Method and device for transmission of entitlement management messages
Abstract
Procedure for transmitting ownership management messages (EMM) of data and / or services provided to a plurality of terminals of a data exchange network, in which each terminal receives content encoded with a CW key transmitted in a message of ECM access control and at least one decryption key of said CW key transmitted in an EMM ownership management message, a procedure characterized in that it comprises the following steps: In the issuance: - define a set of EMM message types based on at least one criterion representative of the type of data and / or services provided; - define a plurality of types of logical transmission paths and associate at least one parameter to each type of path (STREAM_TYPE) to indicate to the terminals the types of EMM that pass through each of the described logical paths; - assign to each type of EMM message at least one path between the defined logical transmission paths - transmit the parameter (STREAM_TYPE) and said logical paths to each terminal; - multiplex the logical transmission paths in the same data stream; - transmit said data flow to the terminals; and on reception: - each terminal filters incoming EMMs based on the parameter (STREAM_TYPE) and at least one status parameter that depends on the current operation of the terminal.

Term
Term ended
Projected expiry passed 28 January 2023, 3.7 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
16 claims: 3 independent, 13 dependent
- 1ES 2 287 486 T3 REIVINDICACIONES 1. Procedimiento de transmisión de mensajes de gestión de titularidad (EMM) de datos y/o servicios suministrados a una pluralidad de terminales de una red de intercambio de datos, en la cual cada terminal recibe un contenido codificado con una clave CW transmitida en un mensaje de control de acceso ECM y al menos una clave de descifrado de dicha clave CW transmitida en un mensaje de gestión de titularidad EMM, procedimiento caracterizado porque comprende las siguientes etapas:En la emisión: - definir un conjunto de tipos de mensajes EMM en función de al menos un criterio representativo del tipo de datos y/o servicios suministrados;- definir una pluralidad de tipos de vías lógicas de transmisión y asociar a cada tipo de vía al menos un parámetro (STREAM_TYPE) para indicar a los terminales los tipos de EMM que pasan por cada una de las vías lógicas descritas;- asignar a cada tipo de mensaje EMM al menos una vía entre las vías lógicas de transmisión definidas - transmitir el parámetro (STREAM_TYPE) y dichas vías lógicas a cada terminal;- multiplexar las vías lógicas de transmisión en un mismo flujo de datos;- transmitir dicho flujo de datos a los terminales;y en la recepción: - cada terminal filtra los EMM entrantes en función del parámetro (STREAM_TYPE) y de al menos un parámetro de estado que depende del funcionamiento actual del terminal.
- 2Procedimiento de acuerdo con la reivindicación 1, caracterizado porque dicho parámetro (STREAM_TYPE) se transmite a cada terminal en una estructura de datos dinámica que representa una vía lógica de control.
- 3Procedimiento de acuerdo con la reivindicación 2, caracterizado porque dicha estructura de datos dinámica se transmite en un EMM cifrado.
- 4Procedimiento de acuerdo con la reivindicación 3, caracterizado porque dicha estructura dinámica tiene al menos uno de los siguientes campos:- un primer campo (EMM_XID) para permitir al terminal identificar la vía lógica descrita por la estructura;- un segundo campo (Version_Number) para indicar al terminal una evolución de los datos y/o una evolución de la estructura dinámica que corresponde a la transmisión de dichos nuevos datos por la vía descrita de modo que el terminal adapte su filtrado para recuperar dichos nuevos datos;- un tercer campo (Listen_Time) para indicar al terminal un periodo de escucha de la vía descrita.
- 5Procedimiento de acuerdo con la reivindicación 4, caracterizado porque dicho tercer campo (Listen_Time) representa un periodo mínimo fijo suficiente para recuperar los mensajes transmitidos.
- 6Procedimiento de acuerdo con la reivindicación 4, caracterizado porque dicho tercer campo (Listen_Time) representa un periodo mínimo variable en función de la cadencia de repetición de los envíos de mensajes EMM.
- 7Procedimiento de acuerdo con una de las reivindicaciones 5 ó 6, caracterizado porque los tipos de vías lógicas definidos comprenden al menos:- una vía RÁPIDA para transmitir mensajes EMM destinados a terminales que han solicitado expresamente estos mensajes;- una vía DEDICADA para transmitir mensajes EMM que tienen objetivos funcionales iguales;- una vía NORMAL para transmitir mensajes EMM cuyo contenido no es previsible y que pueden estar diferidos en el tiempo;- una vía DIFERIDA para transmitir a los terminales mensajes EMM no urgentes y de diversos objetivos funcionales;ES 2 287 486 T3 - una vía de DESVÍO para retransmitir a los terminales mensajes que ya se hayan transmitido por una vía diferente de la DEDICADA.
- 8Procedimiento de acuerdo con las reivindicaciones 6 y 7, caracterizado porque para las vías RÁPIDA, NORMAL, DIFERIDA y DEDICADA el periodo mínimo variable se estima en función de la cadencia de repetición de los envíos de mensajes EMM.
- 9Procedimiento de acuerdo con una de las reivindicaciones 1 a 8, caracterizado porque los datos y/o servicios suministrados a los terminales representan programas multimedia.
- 10Procedimiento de acuerdo con la reivindicación 9, caracterizado porque los datos y/o servicios suministrados a los terminales representan programas audiovisuales.
- 11Procedimiento de acuerdo con una de las reivindicaciones 1 a 10, caracterizado porque los mensajes EMM se transmiten en modo difuso.
- 12Procedimiento de acuerdo con una de las reivindicaciones 1 a 10, caracterizado porque los mensajes EMM se transmiten en modo conectado.
- 13Procedimiento de acuerdo con una de las reivindicaciones 11 ó 12, los mensajes EMM se encapsulan en un formato MPEG.
- 14Procedimiento de acuerdo con la reivindicación 13, caracterizado porque las secciones MPEG obtenidas tienen al menos las siguientes informaciones privadas:- EMM_XID que representa el identificador del EMM;- LG_EMM que representa la longitud del EMM, y - el contenido del EMM.
- 15Dispositivo de transmisión de mensajes de control de acceso (EMM) a datos y/o servicios suministrados a una pluralidad de terminales en una red de intercambio de datos, caracterizado porque comprende:- medios (16, 18) para definir un conjunto de tipos de mensajes EMM en función de al menos un criterio representativo del tipo de datos y/o servicios suministrados;- medios (10) para definir un conjunto de tipos de vías lógicas de transmisión en función del contenido a transmitir en cada vía;- medios (4) para asignar a cada tipo de mensaje EMM una vía lógica de transmisión y para asociar a cada tipo de vías al menos un parámetro (STREAM_TYPE) para indicar a los terminales los tipos de EMM que pasan por cada una de las vías lógicas descritas;- medios (12) para multiplexar las vías lógicas de transmisión en un mismo flujo de datos;- medios para transmitir dicho flujo de datos a los terminales, y - medios para filtrar, a nivel de un terminal, los EMM entrantes en función de los tipos de vías definidos.
- 16Dispositivo de acuerdo con la reivindicación 15, caracterizado porque comprende:- medios (36) para transmitir el parámetro (STREAM_TYPE) a cada terminal;- medios (22) para permitir a cada terminal filtrar los EMM entrantes en función del parámetro (STREAM_TYPE) y de al menos un parámetro de estado que refleje el actual funcionamiento del terminal.
Independent claims16
195 paragraphs in 9 sections, as filed
ES 2 287 486 T3
DESCRIPTION
Procedure and device for transmitting ownership management messages.
Technical field
The invention relates to the field of transmissions of data and / or encrypted services towards a plurality of terminals connected to a data exchange network and relates more particularly to a method of transmission of ownership management messages (EMM) of these data and these services as well as a device to implement the procedure.
Prior state of the art
With the development of data exchanges through open networks such as the Internet, the protection of exchanges has an increasing importance in the activities of operators and service providers. This protection has as main purposes:
- prevent transactions carried out through the network from being intercepted;
- ensure the integrity of the data, that is, determine whether the transmitted data has been altered during communication;
- allow authentication, that is to say, ensure the identity of the interlocutors of a transaction and confidentiality, which consists in rendering the information incomprehensible to people other than those who carry out the transaction.
Authentication is done through access control that only allows access to resources to authorized persons.
In the field of broadcasting encrypted audiovisual programs, the DVB protocol defines a common encryption algorithm (by Common Scrambling Algorithm), but does not foresee anything in terms of access control, leaving operators and service providers the freedom to define your own systems.
However, the DVB protocol provides for the transport of access control data that is retrieved on reception by means of data decryptors in an access control table (CAT, for Conditional Access Table) inserted in the MPEG transport multiplexer and by means of other private data packets indicated by means of data decryptors in a program table (PMT, by Program Map Table) containing PID identification numbers (by Packet Identifier) of each program component encoded in the form of an MPEG PES (by Packetized Elementary Stream) elementary set.
Generally, the information necessary for decoding is transmitted in specific access control messages called CAM conditional access messages (for Conditional Access Messages), which comprise at least one ECM (Entitlement Control Message) ownership control message and one ECM (Entitlement Control Message) message. EMM entitlement management (for Entitlement Management Message).
These conditional access messages are generated from at least three input data:
- a CW control word (per Control Word) to initialize the decoding sequence,
- a service key (Service Key) used to encrypt the control word for a group of one or more users;
- a user key (User Key) used to encrypt the service key.
ECMs are based on control word and service key while EMMs are based on service key and user key.
ECMs and EMMs are periodically and permanently transmitted to terminals to ensure their reception by users.
At reception, the decryption principle consists of recovering the service key from the EMMs and the user key contained in a security processor, for example a chip card. The service key is then used to decrypt the ECMs to retrieve the control word, allowing the decoding system to start.
ES 2 287 486 T3
In known access control systems, the transmission of EMMs is carried out sequentially, without priority or scheduling regardless of the specific functions of each transmitted EMM message. However, the different EMMs do not necessarily refer to the same data or the same services and therefore are not subject to the same transmission restrictions. Indeed, EMMs can be divided into three large families that differ in their respective functions and in their transmission conditions. As an example, the following can be mentioned:
- messages linked to a previous contract between the subscriber and the operator, such as for example a subscription to a service for a specified period. In this case, the EMM messages are transmitted permanently during the subscription period. This transmission represents a very important data flow that however must be maintained to ensure its reception by the subscriber.
- so-called dynamic messages that correspond to an immediate need of a subscriber such as for example the purchase of a session or an event.
- messages of technical management of the security processor decided by the operator in agreement with the subscriber.
Sequential transmission, without priority or scheduling, of these EMM messages generates a significant cycle time, which varies from site to site and causes significant waiting time for the subscriber. In addition, the mixture of messages having different characters and degrees of priority leads to a non-optimized occupation of the passband.
The object of the invention is to alleviate the drawbacks described above.
Document EP-A-1 111 923 describes a method of managing a conditional access control system that has a plurality of subscribers each equipped with a terminal provided with a conditional access module and a protected circuit to store the entitlements. , each terminal receives an ECM comprising a first key CW encrypted with a service key P<sub>T</sub>, each protected circuit receives an EMM message comprising at least the service key P<sub>T</sub> required for CW decryption.
This method aims to trace a protected circuit used fraudulently by sending different keys to the terminals to obtain the first CW keys and observing the information of a key supplied by a pirate. For this purpose, paging EMM messages are sent to a part of the terminals. These messages comprise at least the key P<sub>T</sub> and an artificial key (P<sub>D1</sub> or P<sub>D2</sub>) and identifiers of said keys P<sub>T</sub> And p<sub>D1</sub> or P<sub>D2</sub>. According to this method, the first EMM messages comprising P<sub>T</sub> And p<sub>D1</sub> to a first part of the terminals and the second EMM messages comprising PT and PD2 are transmitted to a second part of the terminals, then an ECM message is transmitted that identifies the PT key that must be used to decrypt CW, to all the terminals immediately before said CW key is requested to decrypt the content.
In this way, the hacker is obliged to make public all the keys, between PD1 and PD2, long before the CW key is requested. This makes it possible to track down the pirate who distributes PD1 and PD2.
Document EP 0 866 615 A2 describes an apparatus for transmitting multiplexed numerical data in coded form to terminals in which the decryption data specific to each terminal and the decryption data common to the different terminals are transmitted with said encrypted data.
Presentation of the invention
The invention proposes a procedure for transmitting ownership management messages (EMM) of data and / or services supplied to a plurality of terminals of a data exchange network, characterized in that it comprises the following steps:
In the broadcast:
- define a set of types of EMM messages based on at least one criterion representative of the type of data and / or services provided;
- defining a plurality of types of logical transmission paths and associating to each type of path at least one parameter (STREAM_TYPE) to indicate to the terminals the types of EMM that pass through each of the described logical paths;
- assign to each type of EMM message at least one path among the defined logical transmission paths
- transmit the parameter (STREAM_TYPE) and said logical paths to each terminal;
ES 2 287 486 T3
- multiplexing the logical transmission paths in the same data stream;
- transmitting said data stream to the terminals; and at the reception:
- each terminal filters incoming EMMs based on the parameter (STREAM_TYPE) and on at least one status parameter that depends on the current operation of the terminal.
Preferably, the parameter (STREAM_TYPE) is transmitted to each terminal in a dynamic data structure representing a logical control path.
According to a preferred embodiment, the dynamic structure is transmitted in an encrypted EMM and has at least one of the following fields:
- a first field (EMM_XID) to allow the terminal to identify the logical path described by the structure;
- a second field (Version_Number) to indicate to the terminal an evolution of the data and / or an evolution of the dynamic structure corresponding to the transmission of said new data through the described path so that the terminal adapts its filtering to recover said new ones data;
- a third field (Listen_Time) to indicate to the terminal a listening period of the described path.
Said third field (Listen_Time) represents a fixed minimum period or a variable minimum period, sufficient to allow the terminal to retrieve the transmitted messages.
In a variant embodiment, the types of logical paths defined comprise at least:
- a FAST way to transmit EMM messages destined for terminals that have expressly requested these messages.
- a DEDICATED path to transmit EMM messages that have the same functional objectives;
- a NORMAL way to transmit EMM messages whose content is not predictable and which may be delayed in time.
- a DEFERRED path to transmit non-urgent EMM messages with various functional purposes to the terminals;
- a BYPASS channel to retransmit messages that have already been transmitted by a channel other than the DEDICATED one to the terminals.
Preferably, for the FAST, NORMAL, DEFERRED and DEDICATED routes, the minimum variable period is estimated as a function of the repetition rate of the sending of EMM messages.
In an example of application of the method according to the invention, the data and / or services supplied to the terminals represent multimedia programs.
In another application example, the data and / or services supplied to the terminals represent audiovisual programs.
In both types of application, EMM messages are encapsulated in MPEG format and transmitted in diffuse mode or in connected mode. In addition to the content of the EMM, the obtained MPEG sections also have at least the following private information:
- EMM_XID that represents the identifier of the EMM;
- LG_EMM that represents the length of the EMM.
The method according to the invention is put into practice with a device having:
- means for defining a set of EMM message types based on at least one criterion representative of the type of data and / or services provided;
ES 2 287 486 T3
- means for defining a set of types of logical transmission paths as a function of the content to be transmitted on each path;
- means for assigning each type of EMM message a logical transmission path;
- means for multiplexing the logical transmission paths in the same data stream;
- means for transmitting said data stream to the terminals, and
- means of filtering, at the terminal level, incoming EMMs based on the defined path types.
In the preferred embodiment of the invention, the device comprises:
- means for associating to each type of channel at least one parameter (STREAM_TYPE) to indicate to the terminals the types of EMM that pass through each of the described logical channels;
- means for transmitting the parameter (STREAM_TYPE) to each terminal;
- means for allowing each terminal to filter incoming EMMs based on the parameter (STREAM_TYPE) and on at least one status parameter that reflects the current operation of the terminal.
Brief description of the drawings
Other characteristics and advantages of the invention will result from the following description, taken as a non-limiting example, with reference to the attached figures in which:
figure 1 schematically illustrates a system in which an entitlement management message (EMM) transmission device is used according to the invention;
figure 2 represents a diagram of the operation of the device according to the invention;
Figure 3 schematically represents a communication mode between an EMM message generator and a Multiplexer according to a preferred embodiment of the invention.
figure 4 schematically illustrates the encapsulation of EMM in the MPEG section according to an example of implementation of the invention.
Detailed exposition of particular realizations
The following description refers to a particular application of the method according to the invention in an audiovisual program distribution system to a plurality of subscriber terminals connected to a data exchange network, such as, for example, the Internet network or to a network private broadcasting of programs.
This system allows a first set 2 of SMS subscriber management equipment, arranged for example in a commercial operator, to communicate, by means of a second set of subscriber ownership management equipment 6, with a third set 4 of transmission of ownership (EMM).
Each subscriber has a decoder 8 and a security processor in which the ownership is registered.
The third set 4 has a first module 10 named in the description below B-SAS (for Broadcast Subscription Authorization System) that allows ensuring the organization and dissemination of the EMMs in accordance with the guidelines coming from the equipment of the first set 2. The first B-SAS module communicates, on the one hand, with equipment from set 6 and on the other hand with a second multiplexing module 12 connected to a third module 14 for broadcasting the EMMs towards the decoder 8.
The set 6 of subscriber ownership management equipment has a first SAS 16 equipment that ensures the technical management of the security and ownership processors and a second STB-MS 18 equipment that ensures the management of the terminals of the subscribers.
The function of the first SAS equipment 16 is to express the requests for services from the SMS 2 of the different operators in EMM messages that can be used by the security processor or the terminal and transmit them to the B-SAS module 10 for transmission in diffuse mode to the subscriber terminals or to an I-SAS module 17 to distribute these EMMs in connected mode. The first SAS equipment 16 also allows to carry out near the B-SAS module 10, requests to add, send and replace EMMs destined for the terminals and requests to delete the sending of EMMs.
ES 2 287 486 T3
The second equipment STB-MS 18 also allows the SMS 2 equipment to define and maintain the characteristics of the subscriber terminals.
The second STB-MS device 18 also makes it possible to carry out, near the B-SAS module 10, requests for adding, sending and replacing EMMs destined for the terminals and requests for deleting sending EMMs. This STB-MS equipment is suitable for expressing the requests for services from the SMS 2 of the different operators in messages that can be used by the security processor or the terminal and for transmitting them to the I-SAS module 17 to distribute these EMMs in connected mode.
The decoder 8 located at the subscriber's home contains the security processor in which the ownership of the subscribers is registered and whose function is, in a known way, to process the EMM messages contained in the diffuse stream, to manage a presented HMI Human-Machine interface to the subscriber and communicate with the subscriber's security processor and a technical operator's server.
Figure 2 represents a detailed operating diagram of the B-SAS 10 module. The latter has a first block 20 to collect messages from the first SAS devices 16 or second STB-MS devices 18, a second block 22 to manage the waiting queues, a third block 24 to manage the broadcast of the EMMs an fourth block 26, controlled by an administrator, to define the system configuration information and a fifth supervision block 28 to collect technical and applicable information in the system.
The messages collected by the first block 20 can be requests to send EMM, replace or delete EMM by means of an application protocol such as TCP-IP, CORBA, HTTP + XML, RMI or a proprietary protocol.
Definition of EMM
The device and the method of the invention make it possible to define a set of types of EMM messages based on at least one criterion representative of the type of data and / or services provided. To this end, the SAS 16 and STB 18 upstream equipment request the insertion of an EMM in a cycle, specifying the diffusion modes (Reference of the transmission model, Start and end date of the EMM diffusion) and the description of the EMM (header structure, header size, EMM content).
Prior to broadcasting the EMMs, a plurality of types of logical transmission paths are defined with a parameter (STREAM_TYPE) to indicate to the terminals the types of EMMs that pass through each of the logical paths described. This parameter (STREAM_TYPE) is transmitted to each terminal in the form of a dynamic data structure that represents a logical control path that has at least one of the following fields:
- a first field (EMM_XID) to allow the terminal to identify the logical path described by the structure;
- a second field (Version_Number) to indicate to the terminal an evolution of the dynamic structure. This evolution signals to the terminal the transmission of new data in the way described so that the latter adapts its filtering to recover these new data;
- a third field (Listen_Time) to indicate to the terminal a listening period of the described path.
A logical path is a sub-part of a flow identified with a PID in the diffuse signal. The definition of these logical paths allows them to be multiplexed in the same flow in which the EMMs that pass through the same path have the same identifier EMM_XID. Thus, on reception, the terminal can filter incoming EMMs in a stream by selecting only EMMs from one or more particular channels. To do this, the terminal filters incoming EMMs by placing a mask at the head of the data stream.
In a particular embodiment, the size of the EMM_XID identifier is 8 bits, which allows multiplexing up to 8 EMM channels in a flow, assigning one bit to each channel.
To assign each type of EMM message at least one path among the defined logical transmission paths, the B-SAS 10 module has technical characteristics linked to the transmission models that allow it to determine the transmission path of an EMM. . The time offsets between the broadcast start date and end date are determined by each model. The defined logical paths are multiplexed in the same data stream and then transmitted to the terminals.
Adding EMM
During the request to add an EMM, the B-SAS 10 module performs the following treatments: ### Syntactic analysis of the request, ### Verification of the existence of the transmission model,
ES 2 287 486 T3 ### Verification of the consistency of the diffusion dates, ### Verification of the validity of the EMM identifier, ### Updating of the database, ### Orientation of the EMM towards block 22 management of waiting queues, ### Error management (equipment overload, ...), ### Confirmation of receipt of the request.
EMM replacement
Upstream SAS 16 or STB-MS equipment can request the replacement of an EMM in a cycle by specifying the identifier of the EMM to be replaced. This message will be used, for example, by the first SAS 16 team to increase the population expected by an EMM as part of a registration to a commercial offer.
During the request for an EMM replacement, the B-SAS 10 module performs the following treatments:
### Syntactic analysis of the request;
### verification of the existence of the transmission model;
### Verification of the consistency of the broadcast dates;
### Verification of the validity of the identifier of the EMM to be replaced;
### Verification of the validity of the identifier of the new EMM;
### Upgrade of data base;
### Orientation of the EMM towards the queue management block 22;
### Error management (equipment overload ...);
### Confirmation of receipt of the request.
EMM suppression
During the request for an EMM deletion, the B-SAS 10 module performs the following treatments:
### Syntactic analysis of the request;
### Verification of the validity of the EMM identifier;
### Upgrade of data base;
### Suppression of the diffusion of the EMM on the associated path;
### Error handling;
### Confirmation of receipt of the request.
Note that, even though only the B-SAS module 10 manages the EMM suppression at the end of the validity period, the SAS 16 or STB-Ms 18 equipment can explicitly suppress the broadcast of an EMM.
Managing queues
The B-SAS module 10 must make it possible to comply with the restrictions, particularly those of the terminals and at the same time, those of offering a regular quality of service. To this end, the second block 22 allows:
### organize fuzzy EMMs to allow the terminal to validate them;
### control the bandwidth of EMM channels in a transponder. Generally this bandwidth is of the order of 50 to 500 kbits / second.
### schedule the diffusion of certain EMMs expressed in very short periods of time;
ES 2 287 486 T3 ### schedule the broadcast of certain EMMs for a period of time long enough for them to be processed by all terminals.
### target non-emergency EMMs into message queues with different characteristics and organize these rows or logical paths so that the EMM bandwidth is acceptable to a terminal.
Description of the defined road types
In a preferred embodiment of the invention, the types of logical pathways defined comprise a FAST pathway, a DEDICATED pathway, a NORMAL pathway, a DEFERRED pathway and a BYPASS pathway.
The FAST path is used in the case in which it is certain that the terminal is listening to this path at the time of the diffusion of an EMM that concerns it. The most common use is the dissemination of specific entitlements for an interactive service that the terminal requests from a service provider. This route can also be used for a user's claim. EMMs are repeated on this fast track a number of times, with a time delay between each send, and then broadcast is suppressed. If the number of messages in the queue becomes too large, the path's cycle time period approaches the QoS limit.
The DEDICATED path transmits EMM whose characteristics are the same. Two types of EMMs are identified to form dedicated pathways: Renewal EMMs and Keyswitch EMMs.
Each dedicated lane is regulated independently of the other lanes, for the organization of broadcasting or to respect the bandwidth assigned to the lane. Only expressways can interrupt their operation.
The NORMAL route is obligatorily present and allows any EMM to be issued. This channel transmits the set of messages necessary for permanent use by the subscriber (security processor management, private data ...).
During operation, the terminal listens for this type of path for the period of time specified in the path descriptor or during a change in the path descriptor. This listening can be permanent.
The DEFERRED pathway is only periodically present in the flow. This channel allows EMMs to be issued that can accept a treatment with a time shift such as EMM for technical management of the security or information processor. The reading of this track by the terminal will promptly be caused by the change of the track version number.
The BYPASS path allows downloading of the other logical paths that have already been broadcast for several cycles and that have already been assessed by the terminal in a large number of cases. EMM broadcast modes are specified in the broadcast model. The terminal will listen to this track when the terminal starts up or when the version number of the track changes.
According to a preferred embodiment of implementation of the procedure, a control channel, also called channel 0, transmits an encrypted description EMM to the terminals, in which the technical characteristics of the logical channels that share the same one are described. PID. This description EMM is generated by the B-SAS module 10 based on the configuration parameters and the content to be transmitted on the tracks.
Upon receiving the description EMM, each terminal is placed on this path 0 to retrieve and analyze the descriptor to determine the logical paths to listen to and under what conditions. Each terminal will calculate the filter criteria based on the result of the descriptor analysis.
Broadcast EMMs must meet the following restrictions:
The diffusion period of the EMM must be valid.
- for an EMM broadcast on a FAST path the maximum amount of broadcast must not be reached;
- for an EMM transmitted on the other types of road, the broadcast date must be between the start date and the end date of the specified broadcast.
Scheduling the sending of EMMs allows the terminal to capture the entire EMM from the stream in a minimum of cycles.
To comply with this restriction, an algorithm called random diffusion organizes the sending of the EMMs by randomly programming the EMMs to be sent in a diffusion cycle.
The timing between two EMMs transmitted on the control path (channel 0) must be at least 100 ms.
ES 2 287 486 T3
Management of EMM dissemination
In the described embodiment, the definition of the broadcast resources and the management of the broadcast of the EMMs is in accordance with the EMMG / PDG protocol, part of the ETSI TS 103 197 "Head-End implementation of DVB Simulcrypt" standard . This protocol provides for the use of "Channel" and "streams", which are designated in the description below "channel" and "stream" respectively, to communicate with the multiplexing MUX module 12.
Channel and stream management
As schematically illustrated in figure 3, the communication between an EMM message generator 30 and the MUX module 12 is carried out through a channel 34 identified by a client_id identifier that identifies the conditional access system and that can be particular to each operator.
The B-SAS 4 module establishes a “channel” 32 per operator or per group of operators, which allows the creation of one or more “streams” 34 identified by the stream_id (Stream_id 1, Stream_id 2, ...) unique in the "Channel". A "stream" 34 is made up of a command path and a data path through which the EMMs pass in MPEG2 TS packets. The data path can be structured according to the TCP / IP or UDP / IP protocols in fuzzy mode.
Each "streams" 34 gives rise to the creation of a component 36 of the transponder identified with a PID packet identifier (by Packet Identifier) at the output of the MUX module 12.
According to a variant embodiment, by default, the B-SAS module 4 only creates one "stream" 34. A second "stream" 34 is created if the number of channels per operator exceeds 8 (maximum number of channels multiplexed in one same EMM stream). The EMM generator 30 and the MUX multiplexing module 12 negotiate the passband, at the initiative of the generator 30, for each stream 34.
EMM shipment management
The preparation of the EMMs for their diffusion towards the multiplexer 13 is carried out in two stages. The first stage consists of the encapsulation of the EMMs in the MPEG 2 section, the second stage consists of composing MPEG 2 TS transport packets to send to the MUX 12.
The MPEG sections obtained by encapsulation have at least the following private information:
- EMM_XID that represents the identifier of the EMM;
- LG_EMM representing the length of the EMM, and
- the content of the EMM.
The encapsulation rules are as follows:
### One and only one EMM per section, ### One or more sections chained by EMM.
The B-SAS module 10 composes MPEG2 TS packets of fixed size (188 bytes, including the header). Therefore, the MPEG2 sections are either inside the packet or distributed between two or more than two packets.
A TS packet respects the format schematically illustrated in figure 4 in accordance with the ISO / 1EC 13818-1 standard "Generic coding of moving pictures and associated audio information: Systems". This packet has a first Sync synchronization field 40 comprising eight bits, a header (ent) 42, a "ptr" pointer 44 and a block 46 comprising the useful data (DATA);
Header 42 comprises:
- a transport error indicator bit (transport_error_indicator);
- a bit indicating the start of a section in the packet (payload_unit_start_indicator);
- a bit indicating the transport priority (transport priority);
- a block of thirteen bits representing the PID identifier of the packet;
- two encoding control bits;
- two adaptation field control bits;
- two continuity index bits.
ES 2 287 486 T3
The payload_unit_start_indicator bit indicates whether to start a section in the packet. If this is the case, this bit is equal to 1 and the “prt” field is reassigned and indicates the range of the beginning of the section in the useful data 46.
If this is not the case, the payload_unit_start_indicator bit is zero and the "prt" field does not exist. This is the case of a section in more than two packages or a partially filled package.
Exchanges of the B_SAS 10 module with the other devices
The needs of the different clients requesting the equipment are expressed in the BSAS module 10 by means of a trigger event that can be a message that passes through the interfaces of the sending equipment / BSAS or the requests come from, for example, an operation manager.
SAS 16 First Team Needs
Sending an EMM
The first SAS equipment 16 communicates 10 EMM messages to the B_SAS module to broadcast them to a decoder
8. This communication is carried out by means of a request in which the first SAS equipment 16 specifies the EMM broadcast modes, particularly the transmission model to be used and the start and end dates of the transmission. The B_SAS module 10 constitutes and organizes the sending of EMMs in the logical paths specified by the transmission model and as a function of the diffusion dates on which time offsets can be applied.
Replacing an EMM
The SAS equipment 16 can be adapted to optimize the broadcast of the EMMs destined for the B_SAS module 10. In this case, the first SAS equipment 16 replaces a broadcast EMM with another EMM that specifies a more complete population. The first SAS equipment 16 requests the B_SAS module 10 to replace one EMM with another in the broadcast. Suppress sending an EMM
The first SAS equipment 16 can also request the B_SAS 10 to immediately delete an EMM, from the current broadcast.
Second equipment requirements STB-MS18
The STB-MS manages the terminal pool of one or more operators. As such, this team can perform, near the B_SAS 10, EMM Substitution or Submission Requests destined for Terminals and EMM Submission Suppression Requests.
Sending an EMM
The EMMs destined for the terminal are supplied to the B_SAS module 10 via a message from the STBMS / BSAS interface. This message and the associated treatment are the same as those of the first SAS 16 device.
Replacing an EMM
The STB-MS 18 device, like the first SAS 16 device, can be adapted to optimize the dissemination of its EMMs and uses for this purpose the same command as the first SAS 16 device. The STB-MS 18 device also allows SMS devices 2 define and maintain the characteristics of subscriber terminals.
Suppress sending an EMM
Similarly, the second STB-MS device 18 can request the SAS B module 10 to delete an EMM from the broadcast in progress.
Decoder needs
The terminal receives streams of EMMs issued by different B_SAS 10 modules. These EMMs are supplied by the different equipment connected to the B_SAS 10 module, namely the SAS 16 and the STB-MS 18 and are issued to the security processor , to one or more security processors or to one or more terminals.
Reception of the logical path descriptor
The terminal must be able to extract the management messages that concern it from the signal. To perform this function, the B_SAS module 10 transmits on the control channel, the descriptor and the diffusion modes of the different logical channels that make up the flow.
ES 2 287 486 T3
Reception of the EMMs issued by the B_SAS 10 module
The terminal must be able to extract from a logical path the set of management messages that concern it and if necessary reconstitute them in the case of EMMs divided into several sections. Furthermore, some components of the terminal, such as demultiplexers, impose broadcast restrictions particularly on the number of EMMs broadcast by the same security processor in defined periods of time.
The B_SAS module 10 validates these restrictions by applying an algorithm of random diffusion of the EMMs and complying with the MPEG section clipping restrictions.
Contents9
3 sheets
Sheet 1 Sheet 2 Sheet 3
19 members in 12 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 0201146 | France | A | |
| 0201146 | France | A | |
| 20020001146 | France | – | |
| 037347390201146 | – | – | – |
| FR20020001146 | – | – | – |
Members19
| Document | Office | Kind | |
|---|---|---|---|
| FR2835371A1 | France | A1 | |
| WO03065650A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003239027A1 | Australia | A1 | |
| WO03065650A3 | World Intellectual Property Organization (WIPO) | A3 | |
| FR2835371B1 | France | B1 | |
| EP1470690A2 | European Patent Office (EPO) | A2 | |
| KR20040090992A | Republic of Korea | A | |
| JP2005516536A | Japan | A | |
| US2005120197A1 | United States of America | A1 | |
| CN1625883A | China | A | |
| EP1470690B1 | European Patent Office (EPO) | B1 | |
| AT362267T | Austria | T | |
| ATE362267T1 | Austria | T1 | |
| DE60313739D1 | Germany | D1 | |
| DK1470690T3 | Denmark | T3 | |
| ES2287486T3This record | Spain | T3 | |
| JP4204477B2 | Japan | B2 | |
| US7614079B2 | United States of America | B2 | |
| CN1625883B | China | B |
Numbers
- Publication
- 2287486
- Publication, DOCDB
- 2287486
- Publication, EPODOC
- ES2287486T
- Application
- 3734739
- Application, DOCDB
- 03734739
- Application, EPODOC
- ES20030734739T
Titles2
- Spanish
- PROCEDIMIENTO Y DISPOSITIVO DE TRANSMISION DE MENSAJES DE GESTION DE TITULARIDAD.
- English
- PROCEDURE AND DEVICE FOR TRANSMISSION OF OWNERSHIP MANAGEMENT MESSAGES.
Classification
- CPC, 1
- H04L63/0428
- IPC, 5
- H04L12 22
- H04L29 06
- H04N7 16
- H04N21 266
- H04N21 418