Method for checking the integrity and authenticity of data (variants)
Abstract
The invention concerns a method and a device for guaranteeing the integrity and authenticity of data transmitted between a management centre and one or several receiver units, wherein each receiver unit comprises a decoder (IRD) and a security unit (SC) and means for communicating (NET, REC) with the management centre. The method consists in calculating a control information (Hx) representing the result of a function said to be unidirectional and collision-free, performed on all or part of the transmitted data and in transmitting the result to the management centre for verification. The centre will be able to inform the decoder concerning the authenticity of the data by return channels or bythe main channel.
Term
No projected expiry on record.
- Priority
- Filed
- Granted
- Today
26 claims: 14 independent, 12 dependent
- 1Method of verification the integrity and authenticity of the data set (from M1 to Mn) taken by the block decoding of a pay-TV receiver, which includes an IRD and a security unit (SC), as well as communication means (NET, REC) with the control center under which calculation of control information (Hx), which is a reflection of the result application of unidirectional and conflict-free functions to all or only to the part of the data (from M1 to Mn) which is different the fact that it includes the following steps:1. Спосіб перевірки цілісності та автентичності набору даних (від М1 до Мn), прийнятих блоком декодування приймача платного телебачення, до складу якого входять декодер (IRD) і блок захисту (SC), а також засоби зв'язку (NET, REC) з центром управління, згідно з яким здійснюють розрахунок контрольної інформації (Нх), що є відображенням результату застосування однонаправленої і вільної від конфліктів функції до всіх або лише до частини даних (від М1 до Мn), який відрізняється тим, що він включає такі етапи: - transmission Control information (Nh) to the security block (SC) and encryption of this control information (Нх) with the help of the first шифроключа (k1);- передавання контрольної інформації (Нх) до блока захисту (SC) і шифрування цієї контрольної інформації (Нх) за допомогою першого шифроключа (k1);- forwarding encrypted control information k1 (Нх) to the control center;- пересилання зашифрованої контрольної інформації k1 (Нх) до центра управління;- decryption of the encrypted control information k1 (Hx) by the control center and comparing it with the reference the value of control information (Well);- дешифрування зашифрованої контрольної інформації k1 (Hx) центром управління і порівняння її з еталонним значенням контрольної інформації (Ну);- transfer of managers data (R) containing the result comparison, in encrypted form to the protection block (SC);- передавання керуючих даних (R), що містять результат порівняння, в зашифрованому вигляді до блока захисту (SC);- decryption encrypted comparison result by the security unit (SC) and information decoder (IRD) for data integrity (from M1 to Mn). - дешифрування зашифрованого результату порівняння блоком захисту (SC) та інформування декодера (IRD) про достовірність даних (від М1 до Мn).
- 4Method for any of claims 1 to 3, which is different the fact that the calculations are carried out by the protection block (SC), and from the decoder (IRD) to the security block (SC) the data is transmitted (from M1 to Mn). 4. Спосіб за будь-яким з пп.1-3, який відрізняється тим, що розрахунки проводяться блоком захисту (SC), а від декодера (IRD) до блока захисту (SC) передаються дані (від М1 до Мn).
- 5Method for any one of claims 1 to 4, which is different in that it includes a service availability descriptor (D) for the data (from M1 to Mn) in the control data (R), the decryption control data (R) and transmission The descriptor (D) to the decoder (IRD), if the result of the comparison is positive, processing data (from M1 to Mn) decoder (IRD) according to the directives contained in descriptors (D). 5. Спосіб за будь-яким з пп.1-4, який відрізняється тим, що він включає наявність сервісного описувача (D) для даних (від М1 до Мn) в керуючих даних (R), дешифрування керуючих даних (R) та передавання описувача (D) до декодера (IRD), якщо результат порівняння позитивний, обробки даних (від М1 до Мn) декодером (IRD) згідно з директивами, що містяться в описувачі (D).
- 6Method for any of claims 1 to 5, which is different the fact that data (from M1 to Mn) are accompanied by information about authenticity (CRC, CS, H) of the mentioned data, and in which the security unit (SC) transmits information to the decoder, whether or not to use it to verify the data (from M1 to Mn) this information regarding reliability. 6. Спосіб за будь-яким з пп.1-5, який відрізняється тим, що дані (від М1 до Мn) супроводжуються інформацією щодо достовірності (CRC, CS, Н) згаданих даних, і в якому блок захисту (SC) передає до декодера інформацію, використовувати чи ні для перевірки даних (від М1 до Мn) цю інформацію щодо достовірності.
- 8Method for any from pp.1-7, which is different because it contains global control information in the control data (R) (N'u), which is a reflection of the result of the application of unidirectional and free from conflicts of function to all or only to a part of global data (from M0 to Mm);these data are the same as the received data (from M1 to Mn), or contain them. 8. Спосіб за будь-яким з пп.1-7, який відрізняється тим, що в керуючих даних (R) він містить глобальну контрольну інформацію (Н'у), яка є відображенням результату застосування однонаправленої і вільної від конфліктів функції до всіх або лише до частини глобальних даних (від М0 до Mm);ці дані є тими ж, що і прийняті дані (від М1 до Мn), або містять їх.
- 13Method for any of claims 10-12, which is different the fact that periodic calculations are made on request from the management center, from block of protection, from the test block (TEST) or from one of the means of communication (NET, REC). 13. Спосіб за будь-яким з пп.10-12, який відрізняється тим, що періодичні розрахунки проводяться на запит від центра управління, від блока захисту, від блока тестування (TEST) або від одного із засобів зв'язку (NET, REC).
- 14Method for any of claims 10-13, which is different because the result of the comparison is transmitted in the created subscriber a message that is common to the system. 14. Спосіб за будь-яким з пп.10-13, який відрізняється тим, що результат порівняння передається у створеному абонентом повідомленні, яке є звичайним для функціонування системи.
- 15Method for any of claims 10-13, which is different the fact that the calculated value (N'h) is passed to the control center inside the subscriber's messages, which are normal for functioning system, with each message containing a part of the calculated value (N'ch). 15. Спосіб за будь-яким з пп.10-13, який відрізняється тим, що розраховане значення (Н'х) передається до центра управління всередині створених абонентом повідомлень, які є звичайними для функціонування системи, причому кожне повідомлення містить частину розрахованого значення (Н'х).
- 16Method for any of the previous paragraphs that is different the fact that the transmission to the control center is carried out in a delay mode, according to the schedule, formed in a pseudo-random way inside beforehand certain time limits. 16. Спосіб за будь-яким з попередніх пунктів, який відрізняється тим, що передача до центра управління здійснюється в режимі затримки, згідно з розкладом, сформованим у псевдовипадковий спосіб всередині заздалегідь визначених часових меж.
- 17Method of verification integrity and authenticity of the data set (from M1 to Mn) stored in a storage device that is linked to a security unit (SC), which includes the following steps:17. Спосіб перевірки цілісності та автентичності набору даних (від М1 до Мn), що зберігаються в запам'ятовуючому пристрої, котрий зв'язаний з блоком захисту (SC), який включає такі етапи: - transfer from the storage device to the control unit (SC) of the control data (R1) containing the encrypted control information k1 (Well), which is a reflection of the result application of unidirectional and conflict-free functions to all or only to the data part (from M1 to Mn);- передавання від запам'ятовуючого пристрою до блока захисту (SC) керуючих даних (R1), які містять зашифровану контрольну інформацію k1(Ну), що є відображенням результату застосування однонаправленої і вільної від конфліктів функції до всіх або лише до частини даних (від М1 до Мn);- calculation of the control information (Nh), which is reflection of the result of application of unidirectional and free of conflicts functions to all or only part of the data (from M1 to Mn);- розрахунок контрольної інформації (Нх), яка є відображенням результату застосування однонаправленої і вільної від конфліктів функції до всіх або лише до частини даних (від М1 до Мn);- comparison of calculated value (Нх) with the encrypted reference value (Well) carried out by the security block (SC) and the forwarding of the administrative information (R2) containing the result of the comparison to storage device. - порівняння розрахованого значення (Нх) із зашифрованим еталонним значенням (Ну), що здійснюється блоком захисту (SC), і пересилання адміністративної інформації (R2), яка містить результат порівняння, до запам'ятовуючого пристрою.
- 20Method for any of claims 17-19, which is different the fact that inside the control data (R1) it contains the service descriptor (D) for data (from M1 to Mn), and if the result the comparison is positive, sends the service descriptor (D) in the encrypted form back to the data storage device (from M1 to Mn) memory device in accordance with the directives contained in the descriptor (D). 20. Спосіб за будь-яким з пп.17-19, який відрізняється тим, що всередині керуючих даних (R1) він містить сервісний описувач (D) для даних (від М1 до Мn), і якщо результат порівняння позитивний, пересилає сервісний описувач (D) у зашифрованому вигляді назад до запам'ятовуючого пристрою для обробки даних (від М1 до Мn) запам'ятовуючим пристроєм відповідно до директив, що містяться в описувачі (D).
- 22The method for any of claims 17-21, which is different the fact that it includes the calculation, periodically or upon request, of values (Hx), which is a reflection of the result of the so-called unidirectional and conflict-free function to all or only part of the data (from M1 to Mn), and the block of protection (SC) compares the result (Nx) with the reference value (Well). 22. Спосіб за будь-яким з пп.17-21, який відрізняється тим, що він включає розрахунок, періодично або за запитом, значень (Нх), які є відображенням результату застосування так званої однонаправленої і вільної від конфліктів функції до всіх або лише до частини даних (від М1 до Мn), причому блок захисту (SC) порівнює результат (Нх) з еталонним значенням (Ну).
- 23The method for any of claims 17-22, which is different that it includes:23. Спосіб за будь-яким з пп.17-22, який відрізняється тим, що він включає: - remembering data (from M1 to Mn) in encrypted form;- запам'ятовування даних (від М1 до Мn) у зашифрованому вигляді;- transfer to security block (SC) in the control data (R1) of the decryption key (k3) for data (from M1 to Mn);- передавання до блока захисту (SC) в керуючих даних (R1) дешифрувального ключа (k3) для даних (від М1 до Мn);- if the comparison result is Hx = Well positive, decryption of data (from M1 to Mn) with encryption key (k3). - якщо результат порівняння Нх=Ну позитивний, дешифрування даних (від М1 до Мn) за допомогою шифрувального ключа (k3).
- 26The method for any of claims 17-25, which is different the fact that inside the control data (R1) it contains a service descriptor (D) for data (from M1 to Mn) to decrypt the controllers data (R1) and pass the descriptor (D) to the storage device if the result comparison is positive, and processing data (from M1 to Mn) to the memory device in accordance with the directives contained in the descriptor (D). 26. Спосіб за будь-яким з пп.17-25, який відрізняється тим, що всередині керуючих даних (R1) він містить сервісний описувач (D) для даних (від М1 до Мn), щоб дешифрувати керуючі дані (R1) і передати описувач (D) до запам'ятовуючого пристрою, якщо результат порівняння позитивний, та обробити дані (від М1 до Мn) запам'ятовуючим пристроєм відповідно до директив, що містяться в описувачі (D).
Independent claims14
102 paragraphs, as filed
The invention relates to the field of control of the integrity and authenticity of data, and in particular with
downloading software.
The invention can be applied to all devices that contain at least one central unit as in
Currently used in information technology, say, a processor, at least part of the program
which is contained within the memory with the possibility of rewriting.
It is well known that the replacement or damage of data leaves its traces in certain parts of the information that was processed and stored in memory, whether before or after processing. It is also known that in order to determine whether the changes in the data under consideration, a simple mathematical method, such as a "checksum" check, is used through the creation of a reference checksum.
However, it is likely that the control system has also undergone a change, and in the future it can not check the contents of its memory. Therefore, during the conduct of mathematical operations, there may be a spread of compensatingadditional errors, which gives a result identical to the expected. Consequently, in certain cases, verification by known methods may prove ineffective.
Thus, there is a problem that does not have a satisfactory solution, which consists in the need to improve the level of reliability and protection achieved through known verification methods, especially when one and the same block is used to calculate its checksum and compare it with the reference value .
It is well known that in order to make all data changes visible, data is used for unidirectional operations, that is, an operation that is easy to execute in one direction, but is almost impossible to execute in another
direction. For example, operation X<sup>in</sup> performed easily, and at the same time operation V<sup>x</sup> Perform a lot more complicated.
The term "conflict-free operation" means an operation whereby any other combination of incoming data yields a similar result.
In the context of the present invention, this unidirectional operation is a mathematical application of H from the source group to the object group in which each element x of the source group is assigned the Hdo symbol. These functions are especially useful when they are functions known as hash functions according to their definition on page 27 of the publication H5Λ BogoGiogiee "Questions about current cryptography, which often occur, v.4.0." Element x can have any length, but H (x) always consists of a number of symbols of a fixed length (a string of fixed size). It is difficult to invert this function, that is, the knowledge of H (x) does not at all mean that we can find x. It is said that it is more free of conflicts if it is injective, that is, when H (γ) = H (x) leads to = x or Η (γ) ^ Η (χ) leads to y * x.
The object of the present invention is to ensure that the information contained in the decoder of the pay-TV receiver is, on the one hand, the one handed over to the control center and, on the other hand, has not been changed.
This goal is achieved by applying a method for verifying the integrity and authenticity of the data set (from M1 to Mp) stored in the memory of the decoding unit of the pay TV receiver, which includes the actual decoding unit and the security block, as well as communication means (NEC, UES ) with the control center.
The method is:
transmission of data (from M1 to Mp) to the security block;
calculation of control information (Hx), which is a reflection of the result of the use of the function known well-directed and free of conflicts, to all or only to a part of the data (from M1 to Mp);
encryption of control information (Nh) with the help of the first encryption switch (k1); establishingconformity of control information (Nh) by communicating with the control center with one ofthe means of communication.
Thus, the integrity of the data is not further verified by the decoding unit alone, in which the data is stored, but is guaranteed by an external device that is considered to be impenetrable - the security block.
According to the present invention, the decoder itself can perform calculations and transmit the results to the block of protection or transfer to the block of protection the data from M1 to Mp, which then performs the calculation of hash information.
Encryption keys used to encrypt information from the control center are contained exclusively in the security block. The decoder does not have the means to decrypt these messages, and thus to modify the data transmitted by the control center when the same messages pass through the decoder.
These security units are usually executed in the form of a smart card and contain memory, microprocessor and communication means.
By means of communication we understand either bidirectional communication through cable, modem or communication in the range of radio waves. This term covers the main means of data transfer and the means by which messages are forwarded to the security module.
A verification of the conformity of control information (Hx) can be performed in several ways.
The security module sends encrypted control information to the control center, and this latter is responsible for conducting the verification. In response, the control center can send either a simple resultcomparation of the OK / NOK, or the reference value. All these messages are encrypted using the encryption switch module.
The control center enters the result in memory with reference to each subscriber device, as proof of the correctness of the operation of loading, or, conversely, as proof of the change of data, for example, considering retorts.
According to one embodiment of the invention, the control center may first send a reference value directly to the security units. Thus, there is no need to request a central management to verify the compliance of the calculated control information, Nh.
According to another way of conducting operations, and in the case when a request for verification is received from the security block, the control center sends to the security block, as a result of comparison, the reference value (Well) in the encrypted form k2 (Well). As soon as this happens, the control center not only informs the security unit whether it is correct or not, but sends this reference value to the security block. It will be done
mainly when the comparison yields a positive result, so that the security unit could remember the reference
meaning Well
Forwarding this information may be done by auxiliary means, for example, by modem
or using the main data path.
In the case where data from M1 to Mp are already accompanied by verification tools, such as cyclic excess code, checksum or hash function, the decoding block can perform initial testing using the tools contained therein. However, the reliability of this test should call into question, andindepend, if the data will be changed by a third person, it is likely that this third person in the same way will change the means of verification. That is why in the method of the present invention, the security unit can inform block decoding so that it does not accept the test result as a guarantee of the authenticity of the data, and this authenticity is determined in accordance with the method described below.
This option is important in the case of updating a number of decoders, some of which have an older version of the operating system and need verification in the checksum, or belong to those that are already equipped for the system according to the method stated here.
When you download updated software, it is common practice to send only the part that has been changed. Data from M1 to Mp do not represent the whole newly updated program. The reason is that in order to support the reliability of the means of verification of the entire program, it is important to have a reference value N'u, which is a reflection of the hash function in the newly created program.
This is the first way, which is to establish the initial integrity of the program P0, that is, before its updating. To do this, the initial results of the H0 hash functions in the program P0 or initialized at the program installation, or determined according to the method of the present invention.
When the authenticity of the updated revision data is installed and inserted into the memory program, the security unit can command the command so that the hash function is applied to the entire new program P1, which will result in N1.This result will be necessary for subsequent checks or subsequent updates.
One of the options of this method is to obtain from the control center a new value H'u, which is a reflection of the action of the hash function on the whole new program P1, and which is shown here from the sequence from M0 to Mt.
The control data P sent by the control center may contain a service descriptor of the data, indicating the decoding block (NSF) how to use this data. The descriptor can be executed in the form of a table, which contains all addresses and recipients of data. Therefore, this data can not be used without a descriptor, and the latter will be returned to the decoding block (III) only when the comparison gives a positive result.
In accordance with an embodiment of the invention, the control center includes confirmation of the control data P, in order to certify the transmitter.
This verification function is related not only to the loading of new data into the decoder, but also allows to carry out testing of the authenticity and authenticity of data at any time. In this case, the operation is in the calculation, periodically or upon request, the values of the display of Hx the result of the application of the so-called unidirectional and free of conflict functions to all or only to a portion of the data (from m0 to Mt) in the operational memory of the decoder and in the transmission of this information (H ' x) to the protection block for comparison with the reference value (N'u).
To perform this operation there is a first way, which consists in the fact that the calculations are made by the decoder, and their result is transmitted to the security block. According to the option of this method, calculations are carried out by the protection block, and data (from M0 to Mt) is transmitted from the decoder to the security block (AP).
The request for verification of these operations may come from the control center, from the block of protection, from the test block, or from one of the means of communication, only if they are under stress.
Since the security unit compares the calculated values of H'x with the reference value H'u, the latter may bepresented either to a value calculated by the decoder I / v after confirmation of its reliability control center, or the reference value provided by the control center.
One of the ways that commonly used by dishonest people in an attempt to understand how a pay-TV system is, is to monitor the response that follows the attempt to modify the system. That is why this invention is equally open to the method of transmitting a comparison result, executed in another way, for example, when the subscriber decides to accept event information, and created subscriber of the message sent to the control center.
In this message, it is useful to put information that the data from M1 to Mp have been changed, otherwise it will be very difficult to link this modification of data with decoder blocking, which may occur much later.
According to an embodiment of the invention, the value of the result of calculations Hx is transmitted to the center of management. In order to do this and leave it hidden, the result is divided into parts and placed, partly in part, inside the administrative messages used by the system.
The control center again forms the value of Hx, part by part, and when its value becomes complete, determines whether these values have changed.
One of the problems encountered when updating a large number of decoders is the number of requests to the control center to get verified.
One of the proposed solutions within the scope of the present invention is to subdivide the pseudo-random method of this request into a verification center for verification.
Another solution described earlier is the reference of the previous reference value. Therefore, if the data is received correctly, which happens in most cases, the update may take effect without waiting for the request to the control center. In any case, this request will be made to confirm that the upgrade has been completed correctly.
In a particular method of operation, the group under consideration contains a transmitter node located inside the control center, and a receiver that can be executed in the form of a sufficiently large number of peripheral blocks that operate in a similar manner. The purpose of the method is to ensure that the software sent by the node
transmitter, are obtained in the authentic form and in full by each of the peripheral blocks. In accordance with the terminology used in pay-per-view television, which is an important but non-exclusive, in the scope of the present invention, in the remainder of this document, peripheral blocks will be called a combined decoder receiver (ΙΕώ), which includes a receiver, a decoder for processing adopted by it a signal and a central processor, or a CP, which operates predominantly with a non-energy storage device, as is the case with a variety of peripherals.
The non-volatile storage device is a memory whose contents, even if the main source of power is excluded, is maintained intact, for example, by using at least one such independent source of energy as electric batteries. Other types of non-volatile memory devices can be used, for example, programmable permanent memory with electric eraser (EERY) and flash programmable permanent storage device (GERM). It is these non-volatile memory devices that store data intact in the event of an interruption of the supply of current, but it is important for the normal organization of the CPU block III.
Information coming from the control center is obtained by the IIS in the form of a data stream that arrives at the I / O block receiver. In the case of encoded television, or more generally interactive television, this data stream contains video information, audio information, data in the form of data, executable applications, and, finally, different types of control data.
In this case, the problem is to ensure that the information is accepted without errors and was interpreted ΙΕû before being written to RAM, especially in the case of executable data, that is, software.
The receiver of the ΙΕώ unit transmits them to the decoder, which then launches them into the circuit through ΙΕώ with the help of a bus. A special multimedia processor is connected to the bus, which in turn is connected to the monitor and one or more speakers, the nonvolatile memory device mentioned above and one or more required subordinate devices. The processor (SR) organizes the correct operation of the ΙΕû and controls it, as well as various subordinate devices, such as the interface, auxiliary memory device, other processors, or a modem. Moreover, the control center can accept exchange information, for example, via a modem connected to a public data network.
These subordinate devices themselves can be a source of errors, which then need to be detected and corrected, especially in the case of downloading a new version of the current software ΙΕώ, and its special SR, or certain executive programs for ΙΕό or its components.
Software and data for which the authenticity and integrity of the software must be guaranteed may be downloaded by various means. One of these means, as already mentioned, is to send the above-mentioned reciever of the updated memory redundancy together with a data stream that contains a series of data blocks M1, M2, ... Mp, similar to the headers, in order for the central unit to be readily recognizable these data from M1 to Dmp.
Alternatively, or as an add-on, data blocks can reach ΙΕό through one of its optional subordinate devices, for example, via a modem.
In the context of this invention, data blocks M1, M2, ... Mp without any interference can be sent in unciphered form, that is, without being encrypted.
In the present form, the method according to the present invention consists in the first application, during the transmission stage, of the unidirectional or hash function to a part, or to all data blocks M1, M2, ... Mn, in order to result in the mapping of Hx of the group from M1 to Mn. Data blocks M1, M2, ... Mn can be processed separately in a completely similar manner and as a result give H1h, which corresponds to M1, Nh2, which corresponds to M2 and Nhp, which corresponds to Mn. This result or these Hx are stored in the memory of the control center for further verification.
When verifying the authenticity of data, the particular criticism is caused by the system by which these data transmitted through public communication channels, such as radio channels, telephones, or the Internet. In this case, the attacker may take the place of the control center and send data for changes in the system's operation, selected target.
A well-known cryptographic attachment during data transfer to verify their authenticity. However, this cryptogram meets only the needs of the author's data identification, but it does not affect the decoder that lost the benchmark criteria.
The efficiency of the method depends in part on the quality of the unidirectional function of H and on the approval of these signals by a block of protection that is considered impenetrable. Thus, a simple checksum does not allow to find the permutation of two blocks of characters in the data, because the addition in mathematics is consideredcommutative and associative action. On the other hand, the result of using the hash function, Hx, is a dualistic image of x, even if it is much longer than Hx. If the permutation of symbols is carried out in a group of characters x, the function H (x) will find it immediately, and then the system will not be able to further operate. The result will be a refusal caused by the protection.
An important aspect of the invention is that it allows at any time to verify the reliability of data in the memory of peripheral blocks. In fact, the presence of this control information in the security module allows the decoder to perform auto-verification. This verification gives the result without its comparison with the control amount that is commonly used in the program memory. If this verification yields a result similar to the standard, the block has different means (modem connection, cable communication) to inform the external block, for example, the central administration, the program mismatch.
If in the present invention, the advantage of creating and transmitting control information is given to the control center, then the invention also provides a peripheral block in which all or part of the program is preloaded together with the control information as described above. This can be done during production at the moment of initialization before a trading operation using the processor, or by loading this control information through one of the peripheral devices at the stage of initialization.
The invention is illustrated by a block diagram of a combined receiver-decoder.
The I / R or the combined receiver decoder shown in this flowchart is a peripheral part of the system before
which method of the invention is used in the order described below. This IIS contains a central tire
U, to which all other modules are attached. The central module of the III block is executed in the form of a central one
CPU processor, whose task is to perform various processes.
The REC receiver receives a stream of data that contains video and audio information, data in the form of data and executable applications, through various service channels, such as cable, Hertz dipole, satellite parabolic antenna, Internet or other known technology. This REC receiver is connected to the interface of the UC channel data transmission, which is also connected to the bus (UB).
To the bus (ВВ) the following blocks are also attached:
multimedia processor MR, designed for processing video and audio information, which sends it in accordance with the monitor νû and loudspeakers Áû;
test channel TC, which can be connected to the TEEST for factory setting and service;
nonvolatile storage device NνM, which is independent of the main source of energy and has its own power supply;
ΙΝΤ interface for a smart card that physically perceives a smart card; auxiliary storage device or TMEM memory block;
Modem MW, connected to the public network NEC, which uses widely known technical and service means;
other processors OR, PC with different functions in accordance with the needs of the user, in particular those related to data processing.
It is the CR that manages the software update, an example of which will be described. He accepts them or discards depending on the results of testing, conducted using the method that is the subject of thisproduct.
These versions of the software for the CII of the III block can be accessed through the IR receiver via the TEZT tester, via the smart card of the AP or via the NTE network. An example will be described below of how streaming video and audio information arrives in the IR through the receiver of the RE.
A dataset representing a new version of the software that arrives in the IPO is written to the timely memory of the TMEM block of the ITU together with the service information after verifying that it is authentic and integral. This allows the control center to download this version of the software in a large number of peripherals and to carry out an error-free installation through IP.
As soon as the message was received by the III block, the data is split into pieces, and these various items are recorded in the temporary memory of TMEM. ΙΡû handles blocks from M1 to Mp in the same state in which they were transmitted, but in reverse order. It is clear that in the case when these blocks are taken in an encrypted form, the first operation is to decrypt the data using the public key of the RIC to have the data unciphered.
The next step is to apply the unidirectional function H to the data blocks from M1 to Mn, so that the result is a value from Nu1 to Nup. In the case when an error occurred in memory blocks M1, M2, ... Mn, during the transmission of the message, this error will manifest itself to Well, which will be different from Nh contained in the control block, and data from M1 to Mp will be rejected. .
These results are transmitted to the smart card of the Armed Forces, which is responsible for verifying their authenticity. As a descriptive note, this operation is carried out by way of communication with the control center, either immediately or later.
An example of functions H is the functions M2, M5, and CNA-1.
According to another embodiment of the invention, the block containing the data does not have a communication channel with the central control. Data comes to the storage device, together with the control information (P1), which is the result of the application of a unidirectional or non-conflict function called the hash function to all or to a portion of the data (from M1 to Mn). The peculiarity of this control information (P1) lies in the fact that, on the one hand, it contains a hash function for the considered data set, and on the other hand, these data are written in encrypted form k2 (Well). The memory device can not recognize or modify them.
During the verification phase, the storage device transmits control information in the encrypted view to the security block. The security block contains means for decrypting this information, especially for creating a result from the use of a hash function (Well).
In addition, in accordance with a first embodiment of the invention, the storage device uses a hash function for data from M1 to Mn, calculates control information Nh and passes it to the security block for comparison. In response, the security unit sends back data to the storage device (P2), including the result of the comparison.
Further, if the data is not authentic, the storage device provides the adoption of the necessary measures.
According to a second embodiment of the invention, the calculation of control information Nh is carried out by a security block, which in this case receives data from the storage device from M1 to Mn.
According to an embodiment of the invention, which provides a higher level of assurance regarding the use of data, the supervising data (P1) appends a key encryption key for encryption of data from M1 to Mn.
These data are pre-recorded in encrypted form, and the hash function is created in these encrypted data. When the data integrity verification for the security block is performed and the result is positive, the security unit inserts a response encryption key k3 into the data (P2) sent to the storage device, which allows the data to be decrypted from M1 to Mp.
According to the variant of the method described above, the block protection does not send the encryption key k3, but the memory device sends the encrypted data from M1 to Mp to the AP protection block for decryption.
As in the previous method, this control can be carried out at any time during the work
storage device.
The control data (E1) contains a D data descriptor that specifies the storage device how to use
these data. This descriptor can be executed in the form of a table containing addresses and recipients of the data.
Therefore, this data can not be used without a descriptor, and the latter will be returned to
a storage device only when the comparison yields a positive result.
You can also provide that a confirmation that the data transmitter certifies to the management data (E1) is added in order to keep it in the security block.
59 members in 40 offices
Priority claims9
| Document | Office | Kind | Date |
|---|---|---|---|
| 143899 | Switzerland | – | |
| 143899 | Switzerland | A | |
| 143899 | Switzerland | A | |
| 0000847 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 0000847 | International Bureau of the World Intellectual Property Organization (WIPO) | W | |
| 143899 | – | – | – |
| CH19990001438 | – | – | – |
| PCTIB0000847 | – | – | – |
| WO2000IB00847 | – | – | – |
Members59
| Document | Office | Kind | |
|---|---|---|---|
| CA2381089A1 | Canada | A1 | |
| CA2686435A1 | Canada | A1 | |
| DZ3211A1 | Algeria | A1 | |
| WO0111820A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU5417500A | Australia | A | |
| IS6188A | Iceland | A | |
| NO20020460D0 | Norway | D0 | |
| NO20020460L | Norway | L | |
| KR20020022092A | Republic of Korea | A | |
| BR0012987A | Brazil | A | |
| EP1201057A1 | European Patent Office (EPO) | A1 | |
| SK1592002A3 | Slovakia | A3 | |
| CZ200277A3 | Czechia | A3 | |
| TR200200286T2 | Türkiye | T2 | |
| EA200200102A1 | Eurasian Patent Organization (EAPO) | A1 | |
| CN1360772A | China | A | |
| IL147589D0 | Israel | D0 | |
| BG106305A | Bulgaria | A | |
| PA8499301A1 | Panama | A1 | |
| HU0201567A2 | Hungary | A2 | |
| HUP0201567A2 | Hungary | A2 | |
| AR025013A1 | Argentina | A1 | |
| HK1047205A1 | Hong Kong, China | A1 | |
| JP2003506963A | Japan | A | |
| EE200200055A | Estonia | A | |
| ZA200200124B | South Africa | B | |
| TW540214B | Taiwan Province of China | B | |
| YU90001A | Yugoslavia, later Serbia and Montenegro (until 2006) | A | |
| CO5300514A1 | Colombia | A1 | |
| MXPA02000213A | Mexico | A | |
| EA003710B1 | Eurasian Patent Organization (EAPO) | B1 | |
| PL353208A1 | Poland | A1 | |
| GEP20033125B | Georgia | B | |
| HRP20020101A2 | Croatia | A2 | |
| AU769218B2 | Australia | B2 | |
| UA66940C2This record | Ukraine | C2 | |
| CN1160904C | China | C | |
| EP1201057B1 | European Patent Office (EPO) | B1 | |
| AT286637T | Austria | T | |
| ATE286637T1 | Austria | T1 | |
| BG64432B1 | Bulgaria | B1 | |
| DE60017261D1 | Germany | D1 | |
| HK1047205B | Hong Kong, China | B | |
| PT1201057E | Portugal | E | |
| ES2235895T3 | Spain | T3 | |
| US6961429B1 | United States of America | B1 | |
| AP1496A | African Regional Intellectual Property Organization (ARIPO) | A | |
| DE60017261T2 | Germany | T2 | |
| US2005281406A1 | United States of America | A1 | |
| HU224845B1 | Hungary | B1 | |
| OA12005A | African Intellectual Property Organization (OAPI) | A | |
| MY130305A | Malaysia | A | |
| IL147589A | Israel | A | |
| KR100782230B1 | Republic of Korea | B1 | |
| RS49730B | Serbia | B | |
| CA2381089C | Canada | C | |
| CZ301928B6 | Czechia | B6 | |
| JP4671088B2 | Japan | B2 | |
| NO332641B1 | Norway | B1 |
Numbers
- Publication
- 66940
- Publication, DOCDB
- 66940
- Publication, EPODOC
- UA66940
- Application
- 2002020857
- Application, DOCDB
- 2002020857
- Application, EPODOC
- UA20020020857
Titles3
- Ukrainian
- СПОСІБ ПЕРЕВІРКИ ЦІЛІСНОСТІ ТА АВТЕНТИЧНОСТІ НАБОРУ ДАНИХ (ВАРІАНТИ)
- English
- METHOD FOR CHECKING THE INTEGRITY AND AUTHENTICITY OF DATA (VARIANTS)
- Russian
- СПОСОБ ПРОВЕРКИ ЦЕЛОСТНОСТИ И ПОДЛИННОСТИ ДАННЫХ (ВАРИАНТЫ)
Classification
- CPC, 2
- H04L9/3236
- H04N21/4367
- IPC, 4
- H04N7 167
- H04L9 32
- G09C1 00
- H04N21 4367