Method to watermark a compressed content encrypted by at least one content key.
Abstract
The aim of the present invention is to enforce the watermarking on a content received by a client device, in particular to compressed video content. The present invention proposes a method to watermark a compressed content encrypted by at least one content key (CA key), said content key as well as pre-marking data forming CAS data, said CAS Data being encrypted by a transmission key and comprising at least one signature to authenticate all or part of the CAS Data, said compressed content being received by a client device comprising : - a Descrambler (103) having an input to receive the encrypted compressed content and an output to produce an compressed content, - a WM inserter (104) directly connected to the output of the Descrambler, said Descrambler and said WM inserter being connected with the Conditioner (200), said Conditioner executing the following steps : - receiving the CAS Data, - decrypting the CAS Data with the transmission key, - verifying the signature of the CAS Data, and if the signature is valid, - transferring the content key (CA key) to the descrambler (103) and the pre-marking data to the WM inserter, - watermarking by the WM inserter, the decrypted content received by the descrambler using the pre-marking data and the identifier.

Term
7.6 yearsleft in the term
Expires 28 April 2034.
- Priority
- Filed
- Granted
- Today
- Expires
14 claims: 2 independent, 12 dependent
- 1CLAIMS REIVINDICACIONES IMPI iMjrmrro mexican · r »la minapuba · industrial IMPI iMjrmrro mexican· r» la míopuba· industrial 1. A method for inserting a watermark in content received by a client device, characterized in that it comprises the steps of:1. Un método para insertar una marca de agua en un contenido recibido por un dispositivo cliente, caracterizado porque comprende los pasos de: - receiving an encrypted compressed content on the client device, the encrypted compressed content being encrypted, by at least one content key;- recibir un contenido comprimido cifrado en el dispositivo cliente, estando cifrado el contenido comprimido cifrado, por lo menos por una clave de contenido;- receiving the encrypted compressed content at an input of a decoder of the client device and producing a decrypted compressed content at an output of the decoder;- recibir el contenido comprimido cifrado en una entrada de un decodificador del dispositivo cliente y producir un contenido comprimido descifrado en una salida del decodi f icado r;- receiving at the client device, a rights control message (ECM) that has at least one content key and is encrypted by a first transmission key, and encrypted pre-marking data;- recibir en el dispositivo cliente, un mensaje de control de derechos (ECM) que tiene al menos una clave de contenido y esta cifrado por una primera clave de transmisión, y datos de pre-marcado cifrados;- decifrar el ECM con la primera clave de trasmisión y extraer la clave de contenido;- decrypt the ECM with the first transmission key and extract the content key;- decifrar los datos de premarcado;- decrypt the pre-dialing data;- verificar una firma de los datos de premarcado por un condicionador del dispositivo cliente y, en respuesta a la verificación de la firma, transferir los datos de premarcado y un identificador contenido en el condicionador, a un insertador de marca de agua del dispositivo cliente;- verifying a signature of the pre-marking data by a conditioner of the client device and, in response to verification of the signature, transferring the pre-marking data and an identifier contained in the conditioner, to a watermark inserter of the client device;- validar la clave de contenido para el decodificador e;- validate the content key for the decoder e;- insertar una marca de agua, por el insertador de marca de agua, en el contenido comprimido descifrado recibido directamente desde el decodificador, utilizando los datos de premarcado y el identificador. - inserting a watermark, by the watermark inserter, into the decrypted compressed content received directly from the decoder, using the pre-marking data and the identifier. -19 MUH-ANC INSTITUTE OF THE IMMjrnUAL AGE -19INSTITUTO MUH-ANC DE LA FROM EDAD INMjrnUAL
- 8A client device for decrypting and inserting a watermark into encrypted compressed content, said device comprising:8. Un dispositivo cliente para descifrar e insertar una marca de agua en un contenido comprimido cifrado, comprendiendo dicho dispositivo: - a decoder with a circuit that has an output to produce a decrypted compressed content and an input configured to receive the encrypted compressed content that has pre-marking data and is encrypted by at least one content key that is received by the client device in a authorization control message (ECM) encrypted by a first transmission key;- un decodificador con un circuito que tiene una salida para producir un contenido comprimido descifrado y una entrada configurada para recibir el contenido comprimido cifrado que tiene datos de premarcado y esta cifrado por al menos una clave de contenido que es recibida por el dispositivo cliente en un mensaje de control de autorización (ECM) cifrado por una primera clave de transmisión;- a conditioner configured to receive the ECM and decrypted pre-dialing data, decrypt the ECM with the first transmission key and extract the content key;- un condicionador configurado para recibir el ECM y los datos de premarcado descifrados, descifrar el ECM con la primera clave de transmisión y extraer la clave de contenido;- an identifier provided in the conditioner;- un identificador dispuesto en el condicionador;- a watermark inserter connected directly to the output of the decoder, configured to insert a watermark in the decrypted compressed content with the pre-marking data and the identifier;- un insertador de marca de agua conectado directamente a la salida del decodificador, configurado para insertar una marca de agua en el contenido comprimido descifrado con los datos de premarcado y el identificador;caracterizado porque el decodificador y el insertador de marca de agua están conectados con el condicionador;el characterized in that the decoder and the watermark inserter are connected with the conditioner;the -21 IMPI iNSTmiT · maxican DE la M »om» AB INBUSTIUM. -21 IMPI iNSTmiT· maxican DE la M»om»AB INBUSTIUM. condicionador está configurado para verificar una firma de los datos de premarcado y, en respuesta a la verificación de la firma, transferir los datos de premarcado y el identif icador al insertador de marca de agua y;el decodificador está configurado para descifrar los datos de premarcado junto con el contenido comprimido cifrado y, para filtrar y dirigir al condicionador los datos de premarcado descifrados. conditioner is configured to verify a signature of the pre-marking data and, in response to verification of the signature, transferring the pre-marking data and identifier to the watermark inserter and;the decoder is configured to decrypt the pre-dial data along with the encrypted compressed content, and to filter and direct the decrypted pre-dial data to the conditioner.
Independent claims2
144 paragraphs in 16 sections, as filed
(54) Title: METHOD FOR INSERTING A WATERMARK IN A COMPRESSED CONTENT ENCRYPTED BY AT LEAST ONE CONTENT KEY.
(54) Title: METHOD TO WATERMARK A COMPRESSED CONTENT ENCRYPTED BY AT LEAST ONE CONTENT KEY.
(57) Summary
The object of the present invention is to apply the insertion of a watermark in content received by a client device, in particular compressed video content. The present invention proposes a method for inserting a watermark in a compressed content encrypted by at least one content key (CA key), said content key, as well as the pre-marking data form the CAS data, said CAS data is encrypted using a transmission key and contains at least one signature to authenticate all or part of the CAS data, said compressed content received by a client device comprises: - a decoder (103) having an input for receiving the encrypted compressed content and an output for producing compressed content, - a WM inserter (104) directly connected to the output of the decoder; said WM inserter are connected with the conditioner (200), said conditioner executes the following steps: - receive the data from the CAS, - decrypt the data from the CAS with the transmission key, - verify the signature of the data from the CAS and if the signature is valid, - transfer the content key (CA key) to the decoder (103) and the pre-dial data to the WM inserter. - inserting a watermark by the WM inserter, the decrypted content received by the decoder using the pre-marking data and the identifier.
(57) Abstract
The aim of the present invention is to enforce the watermarking on a content received by a Client device, in particular to compressed video content. The present invention proposes a method to watermark a compressed content encrypted by at least one content key (CA key), said content key as well as pre-marking data forming CAS data, said CAS Data being encrypted by a transmission key and comprising at least one signature to authenticate all or part of the CAS Data, said compressed content being received by a Client device comprising: - a Descrambler (103) having an input to receive the encrypted compressed content and an output to produce an compressed content, - a WM inserter (104) directly connected to the output of the Descrambler, said Descrambler and said WM inserter being connected with the Conditioner (200), said Conditioner executing the following steps: - receiving the CAS Data, - decrypting the CAS Data with the transmission key, - verifying the signature of the CAS Data, and ¡f the signature ¡s valid, - transferring the content key (CA key) to the descrambler (103) and the pre-marking data to the WM inserter, - watermarking by the WM inserter, the decrypted content received by the descrambler using the pre-marking data and the identifier.
I Μ ΡI ί -% ,.
PATENT TITLE No. 348381
Headlines)
NAGRAVISION SA
Address:
Route de Géneve 22-24, CH-1033, Cheseaux-sur-Lausanne, SWITZERLAND
D nomination:
METHOD FOR INSERTING A WATERMARK INTO COMPRESSED CONTENT ENCRYPTED BY AT LEAST ONE CONTENT KEY.
Classification:
CIP:
CPC:
H04N21 / 8355; H04N21 / 4405; H04N21 / 6334; H04N21 / 8358
H04N21 / 8355; H04N21 / 4405; H04N21 / 8358; H04N21 / 63345; G06F21 / 10;
G06F21 / 16; H04N1 / 3232: H04N7 / 1675; H04N21 / 6334
Inventor (s):
DIDIER HUNACEK; PATRICK SERVET; MINH SON TRAN; PIERRE SARDA
REQUEST
Number:
MX / a / 2015/014979
International Presentation Date of April 2014
Validity:
Country:
EP
<img file="MX348381B_D0001.tif" />
years
PRIORITY
Date:
April 2013
Number:
13165597.9
Due Date: April 28, 2034
Issue Date: June 9, 2017
The withholding patent is based on articles 1, 2, section V, 8, section Hl, and 59 of the Industnai Property Law.
In accordance with article 23 of the Industrial Property Law, this patent has a. as of the filing date of the international application and will be subject to the payment of the flat rate of twenty years non-extendable counted to keep the rights in force.
Whoever signs this title does so based on the provisions of articles 6, sections III and 7<sup>or</sup> bis 2 of the Industrial Property Law (Official Gazette of the Federation (DO.F) 06/27/1991. amended on 08/02/1994, 10/25/1996, 12/26/1997, 05/17/1999 , 01/26/2004, 06/16/2005, 01/25/2006, 05/06/2009, 06/01/2010, 06/18/2010, 06/28/2010, 01/27/2012 and 09 / 04/2012); items 1<sup>or</sup>, 3'fraction V part a), 4<sup>or</sup> and 12th sections I and III of the Regulations of the Mexican Institute of Industnai Property (D.ÓF. 12/14/1899, amended on 07/01/2002, 07/15/2004, 07/28/2004 and 09/07 / 2007); items 1<sup>or</sup>, 3<sup>or</sup>, 4<sup>or</sup>, 5<sup>or</sup> Section V subsection a), 18 sections I and III and 30 of the Organic Statute of the Mexican Institute of Industrial Property (DOF 12/27/1999, amended on 10/10/2002, 07/29/2004, 08/04/2004 and 09/13/2007), 1<sup>or</sup>, 3 · and 5 “Subsection a) of the Agreement that delegates powers to the Deputy General Directors, Coordinator, Divisional Directors. Heads of the Regional Offices, Divisional Deputy Directors, Departmental Coordinators and other subordinates of the Mexican Institute of Industrial Property (DOF 12/15/1999, amended on 02/04/2000, 07/29/2004, 08/04/2004 and 13 / 09/2007).
This document is signed with an advanced electronic signature (FIEL), based on articles 7 BIS 2 of the Industrial Property Law; 3 of its Regulations, and 1 section III, 2 section V, 26 BIS and 26 TER of the Agreement establishing the guidelines for the use of the Payment and Electronic Services Portal (PASE) of the Mexican Institute of Industrial Property, in the procedures indicated.
<td>THE DIVISIONAL DIRECTOR OF PATENTS</td>
<td>NAHANNY CANAL REYES</td>
<td>ΞS Original Chain:</td>
<td>NAHANNY MARISOL CANAL REYES | 00001000000403252793 | Administration Service</td>
<td>Tax | 1695 || MX / 2017/45538 | MX / a / 2015/014979 | PCT patent title | 1027 | RGZ | Page (s) 1 | s + EX9vpVcqsrsfHrORBzbARInuY =</td>
<td>Digital stamp:</td>
<td>jAL / n + ue9cRnsMXMrp + eOf3ARcypDKbh7C58PjJENZ3bQLpkM9zJZrDRVY7o4Q2Dfz2RHHro9¡2se9wb5EiH48lb + w</td>
<td>vRpBRjJ + uxDKIY4ETRJ3FmoSlwuvfQ67Wy / ejSdCpTmrHJ / MUosqwck7ZQ6WAA2AI9z + DCUM4TAxAR7UsbGzXqngzE</td>
<td>ΞΏ & ζ & ΏΠΝΤ 2IKGI + ODO75N2mKFvVfCMMSHrg5OkNL5zlZqXOpYV8EH052WN9pwkb2u9rjioNzSOG4 + u6gq2byyvlblwGzwgED4XZ</td>
<td>REQWGsdowVKBYdp6s3Re3soeGGJYRoJYAB5R6H / WQX7oxllHAzMexvykQwZmytOazOrgbNSQ ==</td>
to go Xochumfco. 16020,
<img file="MX348381B_D0002.tif" />
<img file="MX348381B_D0003.tif" />
<img file="MX348381B_D0004.tif" />
IMPI
INSTITUTO MEXICANO w la r * «m» AD inwutiual
METHOD OF INSERTING A WATERMARK INTO COMPRESSED CONTENT ENCRYPTED BY AT LEAST ONE CONTENT KEY
Background of the Invention
Watermark insertion is a technique used to mark protected content. This mark is used to detect unauthorized use or illegal copies of protected content. The watermark insertion technique consists of embedding a digital mark in the content. From an appearance point of view, the digital watermark can be visible or invisible. From the point of view of the nature of the information, this digital mark can be a single value or a generic symbol, depending on what the content owner wants to control. Especially in the case of the unique value, the insertion of the watermark must be done on the end client device because the brand will have to contain an identifier of this device.
The aim of the watermarking technique is to hide as much as possible the embedded mark / hidden information by spreading one of its representations in the content. To ensure the discretion of the watermark insertion without compromising quality, the insertion generally requires a complex calculation capacity, even demonstrative for the given devices. Consequently, the entire calculation is often divided into pre-processing and post-processing. The preprocessing does most of the heavy lifting that is generated by some tokens called watermark metadata (WMD), which helps to significantly lighten the postprocessing for
ΙΜΡΙ «^ MUKXNe institute ·> LA MK * tlDAB iNraimuu. <sup>M </sup>effectively insert the mark. Where to modify, how to modify typically is the information düllttíllldd in Iwí WMD. This could be in the form of a pre-marked file, each with a table of contents in the form of an address of the block to be marked and with at least one alternative value. In the client device, each record is processed and the alternative value is selected (or not selected) according to the bit of the identifier that will be included in the content.
Therefore, the secrecy of the WMD must be ensured, as well as its insertion, especially when post-processing, within the client device, to avoid the ability to filter, remove and / or adjust it. On the client device, existing digital watermark processing techniques are generally controlled by the device's application software (CPU SERVER), which means that in some cases unprotected and still unmarked content could be accessible by the device. client device software. Therefore, the security of the digital watermark processing depends on the security of the software running on the device, that is, how easy it is to modify and then avoid the processing of the digital mark insertion when the device is attacked with success or only open (no software authentication).
Document US2010 / 128871 describes a solution in which a secondary transmission is generated containing the data that allows to reconstruct the main transmission and at the same time mark the reconstructed transmission. As a consequence, the same transmission contains the data
- 3 IMPI ^
INSTITUTO MWUCAN · er ia mk »i» a> O— '»ΓΗISTRLAL encoded and the watermark data. On reception, this transmission is processed as a set of data to be replaced in the modified transmission.
Document EP 2 391 125 describes a solution to allow individual marking (in the receiving device) based on a common transmission to all devices. The control object contains the original value, an alternative value, and a location. The security unit determines a mathematical operation that must be applied to the alternate value to recover the original value. The mathematical operation is changed according to an internal parameter of the receiving device, so the mathematical operation will be unique per device, allowing this device to be tracked if the transmission of the decoded data is analyzed.
Summary of the Invention
The object of the present invention is to apply the insertion of a watermark in content received by a client device, in particular compressed video content.
The present invention proposes a method to insert a watermark in compressed content encrypted by at least one content key (CA key), the content key (CA key) is part of a rights control message (ECM) and is encrypted by a first transmission key, the pre-dialing data is encrypted by a second transmission key and is authenticated with a signature, said compressed content is received by a client device comprising:
-4- a decoder (103) that has to receive the encrypted compressed content and
IMPIg INSTITUTO MEXICANO F
M THE INDUSTRIAL Htepitdad an entrance to a salldd pdia
<img file="MX348381B_D0005.tif" />
produce a decrypted compressed content, a WM inserter (104) connected directly to the output of the decoder, said decoder and said WM inserter are connected with the conditioner (200), said conditioner executes the following steps:
- receive the rights control message and the pre-dialing data,
- decrypt the rights control message with the first transmission key and extract the content key (CW),
- decrypt the pre-dialing data with the second transmission key,
- verify the signature of the pre-dialing data and if the signature is valid,
- transferring the content key (CA key) to the decoder (103) and the pre-dialing data to the WM inserter.
- inserting a watermark by the WM inserter, the decrypted content received by the decoder using the pre-marking data and the identifier.
Brief Description of the Figures of the Invention
The present invention will be better understood thanks to the attached figures, in which:
Figure 1 illustrates an example of the watermark insertion flow,
Figure 2 illustrates a blogging diagram of the process
<img file="MX348381B_D0006.tif" />
IMPI iwwrvr · Mexican • f A MOHEBAD 'NDUSTWAl.
watermark insertion,
Figure 3 illustrates a flow chart of the watermarking process.
Figure 4 illustrates an example in which the watermark data is contained in the data stream.
Detailed description of the invention
Conditional access data includes content (video or audio data or a combination of them) encrypted by one of a plurality of content keys. Access to this content is possible thanks to CAS data, this data includes the key or keys (CA KEY) to decrypt the encrypted content, and the pre-dialing data of WM. WMDs are a set of registers that allow the WM inserter to determine where a modification can be made to the decrypted content. This is generally in the form of a set of records, each record comprising a location (or address, offset, index) and at least one alternate value. This alternate value may (or may not, depending on the bit that is embedded), replace the original value at the specific location in the content. In case of two alternative values, the bit to be embedded as a watermark can be used to select one value or the other. The CAS data also contains access conditions associated with the content that describe the condition that must be met for the decoder to decrypt the content. The conditioner contains access rights that describe the access conditions of the client device. Access rights are preferably loaded into the conditioner using a
-6IMPI ^
ΓΝΧΓιτυτο mlxican · »> ι> Μ · ΜΙΠΑ ·
NUisnuAi Rights Management Message (EMM) encrypted using a unique key for that conditioner. Conditional flé áóóésb 'dates are transmitted, sent by unicast or sent at the request of the receiver. The CAS data can be part of the conditional access data (eg a substream with a particular PID value) or it can be sent separately to the client device.
On the server side, the compressed content is encrypted by one or a plurality of keys, in the second case, the content is partitioned and each partition is encrypted by a different key. The server also prepares the watermark data (WMD) as a record set using a parser module in order to detect the possible position of the mark in the compressed content (before the encryption step). The result of the parser is to produce at least one alternative value per record, this alternative value, when substituted in the compressed content, does not visually modify the content, but can be detected later. WMD or pre-marked records include, for each record, a content index (that is, the location in which the modification can be made) of the content to be modified and the alternative value to insert. Pre-dial records are not determined according to a particular identifier, they are only values that can help the watermark on the client device to embed the mark according to a local identifier without additional processing (thus reducing the complexity required client device).
Once received on the client device, in the event that the CAS data is embedded in the
-7 IMPIé ^ FMTHTUT MiXIUM Λ • F LA PB <W! E * A * (NBurriiAL conditional access, are extracted and sent to a conditioner (see Figure 2) in charge of the application of the security measures defined in the conditional access conditions. The module contains the first transmission key cave needed to decrypt the CAS data and to extract the key from the CAS data (CA key) and then transfer it to the CA decoder in order to decrypt the contents. In addition to the key, this module also extracts the WMDs, encrypted using a second transmission key. In case the WMDs are in the same message as the CA key, a transmission key is used to encrypt the message. In a particular embodiment, the first and second keys are the same transmission and are used to decrypt the CAS and WMD data. It should be noted that the communication between the conditioner and the CA decoder is encrypted and protected by a key initialized in both elements. Another method to ensure that the communication between these two elements is secure is to use a dedicated bus, that is, not accessible by the server CPU (203) that runs on the client device.
Similar protection is applied in the communication between the conditioner and the WM inserter.
The proposed solution protects WMDs against eavesdropping but also protects WMDs against any easy filtering or extraction. The solution also applies robust WMD detections and also ensures correct branding. Exemplary aspects of the invention may include a conditioner that receives the WMDs, an AC decoder that decodes the content, and a watermark inserter that inserts the mark using the
-8IMPI iNHTrtrri; Mexican 'M LA PWH4UAC
INOUmUAL
<img file="MX348381B_D0007.tif" />
WMD.
Figure 1 is an exemplary application of the watermark insertion process. For example, the header 100 preprocesses the content to find the proper places to insert a mark into the compressed content to form the WMDs. At this stage, the watermark insertion data is independent of the client device and is common to all client devices. This information, together with the content protected by the conditional access system (CAS) is then transmitted 101 to the end client device, for example via satellite.
Protected content enters the device. In this example illustrated by Figure 1, the CA key used to decode the content and the WMDs is transmitted in the content itself. Conditioner 102 extracts the protected CA key and protected WMDs from the channel used to transmit them. It also decrypts and authenticates these two tupias: CA-WMD key.
According to an alternative embodiment, the conditioner transmits the CAS data to a secure element, that is, the secure CPU 205 (see Figure 2). This secure element can be part of the client device, for example a protected software environment dedicated to security operations. It can also be a removable security item, such as a smart card, electronic key, or PCMCIA module. Once the CAS data is decrypted and authenticated by the secure element, the CA key and the WMD are returned to the conditioner. Communication between these two elements is preferably ensured by means of a paired key, that is, during the
-9 INSTITUTO MEXICANO INeumUAL - T initialization phase, the same key is loaded in the conditioner and in the secure element. '
The protected content 111 is transmitted to the CA decoder 103. If the conditioner 102 successfully decrypts the protected CA key and the protected WMDs and authenticates the CA key and WMDs, it could transmit the CA key to the CA decoder 103 and the
WMD to WM inserter 104. CA decoder 103 uses the CA key to unprotect content 112. Unprotected content goes to WM inserter 104. WM inserter 104 is responsible for synchronizing the WMDs (coming from conditioner 102) and the content to insert the brand in the right places. The marked and decrypted content 113 is then passed to the video decoder 105, which decodes the marked content. TV 106 receives marked and uncompressed content.
Authentication is based on signatures. For example, the watermark data includes a signature to authenticate the origin of the data. The signature is the result of the encryption of a summary of the workload (for example, the pre-dial records). The digest is calculated by preprocessing of header 100 (using, for example, a hash function) and encrypted by a signing key to produce the signature. This signature is added to the message and the message is preferably encrypted using a transmission key. On the receiving side, the message is decrypted first and the payload summary is calculated. With the key corresponding to the signature key, the received signature is decrypted and the result is compared with the calculated summary. If both values are equal, the message is
-10IMPI eg *
I HEARD THE FteFIHMl,. ,,. , -, mnurnuAL, authentic. The signing key can be a symmetric key or an asymmetric key (public / private keys) '
Figure 2 is a block diagram illustrating a robust watermark insertion system. The device may include a conditioner 102, a CA decoder 103, a server CPU 203, a WM inserter 104, and optionally a secure CPU 205.
The secure CPU 205, if used, may include circuitry, logic, and / or code that ensure control and customization of the watermark insertion process. The secure CPU 205 must be completely isolated from the server CPU 203 so that untrusted software (firmware) cannot run on it.
Conditioner 102 may include circuitry, logic, and / or code that receives (extracts), decrypts, and authenticates the protected CA key and protected WMDs. If a code is used, this code must be encrypted and authenticated by the
Secure CPU 205. Conditioner 102 must also have access to a reliable and non-modifiable value 204 (identifier, timestamp, etc). Conditioner 102 is also in charge of activating the WM inserter
104. The conditions contained in the CAS data may include instructions for choosing the identifier to be applied as a watermark on the content. This could be a unique identifier of the client device, preferably stored in the secure environment of the conditioner or an identifier contained in the CAS data (eg an identifier of the originator of the content).
The AC decoder 103 may include circuitry,
<img file="MX348381B_D0008.tif" />
IMPI
INSTnVT »MIXKAM M LA nOPIEBAB INBUmUAL logic and / or code to decode content protected with a CA key from conditioner 102. If a code is used, this code must be decrypted and authenticated by the secure CPU 205 and stored securely .
The WM inserter 104 can include circuitry, logic and / or code to insert a mark in the content not protected with the WMDs and the identifier from the conditioner 102. If a code is used, this code must be decrypted and authenticated by the CPU secure 205. Another important task of the WM inserter 104 is to synchronize the WMDs, which indicate where to insert the mark, with the content.
The server CPU 203 may include circuitry, logic and / or code that ensure the general functionalities of the device. The server CPU 203 cannot access the CA key, WMDs, and protected content between the CA decoder 103 and the WM inserter 104.
The secure link 210, 211, and 212 may include a private bus, logic, and / or RAM not accessible by the server CPU 203. Only entities linked by the secure link may have access to the transmitted data. For example, only the CA decoder 103 and conditioner 102 can have access to the CA key.
Apart from the above mentioned process, the purpose of this invention is also to avoid easy filtering of protected WMDs. The protected CA key cannot be removed by an attacker, otherwise the content will not be decrypted. For protected WMDs, the goal is to hide as much as possible, from the server CPU 203's point of view, their detection. Stage "
IMPI
ΜΓΠΤυΤΟ MLXIGAM.
μ the ηοηίΒΑΓ r ^ i —— μ INDUSTRIAL * * ideal will be that the protected WMDs could only be extracted by and be visible from the 1U2 conditioner. However, in most cases the protected WMDs are accessible by the server CPU 203 and therefore the goal is to force the server CPU 203 to pass the protected WMDs to the conditioner 102. Before talking about some means of applying the pass of protected WMDs to conditioner 102, the following list summarizes some possible channels from which the protected CA key and protected WMDs can come:
Protected CA Key and Protected WMDs can come directly from a server over ethernet.
The protected CA key and protected WMDs can be stored in a manifest (such as DASH).
The protected CA key and protected WMDs can be embedded in the content. For example, conditioner 102 can receive the protected CA key in an ECM and protected WMDs can be retrieved by conditioner 102 before AC decoder 103 (Figure 1). Another example illustrated in Figure 2 shows that WMDs are embedded in the content and are only available after the AC decoder (dotted line 230 from the decoder output). The WMDs are then protected, that is, they are encrypted with the CA key. A filter is located at the output of the AC decoder so that the WMD sub-stream is extracted and passed to the conditioner. WMDs extracted from the CA decoder can be further encrypted by a specific WM key known to the conditioner. In order to control the authenticity of the WMD, this data may
-13ΙΜΡ1 ^>
INSTITUTE MLXICANC
MurwiMAT 0-7 ^ »* industrial * g also contain a signature. This data is organized in packages and each package contains a package signature. The signature, as an example of an embodiment, is the hash value of the other data in the packet, this hash value is encrypted using a signing key. When the conditioner receives the WMDs, it then decrypts the signature of the packet and compares it to the hash value of the packet data. If the signature is verified successfully, the conditioner validates the current AC key and continues to power the AC decoder with the future AC keys; otherwise the locking mechanism is enabled.
In this configuration, conditioner 200 must first load the AC key into AC decoder 103 before receiving the WMDs. To this end, the conditioner includes a timer that is initialized when the AC key is loaded into the decoder. If after a predefined time the WMDs are not received by the conditioner, the latter blocks the decoder. This can be done by sending a fake CA key to the set-top box or by blocking future transmission of new CA keys. The timer can be used to release the lock after a second preset time. When this second time elapses, the conditioner transfers the current CA key and waits for the receipt of the WMDs. The timer resets if the WMDs are not received within the first preset time, the conditioner reverts to blocking mode.
In the mode in which the CA key and the WMDs are sent together, the main idea for applying the delivery of the protected WMDs to the conditioner 102 is to cryptographically bind with a signature mechanism (for example,
<img file="MX348381B_D0009.tif" />
IMPI
INSTITUTE MlüUCANH »
Dt LA nomUAL
INWUSTMAl
SHA-256) the CA key and the WDMs. This calculation can only be handled in conditioner 102. For example, video on demand content is rotated with a single CA key and all protected WMDs are stored in one row. To decrypt the content, the conditioner 102 must receive the protected CA key and all the protected WMDs, otherwise, the signature check that is made of the CA key and the WMDs will fail and the content will not be decrypted because the conditioner 102 will not provide the AC key to the AC decoder 103.
However, cryptographic binding between the CA key and the WMDs is not always possible. For example, the CA key has no correlation with the protected media data, which is closely linked to the WMDs in an MPEG-TS stream. WMDs alone can also be protected with the CA key as a media data type. In this case, the protected WMDs must be invisible from the point of view of the server CPU 203. Only the conditioner 102 can detect and use them. To illustrate this, Figure 4 shows the streaming of MPEG-2 TS content. In this example, the WMDs are included in a few stream elementary packages (ESPs) and then mixed together with other ESPs from the content. The workload of these ESPs is encrypted by a key known only to the conditioner 102. These ESPs and normal ESPs are encapsulated in TS packets and then encrypted by the encoder (eg DVB-CSAV2). From the standpoint of the server CPU 203, there is no difference between a TS package that contains a normal PES and one that contains a WMD Pes. The CA decoder 103 decrypts the
-15IMPI »INSTTTUT · MEXICANO DE LA PHOHEDA * INWUSTWAL
TS and then conditioner 102 detects the protected WMDs using specific flags. You can then decrypt them and pass them to the WM 104 inserter.
Another example illustrated in Figure 1 focuses on how to apply the watermark insertion process. Conditioner 102 is placed before AC decoder 103. Conditioner 102 extracts protected WMDs and then decrypts them. In this case the detection of the protected WMDs is easier and can potentially be done by the server CPU 203. To prevent leakage of the protected WMDs, the brand insertion technique is used as described in the patent application published under number EP2458890. With this technique, if protected WMDs are leaked, content will suffer considerable degradation. According to this example, the content decrypted by the CA decoder is not the same as the original and is called modified content. This modified content still includes some values (eg correlation coefficients) altered by the header, the original values are part of the watermark insert data. During the watermark insertion process, executed by the WM inserter, the pre-watermark record contains two values, one is the original value and the other is an alternate value. This alternative value is chosen in such a way that the visual impact is minimal.
Figure 3 is a flow diagram of an exemplary watermarking process. At step 301, after starting at step 300, conditioner 102 is in charge of receiving, decrypting, and authenticating the CA key and the WMDs. In step 302, the conditioner deciphers and checks the
-16IMPI ^
INSTITUTE MEXIGANC
M LA PkORKIAD ~ INBUST1UAL X »signature made in the CA key and in the WMDs. If the CA key and the WMDs cannot be authenticated correctly, the content is not decrypted because the conditioner 102 will not provide the CA key to the CA decoder 103 (step 304). Using this trick, the server CPU 203 is forced to pass the protected CA key and the protected WMDs to the conditioner 102 without any modification or filtering. If all is well, the conditioner 102 is also in charge of providing the WMDs and the trusted value to the WM inserter at the same time as the AC key for the AC decoder 103 (step 303). The trusted value is used only to identify the device. For example, this reliable value can be set and ensured in the device configuration.
This reliable value, as part of the device, is accessible by the conditioner and is also not modifiable by any entity in the device. Some calculations of this reliable value can be done within the conditioner before using it as a watermark workload to improve the robustness of this workload. For example, the trusted value can be a unique identifier that can be transformed / improved through an ECC, or an anti-collusion code such as a Tardos code.
Then in step 305, the Ca decoder decodes the protected content. Then, in step 307, this unprotected content is provided to the WM inserter to be marked. The WM inserter uses the WMDs and the trusted value to correctly insert the mark into the content. Unprotected content is never accessible to the server CPU before it has been properly marked. In step 308, if another key from
<img file="MX348381B_D0010.tif" />
IMPI i
IMSTHVn। MBXKJANW ¡mla noniOM »INTMJTHUAL
CA and / or new protected WMDs, the process will go to step 301.
The WM inserter may include a verification module in charge of verifying that the compressed content is the only one that the decoder is actually decrypting. The first check is based on the receipt of the compressed data. If no data is received at the input of the WM inserter, a message is returned to the conditioner, which in response will stop providing the CA key to the decoder.
Another verification that can be added to the previous one or can be applied independently, is intended to recognize the content to be inserted as a watermark. WM records include not only the content index and an alternate value, but also the original value of the content at the location pointed to by the content index. During the watermark insertion step, the WM inserter decides to change the original value of the content to an alternative value (or leave the original) according to the value of a bit of the identifier. In addition to this operation, the WM inserter can read the original value of the decoded compressed content and compare it with the original value contained in the pre-mark record. If the values are the same, the content that is in process at that moment is the genuine one. If the original value read from the content is different, it means that other compressed content was fed into the input of the WM inserter. In this case a message is sent to the conditioner to take the appropriate action (disable the CA key, for example).
Contents16
15 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15
22 members in 11 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 13165597 | European Patent Office (EPO) | A | |
| 13165597 | European Patent Office (EPO) | A | |
| 131655979 | European Patent Office (EPO) | – | |
| 2014058628 | European Patent Office (EPO) | W | |
| 2014058628 | European Patent Office (EPO) | W | |
| 131655979 | – | – | – |
| EP20130165597 | – | – | – |
| PCTEP2014058628 | – | – | – |
| WO2014EP58628 | – | – | – |
Members22
| Document | Office | Kind | |
|---|---|---|---|
| EP2797335A1 | European Patent Office (EPO) | A1 | |
| CA2908404A1 | Canada | A1 | |
| WO2014174122A1 | World Intellectual Property Organization (WIPO) | A1 | |
| SG11201508181SA | Singapore | A | |
| KR20160002844A | Republic of Korea | A | |
| MX2015014979A | Mexico | A | |
| EP2989805A1 | European Patent Office (EPO) | A1 | |
| US2016080831A1 | United States of America | A1 | |
| CN105432092A | China | A | |
| JP2016522435A | Japan | A | |
| MX348381BThis record | Mexico | B | |
| BR112015027089A2 | Brazil | A2 | |
| US9729941B2 | United States of America | B2 | |
| US2017339472A1 | United States of America | A1 | |
| US10015564B2 | United States of America | B2 | |
| CN105432092B | China | B | |
| JP6438459B2 | Japan | B2 | |
| EP2989805B1 | European Patent Office (EPO) | B1 | |
| BR112015027089A8 | Brazil | A8 | |
| ES2745401T3 | Spain | T3 | |
| CA2908404C | Canada | C | |
| BR112015027089B1 | Brazil | B1 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Publication
- 348381
- Publication, DOCDB
- 348381
- Publication, EPODOC
- MX348381
- Application
- 2015014979
- Application, DOCDB
- 2015014979
- Application, EPODOC
- MX20150014979
Titles2
- Spanish
- METODO PARA INSERTAR UNA MARCA DE AGUA EN UN CONTENIDO COMPRIMIDO CIFRADO POR AL MENOS UNA CLAVE DE CONTENIDO.
- English
- METHOD OF INSERTING A WATERMARK INTO COMPRESSED CONTENT ENCRYPTED BY AT LEAST ONE CONTENT KEY.
Classification
- CPC, 9
- H04N21/8358
- H04N21/4405
- H04N21/63345
- H04N21/8355
- H04N1/3232
- G06F21/10
- H04N21/6334
- H04N7/1675
- G06F21/16
- IPC, 4
- H04N21 8355
- H04N21 4405
- H04N21 6334
- H04N21 8358