IL152435A

Secure digital content delivery system and method over a broadcast network

Abstract

This record has no abstract on file.

IL152435A, drawing sheet 1
Sheet 1 of 8

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

77 claims: 12 independent, 65 dependent

  1. 1
    WHAT IS CLAIMED IS:1. A method for creating a secure transmission mechanism for a plurality of end user devices in a packet-based network, comprising: providing a plurality of packets;securing said plurality of packets according to security information to form secured packets;transmitting said security information to more than one end user device simultaneously through the packet-based network;and multi-casting said secured packets to the plurality of end user devices.
  2. 3
    The method of claims 1 or 2, wherein said packets are distributed through a second distribution channel, said second distribution channel being different from the packet-based network.
  3. 5
    The method of claims 1 or 2, wherein said packets are distributed through the packet-based network.
  4. 6
    The method of any of claims 1 - 5, wherein said security information includes control word information for key generation at each end user device.
  5. 8
    9. The method of claim 8, wherein said EMM is transmitted to said end user devices by an out-of-band message, such that said EMM is not transmitted with said secured packets.
  6. 9
    10. The method of claim 9, wherein said out-of-band message is an e-mail (electronic mail) message.
  7. 10
    11. The method of claims 8-10, wherein the packet-based network is an IP network and said ECM is transmitted through said IP network according to at least one of a multicast IP address and an IP port, such that said end user device is notified of said at least one of said multicast IP address and said IP port through an IP notification protocol.
  8. 11
    12. The method of any of claims 8-11, wherein said end user device filters at least one of said ECM and said EMM according to at least one characteristic selected from the group consisting of a characteristic of said end user device and a characteristic of information stored by said end user device.
  9. 12
    13. The method of claim 12, wherein said end user device filters said ECM according to EMM information, such that only an ECM for which EMM information has been received is accessed by said end user device.
  10. 13
    14. The method of claim 13, wherein said ECM is contained in a packet, and an IP address for said packet is announced to said end user device, such that said end user device filters said ECM by listening to said IP address for receiving said packet if said end user device has received said EMM information.
  11. 15
    16. The method of any of claims 8-15, wherein said EMM information includes a service identifier, and wherein said service identifier is related to a type of content of said secured packets.
  12. 16
    17. The method of claim 16, wherein said secured packets contain a plurality of different types of content, each type of content having a separate service identifier, such that differential access to said different types of content by said end user device is provided according to said service identifiers.
  13. 17
    18. The method of claims 16 or 17, wherein said service identifier corresponds to a plurality of ECMs.
  14. 18
    19. The method of any of claims 8-18, wherein said EMM information includes an identifier for determining access to said secured packets according to at least one characteristic selected from the group consisting of a characteristic of an end user device and a characteristic of information stored on said end user device.
  15. 19
    20. The method of claim 19, wherein said identifier is a blackout identifier for identifying an end user device blocked from accessing a content of said ECM.
  16. 20
    21. The method of claim 20, wherein said blackout identifier corresponds to at least one characteristic stored in said end user device.
  17. 21
    22. The method of claim 21, wherein said at least one characteristic includes a geographical location of said end user device.
  18. 22
    23. The method of any of claims 8 - 22, wherein said ECM enables differential access to said secured packets by said end user device according to a plurality of identifiers transmitted in said EMM.
  19. 23
    24. The method of any of claims 8-23, wherein said end user device stores at least a content of at least one of said ECM and said EMM.
  20. 24
    25. The method of claim 24, wherein said ECM has a limited key period, such that a new ECM is periodically received to access said plurality of packets.
  21. 25
    26. The method of claim 25, wherein a length of said key period is at least partially determined by a length of a session for receiving said secured packets by said end user device.
  22. 26
    27. The method of claim 26, wherein said length of said key period is less than said length of said session, such that at least one of a new ECM and a new EMM must be received repeatedly during said session.
  23. 27
    28. The method of claim 27, wherein said EMM has a limited authorization period, such that a new EMM is periodically received to access said plurality of packets.
  24. 28
    29. The method of any of claims 7 - 28, wherein at least a portion of said secured packets are accessible with said ECM only, without said EMM, as a preview of said secured packets.
  25. 29
    30. The method of any of claims 8 - 29, wherein said security information is transmitted according to a standard IP protocol.
  26. 30
    31. The method of claim 30, wherein said packets are transmitted as part of a multi-cast session, and wherein an announcement for said session is transmitted according to a standard announcement protocol.
  27. 31
    32. The method of claims 30 or 31, wherein said standard IP protocol is IPSEC .
  28. 32
    33. The method of claim 32, wherein said announcement includes information for relating each ECM to a service identifier contained in an EMM.
  29. 33
    34. The method of claim 33, wherein said announcement protocol is SDP (session description protocol).
  30. 34
    35. The method of claims 33 or 34, wherein said ECM is associated with at least a portion of a multi-cast session with said end user device, and wherein said association is transmitted in said secured packets as an attribute parameter.
  31. 35
    36. The method of claim 35, wherein said ECM is synchronized with said secured packets with an SPI (security parameters index) value of said secured packets.
  32. 36
    37. The method of claim 36, wherein a new key period is indicated by a change in said SPI value, such that a new ECM is required to access said secured packets.
  33. 37
    38. The method of any of claims 31 - 37, wherein announcement packets are encrypted.
  34. 38
    39. The method of any of claims 19 - 38, wherein said end user device is blocked from further access to said secured packets through revocation with at least one of an EMM and an ECM.
  35. 39
    40. The method of claim 39, wherein said revocation is for a specific end user device.
  36. 40
    41. The method of claim 40, wherein said revocation is for a plurality of end user devices.
  37. 41
    42. The method of any of claims 39-41, wherein said revocation causes a new service identifier to be required for accessing a content of an ECM corresponding to said secured packets.
  38. 42
    43. The method of any of claims 8 - 42, wherein said end user devices receive at least said secured packets from at least one peer end user device.
  39. 43
    44. The method of claim 43, wherein said at least one peer end user device generates at least one of said EMM and said ECM.
  40. 44
    45. The method of claim 44, wherein said at least one peer end user device includes a secure server for generating said least one of said EMM and said ECM.
  41. 45
    46. The method of claims 44 or 45, wherein said EMM generated by said at least one peer end user device is authenticated by a central authorization entity.
  42. 46
    47. The method of claims 44 - 46, wherein said EMM generated by said at least one peer end user device is mapped to a new ECM for accessing said secure packets by a central authorization entity.
  43. 47
    48. The method of any of claims 44 - 47, wherein said packets are transmitted as part of a multi-cast session, an announcement for said session is transmitted according to a standard announcement protocol, and said announcement includes at least an SPI (security parameters index) for relating each ECM to a service identifier contained in an EMM, such that said at least one peer end user device generates at least one of said announcement and said SPI.
  44. 48
    49. The method of any of claims 37 - 48, wherein said central authorization entity controls at least one of said ECM, said EMM, said announcement and said SPI.
  45. 49
    50. The method of any of claims 37 - 49, wherein at least one of said EMM and said ECM is generated by said central authorization entity.
  46. 50
    51. The method of any of claims 37 - 50, wherein said end user devices are located in a cluster, and wherein each cluster is coordinated by said central authorization entity.
  47. 51
    52. The method of claim 51, wherein said cluster is continuously validated by said central authorization entity.
  48. 52
    53. The method of any of claims 7 - 52, wherein a pay-per-view ECM contains purchasing information for purchasing access to said secured packets and wherein EMM information is not required to access said pay-per-view ECM.
  49. 53
    54. The method of any of claims 7 - 52, wherein an EMM contains a credit for purchasing access to said secured packets for pay-per-view content.
  50. 54
    55. A secure transmission mechanism produced by the method of any of claims 1 - 54.
  51. 55
    56. A method for producing a conditional access (CA) system for use in a packet-switched environment (packet CA system) from a CA system for use in a broadcast environment (broadcast CA system), the method comprising:providing a broadcast CA system comprising at least one CA security characteristic;providing a packet-switched data transmission system including a security subsystem having a plurality of packet-switched security characteristics;and creating a mapping from the at least one CA security element to at least one of the plurality of packet-switched security elements, thereby producing a packet CA system.
  52. 56
    57. The method according to claim 56 and wherein the packet-switched data transmission system comprises an IP system.
  53. 57
    58. The method according to claim 57 and wherein the IP system comprises an IPSEC subsystem, and the IPSEC subsystem comprises the plurality of packet-switched security elements.
  54. 58
    59. The method according to any of claims 56 - 58 and wherein the broadcast CA system comprises an EMM / ECM based CA system.
  55. 59
    60. A conditional access (CA) system for use in a packet-switched environment (packet CA system) produced by the method of any of claims 56 - 59.
  56. 60
    61. A packet-switched conditional access (CA) system for use with an end-user playback device, the CA system comprising:a protected data receiver for receiving protected data protected with at least one key;an ECM packet receiver for receiving at least one ECM packet from a packet-switching network;and an ECM-based key generator for generating said at least one key from said at least one ECM packet.
  57. 61
    62. The system according to claim 61 and also comprising:a key synchronizer for synchronizing said at least one key generated by the ECM-based key generator with a portion of said protected data protected with said at least one key generated by the ECM-based key generator.
  58. 62
    63. The system according to claim 62 and wherein the key synchronizer comprises:an ECM memory for storing a plurality of ECM packets;and an ECM packet chooser for choosing, from among the plurality of ECM packets stored by the ECM memory, an ECM packet corresponding to said portion of said protected data and sending said chosen ECM packet to said ECM-based key generator.
  59. 63
    64. The system according to any of claims 61-63 and wherein the ECM packet receiver comprises an IPSEC receiver for receiving the at least one ECM packet from the packet-switching network using an IPSEC protocol.
  60. 64
    65. A method for providing an entitlement control message (ECM) based conditional access (CA) system based on a packet-switching network comprising:receiving a plurality of ECMs via the packet-switching network;storing the plurality of received ECMs;and choosing, from among the plurality of stored ECMs, an ECM for providing access to CA-protected data.
  61. 65
    66. The method according to claim 65 and wherein the CA-protected data comprises encrypted data, and the method also comprises:utilizing the chosen ECM to decrypt the encrypted data.
  62. 66
    67. The method according to claim 66 and wherein the utilizing comprises:generating, from the ECM, a key for decrypting the encrypted data.
  63. 67
    68. The method according to claim 67 and wherein the generating comprises, at least in part:utilizing at least a portion of the ECM as an input to a one-way function;and utilizing an output of the one-way function as at least a portion of the key.
  64. 68
    69. The method according to any of claims 65 - 68 and wherein the packet-switching network comprises an IP-based network.
  65. 69
    70. The method according to claim 69 and wherein the IP-based network comprises an IPSEC-based network.
  66. 70
    71. The method according to claim 70 and wherein the plurality of ECMs are delivered using an IPSEC-based protocol.
  67. 71
    72. A method for creating a secure transmission mechanism for a plurality of end user devices in an IP network, comprising:providing a plurality of data units for transport through the IP network;securing said plurality of data units according to security information to form secured data units;transmitting said security information to more than one end user device simultaneously through the IP network;transmitting an announcement according to SDP (session description protocol) of IPSEC to said end user devices for indicating an association between said security information and said secured data units;and multi-casting said secured data units to the plurality of end user devices.
  68. 72
    73. The method of claim 72, wherein said security information is related to a key for securing said secured data units, said key being changed according to a key period, a change of said key period being announced by an SPI (security parameters index) in a security information message according to ESP (IP encapsulating security payload) protocol.
  69. 74
    75. Apparatus according to any of claims 55 and 62 - 64 and substantially as described hereinabove.
  70. 75
    76. Apparatus according to any of claims 55 and 62 - 64 and substantially as shown in the drawings.
  71. 76
    77. A method according to any of claims 1 - 54, 56 - 61, and 65 - 74 and substantially as described hereinabove.
  72. 77
    78. A method according to any of claims 1 - 54, 56 - 61, and 65 - 74 and substantially as shown in the drawings. ^^^^־־־׳-^^'־־-־
Independent claims72