détermination tout d'abord un numéro de groupe dans lequel des droits d'accès doivent être mis à jour, puis on détermine tous les modules de sécurité liés à ce numéro de groupe. Ensuite, selon le mode de réalisation choisi, on détermine soit une clé de chiffrement pour chacun des modules dont les droits doivent être mis à jour, soit une clé d'abonnement (KAB) commune à tous les modules de sécurité d'un groupe déterminé dont les droits sont à mettre à jour. Les droits sont ensuite chiffrés avec la clé correspondante. On envoie alors les messages d'autorisation (EMM) contenant lesdits droits d'accès chiffrés et un identifiant des modules de sécurité auxquels ils sont destinés. Ces droits sont ensuite reçus et déchiffrés dans les modules de sécurité correspondants auxdits identifiants.

Term
Term ended
Projected expiry passed 16 December 2023, 2.8 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
3 claims: 2 independent, 1 dependent
- 1The process of updating access rights to conditional access data, especially in a pay television system comprising a management center access rights, the management center transmitting these rights to decoders associated with security modules, characterized in that it comprises the steps of:determining a group number in which access rights are to be update;determination of all security modules associated with this group number;determination of encryption keys of said security modules;Encryption of access rights with said encryption key;sending authorization messages (EMM) containing said encrypted access rights and an identifier of the security modules which they are intended;reception and decryption of access rights in the security modules corresponding to said identifiers.
- 3The process of updating access rights to conditional access data, especially in a pay television system comprising a management center access rights, the management center transmitting these rights to decoders associated with security modules, characterized in that it comprises the steps of:determining a group number in which access rights are to be update;determination of all security modules associated with this group number;determining a subscription key (K AB ) Common to all modules security-related audit group number;encryption access key with said subscription rights;sending an authorization message EMM containing said encrypted and rights identifying security modules which they are intended;reception and decryption of access rights in the security modules corresponding to said identifier.
Independent claims2
20 paragraphs, as filed
0001The present invention relates to a permissions update process at conditional access data, especially in a pay-TV system, when a subscriber has several decoders.
0002Currently, to access an encrypted content corresponding to events broadcast by pay-TV operators, such as movies, sports matches or other, must acquire a subscription, a decoder and a security module. Some customers wish to have more decoders and several security modules for multiple users to access events broadcast from multiple TVs arranged in rooms different from their home.
0003In this case, when access to encrypted content to be loaded into a security module of a subscriber, a management center sends a message a release which contains an identification number corresponding to one or more Security modules determined. This message also contains the right to access load.
0004The authorization messages can be formatted in three different ways. In a first manner, the authorization messages include a number unique identification allowing a single security module to receive and read the message content. In a second way, the message authorization contains an identifier taken in a specific range of identifiers, this range corresponding to a set of security modules. Such an assembly can for example contain 256 security modules. The message can be received and decrypted by all modules of this set. According to a third way, the authorization messages are sent globally to all modules security of a particular operator.
0005A problem arises for managing rights of subscribers with multiple decoders. Indeed, currently, each decoder is considered independent. When a subscriber has several decoders acquires a right, the management center management needs to send a message to each of these decoders. Thus, it is possible that the rights are not loaded identically in each security modules associated with that subscriber decoders.
0006The present invention proposes to overcome the disadvantages of forming processes Update the access rights of the prior art by providing a process which ensures that the rights of a specific subscriber with multiple decoders are loaded in the same way in all of this subscriber decoders.
0007This object is achieved by an update process of access rights as defined in preamble, used in particular in a pay television system comprising a central management of access rights, management center transmitting these rights decoders associated with security modules, characterized in that it comprises the steps of determining a group number in which access rights must be updated; determination of all security modules associated with this group number; determination of the encryption keys of said modules security; Encryption of access rights with said encryption key; sending of authorization messages (EMM) containing said encrypted access rights and identifying security modules which they are intended and reception and decryption of access rights in the corresponding security modules said identifiers.
0008The object of the invention is also achieved by a free update method access to conditional access data, in particular in a system of Pay TV with a management center access rights, the center of Management transmitting these rights to decoders associated security modules, characterized in that it comprises the steps of determining a group number in which access rights are to be updated; determination of all security modules related to that group number; determining a key subscription (K<sub>AB</sub>) Common to all the said related security modules number group; encryption access key with said subscription rights; sending a EMM authorization message containing said encrypted rights and identifying security modules which they are intended and receiving and decrypting access rights in the security modules corresponding to said identifier.
0009The present invention ensures uniform rights for each decoder of a subscriber, so that the rights which that subscriber has from a its top boxes will also be available from its other decoders. The subscriber management is also simpler as seen from the center of management, because the subscribers decoders are managed holistically and not more individually.
0010In some embodiments, the invention also reduces to sensitive way, the number of authorization messages to be transmitted to the subscribers, freeing bandwidth for other applications.
0011The present invention and its advantages will be better understood thanks to the description Detail which will follow and which refers to the accompanying drawings given as of non-limiting example, in which:<ul><li>Figure 1 illustrates schematically a first embodiment of the method according to the present invention; and</li><li>2 illustrates a second embodiment of the inventive method.</li></ul>
0012As is well known, controlling access to data, for example in the field of pay-TV, takes place from a management center CG that sends messages, including authorization messages EMM, to decoders placed with subscribers. Each decoder cooperates with a module Security in charge of the rights of control operations. Security modules contain in particular an encryption key K<sub>UA</sub> which is also stored in the center so management to allow secure data exchange between the management center and the security module of a decoder.
0013It should be noted that in general the method according to the invention is intended for persons who have subscribed for example the monthly type or duration indefinite. This method can however also be applied to people with multiple decoders, but not necessarily subscribe in an operator. These individuals can acquire rights as impulsive purchases or through prepayment. In this case, the decoders of those people must be listed if one wishes to avoid that the benefits vest from one of the decoders and are available from other decoders who do not belong to the same person. In the text below, we speak Subscriber for all people with access to conditional access data, as rights are acquired by a valid subscription for a while or certain amount of impulse buying or prepayment or any other form vesting. Decoders belonging to a subscriber are part of a group and we equally talk group number or number subscription.
0014Referring to the figures, the method according to the invention is carried out from a CG management center that contains, conventionally, a list of numbers AU unique identification of each security module associated with the decoder belonging to subscribers of which this center manages the rights. The management center also contains the encryption key K<sub>UA</sub> associated with each issue identification.
0015In the process according to the invention each subscriber has a number single subscription AB. The management of these subscription numbers and other administrative aspects, is processed in a processing system SMS subscribers, which communicates with the control center. This management center CG comprises a portion containing a database, the subscriber number AB each subscriber whose management center manages the rights, and secondly, the numbers Unique identification UA subscriber security modules. This basic data determines to a subscriber number determined AB, what UA identification numbers of security modules it has.
0016In a first embodiment, shown in Figure 1, when a message EMM authorization must be sent to a subscriber, it is first determined What are the unique numbers of DU identification number associated with the subscriber AB which the message must be transmitted. There are so many unique numbers that the subscriber has decoders. When the UA identification numbers are known, step following the method of the invention is to generate as many messages EMM authorization that there is security modules, and thus decoders, associated with this subscription. As is well known, the authorization messages contain including identifying a clear, allowing decoders to determine whether messages they receive are for security modules to which they are related. The authorization messages also contain rights that are encrypted so that it can only be used by the decoder to which they are intended. In the exemplary embodiment illustrated in Figure 1, a subscriber has three decoders and thus three security modules. The management center generates so three authorization messages, EMM1, EMM2, EMM3. Each of these messages contains an identifier UA1, UA2, UA3 allowing decoders to determine whether these messages are intended for them. They also contain the rights, encrypted by the encryption key K<sub>UA1</sub>, K<sub>UA2</sub>, K<sub>UA3</sub> contained in the management center and in the security module having the identifier UA1, UA2, UA3 correspondent.
0017When the authorization messages are generated for a subscription number AB determined belonging to a subscriber having several decoders, content Light must match identical rights to each decoder. Like the rights are encrypted with a different key for each decoder, the encrypted content is different. Decryption of rights takes place conventionally, in using the key K<sub>UA</sub> stored in the security module associated with the decoder which received the message.
0018In a second embodiment of the invention schematically illustrated in 2, the management center generates a single EMM authorization message for all decoders associated with a particular subscription number. For this, the central contains as previous management, a list of subscription numbers AB, combined with unique identification AU security modules numbers belonging to each subscriber. The management center further contains, for each Unique identification number UA, two encryption keys. The first key K<sub>UA</sub> East the same as that used in the previous embodiment and corresponds to the unique key of a security module. The second key K<sub>AB</sub> is a subscription key common to all security modules belonging to the same subscriber. She is unique for that subscriber so that two subscribers do not have the same key K<sub>AB</sub>. The subscription key can be loaded into a new security module acquired by a subscriber with an existing decoder and a security module. this loading can be done for example by means of a voice server, which the subscriber says its subscription number and the unique identification number of the AU security module he has acquired. A key can be transmitted in a message secure, this key may be identical to a key present in the module Security acquired earlier, or a new key can be sent to all subscriber's security modules. The subscription key can be loaded at the same time we support the rights of any one incident. For this, it is possible to send a single authorization message EMM containing the key K subscription<sub>AB</sub> and rights. This is possible as long as the bandwidth available is sufficient. It is also possible to send the subscription key K<sub>AB</sub> in an independent rights EMM authorization message. This allows minimize the required bandwidth. The subscription key K<sub>AB</sub> is then stored for later use in every subscriber's security modules.
0019The authorization message EMM generated by the management center to a subscriber determined contains a common identifier to all decoders of subscribers, this identifier being for example the subscription number or an identifier in derivative. It also contains rights that are encrypted using the key K<sub>AB</sub>common to all the subscriber's security modules. In this manner, one message can be sent and used by a whole group of decoders owned the same subscriber. This message is then received by the decoders that filter Authorization messages EMM according to the identifier of the safety modules they are associated. When messages are received by the respective decoders and they are filtered by the latter, they are then treated conventionally by each of decoders and associated security modules to extract rights.
0020The method of the invention is particularly advantageous because it simplifies the message management for customers with multiple decoders.
2 sheets
Sheet 1 Sheet 2
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US5748732A | Cites | United States of America | XA | Search report | 1,2 |
| US6466671B1 | Cites | United States of America | XA | Search report | 3 |
4 members in 3 offices; this record represents the family
Members4
| Document | Office | Kind | |
|---|---|---|---|
| US2005129234A1 | United States of America | A1 | |
| EP1545130A1This record | European Patent Office (EPO) | A1 | |
| WO2005069622A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1702467A1 | European Patent Office (EPO) | A1 |
7 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Application deemed to be withdrawnWithdrawn18D | 18D | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWNSTAA | STAA | EP | |
| Designated country de not longer valid8566 | 8566 | DE | |
| Designation fees paidAKX | AKX | EP | |
| Designated contracting statesAK | AK | EP | |
| Request for extension of the european patentAX | AX | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1545130
- Application
- 31047103
Titles3
- German
- Verfahren zum Aktualisieren von Zugriffsrechten auf Daten mit bedingtem Zugriff
- English
- Process for updating access rights to conditional access data
- French
- Procédé de mise à jour de droits d'accès à des données à accès conditionel
Classification
- CPC, 8
- H04N21/4182
- H04N7/163
- H04N7/1675
- H04N21/25808
- H04N21/25866
- H04N21/26606
- H04N21/4181
- H04N21/4623
- IPC, 2
- H04N7 16
- H04N7 167
Designated states31
- Contracting states, 27
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Italy
- Liechtenstein
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Portugal
- Romania
- Sweden
and 3 moreShow fewer
- Slovenia
- Slovakia
- Türkiye
- Extension states, 4
- Albania
- Lithuania
- Latvia
- North Macedonia