Method of revocation of security modules used to secure broadcast messages
Abstract
This record has no abstract on file.
Term
0.9 yearsto projected expiry
Projected expiry 15 August 2027, counted from filing; an application has no term until it is granted.
- Priority
- Filed
- Published
- Today
- Projected expiry
2 claims: 1 independent, 1 dependent
- 1Claims Zastrzeżenia patentowe 1. Sposób unieważnienia modułów zabezpieczających przeznaczonych do odbioru komunikatów zabezpieczających, nadawanych do szeregu modułów zabezpieczających, które to moduły zabezpieczające obejmują przynajmniej jeden klucz prywatny, który to sposób obejmuje kroki podejmowane przed unieważnieniem:A method for invalidating security modules intended for receiving security messages transmitted to a series of security modules, the security modules comprising at least one private key, which method comprises steps taken prior to cancellation: - podział zestawu modułów zabezpieczających na przynajmniej dwie grupy, - splitting the set of security modules into at least two groups, - determination of an asymmetric key for each group, including a public key and a number of different private keys, allowing to decrypt a message encrypted with a public key, - określenie klucza asymetrycznego dla każdej grupy, obejmującego klucz publiczny i szereg różnych kluczy prywatnych, pozwalających na odszyfrowanie komunikatu zaszyfrowanego kluczem publicznym, - loading one of said private keys into each of the security modules, each module receiving a different private key, and these private keys correspond to the public key of the given group, - załadowanie jednego z rzeczonych kluczy prywatnych do każdego z modułów zabezpieczających, przy czym każdy moduł otrzymuje inny klucz prywatny, a te klucze prywatne odpowiadają kluczowi publicznemu danej grupy, - sending one security message to the group, which message is encrypted with the public key of said group;- wysłanie jednego komunikatu zabezpieczającego na grupę, który to komunikat jest zaszyfrowany kluczem publicznym wymienionej grupy;the annulment includes the following steps: unieważnienie obejmuje następujące kroki : sending to each element of the same group, from which one of the modules is annulled, with the exception of the invalidated security module, a new private key corresponding to a public key of another group, each private key being encrypted with a private key of said security module, characterized in that the modules security features include a shared key and the fact that the content of the security message is encrypted additionally with a version key which is encrypted with a shared key and sent shortly before using the content of this security message. wysłanie do każdego elementu tej samej grupy, z której jeden z modułów zostaje unieważniany, z wyjątkiem unieważnianego modułu zabezpieczającego, nowego klucza prywatnego, odpowiadającego kluczowi publicznemu innej grupy, przy czym każdy klucz prywatny zaszyfrowany jest kluczem prywatnym wymienionego modułu zabezpieczającego, znamienny tym, że moduły zabezpieczające zawierają wspólny klucz oraz tym, że treść komunikatu zabezpieczającego jest zaszyfrowana dodatkowo kluczem wersji, który zaszyfrowany jest kluczem wspólnym i wysyłany krótko przed użyciem treści tego komunikatu zabezpieczającego. 2. A cancellation method according to claim 1;1 used in a pay-TV system with an audio / video data stream encrypted using control words (CW) which are transmitted in control messages (ECMs) encrypted with a transmission key, characterized in that the security message includes a transmission key needed to decrypt the control message ( ECM). 2. Sposób unieważnienia według zastrz. 1 używany w systemie telewizji płatnej ze strumieniem danych audio/wideo zaszyfrowanym przy użyciu słów kontrolnych (CW), które nadawane są w komunikatach sterujących (ECM), zaszyfrowanych kluczem transmisji, znamienny tym, że komunikat zabezpieczający zawiera klucz transmisji potrzebny do odszyfrowania komunikatu sterującego (ECM). 2467-PAT-EP-PL PAT-2467-EP-E EP2052539 EP2052539 3. Sposób unieważnienia według zastrz. 1 używany w systemie telewizji płatnej, w której strumień danych audio/wideo jest zaszyfrowany słowami kontrolnymi (CW), które są przesyłane w komunikatach sterujących (ECM), które to komunikaty są zaszyfrowane kluczem transmisji, znamienny tym, że komunikat zabezpieczający zawiera główny klucz szyfrujący ze słowami kontrolnymi (CW). 3. The annulment method according to claim 1 used in a pay-TV system in which the audio / video data stream is encrypted with control words (CW) that are transmitted in control messages (ECMs), which messages are encrypted with a transmission key, characterized in that the security message includes a master encryption key with control words (CW). 4. Sposób unieważnienia według zastrz. 1, znamienny tym, że komunikat zabezpieczający zawiera aktualizacje oprogramowania wymienionego modułu zabezpieczającego. 4. The annulment method according to claim The system of claim 1, wherein the security message includes software updates of said security module. 5. Sposób unieważnienia według zastrz. 1 do 4, znamienny tym, że elementy unieważnianej grupy są przypisywane do innej istniejącej grupy z wyjątkiem unieważnianego modułu zabezpieczającego. 5. The annulment method according to claim The method of any of claims 1 to 4, characterized in that the elements of the invalidated group are assigned to another existing group except for the invalidated security module. 6. Sposób unieważnienia według zastrz. 1 do 4, znamienny tym, że elementy unieważnianej grupy są przypisywane do nowej grupy z wyjątkiem unieważnianego modułu zabezpieczającego. 6. The annulment method according to claim The method of any of claims 1 to 4, characterized in that the elements of the invalidated group are assigned to a new group except for the invalidated security module. 2467-PAT-EP-PL PAT-2467-EP-E EP2052539 EP2052539 Fig. 1 Fig. 1 Ζε7 Ζε7 Fig. 2 Fig. 2 Fig. 3 Fig. 3
57 paragraphs in 9 sections, as filed
[0001] The invention relates to the field of security of security modules, which modules are intended for storing personal data and secrets enabling access to services or performances.
More precisely, the invention relates to the field of pay-TV, in which content is transmitted in encrypted form, and its decryption is subject to certain conditions.
PREVIOUS TECHNICAL CONDITION [0003] In a well known manner, in order to view a pay-TV program, such as a movie, sports competition or in particular a match, a series of streams are transmitted to a multimedia unit, for example a decoder. In particular, on the one hand it is a file with a given program in the form of an encrypted data stream, and on the other hand it is a stream of control messages that allow to decrypt the data stream. The contents of the data stream are encrypted with control words (cw), which are regularly renewed. This second stream is called the ECM (Entitlement Control Message) stream and can be formed in two different ways. According to the first method, the control words are encrypted with a key, called the CT transmission key, which is generally assigned to the transmission system between the management central and the security module assigned to the receiver / decoder. This control word is obtained by decrypting control messages by the CT transmission key.
[0004] According to the second method, the ECM stream does not directly contain scrambled control words, but information allowing the determination of control words. This determination of the control words can be carried out by various operations, in particular by decryption, which decryption can immediately give these control words, corresponding to the first method described above, but decryption can also lead to a data element that will contain this control word that must then be extracted from this piece of data. In particular, this data may contain this control word, as well as a certain value associated with the content intended for transmission, in particular the conditions of access to it.
PAT-2467-EP-E
EP2052539 content. Another operation that allows the determination of this control word may use, for example, an unambiguous hash function, in particular performed on this information.
[0005] Operations related to data protection are usually performed in a security module belonging to a multimedia set or a decoder. The security module can exist in four different forms. One of them is a microprocessor card, a smart card or more generally an electronic module (in the form of a key, cards, ...). This type of module is usually removable and can be connected to a decoder. The form with electrical contacts is the most widely used, but non-contact constructions can be used, for example of the ISO 14443 type.
[0006] A second known form is a normally built-in integrated circuit placed inside a decoder. A variant of this solution is a circuit based on a socket such as a SIM socket.
In a third embodiment, the security module is integrated in the housing of the integrated circuit, which also has another function, e.g. a module for arranging the signal in the decoder or the decoder microprocessor.
[0008] In a fourth embodiment, the security module has no material form and its function is implemented programmatically. Because in these four cases the level of security varies, but the functions are identical regardless of the method of implementation, in this description we will talk about the security module performing its functions regardless of its physical form.
[0009] At the time of decrypting the control message (ECM), it is checked in the security module whether there is permission to access the content in the security module. These rights can be given in the Entitlement Management Message (EMM), which loads those rights to the security module.
[0010] The transmission of digital data on conditional access is usually divided into three modules. The first module is designed to encrypt these digital data using the control words cw and transmit these data.
[0011] The second module prepares control messages ECM, containing control words cw and access conditions, and transmits them to users.
PAT-2467-EP-E
EP2052539 [0012] The third module prepares and transmits EMM authorization messages responsible for determining the reception rights in the security modules connected to the receivers.
[0013] When the first two modules are usually independent of the recipients, the third module manages the user groups and transmits data to a given user, group of users or all users.
One method of bypassing security that is difficult but feasible is to analyze the content of the authorized security module (reverse engineering) to imitate the security component (decrypting messages) by bypassing the authorization verification element. It is therefore possible to produce a "clone" of an authentic security module. Such a clone will have a transmission key that will allow to decrypt the control words c in the control messages ECM. Because the permissions are not verified in this cloned module, it will work as the original in decrypting without the need to have permissions to decrypt.
[0015] In the pay-TV system, it is possible to change the transmission key. You can actually use two different methods for this. The first involves the transmission of a new key to all decoders. The latter can then be updated so that just after using the new key, the decoder can decode the program. This type of update does not allow disabling the cloned decoder, as it also receives update messages as it has the appropriate decryption keys.
[0016] Since each security module includes at least one unique key, the second method consists in sending a new transmission key in a message encrypted with this unique key. In this case, the number of messages is equal to at least the number of installed security modules, and transmission keys are renewed individually. It is known that if the module is turned off (that is, if the mother's camera is not powered), he will not receive such a message and will no longer be able to offer the user the service to which the user has the right rights when he turns on the power of his camera. To avoid this situation when sending a message to the module, this message is repeated many times to ensure that it was correctly received by the recipient.
PAT-2467-EP-E
EP2052539 [0017] Due to the constraints of the available bandwidth and to ensure that each subscriber receives a new key, it is necessary to send this message before this new key is used, for example, in a month's advance, each message being repeated at different times of the day.
[0018] Thus, the owner of the cloned module will request a new transmission key from the technician who provided him with that clone and who has the means to extract the new transmission key from the authentic module. After providing this key, for example on the Internet, all clones can then be updated before this new key is activated. In this way, all clones are always active.
[0019] As a result, sending the transmission keys both as part of the global and individual transmission has disadvantages, as a result of which the cloned module can not be eliminated.
BRIEF SUMMARY OF THE INVENTION [0020] It is therefore an object of the present invention to propose a method for preventing the unauthorized use of data regarding access conditions, in particular via cloned security modules whose protection has been broken.
[0021] This object is achieved by a method of invalidating security modules intended to receive security messages transmitted to a series of security modules, which security modules comprise at least one private key, and the said method comprises the following steps performed prior to cancellation:
- division of the set of security modules into at least two groups,
- definition of an asymmetrical key for each group, containing a public key and a number of different private keys,
- loading one private key into each security module,
- preparation for transmission of one security message per group, which message will be encrypted with the public key of said group; and the annulment includes the following steps:
- sending to each member of the group from which one of the security modules is to be revoked, with the exception of the invalidated module of the new private key,
PAT-2467-EP-E
EP2052539 corresponding to a public key from another group, each private key being encrypted with a private key of said security module.
[0022] For example, the generation of an asymmetric key group may be performed using a Boneha-Franklin system (Dan Boneh, Matthew K. Franklin: An Efficient Public Key Traitor Tracing Scheme. CRYPTO 1999: 338-353). A number of private keys can be generated from the public key, each of which allows decrypting a message encrypted with this public key.
[0023] This allows different keys to be inserted in each security module by sending a limited number of different messages.
Brief description of the drawings [0024] The invention will be better understood by the following detailed description, which refers to the attached figures, given as a non-exclusive example, of which:
- Fig. 1 schematically depicts a pay-TV transmitter and receiver,
- Fig. 2 shows the division into 4 groups, each of which includes 3 security modules,
- Fig. 3 shows the divisions of these groups after canceling a security module.
DETAILED DESCRIPTION OF THE INVENTION [0025] In the field of distribution of security messages prepared and sent from a CG management center to a series of STB multimedia sets, there is a compromise between global addressing, i.e. sending a given message to all sets, and individual addressing, i.e. sending separate ones. messages for individual sets.
[0026] In the first case, the system is fast, since only one message allows, for example, to change the transmission key. It is this key that encrypts messages containing CW control words.
[0027] The consequences of the second case can be imagined when it is necessary to regularly send information to each security module.
[0028] Therefore, in a solution according to the present invention, security modules are divided into groups, each of which may comprise several hundred modules. According to a certain variant, each group consists of 256 elements. Therefore, one million subscribers are represented by
PAT-2467-EP-E
EP2052539 about 4,000 groups and therefore 4000 messages for renewing the transmission keys or updating the security program.
[0029] The CG management center sends security messages to the STB multimedia sets. These sets of STB include the SC security devices illustrated in Fig. 1 by the insertable smart card.
[0030] At the moment of personalization of such a security module, secret keys belonging to each module are loaded. Each security module has an UA identification number that will allow tracking of these secret keys entered into the modules.
[0031] The CG management center has a database with a list of private keys for each security module.
[0032] The division of modules into groups can be carried out either during module personalization (generally before delivery) or on-site during commissioning. According to our invention, a key is needed to access the website offered by the management center, i.e. a certain piece of information. It can be an independent and complementary step in managing permissions. The fact that this key, i.e. information is available to all security modules, does not mean that services are available to subscribers with these security modules.
[0033] As previously indicated, the security module is assigned to a certain group, for example the GrA group. This assignment can be done either during the initialization of this module or by sending a private key corresponding to the GrA group. Sending this key is protected by encrypting this key with one of the private keys of this security module. According to the example in Fig. 2, the protection modules SC1A, SC2A and SC3A belong to this group GrA. Secret information is encrypted with the KGrA key in the CG management center and decrypted by each private key in the security modules.
[0034] In the same way, other GrB, GrC or GrD groups also include SC..B, SC..C or SC..D security modules.
[0035] Thus, this set of security modules receives the secret information needed for the proper functioning of the conditional access system by sending as many different messages as there are sets of modules. It should be noted that repetition of messages is not avoided in the case of
PAT-2467-EP-E
EP2052539 when the decoder does not have a reverse channel. The management center will repeat messages according to a predetermined pattern, e.g. once a day at various times, selected at random.
[0036] When detecting a clone of a security module, for example, if such a module has been compromised by extracting keys from it, its private key will be included in all clones.
Once the clone has been recognized, it is possible to determine which group of security modules has been compromised by comparing the private key of that clone with the private keys stored in the management center. The management center keeps copies of the private key loaded into each security module. According to our example, the invalidation module is the SC1A module. The GrA group will therefore disappear as it is no longer possible to send secret encrypted messages using the KGrA public key. Before you stop sending messages encrypted with the KGrA group key, all security modules must change the group except for the security module that has been violated.
In the example of Fig. 3, the SC2A security module is moved to group B, the SC2A module is moved to the group D. This operation is carried out by sending a group key of this new group. The key of this group is encrypted with the private key of the security module, so that this message can be decrypted only by the appropriate security module. After removing intact items from the compromised group, sending messages with the group A key is paused. From now on, all clones will stop working because they can no longer receive secret information.
[0039] The transfer of members not revoked to other groups may be carried out either to existing groups or to a newly created group.
[0040] Assignment to a group is determined by the presence of a unique private key generated in an asymmetric system using a public key and a series of private keys. According to another embodiment, a group identifier is also assigned to filter messages belonging to that group from other groups. The secret information is encrypted with the public key of a given group, and the group identifier is added to the said message. This allows the decryption of the message and the statement that its content is random due to the use of the wrong key. The group ID should be tested by the host that received this one
PAT-2467-EP-E
EP2052539 identifier from the security module. The security message is sent to the security module only if it contains the same identifier as the security module [0041] Secret information can occur in several forms and is transmitted in security messages. Document WO0156287 describes a method of combining information to obtain a control word. Secret information can be either a main control word that will be combined with control words CW contained in control messages or a key to decrypt a message containing a main control word.
[0042] In another embodiment, the form of secret information is the form of a transmission key. This key is used to decrypt ECM control messages and extract control words from them. The transmission key is changed, for example, every month.
[0043] In practice, for example when changing the transmission keys, sending new keys to all security modules may take some time. The security modules will thus have two elements of secret information, one current and the other prepared for update. In the case of a transmission key, the control message header will contain an indication of which transmission key to use. The simple system is to define even transmission keys and odd transmission keys. The control message ECM will contain a parity bit, and thus a key to be used.
[0044] In order to avoid leaving misguided third parties time to find secret information, steps are taken in one embodiment of the invention to encrypt the secret information using the version key. This key is global and used independently of the groups of security modules. Therefore, each security module will receive a message encrypted with the key of its group and encrypted with a global key. It is also possible to send a message with a version key encrypted with a global key and additionally encrypted with a group key.
[0045] Shortly before the activation of the secret information, e.g. the transmission key, the CG management center sends a message containing the global key, encrypted in accordance with one of the embodiments described above. At the moment, each module will be able to have secret information enabling it to process the relevant security data.
PAT-2467-EP-E
EP2052539
Contents9
19 members in 11 offices
Priority claims7
| Document | Office | Kind | Date |
|---|---|---|---|
| 06119127 | European Patent Office (EPO) | A | |
| 06119127 | European Patent Office (EPO) | A | |
| 07802621 | European Patent Office (EPO) | A | |
| 06119127 | – | – | – |
| 078026218 | – | – | – |
| EP20060119127 | – | – | – |
| EP20070802621 | – | – | – |
Members19
| Document | Office | Kind | |
|---|---|---|---|
| EP1890493A1 | European Patent Office (EPO) | A1 | |
| CA2660593A1 | Canada | A1 | |
| US2008044019A1 | United States of America | A1 | |
| WO2008020041A1 | World Intellectual Property Organization (WIPO) | A1 | |
| EP2052539A1 | European Patent Office (EPO) | A1 | |
| CN101507272A | China | A | |
| US2009208010A1 | United States of America | A1 | |
| US7831045B2 | United States of America | B2 | |
| CN101507272B | China | B | |
| BRPI0714521A2 | Brazil | A2 | |
| US8548167B2 | United States of America | B2 | |
| CA2660593C | Canada | C | |
| EP2052539B1 | European Patent Office (EPO) | B1 | |
| PT2052539T | Portugal | T | |
| DK2052539T3 | Denmark | T3 | |
| ES2611313T3 | Spain | T3 | |
| PL2052539T3This record | Poland | T3 | |
| HUE031879T2 | Hungary | T2 | |
| BRPI0714521B1 | Brazil | B1 |
Numbers
- Publication
- 2052539
- Publication, DOCDB
- 2052539
- Publication, EPODOC
- PL2052539T
- Application
- 7802621
- Application, DOCDB
- 07802621
- Application, EPODOC
- PL20070802621T
Titles2
- English
- METHOD OF REVOCATION OF SECURITY MODULES USED TO SECURE BROADCAST MESSAGES
- Polish
- Sposób unieważniania modułów zabezpieczających używanych do zabezpieczania transmitowanych komunikatów
Classification
- CPC, 12
- H04L63/065
- H04L63/10
- H04L2463/101
- H04N7/163
- H04N7/1675
- H04N21/2585
- H04N21/26606
- H04N21/4181
- H04N21/4623
- G06F21/10
- H04L63/0442
- H04N21/2347
- IPC, 6
- H04N21 258
- H04L9 08
- H04L29 06
- H04N7 16
- H04N7 167
- H04N21 4623