Realize the method and the system thereof of receiving terminal for digital television separation between machine and card
Technical field
The present invention relates to the receiving terminal technology in the digital TV field, relate in particular to the signal demodulation techniques.
Background of invention
Along with the development of Digital Television with popularize, domestic many operators have made up digital TV network and have started operation, and the receiving terminal for digital television (including but not limited to Digital Television or set-top box etc.) as user terminal just progresses into increasing family thus.
The operation of described receiving terminal is except relying on hardware system and software systems support, also to rely on the support of CA (Conditional Access: condition receives) system, any receiving terminal product must be finished integrated with the CA system earlier dropping into before the Digital Television operation system uses, be that receiving terminal manufacturer at first must be by obtaining the CA storehouse to CA manufacturer payment high cost, this CA storehouse could be integrated in the software of receiving terminal, could drop in the Digital Television operation system after the test through CA manufacturer and use thereafter.
Obviously, owing to CA manufacturer and receiving terminal manufacturer are the increases that different manufacturers causes the receiving terminal cost, simultaneously also influence the flexibility of receiving terminal aspect operation and maintenance, the more important thing is separate (just so-called " separation between machine and card ") that can't realize receiving terminal and Digital Television card (i.e. the function card that is built-in with chip of execution decoding function under the CA system management).
Can't realize the problem of separation between machine and card for solving above-mentioned receiving terminal, technical scheme commonly used in the prior art has following two kinds: first kind is called " lesser calorie " scheme, also be smart card solution, its smart card (carrying out the Digital Television card of decoding function) uses the ISO7816 interface, the functional module relevant with carrying out the CA system management function divided into " general module " and " private module " two large divisions, that is: place receiving terminal as general module descrambler under the CA system management and CA system common software, and application programs such as the exclusive charging mechanism of CA system management and customer data management are inserted in the individual chips as the private module, for example the private module can be made IC-card as credit card-sized.
In this " lesser calorie " scheme, only have simple MCU, ROM, EEPROM and be stored in the card operating system of ROM inside, therefore have the lower-cost advantage of chip production, research and development and receiving terminal, but also have following shortcoming simultaneously: data processing speed is slow, the fail safe of CA system reduces, the expansion of CA systemic-function is restricted.
For this reason, relevant departments have released second kind of scheme, promptly so-called " kilocalorie scheme ", be called PCMCIA (Personal Computer Memory Card International Association: PCMCIA (personal computer memory card international association)) card scheme again, 16 slots of this scheme use are counted pcmcia interface with 68 pin and are connected, block mid-have powerful arithmetic element and internal memory, can be with the descrambler under the CA system management, after related software such as customer account management and deciphering all writes in the pcmcia card, by and receiving terminal between general-purpose interface, with above-mentioned be in the middle of the slot of CA module insertion machine top box of core with the pcmcia card, reach the effect that CA system and set-top box are separated fully, and needn't as before this must be in set-top box or Digital Television integrated above-mentioned CA module.This scheme has receiving terminal research and development and production cost is low and the standard operation amount is little advantage, but still has the defective that the R﹠D cycle grows, and the lesser calorie in first kind of scheme, and pcmcia card R﹠D costs and manufacturing cost are higher.
This shows; though above-mentioned two kinds of schemes have realized separation between machine and card to a certain extent; and can realize the standardization and the large-scale production of receiving terminal for digital television; but because the separation between machine and card of two kinds of schemes all realizes by developing a card; therefore when the function of CA system need be revised or increase, perhaps change card again, perhaps upgrade; can cause the wasting of resources and increase use cost and change card, upgrading then exists the problem of upgrade maintenance inconvenience.The more important thing is,, therefore really do not realize separation between machine and card because the Digital Television card must mate with certain specific receiving terminal.
Also there is at present a kind of technology of attempting to solve the separation between machine and card problem, the condition receiving processor and the method for reseptance that are based on shared module architecture that it adopts.This technology is with a CAP (Conditional Access Processor: the condition receiving processor) finish condition and receive required repertoire who is independent of receiving terminal, wherein CAP and certain conditions receiving software binding, constitute a certain conditions receiver module, CAP also is connected with digital television receiver, import Entitlement Control Message (ECM) from receiver, Entitlement Management Message (EMM) and scrambled signals or the data stream encrypted relevant with program, by carrying out the condition receiving software of binding, finish and comprise deciphering, the condition of operation such as descrambling receives to be handled, and signal or deciphering back data flow output in the receiver behind the generation descrambling.This method possesses that function is strong, high security, high flexibility and adaptability, low cost, making and simple operation and other advantages, but the defective that exists is to need the data-interface of supporting that 36M is above, and the cost of this interface is higher relatively.In addition, hand to CAP after signal receives through receiver and handle, data flow or signal after will deciphering after CAP handles are back to receiver again, and it is bigger to cause handling time-delay thus.
It is to be noted, kilocalorie scheme and lesser calorie scheme and above-mentionedly all have a critical defect: really do not realize separation between machine and card based on the technology of sharing the module architecture, its reason is that any receiving terminal for digital television all needs one and sticks into row coupling, and current one family usually has many TVs, must have many deciphering smart cards this moment, therefore the charge to the user has just become problem with the smart card payroll management: if many sheet smart cards that the user has all need to collect same expense, be too high input so for the user; If second of opening an account of user even the 3rd card are free or lower than first card charge, user who has opened an account can apply for that then a lot of secondaries sticks into the row profiteering or uses in other place so.In addition, when adopting this several technology, the interface between TV card or CAP and the receiving terminal for digital television is also indeterminate, and followingly is difficult to unifiedly, and a lot of functions such as the binding machine and card between CA system and the receiving terminal for digital television all can't realize simultaneously.
Summary of the invention
The object of the present invention is to provide the method and the system thereof that can realize the receiving terminal for digital television separation between machine and card, solve the problem that can not really realize separation between machine and card in the prior art.
For achieving the above object, a kind of method that realizes the receiving terminal for digital television separation between machine and card provided by the invention may further comprise the steps:
(1) CA gateway (being independent of the module that is used for the executive condition receiving function of receiving terminal) digital television signal accessing, solve CW (Control Word: control word), with CW send to by the authentication corresponding receiving terminal;
(2) receiving terminal by authentication utilizes CW that digital television signal is carried out descrambling.
Wherein, the process in the described step (1) specifically may further comprise the steps:
The a11CA gateway is encrypted before transmission the CW that solves;
The a12CA gateway can authenticate with all receiving terminals in its communication context being in when sending CW, sends the corresponding CW key that is used to decipher CW to the receiving terminal by authentication;
A13 receives the CW key by the receiving terminal of authentication, utilizes the CW key to solve corresponding C W.
Wherein, the process that solves CW can realize in the following manner: the CA gateway is by the poll to signal frequency point, each frequency is decoded respectively, obtain ECM corresponding and EMM with corresponding frequency, utilize described ECM and EMM, use PDK (the Personal Distribute Key: individual distributing key) solve the CW corresponding in the smart card with each frequency.
Wherein, the CA gateway can be independent of the direct digital television signal accessing of receiving terminal.
Wherein, the process that solves CW can also realize in the following manner: receiving terminal sends positioning service information to the CA gateway, and the CA gateway solves corresponding C W according to this positioning service information.Particularly, the process that solves CW under this mode specifically may further comprise the steps:
When each affirmation of b11 receiving terminal or replacing need the decoded digital TV signal, determine the positioning service information of respective signal and send to the CA gateway;
Its receiving terminal that sends positioning service information of b12CA gateway subtend authenticates, and receiving terminal and corresponding positioning service information by authentication are bound and record;
The corresponding signal frequency point of positioning service information locking that b13CA gateway utilization binding receiving terminal sends, respective digital TV signal on this frequency is carried out the demodulation sign indicating number, obtain corresponding ECM and EMM, utilize described ECM and EMM, use the PDK in the smart card to solve the CW corresponding with described signal;
Wherein, the CA gateway is sent the receiving terminal that CW after positioning service information regularly solves renewal sends to correspondence according to the corresponding receiving terminal that writes down and institute thereof in step b12.
Wherein, described positioning service information comprises frequency, modulation system, symbol rate and the service number of serving the place.
Wherein, CA gateway described in step a12 or the b12 and described receiving terminal authenticate specifically and may further comprise the steps:
The receiving terminal information that c11 and CA gateway can carry out corresponding binding is issued in the CA gateway and record by the CA system in advance, the CA gateway in view of the above with the receiving terminal binding that respectively has the corresponding mandate of CA system, the receiving terminal after bound has corresponding authentication information and authentication password;
The c12 receiving terminal is when start or regularly initiate corresponding binding authentication request to the CA gateway, receives that CA gateway authentication response back sends authentication password to the CA gateway;
The c13CA gateway carries out authentication determination according to the authentication password received and the binding information of storing in step c11, and if by authentication the receiving terminal that will send this password be labeled as by corresponding binding authentication.
Described CA gateway and receiving terminal carry out communication and can adopt wireless or the wire communication technology, and wherein wireless communication technique comprises infrared technique, Bluetooth technology and WLAN technology, and the wire communication technology comprises netting twine and Serial Port Line technology.
Described digital television signal comprises radiofrequency signal, ground signal, satellite-signal and hand-held signal.
The invention also discloses a system that can be used for realizing the receiving terminal for digital television separation between machine and card, this system comprises CA system, CA gateway and receiving terminal.
Wherein, described CA system is positioned at operator's service providing end, be used to store the receiving terminal binding information and provide described binding information to the CA gateway, described CA gateway is positioned at user side, be integrated with digital television signal descrambler, CA common software, contain the CA application program and the digital television intelligent card of exclusive charging mechanism of CA manufacturer and customer data management information, be used for the receiving terminal of initiating request is carried out binding authentication and is used for the digital television signal descrambling for the receiving terminal by described binding authentication provides CW.
Described system can comprise two or more receiving terminal for digital television.
Use the present invention, the independent decryption system of being set up is with low cost, and function is fixed, thus and realized the real separation between machine and card of a card multimachine.Simultaneously, the functions relevant with CA such as mail, note, binding machine and card, zone binding, father and mother's control all can rely on this platform to realize flexibly, thereby communication process is simple and reliable, and implementation is flexible, and is compatible strong.
Description of drawings
Fig. 1 is the networking diagram of CA gateway and receiving terminal;
Fig. 2 is CA gateway receiving digital television signal and the flow chart of broadcasting CW;
Fig. 3 is a CA gateway authentication flow chart;
Fig. 4 is receiving terminal authentication and CW key updating flow process;
Fig. 5 is a receiving terminal descrambling flow chart;
Fig. 6 inquires about CW for CA gateway access wheel and broadcasts flow chart;
Fig. 7 upgrades the receiving terminal information flow chart for the CA gateway;
Fig. 8 is the system diagram that CA system, CA gateway and receiving terminal are formed.
Embodiment
Below in conjunction with the accompanying drawing embodiment that develops simultaneously, describe the present invention.
The invention discloses a kind of method that realizes the receiving terminal for digital television separation between machine and card, and a system that realizes this method.Wherein this method comprises: CA gateway digital television signal accessing, solve CW, and CW sent to receiving terminal for the program demodulation, receiving terminal is when receiving CW and storing, receiving digital television signal is decoded, obtain the signal or the data stream encrypted of scrambling, the CW that utilizes aforementioned storage carries out descrambling to the signal of scrambling or data stream encrypted etc. and drops into and play.
The embodiment that meets inventive concept is described below.
Fig. 1 to Fig. 5 has illustrated the separation between machine and card scheme of the inventive method.As shown in Figure 1, CA gateway digital television signal accessing (cable signal) solves CW, CW is sent to receiving terminals such as corresponding digital TV or set-top box.Each corresponding receiving terminal is when receiving CW and storage, and digital television signal accessing (cable signal) and demodulation obtain the signal or the data stream encrypted of scrambling, and the CW that utilizes aforementioned storage is to this signal or data flow descrambling and drop into and play or use.
In a preferred embodiment of the present invention, the CA gateway can solve the CW word and and then is implemented in and obtains signal or data flow behind the corresponding descrambling under the mode of separation between machine and card by all frequencies of Digital Television being carried out poll.
As shown in Figure 2, the process that the CA gateway received and broadcast CW is: the demodulation from digital signal of CA gateway, decoding obtain network information table (NIT), and jump to the initial frequency of digital television signal according to NIT, receive the ECM and the EMM of current frequency.The smart card that is integrated in the CA gateway demodulates CW according to the ECM and the EMM that receive, and it is encrypted, by the CW behind wireless or wired mode broadcast enciphering.At last, jump to next frequency according to NIT and repeat above-mentioned flow process.
In the time of CW after the CA gateway broadcasts is encrypted, initiate the process that authenticates with receiving terminal, so that to authorizing receiving terminal to send the corresponding secret key that is used to decipher CW.As shown in Figure 3, at first, the CA gateway detects the authentication request that whether exists from receiving terminal, if there is no should ask, and then carries out and detects whether there is authentication request again after a time-delay is ordered; Can if there is authentication request, the CA gateway authenticates this authentication request, by the binding authentication of binding machine and card authentication or CA gateway and receiving terminal with the receiving terminal of determining the transmission authentication request; Can not be if send the receiving terminal of authentication request by above-mentioned authentication, then the CA gateway detects whether there is authentication request again after carrying out a time-delay order; Passed through above-mentioned authentication if send the receiving terminal of authentication request, then the CA gateway sends the key that is used to decipher CW to this receiving terminal.
As shown in Figure 4, the flow process of receiving terminal initiation and CA gateway authentication and CW key updating.In this flow process, receiving terminal at first sends authentication request to the CA gateway.If do not receive the response of CA gateway, receiving terminal is carried out a time-delay order, resends authentication request then.If receive the authentication response that the CA gateway sends, receiving terminal is to the binding information of CA gateway transmitter card binding authentication information or CA gateway and receiving terminal.After the above-mentioned authentication information that the CA gateway sends receiving terminal authenticated, if confirm this receiving terminal not by above-mentioned binding authentication, then receiving terminal was carried out a time-delay order, sends authentication request to the CA gateway again then.If above-mentioned authentication request has been passed through the binding machine and card of CA gateway or the authentication of CA gateway and receiving terminal binding, then receiving terminal receives the CW key from the CA gateway, and this key is preserved (if receiving first) or upgraded (receiving if repeat) operation.Carry out timing authentication or CA gateway to the CW key regularly more under the news at CA gateway and receiving terminal, receiving terminal is preserved the CW key that is received or is upgraded after the operation, also carry out a time-delay order (shown in the part that is labeled as " time-delay 2 " among Fig. 4), and send authentication request to the CA gateway again.
After receiving the CW key of CA gateway transmission, receiving terminal is carried out the flow process of descrambling.As shown in Figure 5, at first, receiving terminal receives also preserving with corresponding encrypted each CW of respective services of CA gateway broadcasts or upgrades.Then, utilize CW key couple each CW corresponding that receives in the abovementioned steps to be decrypted, and use the CW after the deciphering that respective service is carried out descrambling, then the service behind the descrambling is decoded or data interpretation and dropping into is play or used with respective service.
In another preferred embodiment of the present invention, the required CW of positioning service validation of information receiving terminal that the CA gateway sends according to receiving terminal, and in view of the above the signal or the data flow of corresponding frequency are carried out descrambling or deciphering.
As shown in Figure 6, relevant frequency is being carried out poll with before solving the CW word, the CA gateway at first carries out binding authentication to the related service locating information that receiving terminal sends, to judge the legitimacy of this terminal.The process of authentication comprises: the CA gateway adopts wireless or wire communication technology, authenticates with receiving terminal in the given range.The number of the receiving terminal that the CA gateway can be bound is issued on the CA gateway by the CA system that is positioned at supplier's end and is recorded in smart card or other positions of CA gateway, smart card or CA gateway and each mandate receiving terminal are bound simultaneously, receiving terminal after bound just has correct authentication information, can obtain corresponding authentication password.After the receiving terminal of access authentication password sends authentication request,, then send authentication password, just the CA gateway receives behind the authentication password that the receiving terminal with correspondence is labeled as by authentication to the CA gateway if receive the authentication response that the CA gateway sends.
After having carried out the judgement of above-mentioned identifying procedure, if described terminal illegal (not by authentication) is then ignored the information of this terminal transmission and received positioning service information again; If described terminal legal (having passed through authentication) is then judged the record case of this terminal: if record is arranged then upgrade the locating information of this terminal, if no record then create the locating information of this terminal.
Receiving terminal in above CA gateway and the given range authenticates the wireless communication technique that can adopt and comprises wireless technologys such as infrared technique, Bluetooth technology and WLAN, and the wire communication technology that can adopt comprises wire communication technology such as netting twine, Serial Port Line.
As shown in Figure 7, the utilization of CA gateway has obtained the corresponding service of positioning service information locking of the receiving terminal for digital television transmission of CA system authorization, and respective service carried out the demodulation sign indicating number, obtain ECM and the EMM corresponding with this service, use the PDK in the smart card that ECM and EMM are decrypted simultaneously, solve the CW of respective service and send to corresponding terminal; As shown in Figure 7, exist under the situation of privacy requirements, this CW is carried out encrypting and transmitting give relevant terminal, sending corresponding C W key simultaneously.At this moment, whether the CA gateway authorizes receiving terminal to send by last to this record is judged, if not the positioning service information of then extracting next receiving terminal, if then extract the positioning service information that first authorizes receiving terminal.Receiving terminal directly receives and demodulates the digital television signal of scrambling from the corresponding frequency of digital television signal, after receiving CW, utilize the above-mentioned CW key that receives that corresponding CW is decrypted, the CW after the utilization deciphering carries out descrambling and broadcast or use to the scrambled number signal of process demodulation.At last, the CA gateway sends to the bind request terminal according to requesting terminal number that it write down and the CW that will serve after locating information regularly will be upgraded;
The above digital television signal comprises radiofrequency signal, ground signal, satellite-signal and hand-held signal.
System disclosed by the invention comprises CA system, CA gateway and receiving terminal, as shown in Figure 8.
Wherein, described CA system is positioned at operator's service providing end, and the management function that main executive condition receives except that being used to insert the digital television service signal, also being used for setting and storing the receiving terminal binding information and provide described binding information to the CA gateway.
Described CA gateway is positioned at user side, be integrated with digital television signal descrambler, CA common software, contain the CA application program and the digital television intelligent card of exclusive charging mechanism of CA manufacturer and customer data management information, import receiving terminal binding authentication information by HFC (Hybrid fiber coax: optical fibre-coaxial cable mixes) network from the CA system, the receiving terminal of initiating request is carried out binding authentication.After confirming to have the receiving terminal of binding mandate, by from CA system receiving digital television service signal (cable signal), solve ECM and EMM and solve the corresponding CW that respectively authorizes receiving terminal required in view of the above, and be sent to corresponding receiving terminal and be used for the digital television signal descrambling.Requiring under the situation that CW is encrypted, when the CA gateway sends CW to receiving terminal, generating the CW key corresponding and send to the mandate receiving terminal with this CW.
In this system, the quantity of receiving terminal more than one, comprises more than one set-top box at least, perhaps more than one Digital Television, the set of perhaps more than one Digital Television and set-top box.Under the management of CA system, a CA gateway can receive service for above-mentioned a plurality of receiving terminals provide condition simultaneously.Each receiving terminal inserts digital television service signal (cable signal) and demodulation by HFC from the CA system, and the signal descrambling after utilizing CW that the CA gateway provides to demodulation obtains behind the descrambling signal or data flow and drop into playing or using.
The above only is preferred embodiment of the present invention, and is in order to restriction the present invention, within the spirit and principles in the present invention not all, any modification of being made, is equal to replacement, improvement etc., all should be included within protection scope of the present invention.