Video on demand pay per view services with unmodified conditional access functionality
Abstract
This record has no abstract on file.
Term
Term ended
Expired 23 July 2021, 5.2 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
15 claims: 8 independent, 7 dependent
- 1The encrypted access control information and the encrypted program material are received at the receiver, the encrypted program material is encrypted according to the first encryption key, and the access control information is the first. The encrypted access control information received in the first encryption module and the received encrypted program material according to the second encryption key (516), including one encryption key and control data. Further encryption is performed, the second encryption key (516) is encrypted in the second encryption module according to the third encryption key (520), and the fourth encryption key (524) is generated.The furtherEncrypted access control information (518) andTheA program material storage method for subsequent playback that further comprises a step of storing the encrypted program material (514) as well as the fourth encryption key (524) in the data storage device. 暗号化されたアクセス制御情報と暗号化されたプログラム材料とを受信機において受信し、暗号化されたプログラム材料は第1の暗号化キーにしたがって暗号化されており、そしてそのアクセス制御情報が第1の暗号化キーおよび制御データを含み、 第2の暗号化キー(516)にしたがって第1の暗号化モジュールにおいて受信された暗号化されたアクセス制御情報および受信された暗号化されたプログラム材料をさらに暗号化し、 第3の暗号化キー(520)にしたがって第2の暗号化モジュールにおいて第2の暗号化キー(516)を暗号化して、第4の暗号化キー(524)を生成し、該さらに暗号化されたアクセス制御情報(518)および該さらに暗号化されたプログラム材料(514)ならびに第4の暗号化キー(524)をデータ記憶装置に記憶するステップを含んでいる後続する再生のためのプログラム材料記憶方法。
- 4The right is the method described in claim 3 shown in the metadata table. 権利はメタデータ表で示されている請求項3記載の方法。
- 9The re-encrypted program material and the fourth encryption key (524) are read from the data storage device, and the third encryption key (520) is used to obtain the fourth encryption key (524) in the second decryption module. Claim 8 further comprises the step of decrypting to generate a second encryption key (516) and then using the second encryption key (516) to decrypt the program material in the second decryption module. The method described. 再度暗号化されたプログラム材料および第4の暗号化キー(524)をデータ記憶装置から読出し、 第3の暗号化キー(520)により第2の解読モジュールにおいて第4の暗号化キー(524)を解読して、第2の暗号化キー(516)を生成し、 第2の暗号化キー(516)を使用して第2の解読モジュールにおいてプログラム材料を解読するステップをさらに含んでいる請求項8記載の方法。
- 10A tuner for receiving encrypted access control information and program material whose encrypted access control information includes a first encryption key and control data and which is encrypted according to the first encryption key. In (410) and the program material (506) encrypted according to the second encryption key (516) and the first encryption module (512) for further encrypting the encrypted access control information. There is a first encryption module (512) and a third encryption key (520) that can be combined to communicate with the tuner (410) and to communicate with the data storage device (528). A second encryption module (522) for encrypting the second encryption key (516) and generating a fourth encryption key (524) according to the above, and a first encryption module (522). Decrypt the second encryption module (522) and the fourth encryption key (524), which are combined to communicate with 512) and can be combined to communicate with the data storage device (528). With a first decryption module (532) that can be combined to communicate with a disk drive (528) to generate 2 encryption keys (516), Further encrypted program material (514) is decrypted using a second encryption key (516) to obtain encrypted program material (506) and further encrypted access control information (504). A second decryption module (534) that is coupled to communicate with the first decryption module (532) and tuner (410) to generate and can be coupled to communicate with the data storage device (528), A conditional access module (406) that includes a third decryption module (544) for decrypting encrypted access control information to generate a first encryption key, with a tuner (410). A second decryption module (534) and a tuner for selectively receiving access control information selected from a group containing received access control information and access control information decrypted by the second decryption module (534). A conditional access module (406) that can be combined to communicate with (410), For subsequent playback, it comprises a fourth decryption module (510) for decrypting the encrypted program material using the first encryption key to generate the decrypted program material. A device for storing program material in. 暗号化されたアクセス制御情報が第1の暗号化キー及び制御データを含んでおり、第1の暗号化キーにしたがって暗号化された暗号化されたアクセス制御情報およびプログラム材料を受信するためのチューナ(410)と、 第2の暗号化キー(516)にしたがって暗号化されたプログラム材料(506)および暗号化されたアクセス制御情報をさらに暗号化するための第1の暗号化モジュール(512)であって、チューナ(410)と通信するように結合され、データ記憶装置(528)と通信するように結合可能である第1の暗号化モジュール(512)と、 第3の暗号化キー(520)にしたがって第2の暗号化キー(516)を暗号化して、第4の暗号化キー(524)を生成するための第2の暗号化モジュール(522)であって、第1の暗号化モジュール(512)と通信するように結合され、データ記憶装置(528)と通信するように結合可能な第2の暗号化モジュール(522)と、 第4の暗号化キー(524)を解読して、第2の暗号化キー(516)を生成するための、ディスクドライブ(528)と通信するように結合可能な第1の解読モジュール(532)と、 さらに暗号化されたプログラム材料(514)を、第2の暗号化キー(516)を使用して解読し、暗号化されたプログラム材料(506)およびさらに暗号化されたアクセス制御情報(504)を生成するための、第1の解読モジュール(532)およびチューナ(410)と通信するように結合され、データ記憶装置(528)と通信するように結合可能な第2の解読モジュール(534)と、 暗号化されたアクセス制御情報を解読して第1の暗号化キーを生成するための第3の解読モジュール(544)を含んでいる条件付きアクセスモジュール(406)であって、チューナ(410)で受信されたアクセス制御情報および第2の解読モジュール(534)により解読されたアクセス制御情報を含むグループから選択されたアクセス制御情報を選択的に受け取るための、第2の解読モジュール(534)およびチューナ(410)と通信するように結合可能な条件付きアクセスモジュール(406)と、 暗号化されたプログラム材料を、第1の暗号化キーを使用して解読して解読されたプログラム材料を生成するための第4の解読モジュール(510)とを具備している後続する再生のためにプログラム材料を記憶するための装置。
- 12A third encryption module (550) encrypts the decrypted program material and supplies the encrypted program material to the data storage device (528) when the subscriber chooses a trick play operation. 11 Equipment described. 第3の暗号化モジュール(550)は、加入者がトリックプレイ動作を選択したときに、解読されたプログラム材料を暗号化し、暗号化されたプログラム材料をデータ記憶装置(528)に供給する請求項11記載の装置。
- 13The third encryption module (550) encrypts the decrypted program material when the subscriber purchases the program material, and supplies the encrypted program material to the data storage device (528). The device described. 第3の暗号化モジュール(550)は、加入者がプログラム材料を購入したときに、解読されたプログラム材料を暗号化し、暗号化されたプログラム材料をデータ記憶装置(528)に供給する請求項11記載の装置。
- 14A fourth decryption module (510) is coupled to communicate with a first encryption module (512), and a second decryption module (534) is coupled to communicate with a provider (404). Item 10. The device according to item 10. 第4の解読モジュール(510)は第1の暗号化モジュール(512)と通信するように結合され、 第2の解読モジュール(534)は提供装置(404)と通信するように結合可能である請求項10記載の装置。
- 15The first encryption module (512) encrypts the decrypted program material using the second encryption key (516) and supplies the encrypted program material to the data storage device (528). Claim that the second decryption module (534) receives the encrypted program material from the data storage device (528) and decrypts the encrypted program material using the second encryption key (516). 14 Equipment described. 第1の暗号化モジュール(512)は解読されたプログラム材料を、第2の暗号化キー(516)を使用して暗号化し、暗号化されたプログラム材料をデータ記憶装置(528)に供給し、 第2の解読モジュール(534)は暗号化されたプログラム材料をデータ記憶装置(528)から受け取って、暗号化されたプログラム材料を第2の暗号化キー(516)を使用して解読する請求項14記載の装置。
Independent claims8
92 paragraphs, as filed
The present invention relates to a system and a method for providing a video program material to a subscriber, and more particularly to a method and a system for safely storing and playing a media program.
[0002] In recent years, there has been increasing interest in allowing cable and satellite television subscribers to record broadcast media programs for later viewing. This ability, hereafter referred to as Personal Video Recording (PVR), stores media programs to provide video-on-demand (VOD) services, or simply for subscribers to watch repeatedly, or for archiving. Can be used to make it possible to do so.
[0003] Video cassette tape recorders (VCRs) have long been used for such personal video recordings. However, recently, hard disks similar to those used in personal computers have been used to store media programs for later viewing. Unlike VCRs, such devices generally do not include a tuner and are instead coupled to a satellite receiver or cable box. Also, unlike VCRs, these devices are commonly used to record digitized content rather than analog video. This difference is both an advantage and a disadvantage.
[0004] The advantage of such a device is that it can be stored for a long period of time and regenerated many times without substantial deterioration. Another advantage is that trick play features such as fast forward and rewind can be further accelerated. The disadvantage of such devices is that they can copy large amounts of program material without significant degradation. This gives the very real possibility that a large copy of the program material will be produced and distributed without permission. Because of this possibility, some media providers have become reluctant to allow their media programs to be recorded by such devices.
[0005] In order to remedy this problem, it is important to protect the stored media program with strong confidentiality and copy control. Current devices do not scramble media programs prior to storage and do not store copy protection information. Instead, such a device records the decrypted program content in a storage disk using a paired hardware scheme in which the hard disk controller and the hard disk are paired with each other specifically by a particular interface. Since the hard disk controller and the hard disk itself are essentially paired, storage or playback will not work if the disk is removed and moved to another player. The weakness of this secret protection scheme is that it relies solely on paired hardware to ensure confidentiality, and the media programs stored on the disk drive itself are not encrypted.
[0006] While it is probably possible to simply store the data stream as it is received from the broadcaster for future playback, this technique has another drawback. One of these drawbacks is that it gives the pirate a permanently recorded version of the encrypted data stream, and thus performs a detailed analysis of the data stream itself to determine the encryption technique and code. It gives the piracy information that can be used to do so.
[0007] A system and method for safely recording broadcast media programs (including impulse-purchased pay-per-view programs) are required for future reproduction with limited use. ing. Such systems can be used to support Video on Demand (VOD), which allows subscribers to instantly purchase media programs and games from set-top boxes without worrying about program start times. It becomes possible to do. Systems and methods that do not require substantial changes to the subscriber's hardware, such as the conditional access module (CAM) used to generate the key to decrypt the media program to provide to the subscriber. Is also needed.
[0008] One object of the present invention is a broadcast comprising an impulse pay-per-view (IPPV) program that can be reproduced and recorded on a storage medium and allows for future reproduction under restricted use. It is to receive and decrypt media programs. The data itself may be stored for a short period of time, but the playback of the media program can be performed by trick play functions such as fast forward, rewind, fast fast forward, fast rewind, frame forward and pause functions.
[0009] Another object of the present invention is to provide a PVR function for recording, delayed playback and trick play of an IPPV media program from a storage medium without the need to repurchase the IPPV media program. This allows the IPPV media program to be purchased and viewed at the user's convenience without having to purchase the IPPV media program before storage. Ideally, such a system would allow the user to select an IPPV media program from storage, subject to limited playback rights.
[0010] Yet another object of the present invention is to combine the storage medium with elements of the subscriber's IRD to ensure that playback of the media program from the storage device is permitted only by the appropriate IRD. Is.
[0011] Yet another object of the present invention is to provide a secretly secure means for storing broadcast data streams (including IPPV and games) in a data storage device while providing adequate copy protection. To provide.
[0012] Yet another object of the present invention is to provide a system and method for processing the storage and retrieval of media programs and other data in an archive in the event of a data storage device failure.
Yet another object of the present invention is to provide a system and method that allows media program purchases to be recorded in a manner similar to that used for non-broadcasting programs in real time. It is to be.
Yet another object of the present invention is the initial time period by the determination to purchase or cancel the purchase of the media program, whether the program was retrieved from storage or obtained from real-time broadcast. To provide a system that lays the groundwork for the development of a system that allows previews of IPPV media programs to be viewed without modification.
[0015] Yet another object of the present invention is to achieve all of the above without the need for substantive changes to conditional access module hardware and / or software.
In summary, the present invention describes a system and method for storing and retrieving program material for later reproduction. In this method, access control information and program material encrypted according to the first encryption key are received, and the access control information includes the first encryption key and control data, and the second encryption key is used. Therefore, the access control information and the encrypted program material are further encrypted, the second encryption key is encrypted according to the third encryption key to generate the fourth encryption key, and the encrypted access control is performed. It includes steps to store information and encrypted program material as well as a fourth encryption key.
[0017] In the apparatus according to the present invention, the access control information includes the first encryption key and the control data, and for receiving the access control information and the program material encrypted according to the first encryption key. It can be combined with the tuner to communicate with the tuner and to communicate with the data storage device to further encrypt the program material and access control information encrypted according to the second encryption key. To communicate with the first encryption module and the first encryption module to encrypt the second encryption key according to the third encryption key and generate the fourth encryption key. A second encryption module that is combined and can be combined to communicate with the data storage device, and communicates with the disk drive to decrypt the fourth encryption key and generate the second encryption key. The first decryption module, which can be combined so as to, and the encrypted program material are decrypted using the second encryption key, and the encrypted program material and the encrypted access control information are obtained. A first decryption module to generate and a second decryption module that is coupled to communicate with the tuner and can be coupled to communicate with the data storage device, and a second decryption module that decrypts and decrypts the encrypted access control information. Access control selected from a group containing access control information received by the tuner and access control information decrypted by the second decryption module, which contains a third decryption module for generating one encryption key. A second decryption module for selectively receiving information, a conditional access module that can be combined to communicate with the tuner, and encrypted program material are decrypted using the first encryption key. It is equipped with a fourth decryption module for generating the decrypted program material.
The present invention avoids the pervasive problems of unauthorized digital copying of media programs by using strong cryptographic methods. Moreover, the present invention ensures that such material cannot be distributed because the decryption of the stored material is only successful by the encrypted IRD.
BEST MODE FOR CARRYING OUT THE INVENTION In the following description, reference is made to an accompanying drawing which is a part thereof and illustrates some embodiments of the present invention by way of example. In the drawings, the parts corresponding to the same reference numerals are consistently represented. It is understood that other embodiments can be used and structural modifications can be made without departing from the technical scope of the invention.
[0020] FIG. 1 is a schematic diagram showing an outline of the video providing system 100. The video providing system 100 includes a control station 102, which communicates with the uplink center 104 by terrestrial or other link 114, and receives station 130 by the public switched telephone network (PSTN) or other link 120. Communicates with the integrated receiver / decoder (IRD) 132 in. Control station 102 sends program material to uplink center 104 and works in harmony with receiving station 130 to provide subscriber 110 with pay-per-view (PPV) program services, including associated decryption of invoices and video programs. To do.
[0021] The uplink center 104 receives the program material and the program control information from the control station 102, and uses the uplink antenna 106 to transmit the program material and the program control information.<u style="single">Via uplink 116</u>Send to satellite 108. Satellite 108 receives and processes this information and transmits this video program and control information over the downlink 118 to the IRD 132 at the receiving station 130. The IRD132 uses the subscriber antenna 112 to receive this information, which antenna is coupled to communicate with the IRD132.
The video delivery system 100 can include multiple satellites to provide extensive terrestrial coverage, add channels, or increase bandwidth per channel. In one embodiment of the invention, each satellite includes 16 transponders that send and receive program material and other control data to and from the uplink center 104 and supply it to subscriber 110. However, by using data compression and multiplexing techniques, channel performance is significantly improved. For example, two satellites 108 operating together can receive and broadcast over 150 regular (non-HDTV) audio and video channels with 32 transponders.
Although the invention disclosed herein is described with reference to the satellite-based video delivery system 100, the invention is also programmed by either traditional broadcasting means, cable or other means. It can be carried out by ground-based transmission of information. In addition, the various different functions collectively assigned to the control station 102 and the uplink center 104 described above may be reassigned as desired without departing from the technical scope of the invention. It is possible.
[0024] Although the above description has described one embodiment in which the program material provided to the subscriber is a cinematic video (and audio) program material, the methods described above are also merely audio information or data. Can be used to provide programming material, including.
FIG. 2 is a block diagram showing a typical uplink configuration for a single satellite 108 transponder, how video program material is uplinked to satellite 108 by control station 102 and uplink center 104. Indicates whether it will be done. Figure 2 shows three video channels (each with one or more audio channels for high fidelity music, soundtrack information, or a secondary audio program for transmitting a foreign language) and a computer. Indicates a data channel from data source 206.
[0026] The video channel is supplied by the program source of the video material 200A-200C (hereinafter collectively referred to as the video source 200). The data from each video program source 200 is supplied to the encoder 202A-202C (hereinafter collectively referred to as the encoder 202). Each encoder receives a presentation time stamp (PTS) from controller 216. A PTS is a circular binary time stamp used to ensure that video information is properly synchronized with audio information after encoding and decoding. The PTS time stamp is sent by each I frame of the MPEG coded data.
[0027] In one embodiment of the invention, each encoder 202 is a second generation Motion Picture Experts Group (MPEG-2) encoder, but another encoder that implements another coding technique is also available. It can be used. Data channels can be processed by an encoder (not shown) in a similar compression scheme, but such compression is usually unnecessary or done by a computer program in a computer data source (not shown). For example, photo data is typically compressed into * .TIF or * .JPG files before transmission). After encoding by the encoder 202, the signal is converted into a data packet by the packetizer 204A-204F (hereinafter collectively referred to as the packetizer 204) associated with each source 200, 206-210.
A data packet is a system that associates a reference (SCR) from system clock 214, a control term (CW) generated by conditional access control device 208, and each data packet broadcast to a subscriber to a program channel. Assembled using the Channel Identifier (SCID) generator 210. This information is sent to packetizer 204 and used to generate data packets. These data packets are then multiplexed, encoded, modulated and transmitted into serial data. A special packet, known as a control language packet (CWP), consists of control data, including control language (CW) and other control data used to support the provision of conditional access to program material. It is a thing, which is also encrypted and transmitted.
[0029] FIG. 3A is a schematic diagram showing a typical data flow. The first packet segment 302 contains information from video channel 1 (eg, data from the first video program source 200A). The next packet segment 304 contains computer data information obtained, for example, from computer data source 206. The next packet segment 306 contains information from video channel 5 (from one of the video program sources 200), and the next packet segment 308 contains information from video channel 1 (again, from the first video program source 200A). Includes. Therefore, the data stream contains a series of packets from any one of the data sources in the order determined by controller 216. The data stream was encrypted by the encryption module 218, modulated by the modulator 220 (typically using the QPSK modulation scheme), fed to the transmitter 222, and the transmitter 222 was modulated over the frequency bandwidth. The data flow is broadcast to the satellite by the antenna 106.
[0030] Subscriber 110 receives the media program through the subscriber receiver or IRD 132. By using SCID, IRD132 reassembles the packet and replays the program material for each channel. As shown in A of FIG. 3, the empty packet 310 generated by the empty packet module 212 may be inserted into the data stream if desired.
[0031] B in FIG. 3 is a schematic diagram of a data packet. Each data packet (eg 302-316) is 147 bytes in length and contains several packet segments. The first packet segment 320 contains 2 bytes of information including SCID and flag. SCID is a unique 12-bit number that uniquely identifies the data channel of a data packet. The flag contains 4 bits used to control whether the packet is encrypted and which key must be used to decrypt the packet. The second packet segment 322 consists of a 4-bit packet type indicator and a 4-bit continuous state counter. The packet type identifies the packet as one of four data types (video, audio, data or empty). When combined with SCID, its packet type determines how the data packet is used. The contiguous state counter increments once for each packet type and SCID. Next packet segment 324 Contains 127 bytes of payload data, which is part of the video program supplied by the video program source 200. The final packet segment 326 is the data that is required to perform forward error correction.
Media Program Encryption Media programs are encrypted by encryption module 218 prior to transmission to ensure that only authorized subscribers receive and view them. Each media program is a letter number that is hereafter called a control word (CW).<u style="single">First of</u>It is encrypted according to the encryption key. This is done by a variety of data encryption techniques, including symmetric algorithms such as the Data Encryption Standard (DES) and asymmetric algorithms such as the Riverst-Shamir-Adleman (RSA) algorithm.
[0033] In order to decrypt the media program, IRD132 of subscriber 110 must also access the CW. To maintain confidentiality security, CWs must not be sent to IRD132 in plain text. Instead, the CW is encrypted before being sent to the subscriber's IRD132. The encrypted CW is sent as a control word (data) packet to the subscriber's IRD132.
[0034] In one embodiment, CWP data, including CW, is encrypted and decrypted by what is referred to here as an input / output (I / O) unbreakable algorithm.
An I / O undecipherable algorithm is an algorithm applied to an input data stream to generate an output data stream. The input data stream uniquely determines the output data stream, but the algorithm chosen is one whose characteristics cannot be deciphered by comparing a large number of input and output data streams. The secrecy of this algorithm can be further enhanced by adding additional functional components that are non-stationary (ie, they change as a function of time). If such an algorithm were supplied with the same input stream, the output stream supplied at a given time point could be different from the output stream supplied at another time.
[0036] As long as the encryption modules 218 and IRD132 share the same I / O unbreakable algorithm, the IRD132 can decrypt the information in the CWP and retrieve the CW. The IRD132 can then use this CW to decrypt the media program, which can be provided to subscriber 110.
Further, to prevent piracy, the control data required to decrypt the data pad and assemble it into a viewable media program may change over time (specific media). The effectiveness of the control data in the CWP to decrypt the program changes over time). This can be done in a variety of ways.
[0038] For example, since each CWP is associated with an SCID for each media program, the SCID associated with each CWP can change over time.
Another way to implement time-varying control data is to associate a time stamp with the received data flow and CWP control data. In this case, a proper relationship between the time stamp on the data flow and the control data in the CWP is required to decrypt the CWP and successfully generate the CW. This relationship can be defined, for example, by modifying the decoding method used to generate the CW from the CWP according to the time stamp received for that data stream. In this case, if the time stamp on the received data stream does not match the expected value, then the wrong decoding method has been selected and the proper CW (to decode the program media) cannot be obtained. However, if the time stamp on the received data stream matches the expected value, then the appropriate decoding method has been selected and the CWP decoding method will provide the appropriate CW.
[Request for Pay-Per-View Service] The data required to receive a pay-per-view (PPV) media program is stored in the CWP and in another piece of data known as the Purchase Information Parcel (PIP). .. Both CWP and PIP will be broadcast to subscribers in real time by the video delivery system 100. CWP is used by IDR132 to search PPV media programs as described below.
[0041] In general, PPV services can include operator-assisted pay-per-view (OPPV) and impulse pay-per-view (IPPV) services. When requesting OPPV services, subscriber 110 must predetermine the specific media program they want access to. Subscriber 110 then calls an entity such as control station 102 to request access to its media program. When requesting an impulse pay-per-view (IPPV), subscriber 110 moves the cursor over the viewer channel associated with the desired media program and selects input while looking at the program guide. After the decision, the right to purchase the PPV program is confirmed (for example, by checking channel lockout, ratings range and purchase limits), a purchase information parcel (PIP) is received and subscribers for future use. It is stored in the conditional access module 406 (described in more detail below). Conditional access module 406 associates information in CWP with PIP and uses PIP with CWP to its subscriber 110 Inspects the legitimacy of accessing the media program and decrypts the media program.
[0042] However, pre-ordering PPV media programs using PIP is restricted. This is because PIP is broadcast up to 24 hours before the media program itself is broadcast. Since PIP is broadcast in real time, IRD132 wins PIP after subscriber 110 actually requests to purchase the PPV media program.
[Media Program Subscriber Receiving and Decoding] Figure 4 is a simplified block diagram of the IRD132. The IRD132 receives and decodes the media program broadcast by the video delivery system 100. These media programs are sent to IRD132 in real time and may include, for example, video, audio or data services.
The IRD 132 can be coupled to communicate with the Conditional Access Module (CAM) 406. The CAM406 typically consists of a smart card or similar device that is provided to subscriber 110 and inserted into the IRD132. The CAM406 interfaces with the Conditional Access Verification Device (CAV) 408, which performs at least some of the functions required to verify that subscriber 110 has the right to access the media program. CAV408 is coupled to communicate with the Metadata Analysis Module (MAM) 411. By using a metadata table (eg, Figure 8 described below), MAM411 acts as a gatekeeper to determine if the stored media program is decrypted and provided to subscriber 110. This is done by comparing the metadata values with the measured or accumulated values. CAV408 and MAM411 include forwarding port / demultiplexer / decoding device 412 and microcontrol device and memory 414 as shown. It can be configured as a module separate from, or it may be configured via software instructions stored in memory and executed by the microcontrol device 414. The functionality of the MAM411 can also be performed in the verification device 410 inside the IRD132, or in software located elsewhere.
The IRD 132 has a tuner 410, a transfer and demultiplexer module (TDM) 412 operating under the control of a microcontrol unit and associated memory 414, a source decoder 416, and random access combined to communicate with them. It includes memory (RAM) 418 and a user I / O device for receiving commands from subscriber 110 and supplying output information to that subscriber.
[0046] The tuner receives a data packet from the video providing system and supplies the packet to the TDM412. By using the SCID associated with each media program, the TDM412 reassembles the data packets according to the channel selected by subscriber 110 and uses the CW key to decrypt the media program. The TDM412 can consist of a single, secure, confidential chip that is coupled to communicate with the microcontrol and memory 414.
When the media programs are decoded, they are fed to the source decoder 416, which decodes the media program data according to the appropriate MPEG or JPEG standard. The decrypted media program is then fed to a D / A converter (if required) and an external interface 404, which includes a media program provider such as a television, audio system or computer. Can be. The source decoder 416 utilizes RAM418 coupled to communicate with it to perform these functions.
[0048] The CW key is obtained from the CWP using the CAV408 and CAM406. TDM412 supplies CWP to CAM406 via CAV408. The CAM406 uses an I / O undecipherable algorithm to generate a CW, which is sent back to the TDM412. The TDM412 uses this CW to decrypt media programs. On most IRD132s, the CAV408 and CAM406 can decrypt one video / audio / data media program at a time.
As mentioned above, the control data in the CWP used to decrypt a particular media program to prevent possible piracy is the media program in which it has the appropriate time stamp. It may be modified over time to generate the appropriate CW only when applied to. In this case, the CAM406 can select and / or control the decoding method (eg, I / O undecipherable algorithm) according to the time stamp associated with the data stream transmitting the media program. If the media programs are sufficiently separated in time, improper decoding methods will be used and no suitable CW will be generated to decode the media programs.
A more detailed description of the encryption and decryption of a media program is in the Applicant's separate application, US Pat. No. 09 / 491,959, whose rights are assigned to the Applicant. Has been described.
[Storage and retrieval in encrypted form of a media program] FIG. 5 is a schematic diagram illustrating steps of a method used to put one embodiment of the present invention into practical use. Data flow 501 is supplied by subscriber antenna 112 and received by tuner 410 and TDM412 as shown in block 502. The data stream 501 contains a plurality of data including the first encryption key (CW key 546 shown in FIG. 6) and a data packet having program material encrypted according to one or more control word packets (CWP) 504. Contains packets. The control word packet 504 contains access control information and other data, which may be processed to generate the CW key 546 needed to decipher the program material.
The data stream 501 may also include metadata describing information including rights associated with the program material (eg, replay rights and / or copy rights may be included). These rights include the parameters necessary to control the reproduction of program material, including IPPV or pay-per-play services. The metadata can include the information shown in FIG.
Program material is not stored in media program storage 528 (N)<sub>0 </sub>When (as shown by the switch controlled by), the encrypted program material 506 and CWP504 are processed legitimately as shown in Figure 6. The CWP504 is sent to the IPPV control module 540 in the CAM406, which analyzes the access control information in the CWP504 to determine if the subscriber has the right to view the program material. If so, the CW extraction module 544 generates a control word from the data in the CWP and supplies it to the broadcast decoding module 510, which the broadcast decoding module 510 decodes and outputs the program material 511 for display. To do.
Information describing the subscriber's right to view the program material (see, eg, FIG. 8) may have been previously received from the service provider, or the IPPV purchase action, or subscription prior to viewing the program. It may have been received prior to the action initiated by the person. The subscriber action commands the IPPV control module 540 in the CAM406 to store the IPPV rights (emtitlement) information in the purchase history module 542 in the CAM406 for later reporting to the service provider.
[0055] In one embodiment, the metadata table is initially supplied to the subscriber with each setting in the default state, or as part of the IRD132 software. The default metadata tables are joined (for example, by IRD132 verifier 408) when the program to be stored on the hard disk for storage and later PPV is broadcast. The default settings are sufficient for most broadcast events and programs and do not need to be changed further.
If it becomes necessary to change one of the settings for a particular program, only the change for a particular parameter will be broadcast to the subscriber, not the entire metadata table. The IRD132 then recognizes the parameter changes and modifies the metadata table according to the particular parameter changes. In this way, the broadcaster is required to broadcast only the non-default values, rather than broadcasting the same table for each program. This saves IRD132 behavior, which requires beneficial broadcast bandwidth and the formation and storage of numerous metadata tables.
Metadata can also be used to pre-cache content in storage device 528 of subscriber 110. This content is "hidden" from subscriber 110 at the specified time and / or until another condition (which can be described in the metadata table) occurs. For example, the title of the program is not initially given to the available cache or other area of the user interface. After the appropriate conditions are met (eg, at the appropriate time), the content is offered to subscriber 110 as an available program. This allows the video broadcasting system to transmit content at a time convenient for broadcasting, such as at night when bandwidth requirements are low. This can happen on the day of the event or weeks earlier than scheduled. These pre-cached events can be triggered to provide content related to a particular event, or to provide content during the time or date specified by the content provider. ..
Metadata can also be sourced from transponders on satellite 108 that are different from the program material, from different satellites 108, or from terrestrial links such as the PSTN link 120 as part of the data stream 501.
After appropriate processing (ie, MPEG and / or JPEG decoding, decompression, conversion to analog signals, etc.), the program material 511 is fed to a device of external interface 404, which device is like a display 548. A display device may be included.
[0060] When the program material is stored in the media program device 528, the encrypted program material 506 (to show that the program material can contain video, audio or other data, FIGS. 5-7. (Shown as encrypted V / A / D in) is supplied to the storage encryption module 512. The storage encryption module 512 further encrypts the encrypted program material 506 and CWP 504 according to the CP encryption key 516. Further, the key encryption module 522 encrypts the CP key 516 with the box key 520 to generate the encrypted CP key 524.<u style="single">As shown in block 526</u>The resulting further encrypted program material 514, encrypted CWP518 and encrypted CP key 524 are stored in the media programming device 528. When reproduction of the stored program material is desired, further encrypted program material 514, encrypted CWP518 and encrypted CP key 524 are from the media programming device 528 as shown in block 530. It will be searched. By using the box key 520, the encrypted CP key 524 is decrypted by the key decryption module 532 to generate the CP key 516. The CP key 516, as well as the encrypted program material 514 and the encrypted CWP518 are supplied to the memory decryption module 534. By using the CP key 516, the memory decryption module 534 was further encrypted with the CW key as it was when it was received by the tuner 410 with the encrypted program material 506, and the CWP504. (This is also the same as when it was received by the tuner 410) and generate.
[0061] If the storage device 528 fails, the data stored therein can still be recovered. Unlike conventional video storage devices, which prevent data from being duplicated from storage media by a control device that writes data to storage media, the present invention provides at least a portion of the required information in encrypted form. Remember.
[0062] The present invention allows the user to store media in media because the present invention stores the data in an encrypted form and requires a key to decrypt the data (using another key in the IRD132). The data stored in device 528 can be backed up to another data storage device such as a zip drive or a writable CD ROM. Moreover, such backup data is encrypted so that it is not at risk of copying.
[0063] FIG. 6 is a block diagram showing additional actions taken when subscriber 110 chooses to view program material stored in media storage device 528.
When subscriber 110 chooses to view the recorded program material, MAM411 may contain metadata related to the program material (which may contain data regarding the rights shown in Figure 8). Is compared with other stored information to determine if the recorded program material should be decoded and provided. If the comparison made by MAM411 shows that the stored program material has been decrypted and provided to subscriber 110, CWP504 will be supplied to CAM406. The CAM406 includes an IPPV (impulse pay-per-view) control module 540, which instructed the CW extraction module 544 to decrypt the CWP504 and generate the CW546, and the CAM406 also viewed the program material. Provides information about the decision of 110 subscribers to purchase the right to purchase history module 542. Purchase history module 542 is subscriber 110 Records information about the purchase of the program and, if the program material is provided to the subscriber, supplies that information to the entity for creating the invoice. The IPPV control module 540 performs essentially the same functions required for non-memory fit operation. Therefore, the above-mentioned functions are performed without relying on changes in the functions of the CAM406.
It is important that the above embodiments do not require modification of the CAM406, as the behavior shown in FIG. 6 is exactly the same as the normal behavior when the program material is not stored in the media storage device. Is. Moreover, this embodiment does not require modification of the CWP504 to calculate any time-varying relationships between the information in the CWP504 and the program material. This is because any time dependencies between the SCID and CWP of the program material are stored when they are encrypted and stored in the media storage.
FIG. 7 shows that the decrypted program material is re-encrypted and stored in data storage 528 (or another data storage device independent of data storage 528) for provision to subscriber 110. It is a block diagram which shows one Embodiment of this invention which is searched. This embodiment is useful to support, for example, the enhancement of reproduction and copy protection rights shown in FIG. This embodiment is also useful when the subscriber 110 requests a trick play operation when viewing the program material stored in the media storage device 528. These trick play operations include, for example, a play command, a rewind command, a fast forward command, a fast reverse play command, a fast fast forward play command, a pause command, a still image command, and a stop command.
[0067] In this embodiment, the decrypted program material 511 is not supplied directly for display, but is encrypted for copy protection and stored in data storage device 528 (or another data storage device). It is searched and decrypted before supplying the program material for display. In particular, the decrypted program material 511 is fed to another memory encryption module 550. This other memory encryption module 550 encrypts the decrypted program material 511 using the CP encryption key 516 and produces the re-encrypted program material 552. The CP encryption key 516 is also encrypted by the key encryption module 522 to generate an encrypted CP key 524. Both the re-encrypted program material 552 and the encrypted CP key 524 are stored in media storage 528.
[0068] When a user command is supplied to the user I / O 420 requesting reproduction of the program material, the re-encrypted program material 552 and the encrypted CP key 524 are retrieved from the media storage device 528. The encrypted CP key is decrypted by the key decryption module 532 to generate the CP encryption key 516. The re-encrypted program material 552 and CP encryption key 516 are supplied to the memory decryption module 554. The memory decryption module 554 decrypts the encrypted program material 552 again to generate a clear version of the program material 511. Program material 511 is supplied to an external interface 404, such as a display 548, for provision to the user.
[0069] In a preferred embodiment, the memory encryption module 550 and decryption module 554 described above with respect to FIG. 7 are different modules than those described and shown in FIG. This allows parallel encryption operations to take place, thereby speeding up the process and allowing the adaptation of different CP encryption keys. However, the present invention may also be configured so that the same CP encryption and decryption module is used for both operations. This includes configurations where different CP keys are used and switched to the required module.
[0070] Similarly, it should be noted that FIGS. 5 and 7 show embodiments in which the memory encryption and memory decryption modules 550, 554 are separate modules. However, the present invention may also consist of a single storage encryption and decryption module that is switched between encryption and decryption functions.
Similarly, the key encryption and decryption functions shown in FIGS. 5 and 7 are shown as separate modules, but one or more modules are used in the same optional manner to perform that function. May be done.
The present invention is also used for broadcast decryption, storage encryption and decryption, as well as key encryption and decryption, thereby one or more such modules are shown in FIGS. 5 and 7. And envisions the use of the same or similar cryptographic mechanisms that allow any of the decryption functions to be performed.
[0073] In general, the box key 520 is specific to the IRD132 and the CP key is specific to the media program, but this does not have to be. In addition, different techniques and mechanisms can be used to generate and install IRD-specific box keys 520 and media program-specific CP keys. In a preferred embodiment, the box key 520 is factory-configured and the CP key is randomly generated by the IRD 132 and is specific to each stored media program.
Finally, in the embodiments described above, it is recognized that the media storage device 528 shown in FIG. 7 is the same as the media storage device 528 shown in FIG. However, if desired, the re-encrypted program material 552 can be stored in a second (other) media storage device. Incidentally, any of the above-mentioned data can be stored in a plurality of media storage devices in order to increase the throughput or facilitate the addition of confidentiality means. This embodiment allows for faster storage of information and retrieval from disk.
[0075] In the above-described embodiment of the present invention, the data stream received in the IRD 132 further includes metadata including data for controlling reproduction rights and copy protection. This metadata is stored in media storage device 528 for future use, such as when a request to view a media program is received. The stored metadata may or may not be encrypted and / or signed.
[Conclusion] The present invention describes a system and method for recording program-related materials that have not yet been purchased and enabling IPPV purchase during playback and viewing. Invoicing will only be done if the purchase has been made. Depending on the associated metadata for each program, the data stream 501 with program material is subject to different restrictions on such storage and reproduction. Program material may be provided to subscriber 110 in real time or further encrypted before being stored for future reproduction. In either case, the program material is not stored in plain text. Caching technology can be used to allow the user to delay or shift the program, or to support the trick play feature.
If the program material and associated data are not intended to be stored on the hard disk for future playback, the IRD132 sends the encrypted program material 506 and associated CWP504 to the CAM406. CAM406 decrypts CWP504 to obtain CW key 546, which is used to decrypt the program material so that it can be provided to subscriber 110.
If the IRD 132 can utilize the media storage device 528, the media program can be decrypted, re-encrypted, and stored in a media storage device such as a cache, thereby allowing the user to be part of the trick play function. It will be possible to use pause, rewind, fast forward or other features that may be included.
If the IRD132 has media storage 528 available and data is stored on the hard disk prior to purchase for future purchase and playback, the IRD132 bypasses the processing of the CAM406 and the encrypted program material 506. And the associated CWP504 is sent directly to the crypto engine 512 (typically contained within the transfer chip) and the bypass is handled by the CAM. As the data is further encrypted, the information is stored.
[0080] The present invention uses metadata related to each media program included in the broadcast data stream. The metadata contains information that describes the rights to view and / or copy the program material available to subscriber 110. The rights associated with the program material may be provided to the subscriber 110 in a manner convenient to the user.
The rights described in the metadata allow the subscriber to watch the media program as many times as they want within a period of time (video storage model); watch it a predetermined number of times within a period of time. Allows users to watch only one movie within a given time period (modified video storage model); different pricing for different views (ie, first use) Pay 1X as a fee, pay 1 / 2X as the next viewing fee, etc.). Other models store a media program for a given available window setting and allow the program to be automatically deleted after the available window is closed. Due to the access control information and its associated program material, the present invention can be effectively used in systems where the access control information changes over time.
[0082] In general, the IRD 132 handles the generation, encryption, and decryption of encryption keys. The IRD132 also contains the hardware and software needed to install and restore keys for copy-protected services.
[0083] Although the above description has focused primarily on the storage and retrieval of video programs, the present invention is not limited to these media types. Thus, the term "media program" or "program material" refers to video data streams and / or audio data streams and / or any other broadcast data stream, regardless of data type.
The above description of preferred embodiments of the present invention is provided for illustration and description. It is not exclusive and does not limit the invention to the forms disclosed. Many modifications and modifications are possible in light of the above teachings. The technical scope of the present invention is limited by the appended claims, not by this detailed description. The above specification, examples and data fully illustrate the manufacture and use of the structures of the present invention. The present invention is attributed to the appended claims, as many embodiments of the invention can be practiced without departing from the technical scope of the invention.
[Brief Description of Drawings] [Fig. 1] An explanatory diagram showing an outline of a video providing system.
FIG. 2 is a block diagram of a typical uplink configuration showing how video program material is uplinked to a satellite for transmission to a subscriber using a single transponder.
FIG. 3 is a schematic diagram of a typical data flow received from a satellite and the structure of a data packet.
FIG. 4 is a high level block diagram of the IRD.
FIG. 5 is a block diagram showing storage and retrieval of data from a media storage device.
FIG. 6 is a block diagram showing storage and retrieval of data from a media storage device.
FIG. 7 is a block diagram showing storage and retrieval of data from a media storage device.
FIG. 8 shows a table of information contained in metadata.
5 priority claims, no other members on record
Priority claims5
| Document | Office | Kind | Date |
|---|---|---|---|
| 09620832 | United States of America | – | |
| 62083200 | United States of America | A | |
| 62083200 | United States of America | A | |
| 2000620832 | – | – | – |
| US20000620832 | – | – | – |
23 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of no payment of annual feesLAPS | LAPS | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Receipt of annual feesR250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Certificate of patent or registration of utility modelR150 | R150 | |
| First payment of annual fees (during grant procedure)A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Transfer of reconsideration by examiner before appeal (zenchi)AppealA911 | A911 | |
| Written amendmentA521 | A521 | |
| Decision of refusalA02 | A02 | |
| Written amendmentA521 | A521 | |
| Written permission of extension of timeA602 | A602 | |
| Written request for extension of timeA601 | A601 | |
| Notification of reasons for refusalA131 | A131 |
Numbers
- Publication
- 3853180
- Publication, DOCDB
- 3853180
- Publication, EPODOC
- JP3853180B
- Application
- 222229
- Application, DOCDB
- 2001222229
- Application, EPODOC
- JP20010222229
Titles2
- Japanese
- 無修正の条件付きアクセス機能性を備えたビデオ要求時ペイ・パー・ビューサービス
- English
- Video request pay-per-view service with uncensored conditional access functionality
Classification
- CPC, 8
- H04N21/4147
- H04N5/913
- H04N7/1675
- H04N21/2543
- H04N21/4333
- H04N21/4367
- H04N21/4627
- H04N2005/91364
- IPC, 16
- H04L9 08
- G06F21 24
- H04N7 167
- H04N5 92
- G11B20 10
- G06F12 14
- G06F21 60
- G06F21 62
- H04H20 00
- H04N5 91
- H04N5 913
- H04N21 2543
- H04N21 4147
- H04N21 433
- H04N21 4367
- H04N21 4627