WO2007036155A1 - Procede de realisation d'une previsualisation de programmes iptv, appareil de cryptage, systeme central de droits et terminal utilisateur - Google Patents

Procede de realisation d'une previsualisation de programmes iptv, appareil de cryptage, systeme central de droits et terminal utilisateur Download PDF

Info

Publication number
WO2007036155A1
WO2007036155A1 PCT/CN2006/002555 CN2006002555W WO2007036155A1 WO 2007036155 A1 WO2007036155 A1 WO 2007036155A1 CN 2006002555 W CN2006002555 W CN 2006002555W WO 2007036155 A1 WO2007036155 A1 WO 2007036155A1
Authority
WO
WIPO (PCT)
Prior art keywords
preview
program
group
cek
terminal
Prior art date
Application number
PCT/CN2006/002555
Other languages
English (en)
French (fr)
Inventor
Chao Sun
Original Assignee
Huawei Technologies Co., Ltd.
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Huawei Technologies Co., Ltd. filed Critical Huawei Technologies Co., Ltd.
Priority to AT06791142T priority Critical patent/ATE506810T1/de
Priority to DE602006021424T priority patent/DE602006021424D1/de
Priority to EP06791142A priority patent/EP1903799B1/en
Priority to CN2006800122337A priority patent/CN101160965B/zh
Publication of WO2007036155A1 publication Critical patent/WO2007036155A1/zh
Priority to US11/956,038 priority patent/US20080123844A1/en

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N7/00Television systems
    • H04N7/16Analogue secrecy systems; Analogue subscription systems
    • H04N7/167Systems rendering the television signal unintelligible and subsequently intelligible
    • H04N7/1675Providing digital key or authorisation information for generation or regeneration of the scrambling sequence
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/20Servers specifically adapted for the distribution of content, e.g. VOD servers; Operations thereof
    • H04N21/25Management operations performed by the server for facilitating the content distribution or administrating data related to end-users or client devices, e.g. end-user or client device authentication, learning user preferences for recommending movies
    • H04N21/254Management at additional data server, e.g. shopping server, rights management server
    • H04N21/2541Rights Management
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/20Servers specifically adapted for the distribution of content, e.g. VOD servers; Operations thereof
    • H04N21/25Management operations performed by the server for facilitating the content distribution or administrating data related to end-users or client devices, e.g. end-user or client device authentication, learning user preferences for recommending movies
    • H04N21/258Client or end-user data management, e.g. managing client capabilities, user preferences or demographics, processing of multiple end-users preferences to derive collaborative data
    • H04N21/25866Management of end-user data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/60Network structure or processes for video distribution between server and client or between remote clients; Control signalling between clients, server and network components; Transmission of management data between server and client, e.g. sending from server to client commands for recording incoming content stream; Communication details between server and client 
    • H04N21/61Network physical structure; Signal processing
    • H04N21/6106Network physical structure; Signal processing specially adapted to the downstream path of the transmission network
    • H04N21/6125Network physical structure; Signal processing specially adapted to the downstream path of the transmission network involving transmission via Internet
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/60Network structure or processes for video distribution between server and client or between remote clients; Control signalling between clients, server and network components; Transmission of management data between server and client, e.g. sending from server to client commands for recording incoming content stream; Communication details between server and client 
    • H04N21/61Network physical structure; Signal processing
    • H04N21/6156Network physical structure; Signal processing specially adapted to the upstream path of the transmission network
    • H04N21/6175Network physical structure; Signal processing specially adapted to the upstream path of the transmission network involving transmission via Internet
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/60Network structure or processes for video distribution between server and client or between remote clients; Control signalling between clients, server and network components; Transmission of management data between server and client, e.g. sending from server to client commands for recording incoming content stream; Communication details between server and client 
    • H04N21/63Control signaling related to video distribution between client, server and network components; Network processes for video distribution between server and clients or between remote clients, e.g. transmitting basic layer and enhancement layers over different transmission paths, setting up a peer-to-peer communication via Internet between remote STB's; Communication protocols; Addressing
    • H04N21/633Control signals issued by server directed to the network components or client
    • H04N21/6332Control signals issued by server directed to the network components or client directed to client
    • H04N21/6334Control signals issued by server directed to the network components or client directed to client for authorisation, e.g. by transmitting a key
    • H04N21/63345Control signals issued by server directed to the network components or client directed to client for authorisation, e.g. by transmitting a key by transmitting keys
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/80Generation or processing of content or additional data by content creator independently of the distribution process; Content per se
    • H04N21/83Generation or processing of protective or descriptive data associated with content; Content structuring
    • H04N21/835Generation of protective data, e.g. certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/80Generation or processing of content or additional data by content creator independently of the distribution process; Content per se
    • H04N21/85Assembly of content; Generation of multimedia applications
    • H04N21/854Content authoring
    • H04N21/8549Creating video summaries, e.g. movie trailer
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N7/00Television systems
    • H04N7/16Analogue secrecy systems; Analogue subscription systems
    • H04N7/173Analogue secrecy systems; Analogue subscription systems with two-way working, e.g. subscriber sending a programme selection signal
    • H04N7/17309Transmission or handling of upstream communications
    • H04N7/17318Direct or substantially direct transmission and handling of requests

Definitions

  • the present invention relates to the field of network communication technologies, and in particular, to a method for implementing network television program preview, an encryption device, a copyright center system, and a user terminal device. Background of the invention
  • the MDN Media Distribute Network
  • the implementation process of the method is as follows: extracting the segments in the program to form a new program, and previewing the program by the user's on-demand.
  • the premise of previewing the MDN extraction segment is that the program is not encrypted. Therefore, the method cannot preview the encrypted program, and when the preview program is not encrypted, the security of the preview program cannot be guaranteed; when the preview program has an encryption requirement, the extracted segment needs to be encrypted again by the encryption machine, and the processing is performed. The process is complicated.
  • DRM Digital Right Management
  • the specific implementation process is: performing a first-level encryption on the preview program, and carrying the content encryption key of the program in the preview copyright, and the preview copyright also carries information such as the time, the number of times, and the validity period of the preview;
  • the copyright center issues the copyright of the corresponding preview program to the terminal according to the user's application, and the terminal acquires the content key of the program through the copyright, and decrypts the program content, and then plays the program for the user to preview;
  • the play time of the program reaches the preview time specified in the preview copyright, the preview copyright is invalidated, thereby completing the program preview.
  • an object of the present invention is to provide a method for implementing program preview, which realizes pre-authorization of batch programs, reduces concurrent access to the copyright center, and improves system reliability.
  • a method for implementing a preview of a network television program comprising:
  • Digital Rights Management DRM encryption system is provided with at least one preview group, and one preview group corresponds to at least one preview program;
  • the digital rights management DRM encryption system generates group authorization information for the terminal according to the preview group, and delivers the group authorization information to the terminal; the terminal acquires the content encryption key CEK or the generated content of each preview program selected from the corresponding preview group according to the received group authorization information.
  • the preview group is created according to a preview rule, and the preview group corresponds to a method for acquiring a group encryption key GEK or GEK; and the method includes:
  • the GEK is used to encrypt the CEK of each preview program in the preview group or the seed that generates the CEK; the encrypted information is carried in the media description information or the media message of the preview program.
  • the CEK of each preview program of the preview group or the seed decryption key for generating the CEK is the preview group. GEK.
  • the CEK of each preview program or the seed that generates the CEK is encrypted and carried in the content key Content Key parameter of the media description information of the preview program, or is carried in an additional segment of the media message of the preview program.
  • the process of generating the group authorization information and delivering the method includes: when the terminal completes the registration to the copyright center, according to the notification of the electronic program guide EPG, applying to the copyright center to issue the group authorization information of the preview group that has not been saved by itself, the copyright The center generates corresponding group authorization information and sends the information to the terminal, and the terminal saves the group authorization information; or
  • the terminal After the terminal selects the preview program, when the terminal does not save the group authorization information of the preview group in which the program is located, the terminal applies the group authorization information to the copyright center according to the preview group Group ID carried in the program media description information, and the copyright center The corresponding group authorization information is generated and sent to the terminal, and the terminal saves the group authorization information.
  • the group authorization information includes a group ID of the preview group, a preview rule, a CEK of the preview program, a decryption key of the seed that generates the CEK, or a method of acquiring the decryption key and decryption algorithm information.
  • the process of decrypting the preview program to implement preview includes:
  • the Group ID information carried in the media description information of the program delivered by the root media server determines the corresponding group authorization information stored in the terminal, and acquires the CEK or the generated program of the preview program. Decryption key and decryption algorithm information of the seed of the CEK;
  • the terminal decrypts the media description information of the preview program or the encrypted CEK in the additional segment of the media message of the preview program or generates a seed of the CEK according to the obtained decryption key and the decryption algorithm information, and acquires the preview program.
  • CEK or seed that produces CEK
  • the digital rights management agent in the terminal DRM Agent decrypts the media message of each preview program according to the obtained CEK of the preview program or the seed of the generated CEK, and realizes preview of the program.
  • the method also includes:
  • the media message of the preview program When the encryption machine encrypts the content of the preview program, the media message of the preview program generates an additional segment, and in the additional segment, the identifier and the attachment of the current stage of the preview program are set according to the preview rule of the preview program.
  • the control information of the segment, and the process of implementing the preview of the program includes:
  • the DRM agent in the terminal determines, according to the phase identifier and the control information in the additional segment, that the terminal is allowed to perform the program preview, and uses the CEK of the preview program or the seed of the generated CEK to decrypt the media message of each preview program to implement the program.
  • the stage identifier includes an identifier of the previewable stage and an identifier of the non-previewable stage, and the control information is a restriction condition for the terminal to decrypt the media message.
  • the method includes: performing, by the terminal, integrity verification on the phase identification and control information in the additional segment according to the signature key in the media description information of the program delivered by the media server.
  • the method further includes:
  • the terminal After the DRM Agent in the terminal confirms that the stage carried in the additional section of the media message of the preview program is identified as the identifier of the non-previewable stage, the terminal performs the program order processing according to the content identifier Content ID of the program.
  • the invention also provides an encryption device for realizing preview of a network television program, comprising:
  • the storage module at least one preview group is stored, one preview group corresponds to at least one preview program, and one preview group corresponds to a group encryption key GEK or GEK acquisition manner;
  • Encryption module Encrypt the preview program with the CEK of each preview program and deliver it to the terminal, using GEK The CEK of each preview program in the preview group or the seed that generates the CEK is encrypted and delivered to the terminal.
  • the encryption module encrypts the CEK of each preview program or the CEK-generated seed to be carried in the media description information or the media message of the preview program.
  • the encryption module generates an additional segment of the media message of the preview program, and sets, in the additional segment, the identifier of the current stage of the preview program and the control information of the additional segment according to the preview rule of the preview program;
  • the stage identifier includes an identifier of the previewable stage and an identifier of the non-previewable stage, where the control information is a restriction condition for the terminal to decrypt the media message, and the control information is a restriction condition for the terminal to decrypt the media message.
  • the invention also provides a copyright center system, which is provided with a group authorization device;
  • the group authorization device is configured to generate group authorization information for the terminal for the preview group, and send the group authorization information to the terminal, so that the terminal acquires the CEK of each preview program or generates the seed of the CEI according to the group authorization information.
  • the present invention further provides a user terminal device, where the user terminal device is provided with an acquisition key module for obtaining content encryption of each preview program selected by the terminal from the corresponding preview group according to the group authorization information received by the terminal.
  • the key CEK or the seed of the CEK is generated and transmitted to the decryption module;
  • the decryption module decrypts each preview program selected by the user terminal device according to the received CEK or the seed of the generated CEK, and realizes preview of the program.
  • the user terminal device is further provided with a key management module
  • the key management module when the terminal completes the registration to the copyright center, according to the notification of the electronic program guide EPG, applies to the copyright center to issue the group authorization information of the preview group that has not been saved, and receives and saves the group issued by the copyright center.
  • Authorization information or, after the terminal selects the preview program, when it does not save the group authorization information of the preview group in which the program is located, the application is sent to the copyright center according to the preview group Group ID carried in the program media description information.
  • Authorization information receive and save the group authorization information issued by the copyright center.
  • the pre-authorization of the batch program is implemented, which reduces the number of times the user applies for the release of the preview copyright from the copyright center, thereby reducing the waiting time of the user and improving the user experience.
  • Configurable preview rules provide operators with flexible business operations methods, such as the ability to package and sell multiple programs with the same preview rules. .
  • the present invention can be compatible with existing equipment without changing the structure of the existing equipment.
  • FIG. 1 is a flowchart of implementing network television program preview according to an embodiment of the present invention. Mode for carrying out the invention
  • the main technical solution of the present invention is: one or more preview groups are set in the DRM encryption system, and one preview group corresponds to one or more programs that allow preview; the group authorization information is generated for the terminal according to the preview group, and the group authorization information is generated. Delivered to the terminal; the terminal obtains the CEK (Content Encrypt Key) or CEK seed of each preview program selected from the corresponding preview group according to the group authorization information it receives, and selects each preview The program is decrypted to preview the program.
  • the CEK Content Encrypt Key
  • the implementation of the technical solution of the present invention is that the CEK of the preview program or the seed for generating the CEK is unchanged, that is, during the entire playback of the program, the terminal can obtain the CEK according to a certain algorithm according to a random but constant value. .
  • FIG. 1 The specific implementation manner of the method of the present invention is as shown in FIG. 1 and includes the following steps:
  • Step 11 In the DRM encryption system, the encryption machine creates multiple preview groups for the preview program according to different preview rules, and determines a Group ID (Group ID), a GE Encryption Key (Group Encrypt Key) for each preview group. ) or GEK acquisition methods, preview rules and other information.
  • Group ID Group ID
  • GE Encryption Key Group Encrypt Key
  • the encryption machine After the encryption machine creates the preview group, it notifies the copyright center of the group ID, GEK or GEK acquisition method and preview rules corresponding to the preview group.
  • the copyright center saves the information corresponding to the preview group.
  • the preview rule refers to the constraint that the terminal views the preview program, and the preview program can be divided according to the time length, the number of times, or the validity period of the preview program.
  • each preview program can be divided into corresponding preview groups according to respective preview rules, and one preview group can include one or more preview programs with the same preview rules.
  • Step 12 When a program allows previewing, the program is encrypted.
  • the present invention requires a two-stage encryption process for the program, i.e., encrypting the program content and encrypting the CEK of the program or the seed that generated the CEK. These two encryption processes can be performed continuously or separately.
  • the process of encrypting the program content that allows previewing is: determining the CEK of the preview program or generating the seed and signature key of the CEK, and using CEK to encrypt the media message of the program by using a symmetric encryption algorithm. Since the symmetric encryption algorithm is adopted, the decryption key of the program content is the CEK of the program or the seed of the generated CEK, and the decryption algorithm is the corresponding encryption algorithm.
  • the information encrypted by the CEK of the preview program or the seed and signature key that generates the CEK may be carried in the ISMACrypKey (ISMA encryption key) of the media description information of the program (or SDP file if the SDP protocol is used).
  • the encryptor determines the CEK of the preview program or generates the seed and signature key for the CEK. Then, the encryption machine selects a corresponding preview group from the preview group that has been created according to the preview rule of the program, and obtains the Group ID and GEK of the preview group.
  • the parameter GroupID and ContentKey are defined in ISMACrypKey in the media description information of the program, wherein: the value of the parameter Group ID is: the group ID of the preview group corresponding to the program; the content of the parameter Content Key is: Encrypting and encoding the CEK of the program or the seed and signature key of the generated CEK, such as assembling the CEK of the program or the seed and signature key of the generated CEK, and then using the GEK of the preview group, The symmetric encryption algorithm encrypts the assembled content, encodes the encrypted value, and puts the encoded value into the parameter Contentl ey.
  • the CEK of the program or the decryption key of the seed and signature key for generating the CEK is the group encryption key GEK of the corresponding preview group, and the decryption algorithm is the corresponding encryption algorithm.
  • the URL (Unique Resource Link) in ISMACrypKey refers to the address that the order request is sent after the user confirms the subscription.
  • the media message of the program when the encryption machine encrypts the content of the program, the media message of the program generates an additional segment, and the identification and control information of the current stage of the program are set in the additional segment according to the preview rule, and the summary is calculated for the additional segment.
  • the digest is signed with a signature key, and the signature is appended to the additional segment.
  • the stage identification includes: an identification of the previewable stage and an identification of the non-previewable stage.
  • the DRM encryption system can control the decryption process of the preview program content by the terminal according to the stage identification; that is, when the stage is identified as the identifier of the preview stage, the terminal is allowed to decrypt the preview program content, when the stage is When the identifier is identified as a non-previewable stage, the terminal is not allowed to decrypt the preview program content.
  • the control information is a restriction condition for the terminal to decrypt the message; for example, the adult level restriction, the restriction level content, the user is required to input a password, and the like.
  • the terminal satisfies the restriction condition of the control information, the terminal is allowed to decrypt the preview program content, otherwise the terminal is not allowed to decrypt the preview program content.
  • Step 13 The terminal obtains the group authorization information and saves it.
  • the terminal After the terminal completes the registration to the copyright center, it applies to the copyright center to issue the group authorization information of the preview group according to the notification of the EPG (Electric Program Guide) and the locally saved group authorization information; the copyright center is based on the terminal
  • the application, the corresponding information of the corresponding preview group saved by the copyright center, and the information of the terminal generate the corresponding group authorization information and send it to the terminal; the terminal receives and saves the group authorization information delivered by the copyright center.
  • the group authorization information includes: a group ID of the corresponding preview group, a CEK of the preview program in which the preview group is located, or a decryption key (ie, a group encryption key GEK) of the seed that generates the CEK, and decryption algorithm information (ie, a corresponding encryption algorithm), Preview rules and terminal information for applying group authorization information.
  • the decryption algorithm information is the identifier of the decryption algorithm.
  • the purpose of the terminal information in the group authorization information is that only the terminal that meets the terminal information can use the group authorization information to decrypt the preview program, thereby preventing the group authorization information from being stolen and adversely affecting the operator.
  • the terminal After the terminal obtains the group authorization information, the terminal obtains the preview rights of all the programs of the preview group corresponding to the group authorization information. Therefore, when the terminal selects the preview program belonging to the preview group corresponding to the group authorization information, the terminal does not need to issue the corresponding group authorization information, thereby reducing the concurrent access to the copyright center and improving the reliability of the system. At the same time, it also reduces the number of times the terminal applies for the release of the preview copyright from the copyright center, thereby reducing the waiting time of the user; moreover, the operator can also package and sell a plurality of programs with the same preview rule.
  • Step 14 The terminal chooses to preview the program.
  • the terminal obtains a program list from the EPG, and the list includes information such as a URL of each program, a URL of the copyright center, and/or a previewable identifier.
  • the program list contains a previewable identifier, it indicates that the program can be previewed.
  • the terminal selects a certain program according to the program list. If the terminal does not subscribe to the program, and the program is previewable, the system prompts preview or order; when the terminal selects the preview, it goes to step 15.
  • Step 15 The terminal acquires media description information of the preview program from the MDN.
  • Step 16 The terminal acquires the decryption key of the preview program by using the media description information.
  • the terminal retrieves the saved group authorization information according to the obtained value of the parameter Group ID in the ISMACrypKey in the media description information of the program; if the group authorization information corresponding to the preview program exists, the parameter Content Key in the ISMACrypKey is obtained.
  • Decryption key and decryption algorithm identification information the decryption key is the GEK of the preview group corresponding to the preview program, and the decryption algorithm is a corresponding encryption algorithm, and the content key parameter is decrypted according to the GEK and the decryption algorithm information to obtain the preview program.
  • the CEK or the seed of the CEK is generated, ie the decryption key and the signature key of the program content.
  • the terminal applies for the corresponding group authorization information to the copyright center according to the parameter Group ID in the ISMACrypKey in the description information of the program; the copyright center generates a corresponding according to the application of the terminal.
  • the group authorization information is sent to the terminal; the group that the terminal will receive
  • the authorization information is saved, and the decryption key GEK and the decryption algorithm information of the parameter Content Key are obtained, and the terminal decrypts the Content Key parameter according to the GEK and the decryption algorithm information to obtain the CEK of the preview program or the seed of the CEK, that is, the program content. Decryption key and signature key.
  • Step 17 The terminal establishes a connection with the media server; the media message receiving the program is verified and signed and decrypted.
  • the terminal performs integrity verification on the phase identification and control information in the additional segment according to the signature key.
  • the DRM Agent agent in the terminal uses The obtained CEK of the preview program or the seed that generates the CEK decrypts the media message, and the player plays the program to realize the program preview.
  • Step 18 The terminal subscribes to the preview program.
  • the DRM Agent If the stage identifier in the additional segment of the media message received by the terminal is the stage identifier of the program that is currently not previewable, or the terminal does not satisfy the control information of the additional segment, the DRM Agent according to the ISMACrypKey in the media description information of the corresponding program.
  • the content ID retrieves the copyright of the program in the terminal.
  • the player pauses the delivery of the media message and prompts whether to order; if the terminal selects the subscription, according to the description information of the program
  • the URL in the ISMACrypKey initiates a subscription request to the copyright center; after the terminal obtains the copyright of the program, the CEK and the copyright rule of the program are obtained from the copyright to establish a decryption environment; the player continues to deliver the media message, and the DRM Agent continues to receive
  • the encrypted media message is then decrypted according to the CEK of the program or the seed of the generated CEK, and the program is played normally.
  • the media message is stopped.
  • the encryption machine adds an additional segment of the CEK of the preview program or the encrypted information of the seed that generates the CEK to the media message of the program (if the RTP protocol is used, the RTP message)
  • the medium is sent to the terminal, and a key can be implemented for each message to improve the security of the system.
  • the terminal obtains the decryption key of the program content from each encrypted media message according to the method of step 16 above. The text is decrypted.
  • the method of the present invention enables pre-authorization of batch programs, which not only reduces the concurrent access to the copyright center, but also improves the reliability of the system; The number of times the copyright is previewed, thereby reducing user waiting time and improving the user experience; in addition, configurable preview rules provide operators with a flexible method of business operations.
  • the encryption device for realizing the network television program preview function provided by the invention comprises: a storage module and an encryption module.
  • a group authorization device is provided in the copyright center provided by the present invention.
  • the storage module is mainly used to store a preview group, and one preview group corresponds to at least one preview program.
  • Preview program root According to the preview rule, it is divided into multiple preview groups, each preview group corresponding to a Group ID, and a Group ID uniquely identifies a preview group.
  • a preview group corresponds to the way to obtain the group encryption key GEK or GEK.
  • the storage module is responsible for submitting the information of the preview group to the group authorization device.
  • the encryption module is mainly used to deliver the encrypted preview program to the terminal, that is, the encryption module determines the CEK of the preview program to be delivered or generates the seed and signature key of the CEK, and uses the symmetric encryption algorithm to use the CEK for the program.
  • the media message is encrypted. Since the symmetric encryption algorithm is used, the decryption key of the program content is the CEK of the program or the seed of the generated CEK, and the decryption algorithm is the corresponding encryption algorithm.
  • the encryption module generates an additional segment of the media message of the preview program when encrypting the content of the preview program, and sets an identifier of the current stage of the preview program and an additional segment according to a preview rule of the preview program in the additional segment.
  • the stage identifier here includes an identifier of the previewable stage and an identifier of the non-previewable stage, and the control information is a restriction condition for the terminal to decrypt the media message.
  • the cryptographic module also needs to encrypt the CEK of the preview program or the seed and signature key of the generated CEK.
  • the encrypted information can be carried in the media description information of the program (or SDP file if SDP protocol is used) ISMACrypKey (ISMA encryption key) ).
  • the group authorization device is configured to generate group authorization information for the terminal according to the preview group information submitted by the storage module after receiving the request for authorization of the request group transmitted by the user terminal device; the group authorization information includes: a group ID of the preview group (group identifier) The preview rule, the CEK of the preview program or the decryption key of the seed that generates the CEK or the acquisition method of the decryption key, the decryption algorithm identification information, and the like.
  • the CEK of the preview program or the decryption key of the seed that generates the CEK is GEK.
  • the group authorization device delivers the group authorization information generated by the group to the terminal.
  • the user terminal device provided by the present invention is provided with a key management module, a key acquisition module and a decryption module.
  • the key management module is mainly used to apply for group authorization information to the copyright center.
  • the key management module applies to the copyright center to issue a group authorization information of the preview group that has not been saved, and receives and saves the group authorization issued by the copyright center according to the notification of the electronic program guide EPG. information.
  • the user terminal device selects a certain program according to the program list. If the user terminal device does not subscribe to the program, and the program is previewable, the user terminal device prompts preview or order at the interface. When the user terminal device selects a preview, the terminal device acquires media description information of the preview program from the MDN.
  • the obtaining key module requests the key management module to retrieve the saved group authorization information according to the obtained value of the parameter Group ID in the ISMACrypKey in the media description information of the program; if the key module stores the preview program corresponding to the preview program
  • the group authorization information acquires the decryption key GEK and the decryption algorithm identification letter of the parameter Content Key in the ISMACrypKey.
  • the decryption key is the GEK of the preview group corresponding to the preview program, and the decryption method is the corresponding encryption algorithm.
  • the acquisition key module decrypts the Content Key parameter according to the GEK and the decryption algorithm information to obtain the CEK of the preview program or generate a seed and a signature key of the CEK.
  • the acquisition key module transmits the decryption key and the signature key of the decrypted content to the decryption module.
  • the key management module applies to the copyright center to issue the corresponding group authorization information. After receiving the group authorization information transmitted by the copyright center, the key management module stores and notifies the key acquisition module. After receiving the notification of the key management module, the key obtaining module obtains the CEK of the preview program or generates the seed and signature key of the CEK by using the above process, and transmits the decryption key and the signature key of the decrypted content to the decryption. Module.
  • the decryption module receives the decryption key and the signature key, and first uses the signature key to perform signature verification on the additional segment of the media message. After passing, the identifier of the current stage of the preview program and the additional segment are obtained from the additional segment of the media message.
  • the control information is identified in the determination stage as the stage indicator that the preview program is currently previewable, and the terminal satisfies the control information of the additional segment, and the decryption module decrypts the preview program according to the received decryption key to implement the program preview.
  • the content ID (content identifier) in the ISMACrypKey in the media description information of the corresponding program is used to retrieve whether the terminal exists in the terminal.
  • the copyright of the program if not present, suspends the delivery of the media message and prompts whether to order; if the user terminal device selects the subscription, the subscription request is initiated to the copyright center according to the URL in the ISMACrypKey in the description information of the program.
  • the CEK and the copyright rule of the program are obtained from the copyright, and the decryption environment is established; the player continues to deliver the media message, and the decryption module continues to receive the encrypted media message, and then according to the program.
  • the CEK or the seed that generates the CEK decrypts the media message and the program plays normally. If the terminal chooses not to order, the media message is stopped.

Landscapes

  • Engineering & Computer Science (AREA)
  • Multimedia (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Databases & Information Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Computer Graphics (AREA)
  • Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)
  • Circuits Of Receivers In General (AREA)
  • Mobile Radio Communication Systems (AREA)

Description

实现网络电视节目预览的方法、 加密装置、 版权中心系统和用户终端设备 技术领域
本发明涉及网络通信技术领域,尤其涉及一种实现网络电视节目预览的方法、加密 装置、 版权中心系统和用户终端设备。 发明背景
在目前的 IPTV (网络电视)业务提供过程中,一般由 MDN(Media Distribute Network, 媒体分发网络)实现节目的预览功能。 该方法的实现过程为: 抽取节目中的片断组成新 的节目, 通过用户的点播实现该节目的预览。
但是该技术方案存在以下缺点:因为 MDN抽取片断实现预览的前提是节目不加密。 因此, 该方法无法实现对加密节目的预览, 而且, 当预览节目不加密时, 无法保证预览 节目的安全性; 当预览节目有加密需求时, 则需要将抽取的片断通过加密机再次加密, 处理流程复杂。
随着流媒体在互联网上的广泛传播又发展起来一种新技术 DRM ( Digital Right Management, 数字版权管理) , 利用 DRM不仅可以实现对数字内容的保护, 同时还可 以提供节目预览、 批量定购等业务部署功能。
因此, 随着 DRM技术的出现, 又出现了一种实现 IFTV节目预览的方法, 该方法是 基于 DRM加密系统, 通过对终端进行预览授权来实现的。
具体实现过程为:将预览节目进行一级加密,并将节目的内容加密密钥承载在预览 版权中, 该预览版权中还承载有允许预览的时间、 次数以及有效期等信息; 当终端提出 预览申请, 在版权中心完成注册后, 版权中心根据用户的申请, 将相应预览节目的版权 下发给终端, 终端通过版权获取节目的内容密钥, 并对节目内容进行解密后, 播放节目 供用户预览; 当节目的播放时间达到预览版权中规定的预览时间后, 预览版权失效, 从 而完成节目预览。
上述技术方案虽然能够实现对加密节目的预览,而且也省去了再次加密的流程,但 是, 不难看出, 该技术方案存在如下缺点:
1、 极大地增加了版权中心的并发访问量, 降低了系统的可靠性。 因为预览功能一 般对用户是免费的,用户通常的操作习惯是在大量的节目间通过预览选择一个最终决定 付费观看的节目, 而每次的预览操作都需要从版权中心申请下发一个预览版权, 因此当 大量用户选择节目时必然对版权中心的性能提出较高的要求; 2、 由于每次预览一个节目都需要有申请预览版权的过程, 导致用户等待时间长、 体验差。 发明内容
鉴于上述现有技术所存在的问题, 本发明的目的是提供一种实现节目预览的方法, 实现对批量节目的预先授权, 减少对版权中心的并发访问量, 提高系统的可靠性。
本发明的目的是通过以下技术方案实现的:
一种实现网络电视节目预览的方法, 包括:
数字版权管理 DRM加密系统中设置有至少一个预览组, 一个预览组对应至少一个 预览节目;
数字版权管理 DRM加密系统根据预览组为终端生成组授权信息, 并下发至终端; 终端根据接收的组授权信息,获取其从对应预览组中选择的各预览节目的内容加密 密钥 CEK或生成 CEK的种子, 并对其选择的各预览节目进行解密, 实现节目的预览。
下述方法的技术方案为可选技术方案。
所述预览组是根据预览规则创建的,预览组对应有组加密密钥 GEK或 GEK的获取方 式; 且所述方法包括:
利用 GEK对预览组中各预览节目的 CEK或生成 CEK的种子进行加密;加密后信息承 载在预览节目的媒体描述信息或媒体报文中。
对所述预览组的各预览节目的 CEK或生成 CEK的种子进行加密的加密算法为对称 加密算法时,所述预览组的各预览节目的 CEK或生成 CEK的种子解密密钥为所述预览组 的 GEK。
各预览节目的 CEK或生成 CEK的种子进行加密后的信息承载于预览节目的媒体描 述信息的内容密钥 Content Key参数中, 或者, 承载于预览节目的媒体报文的附加段中。
所述生成组授权信息、 并下发的过程包括- 终端完成到版权中心的注册时,根据电子节目指南 EPG的通知, 向版权中心申请下 发自身没有保存过的预览组的组授权信息,版权中心生成相应的组授权信息并下发至终 端, 终端保存组授权信息; 或者,
终端在选择预览节目后, 当终端自身没有保存该节目所在预览组的组授权信息时, 根据该节目媒体描述信息中承载的预览组 Group ID向版权中心申请下发相应的组授权 信息, 版权中心生成相应的组授权信息并下发至终端, 终端保存组授权信息。 所述组授权信息包括- 预览组的 Group ID、预览规则、预览节目的 CEK或生成 CEK的种子的解密密钥或者 所述解密密钥的获取方法以及解密算法信息。
所述对预览节目进行解密实现预览的过程包括:
终端选择预览组中的预览节目后,根¾媒体服务器下发的该节目的媒体描述信息中 承载的 Group ID信息确定保存在终端中的相应的组授权信息, 并获取该预览节目的 CEK 或生成 CEK的种子的解密密钥和解密算法信息;
终端根据获取的解密密钥和解密算法信息解密所述预览节目的媒体描述信息或者 所述预览节目的媒体报文的附加段中的加密后的 CEK或生成 CEK的种子,获取所述预览 节目的 CEK或生成 CEK的种子;
终端中的数字版权管理代理 DRM Agent根据获取的所述预览节目的 CEK或生成 CEK的种子解密各预览节目的媒体报文, 实现节目的预览。
该方法还包括:
加密机在对预览节目的内容进行加密时,该预览节目的媒体报文生成附加段,并在 ' 所述附加段中根据该预览节目的预览规则设置该预览节目当前所处阶段的标识和附加 段的控制信息, ; 且所述实现节目的预览的过程包括:
终端中的 DRM Agent根据所述的阶段标识、附加段中的控制信息确定允许终端进行 节目预览时, 利用所述预览节目的 CEK或生成 CEK的种子解密各预览节目的媒体报文, 实现节目的预览;
所述阶段标识包括可预览阶段的标识和不可预览阶段的标识,所述控制信息为终端 解密媒体报文的限制条件。
所述方法包括:终端根据媒体服务器下发的节目的媒体描述信息中的签名密钥对附 加段中的阶段标识和控制信息进行完整性验证。
所述方法还包括:
当终端中的 DRM Agent确认所述预览节目的媒体报文附加段中所承载的阶段标识 为不可预览阶段的标识后, 终端根据所述节目的内容标识 Content ID进行节目订购处理。
本发明还提供一种实现网络电视节目预览的加密装置, 包括:
存储模块: 存储有至少一个预览组,一个预览组对应至少一个预览节目,一个预览 组对应一个组加密密钥 GEK或 GEK的获取方式;
加密模块: 利用各预览节目的 CEK对预览节目进行加密并下发至终端, 利用 GEK 对预览组中各预览节目的 CEK或生成 CEK的种子进行加密并下发至终端。
下述加密装置的技术方案为可选技术方案。
加密模块对各预览节目的 CEK或生成 CEK的种子进行加密后的信息承载在预览节 目的媒体描述信息或媒体报文中。
加密模块将预览节目的媒体报文生成附加段,并在所述附加段中根据该预览节目的 预览规则设置该预览节目当前所处阶段的标识和附加段的控制信息;
所述阶段标识包括可预览阶段的标识和不可预览阶段的标识,所述控制信息为终端 解密媒体报文的限制条件, 所述控制信息为终端解密媒体报文的限制条件。
本发明还提供一种版权中心系统, 设置有组授权装置;
组授权装置:用于针对预览组为终端生成组授权信息,并将组授权信息下发至终端, 使终端根据该组授权信息获取各预览节目的 CEK或生成 CEI的种子。
本发明还提供一种用户终端设备, 所述用户终端设备中设置有- 获取密钥模块:用于根据终端接收的组授权信息,获取终端从对应预览组中选择的 各预览节目的内容加密密钥 CEK或生成 CEK的种子, 并传输至解密模块;
解密模块:根据接收的 CEK或生成 CEK的种子,对用户终端设备选择的各预览节目 进行解密, 实现节目的预览。
所述用户终端设备还设置有密钥管理模块;
密钥管理模块: 在终端完成到版权中心的注册时, 根据电子节目指南 EPG的通知, 向版权中心申请下发自身没有保存过的预览组的组授权信息,接收并保存版权中心下发 的组授权信息; 或者, 在终端选择预览节目后, 当其自身没有保存该节目所在预览组的 组授权信息时, 根据该节目媒体描述信息中承载的预览组 Group ID向版权中心申请下发 相应的组授权信息, 接收并保存版权中心下发的组授权信息。
由上述本发明提供的技术方案可以看出, 釆用本发明所述的方法具有如下优点-
1、 实现对批量节目的预先授权, 减少对版权中心的并发访问量, 提高系统的可靠 性。
2、 由于实现了对批量节目的预先授权, 减少了用户从版权中心申请下发预览版权 的次数, 从而减少了用户等待时间, 提高了用户体验。
3、 可配置的预览规则为运营商提供了灵活的业务运营方法, 比如可以将预览规则 相同的多个节目进行打包发售。 .
4、 本发明可以不改变现有设备的结构, 能够很好地兼容现有设备。 附图简要说明
图 1为本发明实施例的实现网络电视节目预览的流程图。 实施本发明的方式
本发明的主要技术方案是: DRM加密系统中设置有一个或多个预览组, 且一个预 览组对应一个或多个允许预览的节目; 根据预览组为终端生成组授权信息, 并将组授权 信息下发至终端; 终端根据其接收的组授权信息, 获取其从对应预览组中选择的各预览 节目的 CEK (Content Encrypt Key, 内容加密密钥) 或 CEK的种子, 并对其选择的各预 览节目进行解密, 实现节目的预览。
本发明技术方案的实现前提为:预览节目的 CEK或者生成 CEK的种子是不变的, 即 在节目的整个播放过程中, 终端可以根据一个随机、但是固定不变的值依据某种算法获 得 CEK。
为对本发明有进一步的了解, 下面结合附图对本发明所述的方法进行详细的说明。 本发明所述方法的具体实现方式如图 1所示, 包括以下步骤:
步骤 11 : 在 DRM加密系统中, 加密机根据不同的预览规则, 为预览节目创建多个 预览组, 并且为每个预览组确定 Group ID (组标识) 、 GEK (Group Encrypt Key, 组加 密密钥) 或 GEK的获取方式、 预览规则等信息。
加密机创建预览组后, 将预览组对应的 Group ID、 GEK或 GEK的获取方式、预览规 则等信息通知版权中心, 版权中心保存上述预览组对应的信息。
其中预览规则是指对终端观看预览节目的约束, 可以按照允许预览节目的时间长 度、 次数或者有效期等约束进行预览节目的划分。这样, 可以将每个预览节目根据各自 的预览规则划分到相应的预览组中,一个预览组可以包括一个或多个预览规则相同的预 览节目。
步骤 12: 当某个节目允许预览时, 对该节目进行加密处理。
本发明需要对该节目进行两级加密处理,即对节目内容进行加密和对该节目的 CEK 或生成 CEK的种子再进行加密处理。 这两个加密过程可以连续进行, 也可以单独进行。
对允许预览的节目内容进行加密的过程是:确定该预览节目的 CEK或生成 CEK的种 子和签名密钥, 采用对称加密算法使用 CEK对该节目的媒体报文进行加密处理。 由于采 用的是对称加密算法, 所以该节目内容的解密密钥就是该节目的 CEK或生成 CEK的种 子, 解密算法就是相应的加密算法。 对预览节目的 CEK或生成 CEK的种子和签名密钥进行加密后的信息可以承载于节 目的媒体描述信息 (如果釆用 SDP协议, 则是 SDP文件) 的 ISMACrypKey (ISMA加密 键) 中。
下面详细介绍将预览节目的 CEK或生成 CEK的种子和签名密钥进行加密后的信息 承载于节目的描述信息的 ISMACrypKey中的加密过程。
首先, 加密机确定该预览节目的 CEK或生成 CEK的种子和签名密钥。然后, 加密机 根据该节目的预览规则从已经创建的预览组中选择相对应的预览组, 获得该预览组的 Group ID和 GEK。 最后, 在节目的媒体描述信息中的 ISMACrypKey中定义参数 GroupID 和 ContentKey (内容密钥),其中:参数 Group ID的值为:该节目相对应的预览组的 Group ID; 参数 Content Key的内容为:对该节目的 CEK或生成 CEK的种子和签名密钥加密并编 码后的值, 如先将该节目的 CEK或生成 CEK的种子和签名密钥进行拼装, 然后, 利用预 览组的 GEK、 釆用对称加密算法对拼装后的内容进行加密, 并对加密后的值进行编码, 将编码后的值放入参数 Contentl ey中。
由于釆用的是对称加密算法, 因此, 该节目的 CEK或生成 CEK的种子和签名密钥的 解密密钥就是相应预览组的组加密密钥 GEK, 解密算法就是相应的加密算法。
ISMACrypKey的格式举例如下:
ISMACrypKey=(URL)http://l 0.164.22.58:6080/ri/servletcontentissuer?ContentID=019 ba4422a285ebd;&GroupID=001;&ContentKey=:base64:YXVkcwAAEACAAACqADibcfgS erik7TpMjwFlhnXW5IcAAAAAAAAAAAAAAACBn
ISMACrypKey中的 URL (Unique Resource Link, 唯一资源链接) 是指: 在用户确 认订购节目后, 订购请求发送的地址。
另外, 加密机在对节目的内容进行加密时, 节目的媒体报文生成附加段, 并根据预 览规则在附加段中设置该节目当前所处阶段的标识和控制信息, 同时对附加段计算摘 要, 使用签名密钥对摘要进行签名, 签名附加在附加段中。 阶段标识包括: 可预览阶段 的标识和不可预览阶段的标识。 - 这样, DRM加密系统就可以根据该阶段标识来控制终端对预览节目内容的解密处 理; 也就是说当阶段标识为可预览阶段的标识时, 允许终端对预览节目内容进行解密处 S, 当阶段标识为不可预览阶段的标识时, 不允许终端对预览节目内容进行解密处理。
控制信息是终端解密报文的限制条件; 如成人级别限制, 对限制级内容, 需要用户 输入密码等。 当终端满足控制信息的限制条件, 则允许终端对预览节目内容进行解密, 否则不允许终端对预览节目内容进行解密处理。 步骤 13: 终端获取组授权信息, 并保存。
当终端完成到版权中心的注册后, 根据 EPG (Electric Program Guide, 电子节目指 南)的通知、以及本地保存的组授权信息情况向版权中心申请下发预览组的组授权信息; 版权中心根据终端的申请、版权中心保存的相应预览组对应的信息以及终端的信息 生成相应的组授权信息并下发给终端; 终端接收并保存版权中心下发的组授权信息。
组授权信息包括: 相应预览组的 Group ID、该预览组所在的预览节目的 CEK或生成 CEK的种子的解密密钥 (即组加密密钥 GEK) 及解密算法信息 (即相应的加密算法) 、 预览规则以及申请组授权信息的终端信息等。 解密算法信息如解密算法的标识。
组授权信息中含有终端信息的目的是:只有符合该终端信息的终端才可以利用该组 授权信息解密预览节目, 防止组授权信息被盗而给运营商带来不利的影响。
终端获取组授权信息后,就获得了组授权信息相对应的预览组的所有节目的预览权 利。 因此, 当终端以后选择属于该组授权信息对应的预览组的预览节目时, 则不必再进 行相应组授权信息的下发, 这样, 不但减少了对版权中心的并发访问量, 提高了系统的 可靠性; 同时也减少了终端从版权中心申请下发预览版权的次数, 从而减少了用户的等 待时间; 而且, 运营商也可以将预览规则相同的多个节目进行打包发售。
步骤 14: 终端选择预览节目。
终端从 EPG中获取节目列表, 列表中有各个节目的 URL、 版权中心的 URL和 /或可 预览标识等信息, 当节目列表中含有可预览标识时, 表明该节目可以预览。
终端根据节目列表选中某一节目,如果终端没有订购该节目,并且该节目是可预览 的, 则在界面提示预览或订购; 当终端选择预览时, 到步骤 15。
步骤 15: 终端从 MDN获取该预览节目的媒体描述信息。
步骤 16: 终端利用媒体描述信息获取该预览节目的解密密钥。
终端根据获取的该节目的媒体描述信息中的 ISMACrypKey中的参数 Group ID的值, 检索已经保存的组授权信息; 如果该预览节目相对应的组授权信息存在, 则获得 ISMACrypKey中的参数 Content Key的解密密钥和解密算法标识信息,该解密密钥就是该 预览节目相对应的预览组的 GEK, 解密算法就是相应的加密算法, 并根据该 GEK和解密 算法信息解密 Content Key参数获得该预览节目的 CEK或生成 CEK的种子,即节目内容的 解密密钥和签名密钥。如果该预览节目相对应的组授权信息不存在, 则终端根据该节目 的描述信息中的 ISMACrypKey中的参数 Group ID向版权中心申请下发相应的组授权信 息; 版权中心根据终端的申请生成相应的组授权信息并下发给终端; 终端将接收到的组 授权信息进行保存, 并获取参数 Content Key的解密密钥 GEK和解密算法信息, 终端根据 该 GEK和解密算法信息解密 Content Key参数获得该预览节目的 CEK或生成 CEK的种子 等信息, 即节目内容的解密密钥和签名密钥。
步骤 17: 终端与媒体服务器建立连接; 接收节目的媒体报文验证签名并解密。 首先终端根据签名密钥对附加段中的阶段标识和控制信息进行完整性验证。 通过 后,如果终端接收到的媒体报文的附加段中的阶段标识为该节目当前处于可预览的阶段 标识, 并且终端满足附加段中的控制信息时, 则终端中的 DRM Agent (代理)使用获得 的该预览节目的 CEK或生成 CEK的种子对媒体报文进行解密, 播放器播放节目, 实现节 目预览。
步骤 18: 终端订购预览节目。
如果终端接收到的媒体报文的附加段中的阶段标识为该节目当前处于不可预览的 阶段标识, 或终端不满足附加段的控制信息, 则 DRM Agent根据相应节目的媒体描述信 息中的 ISMACrypKey中的 Content ID (内容标识) 检索终端中是否存在该节目的版权, 如果不存在, 则播放器暂停媒体报文的下发, 并提示是否订购; 如果终端选择订购, 则 根据节目的描述信息中的 ISMACrypKey中的 URL, 向版权中心发起订购请求; 当终端获 得该节目的版权后, 从版权中获得该节目的 CEK和版权规则, 建立解密环境; 播放器继 续下发媒体报文, DRM Agent继续接收加密的媒体报文, 然后根据该节目的 CEK或生成 CEK的种子对媒体报文进行解密,节目正常播放。
如果终端选择不定购, 则停止媒体报文的接收。
本发明的另外一种实施方案是:加密机将预览节目的 CEK或生成 CEK的种子的进行 加密后的信息承载于节目的媒体报文(如果采用 RTP协议, 则是 RTP报文)的附加段中, 下发到终端, 可以实现每个报文一个密钥, 提高系统的安全性; 终端按照上述步骤 16的 方法从每个加密的媒体报文中获取节目内容的解密密钥, 对媒体报文进行解密。
综上所述, 釆用本发明所述的方法, 能够实现对批量节目进行预先授权, 不但可以 减少对版权中心的并发访问量, 提高系统的可靠性; 而且可以减少用户从版权中心申请 下发预览版权的次数, 从而减少了用户等待时间, 提高用户的体验; 另外, 可配置的预 览规则为运营商提供了灵活的业务运营的方法。
本发明提供的实现网络电视节目预览功能的加密装置包括: 存储模块、 加密模块。 本发明提供的版权中心中设置有组授权装置。
存储模块主要用于存储预览组,一个预览组对应至少一个预览节目。预览节目可根 据预览规则划分为多个预览组,每个预览组均对应一个 Group ID (组标识), 一个 Group ID唯一标识一个预览组。一个预览组对应有组加密密钥 GEK或 GEK的获取方式。存储模 块负责将预览组的信息提交给组授权装置。
加密模块主要用于将加密的预览节目下发至终端,即加密模块确定需要下发的预览 节目的 CEK或生成 CEK的种子和签名密钥等信息,釆用对称加密算法使用 CEK对该节目 的媒体报文进行加密处理。 由于采用的是对称加密算法, 所以该节目内容的解密密钥就 是该节目的 CEK或生成 CEK的种子, 解密算法就是相应的加密算法。加密模块在对预览 节目的内容进行加密时, 将该预览节目的媒体报文生成附加段, 并在附加段中根据该预 览节目的预览规则设置该预览节目当前所处阶段的标识和附加段的控制信息, 同时对附 加段计算摘要, 使用签名密钥对摘要进行签名, 签名附加在附加段中。这里的阶段标识 包括可预览阶段的标识和不可预览阶段的标识,控制信息为终端解密媒体报文的限制条 件。 加密模块对预览节目进行加密的具体过程如方法中的描述。 '
加密模块同时需要对预览节目的 CEK或生成 CEK的种子和签名密钥进行加密,加密 后的信息可以承载于节目的媒体描述信息 (如果采用 SDP协议, 则是 SDP文件) 的 ISMACrypKey (ISMA加密键) 中。
组授权装置主要用于在接收到用户终端设备传输来的请求组授权的请求后,根据存 储模块提交的预览组信息为终端生成组授权信息; 组授权信息包括: 预览组的 Group ID (组标识)、 预览规则、 预览节目的 CEK或生成 CEK的种子的解密密钥或者所述解密密 钥的获取方法以及解密算法标识信息等。在釆用对称加密算法时, 预览节目的 CEK或生 成 CEK的种子的解密密钥即 GEK。 组授权装置将其生成的组授权信息下发至终端。
本发明提供的用户终端设备中设置有密钥管理模块、 密钥获取模块和解密模块。 密钥管理模块主要用于向版权中心申请组授权信息。密钥管理模块在终端完成到版 权中心的注册时, 根据电子节目指南 EPG的通知, 向版权中心申请下发自身没有保存过 的预览组的组授权信息, 接收并保存版权中心下发的组授权信息。
用户终端设备根据节目列表选中某一节目,如果用户终端设备没有订购该节目,并 且该节目是可预览的, 则用户终端设备在界面提示预览或订购。 当用户终端设备选择预 览时, 终端设备从 MDN获取该预览节目的媒体描述信息。 获取密钥模块根据获取的该 节目的媒体描述信息中的 ISMACrypKey中的参数 Group ID的值,请求密钥管理模块检索 已经保存的组授权信息; 如果密钥模块中存储有该预览节目相对应的组授权信息, 则获 取密钥模块获得 ISMACrypKey中的参数 Content Key的解密密钥 GEK和解密算法标识信 息,该解密密钥就是该预览节目相对应的预览组的 GEK,解密箅法就是相应的加密算法。 获取密钥模块根据该 GEK和解密算法信息解密 Content Key参数获得该预览节目的 CEK 或生成 CEK的种子和签名密钥。获取密钥模块将解密内容的解密密钥、签名密钥传输至 解密模块。
如果密钥管理模块中没有存储该预览节目相对应的组授权信息,则密钥管理模块向 版权中心申请下发相应的组授权信息。密钥管理模块在接收到版权中心传输来的组授权 信息后, 进行存储, 并通知密钥获取模块。.密钥获取模块在接收到密钥管理模块的通知 后, 釆用上述过程获得预览节目的 CEK或生成 CEK的种子和签名密钥, 并将解密内容的 解密密钥和签名密钥传输至解密模块。
解密模块接收解密密钥和签名密钥,首先使用签名密钥对媒体报文的附加段进行签 名验证, 通过后, 从媒体报文附加段中获取预览节目当前所处阶段的标识和附加段的控 制信息, 在确定阶段标识为该预览节目当前处于可预览的阶段标识, 且终端满足附加段 的控制信息时, 解密模块根据接收的解密密钥对预览节目进行解密, 实现节目预览。在 确定阶段标识为该预览节目当前处于不可预览的阶段标识,或终端不满足附加段的控制 信息时, 根据相应节目的媒体描述信息中的 ISMACrypKey中的 Content ID (内容标识) 检索终端中是否存在该节目的版权, 如果不存在, 则暂停媒体报文的下发, 并提示是否 订购;如果用户终端设备选择订购,则根据节目的描述信息中的 ISMACrypKey中的 URL, 向版权中心发起订购请求。 当用户终端设备获得该节目的版权后, 从版权中获得该节目 的 CEK和版权规则, 建立解密环境; 播放器继续下发媒体报文, 解密模块继续接收加密 的媒体报文, 然后根据该节目的 CEK或生成 CEK的种子对媒体报文进行解密,节目正常 播放。 如果终端选择不定购, 则停止媒体报文的接收。
以上所述, 仅为本发明较佳的具体实施方式, 但本发明的保护范围并不局限于此, 任何熟悉本技术领域的技术人员在本发明揭露的技术范围内, 可轻易想到的变化或替 换, 都应涵盖在本发明的保护范围之内。 因此, 本发明的保护范围应该以权利要求的保 护范围为准。

Claims

权 利 要 求 书
1、 一种实现网络电视节目预览的方法, 其特征在于, 包括:
数字版权管理 DRM加密系统中设置有至少一个预览组,一个预览组对应至少.一个 预览节目;
数字版权管理 DRM加密系统根据预览组为终端生成组授权信息, 并下发至终端; 终端根据接收的组授权信息,获取其从对应预览组中选择的各预览节目的内容加密 密钥 CEK或生成 CEK的种子, 并对其选择的各预览节目进行解密, 实现节目的预览。
2、 根据权利要求 1所述的方法, 其特征在于: 所述预览组是根据预览规则创建的, 预览组对应有组加密密钥 GEK或 GEK的获取方式; 且所述方法包括:
利用 GEK对预览组中各预览节目的 CEK或生成 CEK的种子进行加密;加密后信息承 载在预览节目的媒体描述信息或媒体报文中。
3、 根据权利要求 2所述的方法, 其特征在于: 对所述预览组的各预览节目的 CEK 或生成 CEK的种子进行加密的加密算法为对称加密算法时,所述预览组的各预览节目的 CEK或生成 CEK的种子解密密钥为所述预览组的 GEK。
4、 根据权利要求 2所述的方法, 其特征在于, 所述各预览节目的 CEK或生成 CEK 的种子进行加密后的信息承载于预览节目的媒体描述信息的内容密钥 Content Key参数 中, 或者, 承载于预览节目的媒体报文的附加段中。
5、根据权利要求 1所述的方法, 其特征在于, 所述生成组授权信息、并下发的过程 包括:
终端完成到版权中心的注册时, 根据电子节目指南 EPG的通知, 向版权中心申请下 发自身没有保存过的预览组的组授权信息,版权中心生成相应的组授权信息并下发至终 端, 终端保存组授权信息; 或者,
终端在选择预览节目后, 当终端自身没有保存该节目所在预览组的组授权信息时, 根据该节目媒体描述信息中承载的预览组 Group ID向版权中心申请下发相应的组授权 信息, 版权中心生成相应的组授权信息并下发至终端, 终端保存组授权信息。
6、 根据权利要求 2所述的方法, 其特征在于, 所述组授权信息包括:
预览组的 Group ID、预览规则、预览节目的 CEK或生成 CEK的种子的解密密钥或者 所述解密密钥的获取方法以及解密算法信息。
7、根据权利要求 6所述的方法, 其特征在于, 所述对预览节目进行解密实现预览的 过程包括: 终端选择预览组中的预览节目后,根据媒体服务器下发的该节目的媒体描述信息中 承载的 Group ID信息确定保存在终端中的相应的组授权信息, 并获取该预览节目的 CEK 或生成 CEK的种子的解密密钥和解密算法信息;
终端根据获取的解密密钥和解密算法信息解密所述预览节目的媒体描述信息或者 所述预览节目的媒体报文的附加段中的加密后的 CEK或生成 CEK的种子,获取所述预览 节目的 CEK或生成 CEK的种子;
终端中的数字版权管理代理 DRM Agent根据获取的所述预览节目的 CEK或生成 CEK的种子解密各预览节目的媒体报文, 实现节目的预览。
8、 根据权利要求 7所述的方法, 其特征在于, 该方法还包括:
加密机在对预览节目的内容进行加密时,该预览节目的媒体报文生成附加段,并在 所述附加段中根据该预览节目的预览规则设置该预览节目当前所处阶段的标识和附加 段的控制信息, ; 且所述实现节目的预览的过程包括:
终端中的 DRM Agent根据所述的阶段标识、附加段中的控制信息确定允许终端进行 节目预览时, 利用所述预览节目的 CEK或生成 CEK的种子解密各预览节目的媒体报文, 实现节目的预览; .
所述阶段标识包括可预览阶段的标识和不可预览阶段的标识,所述控制信息为终端 解密媒体报文的限制条件。
9、根据权利要求 8所述的方法, 其特征在于, 所述方法包括: 终端根据媒体服务器 下发的节目的媒体描述信息中的签名密钥对附加段中的阶段标识和控制信息进行完整 性验证。
10、 根据权利要求 8所述的方法, 其特征在于, 所述方法还包括:
当终端中的 DRM Agent确认所述预览节目的媒体报文附加段中所承载的阶段标识 为不可预览阶段的标识后, 终端根据所述节目的内容标识 Content ID进行节目订购处理。
11、 一种实现网络电视节目预览的加密装置, 其特征在于, 包括:
存储模块: 存储有至少一个预览组,一个预览组对应至少一个预览节目,一个预览 组对应一个组加密密钥 GEK或 GEK的获取方式;
加密模块: 利用各预览节目的 CEK对预览节目进行加密并下发至终端, 利用 GEK 对预览组中各预览节目的 CEK或生成 CEK的种子进行加密并下发至终端。
12、根据权利要求 11所述的加密装置,其特征在于: 所述加密模块对各预览节目的 CEK或生成 CEK的种子进行加密后的信息承载在预览节目的媒体描述信息或媒体报文 中。
13、根据权利要求 12所述的加密装置, 其特征在于: 所述加密模块将预览节目的媒 体报文生成附加段,并在所述附加段中根据该预览节目的预览规则设置该预览节目当前 所处阶段的标识和附加段的控制信息;
所述阶段标识包括可预览阶段的标识和不可预览阶段的标识,所述控制信息为终端 解密媒体报文的限制条件, 所述控制信息为终端解密媒体报文的限制条件。
14、 一种版权中心系统, 其特征在于, 设置有组授权装置;
组授权装置:用于针对预览组为终端生成组授权信息,并将组授权信息下发至终端, 使终端根据该组授权信息获取各预览节目的 CEK或生成 CEK的种子。
15、 一种用户终端设备, 其特征在于, 所述用户终端设备中设置有:
获取密钥模块:用于根据终端接收的组授权信息,获取终端从对应预览组中选择的 各预览节目的内容加密密钥 CEK或生成 CEK的种子, 并传输至解密模块;
解密模块:根据接收的 CEK或生成 CEK的种子,对用户终端设备选择的各预览节目 进行解密, 实现节目的预览。
16、根据权利要求 15所述的用户终端设备, 其特征在于, 所述用户终端设备还设置 有密钥管理模块;
密钥管理模块: 在终端完成到版权中心的注册时, 根据电子节目指南 EPG的通知, 向版权中心申请下发自身没有保存过的预览组的组授权信息,接收并保存版权中心下发 的组授权信息; 或者, 在终端选择预览节目后, 当其自身没有保存该节目所在预览组的 组授权信息时, 根据该节目媒体描述信息中承载的预览组 Group ID向版权中心申请下发 相应的组授权信息, 接收并保存版权中心下发的组授权信息。
PCT/CN2006/002555 2005-09-28 2006-09-28 Procede de realisation d'une previsualisation de programmes iptv, appareil de cryptage, systeme central de droits et terminal utilisateur WO2007036155A1 (fr)

Priority Applications (5)

Application Number Priority Date Filing Date Title
AT06791142T ATE506810T1 (de) 2005-09-28 2006-09-28 Verfahren zur realizierung einer vorschau von iptv programme, und verschlüsselungsanordnung, ermächtigungscentersystem und benutzerstation
DE602006021424T DE602006021424D1 (de) 2005-09-28 2006-09-28 Programme, und verschlüsselungsanordnung, ermächtigungscentersystem und benutzerstation
EP06791142A EP1903799B1 (en) 2005-09-28 2006-09-28 A method for realizing preview of iptv programs, an encryption apparatus, a right center system and a user terminal
CN2006800122337A CN101160965B (zh) 2005-09-28 2006-09-28 实现网络电视节目预览的方法、加密装置、版权中心系统和用户终端设备
US11/956,038 US20080123844A1 (en) 2005-09-28 2007-12-13 Method for realizing preview of iptv programs, an encryption apparatus, a right center system and a user terminal

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CNA2005101054777A CN1863041A (zh) 2005-09-28 2005-09-28 实现网络电视节目预览的方法
CN200510105477.7 2005-09-28

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US11/956,038 Continuation US20080123844A1 (en) 2005-09-28 2007-12-13 Method for realizing preview of iptv programs, an encryption apparatus, a right center system and a user terminal

Publications (1)

Publication Number Publication Date
WO2007036155A1 true WO2007036155A1 (fr) 2007-04-05

Family

ID=37390376

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2006/002555 WO2007036155A1 (fr) 2005-09-28 2006-09-28 Procede de realisation d'une previsualisation de programmes iptv, appareil de cryptage, systeme central de droits et terminal utilisateur

Country Status (6)

Country Link
US (1) US20080123844A1 (zh)
EP (1) EP1903799B1 (zh)
CN (2) CN1863041A (zh)
AT (1) ATE506810T1 (zh)
DE (1) DE602006021424D1 (zh)
WO (1) WO2007036155A1 (zh)

Families Citing this family (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7702633B2 (en) * 2007-03-05 2010-04-20 Microsoft Corporation Previews providing viewable regions for protected electronic documents
KR101512321B1 (ko) * 2007-08-22 2015-04-16 삼성전자주식회사 복수의 서비스 제공자의 서비스를 제공/수신하기 위한 방법및 장치
US8484458B2 (en) * 2009-03-17 2013-07-09 At&T Mobility Ii, Llc System and method for secure transmission of media content
KR101377352B1 (ko) * 2009-07-17 2014-03-25 알까뗄 루슨트 중소 기업 내의 디지털 저작권 관리 수행 방법 및 장치 및 디지털 저작권 관리 서비스를 제공하기 위한 방법
CN102710603B (zh) * 2012-05-02 2014-10-08 华为技术有限公司 媒体信息的生成方法、终端、服务器及ahs系统
CN105578208A (zh) * 2015-11-06 2016-05-11 北京腾锐视讯科技有限公司 一种iptv视频加密传输系统
CN108363775B (zh) * 2018-02-09 2022-08-12 上海宝尊电子商务有限公司 基于规则引擎的高扩展性线上预览环境方法
CN111083566B (zh) * 2018-10-19 2021-06-22 华为技术有限公司 音视频预览内容播放方法、装置及存储介质

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5615265A (en) 1994-01-19 1997-03-25 France Telecom Process for the transmission and reception of conditional access programs controlled by the same operator
WO1997024832A1 (en) * 1995-12-29 1997-07-10 Scientific-Atlanta, Inc. Method and apparatus for providing conditional access in connection-oriented, interactive networks with a multiplicity of service providers
CN1209016A (zh) * 1997-08-15 1999-02-24 朗迅科技公司 使用扩展节目头限制选用发送节目内容的密码方法和装置
US20020170053A1 (en) 2000-10-26 2002-11-14 General Instrument, Inc. ECM and EMM distribution for multimedia multicast content
CN1645934A (zh) * 1999-08-29 2005-07-27 英特尔公司 数字视频内容传输加密与解密方法和设备

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5870474A (en) * 1995-12-04 1999-02-09 Scientific-Atlanta, Inc. Method and apparatus for providing conditional access in connection-oriented, interactive networks with a multiplicity of service providers

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US5615265A (en) 1994-01-19 1997-03-25 France Telecom Process for the transmission and reception of conditional access programs controlled by the same operator
WO1997024832A1 (en) * 1995-12-29 1997-07-10 Scientific-Atlanta, Inc. Method and apparatus for providing conditional access in connection-oriented, interactive networks with a multiplicity of service providers
CN1209016A (zh) * 1997-08-15 1999-02-24 朗迅科技公司 使用扩展节目头限制选用发送节目内容的密码方法和装置
CN1645934A (zh) * 1999-08-29 2005-07-27 英特尔公司 数字视频内容传输加密与解密方法和设备
US20020170053A1 (en) 2000-10-26 2002-11-14 General Instrument, Inc. ECM and EMM distribution for multimedia multicast content

Also Published As

Publication number Publication date
CN1863041A (zh) 2006-11-15
US20080123844A1 (en) 2008-05-29
EP1903799A4 (en) 2008-10-29
CN101160965A (zh) 2008-04-09
DE602006021424D1 (de) 2011-06-01
EP1903799B1 (en) 2011-04-20
ATE506810T1 (de) 2011-05-15
EP1903799A1 (en) 2008-03-26
CN101160965B (zh) 2010-05-19

Similar Documents

Publication Publication Date Title
US9900306B2 (en) Device authentication for secure key retrieval for streaming media players
JP4563450B2 (ja) コンテンツ配信システム
TWI510066B (zh) 用於安全串流媒體內容之系統和方法
US8745655B2 (en) Emergency alerts during playback of video streams on portable devices
US11528128B2 (en) Encryption management, content recording management, and playback management in a network environment
US20040168184A1 (en) Multiple content provider user interface
JP5710160B2 (ja) ストリーム内の記録可能なコンテンツを処理すること
WO2007036155A1 (fr) Procede de realisation d'une previsualisation de programmes iptv, appareil de cryptage, systeme central de droits et terminal utilisateur
JP2008524914A (ja) ブロードキャスト/マルチキャストサービスにおけるデジタル著作権管理方法
JP2004529534A (ja) 暗号化されたメディア用鍵の管理
KR20110004333A (ko) 스트림에서의 레코딩가능한 콘텐트의 프로세싱
JP4666015B2 (ja) コンテンツ配信システム、コンテンツ受信端末、及びコンテンツ配信方法
CN101409713A (zh) 内容传送系统、传送服务器、终端以及内容传送方法
WO2008125023A1 (fr) Système, procédé de protection et serveur pour réaliser un service de canal virtuel
EP3231184B1 (en) Reducing start-up delay in streaming media sessions
CN110213669B (zh) 一种基于ts切片的视频内容防盗系统和方法
CN101313510A (zh) 媒体流密钥管理方法及系统以及应用服务器
CN112203118B (zh) 多媒体资源分发方法、装置、电子装置和存储介质
EP4242883A1 (en) Method and system for managing content data access
WO2020078338A1 (zh) 音视频预览内容播放方法、装置及存储介质
JP2004320623A (ja) ストリーミングコンテンツ配信システム、方法、プログラムおよびコンピュータ読取可能な媒体

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application
WWE Wipo information: entry into national phase

Ref document number: 200680012233.7

Country of ref document: CN

WWE Wipo information: entry into national phase

Ref document number: 2006791142

Country of ref document: EP

WWP Wipo information: published in national office

Ref document number: 2006791142

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

WWP Wipo information: published in national office

Ref document number: 11956038

Country of ref document: US