Nova Patents
EP2462587B1

Authentication of data streams

Abstract

This record has no abstract on file.

EP2462587B1, drawing sheet 1
Sheet 1 of 9

Term

3.9 yearsleft in the term

Expires 6 August 2030.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

17 claims: 9 independent, 8 dependent

  1. 1
    A method for encoding a data stream (100) comprising a plurality of data frames (101, 102, 103, 104, 105, 106), the method comprising - generating (207, 208, 209, 210) a cryptographic value (122) of N successive data frames (112) and of configuration information using a cryptographic hash function, with N>1;wherein the configuration information comprises information for rendering the data stream (100);wherein generating (207, 208, 209, 210) the cryptographic value (122) of the N successive data frames (112) comprises, iteratively generating (208) an intermediate cryptographic value of each of the N successive data frames (112) using a starting state of the intermediate cryptographic value until an intermediate cryptographic value of the N th data frame (105) is generated, the intermediate cryptographic value of the N th data frame (105) representing the cryptographic value (122) of the N successive data frames (112);wherein the starting state of the first data frame (103) of the N successive data frames (112) is an intermediate cryptographic value of the configuration information, wherein the starting state of each subsequent data frame (104, 105) of the N successive data frames (112) is the intermediate cryptographic value of the data frame (103, 104) of the N successive data frames (112), which precedes the subsequent data frame (104, 105) of the N successive data frames (112);and - inserting (205) the cryptographic value (122) of the N successive data frames (112) into a frame (106) of the data stream (100) subsequent to the N successive data frames (112).
  2. 2
    The method of any previous claim, wherein the cryptographic value (122) is inserted as a data stream element ;and wherein the data stream element is a syntactic element of a data frame (106) of the data stream (100) and wherein the data stream (100) is an MPEG4-AAC or MPEG2-AAC stream.
  3. 3
    The method of any of claims 1 to 2, wherein the configuration information comprises at least one of:- an indication of a sampling rate;- an indication of a channel configuration of an audio coding system;- an indication of the number of samples in a data frame (101, 102, 103, 104, 105, 106).
  4. 4
    The method of any of claims 1 to 3, comprising - selecting N such that the N successive data frames (112) cover as close to a pre-determined duration of a corresponding signal as possible when played back with an appropriate configuration.
  5. 5
    A method for verifying a data stream (100) at a decoder (414), the data stream (100) comprising a plurality of data frames (101, 102, 103, 104, 105, 106) and a cryptographic value (122) associated with N preceding successive data frames (112), with N>1, the method comprising - generating (308) a second cryptographic value of the N successive data frames (112) and of configuration information using a cryptographic hash function;wherein the configuration information comprises information for rendering the data stream (100);wherein generating the second cryptographic value of the N successive data frames (112) comprises, iteratively generating (208) an intermediate second cryptographic value of each of the N successive data frames (112) using a starting state of the intermediate cryptographic value until an intermediate second cryptographic value of the N th data frame (105) is generated, the intermediate second cryptographic value of the N th data frame (105) representing the second cryptographic value of the N successive data frames (112);wherein the starting state of the first data frame (103) of the N successive data frames (112) is an intermediate second cryptographic value of the configuration information, wherein the starting state of each subsequent data frame (104, 105) of the N successive data frames (112) is the intermediate second cryptographic value of the data frame (103, 104) of the N successive data frames (112), which precedes the subsequent data frame (104, 105) of the N successive data frames (112);- extracting (307) the cryptographic value (122) from a data frame (106) of the data stream (100);and - comparing (309) the cryptographic value (122) with the second cryptographic value.
  6. 9
    A data stream (100) comprising a cryptographic value (122) generated and inserted according to the method of any one of claims 1 to 4.
  7. 10
    An encoder (404) operable to encode a data stream (100) comprising a plurality of data frames (101, 102, 103, 104, 105, 106), the encoder (404) comprising a processor operable to - generate a cryptographic value (122) of N successive data frames (112) and of configuration information using a cryptographic hash function, with N>1;wherein the configuration information comprises information for rendering the data stream (11);wherein generating the cryptographic value (122) of the N successive data frames (112) comprises, iteratively generating an intermediate cryptographic value of each of the N successive data frames (112) using a starting state of the intermediate cryptographic value until an intermediate cryptographic value of the N th data frame (105) is generated, the intermediate cryptographic value of the N th data frame (105) representing the cryptographic value (122) of the N successive data frames (112);wherein the starting state of the first data frame (103) of the N successive data frames (112) is an intermediate cryptographic value of the configuration information, wherein the starting state of each subsequent data frame (104, 105) of the N successive data frames (112) is the intermediate cryptographic value of the data frame (103, 104) of the N successive data frames (112), which precedes the subsequent data frame (104, 105) of the N successive data frames (112);and - insert the cryptographic value (122) into a frame (106) of the data stream (100) subsequent to the N successive data frames (112).
  8. 11
    A decoder (414) operable to verify a data stream (100) comprising a plurality of data frames (101, 102, 103, 104, 105, 106) and a cryptographic value (122) associated with N preceding successive data frames (112), with N>1, the decoder (414) comprising a processor operable to - generate a second cryptographic value of the N successive data frames (112) and of configuration information using a cryptographic hash function;wherein the configuration information comprises information for rendering the data stream (100);wherein generating the second cryptographic value of the N successive data frames (112) comprises, iteratively generating an intermediate second cryptographic value of each of the N successive data frames (112) using a starting state of the intermediate cryptographic value until an intermediate second cryptographic value of the N th data frame (105) is generated, the intermediate second cryptographic value of the N th data frame (105) representing the second cryptographic value of the N successive data frames (112);wherein the starting state of the first data frame (103) of the N successive data frames (112) is an intermediate second cryptographic value of the configuration information, wherein the starting state of each subsequent data frame (104, 105) of the N successive data frames (112) is the intermediate second cryptographic value of the data frame (103, 104) of the N successive data frames (112), which precedes the subsequent data frame (104, 105) of the N successive data frames (112);- extract the cryptographic value (122) from a data frame (106) of the data stream (100);and - compare the cryptographic value (122) with the second cryptographic value.
  9. 12
    A software program adapted for execution on a processor and for performing the method steps of any one of claims 1 to 8 when carried out on a computing device.
  10. 13
    A storage medium comprising a software program adapted for execution on a processor and for performing the method steps of any one of claims 1 to 8 when carried out on a computing device.
  11. 16
    A method for concatenating a first and a second bitstream (501, 502), each comprising a plurality of data frames (101, 102, 103, 104, 105, 106) and a cryptographic value (122) associated with a given number of data frames (101, 102, 103, 104, 105, 106), the method comprising - generating a concatenated bitstream (505) from the first and second bitstream (501, 502), wherein the concatenated bitstream (505) comprises at least a portion of the plurality of data frames (101, 102, 103, 104, 105, 106) from the first and second bitstream (501, 502), and comprises a cryptographic value (122) generated and inserted according to the method of any one of claims 1 to 4.