OA12005A

Method and device for guaranteeing the integrity and authenticity of a set of data.

Abstract

The invention concerns a method and a device for guaranteeing the integrity and authenticity of data transmitted between a management centre and one or several receiver units, wherein each receiver unit comprises a decoder (IRD) and a security unit (SC) and means for communicating (NET, REC) with the management centre. The method consists in calculating a control information (Hx) representing the result of a function said to be unidirectional and collision-free, performed on all or part of the transmitted data and in transmitting the result to the management centre for verification. The centre will be able to inform the decoder concerning the authenticity of the data by return channels or by the main channel.

OA12005A, drawing sheet 1
Sheet 1 of 6

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Granted
  4. Today

26 claims: 16 independent, 10 dependent

  1. 1
    CLAIMS 1. A method to check the integrity and the authenticity of a set of data received (M1 to Mn) by a pay-T.V. decoding unit, consisting of a décoder (IRD) and a security unit (SC), and also by a means of communication (NET, REC) with a control center, including the following steps; - calculation of a check information (Ηχ) which is représentative of the resuit of a mono-direçtional and collision-free function, carried out on ail or only a part of the data (M1 to Mn); characterized in that, this method consisting of :t - transmitting the check information (Hx) to the security unit (SC) and ciphering the s check information (Hx) with a first cipher-key (k1 );- sending the ciphered control information k1 (Hx) to the control center;- deciphering of the ciphered check information k1 (Hx) by the control center and comparing it with a reference value of the check information (Hy);- transmitting the control data (R) including the resuit of the comparison in a ciphered form to the security unit (SC);- deciphering of the ciphered resuit of the comparison by the security unit (SC) and informing the décoder (IRD) of the validity of the data (M1 to Mn).
  2. 3
    A method according to claims 1 and 2, characterized by the fact that the calculation is carried out by the décoder (IRD), with the resuit being transmitted to the security unit (SC).
  3. 4
    A method according to claims 1 to 3, characterized by the fact that ihe calculation is carried out by the security unit (SC), and the data (M1 to Mn) is transmitted from the décoder (IRD) to the security unit (SC).
  4. 5
    A method according to claims 1 to 4, characterized by the fact that it consiste of including a utilization describer (D) for the data (M1 to Mn) in the control data (R), DUPLICATA 1 2005 deciphering the control data (R) and transmitting the describer (D) to the décoder (IRD) if the resuit of the comparison is positive, processing the data (M1 to Mn) by the décoder (IRD) according to the guidelines contained in the describer (D). !
  5. 6
    A method according to daims J to 5, characterized by the fact that the data (M1 to Mn) is accompanied by validity information (CRC, CS, H) for the said data, and in which the security module (SC) transmits to the décoder the information to use or not this validity information to check the data (M1 to Mn).
  6. 8
    A method according to daims 1 to 7, characterized by the fact that it includes a global check information (H’y) in the control data (R) which is représentative of a resuit of a mono-directional and collision-free function, carried out on ail or only a part of the global data (MO to Mm);this data is the same as, or includes, the data received (M1 to Mn).
  7. 10
    A method according to daim 8, characterized by the fact that it consists of calculating periodically, or when_requested, the value (H’x) représentative, of the resuit of a so-called mono-directional and collision-free function, carried out on ail or only a part of the global data (MO to Mm), with the security unit (SC) comparjng the resuit (H’x) with the reference value (H’y).
  8. 13
    A method according to daims 10 to 12, characterized by the fact that the periodic calculation is carried out on request from the control center, from the security unit, from a test unit (TEST) or from one of the means of communication (NET, REC). DUPLICATA 1 2005
  9. 14
    A method according to daims 10 to 13, characterized by the fact that the resuit of the comparison is transmitted in a subscriber generated message common to the functioning of the System.
  10. 15
    A method according to daims JO to 13, characterized by the fact that the value calculated (H’x) is transmitted tô’the control centerinside suoscribèrgeneiated messages common to the functioning of the System, with each message containing a part of the value calculated (H'x).
  11. 16
    A method according to one of the preceding daims, characterized by the fact that the transmission to the control center is carried out in deferred mode, according to a timetable defined in a pseudo-random manner within predefined limits.
  12. 17
    A method to check thé integrity and the authenticity of a set of data (M1 to Mn) memorized ineide a data storage unit connected with a security unit (SC) including the following steps:- ' transmission from the storage unit to the security unit (SC) of the control data (R1) including ciphered reference cheôk information k1(Hy) représentative of the resuit of a mono-directional and collision-free function, carried out on ail or only a part of the data (M1 to Mn);- calculation of check information (Ηχ) which is représentative of the resuit of a mono-directional and collision-free function, carried out on ail or only a part of the data (M1 to Mn);- comparison of the calculated value (Hx) with the deciphered reference value (Hy) by the security unit (SC) and transfer of the management data (R2) including the resuit of the comparison to the storage unit.
  13. 20
    A method according to daims 17 to 19, characterized by the fact that it includes, inside the control data (R1), a utilization describer (D) for the data (M1 to Mn), ΒΗΡΤ.τπδίη» 1 2005 and if the resuit of the comparison is positive, sends the utilization describer (D) back to the storage unit in a deciphered form, to process the data (M1 to Mn) by the storage unit according to the guidelines contained in the describer (D).
  14. 22
    A method according to claims 17 to 21, characterized by the fact that it consists of calculating periodically, or when requested, the values (Hx) représentative of the resuit of a so-called mono-directional and collision-free function, carried out on ail or only a part of the data (M1 to Mm), with the security unit (SC) comparing the resuit (Hx) with the reference value (Hy).
  15. 23
    A method according to claims 17 to 22, characterized by the fact that it consists of:- storage of the data (M1 to Mn) in a ciphered form;- transmission to the security unit (SC) in the control data (R1 ) of a deciphering key (k3) for the data (M1 to Mn). - If the resuit of the comparison Hx=Hy is positive, deciphering of the data (M1 to Mn) with the use of the cipher-key (k3).
  16. 26
    A method according to claims 17 to 25 characterized by the fact that it includes, inside the control data (R1), a utilization describer (D) for the data (M1 to Mn), to decipher the control data (R1 ) and transmit the describer (D) to the storage unit if the resuit of the comparison is positive, to process the data (M1 to Mn) by the storage unit according to the guidelines contained in the describer (D).