Method for securing data exchanged between a multimedia processing device and a security module
Abstract
This record has no abstract on file.
Term
0.1 yearsto projected expiry
Projected expiry 2 November 2026, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
15 claims: 5 independent, 10 dependent
- 1Patent claims Zastrzeżenia patentowe 1. A method of securing the data exchanged between the multimedia processing device (STB) and the security module (M), which security module (M) is managed by a management center having a list of private keys (PK) belonging to the multimedia processing device (STB), which the management center is established to establish security parameters between the mentioned multimedia processing device and the operator, which multimedia processing device (STB) receives an encrypted data stream and is responsible for decrypting and processing this data using a decryption key provided by the security module (M) to convert it into readable form, said multimedia processing device (STB) comprising private key (RK), characterized by the following steps:1. Sposób zabezpieczania danych wymienianych między urządzeniem przetwarzającym multimedia (STB) a modułem zabezpieczającym (M), który to moduł zabezpieczający (M) jest zarządzany przez centrum zarządzania, posiadające listę kluczy prywatnych (PK), należących do urządzenia przetwarzającego multimedia (STB), które to centrum zarządzania powołane jest do ustanowienia parametrów zabezpieczenia pomiędzy wymienionym urządzeniem przetwarzającym multimedia a operatorem, które to urządzenie przetwarzające multimedia (STB) otrzymuje strumień zaszyfrowanych danych i jest odpowiedzialne za odszyfrowanie i przetworzenie tych danych przy użyciu klucza deszyfrującego dostarczonego przez moduł zabezpieczający (M) w celu przekształcenia ich do postaci czytelnej, przy czym wymienione urządzenie przetwarzające multimedia (STB) obejmuje klucz prywatny (RK), znamienny tym, że obejmuje następujące kroki: - calculation by the management center of the security key (VK) formed by the irreversible function based on this private key (RK) of the multimedia processing device (STB) and the entity identifier (CAS_ID) assigned by the said management center to that operator, - obliczenie przez centrum zarządzania klucza zabezpieczającego (VK), utworzonego przez nieodwracalną funkcję opartą na tym kluczu prywatnym (RK) urządzenia przetwarzającego multimedia (STB) i na identyfikatorze podmiotu (CAS_ID), przydzielonym przez wymienione centrum zarządzania temu operatorowi, - loading said security key (VK) into the security module (M), which security module contains the entity identifier (CAS_ID), - załadowanie wymienionego klucza zabezpieczającego (VK) do modułu zabezpieczającego (M), który to moduł zabezpieczający zawiera identyfikator podmiotu (CAS_ID), - otrzymanie przez urządzenie przetwarzające multimedia (STB) wymienionego identyfikatora podmiotu (CAS_ID), zawartego w wymienionym module zabezpieczającym, - the multimedia processing device (STB) receives the subject identifier (CAS_ID) contained in the said security module, 1813-PAT-EP-PL PAT-1813-EP-E EP1946552 EP1946552 - calculation by said multimedia processing device (STB) of said security key (VK) using an irreversible private key (RK) function of said multimedia processing device (STB) and on the entity identifier (CAS_ID) received by this multimedia processing device, - obliczenie przez wymienione urządzenie przetwarzające multimedia (STB) wymienionego klucza zabezpieczającego (VK) przy użyciu nieodwracalnej funkcji opartej na kluczu prywatnym (RK) wymienionego urządzenia przetwarzającego multimedia (STB) i na identyfikatorze podmiotu (CAS_ID), otrzymanym przez to urządzenie przetwarzające multimedia, - using this security key (VK) to secure data exchanged between the multimedia processing device (STB) and the security module (M). - użycie tego klucza zabezpieczającego (VK) do zabezpieczenia danych wymienianych między urządzeniem przetwarzającym multimedia (STB) a modułem zabezpieczającym (M).
- 4The method according to claim The process of any one of claims 1 to 3, characterized in that the multimedia processing device (STB) comprises a decryption and decompression (DD) module in which a private key (RK) is initialized. 4. Sposób według zastrz. 1 do 3, znamienny tym, że urządzenie przetwarzające multimedia (STB) obejmuje moduł deszyfrujący i dekompresujący (DD) , w którym inicjalizowany jest klucz prywatny (RK).
- 6The method according to claim The method of any of claims 1 to 5, characterized in that said irreversible function is of the hash or MAC hash type. 6. Sposób według zastrz. 1 do 5, znamienny tym, że wymieniona funkcja nieodwracalna jest typu hash lub hash MAC. 1813-PAT-EP-PL PAT-1813-EP-E EP1946552 EP1946552
- 9A method according to claims processing multimedia allowing creation 9. Sposób według zastrz przetwarzające multimedia pozwalające na utworzenie 8, characterized in that the STB device) receives multimedia data of this list of identifiers (CAS_ID1 ... CAS_IDn). 8, znamienny tym, że urządzenie STB) otrzymuje dane multimedialne, tej listy identyfikatorów (CAS_ID1...CAS_IDn).
- 13Decryption and decompression module (DD), designed to be mounted in a multimedia processing device (STB) and comprising a central unit, a decryption unit and at least one private key (RK) and means to generate 13. Moduł deszyfrujący i dekompresujący (DD), przeznaczony do zamontowania w urządzeniu przetwarzającym multimedia (STB) i obejmujący jednostkę centralną, jednostkę deszyfrującą i co najmniej jeden klucz prywatny (RK) oraz środki do wygenerowania 1813-PAT-EP-PL PAT-1813-EP-E EP1946552 klucza zabezpieczającego (VK), obliczanego przy użyciu funkcji nieodwracalnej na podstawie klucza personalnego (RK) i identyfikatora podmiotu (CAS_ID), zapisanego w module zabezpieczającym (M) i otrzymanego przez wymieniony moduł deszyfrujący i dekompresujący (DD), przy czym wymieniony moduł zabezpieczający (M) przeznaczony jest do podłączenia do urządzenia przetwarzającego multimedia (STB) w celu przeprowadzania czynności autoryzacyjnych, znamienny tym, że obejmuje ponadto środki do otrzymywania z wymienionego modułu zabezpieczającego danych zaszyfrowanych tym samym kluczem zabezpieczającym (VK) obliczonym przez centrum zarządzania i załadowanym do wymienionego modułu zabezpieczającego (M). EP1946552 security key (VK), calculated using an irreversible function based on a personal key (RK) and entity identifier (CAS_ID), stored in the security module (M) and received by the said decryption and decompression module (DD), with the said security module (M) is intended to be connected to a multimedia processing device (STB) in order to carry out authorization operations, including that further includes means for receiving from said security module data encrypted with the same security key (VK) calculated by the management center and loaded into said security module (M).
Independent claims5
48 paragraphs in 12 sections, as filed
[0001] The invention relates to the field of pay-TV decoders, in particular set-top boxes equipped with a security module to provide an authorization function.
Prior art [0002] A pay-TV decoder typically includes a receiver capable of receiving and processing signals from various sources, such as satellite, cable, IP network; a filtering unit capable of downloading one or more data streams from among many possible such streams; central processor, tasked with managing the decoder and user interface; a modulator for decrypted signals to the display and decryption and decompression, which receives the encrypted data stream from the filter unit and sends this data in decrypted form to the demodulator, which module is designed to decrypt the data stream and decompress it to a standard format such as DVB.
[0003] It should be noted that the physical decryption and decompression module is mounted on a common base with the modulator, so that data in unencrypted form is not accessible after decryption. Such a decoder is connected to a security module, which can take various forms, such as a microprocessor card, SIM card, electronic module of any form, which can be connected to the decoder in a contact or contactless manner.
PAT-1813-EP-E
EP1946552 [0004] The decoder may be in a variety of forms, such as a well-known attachment next to a television set, but also in the form of electronic portable devices such as a Palm, a third generation cell phone or an iPod<sup>TM</sup>.
[0005] In order to ensure secure exchange between the security module and the decoder, the data transmitted by the security module is encrypted with the own key of the given decoder. This solution is described in document WO99 / 57901A1. The keys necessary to decrypt audio or video content are therefore read from security messages that can be read by this module only after verifying the permissions.
[0006] These keys or control words are encrypted with the own key of the security module / decoder pair and sent to the decoder.
[0007] In order to enhance security in the decoder, control words are decrypted only in the decryption module. Each of these modules has its own key, which is given to the security module by secure means, supervised by the control panel. An example of such a solution is also illustrated in document WO2004 / 010698, in which the decryption key is located directly in the stream decryption module, which key allows decryption of the keys sent by the security module.
[0008] The procedures for creating the encryption key for the channel between the decoder and the security module are based on knowledge of a shared secret (see document WO03107585 or
US2004 / 0088558). Therefore, if the decoder must be able to receive data from several security modules, each
PAT-1813-EP-E
EP1946552 module must have access to the secret of opening to create this secure channel.
[0009] Document XP040400335 from SCTE (Society of Cable Telecommunications Engineers, Inc), entitled "Copy Protection for POD Module Interface", SCTE DVS / 213 ("Copy Protection for POD Interface Module"), June 1, 1999, describes the protection mechanism content exchanged between the security module and the control host. To this end, the module decrypts the content (received from various services) and encrypts it again using a shared key for this host and module. The module and host have one private key and the corresponding public key. They exchange their public keys and use those public keys received from each other to create a shared key, starting from their own private keys. Thus, the shared key is determined on the basis of two keys, namely one public key and one private key.
[0010] Document WO 99/18729 describes a method for sending and receiving encrypted data in which the decrypted control word stream is re-encrypted before it is returned to the decoder by the security module. This re-encryption is performed using a shared key that depends on the variable N identifying the decoder. This variable is used to vary the common key previously known to the decoder and security module. The decoder will decrypt this stream using this key and this variable. The receipt of the public key is the result of a previous transmission, as a result of which it is stored in the decoder permanent memory.
PAT-1813-EP-E
EP1946552 [0011] In order to establish a secure connection between the decoder and the security module, document US 2004/088558 suggests using a key sequence in the hierarchy. To this end, he describes a decryption device that uses a unique key that is assigned to it, and a logical circuit that generates a sequence of three related variables, the first of which, being a function of the unique key and random number, serves as the key to encrypt the content and the third variable , deduced from the second variable, serves as the key to decrypt this encrypted content. As a variant, a coupling key that implies the first variable can be used to obtain the second variable.
[0012] Document US 2005/0111666 proposes a method of communication between two devices in order to avoid systematic repetition of the same security key in encryption via a pre-algorithm, communication between two devices. To this end, it is proposed to modify this security key on the basis of algorithmic identification and the key pre-shared with these two devices during the key reconciliation procedure between the two devices.
[0013] As a result of the growing need for interactivity, it became necessary to jointly operate decoders by several operators or several entities, with the entity defined here as a group of decoders having one common feature connected to one common entity (location, type of contract, version of equipment, etc.). This, of course, forces the decryption key to be sent to these various entities. If one of these entities becomes a source
PAT-1813-EP-E
EP1946552 leakage, you can imagine the damage not only to this entity, but to all others.
Brief description of the invention [0014] The purpose of the present invention is to propose a method for creating a secure channel with confirmation of identity between a media processing center and a security module, which channel could be shared between several entities, and data sent through that channel to one entity would not disclose the other entities.
[0015] This object is achieved thanks to the method according to claim 1.
[0016] Thus, a security key is generated for each group of security modules that enables dialogue with this multimedia data processing device.
[0017] The goal is to give each subject only the own key of this multimedia data processing device to enable this device to securely exchange data with said security module.
[0018] The irreversible function may belong to different types, such as, for example, the hash function (SHA, MD2, MD5, HMAC), the hash function (HMAC) or the encryption function, the operator identifier being encrypted with the private key of the multimedia data processing device .
Short description of the drawing
PAT-1813-EP-E
[0019] The invention will be better understood by the following detailed description, which refers to the attached drawing, given as a non-exclusive example, showing a multimedia processing device that can be connected to two security modules.
Detailed description of the invention [0020] The detailed description refers to Fig. 1. The essence of the invention is the ability to secure the communication channel while guaranteeing management by the management center. This management center has a list of private keys for multimedia processing devices. For the purposes of this presentation, let's consider a STB decoder as illustrated in Fig. 1.
[0021] The STB decoder includes a DD decryption and decompression module that receives multimedia data in an encrypted form and which processes them to convert them into a form suitable for use by a visualization device such as a television set.
[0022] To perform data decryption, the decryption keys provided by the security module M must be available. The channel between the security module M and the DD module is encrypted with a security key to avoid the possibility of using the decryption key by more than one decoder. The following describes how to generate this key.
[0023] A management center is established to determine the security parameters for communication between a given entity and a given decoder. The first operation is to assign this entity the CAS_ID identifier that only belongs to it. Second
PAT-1813-EP-E
Ί
EP1946552 operation is to identify the decoder and on this basis to know its personal key RK.
[0024] Based on these two information, the management center calculates the VK security key using an irreversible function using these two information. The simplest solution is the hash function on the block created from the subject identifier and personal key (HMAC). The result gives the VK security key, and its recognition by the operator does not allow him to recreate the RK personal key.
[0025] This security key VK is then loaded into the security module M, either during initialization or during the commissioning phase by sending the control message by the subject via multimedia data.
[0026] In order for the decoder to generate the VK security key, it must know the subject identifier CAS_ID. This information can be obtained in several ways, for example by reading it from data contained in the multimedia data stream. If the decoder is to receive a data stream from only one source, it is possible to include information on the subject identifier in this stream.
In another implementation, it is the security module M to communicate this information to the decryption and decompression module DD. This particular implementation was selected to be illustrated in this patent application, without excluding functionality in the first implementation.
[0028] When the security module wants to establish a dialogue with the STB decoder, for example the M1 module, and in particular with its DD decryption and decompression module, this module sends its entity ID CAS_ID1 to the decryption module and
PAT-1813-EP-E
EP1946552 decompression DD. The latter will calculate the same irreversible function that the control center calculated in order to obtain the security key VK1a. This key is used to decrypt the data received from the M1 security module. If this module does not have this key to encrypt information, the data received from the DD decryption and decompression module will be impossible to decrypt. In order to avoid possible data distortion, it is possible to add a verification phase in which the security key is determined by the DD decryption and decompression module. Thus, it is determined that the next message generated by the security module is a reference variable (e.g. 01010101B), encrypted with the security key VK1a. If this variable is not received by the DD decryption and decompression module, processing will be terminated. In a more sophisticated implementation, the DD decryption and decompression module generates a random number N, encrypts it with a security key, and sends this cryptogram to the security module. The latter decrypts the cryptogram to obtain the random number N. It applies to this random number the previously agreed function (addition, subtraction, XOR, etc.) to obtain N '. The security module encrypts N 'with a security key and sends this cryptogram to the DD decryption and decompression module. The latter decrypts this cryptogram and checks the relationship between the generated random number N and the received number N '. If this relationship is consistent with that previously agreed, it means that both parties have the same key.
PAT-1813-EP-E
EP1946552 [0029] In one embodiment, the entity identifier may be extended to the identifier of the security module. As a result, the management center knows the decoder, so its DD decryption and decompression module and the security module to work with this decoder can generate a security key that is a function of the security module ID and the private key of the DD decryption and decompressing module. This function creates a coupling between the M1 security module and the decryption and decompression module
DD.
[0030] In one variant of this implementation, the security module identifier is formed of two parts, namely the operator identifier and the own identifier of the module in the entity's classification.
[0031] With this coding method, this identifier will be useful in implementations requiring identifier verification with a certain list; only the entity dependent part of the identifier will be verified by the decryption and decompression module
DD.
[0032] In one embodiment, the decryption and decompression module DD comprises means for verifying the compliance of the security module M to which it is connected. In this way, the DD decryption and decompressing module contains a list of allowed identifiers for creating a security key as illustrated in Fig. 1 by CAS_ID lists. In this case it is positive because it includes the allowed CAD_ID; it can also be a negative list and then contains a prohibited CAD_ID list.
PAT-1813-EP-E
EP1946552 [0033] There are many ways to manage these lists and we will now present some of these methods.
Leaflet [0034] In the first case, each DD decryption and decompressing module includes a list of, for example, 100 identifiers CAD_ID1 ... CAS_ID100. The management center can insert into the multimedia data stream commands to deactivate one or more identifiers, which will result in the definitive erasure of one or more identifiers. This will have the effect that these identifiers will no longer be allowed to create security keys with the security module.
[0035] These deactivation commands are preferentially encrypted or signed with a shared key for all DD decryption and decompressing modules.
Evolutionary List [0036] A multimedia data stream includes information that allows forming such a list. At first, no identifier is allowed (or the default CAD_ID1 identifier), and the commands allow you to program authorized identifiers and erase canceled identifiers. The results of these commands are saved to non-volatile memory. As before, these commands are preferentially encrypted or signed with a shared key for all DD decryption and decompressing modules.
[0037] As part of one embodiment, the DD decryption and decompression module includes a volatile memory that is empty when
PAT-1813-EP-E
EP1946552 each inclusion. Then the identifiers received in the current multimedia data stream are loaded into this memory. This allows you to associate the multimedia data stream with a given set of entity identifiers. These identifiers are placed in the table and form part of the SI information stream. It is then possible to allow the contents of this table to be modified during a given data transmission session and based on the list of allowed entities, the DD decryption and decompressing module remembers the ID of the entity with which the security key was created and when the ID table changes, it checks whether the current ID is still found in the new table. If not, the data sent by stops the security and security reception.
this module requests a new key initialization phase
PAT-1813-EP-E
EP1946552
Contents12
8 priority claims, no other members on record
Priority claims8
| Document | Office | Kind | Date |
|---|---|---|---|
| 05110316 | European Patent Office (EPO) | A | |
| 05110316 | European Patent Office (EPO) | A | |
| 06829929 | European Patent Office (EPO) | A | |
| 2006068041 | European Patent Office (EPO) | W | |
| 2006068041 | European Patent Office (EPO) | W | |
| EP20050110316 | – | – | – |
| EP20060829929 | – | – | – |
| WO2006EP68041 | – | – | – |
Numbers
- Publication, DOCDB
- 1946552
- Publication, EPODOC
- PL1946552T
- Application
- 829929
- Application, DOCDB
- 06829929
- Application, EPODOC
- PL20060829929T
Titles2
- English
- METHOD FOR SECURING DATA EXCHANGED BETWEEN A MULTIMEDIA PROCESSING DEVICE AND A SECURITY MODULE
- Polish
- Sposób zabezpieczania danych wymienianych między centrum przetwarzania danych multimedialnych a modułem zabezpieczającym
Classification
- CPC, 4
- H04N21/4181
- H04N7/163
- H04N21/26613
- H04N21/4367
- IPC, 1
- H04N7 16