Process for updating access rights to conditional access data
Abstract
This record has no abstract on file.
Term
Term ended
Projected expiry passed 15 December 2024, 1.8 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
3 claims: 2 independent, 1 dependent
- 1Translation of claims of equivalent WO 2005069622 A1 - o - CLAIMS 1. A method for updating rights of access to conditional access data, in particular in a pay-TV system comprising an access rights management center, this management center transmitting these rights to decoders associated with security modules, characterized in that it comprises the steps of:• determination of a group number in which access rights must be updated;• determination of all security modules related to this group number;Determining the encryption keys of said security modules;Encrypting the access rights with said encryption keys;• sending authorization messages (EMM) containing said encrypted access rights and an identifier of the security modules for which they are intended;Reception and decryption of the access rights in the security modules corresponding to said identifiers.
- 3Method for updating access rights to conditional access data, in particular in a pay television system comprising an access rights management center, this management center transmitting these rights to decoders associated with modules security system, characterized in that it comprises the steps of:• determination of a group number in which access rights must be updated;• determination of all security modules related to this group number;• determination of a subscription key (K AB ) common to all security modules related to said group number;Encrypting the access rights with said subscription key;Sending an EMM authorization message containing said encrypted rights and an identifier of the security modules for which they are intended;receiving and decrypting the access rights in the security modules corresponding to said identifier.
Independent claims2
22 paragraphs in 1 section, as filed
Translation of description of equivalent WO 2005069622 A1
PROCESS UPDATE ACCESS RIGHTS TO ACCESS DATA CONDITIONAL
p0002The present invention concerns a process of updating access rights to conditional access data, especially in a pay television system, when a subscriber has several decoders.
p0003Currently, to access an encrypted content corresponding to events broadcast by pay-TV operators, such as movies, sports games or other, must acquire a subscription, a decoder and a security module. Some customers wish to have more decoders and several security modules for multiple users to access the events broadcast from multiple TVs placed in different rooms of their home.
p0004In this case, when a right of access to an encrypted content is to be loaded in a security of a subscriber module, a management center sends an authorization message which contains an identification number corresponding to one or more security modules determined. This message also contains the right of access to load.
p0005The authorization messages can be formatted in three different ways. In a first manner, the authorization messages include a unique identification number enabling a single security module receive and decrypt the message. In a second way, the authorization message contains an identifier taken in a specific range of identifiers, this range corresponding to a set of security modules. Such a unit can for example contain 256 security modules. The message can be received and decoded by all modules of this set. In a third way, the authorization messages are sent globally to all security modules of a specific operator. This embodiment is particularly described in US Patent No. 6,466,671. A problem arises for managing rights of subscribers with multiple decoders. Indeed, currently, each decoder is considered independent. When a subscriber has several decoders acquiring a right management center management needs to send a message to each of these decoders. Thus, it is possible that the rights are not loaded identically in each of the security modules associated with that subscriber decoders.
p0006The US patent 5,748,732 describes a days setting process rights of a subscriber set top boxes with multiple decoders. In this method, one of the subscriber's decoders is considered as master and the others as slaves. Only the decoder master is direct communication with the management center. The fee for a slave decoder are always transmitted via the corresponding master decoder.
p0007This method has a number of drawbacks. Indeed, as the slave decoders are not in direct communication with the management center, it is necessary to transfer the information between master and slaves via a removable security module. On the one hand, this is inconvenient and secondly, there are more and more applications in which there is no removable security module. Another disadvantage is that the process does not work if the master decoder is triggered or if it is down.
p0008The present invention proposes to overcome the disadvantages of the update process of the access rights of the prior art by providing a process which ensures that the rights of a specific subscriber with multiple decoders are loaded identically in all of this subscriber decoders.
p0009This object is achieved by a free update process for access as defined in the preamble, used especially in a pay television system comprising a management center to access, this management center transmitting these rights decoders associated security modules, characterized in that it comprises the steps of determining a group number in which access rights are to be updated; determination of all security modules associated with this group number; determination of the encryption keys of said security modules; Encryption of access rights with said encryption key; sending of authorization messages (EMM) containing said encrypted access rights and an identifier of the security modules which they are intended and receiving and decrypting the access rights in the corresponding security modules said identifiers.
p0010The object of the invention is also achieved by a free update process for access to conditional access data, especially in a pay-TV system comprising a management center access rights, the center of management transmitting these rights to decoders associated security modules, characterized in that it comprises the steps of determining a group number in which access rights are to be updated; determination of all security modules associated with this group number; determining a subscription key (K<sub>AT</sub>B) common to all security modules related audit group number; encryption access key with said subscription rights; Sending an authorization message EMM containing said encrypted rights and an identifier of the security modules which they are intended and receiving and decrypting the access rights in the security modules corresponding to said identifier.
p0011The present invention ensures uniform rights for each subscriber decoder, so that the rights available to the subscriber from one of its top boxes will also be available from its other decoders. Subscriber management is also simpler from the viewpoint of the management center, because the subscribers decoders are managed holistically rather than individually.
p0012In some embodiments, the invention also reduces significantly the number of authorization messages to be transmitted to subscribers, freeing bandwidth for other applications.
p0013The present invention and its advantages will be better understood from the detailed description which follows and which refers to the accompanying drawings given as non-limiting examples in which:
p0014- Figure 1 illustrates schematically a first embodiment of the method according to the present invention; and - Figure 2 illustrates a second embodiment of the inventive method.
p0015As is well known, controlling access to data, for example in the field of pay-TV, takes place from a management center CG that sends messages, including EMM authorization messages, decoders placed with subscribers. Each decoder cooperates with a security module supports the rights of control operations. Security modules contain in particular an encryption key KU<sub>AT</sub> which is also stored in the center so management to enable secure data exchange between the management center and the security module of a decoder.
p0016It should be noted that in general the process of the invention is intended for persons who have subscribed for example monthly or indeterminate types. This method can however also be applied to people with multiple decoders, but which are not necessarily subscribers from a service provider. These individuals may acquire rights in the form of impulse or through prepayment. In this case, the decoders of these persons should be listed if one wishes to avoid that rights are acquired from one of the decoders and are available from other decoders that do not belong to the same person. In the following text, the subscriber will be discussed to all persons having access to conditional access data, that rights are acquired by a valid subscription for a certain time or a certain amount of impulse buying or prepayment or any other form of vesting. The decoders belonging to a subscriber are part of a group and we equally talk group number or subscription number.
p0017Referring to the figures, the method according to the invention is implemented from a management center CG, comprising, conventionally, a list of unique numbers identifying each AU security module associated with the decoders belonging subscribers whose center that manages the rights. The management center also contains the encryption key KUA associated with each identification number. In the process according to the invention each subscriber has a unique subscription number AB. The management of these subscription numbers, and other administrative aspects, is processed in a processing system of SMS subscribers, which communicates with the control center. This management center CG has a database containing one hand, the subscriber number AB of each subscriber whose management center manages the rights, and secondly, the unique identification numbers AU modules security subscribers. This database is used to determine to a subscriber number determined AB, what UA identification numbers of security modules it has.
p0018In a first embodiment, shown in figure 1, when an authorization message EMM to be transmitted to a subscriber, it is first determined which are the unique identification numbers of UA-related subscriber number AB which the message is transmitted. There are as many unique numbers that the subscriber decoders. AU when these identification numbers are known, the next step of the process according to the invention to generate as many authorization messages EMM that there are security modules, and thus decoders, for this subscription. As is well known, including the authorization messages contain an identifier in the clear, allowing decoders determine whether the messages they receive are for security modules to which they are Lives. The authorization messages also contain rights that are encrypted so that it can only be used by the decoder which they are intended. In the exemplary embodiment illustrated in Figure 1, a subscriber has three decoders and thus three security modules. The management center therefore generates three authorization messages, EMM1, EMM2, EMM3. Each of these messages contains an identifier UA1, UA2, UA3 allowing decoders to determine whether these messages for them. They also contain the rights, encrypted by the encryption key KUAI, KUA2, KUA3 contained in the management center and the security module having the identifier UA1, UA2, UA3 correspondent.
p0019When the authorization messages are generated for a specific subscription number AB belonging to a subscriber having several decoders, content in plain must match identical rights to each decoder. As rights are encrypted with a different key for each decoder, the encrypted content is different. Decryption of rights takes place in a conventional way, using the stored KUA key in the security module associated with the decoder which received the message.
p0020In a second embodiment of the invention illustrated schematically in Figure 2, the management center generates a single EMM authorization message for all decoders associated with a particular subscription number. For this, the management center contains as precedent, a list of subscription numbers AB, combined with unique identification numbers of AU security modules belonging to each subscriber. The management center also contains, for each unique identification number UA, two encryption keys. The first key KU<sub>AT</sub> is the same as that used in the previous embodiment and corresponds to the unique key of a security module. The second key KA<sub>B</sub> is a common subscription key to all security modules belonging to the same subscriber. It is u nique for the subscriber so that two subscribers do not have the same key KAB- The subscription key can be loaded into a new security module acquired by a subscriber with an existing decoder and a module of security. This loading can be done eg via a voice server, which indicates the subscriber's subscription number and the unique identification number UA of the security module that has acquired. A key can be transmitted to it in a secure message, this key can be duplicates a key in the security modules acquired earlier, or a new key can be sent to all of the subscriber security modules. The subscription key can be loaded at the same time we support the rights of any one incident. For this, it is possible to send a single authorization message EMM containing the subscription key KA<sub>B</sub> and rights. This is possible as long as the available bandwidth is sufficient. It is also possible to send the subscription key KAB in an independent rights EMM authorization message. This minimizes the required bandwidth. The subscription key KAB is then stored for later use in every subscriber's security modules.
p0021The authorization message EMM generated by the management center for a specific subscriber contains a common identifier to all decoders of subscribers, this identifier being for example the subscription number or an identifier in derivative. It also contains rights that are encrypted using the key K<sub>AT</sub>B common to all of the subscriber security modules. In this way, a single message can be sent and used by a group of boxes belonging to the same subscriber. This message is then received by decoders that filter EMM authorization messages according to the identifier of the security modules which they are associated. When messages are received by the appropriate decoders and are filtered by them, they are then conventionally treated by each of the decoders and associated security modules to extract rights.
p0022The method of the invention is particularly advantageous because it simplifies the management of messages to subscribers with multiple decoders.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO02102074A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| WO03039153A2 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| WO03075570A1 | Cites | World Intellectual Property Organization (WIPO) | Examiner |
| See also references of WO 2005069622A1 | Non-patent | – | Examiner |
4 members in 3 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 03104710 | European Patent Office (EPO) | – | |
| 03104710 | European Patent Office (EPO) | A | |
| 2004053481 | European Patent Office (EPO) | W |
Members4
| Document | Office | Kind | |
|---|---|---|---|
| US2005129234A1 | United States of America | A1 | |
| EP1545130A1 | European Patent Office (EPO) | A1 | |
| WO2005069622A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP1702467A1This record | European Patent Office (EPO) | A1 |
8 legal events, as 2 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Application refused18R | 18R | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: THE APPLICATION HAS BEEN REFUSEDSTAA | STAA | EP | |
| Refusal decision now finalR003 | R003 | DE | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| First examination report despatched17Q | 17Q | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1702467
- Application
- 48048367
Titles3
- German
- PROZESS ZUM AKTUALISIEREN VON ZUGANGSRECHTEN ZU BEDINGTER-ZUGANG-DATEN
- English
- PROCESS FOR UPDATING ACCESS RIGHTS TO CONDITIONAL ACCESS DATA
- French
- PROCÉDURE DE MISE À JOUR DE DROITS D'ACCÈS À DES DONNÉES À ACCÈS CONDITIONNEL
Classification
- CPC, 8
- H04N21/4182
- H04N7/163
- H04N7/1675
- H04N21/25808
- H04N21/25866
- H04N21/26606
- H04N21/4181
- H04N21/4623
- IPC, 2
- H04N7 16
- H04N7 167
Designated states30
- Contracting states, 30
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Monaco
- Netherlands (Kingdom of the)
- Poland
and 6 moreShow fewer
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye