CN1852416A - Method and system for realizing combined authorization of enciphering system - Google Patents

Method and system for realizing combined authorization of enciphering system Download PDF

Info

Publication number
CN1852416A
CN1852416A CN 200510105607 CN200510105607A CN1852416A CN 1852416 A CN1852416 A CN 1852416A CN 200510105607 CN200510105607 CN 200510105607 CN 200510105607 A CN200510105607 A CN 200510105607A CN 1852416 A CN1852416 A CN 1852416A
Authority
CN
China
Prior art keywords
program stream
program
product
local
message
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN 200510105607
Other languages
Chinese (zh)
Other versions
CN100421468C (en
Inventor
孙超
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Huawei Technologies Co Ltd
Original Assignee
Huawei Technologies Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co Ltd filed Critical Huawei Technologies Co Ltd
Priority to CNB2005101056077A priority Critical patent/CN100421468C/en
Publication of CN1852416A publication Critical patent/CN1852416A/en
Application granted granted Critical
Publication of CN100421468C publication Critical patent/CN100421468C/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)

Abstract

The disclosed system includes processing equipment of operation manager, and set-top box. The equipment defines programs of other operation managers as local products, and grants local users to order the products. Then, following steps are carried out: setting up AC condition; after determining that programs of other operation managers are defined as local products, redefining ECM message, filtering original CA descriptor in PMT table, and adding local encryption descriptor for identifying CA system the program stream belongs to; after determining that local encryption descriptor is existed in PMT table, set-top box parses out original ECM message, product ID, and AC information; after receiving grant information, set-top box controls and processes original message based on AC condition; decrypting and descrambling the program stream. The invention also discloses relevant implementing method. Comparing with prior art, the invention possesses advantages of easy of use and saving cost.

Description

A kind of system and method for realizing combined authorization of enciphering system
Technical field
The present invention relates to the transmission technique field of Digital Television, relate to a kind of system and method for realizing combined authorization of enciphering system or rather.
Background technology
At present, Digital Television is comparatively general.Encryption system has all been adopted in the transmission of Digital Television and broadcast, carries out encrypted transmission with the content to transmission over networks.That is to say transmission again after cryptographic algorithm that the digital content utilization of needs transmission is certain and key are encrypted.Certainly, this just need have on receiver with this encryption system deciphers terminal accordingly, otherwise can't discern the content of encrypting.
For distributed networking, different different user and the transmission networks of operator's management.The user is the resource that belongs to operator oneself for operator.And under this networking mode, the user who usually has certain subordinate of operator wishes to order the program of other operator, such as, the prefecture-level subordinate's of TV station user wishes to order the program of the Chinese Central Television (CCTV).
At this problem, at present mainly is to receive (CA) system by the condition that different operators uses same manufacturer to provide to come common networking, and in whole transmission network, uses diverse ways separately to realize the combined authorization of different operators.Such as, the A of operator carries out encrypted transmission to program S, the B of operator then is provided with the switch at this program transmission, like this, if the B subordinate's of operator user can program receiving S, then needing the user to be authorized by the A of operator on the one hand can program receiving S, also needs the B of operator will transmit the switch opens of program S on the other hand, otherwise the user can not receive this program S.Order the program of the Chinese Central Television (CCTV) for the prefecture-level subordinate's of TV station user, can watch that program=Chinese Central Television (CCTV) of the Chinese Central Television (CCTV) opens the switch of this program at this program to subscriber authorisation+prefecture-level TV station.Wherein, switch is set specifically is the local Q-character set that this program S is set to the B of operator.
Figure 1 shows that the schematic diagram that carries out combined authorization between other operator's program platform and the local service platform by two-stage CA system.Ordering Chinese Central Television's program with the user of local broadcasting stations is example, and other operator among Fig. 1 then is the Chinese Central Television (CCTV).The concrete processing procedure that realizes combined authorization between the Chinese Central Television (CCTV) and the local broadcasting stations as shown in Figure 2, corresponding following steps:
Step 201, local Subscriber Management System (SMS) be by the SMS of the Chinese Central Television (CCTV), or by and the SMS of the Chinese Central Television (CCTV) between interface channel order the TV programme of the Chinese Central Television (CCTV).The SMS of the Chinese Central Television (CCTV) can send this to CA system of the Chinese Central Television (CCTV) and order request after receiving the request of ordering.
The CA system of step 202, the Chinese Central Television (CCTV) is after receiving that this orders request, the EMMG of the Chinese Central Television (CCTV) that is located at local service platform to the Chinese Central Television (CCTV) sends instant entitlement management message (EMM), and the multiplexer/scrambler in the control Chinese Central Television (CCTV) platform sends to multiplexer/scrambler in the local service platform with Chinese Central Television's program by transmission network.
Step 203, when having the local user to order Chinese Central Television's program, local SMS is to the EMMG of the Chinese Central Television (CCTV) transmission local user's who is arranged on local service platform the request of ordering, and the EMMG of the Chinese Central Television (CCTV) then generates the local Q-character set information to central station synchronization in the request of the ordering back of receiving the local user.
Step 204, the EMMG of the Chinese Central Television (CCTV) are after receiving the program EMM of the Chinese Central Television (CCTV) message that CA system of the Chinese Central Television (CCTV) sends, can determine that the user can watch this Chinese Central Television's program according to the local Q-character set information that self generates, therefore to the EMM message of local multiplexer/scrambler transmission at Chinese Central Television's program.
In this step, the EMM information of the EMMG of the Chinese Central Television (CCTV) after the EMM message that local multiplexer/scrambler sends is to handle, in this processing EMM message that specifically to be the local Q-character set information setting that will self be provided with send to CA system of the Chinese Central Television (CCTV), and will in conjunction with after EMM message send to local multiplexer/scrambler.
Multiplexer/the scrambler of step 205, this locality sends to set-top box with Chinese Central Television's program of encrypting, instant authorization control word (ECM) message and EMM message by the HFC net after receiving the EMM message that the EMMG of the Chinese Central Television (CCTV) sends.
Afterwards, set-top box is decrypted Chinese Central Television's program of receiving, specifically be to be decrypted according to EMM message of receiving and ECM message pair centre station synchronization, thus the broadcast of realization Chinese Central Television (CCTV) program.
In the processing of above-mentioned steps 204, original EMM message is that CA system of the Chinese Central Television (CCTV) generates, and local Q-character set information to be the EMMG of the Chinese Central Television (CCTV) in the local CA system generate, for guaranteeing that the EMMG of the Chinese Central Television (CCTV) can add EMM message with local Q-character set information, must guarantee that then these two information are that the EMMG of the Chinese Central Television (CCTV) is understandable, and EMM message is encrypted transmission as the key component of CA, different CA manufacturer is not intercommunication to this message, therefore, local CA must come from same manufacturer with the CA of the Chinese Central Television (CCTV), could guarantee that the EMMG of the Chinese Central Television (CCTV) can handle and generate new EMM message.That is to say, in present multi-operator scheme, all operators must adopt the CA system of same manufacturer, and in fact, different operators tends to use different CA systems, this will cause based on the combining encryption transmission that can not realize program between the operator of different vendor, thereby causes user under the operator can not watch TV programme based on other operator of different CA system, and operator can not increase income by the combined authorization to the TV programme of other operator.
In addition, because the Chinese Central Television (CCTV) need be provided with the EMMG of the Chinese Central Television (CCTV) in local broadcasting stations, and this EMMG need connect with local SMS and CA system of local broadcasting stations, and this has just increased the networking complexity and the maintenance cost of local operator.If local broadcasting stations also need to transmit the program of other operator, then equally corresponding EMMG need be set, make local SMS and local CA to be connected with a plurality of EMMG, further increased the networking complexity and the maintenance cost of local operator.
Summary of the invention
In view of this, subject matter to be solved by this invention is to provide a kind of system that realizes combined authorization of enciphering system, to realize the control to other operator's program easily.
Another problem to be solved by this invention is to provide a kind of method that realizes combined authorization of enciphering system.
For overcoming the above problems, the invention provides following technical scheme:
A kind of system that realizes combined authorization of enciphering system of the present invention, this system comprises:
Operator's processing unit, be used for the program of other operator is defined as native product, the request of ordering according to the local user licenses to the local user with this product, and the set-top box that the native product ID and the authorization message of this product sent to this user, be used to define access criteria (AC) condition of other operator's program, and be used for after other operator's program of determining to receive has been defined as native product, redefine the ECM message according to each instant authorization control word (ECM) message in this program stream, and comprise original ECM message in the new ECM message, the native product ID of this program stream and AC information, filter the initial condition receiving system CA descriptor in the Program Map Table (PMT) of this program stream, the local cipher descriptor of CA system under this program stream of increase sign in this pmt table, and be used for the program stream after handling is sent to set-top box;
Set-top box, be used for after there is the local cipher descriptor in the pmt table of determining program stream, from the new ECM message of program stream, parse original ECM message, product IDs and AC information, and determine to receive the authorization message of this program stream according to product IDs after, according to AC information original ECM message is carried out control and treatment, after having passed through the pairing condition of this AC information, determine CA system under this program stream according to the local cipher descriptor, processing according to the CA system is decrypted the scrambling control word of encrypting to this program stream, and uses the scrambling control word after the deciphering that program stream is carried out descrambling.
Described operator processing unit further comprises: the multiplexer of Local User Management system (SMS), authorization control module, AC control module and enhancing, wherein,
Local SMS is used for the program of other operator is defined as native product, the ID of the native product of this program is sent to the authorization control module, and send authorization requests according to user's the request of ordering to the authorization control module;
The authorization control module, be used for receiving the ID of native product from local SMS, and this native product ID sent to the enhancing multiplexer, and after receiving the authorization requests that local SMS sends, this product is licensed to the local user, and after mandate, authorization message and product IDs are sent to this local user's set-top box;
The AC control module is used to define access criteria, and sends to the multiplexer of enhancing;
The multiplexer that strengthens, receive the program stream of other operator, after determining that according to the product IDs of this program this program is defined as native product, each ECM data segment in this program stream is redefined the ECM message as the load of new ECM message, this new ECM message comprises the native product ID and the AC information of original ECM message, redetermination, and the original CA descriptor in the pmt table of filtrating program stream, and increase is used to identify the local cipher descriptor that this program stream belongs to the CA system in pmt table, and the program stream after will handling afterwards sends to set-top box.
The multiplexer of described enhancing is further used for, and after the program stream of determining to receive is not defined as native product, filters out this program stream by revising Program Association Table (PAT) table, perhaps direct this program stream of transparent transmission.
The multiplexer that strengthens is further used for, and whether has the AC condition corresponding with current program stream in the inquiry AC control module, and obtains corresponding AC condition;
The AC control module is further used for, and after the inquiry of the multiplexer of receiving enhancing, the AC condition of current program stream correspondence is sent to the multiplexer of enhancing.
Further comprise in the set-top box: local decryption processing module, CA processing module and descrambling controller, wherein,
Described local decryption processing module, be used for parsing original ECM message, product IDs and AC information from the new ECM message of program stream, and inquire about the authorization message whether this set-top box receives this product according to product IDs, after acknowledging receipt of the authorization message of this product, according to AC information the ECM message of receiving is carried out control and treatment, and after passing through the pairing AC condition of this AC information, determine original CA processing module by the local cipher descriptor in the pmt table, and original ECM message is sent to original CA processing module;
The CA processing module, be used for original ECM message of receiving being carried out control and treatment according to the processing of CA system, and after control and treatment is passed through, by the EMM information in the program stream scrambling control word in the ECM message is decrypted, and the scrambling control word after will deciphering sends to the descrambling controller;
The descrambling controller is used to use the scrambling control word after the deciphering that this program stream is carried out descrambling.
Described native product ID comprises: primitive network ID, program code and transport stream ID.
A kind of method that realizes combined authorization of enciphering system of the present invention, this method may further comprise the steps:
A. the program with other operator is defined as native product, according to local user's the request of ordering this product is licensed to the local user, and the set-top box that the native product ID and the authorization message of this product sent to this user;
B. define the control AC condition of product, afterwards when receiving the program stream of other operator, after determining that this program is defined as native product, redefine the ECM message according to each the ECM message in this program stream, new ECM message comprises the native product ID and the AC information of original ECM message, redetermination, and filter original CA descriptor in the pmt table of this program stream, increase the local cipher descriptor be used to identify CA system under this program stream in this pmt table, the program stream after will handling afterwards sends to set-top box;
C. after there is the local cipher descriptor in set-top box in the pmt table of determining program stream, from the new ECM message of program stream, parse original ECM message, product IDs and AC information, and determine to receive the authorization message of this program stream according to product IDs after, according to AC information original ECM message is carried out control and treatment, and after passing through the condition of this AC information correspondence, determine CA system under this program stream according to the local cipher descriptor, processing according to the CA system is decrypted to this program stream, and the program stream after the deciphering is carried out descrambling.
Among the described step b,, then filter this program stream if determine that according to the product IDs of program stream the program stream that receives is not defined as native product, or direct this program stream of transparent transmission.
Among the described step c, described set-top box, is decrypted with descrambling program stream and comprises by after the AC condition at definite original ECM message:
Processing according to the CA system is carried out control and treatment to original ECM message, and after control and treatment is passed through, by the EMM information in the program stream scrambling control word of encrypting in the ECM message is decrypted, uses the scrambling control word after deciphering that program stream is carried out descrambling afterwards.
Described native product ID comprises: primitive network ID, program code and transport stream ID.
The present invention program is by encrypting the ECM message in other operator's program and transmitting, thereby avoided in the prior art program being encrypted the complexity that causes needing increase equipment, increase technology to realize, making more problem such as complexity of networking because of the CA system of different vendor, the present invention program only need finish the integrated of various CA system on set-top box, be the CA processing module of integrated various CA system, just can satisfy the demand that the user orders other operator's product.This shows that the present invention program not only implements very convenient, and saved cost.
Description of drawings
Fig. 1 is a schematic diagram of realizing combined authorization in the prior art between other operator's program platform and the local service platform;
Fig. 2 is a flow chart of realizing combined authorization in the prior art between the Chinese Central Television (CCTV) and local broadcasting stations;
Fig. 3 is the present invention program's realization flow figure;
Fig. 4 is the present invention program's a system construction drawing;
Fig. 5 is the concrete structure figure of system shown in Figure 4.
Embodiment
Below in conjunction with drawings and the specific embodiments the present invention program is described in further detail.
Owing to comprised instant authorization control word message (ECM) in the program stream after other operator encrypts, promptly comprised ECM stream, and this ECM stream is along with encrypted program transmits, and this ECM message is that set-top box is to the necessary information of program decryption, therefore, the present invention program's core is by the ECM message in other operator's program being controlled, being reached the purpose that other operator's program is controlled.
The present invention program's realization flow as shown in Figure 3, corresponding following steps:
Step 301, the program of other operator is defined as native product, this product is licensed to the local user according to local user's the request of ordering, and the set-top box that the native product ID and the authorization message of this product sent to this user.
The access criteria of step 302, definition product, it is the AC condition, afterwards when receiving the program stream of other operator, after determining that this program is defined as native product, redefine the ECM message according to each the ECM message in this program stream, new ECM message comprises the native product ID and the AC information of original ECM message, redetermination, and filter original CA descriptor in the Program Map Table (PMT) of this program stream, increase the local cipher descriptor be used to identify CA system under this program stream in this pmt table, the program stream after will handling afterwards sends to set-top box.
Step 303, there is the local cipher descriptor in set-top box in the pmt table of determining program stream after, from the new ECM message of program stream, parse original ECM message, product IDs and AC information, and determine to receive the authorization message of this program stream according to product IDs after, according to AC information original ECM message is carried out control and treatment, and after passing through the condition of this AC information correspondence, determine CA system under this program stream according to the local cipher descriptor, processing according to the CA system is decrypted the scrambling control word to this program stream, and uses the scrambling control word that program stream is carried out descrambling.
The present invention program also provides corresponding system, and this system comprises operator's processing unit and set-top box as shown in Figure 4.
Wherein, operator's processing unit is used for the program of other operator is defined as native product, according to local user's the request of ordering this product is licensed to the local user, and the set-top box that the native product ID and the authorization message of this product sent to this user.Be used to define the control AC condition of other operator's program.And be used for after other operator's program of determining to receive has been defined as native product, redefining the ECM message, and comprise the native product ID and the AC information of original ECM message, this program stream in the new ECM message according to each the ECM message in this program stream.Filter the original CA descriptor in the pmt table of this program stream, in this pmt table, increase the local cipher descriptor of CA system under this program stream of sign.And be used for the program stream after handling is sent to set-top box.
Set-top box is used for parsing original ECM message, product IDs and AC information from the new ECM message of program stream after there is the local cipher descriptor in the pmt table of determining program stream.And determine to receive the authorization message of this program stream according to product IDs after, according to AC information original ECM message is carried out control and treatment, after having passed through the pairing condition of this AC information, determine CA system under this program stream according to the local cipher descriptor, processing according to the CA system is decrypted the scrambling control word to this program stream, and uses the scrambling control word that program stream is carried out descrambling.
System shown in Figure 4 specifically can be to increase AC control module and authorization control module on the basis of original CA system, and the function of multiplexer is strengthened, thereby the system of realization combined authorization as shown in Figure 5 is provided.The multiplexer that specifically comprises local SMS, AC control module, authorization control module and enhancing in this system.Again the function of these several modules is described respectively below.
At first, need the program of other operator be defined as native product by local SMS.
Same as the prior art, this system orders the program of other operator by local SMS, local SMS among the present invention need provide the native product definition of other operator's program, i.e. product IDs is to come this program of unique identification by this product IDs in the transport stream of this program.For local operator program, local SMS can use program code (program_number) and transport stream ID (TS_stream_ID) to define; For other operator's program, then can increase a primitive network ID (OrigNetwork_ID) and define, promptly other operator's program is defined with program_number, TS_stream_ID and OrigNetwork_ID.
Local SMS also offers the order functionality of local user to the redetermination product, receive the user order request after, produce authorization requests, and this authorization requests sent to authorization control module in the system.
The authorization control module receives the ID of native product from local SMS, and by self and the interface that strengthens multiplexer the ID of native product is issued to the enhancing multiplexer.The authorization control module is also authorized the local user at the authorization requests that the native product and the local SMS of this redetermination sends.The authorization control module just can be notified to authorization message EMM and corresponding product IDs this user's set-top box after to subscriber authorisation.Specifically can send to the local deciphering module in the set-top box, so that should according to this EMM information Control corresponding program be decrypted by this locality deciphering module.
The AC control module is to different Product Definition access criteria, and access criteria sent to the multiplexer of enhancing.This access criteria can broadcast for zone limit/and whether standard broadcast grade, parental level, machine card and match, can record etc.The present invention flows by the new ECM of definition access criteria structure.For instance, if the program of other operator allows all users to see, and local operator wishes that the user in regulation zone can see, then can access criteria be defined as regional standard by the AC control module to broadcast, and formulates the zone that can watch.
The multiplexer that strengthens is when receiving the program stream of other operator, according to OrigNetwork_ID, program_number and the local Product Definition of TS_stream_ID inquiry of this program.Because after local SMS is defined as native product with program, local SMS can send to multiplexer with the product IDs that defines by the authorization control module, the search key of product is exactly OrigNetwork_ID, program_number and TS_stream_ID, therefore, if the multiplexer that strengthens does not inquire native product ID by these several keywords, can think that then this program is not defined by native product, afterwards processing that can be different according to the operation strategy execution of operator.Such as, if the operation strategy is not for allowing to play this program, then delete the positional information of the Program Map Table of preserving in the Program Association Table (PAT) (PMT), the feasible positional information that can't obtain pmt table by the inquiry pat table, if and can not obtain pmt table, then can't obtain the position of program stream, thereby this program filtering is fallen.For another example,, directly carry out transparent transmission, be about to program stream and directly send to set-top box if the operation strategy then can not done encryption to the ECM section of program stream for can play-over this program.
If the multiplexer that strengthens inquires this program and has been defined by native product, then with the load of each ECM data segment as new ECM message, redefine the ECM message, and when definition, add local defined product IDs of this program stream and control (AC) information.Therefore, comprise in the definition of new ECM data segment: the native product ID of former ECM data segment, redetermination and AC information.The ECM message that redefines is as shown in table 1.
Descriptor Label value Summary
Product_Descriptor 0x01 The native product numbering
AC_Descriptor 0x02 The newly-increased access criteria of native product
OriginalECM_Descriptor 0x03 Original ECM message
Table 1
Filter out the original CA descriptor in the pmt table of program stream simultaneously, in this pmt table, increase privately owned local cipher descriptor, wherein, the ECM data segment that this newly-increased descriptor is used to indicate which CA system is by local cipher, makes the CA sign that has comprised corresponding CA system in this program stream.The definition of the descriptor that is increased can be set to:
Private_OriginalCA_Descriptor(){
Descriptor_tag 1byte // such as being 100
Descriptor_length 1tyte // descriptor length
CA_system_id 2byte // by the ID of the CA system of native scrambling
}
Set-top box is when receiving program stream, at first analyze pmt table, if there is the local cipher descriptor in this table, then from the new ECM message of program stream, parse original ECM message, product IDs and AC information, and determine to receive the authorization message of this program stream according to product IDs after, according to AC information original ECM message is carried out control and treatment, after having passed through the pairing condition of this AC information, determine CA system under this program stream according to the local cipher descriptor, processing according to the CA system is decrypted the scrambling control word to this program stream, and uses the scrambling control word that program stream is carried out descrambling.
Specifically, generally include decryption processing module, CA processing module and descrambling controller in the set-top box, and there is the local cipher descriptor in set-top box in determining pmt table after, promptly call local decryption processing module; Otherwise, handle according to existing processing scheme.Local decryption processing module is after being called by set-top box, at first analyze the ECM message of receiving, after definite this message has been defined as native product, parse the product IDs of this program in this locality, and inquire about this set-top box and whether received mandate the pairing product of this product IDs, if determine that by native product ID this product does not obtain local mandate, promptly the pairing EMM of this product IDs not in this module then ignores this ECM message; If obtained local mandate, then Ben Di decryption processing module is handled other control information in the ECM message of this this locality.Specifically be to carry out dissection process, promptly carry out the AC condition according to the AC condition, such as, if being regional standard, the AC condition broadcasts condition, judge then whether this set-top box region belongs to this standard and broadcast the zone, if do not belong to, then abandon this ECM message; If belong to, then this ECM message is resolved according to AC condition and native product ID, obtain original ECM message, determine CA system under this program stream by the local cipher descriptor in the pmt table afterwards, can determine original CA processing module, and original ECM message that will obtain is given this original CA processing module and is handled.
The CA processing module is carried out control and treatment according to the processing of this CA system to original ECM message of receiving again, and after control and treatment is passed through, by the EMM information in the program stream control word in the ECM message is decrypted, the control word after will deciphering then sends to the descrambling controller.Wherein, this EMM information is that the local decryption processing module of set-top box receives from the authorization control module.Specifically, the processing that the CA processing module is carried out specifically comprises: carry out the AC condition earlier, after all AC conditions are all passed through, use the EMM information of ECM data segment Central Plains CA that the scrambling control word of encrypting in the ECM message is decrypted, the scrambling control word after the deciphering is set in the descrambling controller.
The descrambling controller then uses the scrambling control word after this deciphering that the program stream of scrambling is carried out descrambling, and the plaintext behind the descrambling is sent to terminal shows.
In addition, the CA processing module of set-top box need be obtained the ECM message when original ECM section is handled, to be used to decipher program stream.In existing the processing, owing to have a plurality of ECM messages in an encryption period, if obtain the ECM message by the CA processing module on the set-top box, then the CA processing module only needs an ECM message can obtain the descrambled control words of program in one-period, therefore, after obtaining the ECM message, filtration can be set, promptly require set-top box not send the ECM that repeats again, also promptly need filtercondition to be set for the ECM message that sends to the CA processing module.But the present invention program is after definite this product obtains local the mandate, ECM stream will directly be received by local decryption processing module, and whether obtain local the mandate by the first basis of local decryption processing module, from each ECM message, parse original ECM message again, therefore just again necessity of filtration has not been set, so can intercept and capture filtercondition setting at ECM.
The above only is the present invention program's preferred embodiment, not in order to limit protection scope of the present invention.

Claims (10)

1, a kind of system that realizes combined authorization of enciphering system is characterized in that, this system comprises:
Operator's processing unit, be used for the program of other operator is defined as native product, the request of ordering according to the local user licenses to the local user with this product, and the set-top box that the native product ID and the authorization message of this product sent to this user, be used to define the access criteria AC of other operator's program, and be used for after other operator's program of determining to receive has been defined as native product, redefine the ECM message according to each the instant authorization control word ECM message in this program stream, and comprise original ECM message in the new ECM message, the native product ID of this program stream and AC information, filter the initial condition receiving system CA descriptor among the Program Map Table PMT of this program stream, the local cipher descriptor of CA system under this program stream of increase sign in this pmt table, and be used for the program stream after handling is sent to set-top box;
Set-top box, be used for after there is the local cipher descriptor in the pmt table of determining program stream, from the new ECM message of program stream, parse original ECM message, product IDs and AC information, and determine to receive the authorization message of this program stream according to product IDs after, according to AC information original ECM message is carried out control and treatment, after having passed through the pairing condition of this AC information, determine CA system under this program stream according to the local cipher descriptor, processing according to the CA system is decrypted the scrambling control word of encrypting to this program stream, and uses the scrambling control word after the deciphering that program stream is carried out descrambling.
2, system according to claim 1 is characterized in that, described operator processing unit further comprises: the multiplexer of the SMS of Local User Management system, authorization control module, AC control module and enhancing, wherein:
Local SMS is used for the program of other operator is defined as native product, the ID of the native product of this program is sent to the authorization control module, and send authorization requests according to user's the request of ordering to the authorization control module;
The authorization control module, be used for receiving the ID of native product from local SMS, and this native product ID sent to the enhancing multiplexer, and after receiving the authorization requests that local SMS sends, this product is licensed to the local user, and after mandate, authorization message and product IDs are sent to this local user's set-top box;
The AC control module is used to define access criteria, and sends to the multiplexer of enhancing;
The multiplexer that strengthens, receive the program stream of other operator, after determining that according to the product IDs of this program this program is defined as native product, each ECM data segment in this program stream is redefined the ECM message as the load of new ECM message, this new ECM message comprises the native product ID and the AC information of original ECM message, redetermination, and the original CA descriptor in the pmt table of filtrating program stream, and increase is used to identify the local cipher descriptor that this program stream belongs to the CA system in pmt table, and the program stream after will handling afterwards sends to set-top box.
3, system according to claim 2, it is characterized in that the multiplexer of described enhancing is further used for, after the program stream of determining to receive is not defined as native product, filter out this program stream by revising Program Association Table PAT, perhaps direct this program stream of transparent transmission.
4, system according to claim 2 is characterized in that, the multiplexer of enhancing is further used for, and whether has the AC condition corresponding with current program stream in the inquiry AC control module, and obtains corresponding AC condition;
The AC control module is further used for, and after the inquiry of the multiplexer of receiving enhancing, the AC condition of current program stream correspondence is sent to the multiplexer of enhancing.
5, system according to claim 1 is characterized in that, further comprises in the set-top box: local decryption processing module, CA processing module and descrambling controller, wherein:
Described local decryption processing module, be used for parsing original ECM message, product IDs and AC information from the new ECM message of program stream, and inquire about the authorization message whether this set-top box receives this product according to product IDs, after acknowledging receipt of the authorization message of this product, according to AC information the ECM message of receiving is carried out control and treatment, and after passing through the pairing AC condition of this AC information, determine original CA processing module by the local cipher descriptor in the pmt table, and original ECM message is sent to original CA processing module;
The CA processing module, be used for original ECM message of receiving being carried out control and treatment according to the processing of CA system, and after control and treatment is passed through, by the EMM information in the program stream scrambling control word in the ECM message is decrypted, and the scrambling control word after will deciphering sends to the descrambling controller;
The descrambling controller is used to use the scrambling control word after the deciphering that this program stream is carried out descrambling.
6, system according to claim 1 is characterized in that, described native product ID comprises: primitive network ID, program code and transport stream ID.
7, a kind of method that realizes combined authorization of enciphering system is characterized in that, this method may further comprise the steps:
A. the program with other operator is defined as native product, according to local user's the request of ordering this product is licensed to the local user, and the set-top box that the native product ID and the authorization message of this product sent to this user;
B. define the control AC condition of product, afterwards when receiving the program stream of other operator, after determining that this program is defined as native product, redefine the ECM message according to each the ECM message in this program stream, new ECM message comprises the native product ID and the AC information of original ECM message, redetermination, and filter original CA descriptor in the pmt table of this program stream, increase the local cipher descriptor be used to identify CA system under this program stream in this pmt table, the program stream after will handling afterwards sends to set-top box;
C. after there is the local cipher descriptor in set-top box in the pmt table of determining program stream, from the new ECM message of program stream, parse original ECM message, product IDs and AC information, and determine to receive the authorization message of this program stream according to product IDs after, according to AC information original ECM message is carried out control and treatment, and after passing through the condition of this AC information correspondence, determine CA system under this program stream according to the local cipher descriptor, processing according to the CA system is decrypted to this program stream, and the program stream after the deciphering is carried out descrambling.
8, method according to claim 7 is characterized in that among the described step b, if determine that according to the product IDs of program stream the program stream that receives is not defined as native product, then filters this program stream, or direct this program stream of transparent transmission.
9, method according to claim 7 is characterized in that among the described step c, and described set-top box, is decrypted with descrambling program stream and comprises by after the AC condition at definite original ECM message:
Processing according to the CA system is carried out control and treatment to original ECM message, and after control and treatment is passed through, by the EMM information in the program stream scrambling control word of encrypting in the ECM message is decrypted, uses the scrambling control word after deciphering that program stream is carried out descrambling afterwards.
10, method according to claim 7 is characterized in that, described native product ID comprises: primitive network ID, program code and transport stream ID.
CNB2005101056077A 2005-09-28 2005-09-28 Method and system for realizing combined authorization of enciphering system Active CN100421468C (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CNB2005101056077A CN100421468C (en) 2005-09-28 2005-09-28 Method and system for realizing combined authorization of enciphering system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CNB2005101056077A CN100421468C (en) 2005-09-28 2005-09-28 Method and system for realizing combined authorization of enciphering system

Publications (2)

Publication Number Publication Date
CN1852416A true CN1852416A (en) 2006-10-25
CN100421468C CN100421468C (en) 2008-09-24

Family

ID=37133882

Family Applications (1)

Application Number Title Priority Date Filing Date
CNB2005101056077A Active CN100421468C (en) 2005-09-28 2005-09-28 Method and system for realizing combined authorization of enciphering system

Country Status (1)

Country Link
CN (1) CN100421468C (en)

Cited By (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101860717B (en) * 2009-04-13 2012-06-27 北京视博数字电视科技有限公司 Viewing control method and device thereof
CN104661075A (en) * 2015-02-04 2015-05-27 深圳创维数字技术有限公司 Data processing method and digital TV receiving terminal
CN109479155A (en) * 2016-05-27 2019-03-15 交互数字Ce专利控股公司 Method and apparatus for personal multi-media content distribution

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101771808B (en) * 2009-12-30 2013-01-02 四川长虹电器股份有限公司 Using control method of FTA set-top box of cable digital TV

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
IL129230A (en) * 1999-03-29 2003-04-10 Nds Ltd System for determining successful reception of a message
CN1175666C (en) * 2001-11-26 2004-11-10 国家广播电影电视总局广播科学研究院 Digital TV subscriber management system and multiple-condition receiving system connection realizing method
CN100423575C (en) * 2002-12-25 2008-10-01 潍坊北大青鸟华光电子有限公司 Method for controlling digital TV receive
EP1564994A1 (en) * 2004-02-13 2005-08-17 Nagravision S.A. Method for managing rights of subscribers to a multi-operator pay television system

Cited By (6)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101860717B (en) * 2009-04-13 2012-06-27 北京视博数字电视科技有限公司 Viewing control method and device thereof
CN104661075A (en) * 2015-02-04 2015-05-27 深圳创维数字技术有限公司 Data processing method and digital TV receiving terminal
CN104661075B (en) * 2015-02-04 2018-07-03 深圳创维数字技术有限公司 A kind of data processing method and receiving terminal for digital television
CN109479155A (en) * 2016-05-27 2019-03-15 交互数字Ce专利控股公司 Method and apparatus for personal multi-media content distribution
CN109479155B (en) * 2016-05-27 2021-06-08 交互数字Ce专利控股公司 Method and apparatus for personal multimedia content distribution
US11057661B2 (en) 2016-05-27 2021-07-06 Interdigital Ce Patent Holdings Method and apparatus for personal multimedia content distribution

Also Published As

Publication number Publication date
CN100421468C (en) 2008-09-24

Similar Documents

Publication Publication Date Title
CN1168304C (en) Global copy protection system for digital home networks
CN1241350C (en) Key allocation method and device in conditional receiving system
CN1153447C (en) Packet filtering
CN101047830A (en) Method and device for authorising conditional access
US8619983B2 (en) Digital TV conditional access system and method of using the same for transmitting and receiving digital data
CN101061666A (en) Method for managing digital rights in broadcast/multicast service
EP1802119A1 (en) Method for protecting broadband video and audio broadcast content
CN101035255A (en) System, protection method and server for realizing the virtual channel service
CN101032167A (en) Method for broadcasting digital data to a targeted set of reception terminals
CN1549595A (en) Information transmitting method and apparatus for interactive digital broadcast television system
CN1822545A (en) Method of controlling communication between a head-end system and a plurality of client systems
CN1867066A (en) Digital television program broadcasting system and method
CN1859559A (en) Method for granting power to user in receiving system under digital TV condition
CN1607831A (en) Bidirectional real-time authentication digital television conditional receiving system
CN1725853A (en) Method for realizing acquisition of user on-line information
CN1852416A (en) Method and system for realizing combined authorization of enciphering system
CN101057446A (en) Method and apparatus for receiving broadcast content
CN1728818A (en) Wireless distribution association mode of digital TV contents for multiple receiving terminals shared in same account
CN1258920C (en) Secure digital content delivery system and method over broadcast network
CN1140121C (en) Process for controlling access to domestic network and device implementing the process
CN100547955C (en) A kind of method of protecting mobile multimedia service, system and equipment
CN1720733A (en) Method of managing the display of event specifications with conditional access
CN1745585A (en) Pay television, method for revoking rights in such a system, associated decoder and smart card, and message transmitted to such a decoder
CN1547836A (en) Local digital network, methods for installing new devices and data broadcast and reception methods in such a network
CN101729750A (en) Implementation method and device of encryption self-adaptation of various digital copyrights in set top box

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant