WO2007076694A1 - Procede et systeme d'autorisation pour abonne, systeme de commande d'autorisation et dispositif terminal associe - Google Patents
Procede et systeme d'autorisation pour abonne, systeme de commande d'autorisation et dispositif terminal associe Download PDFInfo
- Publication number
- WO2007076694A1 WO2007076694A1 PCT/CN2006/003646 CN2006003646W WO2007076694A1 WO 2007076694 A1 WO2007076694 A1 WO 2007076694A1 CN 2006003646 W CN2006003646 W CN 2006003646W WO 2007076694 A1 WO2007076694 A1 WO 2007076694A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- authorization
- user
- message
- group
- address
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N7/00—Television systems
- H04N7/16—Analogue secrecy systems; Analogue subscription systems
- H04N7/167—Systems rendering the television signal unintelligible and subsequently intelligible
- H04N7/1675—Providing digital key or authorisation information for generation or regeneration of the scrambling sequence
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/20—Servers specifically adapted for the distribution of content, e.g. VOD servers; Operations thereof
- H04N21/25—Management operations performed by the server for facilitating the content distribution or administrating data related to end-users or client devices, e.g. end-user or client device authentication, learning user preferences for recommending movies
- H04N21/258—Client or end-user data management, e.g. managing client capabilities, user preferences or demographics, processing of multiple end-users preferences to derive collaborative data
- H04N21/25808—Management of client data
- H04N21/25816—Management of client data involving client authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/20—Servers specifically adapted for the distribution of content, e.g. VOD servers; Operations thereof
- H04N21/25—Management operations performed by the server for facilitating the content distribution or administrating data related to end-users or client devices, e.g. end-user or client device authentication, learning user preferences for recommending movies
- H04N21/258—Client or end-user data management, e.g. managing client capabilities, user preferences or demographics, processing of multiple end-users preferences to derive collaborative data
- H04N21/25866—Management of end-user data
- H04N21/25875—Management of end-user data involving end-user authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/40—Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
- H04N21/45—Management operations performed by the client for facilitating the reception of or the interaction with the content or administrating data related to the end-user or to the client device itself, e.g. learning user preferences for recommending movies, resolving scheduling conflicts
- H04N21/462—Content or additional data management, e.g. creating a master electronic program guide from data received from the Internet and a Head-end, controlling the complexity of a video stream by scaling the resolution or bit-rate based on the client capabilities
- H04N21/4627—Rights management associated to the content
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04N—PICTORIAL COMMUNICATION, e.g. TELEVISION
- H04N21/00—Selective content distribution, e.g. interactive television or video on demand [VOD]
- H04N21/60—Network structure or processes for video distribution between server and client or between remote clients; Control signalling between clients, server and network components; Transmission of management data between server and client, e.g. sending from server to client commands for recording incoming content stream; Communication details between server and client
- H04N21/63—Control signaling related to video distribution between client, server and network components; Network processes for video distribution between server and clients or between remote clients, e.g. transmitting basic layer and enhancement layers over different transmission paths, setting up a peer-to-peer communication via Internet between remote STB's; Communication protocols; Addressing
- H04N21/633—Control signals issued by server directed to the network components or client
- H04N21/6332—Control signals issued by server directed to the network components or client directed to client
- H04N21/6334—Control signals issued by server directed to the network components or client directed to client for authorisation, e.g. by transmitting a key
Definitions
- the present invention relates to the field of multimedia communication technologies, and in particular, to a system and method for authorizing a user who receives multimedia content, and an authorization control system and terminal device thereof. Background of the invention
- NVOD video-on-demand
- CAS Condition Access System
- conditional access system is the core technical guarantee for the reception control of digital TV (satellite, terrestrial, cable), IPTV, mobile TV, mobile TV, other broadcast or multicast media services.
- digital TV wireless, terrestrial, cable
- IPTV IPTV
- mobile TV mobile TV
- mobile TV other broadcast or multicast media services.
- the system can time digital multimedia services according to different situations. Channels and programs are managed and controlled.
- Conditional access refers to a technical means that allows only authorized users to use a certain service, and unauthorized users cannot use the service.
- the conditional access system can realize the authorization management and reception control of various digital television broadcasting services.
- unauthorized users cannot descramble the scrambled program, and thus cannot watch the section ⁇ .
- conditional access system In digital TV (satellite, terrestrial, cable), IPTV, mobile TV, mobile TV, In other broadcast or multicast media services, the conditional access system packages a number of channels into products. If the user orders the product after packaging, the conditional receiving system needs to send a message to authorize the user. Management information is generally authorized by the conditional access system.
- EMM 4 Entitlement Management Message 4 is sent to the terminal device. Since the current broadcast network is mainly a one-way network, the authorized message can only be broadcast to the user through one-way mode. That is, if the current system has 1 million users, the system needs 1 million copies corresponding to the 1 million users.
- the card (for the CAS, the card is the user) respectively issued the EMM authorization ⁇ ⁇ ⁇ text, that is, 1 million cards corresponding to 1 million ⁇ 3 ⁇ 4 text.
- the index of the amount of EMM information data broadcasted will continue to increase, and since the user may not be powered on when the EMM message is sent, the CAS cannot confirm that the user has received the message. This data can only be continuously circulated for a long period of time.
- the EMM header and each sub-information are multiplexed into the transport stream and then expanded to a fixed length of 188 bytes.
- it needs to support 1 million users and 64 sets of programs. Assuming that CAS packs 64 channels into 10 products, the system needs to separate 1 million cards for the 1 million users.
- the data transmitted on the digital TV broadcast network includes video streams, audio streams and other system data streams.
- the EMM occupies a large bandwidth in the CAS, the actual bandwidth occupied by the program is reduced, and because of the scrambler or multiplexer The processing power is limited, so the bandwidth of the EMM data stream on the front-end device cannot be allocated very much.
- the present invention provides a user authorization method, the method comprising the following steps:
- the authentication is performed according to the multicast address, and the authorization information packet is received, and the authorization information is parsed to obtain the authorization data of the user, and the authorization data is used for authorization processing.
- the invention also provides a user authorization system, comprising:
- An authorization control system configured to group users, set a multicast address according to a common address attribute of the group, encapsulate an authorization information message, and send the authorization information message through the transmission network; and the terminal device is configured to use the multicast address according to the And performing the authorization, and receiving the authorization information packet, and parsing the authorization information packet to obtain authorization data of the terminal device, and performing authorization processing according to the authorization data.
- the invention also provides an authorization control system, comprising:
- a user grouping multicast unit configured to group users according to a grouping policy of the user, and set a multicast address according to a common address attribute of the group;
- a message encapsulating unit configured to assemble the multicast address, the authorization data, and the product identifier into 4 authorized information messages
- a message sending unit configured to send the authorization information message.
- the invention also provides a terminal device, comprising:
- An authentication processing unit configured to perform authentication according to a common address attribute
- the message parsing unit is configured to parse the authorization information packet after the common address attribute is authenticated, obtain authorization data, and perform authorization processing according to the authorization data.
- the present invention is sent by means of grouping users by group.
- the EMM packet is sent to the terminal device to authorize the user who subscribes the product, thereby solving the current privilege mode, and the solution provided by the present invention can effectively save the bandwidth requirement of the authorization message.
- FIG. 1 is a flowchart of a main implementation principle of a user authorization method according to first to fourth embodiments of the present invention
- 2A is a schematic structural diagram of a digital television user authorization system applied to the first, second, and third embodiments of the present invention
- 2B is a schematic structural diagram of an authorization control system in a digital television system to which the first, second, and third embodiments of the present invention are applied;
- 2C is a schematic structural diagram of a terminal device in a digital television system to which the first, second, and third embodiments of the present invention are applied;
- 2D is a structural diagram of an EMM message frame in the first embodiment
- 2E is a structural diagram of an EMM message frame in the second embodiment
- 2F is a structural diagram of an EMM message frame in the third embodiment
- FIG. 3A is a schematic structural diagram of a user authorization system for a mobile phone television system according to a fourth embodiment of the present invention.
- 3B is a schematic structural diagram of an authorization control system in a mobile phone television system according to a fourth embodiment of the present invention.
- 3C is a schematic structural diagram of a terminal device in a mobile phone television system according to a fourth embodiment of the present invention.
- FIG. 3D is a flowchart of a user authorization method according to a fourth embodiment of the present invention. Mode for carrying out the invention
- the user authorization method provided by the following embodiments of the present invention includes the following processing steps: First, the authorization control system packages the channel into a product, and the authorization control system sends the authorization information message to the terminal device by means of the group multicast authorization mode, and the The user of the product is authorized.
- the authorization control system When sending a message to the user who ordered the product, first set the multicast address, according to each card Have a unique card address, set a group of cards with common address attributes into the same group; when authorizing a product (product is the program package, is the basic unit for authorizing the card, for several channels)
- the authorization control system assembles the authorization data, the product identifier, and the multicast address into an authorization information message, and sends the authorization information message to the user's terminal device in a multicast authorization manner through the transmission network;
- the terminal device of the specified user group parses the authorization information packet, and obtains the subscription information of the product for the user, and uses the information to authorize the user connected to the terminal device. .
- FIG. 1 is a flowchart of the main implementation principle of the user authorization method provided by the first to fourth embodiments of the present invention, where the authorization information packet specifically refers to the authorization management information.
- Step 110 The authorization control system packages the channel to generate a product identifier.
- Step 120 According to the grouping policy of the user, set a group of users with common address attributes into the same group;
- User's grouping strategy Users are naturally grouped according to their card addresses, without additional processing, that is, they are continuously grouped according to the user card address, and each group has a fixed number of users. The user needs to issue various card-related parameters when opening the card, including the group key (GK), and the SK' in the authorization message, where SK' is to use Gk to encrypt the service key (SK) with an encryption algorithm.
- GK group key
- SK' is to use Gk to encrypt the service key (SK) with an encryption algorithm.
- the terminal device decrypts the SK' using the saved multicast key GK to obtain the SK, and then decrypts the ECM message with the SK to obtain the control word (CW), and finally uses the CW descrambling.
- the program stream can see the program;
- Step 130 The authorization control system assembles the authorization data, the product identifier, and the multicast address into an authorized EMM packet to be modulated into the transmission network.
- the multicast address is obtained according to the common address attribute of the group in step 120; the authorization data indicates both the card address of each user and the order of the user for the product.
- Step 140 The terminal device that belongs to the specified user group in the authorized message receives the EMM authorization message.
- the terminal device performs authentication according to the common address attribute of the group, that is, if the card address of the user meets the common address attribute in the EMM authorization message, that is, the user belongs to the same group of users, the EMM authorization message is received; otherwise, The user cannot receive the EMM authorization message.
- Step 150 The terminal device of the user parses the EMM authorization packet, obtains authorization information for the user, and obtains an order for the user to subscribe to the product.
- the user authorization system includes an authorization control system and a terminal device.
- the authorization control system transmits the authorization information message to the terminal device in a packet multicast manner through the transmission network.
- the terminal device performs the identification according to the multicast address.
- the digital rights management system acts as a terminal device, ie, the set top box 2.
- the digital television system transmission network uses a digital television network such as a satellite transmission network, a digital terrestrial broadcasting network, a wired transmission network, or an IP network.
- the authorization control system can implement packet grouping for users, reduce bandwidth requirements, and save the turnaround time of issuing authorization information messages.
- FIG. 2B is a schematic structural diagram of an authorization control system, that is, a digital television condition receiving system 1 according to an embodiment of the present invention.
- the digital television condition receiving system includes:
- the user packet multicast unit 11 is configured to group users according to a grouping policy of the user, and set a multicast address according to a common address attribute of the group; in this example, the card address is 0x884800010000, 6 bytes are 48 bits in total. 38 bits as a common ground for grouping Address attribute, grouping strategy is divided into groups according to the user card address, wherein each group has a fixed number of users 0x884800010000, 0x884800010001, 0x884800010002..., 0x8848000103FF, which divides 1024 users into one group;
- the packet encapsulating unit 12 is configured to assemble the multicast address, the authorization data, and the product identifier into an authorization information packet, and the specific format is as shown in FIG. 2D.
- group broadcast address ,: 0x884800010000
- Product identification 0x0001, indicating product 1, which includes eight TV channels such as CCTV1, CCTV2...CCTV8;
- Authorization data Each bit represents a card address (user), and also indicates the user's purchase of the product ID. The value can be set to 0 and 1. Specifically, 0 means no purchase, 1 means purchase.
- the message sending unit 13 is configured to send an authorization information message.
- the digital television condition acceptance system of the user packet multicasting unit and the message encapsulating unit is added, and the EMM message can be sent to the terminal device by means of grouping the user packet, and the user who subscribes the product is authorized to solve the current authorization.
- the mode is mainly unicast. With the multicast address and authorization data, the user group can be authorized, thereby reducing the rotation period for the user authorization.
- the terminal device provided by the embodiment of the present invention that is, the structure of the set top box, the set top box 2 includes:
- the authentication processing unit 21 is configured to perform authentication according to a common address attribute; that is, according to the card address
- the message parsing unit 22 is configured to parse the authorization information packet after the authentication process is passed. Obtaining authorization information for the authorized user, and performing authorization processing according to the authorization data: performing authorization processing on the set top box through the common address attribute, if the card corresponding to the set top box of the user has a bit corresponding to 1 indicating that the user can receive the authorization If the corresponding bit is 0, it means that the user cannot receive the authorization and clear the authorization of the existing product.
- the set-top box of the authentication processing unit and the message parsing unit is added, and the set-top box of the grouping user can be authenticated according to the multicasting address, and the authorized set-top box can receive the authorization information packet for authorization processing.
- the set-top box shown in FIG. 2C is connected to the ordinary television set to form a terminal device having an audio-visual playback function, and the message parsing unit parses the license to receive the authorization, and uses the SK to decrypt the ECM message to obtain the control word, and finally uses the CW.
- the program stream is descrambled, and the ordinary TV set can play and receive digital multimedia content.
- the digital television system is introduced, and the digital television conditional receiving system is improved by adding a user packet multicast unit and a message encapsulating unit based on the prior art, thereby A new method for authorizing a user is implemented.
- a common multicast address is assigned to users of the same group, and a value of 1 bit of the authorization data is used to represent the user card address and the product order status. Save bandwidth.
- a group of users can be set to 512, the card address 0x884800010000, the first 39 bits of the 6-byte total 48 bits are used as the common address attribute of the group, and the grouping policy is continuous according to the user card address.
- each group has a fixed number of users 0x884800010000, 0x884800010001, 0x884800010002..., 0x8848000101FF These 512 users are divided into one group; the same can be used to represent a user with two bits in the EMM message.
- the digital television copyright management system can also be utilized as a user authorization control system in a digital television system, that is, a user group multicast unit and a message encapsulation unit are also added in the digital television copyright management system, having the same as described in FIG. 2B.
- a user group multicast unit and a message encapsulation unit are also added in the digital television copyright management system, having the same as described in FIG. 2B.
- first, second, and third embodiments are based on the user authorization system in the digital television system described in the above embodiments, realizing a user authorization method in the digital television system.
- the authorized receiving time depends on the multicast algorithm of the CAS, that is, the number of users that can be authorized by one multicast authorization message.
- the following takes the grouping of 1024 users as an example to illustrate the process in which the conditional receiving system sends an EMM packet to authorize the user who subscribes the product through multicast authorization. The specific steps are as follows:
- Step 2210 The digital television conditional receiving system packages the channel into a product; in this example, the product 1 includes CCTV1, CCTV2, ... CCTV8, and the product 2 includes Phoenix Satellite TV, and the product 3 includes...
- Step 2220 Set a group of users with common address attributes into the same group according to the grouping policy of the user; in this example, the card address 0x884800010000, the first 38 bits of 6 bytes totaling 48 bits are grouped.
- the common address attribute, the grouping policy is continuously divided into groups according to the user card address, wherein each group has a fixed number of users 0x884800010000, 0x884800010001, 0x884800010002..., 0x8848000103FF, and the 1024 users are divided into one group;
- Step 230 Assembling the authorization data, the product identifier, and the multicast address into an authorized EMM message to be modulated into the transmission network.
- the assembled EMM message is as shown in FIG. 2, and the parameters related to the present invention are 6 bytes of "broadcast address,,, 4 bytes of "product identification”, 16 bytes of "SK”, 128 bytes of "authorization data,, the specific settings are as follows:
- Product identification 0x0001, indicating product 1, which includes eight TV channels such as CCTV1, CCTV2...CCTV8;
- SK is the SK in the form of cipher text.
- the set-top box uses the saved multicast key GK to decrypt SK' to get SK:
- Authorization data Each bit represents a card address (user), and also indicates the user's purchase of the product ID. The value can be set to 0 and 1, specifically, 0 means no purchase, 1 means purchase. In this example, as shown in FIG. 2D, it indicates that 0x884800010001 and 0x8 84 800010003 are authorized, and other users are not authorized; through step 220 and step 230, multicasting of users is implemented, and one user in the prior art is solved.
- This unicast method of text implements a packet multicast mode of a group of users and one message;
- Step 2250 The user parses the EMM authorization packet to obtain an order for the user to order the product. According to the EMM packet structure described in step S230, the user parses the authorization data. If the bit corresponding to the card address of the user is 1, the user can receive the authorization. If the corresponding bit is 0, the user cannot receive the authorization. This authorization also removes the authorization of the product that already exists.
- packet grouping authorization information packets are sent to the set top box to which the user belongs, which effectively saves bandwidth requirements and reduces the carousel period.
- 10 products of 1 million users 1 million users are divided into 1000 groups (1024 users per group). Each group has 10 products for authorization.
- There are 10000 packets in total, and the length of each transport stream packet. 188 bytes, calculated according to the bandwidth allocated 50Kbsp, the time of the carousel is (10000 messages xl 88 bytes per message x8bits) 7 (50x1024 bsp) 293.75 seconds, thus getting the round Broadcasting for about 300 seconds is a significant advantage over the prior art in which it takes 300,800 seconds to spin once.
- Step 2310 The conditional receiving system packages the channel into a product; in this example, the product 1 includes CCTV1, CCTV2...CCTV8, the product 2 includes Phoenix Satellite TV, and the product 3 includes...
- Step 2320 According to the user's grouping strategy, a group The user with the common address attribute is set to the same group; in this example, the card address 0x884800010000, the first 39 bits of 6 bytes totaling 48 bits are used as the common address attribute of the packet, and the grouping policy is continuous according to the user card address. Divided into a group, each of which has a fixed number of users 0x884800010000, 0x884800010001, 0x884800010002..., 0x8848000101FF, these 512 users are divided into one group;
- Step 2330 Assembling the authorization data, the product identifier, and the multicast address into an authorized EMM message modulated into the transmission network.
- the assembled EMM is shown in FIG. 2E, where the present invention is related.
- the parameter has 6 bytes of "broadcast address", 4 bytes of "product identification”, 16 bytes of "SK,”, 64 bytes of "authorization data,, the specific settings are as follows:
- Product identification 0x0002, indicates product 2, which includes Phoenix TV channel;
- SK is SK in cipher text, the set-top box uses the saved multicast key GK to decrypt SK after receiving the message. , get SK:
- Authorization data Each bit represents a card address (user), and also indicates that the use
- the value of the purchase of the product ID by the user can be set to 0 and 1, specifically, 0 means no purchase, 1 means purchase.
- 0 means no purchase
- 1 means purchase.
- FIG. 2E it indicates that 0x884800010001 and 0x884800010003 are authorized, and other users are not authorized; and the user group multicast is implemented through steps 320 and 330, which solves one message of a user in the prior art.
- Single-cast mode which achieves a group multicast mode of a group of users;
- Step 2340 The STB that belongs to the specified user group in the authorized message receives the EMM authorization message; the set top box performs authentication according to the common address attribute of the group, that is, the first 39 bits of the common address attribute of the card address 0x884800010000 is used for authentication. Only users who meet the common address attribute can receive the EMM message, for example, 0x884800010001 can receive 4 ⁇ of 0x884800010000, and 0x888800010000 cannot receive 0x884800010000 message;
- Step 2350 The user parses the EMM authorization packet to obtain an order for the user to order the product. According to the EMM packet structure described in step S330, the user parses the authorization message. If the bit corresponding to the card address of the user is 1, the user can receive the authorization. If the corresponding bit is 0, the user cannot receive the message. This authorization also removes the authorization of the product that already exists.
- the "authorization data" in the EMM message uses one bit to represent a user.
- the EMM message represents two users with two bits, and each group of 512 users is used to authorize the product 2.
- the digital eDonkey conditional receiving system sends the EMM message to the user who subscribes the product by means of the multicast authorization.
- the steps of performing the authorization are basically the same as those in the first embodiment and the second embodiment, and only differ in the specific frame format of the EMM message.
- Figure 2F shows the authorization data in the EMM message.
- the two bits represent the frame format of a user, where 11 and 00 respectively represent whether the user has authorization. 2F means to authorize 0x884800010001 and 0x884800010003, and no other users have authorization.
- the second and third embodiments also save bandwidth and reduce the turn cycle.
- the first, second and third embodiments described above mainly describe a method of authorizing a user in a digital television system.
- the digital television system includes a satellite television system, a terrestrial television system, and a cable television system;
- the above-mentioned authorization control system for grouping and multicasting users is operated by a conditional receiving system in a digital television system, wherein the user is a user of the set top box, that is, A user who ordered a digital TV.
- the transmission network in the method of this embodiment includes, but is not limited to, a satellite transmission network, a digital terrestrial broadcast network, a wired transmission network, or an IP network.
- the system for authorizing the user is the same as that of FIG. 2A described above, except that the authorization control system is operated by the mobile phone television conditional access system or the digital rights management system; It is a mobile communication network.
- the authorized object is a mobile TV user such as a PDA or a 3G mobile phone, that is, the user's mobile phone or PDA virtual card address or mobile phone number, SIM card serial number, IMSI number common address attribute is authenticated, in this example Define the virtual card address implementation. For example, you can refer to the 6-byte virtual address defined in the digital TV.
- the card address is 0x884800010000, and the first 38 bits of the 6-byte total 48 bits are used as the common address attribute of the packet.
- the grouping policy is based on the user card.
- the addresses are continuously divided into groups, each of which has a fixed number of users 0x884800010000, 0x884800010001, 0x884800010002..., 0x8848000103FF.
- the 1024 users are divided into one group; the optional scheme can use the mobile phone number, the serial number of the SIM card, IMSI (International Mobile Subscriber Identity) can be used to uniquely identify the number of a mobile terminal.
- IMSI International Mobile Subscriber Identity
- any combination of users such as 13888888880, 13888888881, 1388888888..., 13888888889, etc., use the first 8 digits 13888888000 as the group number, and the last three digits (1000 users) as the intra-group address;
- the strategy is divided into groups according to the user card address.
- the authorization control system can implement packet grouping for users, reduce bandwidth requirements, and save the turnaround time of issuing authorization information messages.
- FIG. 3B the structure diagram of the embodiment of the mobile phone television conditional access system or the digital rights management system of the present invention increases the user packet multicasting unit and the message encapsulating unit, and its structure and function are the same as those described in FIG. 2B of the above embodiment.
- the mobile TV condition acceptance system of the user packet multicasting unit and the message encapsulating unit is added, and the EMM message can be sent to the terminal device by means of the grouping of the user group, and the user who subscribes the product is authorized to solve the current authorization mode.
- Mainly for unicast With the multicast address and the authorization data, the user group can be authorized, thereby reducing the rotation period for authorizing the user.
- FIG. 3C is a schematic structural diagram of an embodiment of a terminal device such as a mobile phone or a PDA in the mobile phone power system of the present invention; the authentication processing unit and the message parsing unit, the structure and function thereof, and the foregoing embodiment FIG. 2C The description is the same and will not be described here.
- the mobile phone or the PDA has an audio and video playback unit, the message parsing unit parses the license, receives the authorization, uses SK to decrypt the ECM message to obtain the control word, and finally uses the CW descrambled program stream to play and receive the digital multimedia content.
- the mobile phone or PDA with the authentication processing unit and the message parsing unit is added, and the mobile phone or PDA of the group user can be authenticated according to the multicast address, and the authorization information message can be received by the authenticated mobile phone or PDA. , for authorization processing.
- the fourth embodiment describes a method of authorizing a user in a mobile phone system.
- Step 3410 The mobile TV conditional receiving system packages the channel into a product; in this example, the product 1 includes CCTV1, CCTV2...CCTV8, and the product 2 includes Phoenix Satellite TV, and the product 3 includes...
- Step 3420 # User's grouping policy, setting a group of users with common address attributes into the same group; in this example, defining a virtual card address implementation, for example, referring to a 6-byte virtual address defined in digital television, the card Address 0x884800010000, 6 bytes of the first 38 bits of 48 bits as the common address attribute of the packet, the grouping strategy is according to the user card
- the addresses are continuously divided into groups, each of which has a fixed number of users 0x884800010000, 0x884800010001, 0x884800010002..., 0x8848000103FF.
- the 1024 users are divided into one group; the optional scheme can use the mobile phone number, the serial number of the SIM card,
- the IMSI full name is International Mobile Subscriber Identification Number
- any combination of users such as 13888888880, 13888888881, 1388888888..., 13888888889, etc., use the first 8 digits 13888888000 as the group number, and the last three digits (1000 users) as the intra-group address;
- Step 3430 Assembling the authorization data, the product identifier, and the multicast address into an authorized EMM message modulation into the transmission network.
- the parameter has a 6-byte "multicast address,,, a 4-byte "product identification”, and a 16-byte "SK,,,, 64-byte "authorization data”.
- the specific settings are as follows:
- Product identification,,: 0x0002 indicates product 2, which includes the Phoenix TV channel;
- SK is the SK in the form of cipher text, the mobile phone or PDA uses the saved multicast key after receiving the message.
- GK decrypts SK and gets SK:
- Authorization data Each bit represents a card address (user), and also indicates the user's purchase of the product ID. The value can be set to 0 and 1. Specifically, 0 means no purchase, 1 means purchase. In this example, as shown in FIG. 2D, it indicates that 0x884800010001 and 0x884800010003 are authorized, and other users are not authorized; through step 3420 and step 3430, packet multicasting to users is implemented, which solves one message of a user in the prior art. Unicast mode, which achieves a group multicast mode of a group of users;
- Step 3440 The mobile phone or the PDA belonging to the specified user group in the authorized message receives the EMM authorization message; the mobile phone or the PDA performs authentication according to the common address attribute of the group, that is, the card address 0x884800010000, a total of 48 bytes of 6 bytes The first 38 bits of the bit are used as points The common address attribute of the group is authenticated. Only the user who meets the common address attribute can receive the EMM message, for example, 0x884800010001 can receive the message of 0x884800010000, and 0x888800010000 cannot receive the message of 0x884800010000.
- Step 3450 The user parses the EMM authorization message to obtain the user's order for the product. According to the EMM packet structure described in step S330, the user parses the authorization message. If the bit corresponding to the card address of the user is 1, the user can receive the authorization. If the corresponding bit is 0, the user cannot receive the message. This authorization also removes the authorization of the product that already exists.
- a group of 512 users can also be selected.
- the specific processing steps are the same as those in the second embodiment.
- the processing steps of the embodiment in which two bits represent one user are the same as the third embodiment.
- the authorization for the user in the mobile television system of the fourth embodiment is the same as the authorization for the user in the digital television system of the first to third embodiments, the only difference being the multicast address, that is, in the mobile television system, the virtual card address is defined. Or use the mobile phone number, SIM card serial number, IMSI, etc. to uniquely identify the number of a mobile terminal as a common address attribute.
- the system for authorizing the user is the same as that shown in FIG. 2A or 3A.
- the authorization control system is operated by the IPTV conditional access system or the digital rights management system;
- the authorized object is an IPTV user such as a networked computer.
- Every networked computer There is only one smart card, that is, the common address attribute of the smart card address is authenticated.
- the smart card address 0x884800010000, the first 39 bits of the 6-byte total 48 bits are grouped as the common address attribute of the group.
- the policies are successively grouped according to the user card address; the system connection relationship is the same as the above embodiment.
- the transport network can be an IP network.
- the authorized object may also be a user who views the program by using an IP set-top box and a television set, that is, the common address attribute of the IP set-top box card address is authenticated.
- the authorization control system can implement packet grouping for users, reduce bandwidth requirements, and save the turnaround time of issuing authorization information messages.
- the user packet grouping unit and the message encapsulating unit are added, and the structure and function thereof are the same as those described in FIG. 2B or 3B of the above embodiment, and details are not described herein again.
- the IPTV condition acceptance system of the user packet multicasting unit and the encapsulation unit is added, and the EMM message is sent to the terminal device by means of the grouping of the user group, and the user who subscribes the product is authorized to solve the current authorization.
- the mode is mainly unicast. With the multicast address and the authorization data, the user group can be authorized, thereby reducing the rotation period for authorizing the user.
- the terminal device such as a networked computer or an IP set-top box, has an authentication processing unit and a message parsing unit, and its structure and function are the same as those described in FIG. 2C or 3C of the foregoing embodiment, and details are not described herein again.
- the networked computer has an audio and video playback unit. After the message parsing unit parses, it receives the authorization, and uses SK to decrypt the ECM message to obtain the control word. Finally, the CW descrambles the program stream, that is, the digital multimedia content can be played and received.
- the IP set-top box is connected to the ordinary television set to form a terminal device having an audio-visual playback function, and the message parsing unit parses the license to receive the authorization, and uses the SK to decrypt the ECM message to obtain the control word, and finally uses the CW to descramble the program stream.
- the TV can play and receive digital multimedia content.
- the networked computer or the IP set-top box of the authentication processing unit and the message parsing unit is added, and the networked computer or the IP set-top box of the group user can be authenticated according to the multicast address, and can be received through the authenticated networked computer or the IP set-top box.
- the packet grouping authorization processing procedure for the user is the same as that of the first embodiment, the second embodiment, and the third embodiment, and the only difference is that the authorization control system for performing packet grouping authorization on the user is
- the IPTV conditional access system or the IPTV digital rights management system, in the IPTV system that is, the common address attribute of the smart card of the networked computer or the IP set top box card address is authenticated, in this example, the smart card or the IP set top box card address is grouped together. Address attribute (specifically the same as in the digital TV system).
- the packet multicasting of the user is also implemented, which solves the unicast mode of one message of one user in the prior art, and achieves a packet multicast mode of one group of users, which reduces the occupied bandwidth and reduces the bandwidth. Take turns.
- the system for authorizing the user is the same as that shown in Fig. 2A or 3A above, except that the authorization control system is operated by the mobile television conditional access system or the digital rights management system.
- Authorized objects are mobile TV users such as car mobile TV or other dedicated terminals with video and audio playback functions and receiving multimedia program streams, such as improved MP4 players, such as virtual card addresses for devices such as MP3, MP4, etc.
- the MP4 can be used as a networked terminal in the mobile TV system, in correspondence with its device identification (such as the body serial number, etc.) or directly using the device identification.
- the authorization control system the system authenticates the virtual card common address attribute of the in-vehicle mobile TV.
- the card address 0x884800010000 the first 39 bits of 6 bytes totaling 48 bits are used as the common address of the group.
- grouping strategy is divided into groups according to the user card address, wherein each group has a fixed number of users 0x884800010.000, 0x884800010001, 0x884800010002..., 0x8848000101FF, the 512 users are divided into one group;
- the transmission network can be a satellite transmission network or a digital terrestrial broadcast network or a mobile communication network.
- the authorization control system can implement packet grouping for users, reduce bandwidth requirements, and save the turnaround time of issuing authorization information messages.
- the mobile TV condition acceptance system that adds the user packet multicast unit and the message encapsulation unit can implement the method of transmitting the EMM message to the terminal device by means of grouping the user group, authorizing the user who subscribes the product, and solving the current authorization.
- the mode is mainly unicast. With the multicast address and the authorization data, the user group can be authorized, thereby reducing the rotation period for authorizing the user.
- a terminal device such as an in-vehicle mobile television device or other dedicated terminal having an audio-visual playback function and receiving a multimedia program stream, such as a modified MP4 player, having an authentication processing unit and a message parsing unit, the structure and function thereof, and the above embodiment
- a multimedia program stream such as a modified MP4 player
- the description of 2C or 3C is the same and will not be described here.
- the car mobile TV device or the improved MP4 player has an audio and video playback unit, and the message parsing unit parses the license to receive the authorization, and uses the SK to decrypt the ECM message to obtain the control word, and finally uses the CW to descramble the program stream, and then the broadcast is received.
- Digital multimedia content Digital multimedia content.
- the in-vehicle mobile television device or the improved MP4 player with the authentication processing unit and the message parsing unit is added, and the grouped mobile TV device or the improved MP4 player can be authenticated according to the multicast address.
- the authenticated in-vehicle mobile television device or the improved MP4 player can receive the authorization information message for authorization processing.
- the packet grouping authorization processing procedure for the user is the same as that of the first embodiment, the second embodiment, and the third embodiment, and the only difference is the authorization control of the group multicast authorization for the user.
- the system is a mobile TV conditional access system or a mobile TV digital rights management system, in a mobile television system, that is, a virtual television set or other dedicated terminal having an audio-visual playback function and receiving a multimedia program stream, such as an improved MP4 player.
- the common address attribute of the card address is authenticated.
- the virtual card address is used as the common address attribute of the packet (specifically, it is consistent with the digital television system:).
- the same is also achieved for user group multicast, which solves a message in the prior art of a user.
- the unicast method achieves a group multicasting method of a group of users, which reduces the occupied bandwidth and reduces the rotation period.
- the user is authorized to perform group packet broadcast, and the authorized terminal device can watch live broadcast or remote on-demand programs from the multimedia server, and can also view the locally stored multimedia. Program stream.
- Embodiments of the present invention provide a user authorization method capable of reducing bandwidth and reducing the turn cycle.
- each group of 1024 and 512 users is implemented, but in principle, the number of each group of users can be changed. In the case of packet fragmentation, more users per group can be implemented, or only partial bytes can be used. Groups of fewer users per group (for example, a group of 2048 users, even a group of 10 users, etc.);
- authorization data uses one bit to represent one user or two bits to represent one user, and a combination of multiple bits may be used to represent one user.
- the above user authorization method is also applied to other broadcast or multicast media services, and the packet grouping authorization processing procedure for the user is the same as the first embodiment, the second embodiment, and the third embodiment.
- the system of other broadcast or multicast media services only needs to add a user packet multicast unit and a message encapsulation unit, and the terminal device has an authentication processing unit and a message parsing unit.
Landscapes
- Engineering & Computer Science (AREA)
- Databases & Information Systems (AREA)
- Computer Security & Cryptography (AREA)
- Multimedia (AREA)
- Signal Processing (AREA)
- Computer Graphics (AREA)
- Computer Networks & Wireless Communication (AREA)
- Two-Way Televisions, Distribution Of Moving Picture Or The Like (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Mobile Radio Communication Systems (AREA)
Description
Claims
Priority Applications (3)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CNA2006800116891A CN101156350A (zh) | 2005-12-31 | 2006-12-28 | 用户授权方法和系统、及其授权控制系统和终端设备 |
EP06840682A EP1853000A4 (en) | 2005-12-31 | 2006-12-28 | PARTICIPANT AUTHORIZATION PROCESS AND SYSTEM, AUTHORIZATION CONTROL SYSTEM AND ASSOCIATED TERMINAL DEVICE. |
US11/847,590 US20080059993A1 (en) | 2005-12-31 | 2007-08-30 | Method and system for transmitting and receiving authorization message |
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN200510121536.X | 2005-12-31 | ||
CNB200510121536XA CN100525434C (zh) | 2005-12-31 | 2005-12-31 | 一种在数字电视条件接收系统中对用户授权的方法 |
Related Child Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
US11/847,590 Continuation US20080059993A1 (en) | 2005-12-31 | 2007-08-30 | Method and system for transmitting and receiving authorization message |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2007076694A1 true WO2007076694A1 (fr) | 2007-07-12 |
Family
ID=37298416
Family Applications (2)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/CN2006/001379 WO2007076652A1 (fr) | 2005-12-31 | 2006-06-19 | Procede d'autorisation utilisateur pour systeme d'acces conditionnel a la television numerique |
PCT/CN2006/003646 WO2007076694A1 (fr) | 2005-12-31 | 2006-12-28 | Procede et systeme d'autorisation pour abonne, systeme de commande d'autorisation et dispositif terminal associe |
Family Applications Before (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/CN2006/001379 WO2007076652A1 (fr) | 2005-12-31 | 2006-06-19 | Procede d'autorisation utilisateur pour systeme d'acces conditionnel a la television numerique |
Country Status (4)
Country | Link |
---|---|
US (1) | US20080059993A1 (zh) |
EP (1) | EP1853000A4 (zh) |
CN (2) | CN100525434C (zh) |
WO (2) | WO2007076652A1 (zh) |
Families Citing this family (14)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
JP2008103864A (ja) * | 2006-10-18 | 2008-05-01 | Nec Corp | Ipマルチキャストサービスシステム、スイッチ装置及びそれらに用いるグループ選択送信方法 |
US20090165074A1 (en) * | 2007-12-21 | 2009-06-25 | General Instrument Corporation | Multi-Address Message Addressing |
US8407486B2 (en) * | 2008-03-12 | 2013-03-26 | International Business Machines Corporation | Sending and releasing pending messages |
EP2124439A1 (fr) * | 2008-05-21 | 2009-11-25 | Nagravision S.A. | Méthode d'allocation et de gestion d'abbonements de réception de produits télédiffusés |
CN101594294B (zh) * | 2008-05-29 | 2011-12-21 | 北京视博数字电视科技有限公司 | 发送授权信息的方法及其条件接收系统前端 |
US20100210239A1 (en) | 2009-02-17 | 2010-08-19 | Jeyhan Karaoguz | Service mobility via a femtocell infrastructure |
US8381260B2 (en) * | 2009-07-08 | 2013-02-19 | Echostar Technologies L.L.C. | Separate addressing of a media content receiver and an installed removable circuit device |
EP2566157A1 (en) | 2011-09-02 | 2013-03-06 | Nagravision S.A. | Method to optimize reception of entitlement management messages in a Pay-TV system |
US9961384B2 (en) | 2012-12-20 | 2018-05-01 | Nagravision S.A. | Method and a security module configured to enforce processing of management messages |
EP2747443B1 (en) | 2012-12-20 | 2019-06-26 | Nagravision S.A. | Method to enforce processing of management messages by a security module |
US10652673B2 (en) * | 2013-05-15 | 2020-05-12 | Gn Hearing A/S | Hearing instrument with an authentication protocol |
CN104363040B (zh) * | 2014-09-26 | 2018-09-11 | 航天数字传媒有限公司 | 卫星授权搜索的方法及装置 |
CN105263133A (zh) * | 2015-09-14 | 2016-01-20 | 惠州Tcl移动通信有限公司 | 一种虚拟sim卡实现方法及系统 |
US10291965B2 (en) * | 2016-03-11 | 2019-05-14 | DISH Technologies L.L.C. | Television receiver authorization over internet protocol network |
Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1360438A (zh) * | 2000-12-18 | 2002-07-24 | 清华同方股份有限公司 | 一种基于分组算法的数字电视有条件接收系统 |
CN1372731A (zh) * | 1999-07-05 | 2002-10-02 | 卡纳尔股份有限公司 | 广播和接收消息 |
EP1343316A1 (de) * | 2002-03-04 | 2003-09-10 | Beta Research GmbH | Verfahren und Vorrichtung zum Adressieren von Mitteilungen eines Anbieters digitaler Dienste |
Family Cites Families (16)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
DE3688855T2 (de) * | 1985-05-01 | 1994-03-17 | Gen Instrument Corp | Satellitenübertragungssystem mit Direktübertragung. |
TR199902274T2 (xx) * | 1997-03-21 | 2000-01-21 | Canal + Societe Anonyme | Yay�nlama ve yay�n alma sistemi, ve bunun i�in ko�ullu giri� sistemi |
HUP0001487A2 (hu) * | 1997-03-21 | 2000-09-28 | CANAL + Socíete Anonyme | Digitális adatjeleket sugárzó és fogadó rendszer, továbbá kódolt jelet vevő- és dekódoló berendezésekhez sugárzó berendezés, továbbá kódolt kisugárzott jeleket fogadó vevő- és dekódoló berendezés, továbbá csipkártyás vevő és dekódoló berendezés, ... |
ID23380A (id) * | 1997-03-21 | 2000-04-20 | Canal & Siciete Anonyme | Metode dan aparatus untuk mencegah akses yang curang dalam sistem akses bersyarat |
US6295361B1 (en) * | 1998-06-30 | 2001-09-25 | Sun Microsystems, Inc. | Method and apparatus for multicast indication of group key change |
US20020003884A1 (en) * | 2000-05-26 | 2002-01-10 | Sprunk Eric J. | Authentication and/or authorization launch |
US6898285B1 (en) * | 2000-06-02 | 2005-05-24 | General Instrument Corporation | System to deliver encrypted access control information to support interoperability between digital information processing/control equipment |
US6862684B1 (en) * | 2000-07-28 | 2005-03-01 | Sun Microsystems, Inc. | Method and apparatus for securely providing billable multicast data |
DE10037630B4 (de) * | 2000-08-02 | 2008-02-07 | Deutsche Telekom Ag | Verfahren zur Adressierung von Endgeräten |
CA2426159A1 (en) * | 2000-10-26 | 2002-09-06 | General Instrument Corporation | Enforcement of content rights and conditions for multimedia content |
US7995603B2 (en) * | 2001-05-22 | 2011-08-09 | Nds Limited | Secure digital content delivery system and method over a broadcast network |
DE10244079A1 (de) * | 2002-09-06 | 2004-04-01 | Deutsche Telekom Ag | Verfahren zum Bereitstellen eines verschlüsselten IP-basierenden Gruppen-Dienstes |
US20040151315A1 (en) * | 2002-11-06 | 2004-08-05 | Kim Hee Jean | Streaming media security system and method |
EP1427208A1 (en) * | 2002-12-02 | 2004-06-09 | Canal + Technologies | Messaging over mobile phone network for digital multimedia network |
US20040181811A1 (en) * | 2003-03-13 | 2004-09-16 | Rakib Selim Shlomo | Thin DOCSIS in-band management for interactive HFC service delivery |
US7266198B2 (en) * | 2004-11-17 | 2007-09-04 | General Instrument Corporation | System and method for providing authorized access to digital content |
-
2005
- 2005-12-31 CN CNB200510121536XA patent/CN100525434C/zh not_active Expired - Fee Related
-
2006
- 2006-06-19 WO PCT/CN2006/001379 patent/WO2007076652A1/zh active Application Filing
- 2006-12-28 CN CNA2006800116891A patent/CN101156350A/zh active Pending
- 2006-12-28 EP EP06840682A patent/EP1853000A4/en not_active Ceased
- 2006-12-28 WO PCT/CN2006/003646 patent/WO2007076694A1/zh active Application Filing
-
2007
- 2007-08-30 US US11/847,590 patent/US20080059993A1/en not_active Abandoned
Patent Citations (3)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN1372731A (zh) * | 1999-07-05 | 2002-10-02 | 卡纳尔股份有限公司 | 广播和接收消息 |
CN1360438A (zh) * | 2000-12-18 | 2002-07-24 | 清华同方股份有限公司 | 一种基于分组算法的数字电视有条件接收系统 |
EP1343316A1 (de) * | 2002-03-04 | 2003-09-10 | Beta Research GmbH | Verfahren und Vorrichtung zum Adressieren von Mitteilungen eines Anbieters digitaler Dienste |
Non-Patent Citations (1)
Title |
---|
See also references of EP1853000A4 * |
Also Published As
Publication number | Publication date |
---|---|
CN1859559A (zh) | 2006-11-08 |
US20080059993A1 (en) | 2008-03-06 |
CN100525434C (zh) | 2009-08-05 |
WO2007076652A1 (fr) | 2007-07-12 |
EP1853000A1 (en) | 2007-11-07 |
CN101156350A (zh) | 2008-04-02 |
EP1853000A4 (en) | 2008-07-02 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
WO2007076694A1 (fr) | Procede et systeme d'autorisation pour abonne, systeme de commande d'autorisation et dispositif terminal associe | |
RU2339077C1 (ru) | Способ функционирования системы условного доступа для применения в компьютерных сетях и система для его осуществления | |
JP4870078B2 (ja) | 低階層キーマネージメントシステムおよび方法 | |
CN102577421B (zh) | 用于使用社交tv服务识别的内容的数字版权管理保护 | |
US7383561B2 (en) | Conditional access system | |
KR101244312B1 (ko) | 헤드-엔드 시스템 및 복수의 클라이언트 시스템들 간의통신을 제어하는 방법 | |
TWI243613B (en) | System and apparatus for supplying audiovisual information to a subscriber terminal | |
US20110093883A1 (en) | System, protection method and server for implementing the virtual channel service | |
WO2008046323A1 (fr) | Procédé, système et appareil pour la protection de service de télévision pour téléphone mobile | |
JP2006523423A (ja) | 条件付きアクセスパーソナルビデオレコーダー | |
JP2002535926A (ja) | ディジタル伝送システムにおけるアドレス割り当て | |
US8693692B2 (en) | Direct delivery of content descrambling keys using chip-unique code | |
EP2373019A1 (en) | Secure descrambling of an audio / video data stream | |
JP4520148B2 (ja) | データ交換ネットワークにおけるスクランブルされたデジタルデータのためのアクセスコントロールを伴う送信方法およびシステム | |
WO2001015448A1 (en) | System and method for securing on-demand delivery of pre-encrypted content using ecm suppression | |
CA2396821A1 (en) | Conditional access and security for video on-demand systems | |
WO2009017367A2 (en) | Method and system for storage and playback of broadcasting contents, rights issuer applied to the same | |
US20060233368A1 (en) | Method for conditional access in a DMTS/DOCSIS enabled set top box environment | |
KR20120014662A (ko) | Iptv의 콘텐트를 포터블 디바이스로 제공하고 포터블 디바이스에서 이를 재생하는 방법 및 장치 | |
CN103634624A (zh) | 基于ip网络的数字电视直播方法及系统 | |
CN113727196B (zh) | 实现cas终端按需授权的方法、装置及存储介质 | |
CN101521570A (zh) | 一种实现iptv组播业务媒体安全的方法、系统及设备 | |
Yang et al. | The Simplified and Secure Conditional Access for Interactive TV service in Converged Network | |
KR101383378B1 (ko) | 다운로드 수신제한 시스템을 이용한 모바일 iptv 서비스 시스템 및 그 방법 | |
Kim et al. | Protection of MPEG-2 multicast streaming in IP-TV |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
WWE | Wipo information: entry into national phase |
Ref document number: 2006840682 Country of ref document: EP |
|
WWE | Wipo information: entry into national phase |
Ref document number: 11847590 Country of ref document: US |
|
121 | Ep: the epo has been informed by wipo that ep was designated in this application | ||
WWE | Wipo information: entry into national phase |
Ref document number: 200680011689.1 Country of ref document: CN |
|
WWP | Wipo information: published in national office |
Ref document number: 2006840682 Country of ref document: EP |
|
WWP | Wipo information: published in national office |
Ref document number: 11847590 Country of ref document: US |
|
NENP | Non-entry into the national phase |
Ref country code: DE |