Utility model content
The utility model for solve the application function of existing Set Top Box single, cannot shared resource and do not possess Information Security Mechanism and cannot ensure the problem of the information security in internet, applications, and can not realize the functions such as digital copyright management, a kind of Intelligent set top box with digital copyright management and information security based on DVB-S is provided.
Intelligent set top box based on DVB-S, DVB-S receiver module, digital audio/video encoding and decoding and browser module, deciphering module, VPN and the wireless routing module, PKI and CPK information security module, intelligent card read/write device and USB-KEY interface module and the digital rights management module that comprise WiFi module, hard disk or SD card, digital switch power module and be integrated in embedded main board; Described DVB-S receiver module and hard disk or SD link and connect, digital rights management module is connected with USB-KEY interface module with hard disk or SD card, deciphering module, PKI and CPK information security module and intelligent card read/write device respectively, described PKI is connected with wireless routing module with WiFi module and VPN with CPK information security module, deciphering module is connected with digital audio/video encoding and decoding and browser module, and described digital switch power module is embedded main board and above-mentioned each module for power supply.
The alternating voltage of the input of described digital switch power module is 90V~260V, the direct voltage of output is+3V ,+5V or+12V.
DVB-S receiver module described in the utility model receives the digital media content that possesses digital publishing rights and the data message distribution version that large data digital is published directed distribution; And the information of reception is sent to hard disk or the management of SD card classified storage; Digital audio/video encoding and decoding and browser module: the information after the deciphering that receiving and deciphering module transmits, and decryption information decoding broadcasting or browser are opened, by demonstration output module, export; Deciphering module: the digital media content that possesses digital publishing rights that digital rights management module is read from hard disk or SD card and data message distribution version, use the key information real time decrypting of corresponding distribution version, and the information after deciphering is sent to digital audio/video encoding and decoding and browser module; VPN and wireless routing module: build virtual radio dedicated network, realize all smart machine interconnected communications and data real-time exchange based in special wireless network coverage; PKI and CPK information security module: information realization PKI public-key cryptosystem and the information security standard of CPK Conbined public or double key cryptographic system and safety certification and the signature verification of digital certificate of the digital content distribution version that digital rights management module is transmitted; Other intelligent terminal establishing the link via VPN and wireless routing module and WiFi module and Intelligent set top box is carried out to digital signature and authentication; Described digital rights management module: according to the digital media content that possesses digital publishing rights of storing in hard disk or SD card and data message distribution version, the sign of corresponding selection digitized content and data message distribution version, and according to the KEY equipment of intelligent card read/write device and the insertion of USB-KEY interface module, by PKI and CPK information security module verification digital certificate, corresponding authorization key information is inquired about in being identified at of the digitized content of choosing according to correspondence and data message distribution version in KEY equipment; And by PKI and CPK information security module verification legitimacy, then decrypt the digitized content of corresponding sign and the key information of data message distribution version, and be sent to deciphering module.
Operation principle of the present utility model: the intelligent terminal product publishing and distributing based on large data digital that Intelligent set top box described in the utility model been has mainly has been researched and developed on embedded system platform.The large data content receive mode of the digital publishing digital distribution of the utility model based on DVB-S is fused on an embedded platform, in the utility model product the inside, realizes.In application design, realized information security certification mechanism and the digital certificate of the double secret key management system of PKI+CPK.Also VPN VPN (virtual private network) and the wireless routing function modular design based on WiFi are realized.In the embedded system platform based on Andriod4.0 system and above version, design has realized U-Console intelligent platform system simultaneously.Make the utility model in network application and information security, obtain reliable security mechanism, realized multisystem platform (Windows operating system in application scenario, IOS operating system, Andriod operating system) IT product can interconnect with the utility model Realization of Product, real time data is mutual, mutually control, or realize and interconnecting via the utility model, real time data is mutual, the application such as mutually control, the Digital Media intelligent terminal product that the utility model publishes and distributes as large data digital has well been realized the digital copyright management of large data digital issued content.
The beneficial effects of the utility model:
One, in Intelligent set top box described in the utility model, realized U-Console intelligent platform, realized at the various computers that Windows system platform, IOS system platform, Andriod system platform have been installed, intelligent terminal (Pad, mobile phone), can both interconnect with the utility model product, control mutually, secure data is mutual.Make simultaneously various computer equipments and intelligent terminal can be by the utility model Realization of Product interconnecting between them, control mutually, secure data is mutual.
Two, Intelligent set top box described in the utility model has been realized PKI+CPK double-point information security authentication mechanism, make the utility model product in internet, applications, there is high-intensity authentic communication safety guarantee, can be good at being applied to have in the system and platform of information security and digital identification authentication for internet terminal.
Three, the utility model has been realized the digital publishing distribution intelligent terminal Set Top Box design receiving based on DVB-S.Four, the utility model possesses VPN and wireless routing function, can and well realize digital copyright management mechanism as the intelligent terminal product of Digital Media as the gateway of internet, applications and the equipment of information security certification mechanism.
Embodiment
Embodiment one, in conjunction with Fig. 1 and Fig. 2, present embodiment is described, the Intelligent set top box based on DVB-S described in present embodiment, on embedded system platform, design realizes U-Console intelligent platform system, comprise DVB-S receiver module, hard disk or SD card, WiFi module, smart card reader module, keyboard and infrared receiving module, digital audio/video encoding and decoding and browser module that embedded main board and plate thereof carry, deciphering module, digital rights management module, PKI and CPK information security module, with USB-KEY interface module, VPN and wireless routing module, input/output interface module, with digital switch power module, based on embedded main board and system, described DVB-S receiver module and hard disk or SD link and connect, digital rights management module is connected with USB-KEY interface module with hard disk or SD card, deciphering module, PKI and CPK information security module and intelligent card read/write device respectively, described PKI is connected with WiFi module with wireless routing module with VPN with CPK information security module, deciphering module is connected with digital audio/video encoding and decoding and browser module, and described digital switch power module is above-mentioned each module for power supply,
In conjunction with Fig. 1, embedded main board comprises master chip, Flash and Dram module and each input/output interface and bus interactive module, mainly contain with lower interface: SATA hard-disk interface, serial ports, network interface, USB2.0 interface, digital video HDMI delivery outlet, component vide delivery outlet (YPbPr), stereo audio delivery outlet, fiber-coaxial digital audio delivery outlet, infrared signal receiving port, Multi-Function Keyboard special purpose interface, signal designation output interface, mains switch input interface etc.
VPN and without line module: realize VPN (virtual private network) and the wireless routing function based on WiFi.PKI and CPK information security module, information security unit, realizes the information security certification based on PKI system and CPK system, digital certificate.Storage compartment is Large ca-pacity and high speed hard-disk/SD card; Intelligent card read/write device and USB-KEY interface module: IC standard card reader deck, be mainly used in connecting smart card-KEY and USB-KEY, realize the key authorization file interaction of digital content.DVB-S receiver module: mainly realize special data receiver and the exchange based on satellite, cable TV network, broadband network.WiFi module: mainly realize WiFi wireless networking capabilities.Wide region digital switch power unit: wide region digital switch power supply, meets electric main 90V, 240V input ,+3V ,+5V, the output of+12V direct current.
Embedded main board described in present embodiment adopts the embedded scheme of high-definition digital video, as SIGMA87XX family chip technical scheme, the chipset conceptual design of the companies such as Conexant, ST, Hai Si is realized, the high resolution audio and video decoder of hardware, high performance RISCCPU(is as ARM9, ARM11, MIPS etc.).Support MPEG1,2,4 and the H.264 real-time hardware decoding of the content output of video code model, support the decoding of the digital audio encodings such as AC-3, PCM, DTS.Embedded a plurality of MPISCPU, host CPU frequency reaches 1.5GHz, supports DDR2 internal memory 2G.Support USB2.0 and 100M network interface etc., video HDMI(HDCP) output, audio optical fibre and coaxial and simulation output.Support large capacity SATA2 interface hard disk storage.On hardware, increase design VPN and WiFi and wireless routing module, smart card reader, the information security module that meets PKI public-key cryptosystem and CPK Conbined public or double key system, the chip model that described PKI and CPK information security module require: HS08K(SSX1106), HS32U2, TF32A09 or VK8001, deciphering module adopts special-purpose high-speed encryption and decryption chip: SSX30, USB-KEY information security interface module, the hardware data receiving element that meets DVB series technique specification and requirement, the above operating system of Andriod4.0 is installed, based on operating system design U-Console intelligent platform system, and various resource managements and application system, man-machine interaction, safe control, digital copyright management, digital certificate, AES encryption and decryption modular unit and application thereof, DVB-OVER-IP data processing unit.Embedded data storehouse system.The above operating system of described Andriod4.0: as the support operation system of product, complete core application functionality exploitation and the base layer support of product itself, and Central Control Function and provide a reliable operation platform for all software systems and the application operation of whole product.
U-Console intelligent platform system: mainly realize between the computer of several operation systems platform and intelligent terminal and interconnecting, as adopt the equipment of Windows operating system, adopt the equipment of IOS operating system, the equipment that adopts Andriod operating system, can interconnect with the utility model product, mutually controls, exchanges data, by this product, can realize between them and interconnecting, control mutually, exchanges data.
The support system of the Intelligent set top box described in present embodiment comprises: described Andriod operating system standard, DVB-S standard and specification requirement, U-Console intelligent platform, DVB-OVER – IP, MEPG1, 2, H.264 4(comprises) series video encoding and decoding compress technique standard, PKI public-key cryptosystem, CPK Conbined public or double key system, AES256/128 position algorithm encryption and decryption standard, RSA enciphering and deciphering algorithm, ECC algorithm, OFFIC document and dependency rule, SQL database standard, AC-3, PCM, the series digit audio coding decoding standards such as DTS, VPN and WiFi wireless routing agreement, USB2.0, ISO7816, TCP/IP, RS232, the host-host protocol standards such as infrared reception, the requirement of wide region digital switch power specifications.
The specific works process of the Intelligent set top box described in present embodiment is:
One, Set Top Box switches on power, and by guidance panel or remote controller, presses key.Guidance panel: Multi-Function Keyboard, infrared receiving module, control interface system and various switches etc.After system starts, start enters human-computer interaction interface, login main interface, the content (the digital distribution version that comprises the contents such as digital audio-video goods, content of multimedia, health care knowledge, food and drug safety, productive life safety, vocational education, middle and primary schools and preschool education, somatic sensation television game, agriculture agrotechnical knowledge, ad content etc.) of the various digital publishing distribution that Set Top Box is pushed by large data digital distribution head-end system by the automatic reception of DVB-S receiver module.By column classification, be automatically saved in the hard disk or SD card of the utility model product.The data content of all digital publishings distribution is close state data content, i.e. distribution version content after encryption, and type and form are various, have high-definition digital video, 3D image, picture, document, digital courseware etc.Large data digital distribution head-end system, all can timing automatic push the digital content that need to issue the same day every day, and Set Top Box described in the utility model is as long as start every day will complete reception automatically.
Two, user is by remote controller or keyboard operation machine, check the distribution version that has received complete digital distribution data content in this product hard disk, and the operation of every application function, the distribution version (digital audio-video goods, content of multimedia, health care knowledge, food and drug safety, productive life safety, vocational education, middle and primary schools and preschool education, somatic sensation television game, digital newspaper, magazine, agriculture agrotechnical knowledge etc.) of all digital distribution data contents of Set Top Box the inside.
Three, pass through human-computer interaction interface, column list is checked in selection, for example choose corresponding digital video content distribution version, select broadcasting, browse operation, first extract the sign of choosing digital video content distribution version, then detect its KEY equipment matching (USB-key or smart card-key) that whether inserted normally, if do not have KEY equipment to insert, by human-computer interaction interface, point out user, " do not insert KEY standby, ask correct insertion KEY equipment ".If normally inserted KEY equipment,, by legitimacy and the validity of its digital certificate of digital signature authentication based on PKI or CPK mechanism, being identified in KEY equipment of the digital video content of then choosing according to correspondence distribution version inquired about and whether had corresponding service condition authorization key information.
If there is no, by dialog box, point out user this digital video content distribution version with no authorized key information, cannot play and browse, please buy or obtain key authorization information.
If existed,, by PKI system or CPK system, verify its legitimacy and corresponding service condition, then decrypt the key file of the digital video content distribution version of corresponding sign, be passed to deciphering module;
Four, the key file that deciphering module utilization passes over, to read the digital video content distribution version data of choosing from hard disk, carry out real time decrypting, the partial data deciphered is real-time is sent to digital audio/video encoding and decoding and browser module is carried out real-time decoding, plays output.
Five, the audio-video signal after real time decrypting is via video output interface (HDMI), output digital video signal, to passing through Special-purpose connecting line cable, the display device (projecting apparatus, panel TV set, display etc.) connecting shows on screen, audio signal, via digital audio interface or analog interface output, is connected to high power digital audio amplification unit module, after final stage power amplification, directly by Speakon interface, outputed on external audio amplifier, go back sound.Also can synchronously together with the digital video signal of HDMI interface and output, deliver to television set, by the audio frequency of television set also system for electrical teaching carry out playback.
In the playing process of the digital video content distribution version of choosing, can carry out F.F., rewind down, the operations such as time-out.The digital video content that correspondence is chosen is issued version and is carried out after normal deciphering decoding broadcasting, system can be according to the type of key authorization condition, the key authorization condition of automatically successively decreasing corresponding, then according to the operation rules of PKI system or CPK system, Reseal key file, write in KEY equipment, upgrade its corresponding key authorization file.If user is by remote controller or operation keyboard, what choose is the distribution version of the digital distribution content of other types, such as document class content, courseware content, image content etc., its whole operating process and example above to choose digital video content distribution version be the same.
The mode of present embodiment based on VPN and wireless routing and other intelligent terminals and information technoloy equipment interconnect, and the operating process of controlling is mutually:
After Intelligent set top box start work, enter normal operating conditions, system automatically starts VPN and wireless routing module enters operating state, operation U-Console intelligent platform system, wireless network is based on WiFi pattern.All intelligent terminal and information technoloy equipments (can be Windows, IOS, the arbitrary operating system of Andriod) of having opened WiFi function in U-Console intelligent platform system automatic search WiFi signal cover, at smart machine, connect in list and represent, user can choose corresponding intelligent terminal to link.
All intelligent terminals and information technoloy equipment all must be installed the client control that the utility model Set Top Box provides, and include digital certificate and the information security system of PKI public-key cryptosystem and CPK Conbined public or double key system in control.In the process that each intelligent terminal and Intelligent set top box described in the utility model link by WiFi, need to by later, could establish the link normally through the digital signature identification of CPK Conbined public or double key system, and then by related software system, realize and mutually controlling, exchanges data etc.
Set up between each intelligent terminal product facility linking with the utility model, also can be via the utility model product, realize their mutually controlling and the operations such as exchanges data each other.
Present embodiment has adopted Andriod operating system platform, and complete hardware system platform scheme design, the complete operations function that has possessed general computer product, can realize all the Internet operations, surf the web, receiving and dispatching mail, the function and applications such as general OFFICE document process, because present embodiment has realized the information security standard of PKI and CPK system, so in internet, applications, owing to thering is digital certificate, thereby realize in the application of the Internet, can carry out digital signature and authentication with corresponding Internet service end or client, in exchanges data, transmission, document process, in mail transmission/reception, can carry out encryption and decryption operation, digital signature.Guarantee the information security in internet, applications, simultaneously can attack protection.Such as Net silver operation, the secure data between set colony, document, mail contact.