Method and device for controlling access to encrypted data
Abstract
Method of control of access to data encoded by control words (CW), these control words being received by a security module in control message (ECM) and returned to a unit of exploitation (STB) of the encoded data, this comprising Method the following stages: - the reception of a first control message (ECM1) comprising at least one control word (CW) and a time stamp (TS), - the reception of a second control message (ECM2) consecutive to the first control message (ECM1), this second message comprising at least one control word (CW) and a time stamp (TS), - the determination of a duration corresponding to the difference between the time stamps (TS) of the two consecutive control messages (ECM1, ECM2); - if this duration is less than a predefined duration (CP), there is an increase in an error counter (CE), - if this duration is equal to or greater than said predefined duration, a decrease in said error counter occurs ( CE), - the forwarding of the control word (CW) to the operating unit (STB) after a waiting time depending on the value of the error counter (CE).

Term
Term ended
Projected expiry passed 6 July 2026, 0.2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
15 claims: 5 independent, 10 dependent
- 1ES 2 336 028 T3 ES 2 336 028 T3 CLAIMS REIVINDICACIONES 1. Access control method to data encoded by control words (CW), these control words being received by a control message security module (ECM) and returned to an operating unit (STB) of the encoded data, comprising this method the following steps:1. Método de control de acceso a datos codificados por palabras de control (CW), recibiéndose estas palabras de control por un módulo de seguridad en mensaje de control (ECM) y devolviéndose a una unidad de explotación (STB) de los datos codificados, comprendiendo este método las siguientes etapas: - la recepción de un primer mensaje de control (ECM1) que comprende por lo menos una palabra de control (CW) y una marca temporal (TS), - the reception of a first control message (ECM1) comprising at least one control word (CW) and a timestamp (TS), - la recepción de un segundo mensaje de control (ECM2) consecutivo al primer mensaje de control (ECM1), comprendiendo este segundo mensaje por lo menos una palabra de control (CW) y una marca temporal (TS), - the reception of a second control message (ECM2) consecutive to the first control message (ECM1), this second message comprising at least one control word (CW) and a time stamp (TS), - determining a duration corresponding to the difference between the timestamps (TS) of the two consecutive control messages (ECM1, ECM2);- la determinación de una duración correspondiente a la diferencia entre las marcas temporales (TS) de los dos mensajes de control consecutivos (ECM1, ECM2);- if this duration is less than a predefined duration (CP), there is an increase of an error counter (CE), - si esta duración es inferior a una duración predefinida (CP), se produce un aumento de un contador de errores (CE), - if this duration is equal to or greater than said predefined duration, there is a decrease in said error counter (CE), - si esta duración es igual o superior a dicha duración predefinida, se produce una disminución de dicho contador de errores (CE), - el reenvío de la palabra de control (CW) a la unidad de explotación (STB) después de un tiempo de espera dependiendo del valor del contador de errores (CE). - forwarding of the control word (CW) to the operating unit (STB) after a waiting time depending on the value of the error counter (CE).
- 6Access control method according to any of claims 1 to 5, characterized in that the first control message (ECM1) comprises a temporary value (TS), in that said second control message (ECM2) comprises a time value (TS) and by the fact that the duration that separates the two consecutive control messages corresponds to the difference between the timestamps (TS) of these two control messages. 6. Método de control de acceso según cualquiera de las reivindicaciones 1 a 5, caracterizado por el hecho de que el primer mensaje de control (ECM1) comprende un valor temporal (TS), por el hecho de que dicho segundo mensaje de control (ECM2) comprende un valor temporal (TS) y por el hecho de que la duración que separa los dos mensajes de control consecutivos corresponde a la diferencia entre las marcas temporales (TS) de estos dos mensajes de control.
- 7Access control method according to any of claims 1 to 5, characterized in that the security module and / or the operating unit contain a clock and by the fact that the duration separating the two consecutive control messages corresponds to the difference between the time of reception of said first control message (ECM1) and the time of reception of said second control message (ECM2), these times being determined by the clock. 7. Método de control de acceso según cualquiera de las reivindicaciones 1 a 5, caracterizado por el hecho de que el módulo de seguridad y/o la unidad de explotación contienen un reloj y por el hecho de que la duración que separa los dos mensajes de control consecutivos corresponde a la diferencia entre el instante de recepción de dicho primer mensaje de control (ECM1) y el instante de recepción de dicho segundo mensaje de control (ECM2), quedando determinados estos instantes por el reloj.
- 11Método de control de acceso según las reivindicaciones 9 y 10, caracterizado por el hecho de que la regla predefinida para el aumento del valor del contador de errores (CE) y aquella para la disminución de este contador de errores (CE) son diferentes entre ellas. eleven. Access control method according to claims 9 and 10, characterized in that the predefined rule for increasing the value of the error counter (CE) and that for decreasing this error counter (CE) are different from each other. .
- 15Dispositivo de control de acceso a datos codificados por palabras de control (CW), recibiéndose estas palabras de control por un módulo de seguridad en mensajes de control (ECM) y devolviéndolas a una unidad de explotación (STB) de los datos codificados, comprendiendo este dispositivo:fifteen. Access control device to data encoded by control words (CW), these control words being received by a security module in control messages (ECM) and returning them to an operating unit (STB) of the encoded data, comprising this device: - means for receiving a first control message (ECM1) comprising at least one control word (CW), - medios de recepción de un primer mensaje de control (ECM1) que comprende por lo menos una palabra de control (CW), - means for receiving a second control message (ECM2) consecutive to the first control message (ECM1), this second message comprising at least one control word (CW), - medios de recepción de un segundo mensaje de control (ECM2) consecutivo al primer mensaje de control (ECM1), comprendiendo este segundo mensaje por lo menos una palabra de control (CW), - means for determining a duration separating the two consecutive control messages (ECM1, ECM2), - medios para determinar una duración que separa los dos mensajes de control consecutivos (ECM1, ECM2), - means of incrementing an error counter (CE) if this duration is less than a predefined time (CP), Y - medios para aumentar un contador de errores (CE) si esta duración es inferior a un tiempo predefinido (CP), y - means to decrease the error counter (CE) if this duration is equal to or greater than the aforementioned predefined duration. - medios para disminuir el contador de errores (CE) si esta duración es igual o superior a la citada duración predefinida. - and means for forwarding the control word (CW) to the operating unit (STB) after a waiting time that depends on the value of the error counter (CE). - y medios para reenviar la palabra de control (CW) a la unidad de explotación (STB) después de un tiempo de espera que depende del valor del contador de errores (CE).
Independent claims5
118 paragraphs in 9 sections, as filed
ES 2 336 028 T3
DESCRIPTION
Encrypted data access control method and device.
Technical field
The present invention relates to a method and device for controlling access to data encoded by control words, these control words being received by a security module in control messages and returned to a unit for operating the encoded data.
The present method like the device applies in particular to the case of pay television.
Previous technique
In a well-known manner, and particularly in the field noted above of pay television, data is encoded by a data provider using encoding keys called control words. These data are transmitted to multimedia units of users or subscribers. In parallel to this, the control words are transmitted to these multimedia units in the form of a control message flow.
Multimedia units in general are made up of an operating unit which, in the case of pay television, is a decoder that receives the streams mentioned above, and a security module in charge of cryptographic operations related to the use of these. flows.
As is known to the person skilled in the art, such a security module can be made essentially in four different ways. One of them is a microprocessor card, a chip card or more generally an electronic module (which can be in the form of a key, a “badge”, etc.). Such a module is generally removable and connectable to the decoder. The form with electrical contacts is the most used, but it does not exclude a contactless link, for example of the ISO 14443 type.
A second known form is that of an integrated circuit box placed, generally permanently and immovably, in the box of the decoder. A variant is constituted by a circuit mounted on a socket or connector such as a SIM module connector.
In a third form, the security module is integrated into an integrated circuit box that also has another function, for example in an anti-interference module of the decoder or the decoder microprocessor.
In a fourth embodiment, the security module is not realized in material form but its function is applied solely in software. Considering that in all four cases, although the level of security differs, the function is identical, we will talk about the security module whatever the way it performs its function or the form that this module may assume.
When a multimedia unit has received the stream containing the control words, it is first checked whether the user has the rights to decode the specific data. If this is the case, the control messages are decoded to extract the control words therefrom. These control words, in turn, are used to decode the data.
Also in a known manner, each control word makes it possible in general terms to decode a small part of the transmitted data. Typically, a control word allows decoding ten seconds of a so-called pay television event. After this duration, called the cryptoperiod, the control word is changed for security reasons.
One possible way to benefit from access to encrypted data without being authorized to do so is to use a true multimedia unit with a true security module, and distribute the control words to a set of decoders. This can be done by means of a server or splitter device known as a "splitter". Thus, the amounts associated with the acquisition of access rights to encrypted data are paid for a single multimedia unit, while the events can be accessible from several multimedia units.
European patent application EP 1 575 293 describes a method intended to prevent the same security module from being shared by several users. For the practical application of this method, the security module has a memory for memorizing command message sequences. The security module also has means for analyzing an abnormal sequence of command messages, means that act by comparing the memorized command messages. When an abnormal sequence is discovered, an error counter is incremented. A delay in the treatment of the control words is introduced as a function of the value of the error counter.
ES 2 336 028 T3
In the method described in this patent application, abnormal behavior is defined on the basis of an analysis of the channels used. By way of example, it is pointed out that when the channel identifier is alternately A and then B, the analysis means are considered to be an abnormal sequence corresponding to a shared phenomenon of the security module. The error counter is then increased. On the other hand, when the channel identifier is A for several cryptoperiods, and then it goes to B for several other cryptoperiods, this will not be considered as abnormal behavior and thus the error counter will not be increased.
The invention described in patent application US 2004/0215691 seeks to prevent such fraudulent use. To achieve this purpose, each time a control message is received by a multimedia unit, this unit or the security module that is associated with it determines to which channel this control message is connected. The channel identifiers are memorized with temporary information. The messages are compared to determine if they are linked to different channels or to the same channel. If they are linked to different channels, a counter with a certain value is increased. When the control messages are linked to the same channel, the counter is decremented or decremented. When the counter reaches a previously defined limit value, this means that numerous changes are made in the channels and thus the decoding of the control words stops.
The two procedures described in document EP 1 575 293 and US 2004/0215691 imply that it is necessary to have an identifier of the channel in question available for each control message. In certain configurations, this is not the case. Using control messages as defined in particular in the Eurocrypt standard No. EN 50094 of December 1992, it is possible to identify, not so much each channel but a class of channels. In this case, it is not possible, with the invention described above, to block the use of several multimedia units that use a single security module and a separator device.
The document called "Countermeasures for Attacks on satellite TV cards using open receivers" XP-002333719 by Francis et al. Describes in a general way, different means to avoid a fraudulent use of security modules. According to a particular aspect, this document suggests verifying that the timestamp of a message is located in the future relative to the timestamp of a previously received message. However, this document does not mention any concrete solutions. In particular, there is no information that allows a distinction to be made between an illegal use of a security module for several users and a change of legal channel by a single user.
Description of the invention
The present invention aims to carry out an alternative solution to that corresponding to the prior art in which it overcomes the aspect of using a channel identifier while registering, however, the use of a separator device that allows several decoders to access a content encoded from of a single security module. Also, according to this solution, an identifier of the channel in question is not necessary so that this solution works equally in the case where the control messages do not contain such a channel identifier but for example the channels are grouped by class.
The object of the invention is achieved by means of an access control method to coded data by means of control words, these control words being received by a security module within control messages and returned to a unit for operating the coded data, comprising this method the following stages:
- the reception of a first control message comprising at least one control word and a time stamp,
- the reception of a second control message consecutive to the first control message, this second message comprising at least one control word and a time stamp,
- determining a duration corresponding to the difference between the timestamps of the two consecutive control messages;
- if this duration is less than a predefined time, an error counter is increased,
- when this duration is equal to or greater than said predefined duration, there is a decrease in the error counter,
The object of the invention is also achieved by means of a control device for accessing data encoded by control words, these control words being received by a security module in control messages and they are returned to an encoded data operating unit. , comprising this device:
- means for receiving a first control message comprising at least one control word,
- means for receiving a second control message consecutive to the first control message, this second message comprising at least one control word,
- means for determining a duration separating the two consecutive control messages,
ES 2 336 028 T3
- means of increasing an error counter if this duration is less than a predefined time,
- and means to decrease the error counter when this duration is equal to or greater than the aforementioned predefined time,
- and means for sending the control word (CW) to the operating unit (STB) after a waiting time depending on the value of the error counter (CE).
In a general way, the method and the device according to the present invention make it possible to determine, in accordance with temporary information linked to the control messages sent by a management center, whether these control messages are sent and are processed according to a use. conventional or fraudulent. The error counter enables action to be taken in the event that abnormal utilization is detected. These measures can be of different natures, such as the momentary interruption of a service, the deceleration of the sending of the control words or even the blocking of the security module in which case the unlocking can be carried out either automatically or on request by means of a telephone service. In the case of conventional use, the user does not perceive any change due to the use of this method. Conventional use also means access to encoded content on a given channel as a channel change (zapping) at a "reasonable" rate and time. On the other hand, in the case of fraudulent use of a separator device that feeds several decoders from a single security module, access to the encrypted content quickly becomes impossible. When the use is correct again, access to the data can once again be authorized.
Summary description of the drawings
The present invention and its advantages will be better understood by referring to the attached figures and the detailed description of a particular embodiment presented as a non-limiting example, in which:
figure 1 illustrates an example of the structure of a control message as used in the present invention;
figure 2 illustrates a configuration in which two decoders are used with a single security module and a separator device;
figure 3 schematically represents an embodiment of the decoding method according to the present invention;
- figure 4 illustrates the reception of ECM control messages as a function of time, and
- figure 5 represents a value of an error counter as a function of time and of the control messages received as illustrated in figure 4,
- Figure 6 illustrates a variant of the invention in which different crypto periods are used on different channels.
Ways of carrying out the invention
Figure 1 schematically illustrates the content and structure of an ECM control message as used in the present invention. This ECM control message contains fields in which there is in particular a TS time stamp that represents a date and time, the duration of the CP cryptoperiod, conditions for CA access to an audio content / video as well as two control words CW1, CW2, of different parities. The control message can also carry other fields not described in detail here. The data contained in the fields of the control message is generally encoded by a transmission key TK. In addition, this message can carry one or more headers that are not necessarily encoded. In particular, such a message comprises a header H which allows the multimedia unit to identify it as a control message ECM and which must not be encoded. It should be noted that the cryptoperiod is not necessarily contained within such a control message. Indeed, if the cryptoperiods of the different channels are identical and remain constant for a certain time, a cryptoperiod can be sent within an EMM management message.
According to a first embodiment, the present invention works in the following general manner. In conventional way, a control message ECM is sent to a multimedia unit comprising a decoder STB and a security module SC. Upon receipt of this control message, the CA access conditions required to access a certain content, hereinafter referred to as audio / video content, are extracted from this control message by the security module. The security module then checks if it has the rights to return the control word. If this is not the case, it does not return the control word. When decoding rights are present, the control word is transmitted to the decoder.
The value of the cryptoperiod CP is also extracted from the control message or is determined in another way. This CP value is stored in a memory connected to the security module. The appropriate control word is sent back to the decoder, generally in a form encoded by a transfer key. The transfer key is generally derived from a pair of asymmetric keys of which one is stored in the security module and the other is stored in the decoder. The keys of this pair are called pairing keys and in
ES 2 336 028 T3 principle are unique and different for each multimedia unit. The encoded content can then be decoded by this control word and applied to a user's screen. The pairing mechanism is described in detail in the European patent published under number EP 1 078 524.
When a subsequent control message is received by the multimedia unit, it is decoded in such a way that, among other things, the time stamp TS can be extracted from it.
This time stamp is compared with the time stamp memorized during the processing of the previous control message. The difference between these two time stamps is compared with the cryptoperiod also memorized during the processing of the previous control message. When this difference is less than the value of the cryptoperiod, which means that the multimedia unit has received more than one message per cryptoperiod, a value is increased within a counter. This counter, called CE error counters in the rest of this description, is located in principle within the security module. This counter is increased in this way when the security module is called to return the control words according to a frequency higher than the cryptoperiod, either due to a change in the user channel, or because of the additional operation of a multimedia drive in the same security module.
Figure 2 represents a configuration against which the present invention tries to fight. In this configuration there are two data exploitation devices or two decoders STB1, STB2 that are supplied with control words by a single safety module and a separator device. In this configuration, when one of the decoders receives a control message ECM, it transmits it to the separator device SP, which in turn sends it to the security module SC. The latter decodes it if it is authorized to do so and then transmits the control word to one or the other of the STB1 or STB2 decoders by means of the separator device SP.
In this figure 2 only two decoders are represented. In practice, it is possible that a greater number of decoders with control words are supplied by a single security module and a separator device.
It should be noted that the procedure only controls durations linked to the ECM control messages. If other types of messages, such as EMM management messages, are sent between two control messages, these other types of messages are not taken into account and do not interrupt the operation of the procedure.
Using the error counter data
A particular embodiment is described below, with reference to Figure 3. In this embodiment, the value of the error counter CE is used to introduce a delay in the sending of the CW control words extracted from the control messages. ECM control. In the example of this figure 3 it is assumed as a hypothesis that the crypto period is 10 seconds. Upon receipt of a first control message ECM1, it is processed in such a way that the control words it contains, identified respectively, CW1 (C1) and CW2 (C1) are extracted. It should be noted that in the figure, the upper part corresponds to channel C1 and the lower part corresponds to channel C2. In order not to overload this figure, the control word CW1 (C1) corresponding to channel C1 is simply identified as CW1. Similarly, control word CW1 (C2) corresponds to channel C2 and CW1 is also identified in the figure. Due to their location in the figure, the distinction between these two control words is evident. In the description, the channel identifier is indicated in parentheses.
The processing of the control message ECM1 generally takes a few tens of milliseconds. While one of the control words, for example the control word CW1 (C1) is used, the other control word CW2 (C1), contained in the same control message ECM1, is memorized. The control message corresponding to the same channel will generally contain the control word memorized during the processing of the previous message as well as an additional control word that is intended to be used during the next cryptoperiod. In this way each control word is sent twice. This way of operating has the advantage that control words other than those received immediately after a channel change are memorized before use so that they are immediately available when necessary.
The error counter CE introduces a delay in sending the control words from the security module to the decoder. This means that instead of processing an ECM control message and resending the control words since they have been extracted, their sending to the decoder is delayed for a time that depends on the value stored in this counter.
Figure 3 represents an example in which a separation device (in English "splitter") is used illegally between the security module and two decoders STB1 and STB2. In the simplest case in which the crypto periods are identical and the users do not change channels, with the configuration described above, two control messages are received during each crypto period. Thus, as in each cryptoperiod, the value of the error counter CE will be increased. This increase can be carried out according to the values defined above, for example of two units. As an example, let's imagine that one introduces a delay in the treatment of control messages of one second per unit of the error counter from the moment this value exceeds a limit of 10. When the counter has not yet reached this limit of 10 or when it is equal to 10, no delay is introduced.
ES 2 336 028 T3
When the initial value of the counter is zero (CE = 0), upon receipt of a first control message ECM1, the value of the cryptoperiod CP will be memorized, for example 10 seconds. Control words CW1 (C1) and CW2 (C1) are decoded. The control word CW1 (C1) is used to decode an audio / video content and the control word CW2 (C1) is stored for later use. The time stamp TS = T0 is extracted from the control message and is memorized. When the control message according to ECM2 is received by the multimedia unit, the latter extracts the time stamp T1. The second control message ECM2 is processed in such a way that the control words are extracted, to use the first one CW1 (C2) and memorize the other CW2 (C2). Then the difference between T0 and T1 is calculated and, for example, 6 seconds is obtained.
This value is compared with the memorized CP cryptoperiod, which in our example is 10 seconds. Considering that the difference of the time stamps T1-T0 is less than the cryptoperiod CP, the mark of the error counter CE is increased, in our example, by 2 units. This mark is therefore equal to 2.
Upon receipt of the control message according to ECM3, corresponding to the first channel C1, the mark of the error counter CE is verified. Since this mark is equal to 2 and therefore is less than the limit value of 10 defined above, no delay is introduced. The security module handles the message by first extracting the timestamp TS = T2. Since the crypto period is 10 seconds, it follows that T2-T0 = 10. Since T1-T0 = 6 in this example, T2-T1 = 4 seconds. Since this value is less than the cryptoperiod, the value of the error counter is increased by two units to go to 4. The control words CW2 (C1) and CW3 (C1) are extracted from the message. During this time, the audio / video content is decoded using the control word CW2 (C1) from the previous control message.
Upon receipt of the control message ECM4, the security module treats the message equally and returns the control words without introducing any delay. During this time the STB2 decoder uses the control word CW2 (C2) from the previous message to decode the audio / video content.
The difference between the timestamp of this message and the previous one is 6 seconds, therefore it is less than the crypto period. The value of the error counter CE is increased by two units and therefore equals 6. The control words CW2 (C2) and CW3 (C2) are extracted from the message. When the audio / video content has to use the control word CW3 (C2) in order to be decoded, this control word will be available since it has been decoded in the previously received control message ECM4.
The multimedia unit will then receive a fifth control message ECM5, which contains the control words CW3 (C1) and CW4 (C1). During that time the control word CW3 (C1) can be decoded to access the audio / video content, due to the fact that this control word has already been sent within the previous control message ECM3. As the difference between the time stamp of the ECM4 control message and the ECM5 message is less than the cryptoperiod, the error counter is increased by 2 units and goes to 8.
In a similar way the following control message ECM6 contains the control words CW3 (C2) and CW4 (C2) that can be used for decoding the audio / video content. The timestamp contained in this message implies that the error counter is increased from two units to 10.
The following ECM7 control message contains the control words CW4 (C1) and CW5 (C1). Since the error counter contains the value 10 which is equal to the limit value, but not higher than it, the ECM7 message is handled in such a way that the control words are forwarded immediately. This means that the CW5 control word (C1) will be available whenever it is needed for audio / video content. The error counter will be increased again by two units to reach 12, that is, beyond the limit value.
The next control message ECM8 contains the control words CW4 (C2) and CW5 (C2). This message is dealt with immediately but the control words it contains will only be sent after a waiting time of 12 seconds. This means that with a crypto period of 10 seconds, the control words are sent 2 seconds after the end of the crypto period. During these 2 seconds, the control word that is required to access the audio / video content is the CW5 (C2) word. However, this control word is not accessible before it has been sent to the decoder. As a result, during these 2 seconds, the audio / video content is not accessible. This can be translated on the user's screen by a blurry image or a uniformly black or white screen, for example.
Thus the procedure continues adding 2 units to the error counter and therefore two seconds to the sending time of the control words. In this way, during the processing of the following control message ECM9, the audio / video content will not be accessible for 4 seconds. For consecutive messages ECM10, ECM11 and ECM12, the time during which access to the audio / video content is not possible is respectively 6 seconds, 8 seconds and 10 seconds. As can be easily seen, since the delay is equal to twice the fifth period, the content is no longer accessible.
The timestamp TS as described above can have a "resolution" of the order of one second or up to a few seconds, for example 4 seconds in practice. This means that the difference between two timestamp values will also be expressed in seconds and not in fraction of seconds.
ES 2 336 028 T3
Note that the example described above uses a time given by the timestamps. When the multimedia unit, that is to say the security module and / or the decoder contains a clock, it is obviously possible to calculate the difference between two times provided by the clock and no longer between two temporary values. In both cases, on the other hand, the principle of the invention remains the same.
Using a buffer
The system as described above has a limitation in the case where a buffer memory is used to memorize the audio / video content, to thus compensate for the delay induced by the security module and thus render it inoperative.
One of the ways to make this memorization useless or at least ineffective, consists of not setting a higher limit to the delay induced by the error counter or setting a very high limit. In this way, in view of the fact that the error counter increases by two during each non-compliant control message, it will reach a value greater than twice the cryptoperiod at almost all times or even more in order to overcome the lag introduced by the buffer memory. . From that moment on, the entire audio / video content is no longer accessible. This, on the other hand, can present a drawback. Indeed, when the error counter has reached a significant value, it is necessary to wait for a considerable duration after stopping the separating device, in order to decrease the error counter sufficiently for the system to function correctly again.
Another way to make this memorization ineffective is not to resend the control words that, taking the delay into account, should be sent during a period during which the content is no longer decoded by the control words, supposedly sent by the control module. security. By way of example it is noted that the control message referenced by ECM8 in FIG. 2 contains the control words CW4 (2) and CW5 (C2). With an error counter value of 12, these control words should be forwarded at the end of the cryptoperiod. In this case, these control words are not simply forwarded. The control word CW4 (C2) is contained in the ECM6 message, therefore the audio / video content can be decoded until the end of the cryptoperiod, using these control words. From the next change, the content will no longer be accessible. The error counter, on the other hand, continues to be increased since the frequency of sending the control messages has not been modified.
Counter decrease
In the unauthorized mode of use, described above, it is evident that when two users have access to the same security module to decode the data, such data will quickly become inaccessible. If one of the users stops the process of accessing the security module, it can be foreseen that the "legal" user can have access to this content again. For this, the proposed solution does not consist in decreasing the error counter according to the pre-established rules.
Figures 4 and 5 schematically illustrate the decrease in the error counter as well as its increase as a function of the cryptoperiod CP and the difference between the time stamps of two successive ECM control messages. According to a possible rule, every time an ECM control message is received correctly, that is, when the difference between the timestamp of a given message and the previous message is equal to the cryptoperiod, the error counter is decreased by one unit. .
By way of illustration, Figure 4 represents ECM control messages received over time while Figure 5 illustrates the value of the error counter CE also as a function of time.
Note that in this example, the initial value of the error counter is not zero but has been set to two. Considering that no delay is introduced for so long so that the limit value has not been exceeded, this initial value not equal to zero does not have a negative effect on decoding. On the other hand, it will have the effect that in case of fraudulent use, the limit value from which a delay is introduced, is reached more quickly.
The forwarding of the control words contained in the first control message is not delayed as the limit value is not reached. The first control word allows access to audio / video content. The second control word is memorized by the decoder. At the end of the crypto period, a new ECM2 control message is received for the multimedia unit. Comparing the timestamp of the two messages with the cryptoperiod of the first control message ECM1, it turns out that the cryptoperiod is equal to the difference between the two timestamps contained in the control messages. At this time the value of the error counter CE is decreased according to the predefined rule, here, by one unit. Therefore it has the value of 1.
When the next control message is received by the multimedia unit, the error counter mark is checked. This is equal to 1. Therefore no delay is applied. During this time, the previously memorized control word from the control message is used to access the audio / video content. The counter value decreases according to the established rule to now adopt a zero value.
ES 2 336 028 T3
In the illustrated example, the multimedia unit receives a new control message ECM4 whose difference between the time stamp of this message and the previous message is less than the cryptoperiod. At this time the counter value is increased by two units to go to two. This increase can occur for two different reasons. According to a first reason, the user changes the channel ("zapping"). According to the other, a "splitter" device is used. As already explained with reference to figure 3, the value of the counter increases, for example two by two.
In the example of Figures 4 and 5, the difference between the timestamps of two consecutive ECM control messages is less than the cryptoperiod up to the control message bearing the reference ECM8. The value of the error counter increases two by two until reaching the value 12. As indicated with reference to figure 3, when this value of the counter CE exceeds 10, a delay is introduced in the sending of the control words. Thus the user will not have access to all the audio / video content. In Figures 4 and 5, during the reception of the control messages ECM9 to ECM12, the difference between the timestamps is equal to the cryptoperiod and the value of the error counter CE is therefore decreased by 1, in each message. From the moment this counter value goes to 10, the treatment delay is canceled and the entire audio / video content will be accessible to the user.
Figure 6 illustrates a particular embodiment of the invention according to which the crypto periods are different from one channel to another. In this figure, it is also assumed that the device according to the invention is used fraudulently to feed two decoders from a single security module and that it also appears that each channel does not receive more than a single control message between two . This use of a control message between two is possible due to the fact that each of these messages contains two control words. Also, even in this case, all the control words for the two channels are available.
By way of example, the cryptoperiod of channel 1, depicted at the top of Figure 6, is assumed to be 7 seconds. The crypto period for channel 2, represented at the bottom of the figure, is 5 seconds. Let us consider the case in which the first control messages of each channel C1 and C2 are received simultaneously. The first control message ECM1 (C1) of channel 1 contains an indication according to which the crypto period is 7 seconds. This message contains the control words CW1 (C1) and CW2 (C1).
The first channel 2 control message contains a cryptoperiod value of 5 seconds as well as the control words CW1 (C2) and CW2 (C2).
In the example shown in this figure 6, the following control messages for each channel are not used. The next message to be used is the ECM2 (C2) reference control message. This message is received two cryptoperiods after the first ECM1 (C2) message, so it is considered valid. The value of the error counter is therefore kept at zero or possibly decreased.
The following example received by the security module has the reference ECM2 (C1). Two cryptoperiods are received after the first ECM1 (C1) message, that is, after 14 seconds in our example. This means that it is also received 4 seconds after the ECM2 (C2) message corresponding to the C2 channel. This 4-second value is less than the continued cryptoperiod in the previous control message. Therefore the value of the error counter is increased by two units when the same rule is applied as in the previous example. Therefore this value of the error counter CE is equal to 2.
The next message will be received after 4 cryptoperiods of the C2 channel, that is (4x5) - (2x7) = 6 seconds after the last message received ECM2 (C1). As this message contained the value 7 seconds for the cryptoperiod, the ECM3 (C2) message is considered incorrect and the value of the error counter is increased by 2. Therefore it reaches the value of 4.
The following ECM3 message (C1) is received after (4x7) - (4x5) = 8 seconds. The previous message contained the value of the cryptoperiod corresponding to that of the C2 channel, namely 5 seconds. The duration of 8 seconds between the previous message is greater than this value of 5 seconds. Therefore the message is considered correct. This decreases the value of the CE error counter by one unit. By continuing the procedure in the manner described above, it can be shown that the error counter will be alternately increased and then decreased. Since the increase is made by jumps of two units and the reduction is made by jumps of one unit, this counter value will increase in the case of fraudulent use as shown in figure 6. This counter will take the values 0, 2, 4, 3, 5, 4, 6, 5,7, ... until it exceeds the limit value from which a delay is generated in the sending of the control words.
It should be noted that the case in which users decode only one control message between two, as described with reference to figure 6, represents the worst case in terms of discovery of fraudulent use. It can be easily seen that in the case where fraudulent users decode all ECM control messages, the value of the error counter will increase faster if the sending of the control words by the security module were delayed equally faster.
ES 2 336 028 T3
Security module and paired decoders
The continuation of the description applies more particularly if it comes exclusively to the case in which the security module and the decoder that form a multimedia unit are paired. In this case they each contain a key and an asymmetric key pair. This pair is unique and different for each security module / decoder assembly. In this configuration, when a multimedia unit is started, a generally symmetric session key is negotiated between the security module and the decoder. This session key is used to encode the CW control words that have been decoded by the security module, before sending them to the decoder. The use of such a session key poses a problem for fraudulent users who exploit a separation device. Indeed, as the session key between the security module and decoder 1 pair is different from the session key between the security module and decoder 2 pair, it is necessary to negotiate a session key for each reception of a message from ECM control on a different channel. In the case illustrated by figure 3, in which the control messages are received alternately on a C1 channel and another C2 channel, according to certain configurations of multimedia units, a session key must be negotiated between each reception of the control message ECM .
To generate the negotiation of such a session key, the security module must be restarted. This is done by sending a reset command to the multimedia drive. Such a command can therefore be sent between each ECM control message. In this case, it is important that the value of the error counter CE is not reset. It is also convenient that this counter value is increased in the event of a reset corresponding to fraudulent use.
To do this, the security module memorizes in a volatile memory, the most recent date that has been received. This date is sent for example by a management center in the form of a control message. Upon receipt of a reset command, this date is memorized in a non-volatile memory.
Parallel to this, as already indicated, the ECM control messages contain a TS timestamp. The multimedia unit or more precisely the security module also memorizes a duration called "latency time" which in principle is greater than or equal to a cryptoperiod.
Upon receipt of each ECM control message, the security module calculates the difference between the TS time stamp of this ECM message and the most recent date received before the last reset, previously stored in non-volatile memory. If this difference is greater than the latency time, the error counter can be set to zero or to a value for which there is no delay in sending the control words. If this difference is less than the delay time, this means that the security module has decoded a control message shortly before zeroing, which may correspond to a configuration in which a separator device is used. The error counter is increased according to a predefined rule, for example 3 units.
According to a first embodiment, from the moment a control message has been processed "a short time" before the resetting or the last memorized date, that is to say for a duration less than the latency time, a delay is introduced . This prevents storing the error counter value in non-volatile memory. On the other hand, in the case of a “legal” reset for technical reasons, the honored user must wait for the delay to elapse before being able to access the audio / video content. If you also change channels during this time, the counter value will increase.
According to another embodiment, the value of the error counter is stored in such a way that a reset command does not cause a reset of the error counter. On the contrary, this value is preserved as before the zeroing. In this way, a reset command between each ECM control message will quickly have the effect of hampering access to audio / video content. In contrast, an occasional reset will not prevent access to the audio / video content for more than a sufficient number of control messages have been handled correctly between two consecutive zeroes. To prevent any cumulative effect under normal circumstances, when the time between the first treatment of a control message (after resetting) and the time of the last treatment before resetting is long enough (for example several hours) the error counter will be reset. The time required for the counter to be reset can be defined in advance and is called idle time.
It should be noted that there are so-called multi-session security modules that are capable of memorizing several session keys. In the cases of normal use, each session key is provided for dialogue with a multimedia unit, or even with a subset of decoding of the content that would be placed on the same device.
During access to the security module by any of the decoding sets, the latter will add an identification reference. The security module will treat this message in an environment specific to this set and that includes the session keys (if a pairing is active) and the other identification data (rights, credit) as well as the data that allows the detection of a use. fraudulent as described above. These are in particular the error counter, the time stamp of the last treatment of a control message and the value of the cryptoperiod.
ES 2 336 028 T3
In this way, the same security module will be able to handle several decoding sets, always verifying that the total number of decoders associated with this module does not exceed the limit set. This limit can be programmed according to the user's profile.
Increase / decrease at different speeds
In the examples indicated, the counter value is increased faster than when it is decreased. For example, it increases by two units when the difference between the timestamp of two successive control messages is less than the cryptoperiod. It increases by 3 units for each reset considered incorrect while it does not decrease more than one unit for each correct reception. This makes it possible to avoid particular cases in which, by playing with the resets and the correct handling of the control messages, it is possible to keep the value of the error counter in an interval in which access to the audio / video content is always or it is practically always possible by fraudulent users.
According to another variant, it is possible to foresee that the decrease will take place more quickly than the increase.
Delay duration in stages
As indicated above, in general terms the introduction of a delay has been foreseen while the value of the error counter reaches a certain limit. Beyond this limit, it can be proportional to the delay to the content of the counter or it can be increased in stages, or it can be fixed. In general, this delay is intended to prevent access to part of the audio / video content during a certain period of fraudulent use, and then to the entire audio / video content after further fraudulent use.
In the examples described above, it is indicated that the duration of the cryptoperiod of a control message is extracted as well as its time stamp and that it is then verified during the reception of the next message if the difference between the time stamp of this message and the previous one is equal to or less than the crypto period. This implies that the cryptoperiod and the timestamp of the first message must be memorized.
According to a variant, it is possible to calculate the difference between the timestamps of two consecutive control messages ECM1 and ECM2 and verify whether this difference is less than or equal to the cryptoperiod extracted from the second received message ECM2. This has the advantage that it does not require the memorization of the cryptoperiod and therefore allows memory savings.
In the examples described, and the value of the error counter can be between zero and a limit value, for example 10 or it can also be higher than this limit value. Between zero and the limit there is no delay. Beyond the limit a delay is introduced. It is evident that it is possible to limit the maximum value of the counter, which also makes it possible to limit the number of consecutive correct messages to be decoded in order to be able to go back to a value below the limit.
According to a variant, it is possible to reverse the direction of the counter, which means that with each correct decoding, the counter is increased while it is decreased during fraudulent decoding. In this case, a delay is introduced when the counter contains a value between zero and a limit, while no delay is introduced if the counter value is beyond this limit.
The examples described mention the use of two decoders for a security module. Obviously it is possible, for fraudulent use, to connect more than two decoders to a security module by means of a separator device. According to the method of the invention, this will have the effect of blocking access to the audio / video content even more quickly and then the error counter will be increased even faster.
References cited in description
This list of references cited by the applicant has been compiled exclusively for the information of the reader. It is not part of the European patent document. It has been made with the greatest diligence; However, the EPO does not assume any responsibility for eventual errors or omissions.
Patent documents cited in description
EP 1575293 A [0012] [0015]
US 20040215691 A [0014] [0015]
EP 1078524 A [0024]
Contents9
3 sheets
Sheet 1 Sheet 2 Sheet 3
30 members in 19 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 05106185 | European Patent Office (EPO) | A | |
| 05106185 | European Patent Office (EPO) | A | |
| 0677763005106185 | – | – | – |
| EP20050106185 | – | – | – |
Members30
| Document | Office | Kind | |
|---|---|---|---|
| EP1742474A1 | European Patent Office (EPO) | A1 | |
| AU2006268683A1 | Australia | A1 | |
| CA2614107A1 | Canada | A1 | |
| WO2007006735A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20080024520A | Republic of Korea | A | |
| EP1900211A1 | European Patent Office (EPO) | A1 | |
| IL188334A0 | Israel | A0 | |
| MX2008000004A | Mexico | A | |
| CN101218822A | China | A | |
| HK1111022A | Hong Kong, China | A | |
| HK1111022A1 | Hong Kong, China | A1 | |
| US2008209232A1 | United States of America | A1 | |
| JP2008545307A | Japan | A | |
| RU2007148552A | Russian Federation | A | |
| ZA200800078B | South Africa | B | |
| EP1900211B1 | European Patent Office (EPO) | B1 | |
| AT449510T | Austria | T | |
| ATE449510T1 | Austria | T1 | |
| DE602006010554D1 | Germany | D1 | |
| PT1900211E | Portugal | E | |
| ES2336028T3This record | Spain | T3 | |
| PL1900211T3 | Poland | T3 | |
| AU2006268683B2 | Australia | B2 | |
| CN101218822B | China | B | |
| RU2409002C2 | Russian Federation | C2 | |
| US7908491B2 | United States of America | B2 | |
| IL188334A | Israel | A | |
| KR101280640B1 | Republic of Korea | B1 | |
| CA2614107C | Canada | C | |
| BRPI0615532A2 | Brazil | A2 |
Numbers
- Publication, DOCDB
- 2336028
- Publication, EPODOC
- ES2336028T
- Application
- 6777630
- Application, DOCDB
- 06777630
- Application, EPODOC
- ES20060777630T
Titles2
- English
- METHOD AND DEVICE FOR CONTROLLING ACCESS TO CODED DATA.
- Spanish
- METODO Y DISPOSITIVO DE CONTROL DE ACCESO A DATOS CODIFICADOS.
Classification
- CPC, 6
- H04N21/44236
- H04N21/4623
- H04N7/1675
- H04N21/26606
- H04N21/4181
- H04N21/4405
- IPC, 3
- G07F7 10
- H04N5 00
- H04N7 167