Method for protecting decryption keys in a decoder and decoder for implementing said method.
Abstract
A method for securing control words (CW) within a decoder (10) in charge of deciphering the digital content protected by these control words, comprising the following steps: - for each decryption unit (14) of this decoder, uploading in a directory (22) a parity key (PK) referenced by means of an identifier (ID) associating said key to a decryption unit, - receiving at least one encrypted control word referenced by means of an indication (D) ) that allows identifying the decryption unit for which it is intended, - decrypting the control word using a first shared key with a security module (30), - identifying in the directory the parity key whose identifier (ID) corresponds to the destination indication (D) associated with the control word,- encrypt this control word using this parity key, - store in a register (15) the control word in a chronological and referenced manner.

Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
13 claims: 3 independent, 10 dependent
- 1A method of securing control words (CW) within a decoder (10) in charge of deciphering at least one digital content protected by said control words, said decoder (10) comprising a connected key processor (20), via a secure channel (25), to a security module (30) responsible for transmitting said control words (CW) to said decoder (10) in encrypted form, at least one decryption unit (14) responsible for decrypting the digital content, and a control word register (15) administered by means of said processor (20), the method comprising the following steps:1. Un método para asegurar pala-hras de control (CW) dentro de un decodificador (10) a cargo de descifrar al menos un contenido digital protegido por dichas palabras de control, comprendiendo dicho decodificador (10) un procesador de claves conectado (20), a través de un canal seguro (25), a un módulo de seguridad (30) a cargo de emitir dichas palabras de control (CW) hacia dicho decodificador (10) de forma encriptada, al menos una unidad de descifrado (14) a cargo de desencriptar el contenido digital, y un registro de palabras de control (15) administrado por medio de dicho procesador (20), comprendiendo el método las siguientes etapas: - cargar, para cada unidad de descifrado (14) en un directorio de claves (22) administrado por dicho procesador (20), una clave de paridad (PK) que por una parte se encuentra referenciada por medio de un identificador (ID) que la asocia con la unidad de descifrado (14) para la cual se destina únicamente y, por otra parte, es conocida por esta unidad de descifrado, - loading, for each decryption unit (14) in a key directory (22) managed by said processor (20), a parity key (PK) which on the one hand is referenced by means of an identifier (ID) which associates it with the decryption unit (14) for which it is intended solely and, on the other hand, is known from this decryption unit, - receiving, by means of said key processor (20), at least one control word (CW) encrypted by the security module (30), said control word (CW) being further referenced by an indication (D) that allows to identify the decryption unit (14) for which it is intended, - recibir, por medio de dicho procesador de claves (20), al menos una palabra de control (CW) encriptada por el módulo de seguridad (30), siendo dicha palabra de control (CW) referenciada además por una indicación (D) que permite identificar la unidad de descifrado (14) para la cual está destinada, - decrypt, by means of the key processor (20), said control word (CW) by means of a decryption key (SK) specific for said secure channel (25), - desencriptar, por medio del procesador de claves (20), dicha palabra de control (CW) por medio de una clave de desencriptación (SK) específica para dicho canal seguro (25) , -37 ,... ..... -37 ,... ..... - identificar, en dicho directjoikfe * - - * - (2 ^) 1 ^ 5 ^ 3 ^^ tNSTiTUTC MEXICANO - identificar, en dicho directjoikfe*- -*-( 2^ )1^5^3^^ tNSTiTUTC MEXICANO D £ THE PROPERTY parity key (PK) whose identifier (ID) cd ^^ S ^ onSte ^ to the destination indication (D) associated with. said word of _ control (CW), then D£ LA PROPIEDAD clave de paridad (PK) cuyo identif icador (ID) cd^^S^onSte^a la indicación de destino (D) asociada con . dicha palabra de _ control (CW), después - encrypt this control word (CW) using the parity key (PK) identified in this way, and - eñcriptar esta palabra de control (CW) utilizando la clave de paridad (PK) identificada de esta manera, y - almacenar, en dicho registro (15) de manera cronológica y referenciada, la palabra de control (CW) así encriptada utilizando la clave de paridad (PK), de manera que cualquier palabra de control específica requerida por la unidad de descifrado (14) pueda retirarse de dicho registro (15) a fin de desencriptarse y utilizarse por esta unidad de descifrado para descifrar una parte de dicho contenido digital. - store, in said register (15) in a chronological and referenced manner, the control word (CW) thus encrypted using the parity key (PK), so that any specific control word required by the decryption unit (14) can be removed from said register (15) in order to be decrypted and used by this decryption unit to decrypt a part of said digital content.
- 4The method according to any one of the preceding claims, characterized in that said control word register (15) is made accessible to any decoding unit (14) of the decoder (10). 4 . El método de acuerdo con cualquiera de las reivindicaciones precedentes, caracterizado en que dicho registro de palabras de control (15) se hace accesible para cualquier unidad de descifrado (14) del decodificador (10).
- 8The method according to the claim 6 o 8. El método de acuerdo con la roivíndícación 6 o 7, caracterizado en que la transmisión de dicha clave de paridad (PK) entre el procesador de claves (20) y dicha unidad de descifrado (14) se lleva a cabo utilizando un segundo canal seguro. 7, characterized in that the transmission of said parity key (PK) between the key processor (20) and said decryption unit (14) is carried out using a second secure channel.
Independent claims3
187 paragraphs in 5 sections, as filed
The reference patent is granted on the basis of Articles 1<sup>o</sup>, 2<sup>o</sup> fraction V, 6'fraction IU, and 59 of the Industrial Property Law.
In accordance with article 23 of the Industrial Property Law. this patent has a validity of twenty non-extendable years, counted from the date of filing of the international application and will be subject to the payment of the fee to maintain the rights in force.
Whoever subscribes to this title is based on the provisions of the articles<sup>0</sup> fractions III and 7 ° bis 2 of the Law of the Industrial Property (Official Journal of the Federation (DO.F.) 27/06/1991, reformed the 02/08/1994, 25/10/1998, 26/12 / 1997, 17/05/1999, 26/01/2004, 16/06/2005, 25/01/2006, 06/05 / 2009.06 / 01/2010, 18/06/2010, 28/06/2010, 27/01/2012 and 09/04/2012); article »1<sup>o</sup>, 3 ° fraction V sub-paragraph a), 4 ° and 12 ”fractions I and III of the Regulation of the Mexican Institute of the Industrial Property (D OF 14/12/1999, reformed the 01/07/2002, 15/07/2004, 28/07/2004 and 7/09/2007); Articles 1<sup>o</sup>, 3°, 4<sup>o</sup>, 5th fraction V sub-paragraph a), 16 fractions I and til and 30 of the Organic Statute of the Mexican Institute of Industrial Property (DOF 12/27/1999, reformed on 10/10/2002, 07/29/2004, 04 / 08/2004 and 13/09/2007); 1 °, 3<sup>o</sup> and the entry into force of the Agreement delegating powers to the Deputy General Directors, Coordinator, Divisional Directors, Heads of Regional Offices, Divisional Deputy Directors, Departmental Coordinators and other subordinates of the Mexican Institute of Industrial Property (BOF 12/15/1999, reformed on 04/02/2000, 29/07/2004, 04/08/2004 and 13/09/2007).
This office is signed with an advanced electronic signature (FIEL), based on articles 7 BIS 2 of the Industrial Property Law; 3 of its Regulations, and 1 fraction III, 2 fraction V, 26 BIS and 26 TER of the Agreement establishing the guidelines for the use of the Electronic Payments and Services Portal (PASE) of the Mexican Institute of Industrial Property, in the procedures indicated.
<td></td><td></td><td>THE DIVISIONAL PATENT DIRECTOR</td>
<td></td><td></td><td>NAHANNY CANAL REYES</td>
<td></td><td></td><td>Original String: NAHANNY MARISOL CANAL REYES | 00001000000403252793 | Administration Service Tax | 1695 || MX / 2017/56899 | MX / a / 2016/000585 | PCT Patent Title | 1027 | RGZ | Page (s) 1 | + W6oyD5IIF3sK5oZZQqTdSZmtkw =</td>
<td>aO</td><td></td><td>Digital Seal: M8KNAZ7CBKfbD1uFJBdGSG5a1mhxVfMRJ6Nhb4aAvipsSnlwpfsvro9uNsXfzdolknvM8cHFdz ADqLgE4RjAkKLRA ywp9BHWUkNujiSsojQfFX7kGe9Ss¡0Yh3Dg7WwfmJ + / o8gy / kQW2z / nXWY29aFCK7JofOG03B8BT6NSxkGiWTQzrTx YcpErAU yQzoJH7htXA2oghsa + + ydLBUy4IGnx5pG / MYvbnAUdoz5lauzCTUr4eT2mWtkgbUszD9fcoFn8kY4TUXaPD ZJ / PnmHOcdhV8fwAjZ1PCcvvCuxoTOBh3iBwo9Wj / 59eU TSpaHum4si9TmfO + / Relk3WYOA ==</td>
Arenal Nc 550. Floor 1, Pueblo Sania Mana Tepepan. Xochimilco. 16020 Mexico City (55) 53340700 www gob.cix / iinpi
111111111111
MX / 2017/56899
METHOD FOR PROTECTING KEYS FROM DE SENCRIPTfrC «
S · - industrial ”DECODER AND DECODER TO IMPLEMENT THIS METHOD
Field of Invention
The present invention relates to the field of conditional acquisition of digital data, such as data transmitted on pay television and in particular, relates to the protection of decryption keys of digital content, mainly audio / video content.
Background of the Invention
A piece of content, for example of the audio / video (A / V) type, is encrypted by means of keys called control words (CW) that change regularly, typically every minute. The content thus encrypted is then transmitted to the receivers according to a diffusion method, ie, the same content is received by a plurality of receivers.
The control words are encrypted by means of a transmission key (TK) that changes with a much lower frequency, for example every month. An encrypted control word is placed in an Enable Control Message (ECM) accompanied by decryption conditions. These conditions describe the rights that the recipient must have to be authorized to access the content. These rights are regularly transmitted to the receiver in encrypted form via Enabling Management Messages (EMM). ECM enable control messages and EMM enable management messages form a set of DT data messages that join
-2IMPI to the encrypted content to form a stream ® iiwu .'- triai (TS) sent to the receivers.
The offer offered to pay-TV subscribers includes many channels (CH1, CH2, CH3, etc.) that are each encrypted according to one or more particular keys. This is necessary because the subscriber can subscribe to one channel, without having the right to enjoy other channels.
ECM enable control messages are encrypted with a specific key for the management system (CAS - Conditional Access System) usually associated with the header from which the transport flow comes. The subscriber's receiver includes, among other things, a secure cryptographic unit (SM - Security Module) in charge of decrypting these messages, and a decoder (STB - decoder) that will decrypt the encrypted content in order to be able to display said content. The management system transmits these ECM messages in encrypted form to the cryptographic unit in charge of decrypting these messages, it manages the authorizations and, according to the subscriber's rights, transmits the information necessary to decrypt the video and audio signals to the decoder .
The results of the decryption by means of the cryptographic unit are precisely the control words CWs. These control words will guide the decoder and therefore the subscriber will enjoy, in an unencrypted way, the transmitted information.
As mentioned above, these control words are changed regularly in order to prevent a hacker
ΙΜΡΙ «
INSTITUTO MEXICANO calculate this control information by «fe® powerful computer, and that the service subject to payment is used freely. This is why these control words are changed at commonly regular intervals, with the period typically being 1 to 20 seconds. This period is called the crypto-period.
ECM enable control messages are sent with a much higher frequency than the crypto-period, for example every 100 milliseconds. This is essential on the one hand when starting the decoder service and on the other hand when changing channels (CH1, CH2, CH3 etc.).
Certainly, in order to be able to observe the desired program, the control words are needed to decrypt the signals. It is difficult to imagine a 5-second wait in front of the monitor until the unencrypted image appears.
In the second case, being the control words specific for each channel, it will be necessary to wait for the end of the crypto-period in order to receive the enable control message that allows the decryption of the signals of the new channel. In the same way as before, it is not possible to tolerate a delay of several seconds when changing the channel.
This is why, in practice, ECM enable control messages are sent at a frequency of 5 to 20 per second.
Therefore, once the decoder has received the control word, it can decrypt the audio / video content. Currently a decoder can process more than one encrypted stream may be the case for a record of a stream and
<img file="MX349246B_D0001.tif" />
PIP (picture-in-picture) function, the display of another, or the simultaneous display of several streams on the same monitor (mosaic of images coming from several different channels) or on several monitors. For this purpose, the decoder will have the ability to process several streams in parallel and therefore has to have several control words at the same time.
Another explanation for the presence of several control words referring to several channels is the speed of the channel change. It is certainly desirable for this change to be made within the shortest possible time and according to a particular method, although the decoder may process one or two streams simultaneously, the decoder may store 10 or 20 control words at a given time. The cryptographic unit in charge of processing the ECMs will extract the control words from a plurality of channels and send them to the decoder even if the decoder is not in charge of decrypting the content. This allows you to be ready immediately with the control word loaded on the decoder as soon as the user requests a channel change.
Even if only one control word is active for a given time, the decoder must have the current control word and the next control word. For this purpose, the encrypted content includes an indication to identify the control word (ODD (EVEN), EVEN (PAR)).
Based on the above, it looks like the decoder
-5 will store a lot of words from
<img file="MX349246B_D0002.tif" />
INSTITUTO MSXICANl cent W »for simultaneous use, to be ready in case of change of channels, or for a combination of these two modes. Therefore, it can decrypt three channels simultaneously and store the control words for the 30 possible channels that the user can receive. Each channel represents two control words.
Because the cryptographic unit is satisfactorily secured, malicious third parties have become interested in intercepting control words transmitted through the cryptographic unit. That is why solutions have been proposed as described in EP 1078524. The encryption of the control words is performed by means of the cryptographic unit before its transmission to the receiver. The receiver and the cryptographic unit share a unique key that allows you to pair these two elements. No message intercepted between these two elements can be used by any other receiver since the parity key is unique.
Once it reaches the receiver, the message is decrypted using the parity key and the control word is stored safely in a secure memory of the receiver.
WO 2006/044547 refers to the time required by the decoder when, starting from an encrypted transport stream, it has to switch from one channel to another in order to satisfy the request of a user wishing to switch from one television channel to another. another. This document sets out the use of a buffer in which control words are temporarily stored for the purpose of reducing the waiting time between the time the
-6_ _. _ Π ______. _. . ι η _, Oí THE PROPERTY user selects another channel and the moment θΠΝουχψΰί® content of this new channel is displayed safely on the TV screen. Within the buffer, the control words are constantly renewed according to the principle of a stack of control words from which the old control words are successively removed to be replaced by the new ones. This buffer is managed by means of a control word processor. In order to be able to reduce the time required for the change, this document suggests in particular storing in the buffer not only the control words useful for deploying the channels at a given time via the TV, but also the words of control of the other channels, ie, the channels that are not displayed or registered at that time. This document finally suggests that control words stored in buffer are stored in encrypted form by means of a specific key for a secure channel that links the control word processor to the security module from which these control words are extracted. of ECM messages. When switching from one channel to another, the control words related to the new channel will be decrypted by the processor using the key associated with the secure channel between this processor and the security module. They will then be transmitted to the appropriate decryption unit so that this unit can proceed with the decryption of the new audio / video channel.
The invention mentioned in US 2012/0257749 is intended to enhance the security of control words
- 7 IMPI ^ while improving efficiency and velow ^ '. W sst • NÜUSTMIAL verification operations before decrypting a protected audio / video stream. To this end, the method suggested in this document essentially focuses on access condition checks performed successively by means of two conditional access devices in an ECM message. Therefore, this invention proposes to modify the ECMs control messages so that each ECM is structured in such a way that the first ECM1 message encapsulates the second ECM2 message instead of the control word commonly contained in the first ECM1 message. Therefore, this document suggests a double check of the access conditions by the successive arrangement of two conditional access devices, one for the ECM1, the other for the ECM2, before returning the control word contained in the second ECM2 message.
Summary of the Invention
This application addresses the security issue of decryption (CW) keys stored in the decoder. The decoder according to the invention is part of the receiver and generally has the form of a specialized circuit that incorporates many functions such as receiver management, menu display, register management. This is a set of specialized components of which one is a microprocessor that integrates a decoder function into a part of the microchip. This component has an internal memory and can access programs or data stored in an external memory.
-8IMPI ^
Generally, the words control an internal memory intended for this purpose. Control words need to be available very quickly when the crypto-period changes. Although it is difficult to access this memory, attacks by software or by technical failure, laser, buffer overflow have provided positive results.
That is why it is proposed to secure the decoder by encrypting the control words waiting to be used.
Therefore, a method is proposed for securing the control words · stored, in a memory, inside a decoder in charge of deciphering at least a piece of the audio / video content protected by said control words. The decoder comprises a key processor connected, via a secure channel, to a security module in charge of transmitting the control words to the decoder in encrypted form, at least one decryption unit in charge of decrypting the audio / video content, and a control word register managed by the key processor. According to the invention, this method includes the following steps:
- load, for each decryption unit in a key directory managed by the processor, a parity key (PK) which on the one hand is referenced by means of an identifier (ID) that associates this key with the decryption unit to which is intended solely and, on the other hand, is known by this decryption unit, to receive, by means of the key processor, the
IMPI ^
INSTITUTO MtXICAN'minus a control word (CW) encrypted by security, this control word (CW) being further referenced by an indication (D) that allows to identify the decryption unit for which it is intended,
- decrypt, by means of the key processor, this control word by means of a specific decryption key for the secure channel,
- identify, in the directory, the parity key whose identifier (ID) corresponds to the destination indication (D) associated with the control word, then
- encrypt this control word using the parity key that has been identified, and
- store, in the register in a chronological and referenced way, the control word encrypted by the key (PK) so that any specific control word required by the decryption unit can be removed from the register in order to be decrypted by means of this unit and used by the unit to decipher such audio / video content (or at least a portion of that content).
The present application also proposes a decoder for the implementation of this method according to any modality of this method. The decoder, according to the second object of the present invention, includes a key processor connected via a secure channel to a security module in charge of transmitting the control words (CW) to the decoder in encrypted form, at least two units of decrypted each in charge of decrypting the audio / video content encrypted by a part of the control words, and a record of control words
UMSTiTUTOMEXlCANC managed by the key processor. This p ^^ g ^^ r xjprMF keys is also configured to decrypt the control words received from the security module and to store them in the registry in encrypted form. According to the invention, this decoder also includes:
- a memory for storing at least one key directory managed by the processor and configured to register a plurality of parity keys (PK), each parity key being referenced by an identifier (ID) that uniquely associates it with one of the decoder units of the decoder,
- a reference module which makes it possible to reference each control word (CW) by means of an indication (D) which identifies the decryption unit for which this control word is intended on the basis of an audio / video channel from which extracts each control word.
According to the invention, the key processor is also configured to have the ability to identify, in the directory, the parity key whose identifier (ID) corresponds to the indication of the destination (D) that references the control word, and to encrypt it using the parity key identified in this way. Finally, the record is configured to store the control words (encrypted by the PK key) chronologically and referenced).
Description of the Figures of the Invention
This invention will be better understood thanks to the explanations based on the Figures in which:
Figure 1 shows the main components of the
<img file="MX349246B_D0003.tif" />
-11 invention in a decoder,
IMPI
INÍTITUTüMEXICaní 'of the PROHEiMD INDUSTRIAL
Figure 2 shows the exchanges that take place between the different elements of this decoder.
Detailed Description of the Invention
Figure 1 shows a decoder 10, in particular the elements of this decoder which are useful for understanding the invention. The decoder 10 receives, in the form of TS transport streams, the audio / video streams encrypted by means of the control words CWs.
In the present description as well as in the accompanying figures, it can be seen that the encryption of a stream or any other data will be indicated by the placement of this data in square brackets. Therefore, in Figure 1, the encrypted transport flow TS by means of the control words is indicated as [TS] cw. This transport stream is typically composed of data packets within a signal transmitted by the header to a plurality of decoders 10, for example via a satellite or terrestrial (radio waves), via a network of cables. (landlines, internet, cable) or over a wireless network (mobile phone network or other broadcast network).
As the data packets have been multiplexed by means of the header so that the information they contain can be transported only by means of a transmission medium (transport flow TS), this composite signal has to be disassembled by means of a demultiplexer. 11 in its entirety in the decoder 10 in order to have the ability to recover each audio / video channel
- 12 IMPIOS
CH1, CH2, CH3, etc., which contains. Each one<sup>J</sup> (still encrypted) includes audio data (eg multiple audio channels), video data, as well as control data (F.CM, EMM) and other information (metadata). As shown in Figure 1, the audio / video data ([A / V]) of each channel is then separated from the other data (Data), in particular the control data ([DT]), by means of of a classification device (SD) 12. This audio / video data is encrypted using the CWs control words contained in the ECM messages that are part of the DT control data. This control data is also encrypted by means of a TK transmission key.
The decoder 10 also includes a key processor (KMG) 20 connected, via a secure channel 25, to a security module (SM) 30. This security module is responsible for providing, in encrypted form, control words to the decoder 10 after verifying that the rights, administered by means of the EMM messages, are also present in the user's environment (in particular in the security module).
Such a safety module 30 can be made in particular according to four different modes. One of them is a microprocessor card, a smart card or, more generally, an electronic module (in the form of a key, badge, ...). Such a module is generally removable, connected to the receiver and is considered secure. The exchange of data between the decoder and the security module that is associated with it is usually performed by means of a physical contact (electrical contacts of a communications port). However, no
-<sup>13</sup>· L'UTITUTO MEXICANO Λ líELAPROmiMI · -, -,. . . ,. . ,. ,, industrial excludes the provision of an exchange of data between these two entities through a connection or ..... f i. ft— sings gí. ^>., -............. for example, of the ISO 15443 type.
A second mode is that of an integrated circuit placed, usually permanently and non-removable, in the housing of the receiver (decoder). A variant is a circuit installed in a base or connector, such as a SIM module connector.
According to a third embodiment, the security module can be integrated, within the receiver, into a device which also has another function, for example in the microprocessor of the decoder.
According to the fourth modality, the security module is not made in material form, but its function is implemented only in software form.
Although the level of security between these cases differs, the function is identical so that it will refer to the security module regardless of how this module is performed. In the four ways described above, the security module has means (memory, central unit) to store and carry out an internal program. This program allows to carry out different security operations such as verifying the rights, carrying out decryptions, activating a module to carry out cryptographic operations in it, etc.
If the presence of the required rights is required to enable access to the audio / video contents of a channel (CH1, CH2, CH3, etc.), the security module 30 extracts the control words CWs from the
<img file="MX349246B_D0004.tif" />
ECM messages, after having decrypted them using the RK transmission key, re-encrypts them using a unique SK key (secret key) which is also only known by the key processor 20 and which is therefore specific to the established secure channel 25 between these two entities 20, 30.
To enable decryption of re-encrypted control words via the security module, the key processor 20 includes a cryptographic module 23 (CRYP). Therefore, this unit 23 is configured in particular to decrypt the control words received from the security module 30 using the unique key SK.
Returning to the main elements that make up the decoder 10, it is noted that the latter includes at least one decryption unit 14 (DSC) in charge of decrypting the encrypted audio / video contents [A / V] received from the classification device 12 corresponding.
The decoder 10 also contains a register 15 (REG) of control words which is managed by the processor 20. As shown in dashed lines in Figure 1, this register 15 (or table of control words) could be a part of the processor 20.
The decoder 10, preferably the key processor 20 of this decoder, also includes a memory for storing a key directory (DIR) 22. This memory or directory is configured to list a plurality of parity keys (PKs). This directory 22 is intended to be managed by the processor 20.
Among the components of this decoder, there is also a reference module 24 (RFM) which
-15IMPI •, r-,. ,,<sub>n</sub> thJF.TbTO MEXICAN ·. Vx * · **. · »<sub>w</sub>·· Γ allows to reference each control word (CW ^ Hrj ^ íwed'í ^ an indication (D) which identifies the decryption unit 14 for which this control word is intended according to the identity (CH1, CH2, CH3 , etc.) from an audio / video channel from which each control word is extracted.
Finally, the decoder may also comprise at least one random number generator 18 that can be used to generate the PK parity keys, as will be described in more detail after the description. Like the register 15, this random number generator could also be part of the processor 20. Alternatively, such a generator 18 could be integrated into or associated with each decryption unit 14.
As shown in Figure 1, the directory 22 and / or the reference module 24 are preferably part of the processor 20. Finally, the processor integrates a central processing unit (CPU) 26 useful for managing the different devices that are or can be be included in the key processor 20.
It should be noted that the number of decryption units 14 (in this case three) shown in Figure 1 is provided as an example and is in no way intended to be limiting. The decoder 10 includes at least one decryption unit 14, preferably at least two units 14, each responsible for decrypting one of the multiplexed audio / video streams. The number of decryption units can be multiplied to enable parallel processing of as many audio / video streams as needed.
After the description of the main components of the decoder that are necessary to understand the invention,
<img file="MX349246B_D0005.tif" />
the steps of the method of this invention.
In its first object, the invention relates to a method for securing the control words CWs within the decoder 10.
The first step of this method is intended to load, for each decryption unit 14, a PK parity key in the key directory 22. This PK parity key is referenced by means of an ID identifier that associates it with the unit of decryption to which it is uniquely intended. Therefore, there will be as many PK parity keys as decryption units 14. As shown in Figure 1, the parity key PK1, i.e., the one found by the identifier ID1, is intended for the decryption unit DSC1, ie the decryption unit 14 which also contains the identifier 1. The association of the parity key PK with the corresponding identifier IDn can be achieved in different ways, for example, by means of a register (ie, a tupia or a computer data structure) that contains exactly these two elements. Therefore, directory 22 will comprise as many records as PK keys and each of these records will comprise at least two data, ie, the PKn key and the IDn identifier associated with this key. Alternatively, the association of the parity key PKn to the identifier IDn could be obtained by means of several directories 22 or sub-directories, each of them being identified by an identifier IDn and comprising the corresponding key PKn.
In addition, each parity key PK is recognized by the decryption unit 14 to which MS! Consequently, each parity key PK is uniquely recognized by a pair formed by the key processor 20 and the decryption unit 14 for which this key is reserved. The transmission of this PK parity key from the processor 20 to the decryption unit 14, or vice versa, can typically be performed during an initialization phase prior to any safe return of the audio / video contents.
The second stage of the method takes place mainly within the key processor 20. This second stage is intended to receive at least one CW control word transmitted, in encrypted form, by the security module 30. For this purpose, each CW control word it is encrypted by means of the secret key SK known only by the decoder 10 (in particular by the key processor 20 of this decoder) and by the security module 30 associated with this decoder 10.
According to the invention, the word control
CW received from the security module 30 is referenced by an indication D which makes it possible to identify the decryption unit for which it is intended. This indication D can be the ID identifier of the decryption unit 14. According to a preferred embodiment, this indication is placed inside the decoder 10 (ie, in a local environment at the user's location) so that the data flow DT, which contains in particular the control messages ECMs and therefore the CWs control words, do not need to be modified or customized. Therefore, the transport flow TS remains as an ordinary flow, ie, a
<img file="MX349246B_D0006.tif" />
flow whose structure is recognized from the prior art and current standards. The Jüydllitírite ^ -e ± decoder 10 described in the present invention is therefore still compatible with such TS flow.
In the preferred embodiment of the invention, the reference of the control words CWs by means of the indication D is carried out by the reference module 24. This reference module is connected to each classification device 12 by means of a path intended for the transfer of DT data from an audio / video channel. Therefore, the reference module has the ability to associate an identifier with each data packet, in particular, with each ECM, coming from each channel (CH1, CH2, CH3). For example, the ECMs provided by the CH1 channel are referenced by the indication DI, those provided by the CH2 channel by the indication D2 and those of the CH3 channel by the indication D3. Because each control word is included in an ECM message, this means associating, within the decoder, a D indication with the control words depending on the identification of an audio / video channel from which each control word can be extracted. by means of an ECM message.
After extracting the CW control word (s) from each ECM, the security module 30 has the ability to transfer to each control word the indication D that had been placed in the ECM message from which it was extracted. this control word. Once transferred to the corresponding control word, the indication D can be kept safe or encrypted by means of the secret key SK. Preferably, the control word CW and its tüTITUTO MEXICANO indication of destination D will be encrypted in a single ^ using the secret key SK by means of the security module 30. Regardless of the mode of operation, the channel (audio / video) of each control word remains identifiable by means of the key processor 20, even after processing these control words by means of the security module 30.
The third step of the method is to decrypt the control word received from the security module through the key processor. For this purpose, the processor will use the secret key SK which is specific to the secure channel 25 established between these two entities. If the control word CW and the associated indication D have been encrypted in a block by the security module using the secret key SK, the operation of decrypting the control word by means of the processor 20 also makes it possible to find the indication D safe. associated with the corresponding control word.
The fourth step is intended to identify, in directory 22, the parity key PK whose identifier ID corresponds to the indication D associated with the control word CW received from the security module. This operation is performed by means of the processor 20, for example, by checking the records stored in the directory 22 to look for the record containing the ID identifier corresponding to the indication D of the control word. Once the processor has identified the searched record, it then has the ability to know the parity key PK which is associated with the decoding unit 14 which is identified in the control word.
-20IMPI
.. -.1C MEXICAN ~ „4_ _ _. . · ____ _, _, · _ _ _ ^ ^ ί2ΠΗ> ΑΙ>
The fifth stage aims at enertt-pus-aisi control word using the parity key PK ....... identified in this way. This encryption can be performed, for example, by means of the cryptographic module 23 of the processor 20.
In the sixth step, the control word is then stored, in this new encrypted form, within the register 15 by means of the processor 20. This storage is carried out chronologically and referenced in such a way that any specific control word required by the decryption unit may be removed from said register in order to be decrypted and used by this decryption unit to decrypt a portion of said audio / video content.
The chronological character of this storage can be obtained by storing the control words in a particular order, in particular in the order of arrival within the transport flow. This order corresponds to the order in which they have to be used by the decryption unit in order to decrypt the audio / video content. A successive stacking of the control words, treated by the processor allows to respect the chronology of these words in a very simple way. Alternatively, it would also be possible to associate a time index with each control word stored in record 15. Such an index could take the form of a value incremented by one unit for each new control word stored. The time index is also in the form of a time stamp determined by a clock enabled, for example, to be used specifically for this purpose.
<img file="MX349246B_D0007.tif" />
encrypted control words in register 15 words can be obtained in the same way as already described to reference the PK parity keys in the directory 22. Therefore, as shown in Figure 1, each encrypted control word using a parity key Particular PK can be stored in a register that includes the indication D related to the destination of this control word [CW] pk. Because this indication D allows either to identify the channel CH1, CH2, CH3 associated with this control word or to identify the decryption unit 14 that will have to use it, the destination of each control word of the register 15 is therefore duly identified .
Advantageously, the encryption and decryption of the control words [CW] pk using the parity key PK are performed locally in the decoder, excluding even the security module of this decoder. Therefore, the protection of these control words is a protection that is unique to each decoder and that only concerns it. At this stage, the security module is therefore no longer required to ensure the decryption of the audio / video content by means of the decryption units 14. In addition, thanks to the directory 22 in which several PK parity keys can be stored, this mode makes it possible to provide particular protection to each decoding unit 14 of the decoder 10. Therefore, even if one of the PK keys is cracked by a malicious person, that person will be disabled to decrypt the audio / video contents of the other channels in the transport stream.
-22INSTITUTO MP.XICAN;
FROM WOPItL Ai: V *<sup>1</sup>* * ^ Γ “μΓ
TS. The level of protection provided by this TOWdo s? 'therefore reinforces advantageously. ,, -, -
In addition, the encryption of the control words CWs by means of the parity key PK is advantageously carried out only by a cryptographic module 23 for all the decryption units 14 of the decoder. Because this operation can be centralized, the decoder's computing resources are streamlined.
Additionally, the memory housing the register 15 advantageously allows a large number of control words to be stored. The storage of these control words in the registry can be by LanLo a more or less durable storage. Certainly, the criterion that determines the duration of this storage does not depend on the size of the memory that houses the register as is generally the case in buffer type memories. In the present case, the control word may remain in the register 15 at least as long as it is not used by the decryption unit for which it is intended.
Advantageously, this invention makes it possible to fully insure it. access to the control words within the decoder 10. Therefore, all paths through which the control words pass are safe paths and no control word uses a path in an unprotected form. Therefore, even if a malicious person were tempted to extract the control words during their transit between the processor 20 and any of the decoding units 14 of the decoder, this person would not be able to use the extracted data. Thanks to the protection of
<img file="MX349246B_D0008.tif" />
IMPI t'üTiTJTO MEXICANO. ,, U¿ LA PROrjMJAl>
all the paths through which traWSTWn control words inside the decoder, it is also possible to physically separate the processor 20 or the register 15 from the decryption units 14. This allows to give a welcome flexibility in the composition of the decoders and, in particular, to ensure the best arrangement of its components.
Even advantageously, this invention suggests storing, in register 15, the control words and not the ECM messages. This type of procedure makes it possible to optimize computing resources, in particular the memory space and the speed of the return of the control word to the decryption unit that requests it when decrypting the audio / video content. Certainly, ECM messages contain indications related to the rights that users (decoders) have to possess. Once the security module processes these indications, it is therefore appropriate to separate it from these indications that have become superfluous and to keep only the essential data in the decoder in such a way that it can decrypt the audio / video contents at any time. Therefore, by deleting the storage of ECM messages, the storage of TK transmission keys can also be deleted, which allows the ECM to be decrypted. Knowing also that these transmission keys change regularly, it also avoids the need to ensure the temporary management of these transmission keys.
In order to further optimize the time for processing the control words by means of the <sup>24</sup>'. ΙΜΡΙ @> ^ tHSTiTOTO MtXICANV Λ
L »£ LA> · κυ Μ He> AI cryptographic algorithm by encr i ptfffTOS<sup>1</sup>· Decrypt them, preference will be given to the choice of a symmetric key as a parity key type PK. In addition, the use of fast algorithms will also be privileged to reduce as much as possible the time required for the encryption / decryption of a simple control word.
Even advantageously, the use of the directory 22 makes it possible to store a plurality of PK parity keys, each duly identified and reserved for one of the decryption units 14 of the decoder. Therefore, the use of this directory allows you to give specific protection to the different control words according to their destination or according to the channel through which they come. The plurality of PK parity keys allows to increase the security level implemented to protect the access to all the control words inside the decoder.
Thanks to this invention, it will be noted that decryption units 14 are only responsible for performing decryption operations during the processing of the audio / video stream (s). Certainly, these operations are intended first to decrypt the control words using the PK parity key and second, to decrypt at least part of the audio / visual content using the control word just decrypted. These two successive operations can therefore be carried out, on the one hand by means of the same entity (decryption unit) and, on the other hand consecutively so that there is no interruption between the moment when the word
-25IMPI control is decrypted and when IHDVSTRIAL crypto-period time is used. Therefore, any risk of stealing the safe password of a malicious person is reduced to zero, since the acquisition and use of this safe password will be carried out consecutively within the same entity.
The decryption of the control words [CW] pk in the decryption unit 14 is carried out, as shown in Figure 1, within a decryption module 13 of this unit 14. The decryption unit and its decoding module decryption are closely linked and are preferably located in the same area in the microchip of an electronic component. Because it is monolithic, such a unit would have to be physically broken to gain access to its internal circuits, in particular its decryption module 13. However, once destroyed, this unit no longer has, of course, the ability to decrypt the control words.
Due to its structure, the register 15 can be placed in a less protected environment. As shown schematically in Figure 1, the register 15 of the control words is preferably made accessible to any decryption unit 14 of the decoder 10. Therefore, when a decryption unit 14 requires a new control word (to subsequently proceed with the decryption of the audio / video content after the end of a crypto-period), it can access the register 15 itself in order to extract of the same the following control word addressed to it, ie the one whose indication D corresponds to the identifier ID which refers to
-26this indication.
you can send one
As an alternative
<img file="MX349246B_D0009.tif" />
request to record 15 (or key processor 20) to indicate that this is a cipher needs to receive the next relevant control word.
Thanks to the ID identifier that, for example, can be associated with the request (to determine the requesting decryption unit) and with the indication D of each control word, the register (or key processor) can then search for the next word control of this unit and can transmit this control word to this unit in response to the request of the unit. In both cases, each control word required by any decryption unit is transmitted and stored in the register, ie in encrypted form (using the parity key PK which is specific to the unit).
If necessary, the decryption unit 14 could also store, for example in a local register specific to this unit, a reserve of control words (for example, the current control word and the next control word), in view of its use. In this case, the decryption unit 14, its local register, as well as its decryption module 13 will be considered as formators of a monolithic entity.
According to one embodiment, the decoder 10 includes at least two decryption units 14 with the ability to process encrypted audio / video streams according to different algorithms. For example, a first decryption unit is of the DVB-CSA type and another is of the AES type. The ECM control message, which contains the control word CW, also contains an indication to identify
IΜ ΡI to which type of algorithm and consequently to cu8? ™ g $ ^ deciphered is intended. This indication (D) is stored in register 15 with the control word [CW]<sub>PK</sub>.
As a result, it is possible (but not necessary) to use a different encryption key for each type of decryption unit. Certainly, the processor 20 may have more than one directory 22 of parity keys, for example one for the DVB-CSA decryption unit and another for the AES decryption unit. Thanks to the indication (D) reported in the control word, the processor 20 can select the parity key PK of the corresponding decryption unit 14 and encrypt the control word CW with this key PK.
It should be noted that, if the decryption units 14 can be identified according to their type, the indication (D) described above can be replaced by simply detecting the format (or type) of the control word. A control word for a DVB-CSA encryption may be of a different size than a control word for an AES encryption. This allows the processor 20 to select the appropriate parity key PK for the corresponding decryption unit.
Figure 2 shows the dynamic operation of the main elements of the decoder shown in Figure 1. Accordingly, this Figure is presented in the form of a diagram that, globally, is read from top to bottom and from left to right. The main elements of the decoder that are useful for understanding this operation are represented in the first top line. The dynamic operation of this set of elements is
-28IMPIO ^ describes by means of a succession of stage ^^ T ^ & t®XiÓ «i ^
IHDUMIUaÍ by shaded and numbered arrows from 1 to 9. These stages define two distinct phases. The first phase is formed by steps (1), (1 ') and (1). The second phase includes steps (2) to (9) which, as shown schematically by means of the rectangular arrow surrounding them, is intended to be repeated for each CW control word.
The first phase aims to load the parity key PK. This loading takes place, on the one hand, in the directory 22 of the processor 20 and, on the other hand, in the decryption module 13 of the decryption unit 14 for which this parity key PK is intended. Several scenarios are possible.
The PK parity key is permanently loaded during a decoder initialization phase. During the manufacture of the decoder or during a phase of preparing the decoder for a given operator or a given customer, the decoder 10 is placed in test mode and a PK parity key is generated (either by means of the test equipment or by the decoder processor) and is transmitted to the directory 22 and the decryption module 13 of the decryption unit 14. This PK parity key is stored during the decoder lifetime until a new test mode is initialized.
The PK parity key is loaded each time the decoder is turned on. For this purpose, a PK parity key is randomly generated, using the generator 18, by means of the processor 20 or by means of the decryption module 13 and transmitted to the other
<img file="MX349246B_D0010.tif" />
<img file="MX349246B_D0011.tif" />
entity, ie respectively to INDUSTRIAL decryption 13 or processor 20. The processor 20 further transfers this PK key to the z2 directory for storage. The parity key PK is generated randomly by means of the random generator 18.
Certainly, this generator can be associated either with the processor 20 or with each decryption unit 14, in particular it can be integrated in the decryption module 13 of each of these units. This generator 18 can be a real source of random numbers, a source of pseudo-random numbers, or even a mixture of physical data from the decoder, such as temperature, date, reaction time of the remote control. The generation of this PK parity key is shown in Figure 2 by means of the eLapa (1). Steps (1 ') and (1) illustrate how this parity key PK is shared respectively between the processor 20, in particular the directory 22, and the decryption unit 14, in particular the decryption module 13 of this unit. It should be noted that the channel between these two entities 20, 14 is secured (second secure channel), ie, a session key is negotiated between these two entities, for example, using the Diffie-Helmann algorithm. Another means of ensuring the protection of such a channel could be to restore material resources. For example, the common link through which the exchanges between entities 20 and 14 pass could be a private common link only accessible by these two entities.
Steps (1), (17) and (1) can therefore be formulated as follows:
-30Γ Ρ
- (1) generating a parity key®for the medium UUSTITlfTC MEXICAN yjrr-.n.,. · Á. of the processor 20 or by the decryption unit<sup>us</sup>í2ív
- assigning to said PK parity key the specific ID identifier for the decrypted unit 14 to which this PK parity key is uniquely associated,
- (1 '), (1) transmitting the parity key PK thus referenced between the key processor 20 and the decryption unit 14 so that this parity key PK is known by these two entities.
According to one embodiment, the random number generated by one of the two entities 14, 20 (using the generator 18) is then applied to a cryptographic function contained in the entity in question and initialized by means of a customization key. This key is initialized during a preliminary initialization phase. Therefore, it is possible to customize each decoder or set of decoders with a particular value of the customization key. The cryptographic function can be of the one-way type (Hash function). The result of the cryptographic function produces the parity key PK. Even if the random number generator is compromised and always generates the same value, modifying this value using the cryptographic function will provide a parity key that will be different from one decoder (or set of decoders) to another.
The step (1) intended to generate the parity key PK may therefore comprise the following sub-steps :
- obtain a random number by means of a random number generator 18, a number source mttLKvssgasxsKS? **
-31 IΜ PT
J »y J JB Γ. * <J pseudo-alcatorios, or a mixture of data ^ -<sub>r</sub>-uhp ^ ¿^ L> <^ el ~ · La¿XCW1> au decoder 10, such as temperature, TecH'a cSt user reaction time, ...... ..___
- apply this random number to a cryptographic function contained in the decoder and initialized by means of a customization key to obtain the parity key PK.
The second stage of Figure 2 shows the steps (2) to (9) that are carried out in the decoder to process and manage each CW control word, from its reception by the security module to its use by one of the decryption units 14. As soon as the processor 20 receives a control word [CW] sk, it sends it (2) to the cryptographic module 23. The latter, thanks to the secret key SK, decrypts it (3), then re-encrypts it immediately (4) thanks to the appropriate parity key PK which has been identified in directory 22, either by means of the central unit 26 or directly by the cryptographic module 23. The identification of this PK parity key can be obtained by establishing an equality between the ID identifier associated with the PK key and the destination indication D that references the control word. Once encrypted using the PK parity key, cryptographic module 23 sends (5) the control word [CW]<sub>PK</sub> to record 15 of the control words. This control word can be stored in it in this new encrypted form at least until use.
When any decryption unit 14 needs a control word to decrypt a new piece of audio / video content that decrypts this unit, it
-32requests from the receipt of record 15 (for this new example by iMPie>
by 1 Apr. <sup>L</sup> OF THE PROPERTY
INDUSTRIAL processor average 20 if this record is not autonomous) transmitting, puf '& jwnÍplu;
an RQ application. In order to obtain the next control word reserved for this unit, this request is accompanied by the identity of the decryption unit 14 so that the record 15 (or the processor 20 that manages this record) can identify the drive unit. decryption 14 corresponding between all the decryption units of the decoder 10. Typically, the request may contain information (ID or D) that allows to ensure this identification. Once the appropriate control word [CW] pk (7) has been transmitted in response to the request of the decryption unit (or obtained by this unit if the latter has direct access to register 15), this decryption control word then (8) by means of the decryption module 14 using the parity key PK destined for the decryption unit 14. Once decrypted, the control word CW is transmitted (9) to the core of the decryption unit 14 in order to be used as a decryption key to decrypt the piece of audio / video content processed by this unit.
The second object of the invention relates to the decoder 10 for the implementation of the method described above according to any of the proposed variants. This decoder will therefore be in charge of deciphering at least a piece of the audio / visual content protected by the CWs control words. As shown in Figure 1, this decoder 10 includes a key processor 20 connected, via a secure channel 25, to a
-33IMPIO ^ security module 30 in charge of issuing
CWs to said encoder in encrypted form. It also includes at least two decryption units responsible for decrypting the audio / video content encrypted by a portion of said CWs control words, and a record 15 of the control words administered by said CWs. processor 20. The latter is configured to decrypt the control words CWs received from said security module 30 and to store them in the register 15 in encrypted form.
According to the invention, this decoder 10 further includes:
- a memory for storing a key directory 22 managed by the processor 20 and configured to register a plurality of PK parity keys, each parity key PK being referenced by means of an identifier ID that uniquely associates it with one of the decoding units 14 of the decoder,
- a reference module 24 which makes it possible to reference each control word CW by means of an indication D which identifies the decryption unit 14 for which this control word is intended according to the audio / video channel from which it is extracted each control word. Each audio / video channel can be identified either by means of an identifier or according to its transfer inside the decoder. Therefore, each channel leaving the des-multiplexer 11 (or each sorting device 12) can be identified and labeled with a particular label.
The processor 20 is also configured on one side
-34for which to identify, in the ID identifier directory corresponds
22, la cla ^ „4 ^^
Di> 1? 1O? IEDAD _ η _ ___ 'L _' £ 'U | STR1AL ·] _ a la indicación ere de
<img file="MX349246B_D0012.tif" />
D that references any word of rnnir ^ l · CW and, ntra part, to encrypt this control word CW using the parity key PK identified in this way. The encryption of the control word using the parity key PK will be carried out for example by means of a cryptographic module 23 integrated in the processor 20.
Finally, register 15 is configured so that the control words [CW]<sub>PK</sub>, encrypted using the PK parity key, can be stored in it in a chronological and referenced way.
In one embodiment, the register 15 is made directly accessible to any decryption unit 14 of the decoder 10. This can be achieved by equipping for example the register 15 with an access path (common link interface and communication) that links it directly to each of the decryption units.
In order to ensure the secret transfer of the parity key PK from the cryptographic module 23 to the decryption module 13, or vice versa, the decoder 10 can further be configured to establish a second secure channel, reserved for this purpose, between the processor 20 and the decryption units 14. Alternatively, the decoder 10 could comprise, for each decryption unit 14, a private common link only accessible to the key processor 20 and to the corresponding decryption unit 14.
According to one embodiment, the decoder 10 may comprise a random number generator 18 with the
-35- --------- INSTITUTO MEXICANO cryptographic 14. Therefore, each of is<sup>0</sup>éai8Du ^ ft ^ will have the ability to obtain a PK parity key that depends on a random number coming from the generator 18.
Such a parity key PK could be obtained for example by applying to this random number a cryptographic function initialized by a customization key.
Although the objects of the present invention relate to audio / video (or audio / visual) content, streams, or channels, it is to be understood that other types of content, streams, or channels may also be considered. These other Lipos could refer to image data (photographic data), audio data (music data), other multimedia data (games), as well as data of any other type (computer programs, texts, digital values, etc. .). Therefore, it should be understood that the adjective ‘audio / video’ or ‘audio / visual’, which qualifies the content of words, flows or channels in this document, is of secondary importance and consequently has a particular character which could be generalized by middle of the digital adjective.
Contents5
17 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9 Sheet 10 Sheet 11 Sheet 12 Sheet 13 Sheet 14 Sheet 15 Sheet 16 Sheet 17
9 priority claims, no other members on record
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 13177287 | European Patent Office (EPO) | A | |
| 13177287 | European Patent Office (EPO) | A | |
| 131772873 | European Patent Office (EPO) | – | |
| 2014064332 | European Patent Office (EPO) | W | |
| 2014064332 | European Patent Office (EPO) | W | |
| 131772873 | – | – | – |
| EP20130177287 | – | – | – |
| PCTEP2014064332 | – | – | – |
| WO2014EP64332 | – | – | – |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Grant or registrationFG | FG |
Numbers
- Publication
- 349246
- Publication, DOCDB
- 349246
- Publication, EPODOC
- MX349246
- Application
- 2016000585
- Application, DOCDB
- 2016000585
- Application, EPODOC
- MX20160000585
Titles2
- English
- METHOD FOR PROTECTING DESCRIPTION KEYS IN A DECODER AND DECODER FOR IMPLEMENTING SUCH METHOD.
- Spanish
- METODO PARA PROTEGER CLAVES DE DESENCRIPTACION EN UN DECODIFICADOR Y DECODIFICADOR PARA IMPLEMENTAR DICHO METODO.
Classification
- CPC, 4
- H04N21/4623
- H04N21/43853
- H04N21/4405
- H04N21/4408
- IPC, 2
- H04N21 438
- H04N21 4623