External security module for a television signal decoder
Claim Score by NHIP
Abstract
A decoder for descrambling encoded satellite transmissions comprises an internal security element and a replaceable security module. The program signal is scrambled with a key and then the key itself is twice-encrypted and multiplexed with the scrambled program signal. The key is first encrypted with a first secret serial number (SSN1) which is assigned to a given replaceable security module. The key is then encrypted with a second secret serial number (SSN0) which is assigned to a given decoder. The decoder performs a first key decryption using the second secret serial number (SSN0) stored within the decoder. The partially decrypted key is then further decrypted by the replaceable security module using the first secret serial number (SSN1) stored within the replaceable security module. The decoder then descrambles the program using the twice-decrypted key. The replaceable security module can be replaced, allowing the security system to be upgraded or changed following a system breach.
Term
Term ended
Expired 11 July 2023, 3.2 years ago.
- Priority
- Filed
- Granted
- Expired
- Today
59 claims: 12 independent, 47 dependent
- 1A security system for transmission of a signal comprising:encoder means for encoding said signal, said encoder means comprising: signal scrambling means for scrambling signal and outputting a scrambled signal and a key for descrambling said scrambled signal;first key encryptor means coupled to said signal scrambling means, for performing a first encryption on said key using a first confidential serial number and outputting a once-encrypted key, and second key encryptor means coupled to said first key encryptor means, for performing a further encryption on said once once- encrypted key using a second confidential serial number and outputting a twice-encrypted key, transmission means coupled to said signal scrambling means and said second key encrypted means for transmitting said scrambled signal and said twice-encrypted key, decoder means coupled to said transmission means for receiving and descrambling said scrambled signal, said decoder means comprising: first key decryptor means coupled to said transmission means, for performing a first key decryption on said twice twice- encrypted key using said second confidential serial number and outputting a partially decrypted key, a replaceable security module, removably attached to said decoder means and containing a second key decryptor means coupled to said first key decryptor means, for performing a second key decryption on said partially decrypted key using a said first confidential serial number and outputting a decrypted key, and signal descrambling means coupled to said second key decryptor means and said transmission means for descrambling said scrambled signal using said twice-decrypted decrypted key and outputting a descrambled signal.
- 7A security system for transmission of a signal comprising:encoder means for encoding said signal, said encoder means comprising: signal scrambling means for scrambling said signal and outputting a scrambled signal and a key for descrambling said scrambled signal, first key encryptor means coupled to said signal scrambling means, for performing a first encryption on said key using a first confidential serial number and outputting a once-encrypted key, and second key encryptor means coupled to said first key encryptor means, for performing a further encryption on said once once- encrypted key using a second confidential serial number and outputting a twice-encrypted key, transmission means coupled to said signal scrambling means and said second key encryptor means for transmitting said scrambled signal and said twice-encrypted key, decoder means coupled to said transmission means for receiving and descrambling said scrambled signal, said decoder means comprising: a replaceable security module, removably attached to said decoder means and containing a first key decryptor means coupled to said transmission means, for performing a first key decryption on said twice twice- encrypted key using said second confidential serial number and outputting a partially decrypted key, a second key decryptor means coupled to said first key decryptor means, for performing a second key decryption on said partially decrypted key using a said first confidential serial number and outputting a decrypted key, and signal descrambling means coupled to said first second key decryptor means and said transmission means for descrambling said scrambled signal using said twice-decrypted decrypted key and outputting a descrambled signal.
- 16A decoder for receiving and descrambling a signal which has been scrambled using a key which has been subsequently twice-encrypted, said decoder comprising:first key decryptor means for performing a first key decryption on said twice twice- encrypted key using said a second confidential serial number and outputting a partially decrypted key, a replaceable security module, removably attached to said decoder and containing a second key decryptor means coupled to said first key decryptor means for performing a second key decryption on said partially decrypted key using a first confidential serial number and outputting a decrypted key, and signal descrambling means coupled to said second key decryptor means for descrambling said scrambled signal using said twice-decrypted decrypted key and outputting a descrambled signal.
- 19A decoder for receiving and descrambling a signal which has been scrambled using a key which has been subsequently twice-encrypted, said decoder comprising:a replaceable security module, removably attached to said decoder and containing a first key decryptor means for performing a first key decryption on said twice twice- encrypted key using said a second confidential serial number and outputting a partially decrypted key, second key decryptor means coupled to said first key decryptor means for performing a second key decryption on said partially decrypted key using a first confidential serial number and outputting a decrypted key, and signal descrambling means coupled to said second key decryptor means for descrambling said scrambled signal using said twice-decrypted decrypted key and outputting a descrambled signal.
- 28A method of transmitting a secure signal comprising the steps of:scrambling said signal using a key to produce a scrambled signal, encrypting said key using a first confidential serial number to produce a once-encrypted key. key, further encrypting said once once- encrypted key using a second confidential serial number to produce a twice-encrypted key, transmitting said scrambled signal and said twice-encrypted key, receiving said scrambled signal and said twice-encrypted key in a decoder, performing a first decryption of said twice-encrypted key using said second confidential serial number to produce a partially decrypted key, performing a second decryption on said partially decrypted key in a replaceable security module removably attached to said decoder using a said first confidential serial number to produce a decrypted key, descrambling said scrambled signal using said decrypted key to produce a descrambled signal, and outputting said descrambled signal.
- 30A method of transmitting a secure signal comprising the steps of:scrambling said signal using a key to produce a scrambled signal, encrypting said key using a first confidential serial number to produce a once-encrypted key, further encrypting said once once- encrypted key using a second confidential serial number to produce a twice-encrypted key, transmitting said scrambled signal and said twice-encrypted key, receiving said scrambled signal and said twice-encrypted key in a decoder, performing a first decryption of said twice-encrypted key in a replaceable security module removably attached to said decoder using said second confidential serial number to produce a partially decrypted key, performing a second decryption on said partially decrypted key using a said first confidential serial number to produce a decrypted key, descrambling said scrambled signal using said decrypted key to produce a descrambled signal, and outputting said descrambled signal.
- 35A method of decoding a signal comprising the steps of:receiving a scrambled signal and a twice-encrypted key in a decoder, performing a first decryption of said twice-encrypted key using a second confidential serial number to produce a partially decrypted key, performing a second decryption on said partially decrypted key in a replaceable security module removably attached to said decoder using a first confidential serial number to produce a decrypted key, descrambling said scrambled signal using said decrypted key to produce a descrambled signal, and outputting said descrambled signal.
- 36A method of decoding a signal comprising the steps of:receiving a scrambled signal and a twice-encrypted key in a decoder, performing a first decryption of said twice-encrypted key in a replaceable security module removably attached to said securing using a second confidential serial number to produce a partially decrypted key, performing a second decryption on said partially decrypted key using a first confidential serial number to produce a decrypted key, descrambling said scrambled signal using said decrypted key to produce a descrambled signal, and outputting said descrambled signal.
- 41A decoder for receiving and descrambling a signal scrambled using a twice-encrypted key, said decoder comprising:connector means for connecting said decoder to a replaceable security module, through which connector means said twice-encrypted key is transmitted to said replaceable security module and a partially-decrypted key is received from said replaceable security module, key decryptor means, coupled to said connector means for performing a decryption on said partially-decrypted key using a second confidential serial number, and outputting a decrypted key, and signal descrambling means coupled to said key decryptor for descrambling said signal with said decrypted key and outputting a descrambled signal.
- 49A decoder for receiving and descrambling a signal scrambled using a twice-encrypted key, said decoder comprising:key decryptor means, for performing a first key decryption on said twice-encrypted key using a first confidential serial number and outputting a partially decrypted key, connector means, coupled to said key decryptor means for connecting said decoder to a replaceable security module, through which connector means said partially decrypted key is transmitted to said replaceable security module and a descrambling control signal is received from said replaceable security module, signal descrambling means, coupled to said connector means and receiving said descrambling control signal for descrambling said signal and outputting a descrambled signal.
- 56Broadest claimClaim Score 75, broad(NHIP)A replaceable security module for storing confidential serial number and performing a partial decryption of a twice-encrypted key and outputting a partially decrypted key, said replaceable security module comprising; comprising:connector means for connecting said replaceable security module to a decoder and through which a said twice-encrypted key is received from said encoder decoder and a partially decrypted key is transmitted to said decoder, memory means for storing at least a said confidential serial number, and decryption means, coupled to said connector means and said memory means for performing a partial decryption on said twice-encrypted key and outputting a said partially-decrypted key.
- 58A replaceable security module for storing a secret serial number and performing a decryption of a partially decrypted key and outputting a descrambling control signal, said replaceable security module comprising; comprising:connector means for connecting said replaceable security module to a decoder and through which a said partially decrypted key is received from said encoder decoder and said descrambling control signal is transmitted to said decoder, memory means for storing at least a said secret serial number, and decryption means, coupled to said connector means and said memory means for performing a decryption on said partially decrypted key and outputting a descrambling control signal.
Independent claims12
96 paragraphs in 4 sections, as filed
BACKGROUND OF THE INVENTION
00011. Field of the Invention
0002The present invention relates generally to the field of scrambling systems and more specifically, to an external security module for a television signal decoder of a broadcast, satellite, or cable television transmission system. The present invention has particular application for B-type Multiplexed Analog Component (B-MAC) satellite transmission, but may also be used for NTSC (National Television Standards Committee), PAL, SECAM, or proposed high definition television formats. In addition, the scrambling system of the present invention can be used in applications in related fields such as electronic banking networks, telephone switching systems, cellular telephone networks, computer networks, etc. The system has particular application to so-called “conditional-access” multichannel television systems, where the viewer may have access to several “basic” channels, one or more “premium” or extra-cost channels as well as “pay-per-view” programs.
00032. Description of the Relevant Art
0004In a pay television system, a pay television service provider typically protects the signal from unauthorized subscribers and pirates through scrambling.
0005For the purposes of the following discussion and this invention, the term “subscriber” means one who is paying for the television service. The “subscriber” could thus be an individual consumer with a decoder in his own home, or could be a system operator such as a local cable TV operator, or a small network operator such as a Hotel/Motel operator with a central decoder for all televisions in the Hotel or Motel. In addition, the “subscriber” could be an industrial user, as described in U.S. Pat. No. 4,866,770 assigned to the same assignee as the present application and incorporated herein by reference.
0006For the purposes of this invention, a network is defined as a program source, (such as a pay television provider), an encoder, (sometimes called a “head end”), a transmission means (satellite, cable, radio wave, etc.) and a series of decoders used by the subscribers as described above. A system is defined as a program source, an encoder, a transmission means, and a single receiving decoder. The system model is used to describe how an individual decoder in a network interacts with the encoder.
0007The scrambling process is accomplished via a key which may itself be encrypted. Each subscriber wishing to receive the signal is provided with a decoder having an identification number which is unique to the decoder. The decoder may be individually authorized with a key to descramble the scrambled signal, provided appropriate payments are made for service. Authorization is accomplished by distributing descrambling algorithms which work in combination with the key (and other information) to paying subscribers, and by denying that information to non-subscribers and to all would-be pirates.
0008The key may be transmitted as a data signal embedded in the normal television transmission associated with the identification number of the decoder. In a typical television signal, there are so-called “vertical blanking intervals” (VBI) occurring in each field and “horizontal blanking intervals” (HBI) occurring in each line between the chrominance and luminance signals. Various other signals can be sent “in-band” in the vertical and horizontal blanking intervals including additional audio channels, data, and teletext messages. The key can be embedded in these “blanking intervals” as is well known in the art. Attention is drawn to U.S. Pat. No. 4,829,569 assigned to the same assignee as the present application and incorporated herein by reference, showing how such data can be embedded in a B-MAC signal. Alternatively, the key may be sent “out-of-band” over a separate data channel or even over a telephone line.
0009Maintaining security in a conditional-access television network depends on the following requirements:
0010(i) The signal scrambling techniques must be sufficiently complex to insure that direct encryptographic attack is not practical.
0011(ii) keys distributed to an authorized decoder cannot be read out and transferred to other decoders.
0012The first condition can be satisfied by practical scrambling algorithms now available such as the DES (Data Encryption Standard) or related algorithmns.
0013The second condition requires the physical security of certain devices within the television signal decoder and is much more difficult to satisfy. Such a device must prevent observation of both the key decryption process and the partially decrypted key signals.
0014<figref idref="DRAWINGS">FIG. 1</figref> shows a prior art conditional-access system for satellite transmission. In encoder <b>101</b>, the source program information <b>102</b> which comprises video signals, audio signals, and data is scrambled in program scrambler <b>103</b> using a key from key memory <b>104</b>. The scrambling techniques used may be any such techniques which are well known in the art. The key can be a signal or code number used in the scrambling process which is also required to “unlock” or descramble the program in program descrambler <b>108</b> in decoder <b>106</b>. In practice, one key can be used (single layer encryption) or more than one key (not shown). The key is usually changed with time (i.e. - monthly) to discourage piracy. The scrambled programs and the key are transmitted through satellite link <b>105</b>, and received by conditional-access decoder <b>106</b>. Decoder <b>106</b> recovers the key from the received signal, stores it in key memory <b>107</b> and applies it to program descrambler <b>108</b> which descrambles the scrambled program received over satellite link <b>105</b>, and outputs unscrambled program <b>109</b>. The system is not totally secure, as the key is transmitted in the clear through the channel and is available for recovery by pirates.
0015To overcome this difficulty and referring to prior art <figref idref="DRAWINGS">FIG. 2</figref>, a method of protecting the key during distribution is introduced into the system of FIG. <b>1</b>. Prior to transmission, the key used to scramble source program <b>202</b> in program scrambler <b>203</b> is recovered from key memory <b>204</b> and itself encrypted in key encryptor <b>210</b> using a secret serial number (SSN) from secret serial number database <b>211</b> which contains a list of the secret serial numbers of all legitimate subscribers. These secret serial numbers may relate to the unique identification numbers mentioned above for each decoder of a network of such decoders. The source program has now been scrambled using the key, and the key itself has been encrypted using a secret serial number. Thus, the key is not subject to compromise or recovery during transmission in comparison with the system of FIG. <b>1</b>. In order to scrambledescramble the program, the pirate must first obtain the secret serial number of a legitimate decoder, match it with the appropriately encrypted key, decrypt the key, and then descramble the program. The secret serial number is installed in decoder <b>206</b>, for example, during manufacture in SSN memory <b>212</b> resident in decoder <b>206</b>. The secret serial number is therefore unavailable to pirates provided that decoder <b>206</b> remains physically secure.
0016Each secret serial number is unique to an individual decoder or, at least, unique to a group of decoders in order to be reasonably secure. The encrypted key may therefore be transmitted to each decoder individually by cycling through a database <b>211</b>, containing all the secret serial numbers of the network in encoder <b>201</b> and forming a separate key distribution message in an addressed data packet individually addressed to each authorized decoder in the network. An individual decoder recognizes when its encrypted key has been received by reading the key distribution message attached to the encrypted key.
0017In known B-MAC systems, the key is distributed in an addressed data packet individually addressed to a particular subscriber's decoder by means of its unique identification number. The addressed data packet is typically inserted in lines <b>4</b> through <b>8</b> of the vertical blanking interval. Each addressed data packet is typically addressed to one individual decoder. As there are sixty fields generated per second (30 frames of 2 interlaced fields each) in a B-MAC or NTSC television signal, at the rate of one addressed data packet per field, a possible sixty different decoders (or groups of decoders) can be addressed each second, or 3600 per minute, 215,000 per hour, and over 5 million per day. Since each decoder need only be addressed when the service level or encryption level changes, there are sufficient frames available to individually address each decoder even in large systems. The address rate of the decoders may be increased by transmitting more than one addressed data packet per field. Additional data packets may be inserted in the vertical blanking interval or in the horizontal blanking intervals of each frame. The total number of possible addressable decoders is a function of the number on data bits available for decoder addresses. The B-MAC format typically uses 28 bits for decoder addresses, allowing for over 268 million possible decoder addresses. Attention is drawn to the United States Advanced Television Systems Committee Report T2/62, “MULTIPLEXED ANALOG COMPONENT TELEVISION BROADCAST SYSTEM PARAMETER SPECIFICATIONS”, incorporated herein by reference, which describes the data format in a B-MAC signal.
0018After receiving the addressed data packet, key decryptor <b>213</b> then decrypts the key using the secret serial number stored in SSN memory <b>212</b>. If service to any decoder <b>206</b> in the network is to be terminated, the secret serial number for that decoder is simply deleted from SSN database <b>211</b>, and decoder <b>206</b> is deauthorized at the beginning of the next key period.
0019In a decoder such as the one shown in <figref idref="DRAWINGS">FIG. 2</figref>, the pay television provider has to rely on the physical security of the decoder box itself to prevent a pirate from reading or modifying the secret serial number and key memories in the decoder or observing the key decryption process. In order to provide the necessary physical security, decoder boxes can be equipped with tamper-proof seals, specially headed screws and fasteners, or other tamper resistant packaging to make physical compromise of the decoder difficult. The subscriber is aware that tampering with the decoder could alter the tamper-proof seals or damage the decoder and subsequent examination could lead to discovery.
0020There are several disadvantages of relying on the physical security of the decoder to maintain system security. First, the pay television provider has to maintain ownership and control over all of the decoders of the network and then rent or lease the decoders to subscribers. The pay television provider is thus responsible for maintenance of all decoders and must maintain an expensive parts inventory and maintenance staff. In addition, in order to initiate service, a serviceperson must make a personal visit to the subscriber's location to install the decoder. In a pay television satellite system, such installation and service calls could be quite costly for remote installations which could be located anywhere in the world. Further, the physical security of a decoder could be breached without fear of discovery if a pirate could obtain a decoder that had been stolen either during the distribution process or from an individual subscriber's home.
0021Hence, the system of <figref idref="DRAWINGS">FIG. 2</figref> can be secure only under the following conditions:
0022(i) It must be impossible to read or modify the SSN and key memories in the decoder.
0023(ii) It must be impossible to observe the key decryption process, or the links between the four elements (<b>207</b>, <b>208</b>, <b>212</b>, and <b>213</b>) of the decoder.
0024One way to achieve both of these goals is by the use of a so-called “secure microprocessor”.
0025<figref idref="DRAWINGS">FIG. 3</figref> shows a block diagram of a typical prior art microprocessor <b>320</b> with processor <b>321</b>, program memory <b>322</b>, memory address bus <b>328</b>, memory data <b>326</b> and memory data bus <b>327</b>. In such a device, input data <b>323</b> is processed according to a program stored in program memory <b>322</b>, producing output data <b>324</b>. Program memory <b>322</b> can be “read out” through memory data bus <b>327</b>. That is, the memory can be stepped through by sequentially incrementing memory address <b>325</b> through memory address bus <b>328</b> into program memory <b>322</b>. Output memory data <b>326</b> from memory data bus <b>327</b> will reveal the entire program contents of microprocessor <b>320</b>, including any stored descrambling algorithm and secret serial number. With such data, a pirate can easily decrypt a key transmitted through satellite link <b>205</b> of FIG. <b>2</b>.
0026<figref idref="DRAWINGS">FIG. 4</figref> shows a block diagram of an ideal secure microprocessor <b>420</b> adapted for securing an algorithm and secret serial number according to one aspect of the present invention. The major difference between secure microprocessor <b>420</b> of FIG. <b>4</b> and microprocessor <b>320</b> of <figref idref="DRAWINGS">FIG. 3</figref> is that both memory address bus <b>328</b> and memory data bus <b>327</b> are absent, so there is no way to step through program memory <b>422</b> for the purpose of reading or writing. Memory references are executed only by processor <b>421</b> according to its mask-programmed code which cannot be changed. All input data <b>423</b> is treated as data for processing, and all output data <b>424</b> is the result of processing input data <b>423</b>. There is no mechanism for reading or modifying the content of program memory <b>422</b> via the data inputs.
0027Modern devices are close approximation to this ideal secure microprocessor. There is, however, one requirement which causes a variation from the ideal. Following manufacture, there must be a mechanism available to write into memory <b>422</b> the decoder specific secret serial number <b>430</b>, as well as decryption algorithm <b>434</b>. If this facility were available to a pirate, he could modify the secret serial number for the purpose of cloning. Therefore, this facility must be permanently disabled after the secret serial number has been entered.
0028A variety of techniques may be used to disable the facility for writing into the memory. Secure microprocessor <b>420</b> could be provided with on-chip fusible data links <b>431</b>, a software lock, or similar means for enabling the secret serial number <b>430</b> and descrambling algorithm <b>434</b> to be loaded into memory <b>422</b> at manufacture. Then, for example, the fusible links shown in dashed lines are destroyed so that a pirate has no access to descrambling algorithm <b>434</b> or secret serial number <b>430</b> stored in program memory <b>422</b>.
0029In an alternative embodiment, the microprocessor of <figref idref="DRAWINGS">FIG. 4</figref> can be secured with an “E<sup>2 </sup>bit,” The “E<sup>2 </sup>bit”, a form of software lock, will cause the entire memory (typically EEPROM) to be erased if an attempt is made to read out the contents of the memory. The “E<sup>2 </sup>bit” provides two advantages; first, the memory is secured from would-be pirates, and second, the memory erasure will indicate that tampering has occurred.
0030A pirate would have to have access to extensive micro-chip facilities and a significant budget to compromise such a secure microprocessor. The physical security of the processor would have to be breached, destroying the processor and contents. However, integrated circuit technology continuously improves, and unexpected developments could occur which might enable attacks to be made at the microscopic level which are more economic than those available today. Further, the worldwide market for pirate decoders for satellite transmissions would provide the economic incentive to the increasingly sophisticated pirate electronics industry to compromise such a unit.
0031Copying a single decoder comprising a microprocessor according to <figref idref="DRAWINGS">FIG. 4</figref> could lead to decoder clones based on the single secret serial number in that single decoder. Discovery would result in the termination of that secret serial number, and thus termination of all of the clones. However, a pirate would also have the option of using the single compromised unit to recover the key. The pirate could then develop a decoder design which would accept the key as a direct input. These pirate units could then be illegally distributed to subscribers, who would pay the pirate for a monthly update of the key. The consequence of a security breach could become extremely damaging to the pay television provider.
0032Pay television providers are therefore at risk if security depends exclusively on the physical defenses of the secure microprocessor. <figref idref="DRAWINGS">FIG. 5</figref> shows a device which attempts to overcome the disadvantages of the devices of <figref idref="DRAWINGS">FIGS. 1 and 2</figref> by providing a security device in a replaceable security module <b>514</b>. Replaceable security module <b>514</b> comprises key decryptor <b>513</b>, secret serial number memory <b>512</b> and key memory <b>507</b>. As in <figref idref="DRAWINGS">FIG. 2</figref>, encoder <b>501</b> scrambles source program <b>502</b> comprising video signals, audio signals and data in program scrambler <b>503</b> using a key from key memory <b>504</b>. The key is encrypted in key encryptor <b>510</b> using a secret serial number (SSN) from secret serial number database <b>511</b> which contains a list of the secret serial numbers of all legitimate subscribers.
0033The same SSN is installed in secret serial number memory <b>512</b> in replaceable security module <b>514</b> which is removably attachable to decoder <b>506</b>. Key decryptor <b>513</b> of replaceable security module <b>514</b> decrypts the key using the secret serial number stored in secret serial number memory <b>512</b>. The decrypted key is then stored in key memory <b>507</b>. Unlike <figref idref="DRAWINGS">FIG. 2</figref>, the entire replaceable security module is removably attached to decoder <b>506</b>. Program descrambler <b>508</b> reads the decrypted key from key memory <b>507</b> in replaceable security module <b>514</b> and uses the key to descramble and output descrambled program <b>509</b>. Removable security module <b>514</b> is designed to be replaced by the subscriber, preferably without any special tools and, thus, most conventionally may comprise a plug-in module.
0034The use of a plug-in module gives the pay television provider the ability to upgrade the technology in the security device by swapping it out at very low cost. In the event of a security breach, a new replaceable security module containing the program scrambling algorithm and SSN could be mailed out to authorized subscribers. The authorized subscribers could then remove the old replaceable security module from their decoder and insert the new replaceable security module themselves. System security is thus recovered without the expense of replacing the entire decoder or the expense of sending a service person to replace the replaceable security modules in each decoder. In addition, it is not necessary for the pay television provider to own the decoder itself. The decoder can be a generic commercially available unit purchased by the subscriber, or even integrated into the television itself. To initiate service, the pay television provider need only mail the replaceable security module to the subscriber and no service call is necessary.
0035Although the replaceable security module has the advantages of providing a guarantee that network security is recoverable following a breach, it also has some disadvantages. All the security resides in replaceable security module <b>514</b>, and decoder <b>506</b> itself is a generic unit. The key signal which is generated by replaceable security module <b>514</b> is observable at its transfer point to decoder <b>506</b>. The key can, however, be changed sufficiently often to ensure that it has no value to a potential pirate.
0036The problem with this approach is that a given removable security module <b>514</b> will operate with any decoder <b>506</b>, and that tampering with replaceable security module <b>514</b> does not involve damage to decoder <b>506</b>. Consequently, if replaceable security module <b>514</b> were to be compromised, piracy would become widespread very rapidly.
0037Although the devices as described above show a single key to scramble the program signal (so-called “single layer encryption”) any of the prior art devices could also be practiced using a multiple key (“two layer”, “three layer”, etc.) scrambling system. <figref idref="DRAWINGS">FIG. 6</figref> shows an example of a prior art two layer encryption encoder <b>601</b>. Encoder <b>601</b> contains secret serial number database <b>611</b> which contains a list of secret serial numbers for all authorized subscribers. Key memory <b>604</b> stores the “Key of the Month” (KOM) which in this embodiment can be either an “even” key for even months (February, April, June, etc.) or an “odd” key for odd months (January, March, May, etc.). The key could also be different for each month of the year, or could be made even more unique, depending on the available data bits for such a key. In addition, the key could be changed more frequently or less frequently than the monthly basis shown here.
0038Key encryptor <b>610</b> encrypts the key selected from key memory <b>604</b> and outputs a series of encrypted keys E<sub>SSN</sub>[KOM] each encrypted with a secret serial number from secret serial number database <b>611</b>, to data multiplexor <b>635</b>. Seed memory <b>636</b> contains a “seed” which is used for scrambling the audio and video signals. The “seed” can also be a data code or a signal similar to the key described above. Seed encryptor <b>637</b> encrypts the seed with the key of the month and outputs the encrypted seed E<sub>KOM</sub>[SEED] to data multiplexor <b>635</b>. Thus the key has been encrypted with the secret serial number, and the seed encrypted with the key. Neither the key nor the seed can be easily recovered during transmission.
0039In this embodiment, source program <b>602</b> comprises a Multiplexed Analog Video (MAC) signal <b>639</b> with the typical chrominance and luminance signals described previously, along with multiplexed audio data <b>638</b> which may comprise several different audio and non-audio (data) signals. For example, there may be at least two channels of audio (stereo) and additional channels of teletext for the hearing impaired. In addition, there may be additional channels of audio related to the video signal such as foreign language translations, unrelated audio signals such as radio programs or data signals such as subscriber messages, computer data, etc. All of these signals are digitized and multiplexed together, as is well known in the art, and the resulting multiplexed audio data <b>638</b> is then ready to be scrambled.
0040The seed passes through pseudo-random bit sequencer (PRBS) <b>643</b> and then is added to multiplexed audio data <b>638</b> in adder <b>644</b>. Together, pseudo-random bit sequencer (PRBS) <b>643</b> and adder <b>644</b> comprise a bit-by-bit encryptor <b>645</b> as is well known in the art. The resulting scrambled multiplexed audio data is then passed to data multiplexor <b>635</b> and is multiplexed with the encrypted seed and key.
0041MAC video signal <b>639</b> is scrambled in line translation scrambler <b>603</b> which scrambles the lines of the MAC signal using the “seed” from seed memory <b>636</b> for the scrambling algorithm. The resulting scrambled MAC signal is then sent to multiplexor <b>632</b> which multiplexes the scrambled MAC signal with the output from data multiplexor <b>635</b>. The multiplexed data output of data multiplexer <b>635</b> is modulated into pulse amplitude modulation (PAM) format by P.A.M. modulator <b>645</b>. The output B-MAC signal <b>646</b> contains MAC video signal <b>639</b> and multiplexed PAM audio data <b>638</b>, both scrambled with the seed, along with the seed encrypted with the key of the month, and a series of keys of the month which have been encrypted with the secret serial numbers of the subscriber's decoders, all multiplexed together.
0042In order to descramble the B-MAC signal <b>646</b>, a pirate must be able to decrypt one of the encrypted keys, and use that key to decrypt the seed. However, as in the single layer encryption device described in <figref idref="DRAWINGS">FIG. 2</figref>, the pirate only needs to comprisecompromise one of the transmission means coupled to said signal scrambling means and said second key encryptor means for transmitting said scrambled signal and said twice-encrypted key, decoders in order to obtain a secret serial number, and thus decrypt the key. With the key, a pirate can then decrypt the seed, and with the seed, descramble the program signal. Additional “layers” of encryption (i.e. more seeds and keys) make pirating more cumbersome, as the pirate must decrypt more seeds and keys, however, once the first key has been decrypted, the subsequent keys and seeds can be decrypted as well. In the embodiment shown in <figref idref="DRAWINGS">FIG. 6</figref>, keys need be decrypted every other month (even months and odd months) for the pirate to be able to descramble the program signal all year. The secret serial numbers, seed, and key, as used in <figref idref="DRAWINGS">FIG. 6</figref>, can be used effectively by the pay television provider to terminate a particular decoder by secret serial number and generally discourage piracy by amateurs. However, while this system has not yet been compromised, a determined pirate may compromise such a multi-layered encryption system with the aid of a compromised decoder, the heart of such piracy being the gaining of access to a secret serial number.
0043In view of the deficiencies of the above prior art devices, it still remains a requirement in the art to provide a scrambling system for pay television systems which does not rely solely on the physical security of the decoder components to maintain system integrity.
SUMMARY OF THE INVENTION
0044Therefore, it is an object of the present invention to provide a system of double-encrypting the key using two different secret serial numbers respectively assigned to a subscriber's decoder and removable security module.
0045It is a further object of the present invention to provide a replaceable security module for a television signal decoder where the replaceable security module will work with only one decoder and cannot be used with another decoder.
0046It is a further object of the present invention to provide a decoder with a data interface for a removable security module.
0047Many of the above-stated problems and related problems of the prior art encryption devices have been solved by the principles of the present invention which twice-encrypts the key prior to transmission, first with a first secret serial number (SSN<sub>1</sub>)(SSN<sub>0</sub><i>) </i>of the subscriber's replaceable security moduledecoder, and again with a second secret serial number (SSN<sub>0</sub>)(SSN<sub>1</sub><i>) </i>of the subscriber's decoderreplaceable security module. The double-encryption technique discourages copying the replaceable security module, as each replaceable security module will work only with its mating decoder. The system also allows the replaceable security module to be replaced following a system breach, thus allowing for recovery of system security.
0048The system comprises an encoder for encoding a signal, for encoder further comprising a signal scrambler and a first and second key encrypters. The signal scrambler scrambles the signal and outputs a scrambled signal and a key for descrambling the scrambled signal. The first key encryptor is coupled to the signal scrambler and performs a first encryption on the key using a first secret serial number and outputs a once-encrypted key. The second key encryptor is coupled to the first key encryptor and performs a further encryption on the once-encrypted key using a second secret serial number and outputs a twice-encrypted key.
0049The system further comprises a transmitter coupled to the signal scrambler and the second key encryptor for transmitting the scrambled signal and twice-encrypted key.
0050The system further comprises a decoder coupled to the transmitter for receiving and descrambling the scrambled signal. The decoder comprises first and second key decryptors and a descrambler. The first key decryptor is coupled to the transmitter and performs a first key decryption on the twice-encrypted key using the second secret serial number and outputs a partially decrypted key. The second key decryptor is coupled to the first key decryptor and perform a second key decryption on the partially decrypted key using the first secret serial number and outputs the decrypted key. The descrambler is coupled to the second key decryptor and the transmitter and descrambles the scrambled signal using the decrypted key and outputs the descrambled signal.
0051In an alternative embodiment of the present invention, the decoder may function without the use of a replaceable security module. In the event of a system breach or a service level change, a replaceable security module may then be inserted into the decoder to “upgrade” the decoder.
0052These and other objects and advantages of the invention, as well as the details of an illustrative embodiment, will be more fully understood from the following specification and drawings in which similar elements in different figures are assigned the same last two digits to their reference numeral (i.e., encoder <b>701</b> of FIG. <b>7</b> and encoder <b>801</b> of FIG. <b>8</b>).
BRIEF DESCRIPTION OF THE DRAWINGS
0053<figref idref="DRAWINGS">FIG. 1</figref> shows an example of a prior art conditional-access system for satellite transmission with a key signal sent in the clear to the decoder.
0054<figref idref="DRAWINGS">FIG. 2</figref> shows an example of a prior art conditional-access system for satellite transmission using a single key encryption technique.
0055<figref idref="DRAWINGS">FIG. 3</figref> shows an example of a prior art microprocessor without a secure memory.
0056<figref idref="DRAWINGS">FIG. 4</figref> shows a secure microprocessor with a secure memory and fusible data links adapted for storing an algorithm and secret serial number according to the present invention.
0057<figref idref="DRAWINGS">FIG. 5</figref> shows an example of a conditional-access system for satellite transmission with a replaceable security module containing a first secret serial number.
0058<figref idref="DRAWINGS">FIG. 6</figref> shows another prior art conditional-access system for satellite transmission using an additional layer of encryption.
0059<figref idref="DRAWINGS">FIG. 7</figref> shows one exemplary embodiment of the conditional-access system of the present invention with an encoder encrypting the key with both a first and second secret serial number, a satellite transmission system, and a decoder containing a first secret serial number and a replaceable security module containing a second secret serial number.
0060<figref idref="DRAWINGS">FIG. 8</figref> shown another embodiment of the encryption system of the present invention including a multiplexor and demultiplexor for multiplexing the twice encrypted key with the scrambled program signal prior to transmission, and demultiplexing the twice encrypted key from the scrambled program signal after reception.
0061<figref idref="DRAWINGS">FIG. 9</figref> shows an alternative embodiment of the device of <figref idref="DRAWINGS">FIG. 7</figref> incorporating a telephone controller for bi-directional telephone control for pay-per-view access or key transmission.
0062<figref idref="DRAWINGS">FIG. 10</figref> shows a block diagram of an alternative embodiment of the device of <figref idref="DRAWINGS">FIG. 9</figref>, showing in detail how signals are passed between the decoder and the replaceable security module.
0063<figref idref="DRAWINGS">FIG. 11</figref> shows another embodiment of the device of <figref idref="DRAWINGS">FIG. 10</figref> with the telephone controller, but without a replaceable security module.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENT
0064<figref idref="DRAWINGS">FIG. 7</figref> shows the encryption system of the present invention comprising an encoder <b>701</b> for encoding a source program <b>702</b> for transmission over a satellite link <b>705</b> to a decoder <b>706</b>. According to <figref idref="DRAWINGS">FIG. 7</figref>, the key is encrypted and addressed to individual decoders, similar to the device in FIG. <b>5</b>. However, in this case, the key is encrypted not once, but twice and must also be decrypted twice in the decoder. The first decryption takes place in a replaceable security module <b>714</b> which is mounted on the exterior of the decoder <b>706</b>, for example, as a plug-in module. The second decryption takes place in a fixed security element <b>719</b> which is an integral part of the decoder <b>706</b>. Both decryptions must take place properly for the decoder to receive the key.
0065The encoder <b>701</b> has a key memory <b>704</b> containing the key used to scramble program <b>702</b> in program scrambler <b>703</b>. The key is first encrypted in first key encryptor <b>710</b> with a first secret serial number (SSN<sub>0</sub>) stored in SSN<sub>0 </sub>database <b>711</b>. The key is further encrypted in second key encryptor <b>715</b> with a second secret serial number (SSN<sub>1</sub>) from SSN<sub>1 </sub>database <b>716</b>. This produces a series of twice-encrypted keys which are then transmitted along with the scrambled program via satellite link <b>705</b>. The decoder <b>706</b> receives the encryptedscrambled program and one of the twice-encrypted keys and performs a first key decryption in replaceable security module <b>714</b>. The replaceable security module <b>714</b> contains a second secret serial number (SSN<sub>1</sub>), which could be assigned to a particular security module or series of modules, in SSN<sub>1 </sub>memory <b>717</b>. The replaceable security module <b>714</b> performs a first key decryption in first key decryptor <b>718</b> and outputs a partially decrypted key. The partially decrypted key, still unreadable to a pirate, is sent to second key decryptor <b>713</b> located in decoder <b>706</b> itself. There, the key is fully decrypted using the first secret serial number stored in SSN<sub>0 </sub>memory <b>712</b>. The fully decrypted key is now stored in key memory <b>707</b> and used to descramble the scrambled program received from satellite link <b>705</b> in program descrambler <b>708</b> and output descrambled program <b>709</b>.
0066Both replaceable security module <b>714</b> and an internal security element <b>719</b> of decoder <b>706</b> may be constructed according to the principles of FIG. <b>4</b>. For example, the second secret serial number SSN<sub>1 </sub>may be loaded into SSN<sub>1 </sub>memory <b>717</b> of Module <b>714</b> and fusible links used for loading the memory destroyed during manufacture. Similarly, SSN<sub>0 </sub>memory <b>712</b> of internal security element <b>719</b> may be loaded during manufacture over a fusible link and the link destroyed. Also over a fusible link, algorithms may be loaded into key decryptors <b>718</b>, <b>713</b> during manufacture and the fusible links subsequently destroyed.
0067The effect of twice-encrypting the key is to ensure that replaceable security module <b>714</b> must correspond to a particular decoder <b>706</b> and will not operate with any other decoder. Loss of replaceable security module <b>714</b> during distribution no longer presents a potential security breach. To compromise the system, it is now necessary to break the physical security of both replaceable security module <b>714</b> and internal security element <b>719</b>. In order to fully compromise the system, the internal security element <b>719</b> must be attacked, restoring the risk to the subscriber that his decoder will be damaged.
0068At the same time, the replaceable security module provides the pay television provider with the option of replacing system security by mailing out new replaceable security modules to all authorized subscribers. Returned replaceable security modules <b>714</b> could be re-used for a different subscriber decoder by reprogramming the SSN<sub>0 </sub>and SSN<sub>1 </sub>databases <b>711</b> and <b>716</b> to correspond to the combination of the first secret serial number of decoder <b>706</b> with the second secret serial number of security module <b>714</b>. Alternatively, the returned replaceable security modules <b>714</b> could be destroyed, and a new replaceable security module <b>714</b> sent out, incorporating changes and improvements in the security technology to thwart potential pirates. In the event of a security breach, it is only necessary to replace the replaceable security module and not the complete decoder in order to restore system security.
0069Alternatively, the decoder <b>706</b> may function optionally without the use of the replaceable security module <b>717</b>. In such a system, encoder <b>701</b> may be programmed to perform single level key encryption by encrypting the key from key memory <b>704</b> once in second key encryptor <b>715</b>, bypassing first key encryptor <b>710</b>. Decoder <b>706</b> would sense the absence of removable security module <b>717</b> and perform only a single key decryption in second key decryptor <b>713</b>.
0070If a system breach occurs, the pay television provider then mails out replaceable security modules to subscribers, uses the double encryption technique, and thus recovers system security. The optional usage of the replaceable security module has other attractive benefits as well. Subscribers who do not pay for any premium channels may not be sent a replaceable security module, as the “basic” channels may only use a once-encrypted key or may even be sent in the clear. If the subscriber wishes to upgrade to a premium channel of channels, the pay television provider may then mail that subscriber the appropriate replaceable security module.
0071In addition, the replaceable security module may be used to add other additional features. Many cable television systems offer optional services such as IPPV (Impulse-Pay-Per-View) which require two-way communication between the decoder <b>706</b> and the head end. In the past, if a subscriber wished to upgrade to IPPV service, a subscriber's decoder would have to be altered by inserting a IPPV module internally or by adding an IPPV “side car” externally. Alternatively, the entire decoder would have to be replaced. All three options would necessitate a service call, causing inconvenience to the subscriber, and expense to the pay television provider. Similarly, when a pay television provider wishes to upgrade its entire encoder/decoder system, it must provide a new decoder to each subscriber which will work in the interim with both the old and new encoding techniques, as it is nearly impossible to replace all subscriber decoders simultaneously. Then a decoder manufacturer is faced with the added expense of providing his state-of-the-art decoder with extra circuitry in order to function with the pay television provider's old encoder for the few months during the change over period.
0072In both the above instances, the replaceable security module <b>714</b> may be used to upgrade the decoder <b>706</b> without the expense and inconvenience of a service call. The replaceable security module <b>714</b> may be mailed to the subscriber and the subscriber can then insert the replaceable security module <b>714</b> and instantly upgrade the decoder and add additional features (such as IPPV), alter the encoding technique, or providing an external level of security.
0073The replaceable security module <b>714</b> may take one of several forms. In the preferred embodiment, the module may comprise a “smart card”, a plastic “credit card” with a built-in micro-processor, such as described by the International Standards Organization in standard ISO 7816/1 and ISO7816/2. Attention is drawn on U.S. Pat. No. 4,841,133 issued Jun. 20, 1989 and incorporated herein by reference, describing such a “smart card.” The “smart card” may be equipped with a series of electrical contacts which connect to contacts in the decoder <b>706</b>. The contacts may provide power to the card, along with clock signals and data transmission.
0074<figref idref="DRAWINGS">FIG. 8</figref> shows another embodiment of the present invention wherein the key is twice encrypted and addressed to individual decoders, similar to the device in FIG. <b>7</b>. The encoder <b>801</b> has a key memory <b>804</b> containing the key used to scramble program <b>802</b> in program scrambler <b>803</b>. The key is first encrypted in first key encryptor <b>810</b> with the first secret serial number (SSN<sub>0</sub>) stored in SSN<sub>0 </sub>database <b>811</b>. The key is further encrypted in second key encryptor <b>815</b> with a second secret serial number (SSN<sub>1</sub>) from SSN<sub>1 </sub>database <b>816</b>, producing a series of twice-encrypted keys as in FIG. <b>7</b>. However, in this embodiment, the twice encrypted keys are then multiplexed into the scrambled program in multiplexor <b>832</b> and transmitted via satellite link <b>805</b>.
0075The decoder <b>806</b> receives the encrypted program and demultiplexes the twice encrypted keys from the scrambled program signal in demultiplexor <b>833</b>. The decoder <b>806</b> then chooses the proper twice encrypted key based on the key message associated with the proper key for that decoder, and performs a first key decryption in replaceable security module <b>814</b>. The partially decrypted key is then sent to second key decryptor <b>813</b> located in the decoder <b>806</b> itself. There, the key is fully decrypted using the unique first secret serial number stored in SSN<sub>0 </sub>memory <b>812</b>. The fully decrypted key is now stored in key memory <b>807</b> and used to decrypt the program in the program descrambler <b>808</b> and output the decrypted program <b>809</b>. The second key decryptor <b>813</b>, key memory <b>807</b>, and SSN<sub>0 </sub>memory <b>812</b> together comprise fixed internal security element <b>819</b>.
0076<figref idref="DRAWINGS">FIG. 9</figref> shows an alternate embodiment of the present invention with a telephone controller. Decoder <b>906</b> is similar to the decoder <b>706</b> of <figref idref="DRAWINGS">FIG. 7</figref>, except that decoder <b>906</b> of <figref idref="DRAWINGS">FIG. 9</figref> also includes a telephone controller <b>940</b> for receiving or sending an encrypted key or other data. Telephone controller <b>940</b> adds an additional level of security to the system, as the key does not have to be transmitted with the program signal over a separate channel as in <figref idref="DRAWINGS">FIG. 7</figref> or multiplexed into the signal as in FIG. <b>8</b>. In addition, the telephone controller <b>940</b> can provide two-way communication with the program source for such features as pay-per-view (PPV) or impulse pay-per-view (IPPV) programming.
0077Pay-per-view programming is defined here as any programming where the subscriber can request authorization to watch a particular program. In many pay television systems, pay-per-view programming is used for sporting events (boxing, wrestling, etc.) which are not transmitted on a regular basis. A subscriber wishing to view the event must receive authorization in the form of a special descrambler mechanism, or in the form of a special code transmitted or input to the subscriber's decoder. Some pay-per-view television systems allow the subscriber to request a pay-per-view program (i.e. - movies) to watch. The pay television provider then transmits the requested program and authorizes that subscriber's decoder to receive the signal.
0078Impulse pay-per-view (IPPV) programming is defined here as any programming where the subscriber has a pre-authorized number of “credits” saved in his individual decoder. If a subscriber wishes to view a particular program, the subscriber merely actuates the decoder, the appropriate number of credits are subtracted from the subscriber's remaining credits, and the subscriber is immediately able to view the program.
0079In a pay-per-view embodiment of the present invention, the decoder may send a signal to the head end via the telephone controller <b>940</b> with a request for authorization to decode a pay-per-view program. Alternately, the decoder <b>906</b> may store authorization information (i.e. -credits) for pay-per-view programming, and forward actual pay-per-view data via the telephone controller <b>940</b> at a later time.
0080The telephone controller <b>940</b> could be a computer modem type device, or could work using touch-tone signals to communicate with the head end. Preferably, the telephone controller is a modem type device, communicating with the head end using a TSK protocol. Attention is drawn to copending application Ser. No. 187,978 filed Apr. 29, 1989 describing TSK operation and incorporated herein by reference. The pay television provider can thus send appropriate authorization information (TEL) to the subscriber, encrypted with the subscriber's secret telephone number (STN). The secret telephone number is not a telephone number in the ordinary sense, but rather another type of secret serial number, which could be assigned to a given telephone controller <b>940</b> or series of telephone controllers. Once received by the decoder <b>906</b>, the authorization information may be used to enable descrambling of a particular pay-per-view program or programs.
0081In another embodiment, which could be used in conjunction with the pay-per-view embodiment described above, the telephone controller can be used to receive the key encrypted with the secret telephone number. The scrambled program signal <b>941</b> is input to the decoder <b>906</b> which provides the input signal <b>941</b> to a clock/data recovery unit <b>942</b> and the video/audio descrambler <b>908</b>. The clock/data recovery unit <b>942</b> provides sync and data for the program signal fed to the fixed security element <b>919</b>. Fixed security element <b>919</b> contains a key decryptor, key memory and SSN<sub>0 </sub>memory. The telephone controller <b>940</b> receives the key, encrypted with the secret telephone number of the decoder (STN) stored in the replaceable security module <b>914</b>. The telephone controller <b>940</b> typically commences communication and can be programmed to call the head end at a predetermined time or at a predetermined time interval, or upon receiving a signal from the head end preferably when phone usage is at a minimum (i.e. - early morning hours). The telephone controller can call the head end via a toll free 1-800 number, a so-called “watts” line, or via a local call to a commercial data link such as TYMNET of TELENET. Once the call is connected and communications established, the decoder <b>906</b> uploads to the head end a record of pay-per-view usage encrypted with the secret telephone STN<sub>1</sub>. The head end may then download data similarly encrypted to the decoder <b>906</b> including new keys, secret serial numbers, or decryption algorithms. The encrypted key may be sent to the fixed security element <b>919</b>, which has removably attached thereto the replaceable security module <b>914</b>. The key is then decrypted in the replaceable security module using the secret telephone number, and decoder control information is sent to the program descrambler <b>908</b> to produce the descrambled program <b>909</b>.
0082As discussed above, a new secret serial number or decryption algorithm, encrypted with the secret telephone number, may be sent from the head end to a decoder through telephone controller <b>940</b>. The encrypted secret serial number of decryption algorithm is then decrypted and stored in the replaceable security module. The downloading of decryption algorithms and secret serial numbers via the telephone controller <b>940</b> is sometimes called an “E<sup>2 </sup>patch”, and allows the pay television provider to maintain or recover system security by loading new information into a decoder's EEPROM. An E<sup>2 </sup>patch does not necessarily entail changing the entire decryption algorithm in the decoder <b>906</b>. The secret serial number or merely a portion of the decryption algorithm, such as a particular byte or data table need only be changed in order to sufficiently alter the decryption algorithm. The E<sup>2 </sup>patch allows the pay television provider or upgrade the encryption system to fix “bugs” and recover system security.
0083After receiving a signal through the telephone controller <b>940</b>, the head end will send an acknowledment signal to the decoder, indicating that information has been received. Similarly, after data has been downloaded from the head end to the decoder through the telephone controller, the decoder will return an acknowledgement signal to the head end that data has been received.
0084In addition to pay-per-view requests or records, telephone controller <b>940</b> can also be used to upload other signals from the decoder. For example, tamper protection information such as described in connection with <figref idref="DRAWINGS">FIG. 4</figref> can be sent indicating whether or not the decoder has been tampered with. Further, program viewing information can be uploaded to the pay television provider for television rating purposes (i.e., - Nielson ratings)
0085In general, any data that can be delivered via the B-MAC input <b>941</b> of <figref idref="DRAWINGS">FIG. 9</figref> (or NTSC, PAL, SECAM, etc.) can also be downloaded through the telephone controller <b>940</b>. Such information includes, but is not limited to, blackout codes, tiering information, personal messages number of available credits, group identification numbers, and other system data. Generally, the telephone controller <b>940</b> is used for infrequent communications, such as periodic security level changes and IPPV requests, due to the limited bandwidth of telephone lines and the increased cost of sending information via telephone versus the B-MAC input.
0086The telephone information (TEL) encrypted with the secret telephone number (STN) remains encrypted throughout the decoder <b>906</b> and may only be decrypted in the replaceable security module <b>914</b>. The decrypted telephone information does not pass out of the replaceable security module <b>914</b>, in order to prevent observation by a pirate. In order for the decoder <b>906</b> to descramble a scrambled program, both the telephone information and the addressed data packet received through the B-MAC input <b>941</b> must be present. By relying on both information sources, piracy is virtually impossible, as the potential pirate must break into the pay television provider's telephone system as well as decrypt the twice-encrypted key.
0087<figref idref="DRAWINGS">FIG. 10</figref> shows a more detailed diagram of the device of <figref idref="DRAWINGS">FIG. 9</figref>, showing how the various signals are sent between the fixed security element <b>1019</b> and the replaceable security module <b>1014</b>. In this embodiment, both the fixed and replaceable security modules <b>1019</b> and <b>1014</b> are built around secure microprocessors <b>1050</b> and <b>1051</b> similar to that shown in FIG. <b>4</b>. In <figref idref="DRAWINGS">FIG. 10</figref>, the subscript “0” is used to denote signals and keys stored or decrypted in the fixed security element <b>1019</b>, while the subscript “1” denotes signals and keys stored or decrypted in the replaceable security module <b>1014</b>.
0088Fixed security element <b>1019</b> comprises a secure microprocessor <b>1050</b> which receives signals <b>1053</b>, <b>1054</b>, and <b>1055</b> as inputs. Signal <b>1053</b> is the program (SYS) which has been scrambled with a key-of-the-month (KOM) and is represented by the symbol E<sub>KOM1</sub>(SYS). Signal <b>1054</b> is the key-of-the-month (KOM) which has been twice-encrypted with the two secret serial numbers (SSN<sub>0 </sub>and SSN<sub>1</sub>) of the fixed and replaceable security modules <b>1019</b> and <b>1014</b>, respectively and is represented by the symbol E<sub>SSN0</sub>(E<sub>SSN1</sub>(KOM<b>1</b>)).
0089Signal <b>1055</b> is an additional signal, E<sub>STN1</sub>(TEL), which is the telephone data encrypted with a secret telephone number (STN) described in <figref idref="DRAWINGS">FIG. 9</figref> above. The telephone data can be used to provide an additional level of security, as well as to allow the subscriber to request “pay-per-view” programs via the phone line as described in <figref idref="DRAWINGS">FIG. 9</figref> above.
0090Secure microprocessor <b>1050</b> performs a first decryption of twice-encrypted key <b>1054</b> using the first secret serial number SSN<sub>0 </sub>stored within secure microprocessor <b>1050</b>. Secure microprocessor <b>1050</b> passes partially decrypted key-of-the-month E<sub>SSN1</sub>(KOM) <b>1061</b> to replaceable security module <b>1014</b> along with scrambled program E<sub>KOM1</sub>(SYS) <b>1062</b> and encrypted telephone data E<sub>STN1</sub>(TEL) <b>1060</b>.
0091Replaceable security module <b>1014</b> comprises secure microprocessor <b>1051</b> which has secure memory <b>1052</b> where the second secret serial number SSN<sub>1 </sub>is stored along with the secret telephone number STN<sub>1</sub>, the encryption algorithm E, and other authorization information. Secure microprocessor <b>1051</b> performs a further decryption on partially decrypted key-of-the-month E<sub>SSN1</sub>(KOM) <b>1061</b> received from fixed security element <b>1019</b>, using the second secret serial number SSN<sub>1 </sub>and encryption algorithm E stored within secure memory <b>1052</b>. The decrypted key-of-the-month (KOM<b>1</b>) is stored in the secure memory <b>1052</b> of secure microprocessor <b>1051</b>. As discussed in <figref idref="DRAWINGS">FIG. 4</figref>, secure memory <b>1052</b> cannot be directly addressed or read out, and as such the second secret serial number SSN<sub>1 </sub>and the encryption algorithm E cannot be observed by a potential pirate.
0092Secure microprocessor <b>1051</b> also decrypts the telephone data (TEL) using the secret telephone number STN<sub>1 </sub>stored within the secure memory <b>1052</b> of the secure microprocessor <b>1051</b>. If the key-of-the-month (KOM<b>1</b>) can be decrypted, and authorization is present (for pay-per-view), or unnecessary (for other channels), then scrambled program E<sub>KOM1</sub>(SYS) <b>1062</b> can be descrambled in replaceable security module <b>1014</b>, producing decoder control information DCI<sub>1 </sub><b>1058</b>. Decoder control information DCI<sub>1 </sub><b>1058</b> typically contains the line translation scrambling information for the video signal, and decryption information for the multiplexed audio data along with other information such as whether teletext is enabled and which audio channel is to be selected. The program control information DCI<sub>1 </sub><b>1058</b> and the encrypted telephone data E<sub>STN1</sub>(TEL) are sent to the fixed security element <b>1019</b>. If authorization is present (for IPPV) or unnecessary (for other channels), the secure microprocessor <b>1050</b> outputs the program control data <b>1058</b> to the rest of the decoder (not shown) for program descrambling. On-screen display support information (OSD) <b>1057</b> is decoded from the encrypted program signal EKOM<sub>1</sub>(SYS)E<sub>KOM1</sub><i>(SYS) </i>and provides information how on-screen display is controlled by fixed security element <b>1019</b> to display personal messages, control a barker channel, indicate the number of remaining credits, indicate authorized channels as well as other ways of controlling displayed information.
0093<figref idref="DRAWINGS">FIG. 11</figref> shows a further embodiment of the present invention, without replaceable security module. In this embodiment, the subscript “0” has been used to denote that all decryptions take place within secure microprocessor <b>1150</b>. Decoder <b>1106</b> comprises secure microprocessor <b>1150</b> with secure memory <b>1152</b>. Secure memory <b>1152</b> contains a secret serial number SSN<sub>0 </sub>and a secret telephone number STN<sub>0 </sub>unique to that decoder or a series of decoders loaded during manufacture and secured with an “E<sup>2 </sup>bit” as discussed in connection with FIG. <b>4</b>. Scrambled program E<sub>KOM0</sub>(SYS) <b>1153</b> and once-encrypted key-of-the-month E<sub>SSN0</sub>(KOM<b>0</b>) <b>1154</b> are input to decoder <b>1106</b> along with encrypted telephone data E<sub>STN0</sub>(TEL) <b>1155</b>.
0094Secure microprocessor <b>1150</b> decrypts encrypted telephone data E<sub>STN0</sub>(TEL) <b>1155</b> using the secret telephone number STN<sub>0 </sub>stored in secure memory <b>1152</b>. The decrypted telephone data (TEL) is also stored in secure memory <b>1152</b> to prevent observation by pirates. The telephone data (TEL) may provide authorization information to decode <b>1106</b> as to whether decoder <b>1106</b> is presently authorized to decrypt some or all of the received scrambled programs. In addition, other information may be transferred between the decoder and the head end as discussed in connection with FIG. <b>9</b>.
0095If authorization is present, secure microprocessor <b>1150</b> uses the first secret serial number SSN<sub>0 </sub>stored in secure memory <b>1152</b> to decrypt the key KOM<sub>0</sub>. As in <figref idref="DRAWINGS">FIG. 10</figref>, the secure microprocessor <b>1150</b> then outputs program control information DCI<sub>0 </sub><b>1156</b> to the remainder of decoder <b>1106</b> in order to descramble the program signal.
0096While the present invention has been disclosed with respect to a preferred embodiment and modifications thereto, further modifications will be apparent to those of ordinary skill in the art within the scope of the claims that follow. It is not intended that the invention be limited by the disclosure, but instead that its scope be determined entirely by reference to the claims which follow herein below.
Contents4
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US2004153657A1 | Cited by | United States of America | Pre-grant |
| US2009138728A1 | Cited by | United States of America | Pre-grant |
| US2004076297A1 | Cited by | United States of America | Pre-grant |
| US7849331B2 | Cited by | United States of America | Applicant |
| US8819434B2 | Cited by | United States of America | Applicant |
| US2013298255A1 | Cited by | United States of America | Pre-grant |
| US7832016B2 | Cited by | United States of America | Search report |
| US7539312B2 | Cited by | United States of America | Applicant |
| US7233670B2 | Cited by | United States of America | Search report |
| US7546468B2 | Cited by | United States of America | Applicant |
| US2006280307A1 | Cited by | United States of America | Pre-grant |
| US8782417B2 | Cited by | United States of America | Applicant |
| US10097347B2 | Cited by | United States of America | Search report |
| US2007217614A1 | Cited by | United States of America | Pre-grant |
| US2007283162A1 | Cited by | United States of America | Pre-grant |
| US7617536B2 | Cited by | United States of America | Search report |
| US2004260938A1 | Cited by | United States of America | Pre-grant |
| US8549655B2 | Cited by | United States of America | Applicant |
| US9268949B2 | Cited by | United States of America | Search report |
| US2004105548A1 | Cited by | United States of America | Pre-grant |
| US2017048062A1 | Cited by | United States of America | Search report |
| US9215505B2 | Cited by | United States of America | Applicant |
| US7685435B2 | Cited by | United States of America | Search report |
| US8286889B2 | Cited by | United States of America | Search report |
| US2009037721A1 | Cited by | United States of America | Pre-grant |
| US8190912B2 | Cited by | United States of America | Applicant |
| US2007198413A1 | Cited by | United States of America | Pre-grant |
| EP0132401A2 | Cites | European Patent Office (EPO) | Applicant |
| EP0308219A2 | Cites | European Patent Office (EPO) | Applicant |
| EP0308219A2 | Cites | European Patent Office (EPO) | Search report |
| GB2151886A | Cites | United Kingdom | Applicant |
| US2656408A | Cites | United States of America | Applicant |
| US4281216A | Cites | United States of America | Search report |
| US4317957A | Cites | United States of America | Search report |
| US4337483A | Cites | United States of America | Search report |
| US4377483A | Cites | United States of America | Applicant |
| US4386233A | Cites | United States of America | Search report |
| US4386266A | Cites | United States of America | Search report |
| US4388643A | Cites | United States of America | Search report |
| US4399323A | Cites | United States of America | Search report |
| US4484025A | Cites | United States of America | Search report |
| US4484027A | Cites | United States of America | Search report |
| US4530008A | Cites | United States of America | Search report |
| US4531020A | Cites | United States of America | Search report |
| US4531021A | Cites | United States of America | Search report |
| US4535355A | Cites | United States of America | Applicant |
| US4558175A | Cites | United States of America | Search report |
| US4595950A | Cites | United States of America | Applicant |
| US4608456A | Cites | United States of America | Search report |
| US4613901A | Cites | United States of America | Search report |
| US4634808A | Cites | United States of America | Search report |
| US4658292A | Cites | United States of America | Search report |
| US4663664A | Cites | United States of America | Applicant |
| US4694491A | Cites | United States of America | Applicant |
| US4696034A | Cites | United States of America | Search report |
| US4712238A | Cites | United States of America | Search report |
| US4736422A | Cites | United States of America | Applicant |
| US4757532A | Cites | United States of America | Applicant |
| US4785166A | Cites | United States of America | Search report |
| US4792973A | Cites | United States of America | Applicant |
| US4799635A | Cites | United States of America | Applicant |
| US4802214A | Cites | United States of America | Applicant |
| US4802215A | Cites | United States of America | Applicant |
| US4803725A | Cites | United States of America | Applicant |
| US4807286A | Cites | United States of America | Applicant |
| US4829569A | Cites | United States of America | Search report |
| US4841133A | Cites | United States of America | Search report |
| US4849927A | Cites | United States of America | Applicant |
| US4864615A | Cites | United States of America | Applicant |
| US4866770A | Cites | United States of America | Search report |
| US4885788A | Cites | United States of America | Search report |
| US4890321A | Cites | United States of America | Applicant |
| US4897875A | Cites | United States of America | Search report |
| US4905280A | Cites | United States of America | Search report |
| US4907271A | Cites | United States of America | Applicant |
| US4907273A | Cites | United States of America | Search report |
| US4908834A | Cites | United States of America | Search report |
| US4926444A | Cites | United States of America | Applicant |
| US4933898A | Cites | United States of America | Search report |
| US5237609A | Cites | United States of America | Applicant |
| WO8500491A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| WO8606240A1 | Cites | World Intellectual Property Organization (WIPO) | Applicant |
| USRE33189E | Cites | United States of America | Search report |
| EP132401 | Cites | European Patent Office (EPO) | Third party observation |
| EP308219 | Cites | European Patent Office (EPO) | Third party observation |
| EP308219 | Cites | European Patent Office (EPO) | Search report |
| GB2151886A | Cites | United Kingdom | Third party observation |
| WO8500491 | Cites | World Intellectual Property Organization (WIPO) | Third party observation |
| WO8606240 | Cites | World Intellectual Property Organization (WIPO) | Third party observation |
| A Method of Authentication in EFT Networks Using DES Without Downline Loading of Working Keys, by Marvin Sendrow, Trends and Applications, 5-80. | Non-patent | – | Search report |
| United States Advanced Televisioin Systems Committee Report, "Multiplexed Analog Component Television Broadcast System Parameter Specifications", published Apr. 18, 1987. | Non-patent | – | Search report |
| Smart Card Conditional Access Microcomputers Memories, Motorola, 1988. | Non-patent | – | Search report |
| "HDTV To Alter Cable Security Technology", Multichannel News, Sep. 25, '89. | Non-patent | – | Search report |
| "A Method of Authentication in EFT Networks Using DES Without Downline Loading of Working Keys", Marvin Sendrow, Trends and Applications, 5-80. | Non-patent | – | Search report |
| United Staes Advanced Television Systems Committee report, "Multiplexed Analog Television Broadcast System Parameter Specifications", published Apr. 18, 1987. | Non-patent | – | Search report |
| "Smart Card Conditional Access Microcomputers Memories", Motorola, 1988. | Non-patent | – | Search report |
| Proposal For New Part 6 Of The EBU Specification For The MAC/Packet Family, Version of 24, Published Oct. 1988. | Non-patent | – | Applicant |
| Appendix 1 To Proposed New Part 6: Eurocypher ACM/Receiver Interface Message Definition, Version of 24. Published Oct. 1988. | Non-patent | – | Applicant |
| Annex 1 To Proposal For New Part 6 Of The EBU Specification For The MAC/Packet Family, Version of 21, Published Oct. 1988. | Non-patent | – | Applicant |
| Annex 2 To Proposal For New Part 6 Of The EBU Specification For The MAC/Packet Family, Version of 4, Published Oct. 1988. | Non-patent | – | Applicant |
56 members in 16 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 47344290 | United States of America | A | |
| 47344290 | United States of America | A | |
| 5679593 | United States of America | A | |
| 07473442 | – | – | – |
| US19900473442 | – | – | – |
| US19930056795 | – | – | – |
Members56
| Document | Office | Kind | |
|---|---|---|---|
| US5029207A | United States of America | A | |
| CA2049310A1 | Canada | A1 | |
| WO9111884A1 | World Intellectual Property Organization (WIPO) | A1 | |
| AU7340291A | Australia | A | |
| EP0466916A1 | European Patent Office (EPO) | A1 | |
| BR9104261A | Brazil | A | |
| KR920702158A | Republic of Korea | A | |
| EP0506435A2 | European Patent Office (EPO) | A2 | |
| AU1384092A | Australia | A | |
| JPH04506736A | Japan | A | |
| BR9201106A | Brazil | A | |
| EP0506435A3 | European Patent Office (EPO) | A3 | |
| CN1066950A | China | A | |
| AU635180B2 | Australia | B2 | |
| JPH05145923A | Japan | A | |
| US5237610A | United States of America | A | |
| MX172416B | Mexico | B | |
| AR246145A1 | Argentina | A1 | |
| AU650958B2 | Australia | B2 | |
| EP0679029A1 | European Patent Office (EPO) | A1 | |
| EP0683614A1 | European Patent Office (EPO) | A1 | |
| CN1030955C | China | C | |
| EP0506435B1 | European Patent Office (EPO) | B1 | |
| AT144670T | Austria | T | |
| ATE144670T1 | Austria | T1 | |
| DE69214698D1 | Germany | D1 | |
| DE69214698T2 | Germany | T2 | |
| EP0809402A1 | European Patent Office (EPO) | A1 | |
| SG44801A1 | Singapore | A1 | |
| PH31140A | Philippines | A | |
| EP0683614B1 | European Patent Office (EPO) | B1 | |
| EP0466916B1 | European Patent Office (EPO) | B1 | |
| EP0679029B1 | European Patent Office (EPO) | B1 | |
| AT180373T | Austria | T | |
| AT180936T | Austria | T | |
| AT181196T | Austria | T | |
| ATE180373T1 | Austria | T1 | |
| ATE180936T1 | Austria | T1 | |
| ATE181196T1 | Austria | T1 | |
| KR100193542B1 | Republic of Korea | B1 | |
| DE69229235D1 | Germany | D1 | |
| DE69131285D1 | Germany | D1 | |
| DE69229408D1 | Germany | D1 | |
| DE69229235T2 | Germany | T2 | |
| DE69131285T2 | Germany | T2 | |
| DE69229408T2 | Germany | T2 | |
| EP0809402B1 | European Patent Office (EPO) | B1 | |
| AT192891T | Austria | T | |
| ATE192891T1 | Austria | T1 | |
| DE69132198D1 | Germany | D1 | |
| DE69132198T2 | Germany | T2 | |
| CA2049310C | Canada | C | |
| JP3304084B2 | Japan | B2 | |
| JP3476481B2 | Japan | B2 | |
| USRE39166EThis record | United States of America | E | |
| MY131301A | Malaysia | A |
55 transactions on the USPTO file
Allowed after 2 non-final rejections.
- Non-final rejections
- 2
- Final rejections
- 0
- RCEs
- 0
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Receipt into PubsR1021 | R1021 | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Receipt into PubsR1021 | R1021 | |
| Mail Miscellaneous Communication to ApplicantMM327 | MM327 | |
| Miscellaneous Communication to Applicant - No Action CountM327 | M327 | |
| Pubs Case Remand to TCPUBTC | PUBTC | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Workflow - File Sent to ContractorSENT | SENT | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Mail Examiner's AmendmentMEX.A | MEX.A | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Miscellaneous Incoming LetterLET. | LET. | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Disposal Flag Change2091 | 2091 | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Workflow incoming amendment IFWWAMD | WAMD | |
| Mail Miscellaneous Communication to ApplicantMCTMS | MCTMS | |
| Miscellaneous Action with SSPCTMS | CTMS | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Mail Interference Decision - FavorableMID/F | MID/F | |
| Interference Decision on Priority - FavorableID/F | ID/F | |
| Declaration of InterferenceI.D. | I.D. | |
| Interference Initial Memo Non-DisposalCTIN | CTIN | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Supplemental ResponseSA.. | SA.. | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Interference Initial Memo Non-DisposalCTIN | CTIN | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Affidavit(s) (Rule 131 or 132) or Exhibit(s) ReceivedAF/D | AF/D | |
| Information Disclosure Statement (IDS) FiledM844 | M844 | |
| Information Disclosure Statement (IDS) FiledWIDS | WIDS | |
| Examiner Interview Summary Record (PTOL - 413)EXIN | EXIN | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Preexamination Location ChangeG03V | G03V | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Captured on MicrofilmFILM | FILM | |
| Notice of Reissue Published in Official GazetteNRE. | NRE. | |
| Application Is Now CompleteCOMP | COMP | |
| Notice Mailed--Application Incomplete--Filing Date AssignedINCD | INCD | |
| Initial Exam Team nnIEXX | IEXX |
2 recorded assignments at the USPTO, latest first
- Now
Now: Held by
SCIENTIFIC-ATLANTA LLC - 2014-11-19
Change of name.
- From
- SCIENTIFIC-ATLANTA INC
- To
- SCIENTIFIC-ATLANTA LLC
Recorded 2014-11-19, Signed 2008-12-05
- 2014-11-19
Assignment of assignors interest.
Ownership change- From
- SCIENTIFIC-ATLANTA LLC
- To
- CISCO TECHNOLOGY INC
Recorded 2014-11-19, Signed 2014-11-18
3 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Fee payment procedurePAYOR NUMBER ASSIGNED (ORIGINAL EVENT CODE: ASPN); ENTITY STATUS OF PATENT OWNER: LARGE ENTITYFEPP | FEPP |
Numbers
- Publication
- RE039166
- Publication, DOCDB
- RE39166
- Publication, EPODOC
- USRE39166E
- Application
- 8056795
- Application, DOCDB
- 5679593
- Application, EPODOC
- US19930056795
Titles
- English
- External security module for a television signal decoder
Classification
- CPC, 2
- H04N7/1675
- H04N21/4405
- IPC, 2
- H04L9 10
- H04N7 167
- USPC, 3
- 380228000
- 380239000
- 380281000