Method and apparatus for controlling distribution of digitally encoded data in network
Abstract
Problem to be solved.To provide an apparatus and method for controlling distribution of digital content from a device connected to a network to another device outside the network.
Solution.The method comprises the steps of: receiving location information of a router on the network for routing content to devices outside the network; receiving destination data indicative of location information associated with a destination device to which the device intends to distribute the content; determining whether the destination device is outside the network based on the router location information and the received destination data; examining the authorization field and inhibiting transmission of the content if the destination device is outside the network and the digital signal is in the inhibition mode.
Copyright (C)2010,JPO&INPIT
Term
Projected expiry 8 March 2030.
- Priority
- Filed
- Published
- Today
- Projected expiry
1 claim: 1 independent, 0 dependent
- 1A method of controlling the distribution of data from the device to the destination device via the network in a device connected to the network, which is a digital signal representing program content and the digital outside the network. A step of receiving the digital signal having an authentication field indicating a first transport mode that allows the distribution of the signal and a second transport mode that prohibits the distribution of the digital signal outside the network. The step of determining whether the destination device to which the digital signal is distributed is outside the network, and whether the authentication field indicates the first or second transport mode. When it is determined that the determination step and the authentication field indicate the second transport mode and the destination device is outside the network, transmission of the digital signal is prohibited. A method comprising, the step of transmitting the digital signal to the destination device, if it is determined to be the other case. ネットワークに接続された装置に於いて、前記ネットワークを介して前記装置から宛先装置へのデータの配信を制御する方法であって、 プログラム・コンテンツを表すディジタル信号であり、前記ネットワーク外への前記ディジタル信号の配信を許可する第1のトランスポート・モードと、前記ネットワーク外への前記ディジタル信号の配信を禁止する第2のトランスポート・モードとを示す認証フィールドを有する前記ディジタル信号を受信するステップと、 前記ディジタル信号が配信される前記宛先装置が前記ネットワーク外に在るか否かを判断するステップと、 前記認証フィールドが、前記第1または第2のトランスポート・モードの何れを示しているかを判断するステップと、 前記認証フィールドが、前記第2のトランスポート・モードを示しており、且つ、前記宛先装置が前記ネットワーク外に在ることが判断されると、前記ディジタル信号の送信を禁止し、その他の場合であることが判断されると、前記ディジタル信号を前記宛先装置に送信するステップと、を含む、方法。
34 paragraphs, as filed
(Related application) This application was filed on June 7, 2002, under 35 U.SC (US Patent Law), paragraph 119, and the title of the invention is "Proposal on the Use of the BPDG." It claims the priority of provisional patent application No. 60 / 387,054, which is "Broadcast Flag)".
The present invention generally relates to communication systems, and more particularly to systems and methods for preventing unauthorized distribution of content to remote network locations.
Content creators and content providers, such as movie studios, productions (movie, record production companies), Internet service providers (ISPs), etc., have their own investment targets, such as movies, programs, services, software. Etc. need to be protected. Such content is generally available through terrestrial broadcasts, premium programming (separately charged programming), cable channels, satellite channels, pay-per-view, video cassette retailers, and video cassette rentals. Delivered to consumers.
In terrestrial broadcasting, program content is transmitted in digital format to an access device, such as a digital receiver. Due to the characteristics of digital storage and the characteristics of digital transmission, it is possible to make endless copies with the same quality as the original master. In addition, without encrypting the signal, the received content is easily copied and another product or device that is not authorized to receive such content or is not intended to receive such content. May be transferred to. In addition, products with digital outputs can accommodate the convenience of networked systems, high quality recording of data, and data retransmission. Home networks that receive content for display or recording also need to protect it from unauthorized copying and distribution.
Broadcast Flag (BF) is a digital signal, eg, video, to identify that transmitting digitally encoded data (eg, video content) out of the receiver's own network is prohibited. It has been proposed to insert it in the broadcast stream. As used herein, the term "content" includes the meaning of digital signals, i.e., digitally encoded data, used to deliver program content. The above flag is inserted into the PMT (Program Map Table) / EIT (Event Information Table) field of the MPEG-2 transport stream, for example, as a field consisting of one bit or a plurality of bits. However, there is currently no mechanism to prevent networks such as home networks from sending content out of the network according to this flag.
One feasible solution is to insert a new flag in another part of the digital signal, eg, an Ethernet® header to prevent the content from being forwarded to the outside router, cable modem. And so on. As another proposal, there is also a method of using only a protection interface (encrypted data interface), for example, 5C compatible IEEE1394, HDCP (High-bandwidth Digital Control Protection) compatible DVI (Digital Visual Interface), or the like. However, implementing these has the drawback of increasing the cost of changing the infrastructure of existing and future home networks. Moreover, such infrastructure changes significantly impede consumers' tendency to use their home networks to deliver content to other electronic devices in the home, resulting in home users. It will curb the very promising market for electronic devices and curb content distribution within home networks.
(Outline of the invention) The present invention provides a method of controlling the distribution of digitally coded content from an access device connected to a network to another device outside the network. The access device receives a digital signal representing the program content. This digital signal has authentication fields indicating a first transport mode that allows distribution of content outside the network and a second transport mode that prohibits distribution of content outside the network. The method of the present invention is a step of receiving the location information of a router on the network used to route the content to each device outside the network, and a position corresponding to the destination device to which the access device intends to deliver the content. The step of receiving destination data indicating information, the step of determining whether the destination device is outside the network based on the location information of the router and the received destination data, and the step of examining the authentication field, the destination device is networked. It is determined whether or not the user is outside, and whether or not the transport mode allows or prohibits the distribution of the content outside the network, and the content is determined according to the result of the determination. Includes steps to control the delivery of.
As another feature, the present invention provides a device that is connected to a network and distributes content to at least one other device. The access device receives a digital signal that represents the program content. This digital signal includes a first transport mode in which distribution of the digital signal is permitted outside the network and a second transport mode in which distribution of the digital signal is prohibited outside the network. Contains an authentication field that indicates. This device includes a memory that stores a computer code for performing a transmission operation that transmits data over the network, and a data storage means that stores the address information of each device connected to the network. It includes a processor that controls transmission and reception operations, and a data interface means that is connected to a network, receives data from each device connected to the network, and distributes a digital signal over the network. The processor prohibits the transmission of digital signals over the network when it is determined that the other device is outside the network and the authentication field indicates a second transport mode, and others. When is determined, the digital signal can be transmitted over the network.
<figref num="1">FIG. 1 is a block diagram of a home network system embodying one feature of the present invention.</figref><figref num="2">FIG. 2 is a block diagram illustrating the main functional components corresponding to the propagation and reception of packets representing video frame transport stream information.</figref><figref num="3">FIG. 3 is a block diagram of the transport stream.</figref><figref num="4A">FIG. 4A illustrates the association between PAT and PMT, including broadcast flag authentication fields in the transport stream.</figref><figref num="4B">FIG. 4B illustrates an EIT that includes a broadcast flag authentication field in the transport stream.</figref><figref num="5">FIG. 5 is a flowchart showing an example of a method of performing an operation according to an embodiment of the present invention.</figref>
Figure 1 shows the home network system 10. In this system, multiple access devices 20, 30, 40, 50, and 60 are connected through a home network 70, such as an Ethernet network, and further through an Ethernet switch 80. Connected to router / gateway device 90. The home router 90 allows a number of external service providers (eg, the Internet 100) and remote devices (eg, electronics 110 and optional modem 95) outside the home network to communicate with the home network 70. Connect to. For example, the router 90 transmits media programs from terrestrial broadcasting sources, satellite broadcasting, cables, etc. to corresponding interfaces (for example, terrestrial broadcasting I / F, satellite I / F, ADSL (Asynchronous Digital Subscriber)). It can be received and transferred via Line) I / F, etc.). Note that the router 90, for example good of MPEG-2 via the UNA appropriate protocol, can be performed with IP routing and transport stream routing of data packets for various household electrical electronic equipment inside and outside the home network ..
In the embodiment shown in FIG. 1, the router 90 is a normal router device and has a mapping table for mapping device IP addresses to physical addresses in order to route data inside and outside the home network. The access devices 20 to 60 located in the home network 70 are any number of home electronic devices of any kind, such as servers, digital televisions, digital monitors, MP3 devices, DVD devices, printers. , Print servers, personal computers (PCs), etc., but are not limited to these. In the embodiment of FIG. 1, device 20 is a television device such as an HDTV and is a media renderer (media) via bus 25. Renderer) Connected to device 30 (eg, Replay 4000). The home network system 10 illustrated in FIG. 1 further includes a media server 40, an MP3 network player 50, and a personal computer (PC) 60. Each of these devices has a corresponding IP address, physical address, and subnet mask, as is well known to those of skill in the art.
Router 90 operates to receive a digital signal, such as an MPEG-2 open terrestrial broadcast signal, and transfer it to a suitable receiver on the home network. It should be noted that other terrestrial broadcast signals such as MPEG-1, MPEG-4, JPEG and the like can also be received, processed and transferred to the home network 70.
Each receive / access device in the home network receives and decodes packetized data, such as an MPEG-2 transport stream, containing audio / video / data content, with appropriate hardware and / or software features. It is configured to do. The compression algorithm at the broadcaster reduces the bandwidth required for the transmission medium and maintains good video quality at the receiver.
FIG. 2 shows a configuration example in which video frame content is transmitted by packet over the Ethernet® packet network 70 illustrated in FIG. Each video frame generated by a standard source (not shown) is exemplified as a video frame 210 that is an input to transmitter 201. The video frame 210 is compressed by the encoder 220 according to the encoding program stored in the program memory 225, and its encoded output 221 is formatted into packets 231 by the data packetizer 230. The transmitter processor 235 controls the interaction between the encoder 220 and the program memory 225 and provides the control information necessary to form the packet 231. Packet 231 is transmitted over network 70 and detected by an access device (eg, 30), where the access device's data extractor 250 processes packet 231 to receive compressed output 221 in transmitter 201. Generates the data stream 251 which is the counterpart. The decoder 260 decompresses and decodes this data stream 251 to generate receive frame 211 corresponding to the content contained within the video frame 210.
In this embodiment, the data packetizer 230 generally contains elements corresponding to the MPEG-2 standard, and (a) generates an elementary stream (ES) of the encoded video. MPEG to be transferred over network 70 by (b) generating a Packetized Elementary Stream (PES) from the base stream and (c) generating a transport stream from one or more PESs. -2 Extract packet 231. In the processing of the coded video, information for restoring the frame on the receiving side is added. This information includes, for example, timing information (eg, presentation time stamp (PTS) and decode time stamp (DTS)), clock reference information (eg, PCR), and PMT (Program Map Table) / EIT. <Event Information Table> Contains data. Therefore, in general, the data packetizer 230 converts the encoded video into a transport stream, which contains all the information needed to reconvert the transport stream and extract the content. include.
In the home network system 10 illustrated in FIG. 1, one or more addressing devices (20, 30, 40, 50, 60) receive content transmitted by an MPEG-2 transport stream. And, the content can be transmitted to another device located in the home network 70 or outside the home network 70, that is, redistributed. This transmission is done using a "protocol stack", which is the "application / service" level layer for generating encoded MPEG-2 audio / video / data stream packets. Applications and headers (eg RTP (Realtime Transport Protocol) headers, UDP (User Datagram) By adding a Protocol) header), a "transport" level layer application for encapsulating each packet in an MPEG-2 stream, and by adding IP header information, including, for example, routing information or rerouting information. Includes a "network" level layer application for further encapsulating the layers of. A "data link" level layer application also performs error control and access control and further encapsulates the resulting packet, for example by adding an Ethernet® header. Also, the "physical" level layer application makes the actual transmission at the bit level.
In one configuration, the access device 30 is exemplified by the transmitter 201 of FIG. 2 which, in addition to the receiving function, transmits, that is, redistributes, the content received in the transport stream to another device. Each functional element is also included.
As one feature of the present invention, when the access device in the home network receives the terrestrial broadcast signal as described above, the content contained in the broadcast signal is transmitted in the network via the home router. It has a function that can be distributed to another device outside the network. However, for example, depending on the type of content, it may be desirable to have some restrictions on the redistribution of content to other devices outside the home network.
A feature of the present invention is that the functionality provided within the access device itself at the software application level is included as part of the transport stream packet without the need to modify the infrastructure of the home network environment. Determine if the content can be delivered outside the network based on the flag.
In this home network configuration, the home router is, for example, a network address translation (Network Address) specified in RFC (Request For Comments) 3022. It can be configured to do Translation: NAT). The router receives the packet and looks up the destination IP address of the packet. Based on the subnet mask and its local IP address, the router determines whether the packet is directed to the home network or to a destination device outside the home network. To do. If the packet is destined for a destination outside the home network, the router assigns its public IP address to the source IP address field of the packet and then forwards the packet to an external address. .. When responding, the destination device responds to the public IP address of the router. The router receives the response and maps it to the request to determine which device in the home network made the original request. The router puts the local IP address of the destination device in the destination field and forwards it to the device that originated the original request.
According to the configuration shown in FIG. 1, each device on the Ethernet® network has a physical address and an IP address. As shown in FIG. 3, in one embodiment, the terrestrial broadcast signal 300 consisting of the MPEG-2 transport stream directed to the access device 30 (FIG. 1) in the home network 70 has a header / A payload pair, that is, a header 301 and its associated payload 302, a header 303 and its associated payload 304, and the like are included. The header 301 is generally 4 bytes in length and the payload 302 is 184 bytes. The transport stream 300 is emitted by the data packetizer 230 in FIG. Each header has a PID (Packet) IDentifier) Contains various header information including field data. In addition to the reference information, the payload also consists of compressed video (or, in other applications, audio, data, and teletext / closed captioning) components. Packet 302 contains Program Association Table (PAT) information that associates a PID with a given program, a set of streams, in a common timebase, as well as more detailed reference information. It also contains program map table (PMT) information that further specifies the mapping between the encoded video stream and the actual packet prepared for transmission, and the transport stream on the receiving side. Is used to properly decrypt. FIG. 4A shows a configuration example linking a given PID 110 to the corresponding PAT 320 and PMT 420.
For each line, the PMT420 shows the stream identifier, the type of signal (eg, video, audio, data), the PID assigned to that type by source (source), and the authentication field 430. This authentication field is, for example, the Broadcast Flag (BF), a redelivery control descriptor, intended to represent information downstream of the application regarding permission to redistribute content in a video broadcast stream. It is inserted in the broadcast stream. In one embodiment, the broadcast flag (BF) is one bit in the PMT field of the MPEG-2 transport stream, as shown in Figure 4A. However, additional bits may be added to communicate additional information, for example for processing by the access device.
According to the default rules, a BF bit value of "0" is allowed to redistribute the content in the transport stream packet to devices outside the home network (ie, "transport". Mode ") is shown. Conversely, a BF bit value of "1" indicates that the content in the transport stream packet is not allowed to be redistributed outside the home network (ie, "prohibited mode").
Alternatively, another field in the broadcast stream, for example, the event information table (EIT) 450 shown in FIG. 4B, contains a broadcast flag (BF) for permission to redistribute. The EIT example shown in FIG. 4B shows the target program (PID) and its broadcast start time and broadcast duration, along with the BF flag (430) for permission to redeliver. The EIT may be multiplexed in the transport stream so that it can be received and decrypted by the access device. In one embodiment, for terrestrial broadcasting, the BF flag is included in both the EIT and PMT, and for cable transmission, for example, the BF flag is included in the PMT according to a given protocol (eg, ATSC standard). When an EIT is sent, it may be included in the EIT. The BF flag may appear periodically in the transport stream.
According to one feature of the invention, when an access device receives a broadcast signal and decodes a transport stream, it parses the PMT / EIT field to re-parse the content out of the home network. Determines the status of BF flag 430, which indicates whether distribution is permitted. The software application module, or hardware circuit, examines the received payload data and configures the BF flag to play based on its corresponding table entry and position in the transport stream. You may.
FIG. 5 shows a method of prohibiting unauthorized redistribution of content as an embodiment of the present invention corresponding to the home network system of FIG. The access device 30 (Fig. 1) is connected to the Home Ethernet® network 70 to receive an incoming audio / video / data broadcast stream (step 500) and to replay the content contained in that broadcast stream. When transmission, that is, redelivery operation is possible, the operation described below is performed before redistributing the received content.
The access device performs ARP (Address Resolution Protocol) on the router IP address to obtain the location information corresponding to the gateway / router 90, that is, the physical address of the router (step 505). This physical address is then stored in memory (step 510). Content to be sent in packet form to the destination device (destination device) is formatted according to the default format and rules (steps 515, 520). The access device broadcasts a location request (request) to the destination device to which it intends to send content (step 525). This is achieved by broadcasting ARP for the destination IP address to obtain the physical address of the destination device. When the destination device is on the home network, it responds to the request (request) of the access device by returning its physical address to the access device.
Upon receiving the broadcast ARP message, Router 90 tells whether the destination IP address is in the local subnet, the portion of the address masked by the subnet mask, and the self masked by the same subnet mask. Judgment is made by comparing with the address part of (step 530). When Router 90 determines that the destination device is outside the local network, it returns its physical address in place of the requested remote destination IP address (step 535).
The access device 30 receives the response to the request (request) of the location information of the destination device, and stores the physical address returned in response to the ARP (step 525) and the memory in advance (step 505). ) Compare with the physical address of router 90 (step 540). If the returned physical address is the same as the gateway address stored in memory (step 545), the packet to be sent is destined for a device outside the local home network. In this case, the access device parses the PMT payload field and restores the broadcast flag to determine if the flag is set (step 550). If the flag is set (ie, the flag indicates that external network distribution of the content is not allowed), the access device should discard the packet (step 555) and process it in the following format: Wait for a data packet (step 515).
If the broadcast flag is not set in the transport stream packet (step 550), the access device completes formatting the packet and sends the packet to router 90 so that the content is home. Routed to a destination device outside the network (step 560). Also, the access device has a physical address returned in response to the ARP broadcast that is different from the physical address corresponding to router 90 (steps 540, 545), so the destination device is in the home network and in the local environment. As soon as it is determined that the redelivery of is permitted, packet formation and transmission to the destination device are completed.
The present invention is embodied in machine executable software instructions within an access device and is implemented by a processor that executes each instruction within a processing system. In other embodiments, the present invention can be practiced using a hardwired circuit instead of each software instruction or in combination with each software instruction. Each computer instruction embodying the present invention is to be loaded into memory from persistent storage means, such as mass storage, or from one or more other computer systems over a network. It may be. For example, in each embodiment, the execution of the download of each instruction described above may be directly supported by the microprocessor and may be executed directly by the processor. Alternatively, the execution of each instruction may be performed by the microprocessor operating an interpreter that interprets each instruction, or by the microprocessor executing each instruction, in this case. Each instruction is translated into a format that the microprocessor can directly execute. Therefore, the present invention is not limited to a specific combination of hardware circuits and software, nor is it limited to a specific source for each instruction executed by the access device.
As described in each embodiment, the present invention takes advantage of the differences between IP addresses on the local network and IP addresses outside the local network, and the distinction between these address spaces is the subnet mask and gateway. It can be judged by the address. The mechanism implemented by the present invention parses the packet information in the transport stream to determine if the broadcast flag is set and the application is identified locally by the subnet mask and gateway address. -Prohibit unauthorized redistribution of content by preventing content from being transferred to IP addresses outside the subnetwork.
Although the present invention has been described for each embodiment, the present invention is not limited to these examples. For example, to increase the level of security, home networks may use non-routable IP addresses (ie, private addresses). That is, a specific IP address is specified according to certain standards and rules, such as the IETF standard. Therefore, the mapping table for each Internet router (eg, the router device in Internet 100 in FIG. 1) does not include non-routable addresses. Therefore, if unauthorized content is inadvertently or accidentally delivered outside the home network, those routers that receive this information will direct the content to its intended destination (non-routable address). Cannot be transferred to, therefore delete the packetized data. If additional protection is desired, authentication mechanisms and cryptographic protocols can be used to further enhance security to prevent unauthorized access to certain protected content and its unauthorized redistribution. An access device that attempts to transfer content over a home network may also ensure that the application to which it wants to transfer the content is a reliable and compliant application. Alternatively, the access device may be configured to package the content within the IP stream using a different packing format according to the default rules that only the device that complies with the rules can recognize.
As described above, the present invention has described each embodiment, but is not limited to these examples. For example, each embodiment has described an access device capable of receiving digital signals from a broadcast source such as, but not limited to, a terrestrial broadcast source (source), cable system, etc. It is clear that the digital signal distribution control method can be used for any device connected to a network, such as a home network. The scope of the claims of the present application broadly includes each other embodiment and each modification of the present invention that can be carried out by those skilled in the art without departing from the scope of the equivalent of the present invention.
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US11627376B2 | Cited by | United States of America | Applicant |
| JP2021083101A | Cited by | Japan | Search report |
| JP2021103878A | Cited by | Japan | Search report |
| US11445251B2 | Cited by | United States of America | Applicant |
| JP2005529519A | Cites | Japan | Examiner |
19 members in 9 offices
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 38705402 | United States of America | P | |
| 38705402 | United States of America | P | |
| 60387054 | United States of America | – | |
| 2002387054 | – | – | – |
| US20020387054P | – | – | – |
Members19
| Document | Office | Kind | |
|---|---|---|---|
| WO03104922A2 | World Intellectual Property Organization (WIPO) | A2 | |
| AU2003237388A1 | Australia | A1 | |
| AU2003237388A8 | Australia | A8 | |
| WO03104922A3 | World Intellectual Property Organization (WIPO) | A3 | |
| BR0305026A | Brazil | A | |
| KR20050016519A | Republic of Korea | A | |
| EP1512081A2 | European Patent Office (EPO) | A2 | |
| MXPA04012154A | Mexico | A | |
| CN1659538A | China | A | |
| US2005198282A1 | United States of America | A1 | |
| JP2005529519A | Japan | A | |
| EP1512081A4 | European Patent Office (EPO) | A4 | |
| CN100341015C | China | C | |
| US7318099B2 | United States of America | B2 | |
| JP2010141927AThis record | Japan | A | |
| KR101019981B1 | Republic of Korea | B1 | |
| JP4954471B2 | Japan | B2 | |
| EP1512081B1 | European Patent Office (EPO) | B1 | |
| BRPI0305026B1 | Brazil | B1 |
4 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Decision of refusalA02 | A02 | |
| Notification of reasons for refusalA131 | A131 | |
| Request for written amendment filedA521 | A521 | |
| Written request for application examinationA621 | A621 |
Numbers
- Publication
- 2010141927
- Publication, DOCDB
- 2010141927
- Publication, EPODOC
- JP2010141927
- Application
- 50068
- Application, DOCDB
- 2010050068
- Application, EPODOC
- JP20100050068
Titles2
- Japanese
- ネットワークに於けるディジタル符号化データの配信を制御する方法および装置
- English
- Methods and devices for controlling the distribution of digitally coded data over a network
Classification
- CPC, 16
- H04L63/10
- G06F15/173
- G06Q30/06
- H04L61/10
- H04L2463/101
- H04N7/163
- H04N21/4345
- H04N21/43615
- H04N21/4627
- H04N21/8355
- G06F21/10
- H04L61/00
- H04L65/611
- H04L65/70
- G06F15/16
- H04L65/1101
- IPC, 11
- H04N7 173
- G06F12 14
- G06F15 173
- G06F21 00
- G06F21 10
- G06Q30 06
- H04L12 56
- H04L29 06
- H04L29 12
- H04N7 16
- H04N7 24