Method and apparatus for supporting remote configuration to facilitate subscriber management
Claim Score by NHIP
Abstract
One embodiment of the present invention provides a system that facilitates remotely configuring a device across a network. The system operates by receiving configuration information at the device from a remote system across the network. Next, the system encrypts this configuration information using a device key, which is locally stored at the device and is different from keys associated with other devices. The system then configures the device by storing the encrypted configuration information in a non-volatile configuration store associated with the device. In this way, the encrypted configuration information contained in the non-volatile configuration store cannot be used with another device. In one embodiment of the present invention, receiving the configuration information involves using a secret key, which is locally stored at the device, to decrypt the configuration information received from the remote system. In one embodiment of the present invention, the device key is stored in a one-time programmable memory within the device that can be programmed only once and cannot be reprogrammed.

Term
Term ended
Projected expiry passed 31 May 2021, 5.3 years ago.
- Priority and filed
- Published
- Projected expiry
- Today
25 claims: 3 independent, 22 dependent
- 1Broadest claimClaim Score 80, broad(NHIP)A method for remotely configuring a device across a network, comprising:receiving configuration information at the device from a remote system across the network;encrypting the configuration information using a device key, wherein the device key is locally stored at the device and is different from keys associated with other devices;and configuring the device by storing the encrypted configuration information in a non-volatile configuration store associated with the device;whereby the encrypted configuration information contained in the non-volatile configuration store cannot be used with another device.
- 11An apparatus that facilitates remotely configuring a device across a network, comprising:an interface, at the device, that is configured to receive configuration information from a remote system across the network;an encryption mechanism that is configured to encrypt the configuration information using a device key, wherein the device key is locally stored at the device and is different from keys associated with other devices;and a configuration mechanism that is configured to store the encrypted configuration information in a non-volatile configuration store associated with the device;whereby the encrypted configuration information contained in the non-volatile configuration store cannot be used with another device.
- 23An apparatus that facilitates remotely configuring a device across a network, comprising:an interface, at the device, that is configured to receive configuration information from a remote system across the network;a decryption mechanism that is configured to use a secret key, which is locally stored at the device, to decrypt the configuration information received from the remote system through the interface;an encryption mechanism that is configured to encrypt the configuration information using a device key, wherein the device key is locally stored at the device and is different from keys associated with other devices;and a configuration mechanism that is configured to store the encrypted configuration information in a non-volatile configuration store associated with the device;and a one-time programmable memory within the device for storing the device key and the secret key, wherein the one-time programmable memory can be programmed only once and cannot be reprogrammed;whereby the encrypted configuration information contained in the non-volatile configuration store cannot be used with another device.
Independent claims3
49 paragraphs in 4 sections, as filed
BACKGROUND
[0001] 1. Field of the Invention
[0002] The present invention relates to a system for configuring a remote device across a network. More specifically, the present invention relates to a method and an apparatus for configuring a remote device to facilitate subscriber management.
[0003] 2. Related Art
[0004] As new media technologies continue to proliferate, people are increasingly willing to pay subscription fees for access to content. Monthly cable bills and Internet access bills are becoming as common as other household expenditures, such as utility bills and telephone bills. Unfortunately, existing distribution systems for this type of content have a number of shortcomings.
[0005] It is very cumbersome manage subscribers with existing distribution systems. If a subscriber fails to pay a monthly bill, a cable company typically has to send a service technician out to a remote location in order to disable or reconfigure cable access for the subscriber. A technician visit is also required to add a new subscriber or to change the service level of a subscriber.
[0006] Piracy is also a problem. In existing systems, a transceiver that is used to de-scramble a scrambled signal can typically be replicated or modified to allow a rogue user to access broadcast content without paying. Note that such transceivers can be easily obtained, and thousands of technicians who are employed or were formerly employed by access providers have the knowledge to perform such modifications.
[0007] In order to remedy these shortcomings, some access providers have begun to develop systems that use smart cards and other mechanisms to restrict access to content. However, combining smart cards and other mechanisms into distribution systems can be expensive. Furthermore, even with such mechanisms, distribution systems may still be susceptible to certain types of tampering.
[0008] Moreover, note that it is particularly challenging to remotely manage conditional accesses mechanisms through a broadcast channel that provides only one-way communication from the access provider to the subscriber.
[0009] What is needed is an efficient and low-cost mechanism for configuring a remote device to facilitate subscriber management.
SUMMARY
[0010] One embodiment of the present invention provides a system that facilitates remotely configuring a device across a network. The system operates by receiving configuration information at the device from a remote system across the network. Next, the system encrypts this configuration information using a device key, which is locally stored at the device and is different from keys associated with other devices. The system then configures the device by storing the encrypted configuration information in a non-volatile configuration store associated with the device. In this way, the encrypted configuration information contained in the non-volatile configuration store cannot be used with another device.
[0011] In one embodiment of the present invention, receiving the configuration information involves using a secret key, which is locally stored at the device, to decrypt the configuration information received from the remote system.
[0012] In one embodiment of the present invention, the device key is stored in a one-time programmable memory within the device that can be programmed only once and cannot be reprogrammed.
[0013] In one embodiment of the present invention, receiving the configuration information involves using a public key of the remote system to validate that the configuration information was digitally signed by a corresponding private key belonging to the remote system.
[0014] In one embodiment of the present invention, the device uses the configuration information to control access to a stream of content in order to facilitate subscriber management.
[0015] In one embodiment of the present invention, the configuration information includes either a fixed key or a variable key for decompression and/or decryption of the stream of content.
[0016] In one embodiment of the present invention, the device can include: a computer, a personal digital assistant, a network interface, a cable television interface, a satellite television interface, or a network router.
[0017] In one embodiment of the present invention, the network can include a local area network, a wide area network, or a wireless network.
[0018] In one embodiment of the present invention, configuring the device can involve enabling or disabling the device.
[0019] In one embodiment of the present invention, the device is embodied in an integrated circuit.
BRIEF DESCRIPTION OF THE FIGURES
[0020]FIG. 1 illustrates a remotely configurable device in accordance with an embodiment of the present invention.
[0021]FIG. 2 is a flow chart illustrating the process of initially programming the device in accordance with an embodiment of the present invention.
[0022]FIG. 3 is a flow chart illustrating the process of configuring the device in accordance with an embodiment of the present invention.
[0023]FIG. 4 is a flow chart illustrating how the device is used to restrict access to a stream of content in accordance with an embodiment of the present invention.
DETAILED DESCRIPTION
[0024] The following description is presented to enable any person skilled in the art to make and use the invention, and is provided in the context of a particular application and its requirements. Various modifications to the disclosed embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other embodiments and applications without departing from the spirit and scope of the present invention. Thus, the present invention is not intended to be limited to the embodiments shown, but is to be accorded the widest scope consistent with the principles and features disclosed herein.
[0025] Remotely Configurable Device
[0026]FIG. 1 illustrates a remotely configurable device <b>100</b> in accordance with an embodiment of the present invention. As is illustrated in FIG. 1, device <b>100</b> receives a broadcast transmission <b>116</b> from a remote system <b>114</b>.
[0027] Device <b>100</b> can generally include any type of device or system that can be remotely programmed, including a network router, an appliance, a video game player, a computer system, a personal digital assistant, a cable transceiver or a satellite transceiver. Note that broadcast transmission <b>116</b> can generally include any type of broadcast transmission, including a satellite transmission, a cable transmission, or a free air transmission. Furthermore, broadcast transmission <b>116</b> can generally include any type of content, including audio-visual content as well as unicast or multicast Internet Protocol (IP) transmissions. Moreover, remote system <b>114</b> can include any type of system that can produce a broadcast transmission.
[0028] Broadcast transmission <b>116</b> is received at an interface <b>112</b> within device <b>100</b>. Interface <b>112</b> can generally include various transceivers, tuners and/or demodulators for capturing broadcast transmission <b>116</b>.
[0029] From interface <b>112</b>, broadcast transmission <b>116</b> feeds into semiconductor chip <b>101</b>. Within semiconductor chip <b>101</b>, broadcast transmission <b>116</b> feeds into decryption block <b>110</b>, which decrypts broadcast transmission <b>116</b> (if necessary) using session key <b>121</b>. The decrypted broadcast transmission <b>116</b> is then passed through local interface <b>124</b> to local devices that make use of the content within broadcast transmission <b>116</b>.
[0030] Configuration information <b>120</b> can also be received through broadcast transmission <b>116</b>. Configuration information <b>120</b> can be decrypted at decryption block <b>110</b> using a secret key <b>102</b>, which is unique to semiconductor chip <b>101</b>. This decrypted configuration information <b>120</b> can then be re-encrypted in encryption/decryption block <b>118</b> using device key <b>104</b>, which is also unique to semiconductor chip <b>101</b>. Re-encrypted configuration information <b>120</b> can then be stored in non-volatile store <b>122</b>, which is external to semiconductor chip <b>101</b>. Note that this encryption and decryption can be accomplished through any of a number of known techniques, such as 3DES (Triple Data Encryption Standard). Also note that non-volatile store <b>122</b> can include any type of non-volatile memory, such as EPROM (Electrically Programmable Read Only Memory), flash memory, magnetic storage or optical storage.
[0031] Device secret key <b>102</b> is known only to remote system <b>114</b> and semiconductor chip <b>101</b>. Hence, by encrypting and broadcasting a command using secret key <b>102</b>, remote system <b>114</b> can target only device <b>100</b> to receive the command.
[0032] Furthermore, since device key <b>104</b> is known only to device <b>100</b>, and not to other devices, configuration information <b>120</b> within non-volatile store <b>122</b> can only be used with semiconductor chip <b>101</b> and cannot be used with other semiconductor chips. Hence, even if configuration information <b>120</b> is copied from non-volatile store <b>122</b>, it cannot be used with another device.
[0033] Secret key <b>102</b> and device key <b>104</b> are stored in one-time programmable memory <b>106</b> within semiconductor chip <b>101</b>. One-time programmable memory <b>106</b> has the property that it can be programmed only once and cannot be reprogrammed. For example, one-time programmable memory <b>106</b> can include a PROM (programmable read only memory) or a battery backed up RAM. Note that the contents of a battery backed up RAM disappears if power is interrupted.
[0034] Decryption block <b>110</b> may also include a validation mechanism that uses a public key to validate that a digital signature accompanying configuration information <b>120</b> was produced using a private key belonging to a trusted party.
[0035] Configuration information <b>120</b> can generally include any type of configuration information for device <b>100</b>, such as a fixed session key or variable session key <b>121</b> for decrypting broadcast transmission <b>116</b>. Note that a variable session key is generally valid for a period of time determined with respect to a real-time clock <b>126</b> located on semiconductor chip <b>101</b> and powered by a local battery, or alternatively, with reference to a time signal that is sent from remote system <b>114</b> through broadcast transmission <b>116</b>. Additionally, note that session key <b>121</b> is decrypted in block <b>118</b> before being used by decryption block <b>110</b> to decrypt broadcast communication <b>116</b>.
[0036] Configuration information <b>120</b> can include information that enables or disables access to certain channels available in broadcast transmission <b>116</b>. In one embodiment of the present invention, configuration information <b>120</b> can completely enable or disable device <b>100</b>.
[0037] Configuration information <b>120</b> can also be used to set masks that indicate which bits within control registers <b>118</b> can be read from and/or written to. Note that semiconductor chip <b>101</b> includes a number of control registers <b>118</b> that control various functions within semiconductor chip <b>101</b>. These control registers <b>118</b> can be configured by remote system <b>114</b>. Remote computer system <b>114</b> can cause configuration information to be loaded into control registers <b>118</b>. Moreover, by setting appropriate mask bits associated with control registers <b>118</b>, remote system <b>114</b> is able to make some of these registers accessible through local interface <b>124</b>.
[0038] Note that local interface <b>124</b> is insulated from the rest of semiconductor chip <b>101</b>, so that it is impossible to read from or write to secret key <b>102</b>, device key <b>104</b>, or configuration information <b>120</b> through local interface <b>124</b>. This prevents a user of device <b>100</b> from gaining access to secret key <b>102</b>, device key <b>104</b>, or configuration information <b>120</b>.
[0039] Also note that the above-described mechanisms within semiconductor chip <b>101</b> are controlled by controller <b>108</b>. Controller <b>108</b> can include any type of circuitry that can be used to implement control functions. For example, controller <b>108</b> can include a microprocessor within semiconductor chip <b>101</b>.
[0040] Initial Programming
[0041]FIG. 2 is a flow chart illustrating the process of initially programming device <b>100</b> in accordance with an embodiment of the present invention. At the factory, a unique secret key <b>102</b> is first obtained for semiconductor chip <b>101</b>, and is then programmed into one-time programmable memory <b>106</b>. Secret key <b>102</b> is also shared with remote system <b>114</b> so that remote system <b>114</b> can use secret key <b>102</b> to communicate with device <b>100</b>. A unique device key <b>104</b> is also obtained for semiconductor chip <b>101</b>, and is then programmed into one-time programmable memory <b>106</b> (step <b>202</b>). The programmability of one-time programmable memory <b>106</b> is subsequently disabled so it cannot be reprogrammed.
[0042] In an optional step, device <b>100</b> can be pre-programmed at the factory to initially operate in a restricted access mode (step <b>204</b>).
[0043] After installation, an access provider sends a broadcast transmission <b>116</b> to device <b>100</b> in order to configure device <b>100</b> (step <b>206</b>). This configuration process is described in more detail below with reference to FIG. 3.
[0044] Configuring Device
[0045]FIG. 3 is a flow chart illustrating the process of configuring device <b>100</b> in accordance with an embodiment of the present invention. During the configuration process, device <b>100</b> receives configuration information <b>120</b> through broadcast transmission <b>116</b> (step <b>302</b>). Device <b>100</b> then decrypts configuration information <b>120</b> using secret key <b>102</b> from one-time programmable memory <b>106</b> (step <b>304</b>). Device <b>100</b> can also use a public key to validate a digital signature accompanying configuration information <b>120</b> to ensure that configuration information <b>120</b> was signed with a corresponding private key belonging to a trusted entity (step <b>306</b>).
[0046] Next, the system encrypts configuration information <b>120</b> using device key <b>104</b> (step <b>308</b>), and then stores the encrypted configuration information <b>120</b> in non-volatile store <b>122</b> (step <b>310</b>).
[0047] Restricting Access with the Device
[0048]FIG. 4 is a flow chart illustrating how the device is used to restrict access to a stream of content in accordance with an embodiment of the present invention. Device <b>100</b> first receives a stream of content through broadcast transmission <b>116</b> (step <b>402</b>). Device <b>100</b> then uses configuration information <b>120</b> to selectively restrict access to certain channels available through broadcast transmission <b>116</b> (step <b>404</b>).
[0049] The foregoing descriptions of embodiments of the present invention have been presented for purposes of illustration and description only. They are not intended to be exhaustive or to limit the present invention to the forms disclosed. Accordingly, many modifications and variations will be apparent to practitioners skilled in the art. Additionally, the above disclosure is not intended to limit the present invention. The scope of the present invention is defined by the appended claims.
Contents4
4 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10404463B1 | Cited by | United States of America | Search report |
| US10979429B2 | Cited by | United States of America | Applicant |
| DE102016004735A1 | Cited by | Germany | Search report |
| US9722992B2 | Cited by | United States of America | Search report |
| US10262164B2 | Cited by | United States of America | Applicant |
| US2004153657A1 | Cited by | United States of America | Pre-grant |
| US9489318B2 | Cited by | United States of America | Applicant |
| US7849331B2 | Cited by | United States of America | Applicant |
| US10607032B2 | Cited by | United States of America | Applicant |
| US2013279691A1 | Cited by | United States of America | Pre-grant |
| US9652637B2 | Cited by | United States of America | Applicant |
| US2004105548A1 | Cited by | United States of America | Pre-grant |
| US10404454B1 | Cited by | United States of America | Applicant |
| US10796024B2 | Cited by | United States of America | Applicant |
| US8171143B2 | Cited by | United States of America | Applicant |
| US7530101B2 | Cited by | United States of America | Applicant |
| US10262163B1 | Cited by | United States of America | Search report |
| US11093654B2 | Cited by | United States of America | Search report |
| US9904809B2 | Cited by | United States of America | Applicant |
| US2006168238A1 | Cited by | United States of America | Pre-grant |
| US8429410B2 | Cited by | United States of America | Search report |
| US2008028051A1 | Cited by | United States of America | Pre-grant |
| US11093655B2 | Cited by | United States of America | Applicant |
| US7139817B1 | Cited by | United States of America | Search report |
| US2009138728A1 | Cited by | United States of America | Pre-grant |
| US8751786B1 | Cited by | United States of America | Search report |
| US6957335B2 | Cited by | United States of America | Search report |
| EP1524817A1 | Cited by | European Patent Office (EPO) | Search report |
| US10607030B2 | Cited by | United States of America | Applicant |
| US10372943B1 | Cited by | United States of America | Applicant |
| US10200196B1 | Cited by | United States of America | Applicant |
| US10936758B2 | Cited by | United States of America | Applicant |
| US11042669B2 | Cited by | United States of America | Search report |
| US2009037721A1 | Cited by | United States of America | Pre-grant |
| US9553848B2 | Cited by | United States of America | Search report |
| US10256974B1 | Cited by | United States of America | Applicant |
| US2007290715A1 | Cited by | United States of America | Pre-grant |
| US2007217614A1 | Cited by | United States of America | Pre-grant |
| US10885228B2 | Cited by | United States of America | Applicant |
| US7546468B2 | Cited by | United States of America | Applicant |
| WO2004075477A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US2004088559A1 | Cited by | United States of America | Pre-grant |
| US2010275029A1 | Cited by | United States of America | Pre-grant |
| US7539312B2 | Cited by | United States of America | Applicant |
| US10607031B2 | Cited by | United States of America | Applicant |
| US8443064B2 | Cited by | United States of America | Applicant |
| US2006233149A1 | Cited by | United States of America | Pre-grant |
| US2006101506A1 | Cited by | United States of America | Pre-grant |
| US2016006724A1 | Cited by | United States of America | Pre-grant |
| EP1869886B1 | Cited by | European Patent Office (EPO) | Examiner |
| US9461825B2 | Cited by | United States of America | Applicant |
| US7685435B2 | Cited by | United States of America | Applicant |
| US8190912B2 | Cited by | United States of America | Applicant |
| US9608804B2 | Cited by | United States of America | Search report |
| US2004151314A1 | Cites | United States of America | Pre-grant |
| US4888802A | Cites | United States of America | Pre-grant |
| US5237610A | Cites | United States of America | Pre-grant |
| US5954817A | Cites | United States of America | Pre-grant |
| US5970142A | Cites | United States of America | Pre-grant |
| US6073172A | Cites | United States of America | Pre-grant |
| US6223284B1 | Cites | United States of America | Pre-grant |
| US6636971B1 | Cites | United States of America | Pre-grant |
| US6697489B1 | Cites | United States of America | Pre-grant |
2 members in 2 offices
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 87262201 | United States of America | A | |
| US20010872622 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| US2002184512A1 | United States of America | A1 | |
| WO02098106A1 | World Intellectual Property Organization (WIPO) | A1 |
16 transactions on the USPTO file
Abandoned after 1 non-final rejection.
- Non-final rejections
- 1
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | |
|---|---|
| Mail Abandonment for Failure to Respond to Office ActionAbandoned | |
| Aband. for Failure to Respond to O. A. | |
| Mail Non-Final RejectionNon-final rejection | |
| Non-Final RejectionNon-final rejection | |
| Case Docketed to Examiner in GAU | |
| IFW TSS Processing by Tech Center Complete | |
| Case Docketed to Examiner in GAU | |
| Case Docketed to Examiner in GAU | |
| Reference capture on IDS | |
| Information Disclosure Statement (IDS) Filed | |
| Information Disclosure Statement (IDS) Filed | |
| Case Docketed to Examiner in GAU | |
| Application Dispatched from OIPE | |
| Correspondence Address Change | |
| IFW Scan & PACR Auto Security Review | |
| Initial Exam Team nn |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Information on status: application discontinuationABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTIONSTCB | STCB | |
| AssignmentAS | AS |
Numbers
- Publication, DOCDB
- 2002184512
- Publication, EPODOC
- US2002184512
- Application
- 9872622
- Application, DOCDB
- 87262201
- Application, EPODOC
- US20010872622
Titles
- English
- Method and apparatus for supporting remote configuration to facilitate subscriber management
Classification
- CPC, 7
- H04L41/28
- G06F21/572
- G06F2221/2107
- G06F2221/2115
- H04L41/0803
- H04L63/0442
- H04L63/0876
- IPC, 3
- G06F21 00
- H04L12 24
- H04L29 06
- USPC, 2
- 713193000
- 380233000