Method and device for controlling access to encrypted data
15 claims: 5 independent, 10 dependent
- 1Méthode de contrôle d'accès à des données chiffrées par des mots de contrôle (CW), ces mots de contrôle étant reçus par un module de sécurité dans des messages de contrôle (ECM) et retournés à une unité d'exploitation (STB) des données chiffrées, cette méthode comprenant les étapes suivantes :- réception d'un premier message de contrôle (ECM1) comprenant au moins un mot de contrôle (CW) et une marque temporelle (TS), - réception d'un second message de contrôle (ECM2) consécutif au premier message de contrôle (ECM1), ce second message comprenant au moins un mot de contrôle (CW) et une marque temporelle (TS), - détermination d'une durée correspondant à la différence entre les marques temporelles (TS) des deux messages de contrôle consécutifs (ECM1, ECM2), - si cette durée est inférieure à durée pré-définie (CP), incrémentation d'un compteur d'erreurs (CE), - si cette durée est égale ou supérieure à ladite durée pré-définie, décrémentation dudit compteur d'erreurs (CE), - renvoi du mot de contrôle (CW) à l'unité d'exploitation (STB) après un temps d'attente dépendant de la valeur du compteur d'erreurs (CE).
- 2Méthode de contrôle d'accès selon la revendication 1, caractérisée en ce que la valeur de ladite durée pré-définie est contenue dans au moins l'un des messages de contrôle (ECM1, ECM2).
- 3Méthode de contrôle d'accès selon la revendication 1, caractérisée en ce que la valeur de ladite durée pré-définie est contenue dans un message de gestion (EMM).
- 4Méthode de contrôle d'accès selon la revendication 3, caractérisée en ce que la valeur de ladite durée pré-définie est commune à une pluralité de services sur lesquels sont diffusées les données chiffrées.
- 5Méthode de contrôle d'accès selon la revendication 1 ou 2, caractérisée en ce que la valeur de ladite durée pré-définie est égale à une durée pendant laquelle les données sont chiffrées avec le même mot de contrôle (CW).
- 6Méthode de contrôle d'accès selon l'une quelconque des revendications 1 à 5, caractérisée en ce que ledit premier message de contrôle (ECM1) comprend une valeur temporelle (TS), en ce que ledit second message de contrôle (ECM2) comprend une valeur temporelle (TS), et en ce que la durée séparant les deux messages de contrôle consécutifs correspond à la différence entre les marques temporelles (TS) de ces deux messages de contrôle.
- 7Méthode de contrôle d'accès selon l'une quelconque des revendications 1 à 5, caractérisée en ce que le module de sécurité et/ou l'unité d'exploitation contiennent une horloge et en ce que la durée séparant les deux messages de contrôle consécutifs correspond à la différence entre l'instant de réception dudit premier message de contrôle (ECM1) et l'instant de réception dudit second message de contrôle (ECM2), ces instants étant déterminés par ladite horloge.
- 8Méthode de contrôle d'accès selon la revendication 1, caractérisée en ce que le temps d'attente est nul lorsque la valeur du compteur d'erreurs (CE) est inférieure à un seuil prédéfini.
- 9Méthode de contrôle d'accès selon la revendication 1, caractérisée en ce que l'incrémentation de la valeur du compteur d'erreurs (CE) est réalisée selon une règle prédéfinie.
- 10Méthode de contrôle d'accès selon la revendication 1, caractérisée en ce que la décrémentation de la valeur du compteur d'erreurs (CE) est réalisée selon une règle prédéfinie.
- 11Méthode de contrôle d'accès selon les revendications 9 et 10, caractérisée en ce que la règle prédéfinie pour l'incrémentation de la valeur du compteur d'erreurs (CE) et celle pour la décrémentation de ce compteur d'erreurs (CE) sont différentes l'une de l'autre.
- 12Méthode de contrôle d'accès selon la revendication 11, caractérisée en ce que l'incrémentation de la valeur du compteur d'erreurs (CE) est plus rapide que la décrémentation.
- 13Méthode de contrôle d'accès selon la revendication 1, caractérisée en ce que, lorsque ledit module de sécurité a été réinitialisé, cette méthode comprend en outre les étapes suivantes :- détermination d'une date correspondant à la dernière date reçue par l'unité multimédia, - détermination de la date de réception d'un nouveau message de contrôle (ECM), - calcul de la différence entre ces deux dates, - si cette différence est inférieure à un temps de latence prédéfini, incrémentation de la valeur du compteur d'erreurs (CE).
- 14Méthode de contrôle d'accès selon la revendication 13, caractérisée en ce que , si la différence entre les deux dates est supérieure à un temps d'inactivité prédéfini, le compteur d'erreurs (CE) est réinitialisé.
- 15Dispositif de contrôle d'accès à des données chiffrées par des mots de contrôle (CW), ces mots de contrôle étant reçus par un module de sécurité dans des messages de contrôle (ECM) et retournés à une unité d'exploitation (STB) des données chiffrées, ce dispositif comprenant:- des moyens de réception d'un premier message de contrôle (ECM1) comprenant au moins un mot de contrôle (CW), - des moyens de réception d'un second message de contrôle (ECM2) consécutif au premier message de contrôle (ECM1), ce second message comprenant au moins un mot de contrôle (CW), - des moyens pour déterminer une durée séparant les deux messages de contrôle consécutifs (ECM1, ECM2), - des moyens pour incrémenter un compteur d'erreurs (CE) si cette durée est inférieure à durée pré-définie (CP), - des moyens pour décrémenter ledit compteur d'erreurs (CE) si cette durée est égale ou supérieure à ladite durée pré-définie. - et des moyens pour renvoyer le mot de contrôle (CW) à l'unité d'exploitation (STB) après un temps d'attente dépendant de la valeur du compteur d'erreurs (CE).
Independent claims15
88 paragraphs in 5 sections, as filed
TECHNICAL AREA
p0001The present invention relates to a method and an access control device to data encrypted by control words, these control words being received by a security module in control messages and returned to a unit operating data encrypted.
p0002The present method as well as the device are particularly applicable in the case of pay-TV.
PRIOR ART
p0003As is well known, particularly in the field mentioned above pay TV, data is encrypted by a data provider using encryption keys called control words. This data is transmitted to multimedia units of users or subscribers. Parallel to this, the control words are transmitted to these multimedia units in the form of a flow of control messages.
p0004The multimedia units are generally formed an operating unit which, in the case of pay-TV, is a decoder receiving streams mentioned above, and a security module responsible for the cryptographic operations related to use of these flows.
p0005As is well known in the art, such a security module can essentially be produced according to four distinct forms. One of these is a microprocessor card, a smart card, or more generally an electronic module (taking the form of a key, a badge, ...). Such a module is generally removable and connectable to the decoder. The form with electrical contacts is the most used, but does not exclude a connection without contact for example of ISO 14443.
p0006A second known form is that of an integrated circuit package, generally placed definitive and irremovable way in the decoder box. An alternative is made of a circuit mounted on a base or connector such as a SIM module connector.
p0007In a third form, the security module is integrated into an integrated circuit package having also another function, for example in a descrambling module of the decoder or the microprocessor of the decoder.
p0008In a fourth embodiment, the security module is not realized in hardware, but its function is implemented only in software form. Since in all four cases, although the security level differs, the function is the same, we talk about a security module regardless of the way in which it functions or the form that this module may take.
p0009When a multimedia unit has received the stream containing the control words, it is first checked whether the user has rights to decrypt specific data. If this is the case, the control messages are decrypted in order to extract the control words. These control words are used in turn to decrypt the data.
p0010Also known, each control word generally allows a small part to decipher the data transmitted. Typically, a control word used to decrypt 10 seconds of a Pay-TV event. After this time, called crypto, the control word is changed for security reasons.
p0011One possible way to enjoy access to encrypted data without being authorized is to use a genuine multimedia unit with a real security module, but distributing the control words to a set of decoders. This can be done using a server or separating device known as the "splitter". Thus, the amounts related to the acquisition of access rights to encrypted data are paid by a single multimedia unit while the events are accessible from several multimedia units.
p0012The European patent application <patcit id="pcit0001" dnum="EP1575293A"><text>EP 1575293</text></patcit> describes a method to prevent the same security module is shared by multiple users. For the implementation of this method, the security module has a memory for storing sequences of control messages. The security module also has means for analyzing an abnormal sequence of control messages, these means acting by comparing the stored control messages. When an abnormal sequence is detected, an error counter is incremented. A time delay in processing the control words is introduced depending on the value of the error counter.
p0013In the method described in this patent application, an abnormal behavior is defined based on the analysis of the channels used. For example, if the channel identifier is alternatively A and B, the analysis means judges that it is an abnormal sequence corresponding to a share of the security module. The error counter is incremented. On the contrary, if the channel identifier is A for several cryptoperiods then passes to B for several crypto, this will not be considered abnormal behavior and the error counter will not be incremented.
p0014The invention described in the patent application <patcit id="pcit0002" dnum="US20040215691A"><text>US 2004/0215691</text></patcit> seeks to prevent this fraudulent use. To achieve this, whenever a control message is received by a multimedia unit, the unit or the security module associated with it determines which channel is linked this control message. The channel identifiers are memorized with a time information. Messages are compared so as to determine if they are related to different channels or the same channel. They are related to different channels, a counter is incremented by a certain value. If control messages are related to the same channel, the counter is decremented. If the counter reaches a predefined threshold value, which means that many channel changes have occurred, the decryption of the control words is stopped.
p0015Both methods disclosed in <patcit id="pcit0003" dnum="EP1575293A"><text>EP 1575293</text></patcit> and <patcit id="pcit0004" dnum="US20040215691A"><text>US 2004/0215691</text></patcit> imply that it is necessary to have available an identifier of the channel concerned for each control message. In some configurations, this is not the case. Using control messages as defined in particular in the Eurocrypt Standard No. EN 50094 of December 1992 it is possible to identify not every channel but a channel class. In this case, it is not possible, with the invention described above, block the use of several multimedia units that use a single security module and a separating device.
p0016The document "Countermeasures for Attacks on satellite TV receivers open cards using" XP-002333719 Francis et al. described in very general terms, different means to prevent fraudulent use of security modules. In a particular aspect, this document suggests to check that the time stamp of a message is in the future compared with the time stamp of a previously received message. This document does not however mention any concrete solution. In particular, there is no information to distinguish between an illegal use of a security module for multiple users and a legal change of channel by a single user.
DISCLOSURE OF INVENTION
p0017The present invention proposes to provide an alternative to that of the prior art, in which dispenses with the use of an identifier of the channel while preventing the use of a splitter allowing multiple decoders access an encrypted content from a single security module. In addition, according to this solution, an identifier of the channel concerned is not required, so that this solution also works in the case where the control messages do not contain such a channel identifier, but where, for example, channels are grouped by class.
p0018The object of the invention is achieved by a method of controlling access to data encrypted by control words, these control words being received by a security module in control messages and returned to a processing unit encrypted data, this method comprising the following steps:<ul><li>receiving a first control message comprising at least one control word and a time stamp,</li><li>receiving a second consecutive control message to the first control message, the second message comprising at least one control word and a time stamp,</li><li>determining a period corresponding to the difference between the time stamps of two consecutive control messages, </li><li>if this period is less than pre-set time, incrementing a counter of errors,</li><li>if this duration is equal to or greater than said predefined duration, decrementation of said error counter.</li></ul>
p0019The object of the invention is also achieved by an access control device to data encrypted by control words, these control words being received by a security module in control messages and returned to a unit operating figures, the apparatus comprising:<ul><li>means for receiving a first control message comprising at least one control word,</li><li>means for receiving a second consecutive control message to the first control message, said second message comprising at least one control word,</li><li>means for determining a duration separating the two consecutive control messages,</li><li>means for incrementing an error counter if this time is less than pre-set time,</li><li>and means for decrementing said error counter if this duration is equal to or greater than said predefined duration.</li><li>and means for returning the control word (CW) to the operating unit (STB) after a waiting time depending on the value of the error counter (CE).</li></ul>
p0020In general, the method and apparatus of the present invention determines, from time information related to control messages sent by a management center, if these control messages are sent and processed in a conventional or fraudulent use . The error counter allows to take action if abnormal operation is detected. These measures may be of various kinds, such as temporary interruption of service, slow return of control words or blocking of the security module, in which case the release can be done either automatically or on request from a telephone service. If conventional use, the user does not perceive any change due to the use of this method. By conventional use, includes both access to encrypted content on a given channel a channel change (zapping) at a rate and for a time "reasonable". By cons, in case of fraudulent use of a separator device supplying several decoders from only one security module, access the encrypted content rapidly becomes impossible. When use is again correct, access to data can be authorized again.
BRIEF DESCRIPTION OF DRAWINGS
p0021The present invention and its advantages will be better understood with reference to the accompanying figures and detailed description of a particular embodiment given by way of non-limiting example, in which:<ul><li>the <figref idrefs="f0001">figure 1</figref> illustrates an exemplary structure of a control message as used in the present invention;</li><li>the <figref idrefs="f0001">2</figref> illustrates a configuration in which two decoders are used with only one security module and a separating device,</li><li>the <figref idrefs="f0002">3</figref> schematically shows an embodiment of the decryption method according to the present invention;</li><li>the <figref idrefs="f0001">4</figref> illustrates receiving control messages ECM according to time; and</li><li>the <figref idrefs="f0001">5</figref> represents a value of an error counter as a function of time and the received control messages such as illustrated by the <figref idrefs="f0001">4</figref>.</li><li>the <figref idrefs="f0003">6</figref> illustrates a variant of the invention in which different cryptoperiods are used on different channels.</li></ul>
WAYS OF CARRYING OUT THE INVENTION
p0022The <figref idrefs="f0001">figure 1</figref> diagram of the content and structure of a control message ECM as used in the present invention. This control message ECM contains fields into which particular are a time stamp (Time stamp) TS representing a date and time, duration of the crypto-CP, CA Access conditions to an audio / video content and two words CW1 of control, CW2 of different parities. The control message may also include other fields not described in detail here. The data in the fields of the control message is generally encrypted by a transmission key TK. This message may also include one or headers that are not necessarily encrypted. In particular, such a message comprises a header H that allows the multimedia unit to identify it as a control message ECM, which should not be encrypted. Note that the crypto is not necessarily contained in such control message. Indeed, if the crypto different channels are identical and remain constant for some time, the crypto can be sent in a management message EMM.
p0023According to a first embodiment, the present invention operates in the following general manner. Conventionally, a control message ECM is sent to a multimedia unit comprising a set-top box and a security module SC. Upon receipt of this control message, the AC access conditions required to access a specific content, called hereinafter audio / video content, are extracted from this control message by the security module. Then the security module checks if it has the rights to return the control word. If it does not, it does not return the control word. If the decryption rights are present, the control word is transmitted to the decoder.
p0024The value of the crypto-period CP is also extracted from the control message or determined in another manner. This CP value is stored in a memory linked to the security module. Adequate control word is returned to the decoder, usually in encrypted form by a session key. The session key is generally derived from a pair of asymmetric keys of which one of the keys is stored in the security module and the other is stored in the decoder. The keys to this key pair is called pairing keys and are in principle unique and different for each multimedia unit. The encrypted content can then be decrypted by this control word and displayed on a user's screen. The matching mechanism is described in detail in the European patent published under N °<patcit id="pcit0005" dnum="EP1078524A"><text>EP 1078524</text></patcit>.
p0025When a subsequent control message is received by the multimedia unit, it is decrypted in order to extract among others, the time stamp TS.
p0026This time stamp is compared with the stored timestamp when processing the previous control message. The difference between these two time stamps is compared to the stored crypto also when processing the previous control message. If this difference is less than the value of the crypto, which means that the multimedia unit has received more than one message by crypto, a value of a counter is incremented. This counter, referred to as the error counter in the following description, is placed in principle in the security module. The increment of this counter is thus performed when the security module is called to return the control words according to a higher frequency than the crypto-period, this is by a user's channel change, or by the function of more than a multimedia unit on the same security module.
p0027The <figref idrefs="f0001">2</figref> represents a configuration against which the present invention seeks to fight. In this configuration, two operating devices or data decoders two STB1, STB2 are supplied with control words by a single security module and a separating device. In this configuration, when one of the decoders receives a control message ECM, it transmits it to the SP that returns the separator device to turn the security module SC. It decrypts it if it is authorized, then transmits the control word to one or other of STB1 decoders or STB2 through the separating device SP.
p0028On this <figref idrefs="f0001">2</figref>Only two decoders are represented. In practice, it is possible that a larger number of decoders are supplied with control words by a single security module and a separating device.
p0029It should be noted that the process controls only durations related to control messages ECM. If other message types, such as EMM management messages are sent between two control messages, these other types of messages are not taken into consideration and do not disrupt the operation of the process.
Using data from the error counter
p0030A particular embodiment is described below with reference to <figref idrefs="f0002">3</figref>. In this embodiment, the value of the error counter is used to introduce a time delay in returning the control words CW extracted from the control messages ECM. In the example of this<figref idrefs="f0002">3</figref>It assumes that the crypto is 10 seconds. Upon receipt of a first control message ECM 1, it is processed to extract the control words that it contains, denoted respectively CW1 (C1) and CW2 (C1). It should be noted that in the figure, the upper part corresponds to the channel C1 and the lower part corresponds to the channel C2. In order not to overload this figure, the control word CW1 (C1) corresponding to the channel C1 is simply noted CW1. Similarly, the control word CW1 (C2) corresponding to channel C2 is also noted CW1 in the figure. Because of their location in the figure, the distinction between these two control words is obvious. In the description, the channel identifier is indicated in parentheses.
p0031The treatment of the control message ECM 1 generally lasts a few tens of milliseconds. While one of the control words, for example the control word CW1 (C1) is used, the other control word CW2 (C1) contained in the same control message ECM 1 is stored. The control message corresponding to the same channel will generally contain the control word memorized during the processing of the previous message, and an additional control word that is intended for use in the next crypto. In this way, each control word is sent twice. This way of proceeding has the advantage that the control words other than those received immediately after a channel change are stored prior to use, so they are readily available when needed.
p0032The error counter CE introduces a delay in the return of the security module control words to the decoder. This means that instead of processing a control message ECM and returning the control words as soon as they have been extracted, they are sent to the decoder is delayed for a period which depends on the value stored in this counter.
p0033The <figref idrefs="f0002">3</figref> shows an example where a separator (splitter) device is illegally used between the security module and two STB1 and STB2 decoders. In the simplest case the cryptoperiods are identical and where users do not change channels with the configuration described above, two control messages are received for each crypto. Thus, each crypto, the value of the error counter will be incremented. This increment can be done according to predefined values, eg two units. For example, imagine that we introduce a time delay of processing control messages of 1 second per unit of error counter as soon as it exceeds a threshold of 10. When the counter has not yet reached that threshold or 10 is 10, no delay is introduced.
p0034If the initial value of the counter is zero (CE = 0), on receipt of a first control message ECM 1 the value of the crypto PC, for example 10 seconds, is stored. CW1 control words (C1) and CW2 (C1) are decrypted. The control word CW1 (C1) is used to decrypt an audio / video content and control word CW2 (C1) is stored for later use. The time stamp TS = T0 is extracted from the control message and stored. When the following control message ECM 2 is received by the multimedia unit, it extracts the time stamp T1. The second control message ECM 2 is processed to extract the control words, to use the first of them CW1 (C2) and memorize the other CW2 (C2). Then, the difference between T0 and T1 is calculated and for example 6 seconds is obtained.
p0035This value is compared to the stored crypto-CP is, in our example, 10 seconds. Since the difference of the time stamps T1-T0 is less than the crypto-CP, the mark of the error counter is incremented, in our example of 2 units. This mark is therefore 2.
p0036Upon receipt of the following control message ECM 3, corresponding to the first channel C1, the mark of the error counter is verified. This mark is 2 and thus less than the threshold value 10 defined above, no time delay is introduced. The security module processes the message by first extracting the time stamp TS = T2. As the cryptoperiod is 10 seconds, it follows that T2-T0 = T1-T0 10. As = 6 in this example, T2-T1 = 4 seconds. This value being lower than the crypto-period, the value of the error counter is incremented by two units and passes to 4. The control words CW2 (C1) and CW3 (C1) are extracted from the message. Meanwhile, the audio / video content is decrypted using the control word CW2 (C1) from the previous control message.
p0037Upon receipt of the following control message ECM4, the security module also processes the message and returns the control words without introducing a time delay. Meanwhile, the STB2 decoder uses the control word CW2 (C2) from the previous message to decrypt the audio / video content.
p0038The difference between the time stamp of this message and the previous is 6 seconds, so less than the crypto. The value of the error counter is incremented by two units and therefore is 6. The control words CW2 (C2) and CW3 (C2) are extracted from the message. When the audio / video content will have to use the control word CW3 (C2) to be decrypted, this control word will be available since it was deciphered in the control message received previously ECM4.
p0039The multimedia unit will then receive a fifth ECM5 control message containing control words CW3 (C1) and CW 4 (C1). Meanwhile, the control word CW3 (C1) can be decrypted to access the audio / video content, because this control word has already been sent in the previous ECM3 control message. As the difference between the time stamp of ECM4 control message and ECM5 message is lower than the cryptoperiod, the brand of the error counter is incremented by 2 units and passes to 8.
p0040Similarly, the following control message ECM6 contains the control words CW3 (C2) and CW 4 (C2) that can be used to decrypt the audio / video content. The time stamp contained in this message implies that the error counter is incremented by 2 units to pass to 10.
p0041The following ECM7 control message contains the control words CW 4 (C1) and CW5 (C1). As the error counter 10 contains the value that is equal to the threshold value, but not more than this value, the ECM7 message is processed to return the control words immediately. This means that the control word CW5 (C1) will be available when it is needed for audio / video content. The error counter is again incremented by two units to pass to 12, thus beyond the threshold value.
p0042The following control message ECM8 contains the control words CW 4 (C2) and CW5 (C2). This message is processed immediately, but the control words that it contains will not be diverted after a wait time of 12 seconds. This means that with a crypto 10 seconds, the control words are returned 2 seconds after the end of the crypto. During those two seconds, the control word that is required to access the audio / video content is the word CW5 (C2). But this control word is not accessible before being sent to the decoder. The result is that during these two seconds, the audio / video content is not available. This may result in the display of the user by a blurred image or a uniformly black or white screen for example.
p0043The method continues by adding 2 units to the error counter and therefore two seconds time of return of the control words. Thus, when processing the following control message ECM9, audio / video content will not be accessible for 4 seconds. For consecutive messages ECM10, ECM 11 and ECM12, the time during which access to the audio / video content is not possible is respectively 6 seconds, 8 seconds and 10 seconds. As can be readily seen, since the delay time is equal to twice the cryptoperiod, the content is no longer accessible.
p0044The time stamp TS as described above can have a "resolution" of the order of a second or even a few seconds, for example 4 seconds in practice. This means that the difference between two time stamp values will also be expressed in seconds and not in fractions of seconds.
p0045It should be noted that the example described above uses a time given by the time stamps. If the multimedia unit, that is to say the security module and / or the decoder contain a clock, it is of course possible to calculate the difference between two time provided by the clock rather than between two time values . In both cases, the principle of the invention remains the same.
Using a buffer
p0046The system as described above has a limitation in the case where a buffer memory is used for storing the audio / video content, so as to compensate the delay induced by the security module and make it ineffective.
p0047One way to make this unnecessary storage or at least somewhat effective is to set no upper limit to the delay induced by the error counter or set a high limit. In this way, as the error counter increases by two to each message improper control, it almost always reach a value greater than twice the cryptoperiod even more so exceeding the shift introduced by the buffer. From that moment, the entire audio / video content is no longer accessible. However, this may be a disadvantage. Indeed, if the error counter has reached a significant value, it is necessary to wait for a long period after stopping the separator device to decrement the error count enough for the system to work properly again.
p0048Another way to make this ineffective memorization is not to return the control words that, taking into account the delay, should be sent for a period during which the content is not encrypted by control words supposed to be sent by the security module. For example, the message referenced control on ECM8<figref idrefs="f0001">2</figref> contains the control words CW 4 (C2) and CW5 (C2). With a value of the error counter 12, these control words should be returned after the end of the crypto. In this case, these control words are simply not returned. The control word CW 4 (C2) being contained in the message ECM6, audio / video content can be decrypted until the end of the crypto use the control words. From the next change, the content will not be accessible. However, the error counter continues to be incremented since the sending control messages frequency has not changed.
Decrementation
p0049In the unauthorized use mode described above, it is clear that if two users access the same security module to decrypt data, this data will be quickly accessible. If a user stops accessing the security module, it can be expected that the "legal" user to regain access to this content. For this, the proposed solution is to decrease the error counter CE according to predetermined rules.
p0050The <figref idrefs="f0001">Figures 4 and 5</figref> schematically illustrate decrementing error counter and incrementing according to the cryptoperiod CP and the difference between the time stamps of two successive control messages ECM. In one possible rule, whenever a control message ECM is received correctly, that is to say when the difference between the time stamp of a given message and the preceding message is equal to the crypto, the error counter is decremented by one.
p0051As an illustration, <figref idrefs="f0001">4</figref> represents the control messages ECM received during the time when the <figref idrefs="f0001">5</figref> illustrates the value of the error counter is also a function of time.
p0052Note that in this example, the initial value of the error counter is not zero, but was set at 2. Since no delay is introduced as long as the threshold value has not exceeded, this non-zero initial value has no negative effect on decryption. By cons, it will mean that, in the event of fraudulent use, the threshold value from which a delay is introduced is reached faster.
p0053The return of control words contained in the first control message is not delayed since the threshold value is reached. The first control word allows access to audio / video content. The second control word is memorized by the decoder. At the end of the cryptoperiod, a new control message ECM 2 is received by the multimedia unit. Comparing the time stamp of the two messages with the cryptoperiod the first control message ECM 1, it appears that the crypto is equal to the difference between the two time stamps contained in the control messages. At this time, the value of the error counter is decremented according to predefined rule here by one. So it is 1.
p0054When the following control message is received by the multimedia unit, the mark of the error counter is verified. This is 1. No delay time is therefore applied. Meanwhile, the previously stored control word from the previous control message is used to access the audio / video content. The counter value is decremented according to the preset rule and now takes a zero value.
p0055In the example shown, the multimedia unit receives a new ECM4 control message which the difference between the time stamp of this message and the preceding message is less than the crypto. At this time, the counter value is incremented by 2 units to pass to 2. This increment can happen for two different reasons. According to one of the reasons, the user changes channels (zapping). According to another reason, a splitter (splitter) is used. As already explained with reference to<figref idrefs="f0002">3</figref>, The counter value increases, for example every two.
p0056In the example of <figref idrefs="f0001">Figures 4 and 5</figref>The difference between the time stamps of two consecutive control messages ECM is lower than the crypto-up control message carrying the ECM8 reference. The value of the error counter 2 increases by 2 until the value 12. As indicated with reference to the<figref idrefs="f0002">3</figref>When this counter value exceeds 10 CE, a time delay in the return of the control words is introduced. Thus, the user will not have access to the entire audio / video content. On the<figref idrefs="f0001">Figures 4 and 5</figref>, When receiving the control messages to ECM9 ECM12, the difference between the time stamp is equal to the crypto-period and the value of the error counter is decremented by 1 for each message. As soon as this counter value reaches 10, the delay time in processing is canceled and the entire audio / video content is accessible to the user.
p0057The <figref idrefs="f0003">6</figref> illustrates a particular embodiment of the invention in which the crypto are different from one channel to another. In this figure, it is also assumed that the device of the invention is used fraudulently to supply two decoders from only one security module and further, each channel receives a control message two. This use of a control message of two is possible as each of these messages contains two control words. Thus, even in this case, all the control words will be available for two channels.
p0058For example, it is assumed that the cryptoperiod for channel 1, shown in the upper part of the <figref idrefs="f0003">6</figref>Is 7 seconds. The crypto period of the channel 2, shown in the lower part of the figure, is 5 seconds. Consider the case where the first control messages of each channel C1 and C2 are received simultaneously. The first control message ECM 1 (C1) of channel 1 contains an indication that the crypto is 7 seconds. This message contains the control words CW1 (C1) and CW2 (C1).
p0059The first 2 Channel control message contains a crypto-value 5 seconds and the CW'1 control words (C2) and CW'2 (C2).
p0060In the example shown in this <figref idrefs="f0003">6</figref>The following control messages of each channel are not used. The next message to be used is the reference control message ECM 2 (C2). This message is received two cryptoperiods after the first message ECM 1 (C2) so it is considered valid. The value of the error counter is maintained at a zero value or possibly decremented.
p0061The message received by the security module is referenced by ECM2 (C1). He received two cryptoperiods after the first message ECM 1 (C1), or after 14 seconds in our example. This means it is also received 4 seconds after the message ECM 2 (C2) corresponding to channel C2. This value is 4 seconds lower than the cryptoperiod contained in the previous control message. The value of the error counter is incremented by 2 units, if we apply the same rule as in the previous example. The value of the error counter is 2.
p0062The following message will be received after 4 cryptoperiods C2 channel, that is to say (4x5) - (2x7) = 6 seconds after the last message received ECM2 (C1). Since this message contained the value 7 seconds for crypto, the ECM3 Message (C2) is considered incorrect and the value of the error counter is incremented by 2. It thus reaches the value of 4.
p0063The following message ECM 3 (C1) is received after (4x7) - (4x5) = 8 seconds. The previous message contained the value of the crypto corresponding to that of channel C2, namely 5 seconds. The duration of 8 seconds between the previous message is greater than this value of 5 seconds. The message is considered correct. The value of the error counter will be decremented by one. Continuing the process as described above, it can be shown that the error counter will be incremented and decremented alternately. As incrementing is done by steps of two and decrementing is done in steps of one unit, this counter value will increase in the case of fraudulent use as shown by the<figref idrefs="f0003">6</figref>. This counter will take the values 0, 2, 4, 3, 5, 4, 6, 5, 7, ... until it exceeds the threshold value from which a delay in the return of words control is generated.
p0064It should be noted that the case where users decrypt only one control message of two, as described with reference to <figref idrefs="f0003">6</figref>Represents the worst case for misuse detection. One can easily observe that if fraudulent users decrypt all the control messages ECM, the value of the error counter will increase faster and the return of the control words by the security module will be even faster delayed.
safety and matched decoders module
p0065The following description applies more particularly, but not exclusively, if the security module and the decoder forming a multimedia unit are paired. In this case, they each contain a key to an asymmetric key pair, said pair being unique and different for each security unit assembly / decoder. In this configuration, when a multimedia unit is activated, a session key, generally symmetrical is negotiated between the security module and the decoder. This session key is used to encrypt the control words CW that have been decrypted by the security module, before sending them to the decoder. The use of such a session key is a problem for fraudulent users who operate a separation device. Indeed, as the session key between the pair security / decoder module 1 is different from the session key between the pair security module / decoder 2, it is necessary to negotiate a key sessions at each reception of a message ECM control on a different channel. In the case illustrated in<figref idrefs="f0002">3</figref> where the control messages are alternatively received on channel C1 and another channel C2, under certain configurations of multimedia units, a session key is to be negotiated between each control message ECM reception.
p0066To generate the negotiation of such a session key, you must reset the security module. This is done by sending a command to reset (reset) to the multimedia unit. Such an order can be sent between each control message ECM. In this case, it is important that the value of the error counter is not reset. It is also desirable that this counter value increases when reset corresponds to fraudulent use.
p0067To achieve this, the security module stores in volatile memory, the most recently he received. This date is sent for example by a management center as a control message. Upon receipt of a reset command, this date is stored in non-volatile memory.
p0068Alongside this, as already mentioned, the control messages ECM contain a time stamp TS. The multimedia unit or more precisely the security module also stores a term called "latency" which is in principle superior or equal to a crypto.
p0069Upon receipt of each control message ECM, the security module calculates the difference between the time stamp TS of the ECM and the most recently received before the last reset, previously stored in the nonvolatile memory. If this difference is greater than the latency, the error counter can be set to zero or to a value for which there is no delay in the return of the control words. If this difference is less than the latency time, this means that the security module has decrypted a control message shortly before the reset, which can correspond to a configuration in which a separating device is used. The error counter is incremented according to a predefined rule, for example, 3 units.
p0070In a first embodiment, when a control message has been processed "shortly" before resetting or the last stored date is to say a duration lower than the latency, a delay time is introduced. This prevents the storage of the value of the error counter in non-volatile memory. By cons, if reset "legal" for technical reasons, the honest user will wait until the delay time has elapsed before access to the audio / video content. If more he changes channels during this time, the counter value will increase.
p0071According to another embodiment, the value of the error counter is stored so that a reset command does not cause a reset of the error counter. Instead, this value is preserved as before zeroing. In this way, a reset command between each control message ECM will rapidly effect of preventing access to the audio / video content. By cons, a discount to occasional zero will not prevent access to the audio / video content that a sufficient number of control messages have been processed correctly between two consecutive reset to zero. To prevent cumulative effect under normal circumstances, if the time between the first processing of a control message (after the reset) and time of the last treatment before the reset is long enough (eg several hours) the error counter will be reset. The time required for a reset of the counter is performed can be defined in advance and is named downtime.
p0072Note that there are so-called security modules multi-sesions that are able to store several session keys. In cases of normal use, each session key is set for dialogue with a multimedia unit or as a content decryption together that would be placed in the same unit.
p0073When access to the security module by a decryption sets, it will add a reference ID. The security module will process this message in a clean environment in this together and that includes the key sessions (if a match is active), other identification data (rights, credit) and data for use in the detection fraudulent as described above. This is particularly the error counter, the time stamp of the last processing of a control message and the value of the crypto.
p0074Thus, the same security module can process several decrypting units while ensuring that the total number of decoders associated to this module does not exceed the limit. This limit can be programmed according to the user profile.
Increment / decrement at different speeds
p0075In the examples shown, the counter is incremented faster than it is decremented. It increases e.g. two units when the difference between the time stamp of two successive control messages is lower than the cryptoperiod. It increases three units at each reset considered invalid while it decreases as one each correct reception. This prevents individual cases in which, playing on reset and correct processing of control messages, it is possible to maintain the value of the error counter in a range in which access to the audio content / video is always or almost always possible by fraudulent users.
p0076In another variant, it is possible to provide for the decrement occurs faster than the increment.
delay time increments
p0077As indicated above, it is generally expected to introduce a delay when the value of the error counter reaches a certain threshold. Beyond this threshold, the delay can be proportional to the content of the counter or increase in increments or be fixed. Generally, this delay is provided for it prevents access to a part of the audio / video content for a time of fraudulent use, then the entire audio / video content after a time of greater misuse.
p0078In the examples described above, it is indicated that the duration of the crypto period a control message is extracted as well as its time stamp and then is verified upon reception of the next message, if the difference between the mark time of the message and the previous is equal to or lower than the cryptoperiod. This implies that it must memorize the cryptoperiod and the time stamp of the first message.
p0079Alternatively, it is possible to calculate the difference between the time stamps of two consecutive control messages ECM 1 and ECM 2 and check if this difference is less than or equal to the crypto-extracted from the second received message ECM2. This has the advantage of not requiring the storage of the cryptoperiod and thus allows memory economy.
p0080In the examples described, the value of the error counter may be between 0 and a threshold value, for example 10 or be greater than this threshold value. 0 to the threshold, there is no time delay. Beyond the threshold, a delay is introduced. Clearly it is possible to limit the maximum value of the counter, which also limits the number of consecutive correct messages to be deciphered in order to again pass under the threshold value.
p0081Alternatively, it is possible to reverse the direction of the counter, which means that every correct decryption, the counter is incremented while it is decremented when a fraudulent decryption. In this case, a time delay is introduced when the counter contains a value between 0 and a threshold while no time delay is introduced if the counter value is beyond the threshold.
p0082The examples mention the use of two decoders to a security module. It is of course possible for a fraudulent use, to connect more than two decoders to a security module by means of a separating device. According to the method of the invention, this will result in even faster block access to the audio / video content, since the error counter will be incremented even faster.
Contents5
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office |
|---|---|---|
| EP0866613A | Cites | European Patent Office (EPO) |
| EP1353511A | Cites | European Patent Office (EPO) |
| EP1441525A | Cites | European Patent Office (EPO) |
| EP1575293A | Cites | European Patent Office (EPO) |
| WO9957901A | Cites | World Intellectual Property Organization (WIPO) |
| WO03069910A | Cites | World Intellectual Property Organization (WIPO) |
| US5461675A | Cites | United States of America |
| US2004215691A1 | Cites | United States of America |
| FRANCIS ET AL: "Countermeasures for attacks on satellite TV cards using open receivers" AUSTRALASIAN INFORMATION SECURITY WORKSHOP.: DIGITAL RIGHTS MANAGEMENT, XX, XX, 6 novembre 2004 (2004-11-06), pages 1-6, XP002333719 | Non-patent | – |
| "FUNCTIONAL MODEL OF A CONDITIONAL ACCESS SYSTEM" EBU REVIEW- TECHNICAL, EUROPEAN BROADCASTING UNION. BRUSSELS, BE, no. 266, 21 décembre 1995 (1995-12-21), pages 64-77, XP000559450 ISSN: 0251-0936 cité dans la demande | Non-patent | – |
| "MCCORMAC HACK OVER CABLEMODEM" HACKWATCH.COM, 10 août 1998 (1998-08-10), XP002292343 cité dans la demande | Non-patent | – |
31 members in 19 offices
Priority claims3
| Document | Office | Kind | Date |
|---|---|---|---|
| 05106185 | European Patent Office (EPO) | – | |
| 05106185 | European Patent Office (EPO) | A | |
| 2006063988 | European Patent Office (EPO) | W |
Members31
| Document | Office | Kind | |
|---|---|---|---|
| EP1742474A1 | European Patent Office (EPO) | A1 | |
| AU2006268683A1 | Australia | A1 | |
| CA2614107A1 | Canada | A1 | |
| WO2007006735A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20080024520A | Republic of Korea | A | |
| EP1900211A1 | European Patent Office (EPO) | A1 | |
| IL188334A0 | Israel | A0 | |
| MX2008000004A | Mexico | A | |
| MX2008000004A | Mexico | A | |
| CN101218822A | China | A | |
| HK1111022A | Hong Kong, China | A | |
| HK1111022A1 | Hong Kong, China | A1 | |
| US2008209232A1 | United States of America | A1 | |
| JP2008545307A | Japan | A | |
| RU2007148552A | Russian Federation | A | |
| ZA200800078B | South Africa | B | |
| EP1900211B1This record | European Patent Office (EPO) | B1 | |
| AT449510T | Austria | T | |
| ATE449510T1 | Austria | T1 | |
| DE602006010554D1 | Germany | D1 | |
| PT1900211E | Portugal | E | |
| ES2336028T3 | Spain | T3 | |
| PL1900211T3 | Poland | T3 | |
| AU2006268683B2 | Australia | B2 | |
| CN101218822B | China | B | |
| RU2409002C2 | Russian Federation | C2 | |
| US7908491B2 | United States of America | B2 | |
| IL188334A | Israel | A | |
| KR101280640B1 | Republic of Korea | B1 | |
| CA2614107C | Canada | C | |
| BRPI0615532A2 | Brazil | A2 |
86 legal events, as 13 offices reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | Office | |
|---|---|---|---|
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Announcement of lapse in spainLapsedFD2A | FD2A | ES | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Patent lapsedLapsedMM4A | MM4A | IE | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | BE | |
| Gb: european patent ceased through non-payment of renewal feeCeasedGBPC | GBPC | EP | |
| Lapsed because of non-payment of the annual feeLapsedMM | MM | NL | |
| Patent ceasedCeasedPL | PL | CH | |
| Application deemed withdrawn, or ip right lapsed, due to non-payment of renewal feeWithdrawnR119 | R119 | DE | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Fee paymentPLFP | PLFP | FR | |
| Fee paymentPLFP | PLFP | FR | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Epo decision maintaining patent unamended now finalR100 | R100 | DE | |
| Opposition rejectedOpposition27O | 27O | EP | |
| Opposition rejectedOppositionORIGINAL CODE: 0009273PLBN | PLBN | EP | |
| Information on the status of an ep patent application or granted ep patentGrantedSTATUS: OPPOSITION REJECTEDSTAA | STAA | EP | |
| Communication despatched that opposition was rejectedOppositionORIGINAL CODE: EPIDOSNREJ1PLCK | PLCK | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Annual fee paid to national office [announced via postgrant information from national office to epo]GrantedPGFP | PGFP | EP | |
| Reply of patent proprietor to notice(s) of opposition receivedOppositionORIGINAL CODE: EPIDOSNOBS3PLBB | PLBB | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Information modified related to communication of a notice of opposition and request to file observations + time limitOppositionORIGINAL CODE: EPIDOSCOBS2PLAF | PLAF | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Notice of opposition and request to file observation + time limit sentOppositionORIGINAL CODE: EPIDOSNOBS2PLAX | PLAX | EP | |
| Opposition filedOpposition26 | 26 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Opposition filedOppositionORIGINAL CODE: 0009260PLBI | PLBI | EP | |
| Standard patents granted in hong kongGrantedGR | GR | HK | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| New agentNV | NV | CH | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Lapsed in a contracting state [announced via postgrant information from national office to epo]LapsedPG25 | PG25 | EP | |
| Translation of ep patentT3 | T3 | PL | |
| Lt: invalidation of european patent or patent extensionLTIE | LTIE | EP | |
| Definitive protectionFG2A | FG2A | ES | |
| Translation is availableAVAILABILITY OF NATIONAL TRANSLATIONSC4A | SC4A | PT | |
| Ep patent valid in romaniaEPE | EPE | RO | |
| Corresponds to:REF | REF | EP | |
| European patents granted designating irelandGrantedFG4D | FG4D | IE | |
| European patent takes effect as a national patent in ch/liEP | EP | CH | |
| Designated contracting statesAK | AK | EP | |
| European patent grantedGrantedNOT ENGLISHFG4D | FG4D | GB | |
| (expected) grantORIGINAL CODE: 0009210GRAA | GRAA | EP | |
| Grant fee paidORIGINAL CODE: EPIDOSNIGR3GRAS | GRAS | EP | |
| Party data changed (applicant data changed or rights of an application transferred)RAP1 | RAP1 | EP | |
| Despatch of communication of intention to grant a patentORIGINAL CODE: EPIDOSNIGR1GRAP | GRAP | EP | |
| Requests to designate patent in hong kongDE | DE | HK | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Information on inventor provided before grant (corrected)RIN1 | RIN1 | EP | |
| Request for extension of the european patent (deleted)DAX | DAX | EP | |
| Request for examination filed17P | 17P | EP | |
| Designated contracting statesAK | AK | EP | |
| Public reference made under article 153(3) epc to a published international application that has entered the european phaseORIGINAL CODE: 0009012PUAI | PUAI | EP |
Numbers
- Publication
- 1900211
- Application
- 67776302
Titles3
- German
- VERFAHREN UND EINRICHTUNG ZUR KONTROLLE DES ZUGANGS ZU VERSCHLÜSSELTEN DATEN
- English
- METHOD AND DEVICE FOR CONTROLLING ACCESS TO ENCRYPTED DATA
- French
- METHODE ET DISPOSITIF DE CONTROLE D'ACCES A DES DONNEES CHIFFREES
Classification
- CPC, 6
- H04N21/44236
- H04N21/4623
- H04N7/1675
- H04N21/26606
- H04N21/4181
- H04N21/4405
- IPC, 3
- H04N7 167
- H04N5 00
- G07F7 10
Designated states31
- Contracting states, 31
- Austria
- Belgium
- Bulgaria
- Switzerland
- Cyprus
- Czechia
- Germany
- Denmark
- Estonia
- Spain
- Finland
- France
- United Kingdom
- Greece
- Hungary
- Ireland
- Iceland
- Italy
- Liechtenstein
- Lithuania
- Luxembourg
- Latvia
- Monaco
- Netherlands (Kingdom of the)
and 7 moreShow fewer
- Poland
- Portugal
- Romania
- Sweden
- Slovenia
- Slovakia
- Türkiye
