Encryption/decryption of program data but not psi data
Abstract
Triple wrap decryption method to decrypt an encrypted message (PKMS, MKMS) to give decrypted data that have sequential first, second, third and fourth decrypted data parts, in which the encrypted message has sequential first, second, third and fourth encrypted parts , the method comprising: receiving, from a transmitter (8), the encrypted message (PKMS, MKMS); decrypt (in 242) together the first and fourth encrypted parts according to a first key to produce first intermediate decrypted data and the fourth part of decrypted data, in which one half of the decryption result is the first intermediate decryption data and the other half is the quarter of decrypted data, in which a quarter of decrypted data includes one third of a decrypted message; process (in 236) the first intermediate decrypted data through a first EXCLUSIVE OR operator to which a Hash value is applied as the second key to produce a first operator output; decrypt (in 244) together the first operator output and the third part encrypted according to a third key to produce second intermediate decrypted data and the third part of decrypted data, in which one half of the decryption result is the second intermediate decryption data and the another half is later part of decrypted data, in which the third part of decrypted data includes one third of the decrypted message; process (in 238) the second intermediate decrypted data through a second EXCLUSIVE operator to which a Hash value is applied as the fourth key to produce a second operator output; decrypt (in 246) together the second operator exit and the second part encrypted according to a fifth key to produce third intermediate decrypted data and the second part of decrypted data, in which the middle of the decryption result is the third intermediate decryption data and the another half is the second part of decrypted data, in which the second part of decrypted data includes a third of the decrypted message; and, process (in 240) the third intermediate decrypted data by means of a third EXCLUSIVE OR operator to which a Hash value is applied as the sixth key to produce the first part of decrypted data, in which the first part of decrypted data includes an initial value.

Term
Term ended
Projected expiry passed 18 May 2026, 0.4 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
18 claims: 1 independent, 17 dependent
- 1ES 2 398 347 T3 REIVINDICACIONES 1. Método de descifrado de triple envoltura para descifrar un mensaje cifrado (PKMS, MKMS) para dar datos descifrados que tienen partes de datos descifrados primera, segunda, tercera y cuarta secuenciales, en el que el mensaje cifrado tiene partes cifradas primera, segunda, tercera y cuarta secuenciales, comprendiendo el método:recibir, desde un transmisor (8), el mensaje cifrado (PKMS, MKMS);descifrar (en 242) juntas las partes cifradas primera y cuarta según una primera clave para producir primeros datos descifrados intermedios y la cuarta parte de datos descifrados, en el que una mitad del resultado de descifrado son los primeros datos de descifrado intermedios y la otra mitad es la cuarta parte de datos descifrados, en el que la cuarta parte de datos descifrados incluye un tercio de un mensaje descifrado;procesar (en 236) los primeros datos descifrados intermedios mediante un primer operador EXCLUSIVE OR a los que se aplica un valor Hash como segunda clave para producir una primera salida de operador;descifrar (en 244) juntas la primera salida de operador y la tercera parte cifrada según una tercera clave para producir segundos datos descifrados intermedios y la tercera parte de datos descifrados, en el que una mitad del resultado de descifrado son los segundos datos de descifrado intermedios y la otra mitad es la tercera parte de datos descifrados, en el que la tercera parte de datos descifrados incluye un tercio del mensaje descifrado;procesar (en 238) los segundos datos descifrados intermedios mediante un segundo operador EXCLUSIVE OR a los que se aplica un valor Hash como cuarta clave para producir una segunda salida de operador;descifrar (en 246) juntas la segunda salida de operador y la segunda parte cifrada según una quinta clave para producir terceros datos descifrados intermedios y la segunda parte de datos descifrados, en el que una mitad del resultado de descifrado son los terceros datos de descifrado intermedios y la otra mitad es la segunda parte de datos descifrados, en el que la segunda parte de datos descifrados incluye un tercio del mensaje descifrado;y, procesar (en 240) los terceros datos descifrados intermedios mediante un tercer operador EXCLUSIVE OR a los que se aplica un valor Hash como sexta clave para producir la primera parte de datos descifrados, en el que la primera parte de datos descifrados incluye un valor inicial.
- 2Método según la reivindicación 1, en el que la primera parte de datos descifrados comprende un valor inicial (IV) para su comparación con un valor inicial usado durante el cifrado.
- 3Método según la reivindicación 2, comprendiendo el método además detectar errores de descifrado como resultado de una comparación de la primera parte de datos descifrados con un valor inicial usado durante el cifrado.
- 4Método según la reivindicación 2, en el que las partes de datos descifrados segunda, tercera y cuarta comprenden información de control, y en el que la información de control incluye punteros de dirección que apuntan a ubicaciones de memoria en una memoria de receptor.
- 5Método según la reivindicación 2, en el que la segunda parte de datos descifrados comprende información de control, en el que la información de control incluye punteros de dirección que apuntan a ubicaciones de memoria en una memoria de receptor, en el que las partes de datos descifrados tercera y cuarta comprenden una clave de programa, y comprendiendo el método además:recibir datos de programa cifrados (en 182);y, descifrar los datos de programa cifrados (en 184) según la clave de programa.
- 6Método según la reivindicación 2, en el que la segunda parte de datos descifrados comprende información de control, y en el que las partes de datos de entrada tercera y cuarta comprenden una clave de modificación (MK) que se usa para descifrar una clave de programa (PK) que se usa para descifrar datos de programa.
- 7Método según la reivindicación 1, en el que las claves segunda, cuarta y sexta son más cortas que las claves primera, tercera y quinta.
- 8Método según la reivindicación 1, en el que las claves segunda, cuarta y sexta tienen una longitud que es la mitad de la longitud de las claves primera, tercera y quinta.
- 9Método según la reivindicación 1, que comprende además:ES 2 398 347 T3 recibir una clave de programa antes del mensaje cifrado;recibir, desde el transmisor, datos cifrados en el flujo de transporte MPEG;y, sincronizar, en respuesta al mensaje cifrado recibido, el uso de la clave de programa para descifrar los datos cifrados recibidos.
- 10Método según la reivindicación 9, en el que la recepción de un mensaje cifrado comprende recibir un mensaje cifrado actual, en el que la recepción de una clave de programa comprende recibir una señal de clave de programa en el flujo de transporte MPEG antes de recibir el mensaje cifrado actual, y en el que la señal de clave de programa contiene la clave de programa recibida.
- 11Método según la reivindicación 10, en el que la clave de programa recibida del transmisor está cifrada, y en el que la sincronización del uso de la clave de programa para descifrar los datos cifrados recibidos comprende;descifrar la clave de programa cifrada;y, descifrar los datos cifrados recibidos según la clave de programa descifrada.
- 12Método según la reivindicación 11, en el que el descifrado de la clave de programa cifrada comprende descifrar la clave de programa cifrada según una clave de modificación, comprendiendo el método además recibir una señal de clave de modificación que se recibe en una señal recibida antes de recibir una señal de clave de programa, y en el que la señal de sincronización de clave de modificación contiene la clave de modificación.
- 13Método según la reivindicación 9, en el que el mensaje cifrado recibido se descifra tras sincronizar el uso de la clave de programa para descifrar los datos cifrados recibidos mediante el mensaje cifrado recibido.
- 14Método según la reivindicación 1, que comprende además:recibir una clave de programa cifrada;descifrar la clave de programa cifrada según una o más de las partes de datos descifrados primera, segunda, tercera y cuarta;y, descifrar los datos cifrados recibidos según la clave de programa descifrada.
- 15Método según la reivindicación 14, en el que el mensaje cifrado comprende un primer mensaje cifrado recibido en el flujo de transporte MPEG, en el que la recepción de una clave de programa cifrada comprende recibir la clave de programa cifrada en un segundo mensaje cifrado tras recibirse el primer mensaje cifrado, en el que el descifrado de la clave de programa cifrada comprende descifrar la clave de programa cifrada según una clave de modificación, y en el que la clave de modificación está contenida en el primer mensaje cifrado.
- 16Método según la reivindicación 1, que comprende además:recibir una pluralidad de claves de programa;rotar las claves de programa según un patrón, en el que el patrón es una secuencia de rotación de repetición;y, descifrar datos recibidos basándose en las claves de programa rotadas, en el que la rotación de las claves hace que se usen diferentes secuencias de las mismas claves en el descifrado de los datos recibidos.
- 17Método según la reivindicación 16, que comprende además recibir una identificación del patrón desde un transmisor.
- 18Método según la reivindicación 1, que comprende además:recibir al menos un programa cifrado y datos PSI no cifrados, en el que los datos PSI no cifrados se refieren al programa cifrado;localizar el programa cifrado según los datos PSI no cifrados;y, descifrar el programa cifrado localizado según una clave de programa.
Independent claims18
163 paragraphs in 6 sections, as filed
ES 2 398 347 T3
DESCRIPTION
Encryption / decryption of program data but not PSI data
Related requests
This application refers to U.S. Patent Application Serial Number 11 / 137,272, filed May 25, 2005.
Technical field of the invention
The present invention relates to the encryption and decryption of data transmitted between a transmitter and a receiver and, more particularly, to the encryption and decryption of both data and encryption keys used to encrypt the data.
Background of the invention
There are many systems in which unauthorized copying of data has undesirable consequences. For example, in pay-per-view systems such as those offered by hotels, hostels, and cable systems, the provider offering pay-per-view programming loses significant benefits if their programs are hacked.
Numerous tools are routinely available in hardware stores, entertainment stores, university labs, and provided by hackers and experts to enable reverse engineering of all aspects of data transmission systems, including pay-per-view systems. Consequently, pay-per-view providers and others interested in copy protection implement various copy protection systems in order to prevent unauthorized copying.
Copy protection systems have several security objectives. For example, copy protection systems seek to prevent theft of high-quality compressed digital content, prevent theft of high-quality uncompressed digital content, and limit losses caused by improper access.
The copy protection system of the present invention is intended to thwart unauthorized copying of content.
Published US patent application 2004/0268117 A1 discloses a key synchronization satellite broadcast conditional access system using indexing of an authorization stream to quickly restart the decryption process after short carrier fades and after handoffs. carrier.
Published European Patent Application No. 1 187 483 discloses an encryption apparatus and a method for synchronizing multiple encryption keys with a data stream.
European Published Patent Application No. 0 706 118 483 discloses a data protection system that allows authorized users to use target data through a simple operation but does not allow unauthorized users to use the program even though they may copy.
Summary of the invention
The invention provides a triple envelope decryption method according to claim 1.
Preferred embodiments are defined by the dependent claims.
Brief description of the drawings
These and other features and advantages will become more apparent from a detailed consideration of the invention taken in conjunction with the drawings, in which:
Figure 1 illustrates a scrambling encoder of a copy-protected transmitter according to an embodiment not belonging to the present invention;
Figure 2 illustrates the data encryption block of Figure 1 in greater detail;
Figure 3 illustrates the dynamic key block of Figure 1 in greater detail;
Figure 4 illustrates the key expansion block of Figure 3 in greater detail;
Figure 5 illustrates parts of Figure 1 in greater detail;
Figure 6 illustrates the key modifier of Figure 5 in greater detail;
Figure 7 illustrates an example MM modifier message used in the copy protection system of Figure 1;
Figure 8 illustrates a control portion of the modifier message MM illustrated in Figure 7;
Figure 9 illustrates an example definition of the system control bytes of the modifier message MM illustrated in Figure 8;
Figure 10 illustrates an example MS message segment used in the copy protection system of Figure 1;
Figure 11 illustrates the encryption block of the program key, the modification key and the modifier message MM of Figure 1 in greater detail;
Figure 12 illustrates an example key message that is part of the MS message segment illustrated in Figure 10;
Figure 13 illustrates a pair of example MS message segments used to transmit program keys and modification keys;
Figure 14 illustrates the timing of the transmitter and receiver with respect to message generation and use;
Figure 15 illustrates an example rotation for applying program keys PK during encryption of program data;
Figure 16 illustrates an example of the parts of a program data segment of a field to which rotation is applied;
Figure 17 illustrates a decryption decoder of a copy protection receiver according to an embodiment of the present invention;
Figure 18 illustrates the data decryption block of Figure 17 in greater detail;
Figure 19 illustrates parts of the decryption decoder of Figure 17 in greater detail; and, Figure 20 illustrates the key decryption block and modifier message of Figure 17 in greater detail.
Detailed description
In FIG. 1, an example encryption encoder 8 of a copy-protected transmitter includes a PID filter 10 that receives an MPEG transport stream and determines which packets in the MPEG transport stream contain data to be encrypted. As discussed below, the PID filter 10 also identifies null packets that must be replaced with MS message segments that give the receiver enough information to decrypt the encrypted program data in the received signal, and the PID filter 10 further identifies packets that they contain information that should not be encrypted.
A dynamic program key and modification key generator 12 dynamically generates program keys PK that are applied by a first encryption engine 14 in order to encrypt the program data in the MPEG transport stream that has been selected for encryption. . The first encryption engine 14, for example, may be a single-envelope encryption engine, and may be arranged to implement the single-envelope encryption process specified in the Advanced Encryption Standard (AES). The encrypted program data packets are supplied to an input of an output multiplexer 16.
The dynamically generated PK program keys are applied through a multiplexer 24 after which they are themselves encrypted by a second encryption engine 18. The second encryption engine 18 may be a triple-wrap encryption engine, and may be arranged to apply the triple envelope encryption process specified in the Advanced Encryption Standard.
Unlike the dynamically generated PK program keys that are used by the first encryption engine 14 to encrypt the program data, the keys used by the second encryption engine 18 to encrypt the dynamically generated PK program keys they are message segment keys. Fixed keys are stored in a memory 20, these fixed keys are used by a message segment key generator and control 22 to generate message segment keys, and the message segment keys are supplied to the second encryption engine 18.
The fixed keys stored in memory 20 are, for example, 128 bits long, and there are, for example, sixty-four fixed keys stored in memory 20. The hash values discussed in this document are, for example, sixty and four bits each and are derived as selected parts of the fixed keys. Alternatively, hash values can be stored separately in memory 20, and hard keys and values
ES 2 398 347 T3 hashes can be of any desired length and number.
Therefore, the message segment key generator and control 22 selects the fixed keys to be used by the second encryption engine 18 from memory 20, uses them to generate message segment keys, and supplies the encryption keys. message segments to the second encryption engine 18. The second encryption engine 18 encrypts the dynamically generated program keys PK based on the message segment keys of the control and message segment key generator 22.
As discussed below, an MM modifier message and MK modifier keys are also applied through multiplexer 24 and encrypted by second encryption engine 18. The encrypted dynamically generated PK program keys and MM modifier message Ciphers are assembled into PKMS program key message segments that are forwarded to the receiver. As will be discussed further below, the encrypted MK modification keys, an encrypted checksum, and the encrypted MM modifier message are similarly assembled into MKMS modification key message segments that are also forwarded to the receiver.
The modification keys, dynamically generated by the program and modification key generator 12, are used with the fixed keys to generate the message segment keys that are used to encrypt the program keys, and the checksum it is based on the fixed keys stored in memory 20. The checksum, for example, can comprise 128 bits, and can be generated from all the fixed keys stored in memory 20. Consequently, the receiver can compare the checksum from the transmitter with a checksum generated from its own fixed keys to verify that its fixed keys match the fixed keys from the transmitter. The checksum can also be used to determine transmission errors.
As noted above, the PKMS program key message segment and the MKMS modification key message segment give the receiver the information it requires to decrypt the encrypted program data in the received signal.
Figure 2 shows the first encryption engine 14 in greater detail. As shown in Figures 1 and 2, the first encryption engine 14 is coupled between the PID filter 10 and the output multiplexer 16.
The first encryption engine 14 has three sections 14A, 14B, and 14C. Section 14A includes a demultiplexer 30, memories 32 and 34, and a multiplexer 36. Section 14B includes a RAM delay 38, a cipher block 40, and a multiplexer 42. Section 14C includes a demultiplexer 44, memories 46 and 48 , and a multiplexer 50.
The PID filter 10 passes the transport packets in the MPEG transport stream to demultiplexer 30. The transport packets are demultiplexed and stored in memories 32 and 34 which operate in a ping-pong fashion. Transport packets in memories 32 and 34 are supplied to multiplexer 36.
Multiplexer 36 passes all packets from memories 32 and 34 to both RAM delay 38 and encryption block 40. These packets include program packets, null packets, and non-program packets such as PIDs, PSIPs, PMTs, and PATs. Encryption block 40 uses dynamically generated program keys PK to encrypt all packets it receives and delivers the encrypted packets to multiplexer 42. In response to an encryption flag from PID filter 10, multiplexer 42 selects only the encrypted packets from encryption block 40 that correspond to the selected program or programs to be encrypted. It will be understood that the MPEG transport stream may contain one or more programs and that any one or more of these programs may be indicated for encryption. All other packets (those that do not correspond to the program to be encrypted) are selected by multiplexer 42 from RAM delay 38. Therefore, the output of multiplexer 42 is the input MPEG transport stream except that the packets corresponding to the selected program are encrypted. The multiplexer 42 passes the encrypted and unencrypted packets to the demultiplexer 44.
Among the packets that the multiplexer 42 selects from the RAM delay 38 are PSI (Program Specific Information) packets such as PSIP (Program and System Information Protocol) packets, PAT (Program Specific Information Protocol) packets. Association Table, program association table), PMT packages (Program Map Table) and / or packages containing adaptation fields. Accordingly, the unencrypted packets emitted by multiplexer 42 include PSI packets. PSI packets contain information that helps the receiver to determine which channel and which parts of the transport stream contain the program selected by the user. If PSI packets were encrypted, the receiver would not be able to locate user-selected programs for decryption.
Encrypted and unencrypted packets from demultiplexer 44 are stored in memories 46 and 48 which operate in a ping-pong fashion. Encrypted and unencrypted packets in memories 46 and 48 are supplied through multiplexer 50 to output multiplexer 16.
Sections 14A and 14C of first encryption engine 14 are controlled to maintain proper timing, data flow rates, and timing.
Fig. 3 shows a dynamic part of the program key generator 12A of the dynamic key generator
ES 2 398 347 T3 program and modification keys 12 in more detail. The dynamic portion of the program key generator 12A includes a seed generator 60 that supplies a seed to a random number generator 62. For example, the seed generator 60 may select, as desired, the seed from anywhere of the MPEG 61 transport stream, such as video and / or audio, in one or more program data packets.
A demultiplexer 64 selects four 128-bit random numbers from the random number generator 62 and stores these four 128-bit random numbers as four dynamically generated program keys in a next part of memory 66 while the cipher block 40 it uses the four dynamically generated program keys previously stored in an active portion of memory 66 to encrypt program data. Thus, while the four dynamically generated program keys PK stored in the active portion of memory 66 are currently being used to encrypt program data, the demultiplexer 64 selects another four 128-bit random numbers from the random number generator. 62 and stores these four additional 128-bit random numbers as four dynamically generated PK program keys in the next part of memory 66.
As explained below in connection with FIG. 14, at the time a MKMS modification key message segment is transmitted, the use of the four dynamically generated PK program keys stored in the active part of the memory 66, and the use of the four new dynamically generated PK program keys stored in the next part of memory 66 begins. At this transition point, the old next part of memory 66 becomes the new active part of memory 66, and the old active part of memory 66 becomes the next new part of memory 66. Furthermore, while Since these four new dynamically generated PK program keys are being used to encrypt program data, four more PK program keys are dynamically generated and stored in the next new portion of memory 66.
A multiplexer 68 supplies the four dynamic program keys from the active portion of memory 66 to a key expander 70 such as that shown in Figure 4. As needed, the key expander 70 expands each of the program keys. Dynamic PKs from 128-bit keys to, for example, 1408-bit expanded keys. The expanded dynamic PK program keys are supplied to the encryption block 40 of FIG. 2.
Key expander 70 as shown in Figure 4 includes a reverse key block. The reverse key block is enabled during program encryption and disabled during encryption of the PKMS program key message segment and MKMS modification key message segment.
Thus, four dynamically generated PK program keys are used to encrypt program data while the next four PK program keys are dynamically generated. The four dynamically generated PK program keys that are being used from the active portion of memory 66 continue to be used until the MKMS modification key message segment is generated.
The time between message segments, for example, can be made dependent on the availability of null packets in the incoming MPEG transport stream because message segments are transmitted instead of selected null packets. The PID filter 10 detects the null packet and instructs the output multiplexer 16 to pass a message segment instead of packets from the multiplexer 50.
As shown in Figure 5, a fixed key selector 80 uses random numbers generated by the random number generator 62 in order to access memory 20 to select the fixed keys from memory 20. For example, each key The fixed key stored in memory 20 can be 128-bit, and four 32-bit address words can be used to read each fixed key from memory 20. These fixed keys are used to encrypt the program keys and modification keys (described in more detail later herein) that are sent to the receiver and required by the receiver to decrypt the received encrypted program data.
More specifically, three fixed keys are selected from memory 20 by fixed key selector 80 and stored as fixed keys Ka in fixed key memory 82. Three more fixed keys are selected from memory 20 by fixed key selector 80 and are stored as fixed keys Kb in a fixed key memory 84. For example, each of these three fixed keys Ka and three fixed keys Kb can be 128 bits in length. The three fixed keys Ka stored in fixed key memory 82 and the three fixed keys Kb stored in fixed key memory 84 are selected based on random addresses from random number generator 62.
In addition, three hash values A, B and C are selected by the fixed key selector 80 and stored in a memory of hash values and message segment keys 86. The three hash values A, B and C are also selected based on random addresses from random number generator 62. For example, each of the three hash values A, B, and C can be 64 bits or 1/2 of a fixed key. In addition, three random numbers from random number generator 62 are stored in a modification key memory 88 as modification keys Km. Each of the modification keys, for example, may be 128 bits in length.
ES 2 398 347 T3
A message segment key generator 90, shown in more detail in FIG. 6, includes latches 92i, 922, and 923 and a 96x32 look-up table 94. Latch 921 holds the first 32 bits of a first of the three fixed keys Ka stored in fixed key memory 82, latch 922 holds the first 32 bits of a first of three fixed keys Kb stored in fixed key memory 84, and latch 923 holds the first 32 bits of a first of the three Km modification keys stored in modification key memory 88. These 96 bits retained form a 96-bit address that read extracts the first 32 bits of a first message segment key for storage in memory of message segment keys and hash values 86.
Figure 6 also shows, in simplified form, four of the lookup tables that are stored in the lookup table 94. One of the tables is selected to provide the three message segment keys that are stored in the key memory of the message segments and hash values 86. The simplified form of table 0 in figure 6 shows the relationship between the address and the bits that are stored in table 0. Therefore, if the first Km bit of an address is 0 and the first Ka bit of an address is 0 and the first Kb bit of an address is 0, table 0 will read out a 0 bit for the first K0 bit of an address. message segment key. However, if the first Km bit of an address is 1 and the first Ka bit of an address is 1 and the first Kb bit of an address is 0, table 0 will read extract a 1 bit for the first bit instead. K0 bit of a message segment key. If the next Km bit of an address is 0 and the next Ka bit of an address is 0 and the next Kb bit of an address is 0, table 0 will read out a 0 bit for the next K0 bit of the segment key message. However, if the next Km bit of an address is 0 and the next Ka bit of an address is 1 and the next Kb bit of an address is 0, table 0 will instead read a 1 bit for the next K0 bit of a message segment key.
The bits that are stored in the tables can have any desired relationship to their addresses. The relationship can be a random relationship, OR, XOR, Y, NAND, NOT, MUX, one's complement, two's complement, or grayscale, and each table can have a different relationship between the address and the bits stored.
After the first 32 bits of the first message segment key have been read from lookup table 94 and stored in memory of message segment keys and hash values 86, latch 921 holds the second 32 bits of the first of the three fixed keys Ka stored in fixed key memory 82, latch 922 holds the second 32 bits of the first of three fixed keys Kb stored in fixed key memory 84, and latch 923 holds the second 32 bits of the first of the three Km modification keys stored in the modification key memory 88. These 96 bits held form a second 96-bit address that extracts by reading the second 32 bits of the first message segment key for storage in memory of message segment keys and hashes 86.
The third and fourth 32 bits of the first of the three fixed keys Ka stored in the fixed-key memory 82, of the first of the three fixed keys Kb stored in the fixed-key memory 84, and of the first of the three keys Modification keys Km stored in modification key memory 88 are used to read out the third and fourth 32 bits of the first message segment key from look-up table 94. These third and fourth 32 bits of the first message segment key are also stored in the hash value and message segment key memory 86 to form all 128 bits of the first message segment key. The second and third message segment keys are similarly read from lookup table 94 and stored in message segment keys and hashes memory 86. These three message segment keys are used to encrypt the program keys. Three other message segment keys are used to encrypt a set of modification keys as explained in more detail below.
As shown in Figure 5, a multiplexer 96 appropriately multiplexes the following four dynamically generated PK program keys from memory 66, a key control 98, the modification keys from the modification key memory 88 , the memory 20 checksum and a modifier message MM of a modifier message memory 99 to create the PKMS program key message segment and the MKMS modification key message segment which are discussed in more detail below.
An example of the MM modifier message is shown in Figure 7. As shown, the MM modifier message contains a 64-bit initial value and a 192-bit control. The use of the initial value is described below. As shown in Figure 8, the control bits of the MM modifier message comprise, for example, four bytes for system control, nine bytes for address pointers pointing to memory addresses for fixed keys and hash values , and eleven bytes that can be used for any purpose.
The address pointers discussed above point to addresses in memory 20 corresponding to (i) the six fixed keys that are stored in fixed-key memories 82 and 84 and that, in selected combinations, are used by the key generator of message segments 90 to generate the message segment keys A, B and C stored in the memory of message segment keys and hash values 86 and (ii) the hash values A, B and C which are also stored in message segment key memory and
ES 2 398 347 T3 hash values 86. These address pointers are sent in the modifier message MM to the receiver so that the receiver can regenerate the message segment keys A, B and C and the corresponding hash values A, B and C required to decrypt the program keys and modification keys, as explained below.
The 32 bits of the MM modifier message system control are shown by way of example in Figure 9. Bits 0 and 1 are used to designate the copy control assigned to the program data. Bits 2-7 are reserved, except that at least one of these reserved bits is set to one value to indicate that the corresponding message segment is an MKMS modification key message segment and is set to another value to indicate that the corresponding message segment is a PKMS program key message segment.
When this at least one reserved bit is set to a value indicating that the corresponding message segment is an MKMS modification key message segment, the Km bits provided in lookup table 94 are set to a predetermined value such as all zeros while all three message segment keys are being produced for storage in memory of message segment keys and hashes 86. In fact, the message segment keys that are used to encrypt the MKMS modification key message segment are produced with modification keys that have a predetermined value known to both the transmitter and the receiver.
When the modification keys have this default value, the look-up table 94 can pass only the fixed keys Ka as the message segment keys. Alternatively, when the modification keys have this default value, the look-up table 94 could instead pass only the fixed keys Kb as the message segment keys, or the look-up table 94 could read message segment keys based on the fixed keys both Ka and Kb of the fixed key memories 82 and 84. These alternatives are based on which of the tables in look-up table 94 is selected as indicated by bits 8-11 of the system control of the MM modifier message as discussed below. The message segment keys produced with these modification keys having the default value are used to encrypt the MK1, MK2 and MK3 modification key messages and the CRC checksum message.
When this at least one reserved bit is set to the value indicating that the corresponding message segment is a PKMS program key message segment, the Km bits provided to lookup table 94 are the randomly generated modification keys stored in the modification key memory 88, and these randomly generated modification keys are used in conjunction with the fixed keys Ka and Kb to produce the three message segment keys stored in hash value and message segment keys memory 86. Therefore, the message segment keys that are used to encrypt the PKMS program key message segment are produced with the randomly generated modification keys stored in the modification key memory 88 in addition to the fixed keys Ka and Kb of fixed key memories 82 and 84. The message segment keys produced with the randomly generated modification keys stored in the modification key memory 88 are used to encrypt the PK1, PK2, PK3, and PK4 program key messages.
The fixed keys used to generate the message segment keys that encrypt the PKMS program key message segment may be the same as or different from the fixed keys used to generate the message segment keys that encrypt the PKMS key message segment. MKMs modification.
Bits 8, 9, 10, and 11 designate which of the sixteen possible tables stored in look-up table 94 is used to produce the message segment keys stored in hash value and message segment key memory 86.
Bits 12-15 can be used for any purpose such as indicating to the receiver a particular program key rotation, as discussed below.
Bits 16-31 are a checksum produced by a CRC generator of modifier message memory 99. Specifically, the CRC generator of modifier message memory 99 applies a CRC code to bits 0-15 of the byte. control system shown in FIG. 9 in order to generate a checksum. This checksum comprises bits 16-31 as shown in Figure 9. The CRC generator adds this checksum to unmodified bits 0-15 to form the complete system control of the MM modifier message. This complete system control of the MM modifier message is used by the receiver to determine if the PKMS program key message segment and / or the MKMS modification key message segment is not received properly due to, for example, channel noise and is described in more detail below.
As shown in FIG. 5, a multiplexer 100 receives the message segment keys and hashes stored in the message segment key and hash value memory 86. The multiplexer 100 also receives three fixed keys A ', B 'and C' and three hash values A ', B' and C 'stored in a memory 102. For example, each of the three fixed keys A ', B', and C 'stored in memory 102 comprises a 128-bit fixed key, and each of the three Hash values A', B ', and C' stored in memory memory 102 comprises a hash value
ES 2 398 347 T3 64-bit.
The multiplexers 96 and 100 work in conjunction with the second encryption engine 18 to encrypt the encrypted portion of the MS message segments shown in Figure 10. In the case of the PKMS program key message segment, the encrypted portion of the MS message shown in Figure 10 includes the MM modifier message and four program key messages KM1, KM2, KM3, and KM4. In the case of the MKMS modification key message segment, the encrypted part of the MS message segment shown in Figure 10 includes the MM modifier message, the three modification key messages MK1, MK2, and MK3, and the checksum of fixed keys CRC. The modifier messages MM include the initial value and the 192-bit control as shown in Figures 7 and 8. The initial value, for example, can include 64 arbitrary predetermined bits.
In order to encrypt the modifier message MM, multiplexer 100 passes the three fixed keys A ', B', and C 'and the three hash values A', B ', and C' from memory 102 through a key expander. 104 to the second encryption engine 18. The key expander 104, for example, may be similar to the key expander 70 and expands only the fixed keys A ', B' and C '. Key expander 104 does not expand hash values A ', B', and C '. Additionally, multiplexer 96 passes the MM modifier message to second encryption engine 18.
The second encryption engine 18 is shown in more detail in Figure 11. The Hash A 'value applies to an EXCLUSIVE OR (OR EXCLUSIVE) 106, the Hash B' value applies to an EXCLUSIVE OR 108, and the Hash value C 'applies to an EXCLUSIVE OR 110. EXCLUSIVE ORs 106, 108, and 110 process their respective inputs by bits. The expanded fixed key A 'applies to an AES 112 cipher, the expanded fixed key B' applies to an AES 114 cipher, and the expanded fixed key C 'applies to an AES 116 cipher.
The initial value of the MM modifier message is applied to the EXCLUSIVE OR 106, a first 1/3 of the control bits of the MM modifier message is applied to the AES 112 cipher, a second 1/3 of the control bits of the MM modifier message is applies to AES cipher 114, and a third 1/3 of the control bits of the MM modifier message is applied to AES cipher 116.
The AES 112 encryptor encrypts an output of the EXCLUSIVE OR 106 and the first 1/3 of the control bits of the MM modifier message according to the expanded fixed key A ', and supplies half of the encryption result to the EXCLUSIVE OR 108 and the other half as the second 1/4 of the encrypted MM modifier message. The AES 114 encryptor encrypts one output of the EXCLUSIVE OR 108 and the second 1/3 of the control bits of the modifier message MM according to the expanded fixed key B ', and supplies half of the encryption result to the EXCLUSIVE OR 110 and the other half as the third 1/4 of the encrypted MM modifier message. The AES 116 cipher encrypts an output of the EXCLUSIVE OR 110 and the third 1/3 of the control bits of the MM modifier message according to the expanded fixed key C ', and supplies half of the encryption result as the first 1/4 of the message encrypted MM modifier and the other half as the fourth 1/4 of the encrypted MM modifier message.
Each key message in the PKMS program key message segment has the example construction of Figure 12. According to this example, a KM1 program key message includes a 64-bit initial value, which can be the same initial value discussed above or a different initial value, a 64-bit key control 98, and one of the 128-bit program keys split into two 64-bit parts. The KM2, KM3, and KM4 program key messages that contain the other three program keys are constructed similarly.
Key control 98 is used to designate whether the key message contains a program key, a modification key, or the checksum.
In order to encrypt the program key message KM1, the multiplexer 100 passes the three message segment keys A, B, and C and the three hash values A, B, and C from the message segment key memory and values. hash 86 through key expander 104 to second encryption engine 18. As explained above, the three message segment keys A, B, and C that are used to encrypt the program key messages are the message segment keys read from table 94 using the generated modification keys. randomly Km stored in modification key memory 88, fixed keys Ka from fixed key memory 82, and fixed keys Kb from fixed key memory 84. The key expander 104 expands only the message segment keys A, B, and C. The key expander 104 does not expand the hash values A, B, and C. Additionally, the multiplexer 96 passes the first of the four generated program keys dynamically from the next part of memory 66 to the second encryption engine 18.
In the second encryption engine 18, Hash A applies to EXCLUSIVE OR 106, Hash B applies to EXCLUSIVE OR 108, and Hash C applies to EXCLUSIVE OR 110. The expanded message segment key A is applied to AES cipher 112, expanded message segment key B is applied to AES cipher 114, and expanded message segment key C is applied to AES cipher 116. The initial value is applied to the EXCLUSIVE OR 106, the control word is applied to the AES 112 cipher, a first 1/2 of the first of the four dynamically generated program keys is applied to the AES 114 cipher, and a second half of the first of the four dynamically generated program keys is applied to the AES 116 cipher.
The AES 112 encryptor encrypts an output of the EXCLUSIVE OR 106 and the control word according to the expanded message segment key A, and supplies half of the encryption result to the EXCLUSIVE OR 108 and the other half as the
ES 2 398 347 T3 second 1/4 of the KM1 program key message. The AES 114 encryptor encrypts an output of the EXCLUSIVE OR 108 and the first 1/2 of the first of the four dynamically generated program keys based on the expanded message segment key B, and supplies half of the encryption result to the EXCLUSIVE OR 110 and the other half as the third 1/4 of the KM1 program key message. The AES 116 cipher encrypts an output of the EXCLUSIVE OR 110 and the second 1/2 of the first of the four dynamically generated program keys based on the expanded message segment key C, and supplies half of the encryption result as the first 1/4 of the KM1 program key message and the other half as the fourth 1/4 of the KM1 program key message.
The other three program key messages KM2, KM3, and KM4 are generated similarly.
Each modification key message in the MKMS modification key message segment also has the example construction of Figure 12. According to this example, a MK1 modification key message includes a 64-bit initial value, which may be the same initial value discussed above or a different initial value, a 64-bit key control 98, and one of the 128-bit modification keys divided into two 64-bit parts. The MK2 and MK3 mod key messages that contain the other two mod keys are constructed similarly.
Again, key control 98 is used to designate whether the key message contains a program key, a modification key, or the checksum.
In order to encrypt the modification key message MK1, the multiplexer 100 passes the three message segment keys A, B, and C and the three hash values A, B, and C from the message segment key memory and values. hash 86 through key expander 104 to second encryption engine 18. As explained above, the three message segment keys A, B, and C that are used to encrypt the modification key messages are the message segment keys read from table 94 using the modification keys with the default value. Thus, the fixed keys Ka in the fixed key memory 82 can be read from the table 94 as the message segment keys. Alternatively, as explained above, the fixed keys Kb from the fixed key memory 84 can be read from table 94 as the message segment keys or a combination of the fixed keys Ka and Kb can be used to read the segment keys. Table 94. Key expander 104 expands only message segment keys A, B, and C. Key expander 104 does not expand Hash values A, B, and C. In addition, the multiplexer 96 passes the first of the modification keys from the modification key memory 88 to the second encryption engine 18.
Hash values A, B, and C apply to EXCLUSIVE OR 106, 108, and 110 as above. Also, expanded message segment keys A, B, and C apply to AES ciphers 112, 114, and 116 as above. The initial value is applied to the EXCLUSIVE OR 106, the control word is applied to the AES 112 cipher, a first 1/2 of the first of the three modification keys is applied to the AES 114 cipher, and a second half of the first of the three modification keys applies to the AES 116 cipher.
The AES encryptor 112 supplies half of its encryption result to the EXCLUSIVE OR 108 and the other half as the second 1/4 of the MK1 modification key message. The AES encryptor 114 supplies half of its encryption result to the EXCLUSIVE OR 110 and the other half as the third 1/4 of the MK1 modification key message. The AES encryptor 116 supplies half of its encryption result as the first 1/4 of the MK1 modification key message and the other half as the fourth 1/4 of the MK1 modification key message.
The other two modification key messages MK2 and MK3 and the CRC checksum message are generated similarly.
The output multiplexer 16 of Figure 1 multiplexes the encrypted program data, the MPEG PID header of the transport stream, 192 clock bits that can be supplied by a separate generator and that can be the SMPTE time code (if any). any), and 20 bytes of forward error correction of the transport stream with the PKMS encrypted program key message segment and the MKMS encrypted modification key message segment to form the encrypted transport stream. Both the PKMS program key message segment and the MKMS modification key message segment are contained in a corresponding full ATSC data segment.
The second encryption engine 18 generates the MS message segments in pairs, that is, the PKMS program key message segment and the MKMS modification key message segment. This pair of MS message segments is shown in Figure 13. The modifying message MM in each MS message segment is provided according to Figures 8 and 9. The first message segment shown in Figure 13 is the MKMS modification key message segment and contains an encrypted form of the three modification keys stored in the modification key memory 88 and the checksum (CRC) of the memory 20. The second message segment shown in Figure 13 is the PKMS program key message segment and contains an encrypted form of the four new encrypted program keys to be applied by the receiver to decrypt the encrypted program data.
ES 2 398 347 T3
Thus, as shown in Figure 10, the modifier message MM and the four program key messages KM1, KM2, KM3, and KM4 in the PKMS program key message segment are encrypted. Similarly, the modifying message MM, the three modifying key messages MK1, MK2, and MK3, and the CRC checksum message in the modifying key message segment MKMS are encrypted.
The four-byte header of the MS message segment shown in Figure 10 is the MPEG PID. The modifier message MM includes the message control bytes shown in Figure 9. This control byte identifies the MS message segment in a pair as either the PKMS program key message segment or the PKMS message segment. MKMS mod key, as explained above.
Figure 14 shows the transmission and reception timing of relative pairs of messages with which the key timing is determined. When event 1 occurs, which may be a null packet in the MPEG transport stream, a PKMS program key message segment is transmitted as shown in Figure 14. The receiver receives this PKMS program key message segment, decrypts it, and stores the program keys that were contained in the PKMS program key message segment as next program keys. However, the receiver does not start using these next program keys yet.
After the transmitter transmits the PKMS program key message segment, the transmitter encryption encoder 8 creates the three modification keys and the MM modifier message, and encrypts the MM modifier message and the three modification keys using the keys of message segments and hash values as described above. The encryption encoder 8 then assembles the MKMS modification key message segment containing the encrypted MM modifying message and the three modification keys as described above. When a null packet is detected (event 2), the transmitter transmits the MKMS modification key message segment instead of the null packet, and at the same time, the encryption encoder 8 begins to use the following program keys stored in the memory 66 as the active program keys for encrypting program data. Therefore, the following program keys become the active program keys.
At the same time, the receiver receives this MKMS modification key message segment and immediately begins using its previously stored program keys as the active program keys to decrypt the program content. Consequently, the replacement of the active program keys with the following program keys is done at the same time in the transmitter and receiver so that the transmitter and receiver use the same program keys to encrypt and decrypt the same program content. .
After the transmitter transmits the MKMS modification key message segment and changes program keys, the transmitter encryption encoder 8 creates new program keys, and stores the new program keys in memory 66 as the following keys of program. The encryption encoder 8 encrypts the new program keys and assembles another PKMS program key message segment containing the new program keys and waits for an opportunity (event 3 such as a null packet) to transmit this key message segment PKMS program.
Although the transmitter encryption encoder 8 creates new program keys, saves the new program keys, and assembles the next PKMS program key message segment, the receiver decrypts the MKMS modification key message segment that was just passed. receive, and save the MM modifier message and the modification keys contained in this message.
During the segments where the encryption encoder 8 is not transmitting PKMS program key message segments and MKMS modification key message segments, the encryption encoder 8 is using the active program keys to encrypt program data and it is transmitting the encrypted program data to the receiver.
During the segments where the receiver is not receiving PKMS program key message segments and MKMS modification key message segments, the receiver is using the active program keys to decrypt program data.
In an embodiment where the transmission of messages and key usage is synchronized with the occurrence of null packets, there may be occasions when null packets appear at a high frequency in an undesirable manner. For example, during periods when there is little activity on the video, many null packets may appear during a single frame. Therefore, it may be desirable to add a delay function so that the transmission of messages and the change of keys does not occur more frequently than with a predetermined frequency. For example, this delay function can be set so that the transmission of messages and the change of keys does not occur more frequently than once every two or three ATSC frames.
During encryption of program data, the encryption block 40 rotates the four active program keys PK. Figure 15 shows the rotation. As shown in Figure 16, each program data segment of a field to be transmitted to the receiver includes an unencrypted four-byte MPEG header that identifies the segment as a program data segment, eleven blocks containing each one 128 bit encrypted data
ES 2 398 347 T3 program, eight bytes of unencrypted program data, and twenty bytes of unencrypted forward error correction data.
As shown in Figure 15, the four active program keys A, B, C, and D are applied in the following order to the eleven data blocks in the first segment of program data: A, B, C, D , A, B, C, D, A, B, C. Therefore, the active program key A applies to the first of the eleven data blocks to be encrypted, the active program key B applies to the second of the eleven data blocks to be encrypted, ..., and the key Active program code C applies to the eleventh of the eleven data blocks to be encrypted.
This same rotation scheme ABCDABCDABC can be used for the next and subsequent program data segments of a field.
Alternatively, the next segment of program data can continue the rotation. Therefore, the active program keys A, B, C, and D are applied in the following order to the eleven blocks of data to be encrypted in the second segment of program data: D, A, B, C, D, A , B, C, D, A, B. Therefore, the active program key D applies to the first of the eleven data blocks to be encrypted, the active program key A applies to the second of the eleven data blocks to be encrypted, ..., and the key active program code B applies to the eleventh of the eleven data blocks to be encrypted. Rotation can then continue for subsequent program data segments as indicated by FIG. 15.
As a further alternative, other rotation sequences can be used. Bits 12-15 of the system control byte shown in Figure 9 can be used to indicate to the receiver the particular rotation that is being used at the transmitter.
Output multiplexer 16 transmits encrypted program data segments continuously until an opportunity (event) arises to transmit an MS message segment (either a PKMS program key message segment or a key message segment. MKMS Modification). The appearance of a null packet gives rise to the opportunity to transmit one of these message segments, the appearance of the next null packet gives rise to the opportunity to transmit the other of the MS message segments in the pair, and so on. A goal can be set to transmit an MS message segment in a periodic manner that is dependent on the occurrence of a null packet. For example, the goal may be to transmit an MS message segment no more often than once per 312 segment field.
An exemplary decryption decoder 180 of a copy protection receiver is shown in FIG. 17. Decryption decoder 180 includes a PID filter 182 that, based on PID numbers, detects and forwards encrypted program data to a first engine. decryption key 184 and detects and forwards PKMS program key message segments and MKMS modification key message segments to a second decryption engine 186. The first decryption engine 184 performs a single-envelope decryption process that is complementary to the single-envelope encryption process performed by the first encryption engine 14.
When the MKMS modification key message segment is received, the second decryption engine 186 decrypts (unwraps) this message segment in order to retrieve the modification keys and the fixed key and hash value addresses from a memory 188. A fixed key selector and message segment key generator 190 uses these fixed key and hash value addresses to retrieve fixed keys and hash values from memory 188. In the case of decrypting the MKMS modification key message segment, the fixed key selector and the message segment key generator 190 use the fixed keys and hash values retrieved from memory 188 along with the known modification keys above, that is, the mod keys that have the known default value, in order to regenerate the message segment keys that were used in the encryption encoder 8 to encrypt the modification keys and the CRC checksum message and that the decryption decoder 180 requires to decrypt the encrypted modification keys and the CRC checksum message. In the case of decrypting the PKMS program key message segment, the fixed key selector and message segment key generator 190 uses the fixed keys and hash values retrieved from memory 188 based on the memory addresses contained in the modifying message of the PKMS program key message segment along with the decrypted modification keys in order to regenerate the message segment keys that were used in the encryption encoder 8 to encrypt the program keys and that the Decryption 180 requires KM1, KM2, KM3 and KM4 encryption program key messages to decrypt.
When the PKMS program key message segment is received, the second decryption engine 186 decrypts the program keys in the MS message segment using the message segment keys from the fixed key selector and the password generator. message segments 190 and stores the decrypted program keys in the next part of a memory 192. Meanwhile, the first decryption engine 184 uses the active program keys stored in memory 192 to decrypt the encrypted data from the program data segments of the field being received.
As shown in FIG. 18, the first decryption engine 184 includes three sections 184A, 184B, and 184C. Section 184A includes a demultiplexer 200, memories 202 and 204, and a multiplexer 206. Section 184B
ES 2 398 347 T3 includes a memory 208, a decryption block 210 and a multiplexer 212. Section 184C includes a demultiplexer 214, memories 216 and 218 and a multiplexer 220. Sections 184A, 184B and 184C are controlled by the PID filter 182.
PID filter 182 passes all packets in the MPEG transport stream to demultiplexer 200. All packets are demultiplexed and stored in memories 202 and 204 which operate in a ping-pong fashion. All packets in memories 202 and 204 are supplied to multiplexer 206.
Multiplexer 206 passes all packets from memories 202 and 204 to memory 208 and to decryption block 210. These packets include program packets (one or more of which may be encrypted), message segments, and unencrypted packets. such as PID, PSIP, PMT and PAT. Decryption block 210 uses decrypted program keys PK to decrypt all packets it receives and delivers the decrypted packets to multiplexer 212. The multiplexer 212, in response to a decryption flag from the PID filter 182, selects only the decrypted packets from the decryption block 210 that correspond to the selected program or programs that were to be decrypted. All other packets (those that do not correspond to the program to be decrypted) are selected by multiplexer 212 from memory 208. Therefore, the output of multiplexer 212 is the original MPEG transport stream minus the null packets and that includes message segments. The multiplexer 212 passes the decrypted and unencrypted packets to the demultiplexer 214.
The decrypted and unencrypted packets from demultiplexer 214 are stored in memories 216 and 218 which operate in a ping-pong fashion. Decrypted and unencrypted packets in memories 216 and 218 are delivered through multiplexer 220 to null inserter 222.
Null inserter 222 is controlled by PID filter 182 to remove the PKMS program key message segments and MKMS modification key message segments from the transport stream, and to insert the null packets back into the stream. instead of the retired PKMS program key message segments and the retired MKMS modification key message segments. The output of the null inserter is the decrypted MPEG transport stream.
Sections 184A and 184C of the first decryption engine 184 are controlled by the message packets to maintain proper timing, data flow rates, and timing.
The fixed key selector and message segment key generator 190 is shown in more detail in Figure 19. As shown in Figure 19, the PKMS program key message segments and the PKMS key message segments Modification MKMS are supplied to the second decryption engine 186. Each of these message segments has the form shown in Figure 10. Therefore, as shown in Figure 20, the modifier message MM in the received message segment is decrypted using the three fixed keys A ', B' and C 'and the three hash values A', B 'and C' that are stored in memory 230. The three fixed keys A ', B and C' and the three Hash values A ', B' and C 'stored in memory 230 are the same fixed keys and Hash values that are stored in the memory 102.
The decrypted MM modifier message indicates to the receiver, among others, whether the corresponding message segment is a PKMs program key message segment or an MKMS modification key message segment. If the corresponding message segment is a PKMS program key message segment, the receiver knows how to use the decrypted modification keys Km as well as the fixed keys Ka and Kb to produce the message segment keys that are required for the decryption of program key messages. If the corresponding message segment is an MKMS modification key message segment, the receiver knows to use the known modification keys that have the default value in order to extract the fixed keys Ka, Kb or some combination of Ka and Kb as well such as the message segment keys that are required for the decryption of the modification key messages and the CRC checksum message.
In order to decrypt the MM modifier message into one received from the MKMS modification key message segments or from the PKMS program key message segments, a multiplexer 232 passes the three fixed keys A ', B' and C ' and the three hash values A ', B' and C 'from memory 230 through a key expander 234 to the second encryption engine 186. Key expander 234, for example, may be similar to key expander 104 and expands only fixed keys A ', B', and C '. Key expander 234 does not expand hash values A ', B', and C '.
The second encryption engine 186 that performs a complementary operation to that performed by the encryption engine 18 is shown in more detail in Figure 20. As shown in Figure 20, the Hash value C 'is applied to an EXCLUSIVE OR 236 , the value Hash B 'applies to an EXCLUSIVE OR 238, and the value Hash A' applies to an EXCLUSIVE OR 240. The EXCLUSIVE OR 236, 238 and 240 process by bits their respective inputs. The expanded fixed key C 'is applied to an AES decryptor 242, the expanded fixed key B' is applied to an AES 244 decryptor, and the expanded fixed key A 'is applied to an AES 246 decryptor.
The first 1/4 of the encrypted MM modifier message is applied to the AES 242 decryptor, the second 1/4 of the encrypted MM modifier message is applied to the AES 246 decryptor, the third 1/4 of the encrypted MM modifier message is applied to the AES 244 decryptor , and the fourth 1/4 of the encrypted MM modifier message is applied to the AES 242 decryptor.
ES 2 398 347 T3
The AES 242 decryptor decrypts the first 1/4 and the fourth 1/4 of the encrypted MM modifier message according to the expanded fixed key C ', and supplies half of the decryption result to the EXCLUSIVE OR 236 and the other half as the third 1 / 3 of the control bits of the decrypted MM modifier message. The AES 244 decryptor decrypts one output of the EXCLUSIVE OR 236 and the third 1/4 of the encrypted MM modifier message according to the expanded fixed key B ', and supplies half of the decryption result to the EXCLUSIVE OR 238 and the other half as the second 1 / 3 of the control bits of the decrypted MM modifier message. The AES 246 cipher decrypts one output of the EXCLUSIVE OR 238 and the second 1/4 of the encrypted MM modifier message according to the expanded fixed key A ', and supplies half of the encryption result to the EXCLUSIVE OR 240 and the other half as the first 1 / 3 of the decrypted MM modifier message. The output of the EXCLUSIVE OR 240 is the initial value of the MM modifier message. If this initial value is not the same initial value that was used during the encryption of the MM modifier message, then the encryption / decryption process has an error indicating bad message decryption.
As shown in FIG. 19, a multiplexer 250 applies the control bits of the decrypted MM modifier message to a modifier message decoder 252.
Upon decryption of the MM modifier message, multiplexer 232 passes the three message segment keys A, B, and C and the three hash values A, B, and C stored in a message segment key memory 254 to key expander 234. When the MKMS modification key message segment is being decrypted, these three message segment keys are produced with the modification keys having the default value. The key expander expands only the three message segment keys A, B, and C, it does not expand the three hash values A, B, and C. The second decryption engine 186 uses the three message segment keys A, B, and C and the three hash values A, B and C to decrypt the MK1 modification key message in the received MKMs modification key message segment. As stated above, each of the three modification key messages MK1, MK2, and MK3 and the CRC checksum message has the format shown in Figure 12, and the control of each of the messages is the control key 98 indicating whether the particular message is a program key message, a modification key message, or a checksum message.
As shown in Figure 20, Hash C applies to EXCLUSIVE OR 236, Hash B applies to EXCLUSIVE OR 238, and Hash A applies to EXCLUSIVE OR 240. Expanded fixed key C applies to decryptor AES 242, expanded fixed key B is applied to decryptor AES 244, and expanded fixed key A is applied to decryptor AES 246.
The first 1/4 of the encrypted MK1 modification key message is applied to the AES 242 decryptor, the second 1/4 of the encrypted MK1 modification key message is applied to the AES 246 decryptor, the third 1/4 of the key message The encrypted MK1 modification key message is applied to the AES 244 decryptor, and the fourth 1/4 of the encrypted MK1 modification key message is applied to the AES 242 decryptor.
The AES decryptor 242 supplies half of its decryption result to the EXCLUSIVE OR 236 and the other half as the second 1/2 of the decrypted MK1 modification key. The AES decryptor 244 supplies half of its decryption result to the EXCLUSIVE OR 238 and the other half as the first 1/2 of the decrypted modification key. The AES 246 encryptor supplies half of its encryption output to the EXCLUSIVE OR 240 and the other half as the decrypted modification key control. The output of the EXCLUSIVE OR 240 is the initial value of the modify key message. If the initial value is not the same initial value that was used during the MK1 modification key encryption, then the encryption / decryption process has an error indicating the need for corrective action.
Decryption engine 186 similarly decrypts MK2 and MK3 modification key messages and CRC checksum message. The multiplexer 250 passes the checks and checksum as indicated in FIG. 19, and passes the modification keys for storage in a modification key memory 256.
Upon decryption of the received MKMS modification key message segment, the fixed key selector and message segment key generator 190 can begin generating new message segment keys that will be used to decrypt the program keys to starting from the next message segment received from the PKMS program key.
The modifier message decoder 252 decodes the received and decrypted MM modifier message in each of the message segments to determine the addresses according to the definition and format of the modifier message shown in Figures 8 and 9. The fixed key selector 260 uses these addresses to select, from memory 188, the same three keys Ka, the same three fixed keys Kb, and the same three hash values A, B, and C that were used to produce the segment keys. Messages A, B and C that were used to encrypt the PKMS and MKMS message segments in encryption encoder 8. A first key memory 262 stores the three keys Ka, a second fixed key memory 264 stores the three selected fixed keys Kb, and the message segment key memory 254 stores the three selected hash values A, B and C.
A message segment key generator 266 may have the same construction as the message segment generator.
ES 2 398 347 T3 message segment keys 90 shown in Figure 6. Consequently, latch 921 holds the first 32 bits of a first of the three fixed keys Ka stored in fixed key memory 262, latch 922 holds the first 32 bits of a first of three fixed keys Kb stored in memory of fixed keys 264, and latch 923 holds the first 32 bits of a first of the three Km modification keys stored in modification key memory 256 when the message segment keys are being produced for decrypting program keys (otherwise, the keys of modification that have the default value are used to generate message segment keys to decrypt modification keys). These 96 bits retained form a 96-bit address that read out the first 32 bits of a first message segment key for storage in message segment key memory 254.
The same table that was selected at the transmitter is selected at the receiver to provide the three message segment keys that are stored in message segment key memory 254.
After the first 32 bits of the first message segment key have been extracted from lookup table 94 and stored in message segment key memory 254, latch 921 holds the second 32 bits of the first of the three fixed keys Ka stored in fixed key memory 262, latch 922 holds the second 32 bits of the first of three fixed keys Kb stored in fixed key memory 264, and latch 923 holds the second 32 bits of the first of the three Km modification keys stored in modification key memory 256 when the message segment keys for decrypting program keys are being produced (otherwise, the keys of modification that have the default value are used to generate message segment keys to decrypt modification keys). These 96 bits retained form a second 96-bit address that read out the second 32 bits of the first message segment key for storage in message segment key memory 254.
The third and fourth 32 bits of the first of the three fixed keys Ka stored in the fixed-key memory 262, of the first of the three fixed keys Kb stored in the fixed-key memory 264, and from the first of the three modification keys Km stored in the modification key memory 256 are used to read the third and fourth 32 bits of the first message segment key from the look-up table 94 when the message segments are being produced to decrypt program keys (otherwise, Modification keys that have the default value are used to generate message segment keys to decrypt modification keys. These third and fourth 32 bits of the first message segment key are also stored in message segment key memory 254 to form all 128 bits of the first message segment key. The second and third message segment keys are similarly retrieved from lookup table 94 and stored in message segment key memory 254.
When the next PKMS program key message segment is received, the MM modifier message in the received MS message segment is decrypted as above using the fixed keys A ', B' and C 'and the hash values A', B 'and C' stored in memory 230. Subsequently, multiplexer 232 passes the three message segment keys A, B, and C and the three hash values A, B, and C from message segment key memory 254 through key expander 234 to the second delivery engine. encryption 186. Key expander 234 expands only message segment keys A, B, and C. Key expander 234 does not expand hash values A, B, and C.
In the second encryption engine 186, the Hash C value applies to the EXCLUSIVE OR 236, the Hash B value applies to the EXCLUSIVE OR 238, and the Hash A value applies to the EXCLUSIVE OR 240. The expanded fixed key C applies to the decryptor AES 242, the expanded fixed key B is applied to the decryptor AES 244, and the expanded fixed key A is applied to the decryptor AES 246.
The first 1/4 of the first encrypted KM1 program key message is applied to the AES 242 decryptor, the second 1/4 of the first encrypted KM1 program key message is applied to the AES 246 decryptor, the third 1/4 of the first message The encrypted KM1 program key message is applied to the AES 244 decryptor, and the fourth 1/4 of the encrypted KM1 program key message is applied to the AES 242 decryptor.
The AES 242 decryptor decrypts the first 1/4 and the fourth 1/4 of the first encrypted KM1 program key message according to the expanded fixed key C, and supplies half of the decryption result to the EXCLUSIVE OR 236 and the other half as the second 1/2 of the first program key of the first decrypted KM1 program key message. The AES 244 decryptor decrypts an output of the EXCLUSIVE OR 236 and the third 1/4 of the first KM1 program key message encrypted according to the expanded fixed key B, and supplies half of the decryption result to the EXCLUSIVE OR 238 and the other half as the first 1/2 of the first program key of the first decrypted KM1 program key message. The AeS 246 encryptor decrypts an output of the EXCLUSIVE OR 238 and the second 1/4 of the first KM1 program key message encrypted according to the expanded fixed key A, and supplies half of the encryption result to the EXCLUSIVE OR 240 and the other half as control of the first decrypted KM1 program key message. The output of the EXCLUSIVE Or 240 is the initial value of the first KM1 program key message. If this initial value is not the same initial value that was used during the encryption of the first KM1 program key message, then the encryption / decryption process has an error indicating the need for corrective action.
ES 2 398 347 T3
The other three program key messages KM2, KM3, and KM4 are similarly decrypted.
The multiplexer 250 of FIG. 19 passes these four program keys to the next portion of memory 192 and passes control of each of the decrypted KM1, KM2, KM3, and KM4 program key messages.
A multiplexer 270 passes the active program keys, using the rotation discussed above in connection with Figures 15 and 16, through a key expander 272 to decryption block 210 so that the appropriate data can be decrypted. Key expander 272 can be constructed according to Figure 4. As in the case of key expander 70, key expander 272 also includes a reverse key block. This reverse key block is disabled during program decryption and enabled during decryption of the PKMS program key message segment and the MKMS modification key message segment.
While decryption block 210 is using the active keys from the active part of memory 192 to decrypt data, the next program keys are received and stored in the next part of memory 192.
The modifier message decoder 252 also decodes all system control of the received and decrypted modifier message MM. As discussed earlier, the MM modifier message system control is shown in Figure 9. Consequently, the modifier message decoder 252 applies the same CRC code as the encoder to bits 0-15 of the MM modifier message system control in the received PKMS or MKMS message segment in order to recalculate the bits. 16-31 checksum. The receiver compares the recalculated checksum of bits 0-15 with checksum bits 16-31 in the received system control. If the recalculated checksum of bits 0-15 with received checksum bits 16-31 do not match, the received message segment is treated as the next message segment expected to be received in the sequence of segments messages received.
In addition, modifier message decoder 252 uses decoded bits 12-15 of system control to determine the program key rotation that decryption block 210 should use to decrypt encrypted program packets as shown by the extending line from modifier message decoder 252 to control of multiplexer 270 which selects the next active key to be used.
Certain modifications of the present invention have been discussed above. Other modifications of the present invention will occur to those skilled in the art of the present invention. For example, the memories as described above can be non-volatile ROM, RAM, RAM, and / or any other suitable memory device.
Furthermore, as previously disclosed, a 96 x 32 lookup table 94 is used to produce the message segment keys. Consequently, the 96 address bits are used to read 32 bits of a message segment key. Instead, other lookup tables and address schemes can be used to produce the message segment keys. For example, a 384 x 128 look-up table can be used to produce the message segment keys. Consequently, the 384 address bits comprising 128 bits of Km, 128 bits of Ka, and 128 bits of Kb are used to read a 128-bit message segment key. Regardless of which look-up table and addressing scheme is used at the transmitter, the same look-up table and the same addressing scheme must be used at the receiver.
Contents6
11 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11
53 members in 9 offices
Priority claims25
| Document | Office | Kind | Date |
|---|---|---|---|
| 137272 | United States of America | – | |
| 13727205 | United States of America | A | |
| 13727205 | United States of America | A | |
| 342460 | United States of America | – | |
| 34246006 | United States of America | A | |
| 34246006 | United States of America | A | |
| 342479 | United States of America | – | |
| 34247906 | United States of America | A | |
| 34247906 | United States of America | A | |
| 343060 | United States of America | – | |
| 34306006 | United States of America | A | |
| 34306006 | United States of America | A | |
| 342472 | United States of America | – | |
| 34247206 | United States of America | A | |
| 34247206 | United States of America | A | |
| 137272 | – | – | – |
| 342460 | – | – | – |
| 342472 | – | – | – |
| 342479 | – | – | – |
| 343060 | – | – | – |
| US20050137272 | – | – | – |
| US20060342460 | – | – | – |
| US20060342472 | – | – | – |
| US20060342479 | – | – | – |
| US20060343060 | – | – | – |
Members53
| Document | Office | Kind | |
|---|---|---|---|
| US861891A | United States of America | A | |
| CA2609505A1 | Canada | A1 | |
| CA2854952A1 | Canada | A1 | |
| CA2856945A1 | Canada | A1 | |
| CA2862725A1 | Canada | A1 | |
| CA2868652A1 | Canada | A1 | |
| CA2873159A1 | Canada | A1 | |
| CA2876882A1 | Canada | A1 | |
| CA2882912A1 | Canada | A1 | |
| US2006269063A1 | United States of America | A1 | |
| US2006269067A1 | United States of America | A1 | |
| WO2006127405A2 | World Intellectual Property Organization (WIPO) | A2 | |
| US2006280298A1 | United States of America | A1 | |
| US2007058813A9 | United States of America | A9 | |
| WO2006127405A3 | World Intellectual Property Organization (WIPO) | A3 | |
| US2007189529A1 | United States of America | A1 | |
| US2008013731A1 | United States of America | A1 | |
| EP1889478A2 | European Patent Office (EPO) | A2 | |
| KR20080026100A | Republic of Korea | A | |
| CN101213839A | China | A | |
| HK1112699A1 | Hong Kong, China | A1 | |
| US2009169002A1 | United States of America | A1 | |
| US2009208009A1 | United States of America | A1 | |
| US2010067700A1 | United States of America | A1 | |
| US2010067704A1 | United States of America | A1 | |
| CN101213839B | China | B | |
| EP2219376A1 | European Patent Office (EPO) | A1 | |
| US7929704B2 | United States of America | B2 | |
| US7936870B2 | United States of America | B2 | |
| EP1889478B1 | European Patent Office (EPO) | B1 | |
| AT515885T | Austria | T | |
| ATE515885T1 | Austria | T1 | |
| EP1889478B8 | European Patent Office (EPO) | B8 | |
| US8054974B2 | United States of America | B2 | |
| ES2368580T3 | Spain | T3 | |
| US8144868B2 | United States of America | B2 | |
| US8189786B2 | United States of America | B2 | |
| EP2219376B1 | European Patent Office (EPO) | B1 | |
| KR20120135430A | Republic of Korea | A | |
| US8345877B2 | United States of America | B2 | |
| ES2398347T3This record | Spain | T3 | |
| US8401189B2 | United States of America | B2 | |
| KR101248218B1 | Republic of Korea | B1 | |
| KR101260387B1 | Republic of Korea | B1 | |
| US8442226B2 | United States of America | B2 | |
| CA2854952C | Canada | C | |
| CA2856945C | Canada | C | |
| CA2609505C | Canada | C | |
| CA2862725C | Canada | C | |
| CA2868652C | Canada | C | |
| CA2882912C | Canada | C | |
| CA2876882C | Canada | C | |
| CA2873159C | Canada | C |
Numbers
- Publication
- 2398347
- Publication, DOCDB
- 2398347
- Publication, EPODOC
- ES2398347T
- Application
- 10162797
- Application, DOCDB
- 10162797
- Application, EPODOC
- ES20100162797T
Titles2
- Spanish
- Cifrado/descifrado de datos de programa pero no de datos PSI
- English
- Encryption / decryption of program data but not PSI data
Classification
- CPC, 10
- H04N7/1675
- H04N21/2347
- H04N21/23476
- H04N21/2362
- H04N21/26606
- H04N21/4345
- H04N21/4405
- H04N21/44055
- H04N21/835
- H04L9/08
- IPC, 2
- H04N7 167
- H04L9 08