Electronic module for digital television receiver
Claim Score by NHIP
Abstract
An electronic module for a digital television receiver comprises a multimedia CPU (211), a non-volatile memory block (212) connected with the multimedia CPU (211) via a memory interface (220) and storing a booter application for initializing the start-up of the digital television receiver, and a buffer (213) connected to the memory interface (220), configurable to enable or block access to the memory interface (220) for components (206, 209) external to the module. The invention provides a solution for securing the set-top box elements, including CA system elements and proprietary set-top box software, to prevent unauthorized access to them, their monitoring or replacement.

Term
Projected expiry 19 October 2027.
- Priority
- Filed
- Published
- Today
- Projected expiry
14 claims: 1 independent, 13 dependent
- 1Broadest claimClaim Score 81, broad(NHIP)An electronic module for a digital television receiver, comprising:a multimedia CPU ( 210 );a non-volatile memory block ( 211 ) connected with the multimedia CPU ( 210 ) via a memory interface ( 220 , 320 ) and storing a booter application ( 601 ) for initializing the start-up of the digital television receiver;and a buffer ( 213 , 313 ) connected to the memory interface ( 220 , 320 ), configurable to enable or block access to the memory interface ( 220 , 320 ) for components ( 206 , 209 ) external to the module.
44 paragraphs in 5 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATIONS
0001This application claims priority to the European Patent Application No. EP06465015.3, filed Oct. 19, 2006, the contents of which are incorporated herein by reference.
BACKGROUND OF THE INVENTION
00021. Field of the Invention
0003The object of the invention is an electronic module for a digital television receiver.
00042. Brief Description of the Background of the Invention Including Prior Art
0005In a design of a digital television receiver, also called a set-top box (STB), a lot of attention must be paid to security issues. The elements often subject to security risks are the conditional access (CA) system and proprietary low- and high-level software modules.
0006The CA system combines hardware elements (such as descramblers, security chips, Smart Cards) and software elements (CA kernel application, encryption algorithms) to decrypt protected content or to enable specific device functionality. The operation of the CA system usually depends on subscription fee payments, and certain users tend to “hack” the system in order to avoid these payments. Early CA systems utilized Smart Cards to store user identity and subscription information, but hacking techniques have been developed to produce falsified cards. Later, further hacking techniques have been developed to produce pirated CA software to replace the original software provided by the CA vendor. Therefore, it has become evident that in order to provide a completely safe CA system, all the elements of the system shall be secured to prevent hacking.
0007Proprietary software, such as an operating system or high-level user applications, can be also subject to pirate attacks, e.g. for the purpose of unlocking specific functionality or cloning the software at unauthorized devices. One method to protect such software is to hash or scramble the code with a signature key. The authenticity of software can be checked during start-up of the set-top box by a booter application. Therefore, it is essential to secure the booter application and signature keys against unauthorized access and modifications, as it guarantees the security of the higher-level software.
0008A conventional set-top box, as shown in <figref idref="DRAWINGS">FIG. 1</figref>, comprises a multimedia CPU <b>101</b> which controls the operation of the set-top box and performs stream-processing functions, such as decoding and descrambling. The CPU <b>101</b> receives data streams through a front-end block <b>102</b>, for example a satellite, terrestrial, cable or an IPTV front-end. The software executed by the CPU is stored in a non-volatile memory <b>109</b>, sharing a memory interface with other peripheral devices via a peripheral interface <b>106</b>, such as an Ethernet interface. Software is executed in a system RAM <b>108</b>, and the received audio/video stream is decoded in a video RAM <b>107</b>. The CA system elements may cooperate with a smart card placed in a smart card interface <b>103</b>. A mass storage device <b>105</b>, e.g. a hard disk, may be used to store additional software or audio/video streams. The CPU <b>101</b> also communicates with other elements <b>104</b>, such as a front panel interface, back end processors, etc.
0009The conventional set-top box architecture presented in <figref idref="DRAWINGS">FIG. 1</figref> has a number of security problems. For example, the CPU and individual memory chips, as well as data buses between them are easily accessible. Software stored in the memory chips, including CA system components and other proprietary software can be easily read and possibly replaced. Furthermore, transmitted data, such as CA keys or descrambled audio/video streams, can be easily read as well. Moreover, apart from re-programming, the memory chips can be replaced by other chips with pirated software. A conventional method to secure these elements is to cover the elements and data buses with a strong adhesive material, such as an epoxy, to block physical access to these elements. However, such solution introduces a substantial cost at the production stage. Further, it does not guarantee traceability of proprietary software, which can be copied and duplicated in unauthorized devices produced by unauthorized parties. Moreover, elements covered by the epoxy cannot be replaced and in order to service the set-top box, the whole printed circuit board must be changed.
0010From the European Patent Application Publication No. EP 0961193 A2 entitled “Secure computing device” is known a secure computing system, which is encrypted with a private key. A boot ROM of this system on the same integrated circuit as the data processor and inaccessible from outside includes an initialization program and a public key corresponding to the private key. On initialization the boot ROM decrypts at least a verification portion of the program, after which normal operation is enabled.
0011In turn the US Patent Application Publication No. US 2005/0078936 A1 entitled “Memory card fir digital television decoder and method of processing data using memory card and method of rental memory card” teaches a memory card for a digital television decoder, which has a memory block with a separate data memory area. Moreover, the card also comprises a conditional access circuit for descrambling of data stored in the separate data memory and a controller for controlling the data flow inside the card.
SUMMARY OF THE INVENTION
Purposes of the Invention
0012It is an object of the present invention to provide a better solution for securing the set-top box elements, including CA system elements and proprietary set-top box software, to prevent unauthorized access to them, their monitoring or replacement.
0013It is a further object of the present invention to provide a solution for secure traceability of proprietary software.
0014These and other objects and advantages of the present invention will become apparent from the detailed description, which follows.
Brief Description of the Invention
0015The present invention solves the aforementioned problems by providing an electronic module comprising a multimedia CPU, a non-volatile memory connected with the CPU via a memory interface, and a buffer or controller configurable to enable or block access to the memory interface for components external to the module. The non-volatile memory stores at least a booter application for initializing the start-up of the digital television receiver. It may further store CA system signature keys, high-level software protection keys or a loader application. Such configuration protects integrity of software stored in the non-volatile memory block, especially of the booter, the loader, the CA system kernel, signature keys and serialization data. In addition, the module provides higher level of security of data and audio/video content by comprising integrated system RAM and video RAM blocks. Further, the module may comprise a smart card chip for improved CA system security level. Moreover, the memory interface can be a bus having data, address and control lines whereas the buffer can be configurable to enable or block access to at least one line or to enable or block access to at least ⅓ of the lines. The module can be packaged in Chip on Board, Die on Board, Multi Chip Module, Multi Die Module or System in Package technology.
BRIEF DESCRIPTION OF THE DRAWINGS
0016The invention will now be described by way of example and with reference to the accompanying drawings in which:
0017<figref idref="DRAWINGS">FIG. 1</figref> shows a conventional set-top box architecture;
0018<figref idref="DRAWINGS">FIG. 2</figref> shows a set-top box architecture with an STB module according to the first embodiment of the invention;
0019<figref idref="DRAWINGS">FIG. 3</figref> shows a configuration of the buffer of the STB module;
0020<figref idref="DRAWINGS">FIG. 4</figref> shows a set-top box architecture with an STB module according to the second embodiment of the invention;
0021<figref idref="DRAWINGS">FIG. 5</figref> shows a set-top box architecture with an STB module according to the third embodiment of the invention;
0022<figref idref="DRAWINGS">FIG. 6</figref> shows a configuration of internal non-volatile memory of the STB module; and
0023<figref idref="DRAWINGS">FIG. 7</figref> shows a flow chart of start-up process of the set-top box.
DESCRIPTION OF INVENTION AND PREFERRED EMBODIMENT
0024<figref idref="DRAWINGS">FIG. 2</figref> presents a set-top box architecture with an electronic module <b>210</b>, called an STB module throughout the description, according to the first embodiment of the invention.
0025The STB module <b>210</b> is provided in a package, which contents are inaccessible in a direct way from the outside. For example, the STB module can be made in a technology such as Chip on Board (COB), Die on Board (DOB), Multi Chip Module (MCM), Multi Die Module (MDM) or System in Package (SiP). Such solution guarantees physical security of data stored and transmitted within the module, including essential CA system data and proprietary low- and high-level software.
0026In the first embodiment, the STB module <b>210</b> comprises a multimedia CPU <b>211</b>, an internal non-volatile memory <b>212</b> communicating with the CPU <b>211</b> via a memory interface <b>220</b> and a buffer or controller <b>213</b>. The buffer <b>213</b> is configurable to enable or block access to the memory interface <b>220</b> for components <b>206</b>, <b>209</b> external to the module. Therefore, the buffer enables the CPU to exchange data with components external to the STB module and blocks access to the contents of the non-volatile memory <b>212</b> block and data transmitted between the multimedia CPU <b>211</b> and the non-volatile memory block <b>212</b>. A more detailed configuration of the buffer <b>213</b> is shown in <figref idref="DRAWINGS">FIG. 3</figref>. The internal non-volatile memory <b>212</b>, e.g. a NOR Flash memory die, stores at least a booter application for secure start-up of the system, and preferably other elements, as shown in details in <figref idref="DRAWINGS">FIG. 6</figref>. By securing the booter application, all other system elements whose authenticity is checked by the booter are protected as well. The CA system elements placed in the internal non-volatile memory <b>212</b> are also secure.
0027The set-top box may be equipped with another non-volatile memory block <b>209</b>, for example a Flash NAND memory chip, external to the module <b>210</b>. The size of that memory block may be substantially greater than the size of the internal non-volatile memory block, to store high-level operating system and applications. The external non-volatile memory block <b>209</b> and the peripheral interface <b>206</b> communicate with the CPU in the STB module via the memory interface <b>220</b>. The access to the internal non-volatile memory block <b>212</b> via this interface <b>220</b> is controlled by means of the buffer <b>213</b>. Such configuration, i.e. use of the same memory interface for both the internal <b>212</b> and external <b>209</b> non-volatile memory blocks allows use of a standard processor, designed for a conventional application as shown in <figref idref="DRAWINGS">FIG. 1</figref>. This allows for using standard components inside the STB module <b>210</b>, which considerably reduces the costs and allows for an easy design of the module.
0028The other elements of the set-top box architecture, such as a front-end block <b>202</b>, an SC interface <b>203</b>, others elements <b>204</b>, a mass storage <b>205</b>, a video RAM <b>207</b> and a system RAM <b>208</b> communicate with the STB module <b>210</b> in a conventional way, as described in conjunction with <figref idref="DRAWINGS">FIG. 1</figref>.
0029<figref idref="DRAWINGS">FIG. 3</figref> presents a configuration of the buffer or controller <b>313</b> of the STB module <b>310</b>. The CPU <b>311</b> has a memory interface <b>320</b> via which both the internal non-volatile memory and external modules, such as external non-volatile memory <b>309</b> or peripheral interfaces <b>306</b>, may communicate. It is essential to block access to the contents of the non-volatile memory block <b>312</b> and data transmitted between the CPU <b>311</b> and the non-volatile memory block <b>312</b> for the external modules. This is made possible by the buffer <b>313</b>, which is configurable to enable or block access to the memory interface <b>320</b> for the external components. In the presented example, the memory interface <b>320</b> is a bus having 50 lines, being data, address and control lines. The buffer <b>313</b> may control access to all the bus lines, or, as presented in the example, only to a number of lines, for example 20 lines. Securing only a part of lines does not limit safety, as information on only part of address or only part of data word is useless for a potential hacker. Limiting the number of protected lines simplifies the design of the module, as a relatively small buffer <b>313</b> (or a small number of buffers) can be used. A secure protection can be obtained by protecting a reasonable number of lines, for example at least ⅓ of the memory bus lines. A 74LVC245 chip can be used as a buffer. The buffer <b>313</b> operation is controlled by the CPU <b>311</b> via a buffer control bus. In case the CPU <b>311</b> accesses the internal memory <b>312</b> of the module, it sets the buffer <b>313</b> to a state in which access to the memory interface from the outside is blocked. The buffer <b>313</b> is unlocked only in situation where communication with external modules is necessary.
0030<figref idref="DRAWINGS">FIG. 4</figref> presents a set-top box architecture with an STB module <b>410</b> according to the second embodiment of the invention.
0031In comparison to the embodiment shown in <figref idref="DRAWINGS">FIG. 2</figref>, the STB module <b>410</b>, besides a non-volatile memory <b>412</b> and a buffer or controller <b>413</b>, comprises an internal smart card chip <b>414</b> used by the CA system. Such configuration provides complete security of data transmitted between the CPU <b>411</b> and the smart card chip <b>414</b>, such as descrambling keys for received video and audio content. The set-top box may be equipped with a peripheral interface <b>406</b> and another non-volatile memory block <b>409</b>.
0032In addition, an external smart card interface <b>403</b> can be provided for additional applications or for additional CA system having lower security requirements.
0033The other elements of the set-top box architecture, such as a front-end block <b>402</b>, others elements <b>404</b>, a mass storage <b>405</b>, a video RAM <b>407</b> and a system RAM <b>408</b>, communicate with the STB module <b>410</b> in a conventional way, as described in conjunction with <figref idref="DRAWINGS">FIG. 1</figref>.
0034<figref idref="DRAWINGS">FIG. 5</figref> presents a set-top box architecture with an STB module <b>510</b> according to the third embodiment of the invention.
0035In comparison to the embodiment shown in <figref idref="DRAWINGS">FIG. 2</figref>, the STB module <b>510</b>, besides a non-volatile memory <b>512</b> and a buffer or controller <b>513</b>, comprises integrated Video RAM <b>515</b> and System RAM <b>514</b> chips. Integration of the Video RAM <b>515</b> enables greater level of content protection, as the descrambled content is no longer accessible outside the STB module <b>510</b>. Moreover, integration of the System RAM <b>514</b> enables greater level of CA system protection, by blocking access to CA keys and fragments of CA system software executed in the system RAM <b>514</b>.
0036The other elements of the set-top box architecture, such as a front-end block <b>502</b>, an SC interface <b>503</b>, others elements <b>504</b>, a mass storage <b>505</b>, a peripheral interface <b>506</b> and another non-volatile memory block <b>509</b>, communicate with the STB module <b>510</b> in a conventional way, as described in conjunction with <figref idref="DRAWINGS">FIG. 1</figref>.
0037Further embodiments are possible, such as integrating only Video RAM or System RAM inside the STB module. Moreover, embodiments of <figref idref="DRAWINGS">FIG. 4 and 5</figref> can be combined, to provide an STB module with integrated CPU, non-volatile memory, buffers, System RAM, Video RAM and smart card chip, thereby providing the greatest level of security.
0038<figref idref="DRAWINGS">FIG. 6</figref> presents a configuration of the non-volatile memory of the set-top box. The internal non-volatile memory comprises a booter application <b>601</b> for initializing the start-up process of the set-top box according to the procedure of <figref idref="DRAWINGS">FIG. 7</figref>. It may also comprise additional data, such as serialization data <b>602</b>, high level software signature keys <b>603</b>, CA signature keys <b>604</b> or loader data <b>605</b>. As an option, the internal memory or its fragment can be configured as an OTP (one-time-programming) block, which guarantees that its contents will not be changed.
0039Other applications can be stored in the internal or in the external non-volatile memory, depending on the system design. For example, the loader application <b>606</b>, used to update higher-level software <b>607</b>, can be stored in the internal memory together with loader data. The internal memory, if its size permits, may store CA kernel application <b>607</b> for improved CA system security.
0040Data in the external memory, such as high-level software <b>608</b>, is encrypted using high level software signature keys <b>603</b> such that it is accessible only to STB modules having specific serialization data <b>602</b>. For example, the encryption may be performed according to the X.509 standard. This enables traceability of many production parameters, such as the quantity of modules produced, their configuration, the client and software versions. It also prevents the software from unauthorized modifications, monitoring or replacement
0041<figref idref="DRAWINGS">FIG. 7</figref> presents a flow chart of start-up process of the set-top box. The procedure is initiated in step <b>701</b> at a power-up or after a hard reset of the set-top box. First, the booter application is initialized in step <b>702</b> and the booter signature is checked in step <b>703</b> to ascertain that the booter application has not been changed by unauthorized persons. If the booter signature is not correct, the procedure stops in step <b>704</b>. If the booter signature is correct, it is determined in step <b>705</b> which application should be executed next—a loader or a high level application. The loader can be executed at the first power-up of the set-top box at customer premises or if a flag has been set by the high level software. The high level application is executed if no need for software update has been signaled. The signature of the high level application is checked in step <b>706</b> and if it is correct, the high level application is executed in step <b>707</b>. If the signature is not correct, the high level code can be deleted in step <b>708</b> and the procedure continues to initiate the loader. The loader signature is checked in step <b>709</b> and if it is not correct, then the procedure stops in step <b>710</b>. If the loader signature is correct, the loader application is executed in step <b>711</b> for updating the software.
0042The preferred embodiment having been thus described, it will now be evident to those skilled in the art that further variation thereto may be contemplated. Such variations are not regarded as a departure from the invention, the true scope of the invention being set forth in the claims appended hereto.
Contents5
8 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| WO2011068392A3 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US8532290B2 | Cited by | United States of America | Search report |
| US2012226915A1 | Cited by | United States of America | Pre-grant |
| US9105316B2 | Cited by | United States of America | Applicant |
| US2011133826A1 | Cited by | United States of America | Pre-grant |
| US8583909B2 | Cited by | United States of America | Applicant |
| US2011093904A1 | Cited by | United States of America | Pre-grant |
| US2012033139A1 | Cited by | United States of America | Pre-grant |
| US9367517B2 | Cited by | United States of America | Search report |
| US2011138164A1 | Cited by | United States of America | Pre-grant |
| US8891022B2 | Cited by | United States of America | Search report |
| WO2011068392A2 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| US2002116706A1 | Cites | United States of America | Pre-grant |
| US2005078936A1 | Cites | United States of America | Pre-grant |
| US2006112266A1 | Cites | United States of America | Pre-grant |
| US2007186237A1 | Cites | United States of America | Pre-grant |
| US7284268B2 | Cites | United States of America | Pre-grant |
| US7404054B2 | Cites | United States of America | Pre-grant |
| US7526785B1 | Cites | United States of America | Pre-grant |
| US7636838B2 | Cites | United States of America | Pre-grant |
2 members in 2 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 06465015 | European Patent Office (EPO) | A | |
| 064650153 | European Patent Office (EPO) | – | |
| 064650153 | – | – | – |
| EP20060465015 | – | – | – |
Members2
| Document | Office | Kind | |
|---|---|---|---|
| EP1914990A1 | European Patent Office (EPO) | A1 | |
| US2008098418A1 | United States of America | A1 |
37 transactions on the USPTO file
Abandoned after 1 non-final rejection and 1 final rejection.
- Non-final rejections
- 1
- Final rejections
- 1
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Email NotificationEML_NTR | EML_NTR | |
| Mail Abandonment for Failure to Respond to Office ActionAbandonedMABN2 | MABN2 | |
| Aband. for Failure to Respond to O. A.AbandonedABN2 | ABN2 | |
| Email NotificationEML_NTR | EML_NTR | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTF | EML_NTF | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Email NotificationEML_NTR | EML_NTR | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| IFW TSS Processing by Tech Center CompleteTSSCOMP | TSSCOMP | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Email NotificationEML_NTR | EML_NTR | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Sent to Classification ContractorPGPC | PGPC | |
| Cleared by L&R (LARS)L128 | L128 | |
| Referred to Level 2 (LARS) by OIPE CSRL198 | L198 | |
| Information Disclosure Statement consideredIDSC | IDSC | |
| Reference capture on IDSRCAP | RCAP | |
| Electronic Information Disclosure StatementEIDS. | EIDS. | |
| Request from applicant for the USPTO to retrieve the Priority DocumentPDREQUST | PDREQUST | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Initial Exam Team nnIEXX | IEXX |
2 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Information on status: application discontinuationABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTIONSTCB | STCB | |
| AssignmentAS | AS |
Numbers
- Publication
- 20080098418
- Publication, DOCDB
- 2008098418
- Publication, EPODOC
- US2008098418
- Application
- 11874912
- Application, DOCDB
- 87491207
- Application, EPODOC
- US20070874912
Titles
- English
- ELECTRONIC MODULE FOR DIGITAL TELEVISION RECEIVER
Classification
- CPC, 8
- H04N7/16
- H04N21/4181
- H04N21/426
- H04N21/42692
- H04N21/4432
- H04N21/818
- G06F21/85
- G06F2221/2147
- IPC, 3
- H04N5 44
- G06F12 16
- H04N7 16
- USPC, 4
- 725025000
- 348E07054
- 725151000
- 725152000