CN101640785A - Encrypting/decrypting system and encrypting/decrypting method for interactive network television - Google Patents

Encrypting/decrypting system and encrypting/decrypting method for interactive network television Download PDF

Info

Publication number
CN101640785A
CN101640785A CN200810117450A CN200810117450A CN101640785A CN 101640785 A CN101640785 A CN 101640785A CN 200810117450 A CN200810117450 A CN 200810117450A CN 200810117450 A CN200810117450 A CN 200810117450A CN 101640785 A CN101640785 A CN 101640785A
Authority
CN
China
Prior art keywords
key
ciphertext
authorization
content
programme content
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Granted
Application number
CN200810117450A
Other languages
Chinese (zh)
Other versions
CN101640785B (en
Inventor
戴才良
于志强
张飚
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Aisino Corp
Original Assignee
Aisino Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Aisino Corp filed Critical Aisino Corp
Priority to CN2008101174503A priority Critical patent/CN101640785B/en
Publication of CN101640785A publication Critical patent/CN101640785A/en
Application granted granted Critical
Publication of CN101640785B publication Critical patent/CN101640785B/en
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Landscapes

  • Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)

Abstract

The invention discloses an encrypting/decrypting system and an encrypting/decrypting method for an interactive network television. By using a cryptographic algorithm approved by the national cryptogram management department, adopting a secure three-layer key system, namely a program content key, an authorized key and a user personal ECC key pair, and adopting a mature identity authentication technique, the security of a service system is protected, so the identity authentication problem of the system can be solved, and simultaneously the security protection for on-demand and living broadcast services also can be realized.

Description

The enciphering/deciphering system and the method for encryption/decryption of IPTV
Technical field
What the present invention relates to is a kind of digital safety system and method for IPTV, particularly be a kind of enciphering/deciphering system and method for encryption/decryption of IPTV.
Background technology
Because IPTV (IPTV) technology is at the early-stage in China; the IPTV business is also being carried out among the pilot process; compare with safe practice; operator more is concerned about the operation system function diversity; therefore, do not adopt the Ciphor safety technology of system that media content is carried out effective safeguard protection mostly in the IPTV of usefulness operation system at present.
Though in the classical ip TV DRM model that with OMA is representative; introduced cryptographic algorithm; in order to realizing safeguard protection, but because the emphasis difference of each IPTV business model to Media Stream, the very big difference of existence on the design of security system and specific implementation.Existing IPTV system password application technology mainly contains:
The IPCAS technology by the IP technological transformation to the CA system of DVB-C, is encrypted control to programme televised live.The problem of this technology is:
1), owing to is the rating control technology of unidirectional broadcast network on the CA technological essence of DVB, though can realize the programming of IP network after IP transforms, but can not effectively utilize the interactivity characteristics of IP network to realize the user's online authentication, can not effectively prevent illegal rating;
2), the IPCAS technology only provides the safety encipher in the program stream transmission course, can not carry out safeguard protection to the programme content after landing, therefore, can not effectively prevent the user to rating to program share, the illegal propagation such as distribution;
3), IPCAS uses general scrambling algorithm that program is encrypted, the intensity of scrambling algorithm is low, can not effectively resist the brute force attack based on the internet powerful calculating ability.
With OMA is the digital copyright technology of representative, is to use resist technology at the password of mobile TV, has defined the password application flow that program request/file is downloaded.But the problem that this technology exists has:
1), do not have definition at the safe handling flow process of programme televised live, can not satisfy the needs of IPTV business;
2), the RSA digital certificate technique that the adopts ECC digital certificate technique of comparing native system has certain inferior position, replaces the RSA digital certificate as the digital certificate that adopts the ECC algorithm, has advantages such as operation efficiency height, key weak point, fail safe height.
Mostly above-mentioned two kinds of employed cryptographic algorithms of technical system are to adopt external algorithm, and the fail safe of algorithm and Intellectual Property Rights Issues can be brought certain obstacle for the application of product; At present, the commercial cipher algorithm of national Password Management office also can satisfy application demand fully.
In view of above-mentioned defective, creator of the present invention is through research and practice have obtained this creation finally for a long time.
Summary of the invention
The object of the present invention is to provide a kind of enciphering/deciphering system and method for encryption/decryption of IPTV, in order to overcome above-mentioned technological deficiency.
For achieving the above object, the technical solution used in the present invention is, a kind of encryption system of IPTV at first is provided, and it comprises:
One Key Management server, also store program content key, authorization key and individual subscriber ECC key are right in order to produce;
One content key encryption unit is in order to encrypt production ciphertext content key to described content key by described authorization key;
One authorization key ciphering unit in order to by a PKI in the described individual subscriber ECC key described authorization key is encrypted, produces the ciphertext authorization key;
One media content ciphering unit, in order to by described programme content key to encrypting from the programme content of a media server, generate the media program content ciphertext;
One medium encapsulation process unit in order to described media program content ciphertext and the packing of ciphertext content key, transfers to a decryption system by an IP network;
One authorization unit generates an authority in order to utilize described ciphertext authorization key and program authorization message, passes to described decryption system by described IP network.
Wherein, described Key Management server comprises:
One programme content key generator is in order to generate described programme content key;
One programme content cipher key management unit is in order to store described programme content key;
One authorization key maker is in order to generate described authorization key;
One authorization key administrative unit is in order to store described authorization key;
One individual subscriber ECC key is to maker, and is right in order to generate described individual subscriber ECC key;
One individual subscriber ECC cipher key management unit is in order to store the PKI of described individual subscriber ECC cipher key pair.
Wherein, also comprise: a digital signature authentication unit, in order to utilize in the described individual subscriber ECC key PKI user's program application signing messages that obtains is verified, and will be verified the operation system of result transmission to an IPTV.
Preferable, also comprise: described programme content key generator, authorization key maker and described individual subscriber ECC key all comprise maker: a tandom number generator.
Next provides a kind of decryption system of IPTV, and it comprises:
One authorization resolution unit in order to receive and to resolve an authority of obtaining by an IP network, is resolved generation one program authorization message and ciphertext authorization key;
One authorization key decrypting device in order to receiving described ciphertext authorization key, and is decrypted by a private key in the individual subscriber ECC key, generates an authorization key expressly;
One terminal key management server in order to private key in the described individual subscriber ECC key to be provided, and is stored described plaintext authorization key;
One medium dissection process unit comprises the packet of media program content ciphertext and ciphertext content key in order to obtain one, and distributes;
One content key resolution unit in order to obtain described ciphertext content key and described plaintext authorization key, generates a clear content key;
One media content decrypting device is decrypted described media program content ciphertext in order to utilize described clear content key, gives the equipment that displays the play with content delivery.
Wherein, described terminal key management server comprises:
One individual subscriber ECC cipher key management unit is in order to provide the private key in the described individual subscriber ECC key;
One authorization key administrative unit is in order to store described plaintext authorization key.
Preferable, also comprise: a digital signature unit, it is encrypted to user's program application signing messages by the private key in the described individual subscriber ECC key with user's program application information.
A kind of encryption method of IPTV is provided once more, it is characterized in that, it step that comprises is:
Step a: a programme content key is sent to a media content ciphering unit and programme content secret key encryption unit;
Step b: a media server is sent to described media content ciphering unit with programme content;
Step c: by described programme content key described programme content is encrypted, generated the programme content ciphertext;
Steps d: utilize an authorization key, to described programme content secret key encryption, generate a ciphertext programme content key in described programme content secret key encryption unit;
Step e: use the PKI in the individual subscriber ECC key,, described authorization key is encrypted acquisition one ciphertext authorization key at described authorization key ciphering unit;
Step f: described programme content ciphertext, ciphertext programme content key, ciphertext authorization key and a program authority are reached client by IP network.
Preferable, also comprise: step e ': digital signature authentication is carried out in the program application request from client, if by described program authority would be provided.
Wherein, described authorization key is corresponding one by one with described programme content.
Wherein, described programme content ciphertext, ciphertext programme content key send after encapsulating by medium encapsulation unit packing.
Wherein, the programme content among the described step b is corresponding with the program application request of described client.
A kind of decryption method of IPTV is provided at last, and it step that comprises is:
Step a ': receive a programme content ciphertext, a ciphertext programme content key, a ciphertext authorization key and a program authority;
Step b ': utilize the private key in the individual subscriber ECC key, described ciphertext authorization key deciphering is generated expressly authorization key;
Step c ': utilize described plaintext authorization key, described ciphertext programme content key is decrypted, generate expressly programme content key;
Steps d ': utilize described plaintext programme content key, described programme content ciphertext is decrypted, generate expressly programme content, be transferred to player.
Preferable, also comprise: the program application request process that sends client: digital signature is carried out in the program application request that sends client by the private key in the described individual subscriber ECC key.
Beneficial effect of the present invention compared with the prior art is, can not only effectively prevent the user to rating to program share, distribution etc. is illegal propagates, and can effectively resist brute force attack, short, fail safe and the standardization that IPTV is provided of operation efficiency height, key simultaneously based on the internet powerful calculating ability.
Description of drawings
Fig. 1 is the structure chart of the encryption system of IPTV of the present invention;
Fig. 2 is the structure chart of the decryption system of IPTV of the present invention;
Fig. 3 is the flow chart of the encryption method of IPTV of the present invention;
Fig. 4 is the flow chart of the decryption method of IPTV of the present invention.
Embodiment
Below in conjunction with accompanying drawing, be described in more detail with other technical characterictic and advantage the present invention is above-mentioned.
For the encrypting and deciphering system of IPTV; we use the cryptographic algorithm of national Password Management department approval; adopt three layers of key code system of safety; that is: programme content key; authorization key; individual subscriber ECC key is right; and ripe identity identifying technology; operation system is carried out safeguard protection; Verify Your Identity questions that not only can resolution system; simultaneously, also can realize safeguard protection, wherein to program request and live broadcast service; described programme content key; the symmetrical block cipher (SM1) that is the national Password Management of cooperation office uses, and key length 128bit is used for the programme content encryption and decryption.
Authorization key is that the symmetrical block cipher (SM1) of the national Password Management of cooperation office uses, and key length 128bit is used for the programme content key is carried out encryption and decryption.
Individual subscriber ECC key is to being PKI PubK and private key PriK, is to cooperate the ECC asymmetric cryptographic algorithm (SM2) of national Password Management office to use, be used for authorization key is carried out encryption and decryption, and signature and checking during authentication.The digest algorithm that relates to when cooperating the ECC asymmetric cryptographic algorithm ECC of national Password Management office to use also adopts the Secure Hash Algorithm (SM3) of national Password Management office.
See also shown in Figure 1ly, it is the structure chart of the encryption system of IPTV of the present invention; The encryption system of described IPTV, it comprises: a Key Management server 11, also store program content key, authorization key and individual subscriber ECC key are right in order to produce; One content key encryption unit 12 is in order to encrypt production ciphertext content key to described content key by described authorization key; One authorization key ciphering unit 13 in order to by a PKI in the described individual subscriber ECC key described authorization key is encrypted, produces the ciphertext authorization key; One media content ciphering unit 14, in order to by described programme content key to encrypting from the programme content of a media server 4, generate the media program content ciphertext; One medium encapsulation process unit 15 in order to described media program content ciphertext and the packing of ciphertext content key, transfers to a decryption system by an IP network 6; One authorization unit 16 generates an authority in order to utilize described ciphertext authorization key and program authorization message, passes to described decryption system by described IP network 6; Also comprise: a digital signature authentication unit 17, in order to utilize in the described individual subscriber ECC key PKI user's program application signing messages that obtains is verified, and will be verified the operation system 5 of result transmission to an IPTV.After the operation system 5 of described IPTV obtains the request of compliant, just corresponding programme content can be transferred to described media server 4, the encryption system of actual described IPTV mainly is the primary structure as the interactive network TV service end, and in fact described decrypting device is exactly subscription client.
Wherein, described Key Management server 11 comprises:
One programme content key generator 111 is in order to generate described programme content key; One programme content cipher key management unit 114 is in order to store described programme content key; Be used for business tine is carried out the algorithm employing symmetric cryptographic algorithm SM1 of encryption and decryption; Receive the random number from programme content key generator 111 when the programme content key generates, the random data that obtains 128bit length is as the programme content key.
One authorization key maker 112 is in order to generate described authorization key; One authorization key administrative unit 115 is in order to store described authorization key; Be used for the algorithm of programme content key encryption and decryption is adopted symmetric cryptographic algorithm SM1; Receive the random number from authorization key maker 112 when authorization key generates, the random data that obtains 128bit length is as authorization key.
One individual subscriber ECC key is to maker 113, and is right in order to generate described individual subscriber ECC key; One individual subscriber ECC cipher key management unit 116 is in order to store the PKI of described individual subscriber ECC cipher key pair.Be used for the algorithm of authorization key encryption and decryption is adopted ECC algorithm SM2, corresponding secret key to be (PubK, PriK).The ECC key when generating according to the parameter of curve of the ECC algorithm of national Password Management office, through computing obtain the ECC key to (PubK, PriK).
The distribution of programme content key is after encrypting by authorization key, to be distributed to the user with the ciphertext form with program stream.
The distribution of authorization key is after encrypting by PKI PubK in the individual subscriber ECC key, is distributed to the user in the mode of ciphertext form by authority.
Individual subscriber ECC key is when the user uses interactive Web TV system to be registered as system user to the distribution of PubK and PriK, and system is distributed to the user by certain safe channel (writing user terminal as offline mode) with PKI PubK and private key PriK.
The programme content key updating is looked the program demand, and in order to guarantee the fail safe of programme content secret key encryption program, the life cycle of programme content key is shorter, as 30 seconds, during the programme content key updating, is filed an application by operation system, and key management system is finished.
Authorization key upgrades the application of different programs according to the user, is usually initiating newly when professional, is filed an application by operation system, and key management system is finished the renewal of authorization key.
Individual subscriber ECC key is right, usually when finishing, the life cycle of this key changes, the life cycle of this key is generally longer, as 2 years, when if user or system threaten for the security facing that it is right that safety management need be thought individual subscriber ECC key, also can propose the more request of new key, finish the right renewal of this key by certain safe channel by system and user.
See also shown in Figure 2ly, it is the structure chart of the decryption system of IPTV of the present invention; The decryption system of described IPTV comprises: an authorization resolution unit 26, in order to receive and to resolve an authority of obtaining by an IP network 6, resolve generation one program authorization message and ciphertext authorization key; One authorization key decrypting device 23 in order to receiving described ciphertext authorization key, and is decrypted by a private key in the individual subscriber ECC key, generates an authorization key expressly; One terminal key management server 21 in order to private key in the described individual subscriber ECC key to be provided, and is stored described plaintext authorization key; One medium dissection process unit 25 comprises the packet of media program content ciphertext and ciphertext content key in order to obtain one, and distributes; One content key resolution unit 22 in order to obtain described ciphertext content key and described plaintext authorization key, generates a clear content key; One media content decrypting device 24 is decrypted described media program content ciphertext in order to utilize described clear content key, gives the equipment 3 that displays the play with content delivery.Also comprise: a digital signature unit 27, it is encrypted to user's program application signing messages by the private key in the described individual subscriber ECC key with user's program application information, pass to the digital signature authentication unit of enabling decryption of encrypted unit by IP network 6, thereby be decrypted by means of the PKI in the described individual subscriber ECC key, give interactive network TV service system 5 thereby obtain user's program application information.
Wherein, described terminal key management server 21 comprises: an individual subscriber ECC cipher key management unit 216, in order to the private key in the described individual subscriber ECC key to be provided; One authorization key administrative unit 215 is in order to store described plaintext authorization key.
According to above-mentioned encryption system and decryption system, can correspondence go out two methods in fact, promptly a kind of is that encryption method is a kind of for decryption method.See also shown in Figure 3ly, it is the flow chart of the encryption method of IPTV of the present invention;
Step a: a programme content key is sent to a media content ciphering unit and programme content secret key encryption unit;
Step b: a media server is sent to described media content ciphering unit with programme content;
Step c: by described programme content key described programme content is encrypted, generated the programme content ciphertext;
Steps d: utilize an authorization key, to described programme content secret key encryption, generate a ciphertext programme content key in described programme content secret key encryption unit;
Step e: use the PKI in the individual subscriber ECC key,, described authorization key is encrypted acquisition one ciphertext authorization key at described authorization key ciphering unit;
Step e ': digital signature authentication is carried out in the program application request from client, if by described program authority would be provided;
Step f: described programme content ciphertext, ciphertext programme content key, ciphertext authorization key and a program authority are reached client by IP network.
In fact the user needs to register by certain secure way before using interactive network TV service, submits the real user personal information to interactive Web TV system, and interactive Web TV system is preserved individual subscriber ECC public key information., produce PKI PubK and private key PriK in the individual subscriber ECC key, and have individual subscriber ECC cipher key management unit 116 to preserve, (this request also can be individual subscriber key updating request) maker 113 by individual subscriber ECC key; By secured fashion, give the user with the individual subscriber key distribution; The user logins the interactive network TV service system, and use individual subscriber ECC private key asks for an autograph to program audience and submits to interactive Web TV system.System receives the request of Client-initiated program audience, using this program audience request of individual subscriber ECC public key verifications of retaining before the user is to come from this user, promptly realize the affirmation to user identity, checking is passed through back IPTV operation system 5 to media server 4 request content services.Operation system is initiated key to key management system and is generated request, produces programme content key (this key request also can be programme content key updating request) by programme content key generator 111; After described programme content key produced, key management system called authorization key generator 112 and produces authorization key (this key request can be the update request of authorization key), and described authorization key is corresponding one by one with described programme content; The programme content of described media server 4 is by media content ciphering unit 14 time, key management system calls the programme content key programme content is encrypted, call authorization key to the programme content secret key encryption, and ciphertext program and ciphertext are sent to the user by procotol.
Key management system invoke user individual ECC PKI PubK encrypts authorization key, authorization key after the encryption, the authorization message that provides with described authorization unit 16 generates user authorization file, is handed down to the user by http protocol when treating that the user applies for authorizing; Described programme content ciphertext, ciphertext programme content key send after encapsulating by a medium encapsulation process unit 15 packings.
Needing the above-described of explanation is at the cipher key operation under the situation of programme televised live stream, but when the business of download and program request takes place, at the service security demand, no longer need to use the programme content key that programme content is encrypted, but the use authority key is to program encryption, other operation is constant, has just repeated no more here.
See also shown in Figure 4ly, it is the flow chart of the decryption method of IPTV of the present invention.It step that comprises is:
Step a ': receive a programme content ciphertext, a ciphertext programme content key, a ciphertext authorization key and a program authority;
Step b ': utilize the private key in the individual subscriber ECC key, described ciphertext authorization key deciphering is generated expressly authorization key;
Step c ': utilize described plaintext authorization key, described ciphertext programme content key is decrypted, generate expressly programme content key;
Steps d ': utilize described plaintext programme content key, described programme content ciphertext is decrypted, generate expressly programme content, be transferred to player.
Decryption system (user terminal) sends program application request to IPTV operation system 5 after receiving the program stream of encryption, send the program application request process of client:
By the private key PriK in the described individual subscriber ECC key digital signature is carried out in the program application request that sends client.After obtaining the download authorization message, at first resolve the ciphertext of the key of obtaining the authorization by authorization resolution unit 26, and the private key PriK decrypt authorized key ciphertext in the invoke user individual ECC key obtains expressly authorization key, authorization key is imported programme content cipher key decryption unit 22, deciphering programme content key ciphertext obtains the programme content key plain.Next, obtain the programme content key plain by described media content decrypting device 24 after, just can decipher, and the original program information after will decipher outputs to display device broadcast 3 programme content, finish program audience.
Same corresponding top encryption method, if user terminal is when receiving the live TV stream program of interactive Web TV system end, can carry out according to aforesaid operations, if program is program request or downloaded forms, homologous ray end correspondence, do not comprise the decryption oprerations of content key, only programme content is decrypted and gets final product to the authorization key deciphering and with it.
The above only is preferred embodiment of the present invention, only is illustrative for the purpose of the present invention, and nonrestrictive.Those skilled in the art is understood, and can carry out many changes to it in the spirit and scope that claim of the present invention limited, revise, even equivalence, but all will fall within the scope of protection of the present invention.

Claims (14)

1, a kind of encryption system of IPTV is characterized in that, it comprises:
One Key Management server, also store program content key, authorization key and individual subscriber ECC key are right in order to produce;
One content key encryption unit is in order to encrypt production ciphertext content key to described content key by described authorization key;
One authorization key ciphering unit in order to by a PKI in the described individual subscriber ECC key described authorization key is encrypted, produces the ciphertext authorization key;
One media content ciphering unit, in order to by described programme content key to encrypting from the programme content of a media server, generate the media program content ciphertext;
One medium encapsulation process unit in order to described media program content ciphertext and the packing of ciphertext content key, transfers to a decryption system by an IP network;
One authorization unit generates an authority in order to utilize described ciphertext authorization key and program authorization message, passes to described decryption system by described IP network.
2, the encryption system of IPTV according to claim 1 is characterized in that, described Key Management server comprises:
One programme content key generator is in order to generate described programme content key;
One programme content cipher key management unit is in order to store described programme content key;
One authorization key maker is in order to generate described authorization key;
One authorization key administrative unit is in order to store described authorization key;
One individual subscriber ECC key is to maker, and is right in order to generate described individual subscriber ECC key;
One individual subscriber ECC cipher key management unit is in order to store the PKI of described individual subscriber ECC cipher key pair.
3, the encryption system of IPTV according to claim 2, it is characterized in that, also comprise: a digital signature authentication unit, in order to utilizing in the described individual subscriber ECC key PKI that the user's program application signing messages that obtains is verified, and will verify the operation system of result transmission to an IPTV.
4, the encryption system of IPTV according to claim 2, it is characterized in that, also comprise: described programme content key generator, authorization key maker and described individual subscriber ECC key all comprise maker: a tandom number generator.
5, a kind of decryption system of IPTV is characterized in that, it comprises:
One authorization resolution unit in order to receive and to resolve an authority of obtaining by an IP network, is resolved generation one program authorization message and ciphertext authorization key;
One authorization key decrypting device in order to receiving described ciphertext authorization key, and is decrypted by a private key in the individual subscriber ECC key, generates an authorization key expressly;
One terminal key management server in order to private key in the described individual subscriber ECC key to be provided, and is stored described plaintext authorization key;
One medium dissection process unit comprises the packet of media program content ciphertext and ciphertext content key in order to obtain one, and distributes;
One content key resolution unit in order to obtain described ciphertext content key and described plaintext authorization key, generates a clear content key;
One media content decrypting device is decrypted described media program content ciphertext in order to utilize described clear content key, gives the equipment that displays the play with content delivery.
6, the decryption system of IPTV according to claim 5 is characterized in that, described terminal key management server comprises:
One individual subscriber ECC cipher key management unit is in order to provide the private key in the described individual subscriber ECC key;
One authorization key administrative unit is in order to store described plaintext authorization key.
7, the decryption system of IPTV according to claim 6, it is characterized in that, also comprise: a digital signature unit, it is encrypted to user's program application signing messages by the private key in the described individual subscriber ECC key with user's program application information.
8, a kind of encryption method of IPTV is characterized in that, it step that comprises is:
Step a: a programme content key is sent to a media content ciphering unit and programme content secret key encryption unit;
Step b: a media server is sent to described media content ciphering unit with programme content;
Step c: by described programme content key described programme content is encrypted, generated the programme content ciphertext;
Steps d: utilize an authorization key, to described programme content secret key encryption, generate a ciphertext programme content key in described programme content secret key encryption unit;
Step e: use the PKI in the individual subscriber ECC key,, described authorization key is encrypted acquisition one ciphertext authorization key at described authorization key ciphering unit;
Step f: described programme content ciphertext, ciphertext programme content key, ciphertext authorization key and a program authority are reached client by IP network.
9, the encryption method of IPTV according to claim 8 is characterized in that, also comprises: step e ': digital signature authentication is carried out in the program application request from client, if by described program authority would be provided.
10, the encryption method of IPTV according to claim 9 is characterized in that, described authorization key is corresponding one by one with described programme content.
11, the encryption method of IPTV according to claim 10 is characterized in that, described programme content ciphertext, ciphertext programme content key send after encapsulating by medium encapsulation unit packing.
12, the encryption method of IPTV according to claim 9 is characterized in that, the programme content among the described step b is corresponding with the program application request of described client.
13, a kind of decryption method of IPTV is characterized in that, it step that comprises is:
Step a ': receive a programme content ciphertext, a ciphertext programme content key, a ciphertext authorization key and a program authority;
Step b ': utilize the private key in the individual subscriber ECC key, described ciphertext authorization key deciphering is generated expressly authorization key;
Step c ': utilize described plaintext authorization key, described ciphertext programme content key is decrypted, generate expressly programme content key;
Steps d ': utilize described plaintext programme content key, described programme content ciphertext is decrypted, generate expressly programme content, be transferred to player.
14, the decryption method of IPTV according to claim 13, it is characterized in that, also comprise: the program application request process that sends client: digital signature is carried out in the program application request that sends client by the private key in the described individual subscriber ECC key.
CN2008101174503A 2008-07-30 2008-07-30 Encrypting/decrypting system and encrypting/decrypting method for interactive network television Active CN101640785B (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN2008101174503A CN101640785B (en) 2008-07-30 2008-07-30 Encrypting/decrypting system and encrypting/decrypting method for interactive network television

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
CN2008101174503A CN101640785B (en) 2008-07-30 2008-07-30 Encrypting/decrypting system and encrypting/decrypting method for interactive network television

Publications (2)

Publication Number Publication Date
CN101640785A true CN101640785A (en) 2010-02-03
CN101640785B CN101640785B (en) 2011-08-17

Family

ID=41615537

Family Applications (1)

Application Number Title Priority Date Filing Date
CN2008101174503A Active CN101640785B (en) 2008-07-30 2008-07-30 Encrypting/decrypting system and encrypting/decrypting method for interactive network television

Country Status (1)

Country Link
CN (1) CN101640785B (en)

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102238422A (en) * 2010-05-07 2011-11-09 航天信息股份有限公司 Digital television broadcasting conditional access system
CN102325270A (en) * 2011-09-13 2012-01-18 北京网康科技有限公司 Network video identification method and network video identification device thereof
CN102857522A (en) * 2012-10-12 2013-01-02 广州市品高软件开发有限公司 Identity authentication method and system for cloud computing desktop terminal
CN102857821A (en) * 2011-06-30 2013-01-02 航天信息股份有限公司 IPTV (internet protocol television) security terminal
CN102917259A (en) * 2012-10-31 2013-02-06 深圳市多尼卡电子技术有限公司 Method, system and server for playing programs in encryption manner
CN107547918A (en) * 2016-06-28 2018-01-05 中兴通讯股份有限公司 The methods, devices and systems that a kind of IPTV channel plays safely
CN108683499A (en) * 2018-05-15 2018-10-19 北京智芯微电子科技有限公司 Minimize the terminal device initial key distribution method and device of key management cost

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN109726569A (en) * 2018-12-24 2019-05-07 无锡市同威科技有限公司 One kind plus/two channel decision system of DecryptDecryption Dynamic data exchange and its application

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6718502B1 (en) * 2000-08-11 2004-04-06 Data Storage Institute Precoders for partial response channels
CN100428140C (en) * 2007-01-05 2008-10-22 东南大学 Implement method of elliptic curve cipher system coprocessor
CN100555936C (en) * 2007-01-08 2009-10-28 中国信息安全产品测评认证中心 A kind of method that in smart card and USB flash disk equipment complex, improves access security

Cited By (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN102238422A (en) * 2010-05-07 2011-11-09 航天信息股份有限公司 Digital television broadcasting conditional access system
CN102238422B (en) * 2010-05-07 2013-08-28 航天信息股份有限公司 Digital television broadcasting conditional access system
CN102857821A (en) * 2011-06-30 2013-01-02 航天信息股份有限公司 IPTV (internet protocol television) security terminal
CN102325270A (en) * 2011-09-13 2012-01-18 北京网康科技有限公司 Network video identification method and network video identification device thereof
CN102857522A (en) * 2012-10-12 2013-01-02 广州市品高软件开发有限公司 Identity authentication method and system for cloud computing desktop terminal
CN102917259A (en) * 2012-10-31 2013-02-06 深圳市多尼卡电子技术有限公司 Method, system and server for playing programs in encryption manner
CN107547918A (en) * 2016-06-28 2018-01-05 中兴通讯股份有限公司 The methods, devices and systems that a kind of IPTV channel plays safely
CN108683499A (en) * 2018-05-15 2018-10-19 北京智芯微电子科技有限公司 Minimize the terminal device initial key distribution method and device of key management cost
CN108683499B (en) * 2018-05-15 2021-03-12 北京智芯微电子科技有限公司 Terminal equipment initial key distribution method and device for minimizing key management cost

Also Published As

Publication number Publication date
CN101640785B (en) 2011-08-17

Similar Documents

Publication Publication Date Title
CN103354998B (en) Control word is protected
CN101640785B (en) Encrypting/decrypting system and encrypting/decrypting method for interactive network television
CN101076109B (en) Two-way CA system of digital TV-set and method for ordering and cancelling programm based on it
CN108881205B (en) HLS streaming media safe playing system and playing method
US8176331B2 (en) Method to secure data exchange between a multimedia processing unit and a security module
CA2621091A1 (en) Method and apparatus for distribution and synchronization of cryptographic context information
CN103841469A (en) Digital film copyright protection method and device
CN102625188B (en) Method and system for displaying program
CN106803980B (en) Guard method, hardware security module, master chip and the terminal of encrypted control word
CN102917252B (en) IPTV (internet protocol television) program stream content protection system and method
CN101521668B (en) Method for authorizing multimedia broadcasting content
CN100521771C (en) A conditional reception system merging Internet and cable television network environments
CN105915345A (en) Realization method for authorized production and reform in home gateway device production testing
CN105376221A (en) Game message encryption mechanism based on dynamic password, and game system
CN101202883A (en) System for numeral copyright management of IPTV system
CN102510374B (en) License management method and device capable of detecting clone for front-end system
CN101505400A (en) Bi-directional set-top box authentication method, system and related equipment
CN102694819A (en) Streaming media transmission method based on broadcast encryption
CN103546767A (en) Content protection method and system of multimedia service
CN106341424B (en) Video encryption system based on identity authentication and implementation method
CN101500146A (en) Digital television receiving control method and apparatus based on bi-directional network
CN101500147B (en) Digital television receiving control method and apparatus based on bi-directional network
CN101552793B (en) Method for downloading digital multimedia file and program order commission
JP2013042331A (en) Unidirectional communication system, method, and program
CN106303575B (en) Video encryption system based on domestic commercial cipher module and implementation method

Legal Events

Date Code Title Description
C06 Publication
PB01 Publication
C10 Entry into substantive examination
SE01 Entry into force of request for substantive examination
C14 Grant of patent or utility model
GR01 Patent grant