Method and device for controlling access to encrypted data
Abstract
This record has no abstract on file.
Term
Term ended
Projected expiry passed 6 July 2026, 0.2 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
15 claims: 2 independent, 13 dependent
- 1Patent claims Zastrzeżenia patentowe 1. A method of controlling access to encrypted data using control words (CW), which control words are received by the security module in control messages (ECM) and returned to the user set (STB) using the encrypted data, which method includes the following steps:1. Sposób kontrolowania dostępu do danych zaszyfrowanych przy użyciu słów kontrolnych (CW), które to słowa kontrolne są otrzymywane przez moduł zabezpieczający w komunikatach sterujących (ECM) i zwracane do zestawu użytkownika (STB) wykorzystującego zaszyfrowane dane, przy czym sposób ten obejmuje następujące kroki: - odebranie pierwszego komunikatu sterującego (ECM1), obejmującego co najmniej jedno słowo kontrolne (CW) i znacznik czasu (TS), - receiving the first control message (ECM1), including at least one control word (CW) and time stamp (TS), - odebranie drugiego komunikatu sterującego (ECM2) bezpośrednio po pierwszym komunikacie sterującym (ECM1), który to drugi komunikat obejmuje co najmniej jedno słowo kontrolne (CW) i znacznik czasu (TS), - receiving a second control message (ECM2) immediately after the first control message (ECM1), which second message includes at least one control word (CW) and time stamp (TS), - determination of the time corresponding to the difference between the time stamps (TS) from two successive control messages (ECM1, ECM2), - określenie czasu odpowiadającego różnicy między znacznikami czasu (TS) z dwóch kolejnych komunikatów sterujących (ECM1, ECM2), - if this time is shorter than the predetermined period of time (CP), an increase in the error counter (CE), - jeśli ten czas jest krótszy od określonego z góry okresu czasu (CP), zwiększenie stanu licznika błędów (CE), - if this time is equal to or longer than the specified predetermined period of time, a reduction of said error counter (CE), - jeśli ten czas jest równy lub dłuższy od wymienionego określonego z góry okresu czasu, zmniejszenie wymienionego licznika błędów (CE), - returning the control word (CW) to the user set (STB) after waiting for a time dependent on the error counter (CE). - zwrócenie słowa kontrolnego (CW) do zestawu użytkownika (STB) po odczekaniu czasu zależnego od stanu licznika błędów (CE).
- 15A device for controlling access to encrypted data using control words (CW), which control words are received by the security module as part of control messages (ECM) and returned to the user set (STB) to use encrypted data, the device comprising:15. Urządzenie do kontrolowania dostępu do danych zaszyfrowanych przy użyciu słów kontrolnych (CW), które to słowa kontrolne są odbierane przez moduł zabezpieczający w ramach komunikatów sterujących (ECM) i zwracane do zestawu użytkownika (STB) w celu wykorzystania danych zaszyfrowanych, przy czym urządzenie obejmuje: - means for receiving a first control message (ECM1) including at least one control word (CW), - środki do odbierania pierwszego komunikatu sterującego (ECM1), obejmującego co najmniej jedno słowo kontrolne (CW), - means for receiving a second control message (ECM2) immediately after the first control message (ECM1), which second message comprises at least one control word (CW), - środki do odbierania drugiego komunikatu sterującego (ECM2) bezpośrednio po pierwszym komunikacie sterującym (ECM1), który to drugi komunikat obejmuje co najmniej jedno słowo kontrolne (CW), - means for determining the time interval separating two successive control messages (ECM1, ECM2), - środki do określenia odstępu czasu oddzielającego dwa kolejne komunikaty sterujące (ECM1, ECM2), - measures to increase the error counter (CE) if this time is shorter than the specified time (CP), - środki do zwiększenia stanu licznika błędów (CE), jeśli ten czas jest krótszy od określonego czasu (CP), -PAT-684 EP-PL 684-PAT-EP-PL EP 1900 211 EP 1900 211 - measures to reduce the condition of said error counter (CE) if this time is equal to or longer than the specified time stated, - środki do zmniejszenia stanu wymienionego licznika błędów (CE), jeśli ten czas jest równy lub dłuższy od wymienionego określonego czasu, - and means for returning the CW control word to the user set (STB) after a waiting time depending on the error counter (CE) state. - oraz środki do zwrócenia słowa kontrolnego CW do 5 zestawu użytkownika (STB) po czasie oczekiwania zależnym od stanu licznika błędów (CE). -PAT-684 EP-PL 684-PAT-EP-PL EP 1900 211 EP 1900 211 -PAT-684 EP-PL 684-PAT-EP-PL EP 1900 211 EP 1900 211 CW1 I CW2 I CW3 I CW4 I CW5 I CWG I CW7 I CWS CW1 I CW2 I CW3 I CW4 I CW5 I CWG I CW7 I CWS FIG.3 FIG.3 -PAT-684 EP-PL 684-PAT-EP-PL EP 1900 211 EP 1900 211
Independent claims2
134 paragraphs in 51 sections, as filed
TECHNICAL FIELD
The invention relates to a method and apparatus for controlling access to encrypted data using control words, which control words are received as part of control messages by the security module and returned to the encrypted data processing unit.
The method and apparatus of the invention are applicable in particular in the field of pay-TV.
PRIOR ART
As part of the well-known method, especially in the above-mentioned pay-TV field, the data is encrypted by the data provider via encryption keys called control words. These data are sent to multimedia sets of users or subscribers. At the same time, control words are sent to these multimedia sets as part of the control message stream.
Multimedia sets generally include a processing set, which in the case of pay-TV includes a decoder receiving the stream mentioned above, and a security module responsible for cryptographic operations related to the use of these streams.
-PAT-684 EP-PL
EP 1900 211
As is well known to those skilled in the art, such a security module can be implemented in four different forms. One of them is a microprocessor card, a smart card or more generally some electronic module (in the form of a key, pendants, etc.). Modules of this type can usually be removed and connected to the decoder. The most widely used is the form with electric contacts, however it is not excluded to use a contactless connection, such as the ISO 14443 type.
The second known form is the housing with integrated circuit placed, usually in a certain way preventing its removal, in the decoder housing. One variant creates a circuit mounted on a base or a card such as a SIM card.
In a third embodiment, the security module is integrated in the form of an integrated circuit embedded in the housing of the device that also performs other functions, for example a decoder decryption module or in a decoder microprocessor.
In the fourth embodiment, the security module is not made in material form, and its function is implemented in program form. Given that, although the security levels are different in all four cases, the functions are identical, but you can talk about a security module regardless of the form in which it exists.
-PAT-684 EP-PL
EP 1900 211
When the media system receives a stream containing control words, it first checks to see if the user has the rights to decrypt this data. If this is the case, control messages are decrypted to read control words. These control words are in turn used to decrypt the data.
As is also known, each control word usually allows you to decrypt a small piece of transmitted data. Usually one control word allows you to decrypt 10 seconds of pay TV transmission. After this period of time, called the encryption period, the control word is changed for security reasons.
One of the possible ways to gain access to encrypted data without authorization is to use a legal multimedia set with an authentic security module and distribute control words to the set of decoders. This can be done through a server or device called a splitter. Then the receivables resulting from the acquisition of access rights to encrypted data are paid for a single multimedia set when transmissions are available on several multimedia sets.
European patent application EP 1 575 293 describes a method to prevent the security module from being shared by several users. In order to implement this method, the security module is equipped with a memory intended to store a certain sequence of control messages. The security module has
-PAT-684 EP-PL
EP 1900 211 also means for analyzing abnormal control message sequences, which means operate by comparing stored control messages. When an abnormal sequence is detected, the error counter is increased. A time delay is introduced in the processing of control words as a function of the error counter value.
In the method described in this patent application, abnormal behavior is defined based on the analysis of the channels used. For example, if the channel identifier is alternating A, then B, the analyzing means check for an abnormal sequence indicating that the security module is sharing. If so, the error counter is increased. However, if the channel identifier remains A for several encryption periods and then changes to B for several encryption periods, this will not be considered abnormal and the error counter will not be increased.
The invention described in patent application US 2004/0215691 is intended to protect against such abuse. To this end, each time the multimedia set receives a control message, the set or the security module assigned to it determines which channel the control message relates to. Channel identifiers are saved with time information. These messages are compared to determine if they apply to different channels or to the same channel. If they apply to different channels, the counter is increased by a certain value. If control messages
-PAT-684 EP-PL
EP 1900 211 relate to the same channel, the counter is reduced. If the counter reaches the set threshold, it means that there have been numerous channel changes and decryption of control words is being suspended.
The two processes described in EP 1 575 293 and US 2004/0215691 imply that a channel identifier must be available for each control message. In some configurations this is not the case. By using control messages as specified in particular in the Eurocrypt N ° EN 50094 standard of December 1992, it is possible to find not so much each channel individually as the class of channels. In this case, it is impossible under the invention described above to block the use of several multimedia sets that use only one security module and a splitter.
Document "Countermeasures for Attacks on satellite TV cards using open receivers" XP-002333719 by Francis et al. describes in a very general way various measures to prevent the unauthorized use of security modules. In one particular aspect, this document suggests checking whether the message timestamp is located in the future relative to the time stamp of the previously received message. However, this document does not mention any specific solution. In particular, there is no information to distinguish between illegal use
-PAT-684 EP-PL
EP 1900 211 security module by several users and legal change of channels by only one user.
DESCRIPTION OF THE INVENTION
According to the invention, it is proposed to implement an alternative solution to the prior art, which avoids the use of channel identifiers while preventing the use of a separation device, allowing several decoders to gain access to encrypted content from one security module. What's more, this channel identifier is not necessary as part of this solution, because this solution also works if the control messages do not contain such channel identifier, but for example the channels are grouped into classes.
The object of the present invention is achieved by a method of controlling access to data encrypted by control words, which control words are received by security modules as part of control messages and returned to the encrypted data processing unit, which method includes the following steps:
- receiving the first control message containing at least one control word and a time stamp,
- receiving a second control message after the first control message, which second message comprises at least one control word and a time stamp,
-PAT-684 EP-PL
EP 1900 211
- determining the time interval corresponding to the difference between the time stamps of two successive control messages
- if the time interval is shorter than the set interval, the error counter is increased,
- if this interval is equal to or greater than the specified interval, said error counter is reduced.
The object of the present invention is also realized by means of a device for controlling access to data encrypted by control words, which control words are received by the security module in control messages and returned to the encrypted data processing unit, which device includes:
- means for receiving a first control message including at least one control word,
- means for receiving a second control message following the first control message, which second message comprises at least one control word,
- means for determining the time interval separating these two successive control messages,
- measures to increase the error counter if this interval is less than the specified interval,
- and measures to reduce said error counter if the interval is equal to or greater than the specified interval,
-PAT-684 EP-PL
EP 1900 211
- and means for returning the control word (CW) to the processing unit (STB) after a waiting time depending on the error counter (CE).
In general, the method and apparatus according to the invention make it possible to determine on the basis of time information about control messages sent by the management center whether these control messages are sent conventionally or processed in violation of rights. The error counter allows you to take steps if abnormal use is detected. There are various types of steps such as temporary suspension of the service, delay in the return of control words, and even blocking of the security module, in which case the unlocking can be carried out either automatically or on demand by telephone service. In the case of conventional use, the user will not notice any change as a result of using this method. Conventional use means both access to content encrypted on one specific channel and channel change (zapping) at a "reasonable" size and time period. However, in the case of unauthorized use of the separation device, supplying several decoders from a single module securing access to encrypted content quickly becomes impossible. When the use becomes valid again, access to the data may be authorized again.
BRIEF DESCRIPTION OF THE DRAWING
-PAT-684 EP-PL
EP 1900 211
The described invention and its advantages can be better understood by referring to the drawing attached to the detailed description of individual implementations, given as a non-limiting example, in which:
- Fig. 1 shows an example of the structure of a control message as used in the present invention;
- Fig. 2 shows a configuration in which two decoders are used with only one protection module and a separation device,
- Fig. 3 schematically shows the implementation of the decryption process according to the invention;
- Fig. 4 shows the reception of the ECM control message as a function of time; and
- Fig. 5 shows the error counter as a function of time and control messages received, as illustrated in Fig. 4,
- Fig. 6 shows a variant of the invention in which different encryption period lengths are used for different channels.
MEDTODS FOR IMPLEMENTING THE INVENTION
Fig. 1 schematically shows the content and structure of the ECM control message as used in the present invention. This ECM control message contains fields in which there is in particular a Time stamp TS representing the date and time, length of the CP encryption period, CA access conditions for audio / video content and two CW1, CW2 control words with different parity. Control messages may also include other fields, no
-PAT-684 EP-PL
EP 1900 211 described here. The data contained in these control message fields are generally encrypted by the TK transmission key. This message may also include one or more headers that are not necessarily encrypted. In particular, such a message includes an H header that allows the multimedia kit to identify it as an ECM control message and which cannot be encrypted. It should be noted that the encryption period need not be included in such control message. Indeed, if the encryption periods of the different channels are identical and remain unchanged during a certain period of time, the encryption period may be sent in the EMM management message.
According to the first embodiment, the invention operates in the following general manner. Conventionally, an ECM control message is sent to a multimedia kit including a STB decoder and an SC security module. Upon receiving this control message, the security module reads from this control message the CA access conditions required to access specific content, hereinafter referred to as audio / video content. The security module then checks to see if it has the right to return the control word. If this is not the case, it does not return this control word. If decryption rights are present, the control word is sent to the decoder.
The value of the CP encryption period is also read from the control message or otherwise determined. this
-PAT-684 EP-PL
EP 1900 211 CP value is stored in the memory connected to the security module. The corresponding control word is returned to the decoder, usually in encrypted session key. The session key is usually obtained from an asymmetric key pair in which one of the keys is stored in the security module and the other in the decoder. The keys belonging to this pair are called paired keys and are basically different and unique for each multimedia set. Encrypted content can be decrypted by this control word and displayed on the user's screen. The evaporation mechanism is described in detail in the European patent published under the number EP 1 078 524.
When the multimedia system receives the next control message, it is decrypted so as to read, among others, the TS time stamp.
This time stamp is compared with the time stamp saved during processing of the previous control message. The difference between these two time stamps is compared with the encryption period also remembered when processing the previous control message. If this difference is lower than the value of the encryption period, it means that the multimedia set received more than one control message during the encryption period and the meter reading is increased. This counter, hereinafter referred to as the CE error counter, is basically located in the security module. Increasing this counter is therefore carried out when the module
-PAT-684 EP-PL
EP 1900 211 security is to return control words at a frequency greater than the encryption period, either due to a user changing the channel or due to the operation of more than one multimedia set with the same security module.
Fig. 2 shows the configuration to be controlled by the present invention. In this configuration, two data processing devices or two STB1, STB2 decoders receive control words from only one security module and a separation device. In this configuration, when one of the decoders receives an ECM control message, it forwards it to the SP splitter, which in turn sends it back to the SC security module. The latter decrypts the said message, if it has the authority to do so, and then sends this control word to one of the STB1 or STB2 decoders via the SP splitter.
In Fig. 2 only two decoders are shown. In practice, it is possible to provide control words to more decoders through only one security module and a separation device.
Note that the process only controls durations in relation to ECM control messages. If other types of messages, such as EMM management messages, are sent between two control messages, these other types of messages are not taken into account and do not interfere with the process.
-PAT-684 EP-PL
EP 1900 211
Application of error counter data
The following is an example of a particular embodiment with reference to Fig. 3. In this embodiment, the error state CE is used to enter a time delay in the return of CW control words read from ECM control messages. In the example in Fig. 3, the encryption period is assumed to be 10 seconds. Upon receipt of the first ECM1 control message, it is processed in such a way that the control words it contains, called CW1 (C1) and CW2 (C1), are read. It should be noted that in this drawing the upper part corresponds to channel C1 and the lower part corresponds to channel C2. To avoid placing too much detail in this drawing, the control word CW1 (C1), corresponding to channel C1, is simply labeled CW1. Similarly, the control word CW1 (C2) corresponding to channel C2 is also designated CW1 in this drawing. Because of their location in the drawing, the distinction between these two control words is obvious. In the description, the channel name is shown in brackets.
The processing of the ECM1 control message usually takes several dozen milliseconds. When one of the control words is used, for example the control word CW1 (C1), the second control word CW2 (C1) contained in the same control message ECM1 is stored. The control message corresponding to the same channel usually contains a control word memorized during the processing of the previous message, as well as an additional control word that is substituted for use during the next period
-PAT-684 EP-PL
EP 1900 211 encryption. This way, each control word is sent twice. This mode of operation has the advantage that before use, control words that are different from those received immediately after changing channels are memorized, which are thus immediately available when needed.
The CE error counter introduces a delay in returning control words by the security module to the decoder. This means that instead of processing the ECM control message and returning control words immediately after they have been decrypted, the sending of said control words to the decoder is delayed by a time depending on the value stored in this counter.
Fig. 3 shows an example in which a splitter device is illegally used between the security module and two STB1 and STB2 decoders. In the simplest case, in which the encryption periods are identical and the user does not change channels, in the configuration described above, two control messages will be received in each encryption period. Therefore, the CE error counter will be increased for each encryption period. This increase can be done by predefined values, for example by two units. As an example, let's imagine that for processing of control messages a time delay of 1 second per error counter unit is introduced from the moment when this value exceeds the threshold value of 10. When the counter has not yet reached this threshold value of 10 or when it is equal to 10, no time delay is entered.
-PAT-684 EP-PL
EP 1900 211
If the counter's initial value is zero (CE = 0), when the first ECM1 control message is received, the encryption period value, e.g. 10 seconds, will be stored. The control words CW1 (C1) and CW2 (C1) are deciphered. The CW1 (C1) control word is used to decrypt audio / video content, and the CW2 (C1) control word is remembered for future use. The TS = T0 time stamp is read from the control message and stored. When the multimedia system receives the next ECM2 control message, it reads the T1 time stamp. The second ECM2 control message is processed to read control words from it in order to use the first of them CW1 (C2) and store the second CW2 (C2). Then the difference between T0 and T1 is calculated and the result is for example 6 seconds.
This value is compared with the stored CP encryption period, which in our example is 10 seconds. Because the time stamp difference T1-T0 is smaller than the CP encryption period, the error counter is increased, in our example by 2 units. Its condition is therefore 2.
Upon receipt of the next ECM3 control message corresponding to the first channel C1, the CE error counter status is verified. Because its value is 2 and therefore lower than the predefined threshold value 10, no time delay is entered. The security module processes the message starting from reading the TS = T2 time stamp from it. Because the period
-PAT-684 EP-PL
EP 1900 211 encryption is 10 seconds, the result is T2-T0 = 10. Because in this example T1-T0 = 6, T2-T1 = 4 seconds. Because this value is less than the encryption period, the error counter has been increased by 2 units and equals 4. The control words CW2 (C1) and CW3 (C1) are read from this message. During this time, audio / video content is decrypted using the CW2 (C1) control word from the previous control message.
When the next ECM4 control message is received, the security module also processes this message and returns control words without entering a time delay. During this time, the STB2 decoder uses the CW2 (C2) control word from the previous message to decrypt the audio / video content.
The difference between the time stamp from this message and the previous one is 6 seconds, and therefore smaller than the encryption period. The error count CE is increased by two units and reaches 6. The control words CW2 (C2) and CW3 (C2) are read from the message. When the CW3 (C2) control word is needed to decrypt the audio / video content, the word will be available because it has been decrypted in the ECM4 control message received previously.
The multimedia kit will then receive a fifth ECM5 control message containing the CW3 (C1) and control words
CW4 (C1). During this time, the control word CW3 (C1) can be decrypted to provide access to the audio / video content as this control word has already been sent in the previous ECM3 control message.
-PAT-684 EP-PL
EP 1900 211
Because the difference between the time stamp of the ECM4 control message and the ECM5 message is less than the encryption period, the error counter is increased by 2 units and takes the value 8.
Similarly, the next ECM6 control message contains CW3 (C2) and CW4 (C2) control words that can be used to decrypt audio / video content. The time stamp in this message indicates that the error counter is increased by 2 units and reaches 10.
The next ECM7 control message contains the control words CW4 (C1) and CW5 (C1). Because the error counter is 10 and is equal to the threshold but not greater than it, the ECM7 message is processed to immediately return control words. This means that the CW5 (C1) control word will be available when needed for audio / video content. The error counter will be increased again by 2 units and will reach 12, exceeding the threshold value.
The next ECM8 control message contains the control words CW4 (C2) and CW5 (C2). This message is processed immediately, but the control words it contains will not be returned within 12 seconds of delay. This means that with an encryption period of 10 seconds, the control words will be returned 2 seconds after the end of the encryption period. During these two seconds, the control word necessary to access the audio / video content is CW5 (C2). However, this control word is not available before returning it to the decoder. As a result, during these two
-PAT-684 EP-PL
EP 1900 211 seconds audio / video content is not available. As a result, the user's screen may have a hazy or solid white or black image.
The process continues in this way, adding 2 units to the error counter and two seconds respectively until the control words are returned. Therefore, when processing the next ECM9 control message, the audio / video content will not be available for 4 seconds. For subsequent ECM10, ECM11 and ECM12 messages, the times for which access to the audio / video content will be impossible will be 6 seconds, 8 seconds and 10 seconds respectively. As you can easily see, when the time delay equals twice the length of the encryption period, the content is not available at all.
The TS time stamp as described above may have a "resolution" of about a second, or even several seconds, for example in practice 4 seconds. This means that the difference between the two tag values will also be expressed in full seconds instead of fractions of a second.
Note that in the example described above, the time given by the time stamps is used. If the multimedia system, i.e. the security module and / or the decoder contain a clock, it is of course possible to calculate the difference between the two time periods given by the clock and not between the two time stamp values. In both cases, however, the principle of the invention remains the same.
Memory buffer usage
-PAT-684 EP-PL
EP 1900 211
The system as described above has limitations when a memory buffer is used to store audio / video content to compensate for the delay caused by the security module and as a result of its actual shutdown.
One method of making this memorization useless or at least ineffective is by not setting the upper limit of the delay caused by the error counter or by setting this limit at a very high level. In this way, because the error counter is increased by two with each unconventional control message, it practically always reaches twice the encryption period or even exceeds it so that the memory buffer time is exceeded. From now on, all audio / video content will be unavailable. However, this can also cause harm. In fact, if the error counter value reaches a significant value, it is necessary to wait a significant period of time after stopping the distributor so that the error counter value drops sufficiently so that the system can work again correctly.
Another way to make this remembering ineffective is that control words are not returned which, given the time delay, should have been sent during a period of time during which the content is no longer encrypted by the control words, which words should be sent by security module. For example, the control message labeled ECM8 in Fig. 2 includes the control words CW4 (C2) and CW5 (C2). In stock
-PAT-684 EP-PL
EP 1900 211 error counter 12 these control words should be returned after the end of the encryption period. In this case, control words are simply not returned. Because the CW4 (C2) control word is contained in the ECM6 message, the audio / video content can be decrypted until the end of the encryption period using these control words. After the following change, the content will no longer be available. However, the error counter will continue to increase because the frequency at which control messages are sent has not changed.
Decrease meter reading
In the previously described unauthorized use mode, it is clear that if two users have access to the security module at the same time to decrypt the data, this data will quickly become inaccessible. If one of these users stops accessing the security module, it can be ensured that a "legal" user can access this content again. To this end, the proposed solution consists in reducing the CE error counter in accordance with established rules.
Figures 4 and 5 schematically illustrate a decrease in the error counter and its increase depending on the CP encryption period and the difference between time stamps in two successive ECM control messages. According to one possible rule, each time the ECM control message is received correctly, i.e. when the difference between the time stamps in a given message and in
-PAT-684 EP-PL
In the previous message, equal to the encryption period, the error counter is reduced by one unit.
As an illustration, Fig. 4 shows the ECM control message received at this time, and Fig. 5 shows the CE error counter status also at the same time.
Note that in this example the initial error counter is not zero but has been set to 2. Given that no delay is entered until the threshold is exceeded, this non-zero initial value has no negative effect
<td>decryption.</td><td>Contrary</td><td>while,</td><td>in</td><td>event</td>
<td>unauthorized</td><td>use effect</td><td>this will be,</td><td>that</td><td>value</td>
<td colspan="2">threshold, after which</td><td>introduced</td><td>is</td><td>delay,</td>
will be reached faster.
The return of control words contained in the first control message is not delayed because the threshold value has not been reached. The first control word gives access to audio / video content. The second control word is remembered by the decoder. At the end of the encryption period, the multimedia kit receives a second ECM2 control message. By comparing the timestamps of these two messages with the encryption period in the first ECM1 control message, it appears that the encryption period is equal to the difference between the time stamps contained in these control messages. At the moment, the CE error counter is reduced according to the current rule, in this case by one unit. So his condition is 1.
-PAT-684 EP-PL
EP 1900 211
When the multimedia system receives another control message, the error counter is checked. Is 1. Therefore, no time delay is applied. At this time, the control word previously stored and derived from the previous control message is used to provide access to the audio / video content. The meter reading is reduced according to the set rule and is now zero.
In the illustrated example, the multimedia kit receives a new ECM4 control message in which the difference between the time stamp contained in this message and in the previous message is less than the encryption period. At the moment, the meter reading is increased by 2 units and reaches
2. This increase can occur for two reasons. One of these reasons is that the user changes the channel (zapping). The second reason is, a splitter is used. As already explained with reference to Fig. 3, the meter reading increases, for example from two by two.
In the example of Figs. 4 and 5, the difference between the time stamps of two consecutive ECM control messages is lower than the encryption period up to the control message with the designation ECM8. The error counter value is increased by two units to reach the value of 12. As shown with reference to Fig. 3, when the counter value exceeds 10, a time delay is introduced in the return of control words. Thus, the user will not have access to all audio / video content. In fig. 4 and 5 when the control messages ECM9 to ECM12 are received, the difference between the time stamps
-PAT-684 EP-PL
EP 1900 211 is equal to the encryption period, so the error counter status is reduced by 1 for each message. When the counter reaches 10, the processing delay is cleared and all audio / video content becomes available to the user.
Fig. 6 illustrates a particular embodiment of the invention in which the encryption periods differ between the individual channels. It is also assumed in this drawing that the device according to the invention is used in an unauthorized way to supply two decoders from only one security module, and furthermore that each channel receives only one control message out of two. This use of one control message out of two is possible due to the fact that each of these messages contains two control words. Therefore, also in this case all control words will be available for these two channels.
As an example, suppose the channel 1 encryption period, shown in the upper part of Fig. 6, is 7 seconds long. The encryption period for channel 2, shown at the bottom of this figure, is 5 seconds. We will consider the case in which the first control messages from each channel C1 and C2 are received simultaneously. The first ECM1 (C1) control message from channel 1 contains an indication according to which the encryption period is 7 seconds. This message contains the control words CW1 (C1) and CW2 (C1).
The first control message from channel 2 contains an encryption period value of 5 seconds and control words CW'1 (C2) and
CW'2 (C2).
-PAT-684 EP-PL
EP 1900 211
In the example shown in Fig. 6, subsequent control messages from all channels are not used. The next message to use is the control message with the designation ECM2 (C2). This message is received two encryption periods after the first ECM1 (C2) message so that it is considered valid. The error counter is therefore kept at zero or possibly reduced.
The next control message received by the security module is ECM2 (C1). Two encryption periods are received after the first ECM1 (C1) message, namely after 14 seconds in our example. This means that it is also received 4 seconds after the first ECM2 (C2) message corresponding to channel C2. This 4-second value is less than the encryption period contained in the previous control message. The error counter is therefore increased by 2 units if the same rule as in the previous example is used. The error counter is therefore 2.
The next control message will be received after 4 periods of C2 channel encryption, i.e. (4x5) - (2x7) = 6 seconds after the last received ECM2 (C1) message. Because this message contained an encryption period value of 7 seconds, the ECM3 (C2) message is considered invalid and the error counter is incremented by 2. Therefore, it reaches the value
4.
The next ECM3 (C1) message is received after (4x7) - (4x5) = 8 seconds. The previous message contained the period value
-PAT-684 EP-PL
EP 1900 211 encryption suitable for channel C2, namely 5 seconds. The interval of 8 seconds from the previous message is greater than this value of 5 seconds. The message is therefore considered correct. The CE error rate will therefore be reduced by one unit. By continuing the process as described above, it can be shown that the error counter will be increased and then alternately decreased. Since the increase is performed by two units and the decrease by one unit, the error counter will increase in case of unauthorized use as shown in Fig. 6. This counter will be 0, 2, 4, 3, 5, 4, 6, 5 , 7, ... until it exceeds the threshold value at which a delay in returning control words will be generated.
It should be noted that the case in which users decrypt only one control message out of two, as described with reference to Fig. 6, is the most disadvantageous case in terms of detecting unauthorized use. It is easy to see that when an unauthorized user decrypts all ECM control messages, the error counter will increase faster and the return of control words by the security module will be slowed down correspondingly faster.
Security module and coupling of decoders
The rest of this description relates in particular, but not exclusively, to the case in which the security module and decoder forming the multimedia set are coupled. In this case, each of them contains one key from the key pair
-PAT-684 EP-PL
EP 1900 211 asymmetrical, which pair is different and unique for each set of decoder / security module. In this configuration, when the multimedia system is turned on, the session key, which is generally symmetrical, is set between the security module and the decoder. This session key is used to encrypt CW control words that have been decrypted by the security module before sending them to the decoder. Using this session key is a problem for unauthorized users using the splitter. In fact, since the session key between the security module / decoder # 1 pair differs from the session key between the security module / decoder # 2 pair, it is necessary to reconcile the session key each time the ECM control message is received on a different channel. In the case illustrated in Fig. 3, where the control messages are alternately received one on channel C1 and the other on channel C2, as in some multimedia set configurations, the session key must be agreed between successive receipts of ECM control messages.
In order to generate reconciliation of such a session key it is necessary to reset the security module. This is done by sending a reset (reset) instruction to the multimedia system. Such instruction can therefore be sent between two ECM control messages. In this case, it is important that the CE error counter is not reset. It is also desirable for this counter to increase if the reset corresponds to unauthorized use.
-PAT-684 EP-PL
EP 1900 211
To do this, the security module remembers in the volatile memory the last date it received. This date is sent, for example, by the management center in the form of a control message. After receiving the reset instruction, the data is stored in non-volatile memory.
In parallel with this, as already indicated, control messages
ECMs include a TS time stamp. The multimedia kit or more precisely the security module also remembers a duration called a delay time, which is basically greater than or equal to the encryption period.
On receiving each ECM control message, the security module calculates the difference between the TS time stamps of that ECM message and the date received before the last reset, previously stored in non-volatile memory.
If this difference is greater than the delay time, the error counter can be reset or reduced to a state for which there will be no delay in returning control words. If this difference is less than the delay time, it means that the security module has decrypted the control message shortly before zeroing, which may indicate a configuration in which the splitter is used. The error counter is increased according to the set rule, for example by 3 units.
According to the first implementation, from the moment the first control message is processed "shortly" before the last data is reset or stored, that is, in a time shorter than the time delay, a time delay is introduced. In this way, remembering is avoided
-PAT-684 EP-PL
EP 1900 211 error counter status in non-volatile memory. Instead, in the case of "legal" reset for technical reasons, an authorized user must wait a time equal to the time delay before accessing the audio / video content. Moreover, if the channel is changed during this time, the counter will increase.
In another implementation, the error counter status is stored in such a way that the reset instruction does not reset the error counter. On the contrary, this condition is maintained as it was before the reset. In this way, the reset instruction between all ECM control messages will quickly prevent access to audio / video content. On the contrary, occasional reset will not prevent access to audio / video content until a sufficient number of control messages have been correctly processed between two consecutive reset instructions. In order to prevent any accumulation effects under normal circumstances, if the time between processing the first control message (after zeroing) and the time of processing the last message before resetting is long enough (e.g. several hours), the error counter will be reset. The time needed to reset the counter can be pre-determined and is called dead time.
It should be noted that there are security modules called multi-session that are able to remember several session keys. Under normal use, each session key can dialogue with the media kit or even with
-PAT-684 EP-PL
EP 1900 211 a component for decrypting the content that would be placed in the same device.
When accessing the security module through one of the decryption units, an identification name will be added. The security module will process this message in an environment suitable for the entity that contains session keys (if join is active), other identification data (rights, credit), and data to detect unauthorized use as described above. In particular, this applies to the error counter, the time stamp for processing the last control message, and the encryption period value.
Therefore, the same security module can support several decryption units by checking that the total number of decoders associated with this module does not exceed the set limit. This limit can be set according to the user profile.
Increase / decrease at different speeds
In the examples shown, the counter is increased faster than it is decreased. For example, it increases by two units when the difference between the time stamps of two successive control messages is less than the encryption period. It increases by three units for every reset deemed invalid, but only decreases by one unit for each successful pickup. This avoids special cases in which by using zeroing and correct
-PAT-684 EP-PL
EP 1900 211 for processing control messages, it is possible to keep the error counter within limits where unauthorized users can always or almost always access the audio / video content.
According to another alternative, it is possible to introduce the possibility of reducing the meter speed faster than increasing.
Delay time in steps
As indicated above, it is generally provided that you can enter a delay when the error counter reaches a certain threshold. Above this value, the delay can be proportional to the meter reading or it can increase in steps or be set. In general, this delay is introduced to prevent access to part of the audio / video content during a certain period of unauthorized use and then to all audio / video content after a long period of unauthorized use.
In the examples described previously, it is indicated that the length of the control message encryption period is read together with its time stamp, and then verification is carried out when the next control message is received in order to determine whether the difference between the time stamp of this message and the previous one is equal to or less than encryption period This means that you need to remember the encryption period and timestamp of the first message.
-PAT-684 EP-PL
EP 1900 211
According to one variant, it is possible to calculate the difference between the time stamp of two successive ECM1 and ECM2 control messages and to check if this difference is equal to or less than the encryption period read from the second in order of receiving the ECM2 control message. The advantage of this is that it is not necessary to remember the encryption period, so you can save memory.
In the examples described, the error counter status may be between 0 and a threshold value, e.g. 10, or may exceed this threshold value. There is no time delay between 0 and the threshold value. Above the threshold, some time delay is entered. It is clear that you can limit the maximum value of the counter, which also allows you to set a limit on the number of consecutive correct messages that must be decrypted in order to fall below this threshold again.
According to one variant, it is possible to reverse the direction of the counter, which means that with each correct decryption, the counter is increased and decreased with unauthorized decryption. In this case, the time delay is entered when the counter is between 0 and the threshold value, and there is no time delay when the counter is above the threshold value.
The examples described mention the use of two decoders for one security module. It is possible of course
-PAT-684 EP-PL
EP 1900 211 connection for the unauthorized use of more than two decoders to the security module via a splitter. According to the method of the invention, this will block access to audio / video content even faster, as the error counter will increase faster.
-PAT-684 EP-PL
EP 1900 211
Contents51
30 members in 19 offices
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 05106185 | European Patent Office (EPO) | A | |
| 05106185 | European Patent Office (EPO) | A | |
| 06777630 | European Patent Office (EPO) | A | |
| 2006063988 | European Patent Office (EPO) | W | |
| 2006063988 | European Patent Office (EPO) | W | |
| EP20050106185 | – | – | – |
| EP20060777630 | – | – | – |
| WO2006EP63988 | – | – | – |
Members30
| Document | Office | Kind | |
|---|---|---|---|
| EP1742474A1 | European Patent Office (EPO) | A1 | |
| AU2006268683A1 | Australia | A1 | |
| CA2614107A1 | Canada | A1 | |
| WO2007006735A1 | World Intellectual Property Organization (WIPO) | A1 | |
| KR20080024520A | Republic of Korea | A | |
| EP1900211A1 | European Patent Office (EPO) | A1 | |
| IL188334A0 | Israel | A0 | |
| MX2008000004A | Mexico | A | |
| CN101218822A | China | A | |
| HK1111022A | Hong Kong, China | A | |
| HK1111022A1 | Hong Kong, China | A1 | |
| US2008209232A1 | United States of America | A1 | |
| JP2008545307A | Japan | A | |
| RU2007148552A | Russian Federation | A | |
| ZA200800078B | South Africa | B | |
| EP1900211B1 | European Patent Office (EPO) | B1 | |
| AT449510T | Austria | T | |
| ATE449510T1 | Austria | T1 | |
| DE602006010554D1 | Germany | D1 | |
| PT1900211E | Portugal | E | |
| ES2336028T3 | Spain | T3 | |
| PL1900211T3This record | Poland | T3 | |
| AU2006268683B2 | Australia | B2 | |
| CN101218822B | China | B | |
| RU2409002C2 | Russian Federation | C2 | |
| US7908491B2 | United States of America | B2 | |
| IL188334A | Israel | A | |
| KR101280640B1 | Republic of Korea | B1 | |
| CA2614107C | Canada | C | |
| BRPI0615532A2 | Brazil | A2 |
Numbers
- Publication, DOCDB
- 1900211
- Publication, EPODOC
- PL1900211T
- Application
- 777630
- Application, DOCDB
- 06777630
- Application, EPODOC
- PL20060777630T
Titles2
- English
- METHOD AND DEVICE FOR CONTROLLING ACCESS TO ENCRYPTED DATA
- Polish
- Sposób i urządzenie do kontrolowania dostępu do zaszyfrowanych danych
Classification
- CPC, 6
- H04N21/44236
- H04N21/4623
- H04N7/1675
- H04N21/26606
- H04N21/4181
- H04N21/4405
- IPC, 3
- H04N7 167
- G07F7 10
- H04N5 00