WO2001013635A1 - Procede et systeme de peage d'achat-reflexe de services informatiques et multimedia - Google Patents

Procede et systeme de peage d'achat-reflexe de services informatiques et multimedia Download PDF

Info

Publication number
WO2001013635A1
WO2001013635A1 PCT/US2000/021243 US0021243W WO0113635A1 WO 2001013635 A1 WO2001013635 A1 WO 2001013635A1 US 0021243 W US0021243 W US 0021243W WO 0113635 A1 WO0113635 A1 WO 0113635A1
Authority
WO
WIPO (PCT)
Prior art keywords
subscriber
ippu
selection
access controller
accordance
Prior art date
Application number
PCT/US2000/021243
Other languages
English (en)
Inventor
Reem Safadi
Eric J. Sprunk
Doug Makofka
Ray Bontempi
Original Assignee
General Instrument Corporation
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by General Instrument Corporation filed Critical General Instrument Corporation
Priority to KR1020027002030A priority Critical patent/KR20020035575A/ko
Priority to JP2001517799A priority patent/JP2003507803A/ja
Priority to AU65165/00A priority patent/AU6516500A/en
Priority to CA002381363A priority patent/CA2381363C/fr
Priority to BR0013410-4A priority patent/BR0013410A/pt
Priority to EP00952474A priority patent/EP1206876A1/fr
Publication of WO2001013635A1 publication Critical patent/WO2001013635A1/fr

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/60Network structure or processes for video distribution between server and client or between remote clients; Control signalling between clients, server and network components; Transmission of management data between server and client, e.g. sending from server to client commands for recording incoming content stream; Communication details between server and client 
    • H04N21/63Control signaling related to video distribution between client, server and network components; Network processes for video distribution between server and clients or between remote clients, e.g. transmitting basic layer and enhancement layers over different transmission paths, setting up a peer-to-peer communication via Internet between remote STB's; Communication protocols; Addressing
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/47End-user applications
    • H04N21/472End-user interface for requesting content, additional data or services; End-user interface for interacting with content, e.g. for content reservation or setting reminders, for requesting event notification, for manipulating displayed content
    • H04N21/47211End-user interface for requesting content, additional data or services; End-user interface for interacting with content, e.g. for content reservation or setting reminders, for requesting event notification, for manipulating displayed content for requesting pay-per-view content
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/12Payment architectures specially adapted for electronic shopping systems
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06QINFORMATION AND COMMUNICATION TECHNOLOGY [ICT] SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES; SYSTEMS OR METHODS SPECIALLY ADAPTED FOR ADMINISTRATIVE, COMMERCIAL, FINANCIAL, MANAGERIAL OR SUPERVISORY PURPOSES, NOT OTHERWISE PROVIDED FOR
    • G06Q20/00Payment architectures, schemes or protocols
    • G06Q20/08Payment architectures
    • G06Q20/14Payment architectures specially adapted for billing systems
    • G06Q20/145Payments according to the detected use or quantity
    • GPHYSICS
    • G07CHECKING-DEVICES
    • G07FCOIN-FREED OR LIKE APPARATUS
    • G07F17/00Coin-freed apparatus for hiring articles; Coin-freed facilities or services
    • G07F17/16Coin-freed apparatus for hiring articles; Coin-freed facilities or services for devices exhibiting advertisements, announcements, pictures or the like
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/20Servers specifically adapted for the distribution of content, e.g. VOD servers; Operations thereof
    • H04N21/25Management operations performed by the server for facilitating the content distribution or administrating data related to end-users or client devices, e.g. end-user or client device authentication, learning user preferences for recommending movies
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/20Servers specifically adapted for the distribution of content, e.g. VOD servers; Operations thereof
    • H04N21/25Management operations performed by the server for facilitating the content distribution or administrating data related to end-users or client devices, e.g. end-user or client device authentication, learning user preferences for recommending movies
    • H04N21/254Management at additional data server, e.g. shopping server, rights management server
    • H04N21/2543Billing, e.g. for subscription services
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/20Servers specifically adapted for the distribution of content, e.g. VOD servers; Operations thereof
    • H04N21/25Management operations performed by the server for facilitating the content distribution or administrating data related to end-users or client devices, e.g. end-user or client device authentication, learning user preferences for recommending movies
    • H04N21/258Client or end-user data management, e.g. managing client capabilities, user preferences or demographics, processing of multiple end-users preferences to derive collaborative data
    • H04N21/25866Management of end-user data
    • H04N21/25875Management of end-user data involving end-user authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/47End-user applications
    • H04N21/478Supplemental services, e.g. displaying phone caller identification, shopping application
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/60Network structure or processes for video distribution between server and client or between remote clients; Control signalling between clients, server and network components; Transmission of management data between server and client, e.g. sending from server to client commands for recording incoming content stream; Communication details between server and client 
    • H04N21/61Network physical structure; Signal processing
    • H04N21/6106Network physical structure; Signal processing specially adapted to the downstream path of the transmission network
    • H04N21/6125Network physical structure; Signal processing specially adapted to the downstream path of the transmission network involving transmission via Internet
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/60Network structure or processes for video distribution between server and client or between remote clients; Control signalling between clients, server and network components; Transmission of management data between server and client, e.g. sending from server to client commands for recording incoming content stream; Communication details between server and client 
    • H04N21/63Control signaling related to video distribution between client, server and network components; Network processes for video distribution between server and clients or between remote clients, e.g. transmitting basic layer and enhancement layers over different transmission paths, setting up a peer-to-peer communication via Internet between remote STB's; Communication protocols; Addressing
    • H04N21/633Control signals issued by server directed to the network components or client
    • H04N21/6332Control signals issued by server directed to the network components or client directed to client
    • H04N21/6334Control signals issued by server directed to the network components or client directed to client for authorisation, e.g. by transmitting a key
    • H04N21/63345Control signals issued by server directed to the network components or client directed to client for authorisation, e.g. by transmitting a key by transmitting keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N7/00Television systems
    • H04N7/16Analogue secrecy systems; Analogue subscription systems
    • H04N7/162Authorising the user terminal, e.g. by paying; Registering the use of a subscription channel, e.g. billing
    • H04N7/165Centralised control of user terminal ; Registering at central
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N7/00Television systems
    • H04N7/16Analogue secrecy systems; Analogue subscription systems
    • H04N7/167Systems rendering the television signal unintelligible and subsequently intelligible
    • H04N7/1675Providing digital key or authorisation information for generation or regeneration of the scrambling sequence
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N7/00Television systems
    • H04N7/16Analogue secrecy systems; Analogue subscription systems
    • H04N7/173Analogue secrecy systems; Analogue subscription systems with two-way working, e.g. subscriber sending a programme selection signal
    • H04N2007/1739Analogue secrecy systems; Analogue subscription systems with two-way working, e.g. subscriber sending a programme selection signal the upstream communication being transmitted via a separate link, e.g. telephone line

Definitions

  • the present invention relates to communications networks such as cable television, satellite television and computer networks over which services are available for a fee, and more particularly to a method and system for allowing data and multimedia services to be purchased over such networks .
  • Cable and satellite television networks where video services are available for a fee are well known. Also well known are computer network services such as the Internet, America On-Line, CompuServe and others having web sites with different types of applications ranging from general information to entertainment to electronic shopping, all of which can be accessed for a fixed monthly fee.
  • computer network services such as the Internet, America On-Line, CompuServe and others having web sites with different types of applications ranging from general information to entertainment to electronic shopping, all of which can be accessed for a fixed monthly fee.
  • IPPV impulse pay-per-view
  • Such "impulse pay-per-view" (IPPV) services include television movies or special sports events in which a viewer can order a service upon payment of a fee.
  • the provision of pay-per-view services is desirable from a consumer's standpoint since the consumer need only pay for those services which are desired and offered at times that the consumer is able to enjoy them.
  • pay-per-view services whether they be movie or sports events, has prompted system operators and programmers to consider additional types of services to be offered using the pay-per-view approach.
  • One outgrowth of the pay-per-view approach would be the ability to offer services based on data and multimedia applications.
  • Such services may include, without limitation, games or information accompanying the television programming, home-shopping, e-mail services, and the like.
  • acceptable security measures must be implemented.
  • CA conditional access
  • IPPV conditional access to services based on new applications. It would be particularly advantageous to extend such conditional access without requiring a new infrastructure to support these features, i.e., by providing simple extensions to already deployed systems. It would be further advantageous to enable subscriber terminals, such as set-top boxes previously used solely for video IPPV services, to provide "impulse pay per use” (IPPU) services for applications other than video or accompanying the video.
  • IPPU impulse pay per use
  • the present invention provides methods and systems having the aforementioned and other advantages .
  • a method and system are provided for allowing secure impulse pay-per-use (IPPU) services to be obtained over a communication network.
  • IPPU secure impulse pay-per-use
  • a subscriber IPPU selection is sent by a subscriber (e.g., via telephone in the case of call-ahead entitlement or via the subscriber terminal in the case of pre-authorized entitlement) to an access controller.
  • the access controller generates an encrypted message having a service identifier and associated authorization settings related to the subscriber IPPU selection, which encrypted message is then sent from the access controller to the subscriber terminal, together with the cost of the IPPU service selected by the subscriber.
  • the subscriber terminal verifies that the cost of the IPPU selection is within a credit entitlement of the subscriber.
  • the subscriber terminal If such verification is successful, the subscriber terminal generates a secure entitlement token for use by a client application residing in the subscriber terminal.
  • the entitlement token may alternatively be generated by the access controller and forwarded to the subscriber terminal.
  • the client application will then send the entitlement token to a server (e.g., a proxy/policy server) in a secure manner in order to determine the status of the subscriber's entitlement to receive the IPPU selection. If the subscriber's entitlement to receive the IPPU selection is verified, the server will further process the IPPU selection for further enabling the selected service/application for use by the viewer.
  • a server e.g., a proxy/policy server
  • the server can be an independent Internet Service Provider (ISP) proxy/policy server, an ISP proxy/policy server affiliated with a Multiple System Cable Operators' (MSO) or other Network Operators' (NO) proxy/policy/policy server, a NO proxy/policy/policy server, or the like.
  • ISP Internet Service Provider
  • MSO Multiple System Cable Operators'
  • NO Network Operators'
  • the IPPU selection is first sent to a customer response center (CRC) /billing system, which in turn forwards the IPPU selection to the access controller.
  • CRC customer response center
  • the billing system bills the subscriber for the IPPU selection.
  • CRC/billing system via a web browser running at the subscriber terminal and a web server at the billing system.
  • the billing system can actuate the access controller to add the service referred to by the subscriber IPPU selection, which is a separate process from that which tells the access controller which subscribers are entitled to access the service.
  • the term "billing system" as used herein, as well known in the industry, is much broader than just a billing computer.
  • the billing system refers to the business system that runs the Network Operator operation, and includes functions such as billing, system configuration and business operations.
  • the secure entitlement token is a signed and encrypted entitlement token, which signed and encrypted entitlement token is securely sent from the client application to the server for authentication and decryption.
  • the entitlement token may be encrypted using, for example, the subscriber's private key.
  • the proxy/policy server can then use the subscriber's public key to decrypt the entitlement token.
  • the token may be encrypted using symmetric key encryption methods.
  • the token may be encrypted using Data Encryption Standard (DES) techniques, and sent along with the DES key which is encrypted using a public key associated with the server (DES is an encryption standard which is described in US patent no. 3,962,593).
  • DES is an encryption standard which is described in US patent no. 3,962,593
  • the server uses its private key to decrypt the DES key and uses the decrypted DES key to decrypt the token.
  • the entitlement token may be generated at the access controller or at the subscriber terminal.
  • the service identifier is associated with one or more service related codes and data objects which are sent periodically from the access controller to the subscriber terminal.
  • the access controller may be a local access controller or a national access controller.
  • the IPPU services may consist of accessing certain cites, streaming media from the sites, downloading multimedia applications from the sites, accessing content resident on the sites, shopping, email, video mail, or the like.
  • the subscriber terminal may be a cable television set-top box, a digital television or host with point of deployment capability, a personal computer, or the like.
  • the subscriber IPPU selection is pre-authorized at the subscriber terminal for a predetermined credit amount.
  • Pre-authorization for IPPU allows a subscriber to request authorization locally (e.g., in the subscriber terminal) .
  • the subscriber terminal can subtract the cost associated with the subscriber IPPU selection from the credit amount .
  • the subscriber terminal can securely report the subscriber IPPU selection back to the access controller.
  • FIG. 1 is a block diagram of the system in accordance with the present invention.
  • FIG. 2 is a block diagram of the relevant components of a subscriber terminal in accordance with the present invention.
  • impulse pay-per-view concept previously associated with television services is extended to impulse pay-per-use (IPPU) services associated with supplementary data and multimedia applications and the like.
  • IPPU impulse pay-per-use
  • use refers to the act of utilizing either subscriber terminal resources or code/data objects. Such objects comprise software code and/or data, and may be resident in the subscriber terminal or downloaded.
  • the invention securely entitles subscribers to purchase services on impulse. Such services may or may not rely on real time interaction with the network for delivering the service.
  • a secure microprocessor in the subscriber terminal is provided with hardware and/or software to enable the secure processor to generate an entitlement token which is secure and signed, and may be used by the ISP's or NO's proxy/policy server prior to further processing by a server associated with a given service.
  • the token is generated when a subscriber either selects a service (if pre-authorized) or purchases such a service on impulse.
  • Such an IPPU purchase will utilize components resident in the subscriber terminal as well as applicable network components that support IPPU purchase transactions.
  • Various system elements are used in providing IPPU services in accordance with the invention. These include :
  • CRM Customer Response Center
  • CSR Service Representative
  • NO-BS Existing Network Operator Billing System
  • the existing NO billing system interfaces to a national controller (Access Controller-AC) or a local controller (Digital Access Controller-DAC) .
  • Access Controller-AC Access Controller-AC
  • Digital Access Controller-DAC Digital Access Controller-DAC
  • access requirements and authorization rights (entitlements) are conveyed from the Billing System.
  • ISP-BS Internet Service Provider Billing System
  • ISP Internet Service Provider Billing System
  • AC/DAC Access controllers which control the authorization and purchase collection of services on a subscriber basis .
  • Subscriber terminal A device such as a cable television set-top box, a digital television or host with point of deployment capability, a personal computer, or the like that offers video, audio and data services based on subscription, call -ahead, or impulse pay.
  • the subscription and impulse tiers within the conditional access system are associated with service- identifiers which themselves may be associated with one or more service related code and data objects. These objects are carouseled (i.e., sent periodically) on either the out-of-band or a given in-band channel which corresponds to the offered service.
  • the authorization tier is conveyed in an encrypted message and delivered as such to a secure processor in the subscriber terminal .
  • IPPU IP-based resource provisioned by a consumer. If a consumer wishes to purchase a service marked as IPPU, and if he possesses the authorization tier that enables IPPU purchase in general, and if the network has granted him adequate credit, then the consumer can command the purchase directly to the subscriber terminal without the involvement of the network. The subscriber terminal will later report this purchase back to the network in a secure manner, either when requested or autonomously.
  • the server based applications scenarios are more involved. This is due to the fact that certain actions are required by the server (or proxy server) in order to facilitate the use of the selected service/application by the viewer. Such services may include, for example, accessing certain sites, downloading programs from these sites, or accessing content (e.g. streaming media content) resident on these sites.
  • the policy/proxy server requires a secure mechanism to determine whether the subscriber is legitimately entitled to the selected service. The mechanism must be secure to guard against workarounds where a purchase is not registered but an entitlement token (encrypted, signed or otherwise) shows that the subscriber is entitled for a sought after service.
  • the set of impulse-purchasable services (e.g., multimedia applications, home shopping, e-mail, and the like) are associated with corresponding service- identifiers (service_id) that are recognized by both the NO's and the ISP's billing systems.
  • Call ahead service tiers and/or IPPU tiers are associated with each service for each subscriber.
  • Each service_id may have a non zero cost associated with it.
  • a subscriber IPPU selection is sent by a subscriber to an access controller 14 (e.g., via telephone in the case of call-ahead entitlement or via the subscriber terminal in the case of pre-authorized entitlement) .
  • the access controller 14 generates an encrypted message having a service identifier and associated authorization settings (e.g., authorization tier settings) related to the subscriber IPPU selection, which encrypted message is then sent from the access controller 14 to the subscriber terminal 16.
  • the same message (or a separate message) may include the corresponding cost of the IPPU selection.
  • the subscriber terminal 16 verifies that the cost of the IPPU selection is within a credit entitlement of the subscriber. If such verification is successful, the subscriber terminal 16 generates (e.g., by a secure processor located in the subscriber terminal) a secure entitlement token for use by a client application residing in the subscriber terminal 16.
  • the entitlement token may be generated by the access controller 14 and forwarded to the subscriber terminal 16.
  • the client application will then send the entitlement token to a server 18 in a secure manner in order to determine the status of the subscriber' s entitlement to receive the IPPU selection. If the subscriber's entitlement to receive the IPPU selection is verified, the server 18 will further process the IPPU selection to facilitate the use of the service/application by the viewer.
  • the server 18 can be an independent Internet Service Provider (ISP) proxy/policy server, an ISP proxy/policy server affiliated with a Network Operators' (NO) proxy/policy/policy server, a NO proxy/policy/policy server, or the like.
  • ISP Internet Service Provider
  • NO Network Operators'
  • the IPPU selection is first sent to a customer response center (CRC) /billing system 12, which in turn forwards the IPPU selection to the access controller 14.
  • CRC customer response center
  • the billing system 12 bills the subscriber for the IPPU selection.
  • the CRC may be a part of the NO billing system as shown in Figure 1, or the CRC may be a separate entity.
  • the CRC informs the billing system of the call -ahead (or cyber) subscriber selections and sends that information to the NO billing system (NO-BS) .
  • NO-BS NO billing system
  • the subscriber IPPU selection can be sent to the CRC/billing system 12 via a web browser running at the subscriber terminal 16 and a web server at the billing system 12.
  • the server may also inform the ISP's billing system 20 (ISP-BS) about the purchase transaction.
  • ISP-BS ISP's billing system 20
  • NO systems where there is one NO billing system for all services, the ISP's billing system 20 is actually part of or the same as the NO's billing system 12.
  • the subscriber terminal 16 may subtract a subscription fee associated with IPPU (one time purchase until terminated) , and the ISP-BS 20 may charge an additional transaction fee.
  • the subscriber terminal 16 may only register the purchase and convey the entitlement (as mentioned above) with no charge.
  • the ISP's billing system 20 may then apply the charge.
  • the billing system 12 can actuate the access controller 14 to add the service referred to by the subscriber IPPU selection, which is a separate process from that which tells the access controller 14 which subscribers are entitled to access the service.
  • the term "billing system” as used herein, as well known in the industry, is much broader than just a billing computer. Generally, the billing system refers to the business system that runs the NO operation, and includes functions such as billing, system configuration and business operations.
  • the secure entitlement token is a signed and encrypted entitlement token, which signed and encrypted entitlement token is securely sent from the client application to the server 18 for authentication and decryption.
  • the entitlement token may be encrypted using, for example, public key/private key methods and/or DES encryption methods.
  • the subscriber terminal 16 will pass the encrypted entitlement token on to the server 18 for determination of entitlement.
  • the entitlement token may be generated at the access controller 14 or at the subscriber terminal 16.
  • the service identifier is associated with one or more service related codes and data objects which are sent periodically from the access controller 14 to the subscriber terminal 16.
  • the access controller 14 may be a local access controller or a national access controller.
  • the IPPU services may consist of accessing certain sites, streaming media from the sites, downloading multimedia applications from the sites, accessing content resident on the sites, shopping, email, video mail, or the like.
  • the subscriber terminal 16 may be a cable television set-top box, a digital television or host with point of deployment capability, a personal computer, or the like.
  • the subscriber IPPU selection is pre-authorized at the subscriber terminal 16 for a predetermined credit amount.
  • Pre- authorization for IPPU allows a subscriber to request authorization locally (e.g., in the subscriber terminal 16) .
  • the subscriber terminal 16 can subtract the cost associated with the subscriber IPPU selection from the credit amount .
  • the subscriber terminal 16 can securely report the subscriber IPPU selection back to the access controller 14.
  • Figure 2 provides an example of the processing that takes place at the subscriber terminal 16 in a particular embodiment.
  • the subscriber terminal 16 receives the encrypted message from the access controller 14 as discussed in connection with Figure 1.
  • the encrypted message or a separate message may include the corresponding cost of the IPPU selection.
  • a secure processor 32 located in the subscriber terminal 16 then processes the encrypted message to verify whether the cost of the IPPU selection is within the credit entitlement of the subscriber. If such verification is successful, the subscriber terminal 16 then generates (e.g., by the same secure processor 32) a secure entitlement token for use by the client application 40.
  • the client application 40 is provided with this token by an application layer interface routine which will then send the entitlement token to the server 18 in a secure manner as discussed in connection with Figure 1. In this way, the server 18 can further validate the legitimacy of the subscriber's entitlement to the requested service. It also provides non-repudiation of the purchase transaction within the subscriber terminal, allowing the NO to have absolute visibility and control of the purchasable services.
  • the IPPU selection content is forwarded to the subscriber terminal 16 by the server 18 as discussed in connection with Figure 1.
  • the IPPU selection may be received by the secure processor 32 via a conventional receiver circuit (i.e. receiver output of Figure 2) .
  • the secure processor may further process the IPPU content (e.g., if the content associated with the selection is encrypted) .
  • Unencrypted content can then be processed in a conventional manner for display (e.g., by a demultiplexer/decoder 34 or by software in the subscriber terminal 16) .
  • a device memory 30 is provided to store local data related to the subscriber terminal 16 and/or purchases made therewith. This memory can also be used to store software and/or firmware associated with the subscriber terminal 16 as well as data being processed by the CPU 36, depending on the particular implementation chosen.
  • a subscriber terminal is provided with the ability to generate (e.g., by a secure processor located in the subscriber terminal) a signed and/or encrypted token to be used by a NO's or affiliated ISP proxy server to further validate the legitimacy of a subscriber's entitlement to a requested service or set of services offered by the NO or the affiliated ISP.
  • the invention also provides non-repudiation of purchase transactions via a subscriber terminal, thereby requiring a subscriber to pay for all IPPU services ordered.
  • An intended result is to provide NO's with absolute visibility and control of purchasable services.

Landscapes

  • Engineering & Computer Science (AREA)
  • Multimedia (AREA)
  • Signal Processing (AREA)
  • Business, Economics & Management (AREA)
  • Databases & Information Systems (AREA)
  • Accounting & Taxation (AREA)
  • Computer Security & Cryptography (AREA)
  • General Physics & Mathematics (AREA)
  • Finance (AREA)
  • Physics & Mathematics (AREA)
  • Theoretical Computer Science (AREA)
  • General Business, Economics & Management (AREA)
  • Strategic Management (AREA)
  • Development Economics (AREA)
  • Economics (AREA)
  • Computer Graphics (AREA)
  • Human Computer Interaction (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

La présente invention concerne un procédé et un système permettant l'achat-réflexe de services via un réseau de communications tel qu'un réseau de télévision par câble ou satellite. Les services concernés sont essentiellement des informations ou des jeux accompagnant les émissions de télévision, le télé-achat, les services de courrier électronique, et les supports d'information à lecture et enregistrement en continu. La sécurité est assurée par un système d'autorisations produites par le contrôleur d'accès (14) et de jetons d'autorisation produits par un processeur sécurisé. Ce processeur sécurisé est implanté dans le terminal d'abonné (16) par lequel l'abonné se procure les services. Il y a production d'un jeton dès que l'abonné sélectionne le service s'il dispose d'une autorisation préalable ou dès qu'on prend un service par achat-réflexe. Le jeton, qui est sécurisé et signé, peut servir à un serveur de politique ou à un serveur mandataire (18) sous-tendu par le fournisseur de services Internet de l'exploitant de réseau et les services associés de favoriser encore plus l'offre de ces services aux abonnés.
PCT/US2000/021243 1999-08-17 2000-08-03 Procede et systeme de peage d'achat-reflexe de services informatiques et multimedia WO2001013635A1 (fr)

Priority Applications (6)

Application Number Priority Date Filing Date Title
KR1020027002030A KR20020035575A (ko) 1999-08-17 2000-08-03 데이터와 멀티미디어 서비스에 대한 충동 페이-퍼-유즈방법 및 시스템
JP2001517799A JP2003507803A (ja) 1999-08-17 2000-08-03 データ及びマルチメディアサービスのためのインパルス・ペイ・パー・ユース方法及びシステム
AU65165/00A AU6516500A (en) 1999-08-17 2000-08-03 Impulse pay per use method and system for data and multimedia services
CA002381363A CA2381363C (fr) 1999-08-17 2000-08-03 Procede et systeme de peage d'achat-reflexe de services informatiques et multimedia
BR0013410-4A BR0013410A (pt) 1999-08-17 2000-08-03 Método e sistema de "pagar-para-usar" impulso para serviços de dados e multimìdia
EP00952474A EP1206876A1 (fr) 1999-08-17 2000-08-03 Procede et systeme de peage d'achat-reflexe de services informatiques et multimedia

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US14926399P 1999-08-17 1999-08-17
US60/149,263 1999-08-17

Publications (1)

Publication Number Publication Date
WO2001013635A1 true WO2001013635A1 (fr) 2001-02-22

Family

ID=22529487

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2000/021243 WO2001013635A1 (fr) 1999-08-17 2000-08-03 Procede et systeme de peage d'achat-reflexe de services informatiques et multimedia

Country Status (8)

Country Link
EP (1) EP1206876A1 (fr)
JP (1) JP2003507803A (fr)
KR (1) KR20020035575A (fr)
CN (1) CN1174620C (fr)
AU (1) AU6516500A (fr)
BR (1) BR0013410A (fr)
CA (1) CA2381363C (fr)
WO (1) WO2001013635A1 (fr)

Cited By (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2003049443A1 (fr) * 2001-12-05 2003-06-12 France Telecom Procede de gestion de fourniture d'acces a un contenu crypte destine a etre diffuse sur un reseau, ainsi que systeme, serveurs et signal pour la mise en oeuvre de ce procede
WO2003098408A2 (fr) * 2002-05-17 2003-11-27 Dmdsecure.Com Bv Procede et systeme d'evaluation de droit d'acces au contenu pour un dispositif d'utilisateur
EP1376301A2 (fr) * 2002-06-26 2004-01-02 Microsoft Corporation Gestion d'accès à des contenus
EP1483676A1 (fr) * 2002-03-08 2004-12-08 International Business Machines Corporation Connectivite differenciee dans un systeme public d'acces aux donnees facture a l'utilisation

Families Citing this family (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100372303C (zh) * 2004-12-13 2008-02-27 华为技术有限公司 一种实现预付费用户上网策略动态改变的方法
CN100403794C (zh) * 2004-12-29 2008-07-16 华为技术有限公司 一种实现流媒体业务的视讯终端和方法
CN101296420B (zh) * 2008-06-23 2011-07-20 腾讯科技(深圳)有限公司 一种防止免费使用付费游戏的方法、系统、服务器和终端
BRPI1013591A2 (pt) * 2009-03-26 2016-04-19 Xped Holdings Pty Ltd sistema de gerenciamento de comunicação sem fio bi-direncional entre dispositivos

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5003384A (en) * 1988-04-01 1991-03-26 Scientific Atlanta, Inc. Set-top interface transactions in an impulse pay per view television system
US5862220A (en) * 1996-06-03 1999-01-19 Webtv Networks, Inc. Method and apparatus for using network address information to improve the performance of network transactions
WO1999022507A1 (fr) * 1997-10-29 1999-05-06 Helsingin Puhelin Oyj - Helsingfors Telefon Abp Procede de transfert de transactions de paiement dans le reseau internet

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5003384A (en) * 1988-04-01 1991-03-26 Scientific Atlanta, Inc. Set-top interface transactions in an impulse pay per view television system
US5862220A (en) * 1996-06-03 1999-01-19 Webtv Networks, Inc. Method and apparatus for using network address information to improve the performance of network transactions
WO1999022507A1 (fr) * 1997-10-29 1999-05-06 Helsingin Puhelin Oyj - Helsingfors Telefon Abp Procede de transfert de transactions de paiement dans le reseau internet

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
See also references of EP1206876A1 *

Cited By (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2003049443A1 (fr) * 2001-12-05 2003-06-12 France Telecom Procede de gestion de fourniture d'acces a un contenu crypte destine a etre diffuse sur un reseau, ainsi que systeme, serveurs et signal pour la mise en oeuvre de ce procede
EP1483676A1 (fr) * 2002-03-08 2004-12-08 International Business Machines Corporation Connectivite differenciee dans un systeme public d'acces aux donnees facture a l'utilisation
EP1483676A4 (fr) * 2002-03-08 2009-04-15 Ibm Connectivite differenciee dans un systeme public d'acces aux donnees facture a l'utilisation
WO2003098408A2 (fr) * 2002-05-17 2003-11-27 Dmdsecure.Com Bv Procede et systeme d'evaluation de droit d'acces au contenu pour un dispositif d'utilisateur
WO2003098408A3 (fr) * 2002-05-17 2004-04-29 Dmdsecure Com Bv Procede et systeme d'evaluation de droit d'acces au contenu pour un dispositif d'utilisateur
EP1376301A2 (fr) * 2002-06-26 2004-01-02 Microsoft Corporation Gestion d'accès à des contenus
EP1376301A3 (fr) * 2002-06-26 2014-04-09 Microsoft Corporation Gestion d'accès à des contenus

Also Published As

Publication number Publication date
CN1174620C (zh) 2004-11-03
JP2003507803A (ja) 2003-02-25
BR0013410A (pt) 2002-06-25
KR20020035575A (ko) 2002-05-11
AU6516500A (en) 2001-03-13
CN1378743A (zh) 2002-11-06
CA2381363A1 (fr) 2001-02-22
EP1206876A1 (fr) 2002-05-22
CA2381363C (fr) 2009-02-03

Similar Documents

Publication Publication Date Title
US6810525B1 (en) Impulse pay per use method and system for data and multimedia services
US6055314A (en) System and method for secure purchase and delivery of video content programs
US6721956B2 (en) Interactive information services system and associated method for capturing transaction data
US20050066353A1 (en) Method and system to monitor delivery of content to a content destination
AU2007237159B2 (en) Methods and systems to distribute content via a network utilizing distributed conditional access agents and secure agents, and to perform digital rights management (DRM)
US5675647A (en) Cable TV system using passwords
CA2488844C (fr) Systeme de controle d'acces et de gestion des cles pour contenus multimedias diffuses en flux continu
KR100917720B1 (ko) 디지털 멀티미디어 콘텐트 데이터를 안전하게 배포하는 방법
KR100426740B1 (ko) 방송 서비스를 위한 전체적인 조건부 액세스 관리 방법
US8804956B2 (en) Method and device for the partial encryption of a digital content
US20050021467A1 (en) Distributed digital rights network (drn), and methods to access operate and implement the same
CA2402216C (fr) Procede, systeme de communication, et dispositif de reception pour la facturation de programmes et/ou de donnees a acces controle d'emetteurs de diffusion
WO2004051453A1 (fr) Interface utilisateur pouvant etre utilisee par plusieurs fournisseurs de contenu
JP2001512842A (ja) 条件付きアクセスシステムにおいて使用される暗号化装置
KR20060066173A (ko) 방송 및 수신 시스템, 및 수신기
KR20010053558A (ko) 디지털 텔레비전 방송용 조건부 엑세스 시스템
CA2381363C (fr) Procede et systeme de peage d'achat-reflexe de services informatiques et multimedia
AU2001290653B2 (en) A distributed digital rights network (DRN), and methods to access, operate and implement the same
US20200068174A1 (en) Method and apparatus for supporting multiple broadcasters independently using a single conditional access system
CN101022347A (zh) 兼容cas和drm的t-mmb计费系统
US20060059506A1 (en) Conditional access system for digital television content based on prepayment and optimisation of the bandwidth of the channel broadcasting said content
AU2007234610B2 (en) Methods and systems to distribute content via a network utilizing distributed conditional access agents and secure agents, and to perform digital rights management (DRM)
AU2007234609B2 (en) Methods and systems to distribute content via a network utilizing distributed conditional access agents and secure agents, and to perform digital rights management (DRM)
WO2019018431A1 (fr) Procédé et appareil de prendre en charge de multiples diffuseurs indépendamment à l'aide d'un système d'accès conditionnel unique

Legal Events

Date Code Title Description
AK Designated states

Kind code of ref document: A1

Designated state(s): AE AG AL AM AT AU AZ BA BB BG BR BY BZ CA CH CN CR CU CZ DE DK DM DZ EE ES FI GB GD GE GH GM HR HU ID IL IN IS JP KE KG KP KR KZ LC LK LR LS LT LU LV MA MD MG MK MN MW MX MZ NO NZ PL PT RO RU SD SE SG SI SK SL TJ TM TR TT TZ UA UG US UZ VN YU ZA ZW

AL Designated countries for regional patents

Kind code of ref document: A1

Designated state(s): GH GM KE LS MW MZ SD SL SZ TZ UG ZW AM AZ BY KG KZ MD RU TJ TM AT BE CH CY DE DK ES FI FR GB GR IE IT LU MC NL PT SE BF BJ CF CG CI CM GA GN GW ML MR NE SN TD TG

121 Ep: the epo has been informed by wipo that ep was designated in this application
DFPE Request for preliminary examination filed prior to expiration of 19th month from priority date (pct application filed before 20040101)
WWE Wipo information: entry into national phase

Ref document number: 2381363

Country of ref document: CA

WWE Wipo information: entry into national phase

Ref document number: 1020027002030

Country of ref document: KR

WWE Wipo information: entry into national phase

Ref document number: 2000952474

Country of ref document: EP

WWE Wipo information: entry into national phase

Ref document number: 008138982

Country of ref document: CN

WWP Wipo information: published in national office

Ref document number: 1020027002030

Country of ref document: KR

WWP Wipo information: published in national office

Ref document number: 2000952474

Country of ref document: EP

REG Reference to national code

Ref country code: DE

Ref legal event code: 8642

WWW Wipo information: withdrawn in national office

Ref document number: 2000952474

Country of ref document: EP