WO2018014798A1 - 机顶盒动态配置多ca的方法及系统 - Google Patents

机顶盒动态配置多ca的方法及系统 Download PDF

Info

Publication number
WO2018014798A1
WO2018014798A1 PCT/CN2017/093071 CN2017093071W WO2018014798A1 WO 2018014798 A1 WO2018014798 A1 WO 2018014798A1 CN 2017093071 W CN2017093071 W CN 2017093071W WO 2018014798 A1 WO2018014798 A1 WO 2018014798A1
Authority
WO
WIPO (PCT)
Prior art keywords
dynamic
certificate
library
top box
operator
Prior art date
Application number
PCT/CN2017/093071
Other languages
English (en)
French (fr)
Inventor
邓得金
郝探强
Original Assignee
深圳创维数字技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 深圳创维数字技术有限公司 filed Critical 深圳创维数字技术有限公司
Publication of WO2018014798A1 publication Critical patent/WO2018014798A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/41Structure of client; Structure of client peripherals
    • H04N21/418External card to be used in combination with the client device, e.g. for conditional access
    • H04N21/4181External card to be used in combination with the client device, e.g. for conditional access for conditional access
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/41Structure of client; Structure of client peripherals
    • H04N21/418External card to be used in combination with the client device, e.g. for conditional access
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L67/00Network arrangements or protocols for supporting network services or applications
    • H04L67/34Network arrangements or protocols for supporting network services or applications involving the movement of software or configuration parameters 
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/41Structure of client; Structure of client peripherals
    • H04N21/418External card to be used in combination with the client device, e.g. for conditional access
    • H04N21/4182External card to be used in combination with the client device, e.g. for conditional access for identification purposes, e.g. storing user identification data, preferences, personal settings or data
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/43Processing of content or additional data, e.g. demultiplexing additional data from a digital video stream; Elementary client operations, e.g. monitoring of home network or synchronising decoder's clock; Client middleware
    • H04N21/443OS processes, e.g. booting an STB, implementing a Java virtual machine in an STB or power management in an STB
    • H04N21/4431OS processes, e.g. booting an STB, implementing a Java virtual machine in an STB or power management in an STB characterized by the use of Application Program Interface [API] libraries
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/40Client devices specifically adapted for the reception of or interaction with content, e.g. set-top-box [STB]; Operations thereof
    • H04N21/45Management operations performed by the client for facilitating the reception of or the interaction with the content or administrating data related to the end-user or to the client device itself, e.g. learning user preferences for recommending movies, resolving scheduling conflicts
    • H04N21/462Content or additional data management, e.g. creating a master electronic program guide from data received from the Internet and a Head-end, controlling the complexity of a video stream by scaling the resolution or bit-rate based on the client capabilities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04NPICTORIAL COMMUNICATION, e.g. TELEVISION
    • H04N21/00Selective content distribution, e.g. interactive television or video on demand [VOD]
    • H04N21/80Generation or processing of content or additional data by content creator independently of the distribution process; Content per se
    • H04N21/81Monomedia components thereof
    • H04N21/8166Monomedia components thereof involving executable data, e.g. software
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y02TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
    • Y02DCLIMATE CHANGE MITIGATION TECHNOLOGIES IN INFORMATION AND COMMUNICATION TECHNOLOGIES [ICT], I.E. INFORMATION AND COMMUNICATION TECHNOLOGIES AIMING AT THE REDUCTION OF THEIR OWN ENERGY USE
    • Y02D30/00Reducing energy consumption in communication networks
    • Y02D30/50Reducing energy consumption in communication networks in wire-line communication networks, e.g. low power modes or reduced link rate

Definitions

  • the present disclosure relates to the field of set top box technologies, for example, to a method and system for dynamically configuring a multiple CA of a set top box.
  • each cable TV adopts different technical standards, which brings a lot of problems to the unification of the front end. If all the front ends are directly integrated, it takes a lot of manpower and material resources, and it also takes time to give the front end. Unification has brought about no small obstacles.
  • CA is the abbreviation of Conditional Access
  • Chinese is conditional access, referred to as CA.
  • CA is a technical means that allows only authorized users to use a certain service, which cannot be used by unauthorized users.
  • the same set-top box has multiple CAs built in, and multiple CAs work at the same time, but the set-top box only uses the corresponding CA to descramble the channel according to the type of the card, so that the program is normally viewed.
  • the set-top box can work under different front-ends at the same time, if the same CA is used in different places, the functions and versions are different, and it is impossible to ensure that the multiple-CA set-top boxes work simultaneously on the two front ends. In addition, this technology cannot be solved for the cardless CA solution.
  • a set-top box has multiple CAs built in. The resource consumption of the set-top box is too large (the priority of the CA thread must be high), and the built-in multiple CAs are too expensive.
  • the present disclosure aims to provide a method and system for dynamically configuring a multiple CA of a set top box, which aims to solve the problem that a set top box has multiple CAs built in the prior art, and the resource consumption of the set top box is too large (CA thread Priority must be high), second to build multiple CAs, cost too High defects.
  • a method for dynamically configuring a multiple CA in a set top box comprising:
  • the CA adapter library specifically includes:
  • the certificate of the operator is invalid, the certificate of the operator is re-downloaded.
  • the certificate of the operator is decrypted and verified by the chip, and whether the certificate of the operator is legal is determined.
  • the CA adapter library specifically includes:
  • the certificate of the operator is invalid, the certificate of the operator is re-downloaded.
  • the creating a CA software manager where the CA software manager communicates with the dynamic CA adapter library, specifically includes:
  • the public interface refers to defining a function pointer in the dynamic CA adaptation library, and the function pointer passes the corresponding function handle to the CA software manager, and the CA software manager adapts the function handle and the dynamic CA. Distribution library communication.
  • the obtaining the certificate of the operator and the certificate of the dynamic CA adaptation library specifically include:
  • the certificate of the operator and the certificate of the dynamic CA adapter library are obtained from a specified folder in the flash memory.
  • the method further includes:
  • the CA version number is changed, it is judged whether the set top box is suitable for upgrading the dynamic CA adapter library, and if necessary, downloading and upgrading the dynamic CA adapter library.
  • the CA version number is changed, if the CA version number is changed, it is determined whether the set top box is suitable for upgrading the dynamic CA adapter library, and if applicable, downloading and upgrading the dynamic CA adapter library, specifically include:
  • the library if appropriate, downloads and upgrades the dynamic CA adapter library.
  • the method further includes:
  • the replacement of the smart card is detected, and the type of the smart card after the replacement is obtained;
  • the dynamic CA adaptation library is downloaded according to the download address.
  • a set top box dynamically configures a multi-CA system, the system includes:
  • Creating a module configured to create a CA software manager, and the CA software manager communicates with the dynamic CA adapter library;
  • a certificate obtaining module configured to obtain a certificate of the operator and a certificate of the dynamic CA adapter library
  • a certificate verification module configured to determine whether the certificate of the operator and the certificate of the dynamic CA adaptation library are legal, and if the certificate of the operator and the certificate of the dynamic CA adaptation library are legal, loading and starting The dynamic CA adaptation library;
  • control module configured to dynamically switch the multiple CA according to the dynamic CA adaptation library.
  • the certificate verification module specifically includes:
  • the certificate judging unit is configured to determine whether the certificate of the operator is legal, if the certificate of the operator is legal;
  • the verification and loading unit is configured to check whether the certificate of the dynamic CA adapter library is legal by using the certificate of the operator, and if the certificate of the dynamic CA adapter library is legal, loading and starting the dynamic CA adapter library ;
  • the application unit is configured to re-apply the dynamic CA adapter library if the certificate of the dynamic CA adapter library is invalid;
  • the certificate downloading unit is configured to re-download the certificate of the operator if the certificate of the operator is invalid.
  • the creating module is specifically:
  • the CA software manager communicates with the dynamic CA adapter library through a public interface; wherein the public interface refers to defining a function pointer in the dynamic CA adaptation library, The function pointer passes the corresponding function handle to the CA software manager, and the CA software manager communicates with the dynamic CA adapter library through the function handle.
  • the certificate obtaining module specifically includes:
  • a detecting unit configured to initialize a CA software manager, the CA software manager detecting machine Whether the dynamic CA adapter library exists in the top box flash memory;
  • the certificate obtaining unit is configured to obtain the certificate of the operator and the certificate of the dynamic CA adapter library from a specified folder in the flash memory if it is detected that the dynamic CA adapter library exists in the flash memory.
  • the system further includes a determining and downloading module, where the determining and downloading module specifically includes:
  • a determining unit configured to detect whether there is a change in the CA version number
  • the first download unit is configured to determine whether the set top box is suitable for upgrading the dynamic CA adapter library if the CA version number is changed, and download and upgrade the dynamic CA adapter library if applicable.
  • system further includes a smart card replacement and download module, where the smart card replacement and download module specifically includes:
  • the smart card type obtaining unit is configured to detect that the smart card is replaced, and obtain the type of the smart card after the replacement;
  • the download mode and the address obtaining unit are configured to obtain a download address of the dynamic CA adapter library according to the type of the smart card and the set top box information;
  • the second download unit is configured to download the dynamic CA adaptation library according to the download address.
  • a non-transitory computer readable storage medium storing computer executable instructions arranged to perform the method of any of the above.
  • An electronic device comprising:
  • At least one processor At least one processor
  • the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to cause the at least one processor to perform the method of any of the above.
  • the present disclosure provides a method and system for dynamically configuring a multiple CA in a set top box.
  • the set top box can perform a request for a corresponding CA adapter library according to the information description of each place and download it to the set top box, and the set top box uses the downloaded adaptation.
  • the library performs normal program descrambling, which reduces resource consumption and reduces configuration costs.
  • Embodiment 1 is a flowchart of Embodiment 1 of a method for dynamically configuring a multiple CA of a set top box according to the present disclosure
  • FIG. 2 is a flow chart of the step 200 disclosed in the first embodiment
  • Embodiment 3 is a flowchart of Embodiment 2 of a method for dynamically configuring a multiple CA of a set top box according to the present disclosure
  • Embodiment 4 is a flowchart of Embodiment 3 of a method for dynamically configuring a multiple CA of a set top box according to the present disclosure
  • FIG. 5 is a sequence diagram of interaction between a CA software manager and a dynamic CA adapter library in Embodiment 4 of a method for dynamically configuring a multiple set CA of a set top box according to the present disclosure
  • FIG. 6 is a flowchart of a dynamic CA adaptation library startup according to Embodiment 5 of a method for dynamically configuring a multiple CA of a set top box according to the present disclosure
  • FIG. 7 is a timing diagram of a card identification program, a CA software manager, and a front end interaction of a method for dynamically configuring a multiple CA of a set top box according to the present disclosure
  • FIG. 8 is a functional block diagram of a system for dynamically configuring a multiple CA of a set top box according to the present disclosure
  • FIG. 9 is a functional block diagram of a public interface creation module of a system for dynamically configuring a multiple CA of a set top box according to the present disclosure
  • FIG. 10 is a functional block diagram of a certificate obtaining module of a system in which a set top box dynamically configures multiple CAs according to the present disclosure
  • FIG. 11 is a functional block diagram of a determination and download module of a system for dynamically configuring a multiple CA of a set top box according to the present disclosure
  • FIG. 12 is a functional block diagram of a smart card replacement and download module of a system in which a set top box dynamically configures multiple CAs according to the present disclosure
  • FIG. 13 is a schematic structural diagram of hardware of an electronic device provided by the present disclosure.
  • Embodiment 1 of a method for dynamically configuring a multiple CA of a set top box is provided in the present disclosure. As shown in FIG. 1 , the method includes:
  • Step 100 Create a CA software manager, and the CA software manager communicates with the dynamic CA adapter library.
  • Step 200 Obtain a certificate of the operator and a certificate of the dynamic CA adaptation library.
  • Step 300 Determine whether the certificate of the operator and the certificate of the dynamic CA adapter library are legal. If the certificate of the operator and the certificate of the dynamic CA adapter library are legal, the dynamic CA is loaded and started. Adaptation library.
  • Step 400 Dynamically switch the multiple CA according to the dynamic CA adaptation library.
  • step 100 the same terminal set-top box software is required to simultaneously support different front-end dynamic CA adapter libraries, and the terminal set-top box needs to create a new module called CA software manager (hereinafter referred to as DOWNCA), and DOWNCA can simultaneously Multi-CA dynamic switching adopts dynamic loading, so that DOWNCA communicates with the dynamic CA adapter library.
  • CA software manager hereinafter referred to as DOWNCA
  • step 200 after the box is started, the DOWNCA first checks whether there is a dynamic CA adapter library in the flash memory. When a dynamic CA adapter library is found, the license certificate of the operator and the corresponding dynamic CA are found from the designated place of the flash. License certificate for the library.
  • step 300 the carrier is decrypted and verified by the chip to check whether it is legal. Then, the license of the operator is used to verify whether the license of the dynamic CA adapter library is legal. If the license is legal, the license is loaded and started.
  • the dynamic CA adaptation library if it is not legal, goes to the corresponding network-based server to request the corresponding dynamic CA adaptation library according to the corresponding set-top box identification code stbid, according to the card-carrying situation, the area id, the CA version and other set-top box related information. Set-top box gets requested After the dynamic adaptation of the library, the certificate of the operator and the dynamic CA adapter library is verified. Until the certificate of the carrier certificate and the dynamic CA adapter library are both valid, the corresponding dynamic CA adaptation is loaded and started. Library.
  • each local set top box starts the data according to the dynamic CA adaptation library, thereby performing switching of multiple CAs as needed.
  • the step 100 specifically includes:
  • Creating a CA software manager of the management CA the CA software manager communicating with the dynamic CA adaptation library through a public interface; wherein the public interface refers to defining a function pointer in the dynamic CA adaptation library, the function The pointer passes the corresponding function handle to the CA software manager, and the CA software manager communicates with the dynamic CA adapter library through the function handle.
  • the same terminal set-top box software can simultaneously support different front-end dynamic CA adapter libraries, so a unified interface should be encapsulated.
  • DOWNCA adopts dynamic loading mode, which requires establishing a common interface between DOWNCA and dynamic CA adapter library.
  • the method is to use the function pointer in the dynamic library.
  • the function pointer is initialized, and the corresponding function handle is passed to the DOWNCA, and then the function handle and the dynamic library dynamic Interaction.
  • step 200 specifically includes:
  • Step 201 Initialize a CA software manager, and the CA software manager detects whether a dynamic CA adapter library exists in the set top box flash memory.
  • Step 202 If it is detected that the dynamic CA adapter library exists in the flash memory, obtain a certificate of the operator and a certificate of the dynamic CA adapter library from a specified folder in the flash memory.
  • DOWNCA after the set-top box is powered on, first initialize DOWNCA, DOWNCA first checks whether there is a dynamic CA adapter library in the flash flash memory (the default is no dynamic CA adapter library in the empty box), after discovering the dynamic CA adapter library Then, find the license certificate of the carrier and the license certificate corresponding to the dynamic CA adapter library from the specified place in the flash.
  • the method further includes:
  • Step 511 Check whether the CA version number changes.
  • Step 512 If it is detected that the CA version number changes, it is determined whether the set top box is suitable for upgrading the dynamic CA adaptation library, and if necessary, downloading and upgrading the dynamic CA adaptation library.
  • the descriptor descriptor_tag 0x** of the NIT table is monitored. Check whether the dynamic CA adapter library version number changes compared with the last saved local. If it is inconsistent with the last saved or the previous version is not saved, it depends on the set-top box ID, software version number, area ID, OUI, serial number, etc. OUI is the organization number given by the set-top box manufacturer to confirm whether the current set-top box is suitable for upgrading the DOWNCA dynamic library. If it is, then go to the download mode in the descriptor to trigger the download update, and if it does not, do nothing.
  • the download method is IP upgrade.
  • the IP upgrade is a network protocol upgrade that accesses the front-end server to obtain resources through the Internet connection.
  • the format of the data for transmission defined by the transport layer of the MPEG-2 protocol in the IP upgrade, and the NIT table describes the information of the entire transport network.
  • the NIT new descriptor definitions in this disclosure are shown in Table 1:
  • descriptor_tag--8-bit field used to identify each descriptor.
  • Descriptor_length - 8-bit field indicating the number of bytes of the descriptor immediately following this field.
  • Download_mode---Download mode 4-bit field, 0: indicates oc; 1 indicates ip;
  • CA_name Describes the corresponding CA name. Where uimsbf is an unsigned integer.
  • the method further includes:
  • Step 521 It is detected that the smart card is replaced, and the type of the smart card after the replacement is obtained.
  • Step 522 Acquire a download address of the dynamic CA adapter library according to the type of the smart card and the set top box information.
  • Step 523 Download a dynamic CA adaptation library according to the download address.
  • the smart card inserted by the set top box at this time is an A type card.
  • replace a type such as a B card, determine the B card type according to the ATR (Answer to Reset) and the set-top box and smart card communication information, and then obtain the set-top box ID, area ID, OUI information, etc., and then from the flash.
  • Get the download mode (the download mode is the download mode written when the NIT triggers the download. If there is no NIT trigger or the NIT trigger is not written to the download mode, the IP download is used by default).
  • the CA name and the information are packaged into an encrypted command and sent to the front end.
  • the front end decrypts and interprets the command according to the corresponding algorithm, so that the download address of the corresponding dynamic CA adapter library is found from the database and transmitted back to the set top box, and the set top box is downloaded according to the download. Address to download the dynamic CA adapter library. Then check to determine the correctness of the dynamic CA adapter library.
  • the verification method is as in step 200 and step 300 above.
  • the present disclosure also provides a timing diagram of interaction between the CA software manager and the dynamic CA adapter library in the fourth embodiment of the method for dynamically configuring the multiple set CA of the set top box, as shown in FIG. 5 , and the specific timing is as follows:
  • the CA software manager loads the dynamic CA adapter library via dlopen, where dlopen is used to load the program's statements.
  • the dynamic CA adaptation library returns the handle of the dynamic CA adaptation library.
  • the CA software manager finds the corresponding initialization connection according to the handle of the dynamic library through dlsym(handle, symbol_name).
  • the CA software manager calls module->strat_service to notify the dynamic CA adaptation library CA to descramble.
  • the CA software manager calls module->stopservice to notify the dynamic CA adapter library to stop descrambling.
  • the CA software manager calls module->Itocl to go to the dynamic CA adaptation library to obtain information and return information.
  • the dynamic CA adapter library returns CA prompt information, error information, and business information popup.
  • the page displays the corresponding information.
  • the present disclosure further provides a flowchart of a dynamic CA adaptation library startup in a method for dynamically configuring a multiple CA of a set top box. As shown in FIG. 6, the method includes:
  • Step 1 Detect whether there is a dynamic CA adapter library in the set top box. If yes, go to step 2. If no, go to step 3.
  • Step 2 The operator's license and the corresponding dynamic CA adapter library are read from the flash.
  • Step 3 You need to re-apply and download the dynamic CA adapter library.
  • Step 4 Verify that the license of the carrier is legal. If yes, go to step 5. If no, go to step 6.
  • Step 5 Use the legal carrier license to verify the license of the corresponding dynamic CA adapter library.
  • Step 6 Apply for the corresponding carrier license to the front end.
  • Step 7 Whether the download is successful. If yes, go to step 4. If no, go to step 8.
  • Step 8 Contact the staff to update the operator Lisence.
  • Step 9 Check whether the dynamic CA adapter library license is legal. If yes, go to step 21. If no, go to step 10.
  • Step 10 Re-apply and download the corresponding dynamic CA adapter library and related license.
  • step 11 the dynamic CA adapter library and the license corresponding to the request are sent to the front end.
  • Step 12 Whether an abnormality occurs, if yes, step 13 is performed, and if not, step 14 is performed.
  • Step 13 Multiple requests.
  • Step 14 First, the md5 algorithm is used to calculate the signature and the final signature according to the previous four bytes.
  • Step 15. Determine whether the result of the multiple request is normal. If yes, execute step 14. If no, go to step 16.
  • Step 16 pop up an error prompt and prompt to call customer service for help.
  • Step 17. Verify that the signature is successful. If yes, go to step 18. If no, go to step 11.
  • Step 18 Unpack the package to generate a corresponding dynamic CA adapter library and a corresponding license.
  • Step 19 Verify the license of the CA dynamic adapter library by using the legal carrier license.
  • Step 20 Whether the signature is legal, if yes, go to step 21, if no, go to step 11.
  • Step 21 Normally load and run the CA Software Manager.
  • the present disclosure also provides a timing diagram of the card identification program, the CA software manager, and the front end interaction of the sixth embodiment of the method for dynamically configuring the multiple set CA of the set top box, as shown in FIG. 7 , and the specific timing is as follows:
  • the CA software manager Determine whether the card identification program can identify, if it can be identified, according to ATR and machine card communication correctly identify the card, the CA software manager obtains the set-top box ID, area ID, OUI information and puts it together in the name of the CA to send the front end; Unrecognized, judged invalid card, pop-up prompt.
  • a default dynamic CA adapter library is loaded; if there is a default dynamic adaptation library, if not, the CA software manager obtains the set top box ID, the area ID, and the OUI information is associated with the CA name. Put together to send the front end; if it exists, the CA software directly loads and loads Row.
  • the front end goes to the database to find the address of the corresponding dynamic CA adapter library according to the request of the set top box, and sends it to the set top box.
  • the CA software manager requests downloading based on the corresponding address.
  • the front end sends the packaged file to the terminal software.
  • the CA software manager verifies the downloaded package file and then dynamically loads it.
  • the NIT table monitor receives the corresponding NIT descriptor, parses the descriptor to obtain the corresponding version, serial number, CA name, and other information; determines whether the comparison is passed, and if passed, passes the information to the CA software manager; if not, passes the information to the CA software manager; The NIT version is small or the serial number is out of range. The stbid or other information is incorrect.
  • the NIT table monitors and discards the descriptor.
  • the CA software manager obtains the set-top box ID, the area ID, and the OUI information is sent together with the CA name to send the front end.
  • the front end goes to the database to find the address of the corresponding dynamic CA adapter library according to the request of the set top box, and sends it to the set top box.
  • the set-top box CA software manager requests downloading according to the corresponding address.
  • the front end sends the packaged file to the CA software manager.
  • the CA software manager verifies the downloaded package file and then dynamically loads it.
  • the present disclosure also provides a functional block diagram of a system in which a set top box dynamically configures multiple CAs. As shown in FIG. 8, the system includes:
  • the creation module 01 is configured to create a CA software manager that communicates with the dynamic CA adaptation library; as described in the method embodiments.
  • the certificate obtaining module 02 is configured to obtain the certificate of the operator and the certificate of the dynamic CA adapter library; specifically, as described in the method embodiment.
  • the certificate verification module 03 is configured to determine whether the certificate of the operator and the certificate of the dynamic CA adapter library are legal. If the certificate of the operator and the certificate of the dynamic CA adapter library are legal, the module is loaded. The dynamic CA adaptation library is started; as described in the method embodiment.
  • the control module 04 is configured to dynamically switch the multiple CA according to the dynamic CA adaptation library; Specifically, as described in the method embodiments.
  • the public interface creation module 01 specifically includes:
  • a first creating unit 011 configured to create a CA software manager of the management CA, wherein the CA software manager communicates with the dynamic CA adapter library through a public interface; wherein the public interface refers to the dynamic CA adapter library a function pointer is defined, the function pointer passes a corresponding function handle to the CA software manager, and the CA software manager communicates with the dynamic CA adapter library through the function handle; Said.
  • the certificate obtaining module 02 specifically includes:
  • the detecting unit 021 is configured to initialize the CA software manager, and the CA software manager detects whether the dynamic CA adapter library exists in the set top box flash memory; as described in the method embodiment.
  • the certificate obtaining unit 022 is configured to obtain the certificate of the operator and the certificate of the dynamic CA adapter library from the specified folder in the flash memory if the dynamic CA adapter library exists in the flash memory, as described in the method embodiment. .
  • system further includes a determining and downloading module, as shown in FIG. 11, wherein the determining and downloading module specifically includes:
  • the determining unit 0511 is configured to detect whether there is a change in the current CA version number; as described in the method embodiment.
  • the first downloading unit 0512 is configured to determine whether the set-top box is suitable for upgrading the dynamic CA adapter library, and if necessary, downloading and upgrading the dynamic CA adapter library, as described in the method embodiment. .
  • the system further includes a smart card replacement and download module.
  • the smart card replacement and download module specifically includes:
  • the smart card type obtaining unit 0521 is configured to detect that the smart card is replaced when the set-top box is in operation, and obtain the type of the smart card after the replacement; as described in the method embodiment.
  • the download mode and address obtaining unit 0522 is configured to obtain the download address of the dynamic CA adapter library according to the type of the smart card and the set-top box information, which is specifically described in the method embodiment.
  • the second downloading unit 0523 is configured to download the dynamic CA adaptation library according to the download address; Specifically, as described in the method embodiments.
  • the present disclosure also provides a non-transitory computer readable storage medium storing computer executable instructions arranged to perform the method of any of the above embodiments.
  • the present disclosure also provides a hardware structure diagram of an electronic device.
  • the electronic device can perform the corresponding method steps as the set top box provided by the above embodiment.
  • the electronic device (set top box) includes:
  • At least one processor 50 which is exemplified by a processor 50 in FIG. 13; a display screen 51; and a memory 52, which may further include a communication interface 53 and a bus 54.
  • the processor 50, the display screen 51, the memory 52, and the communication interface 53 can complete communication with each other through the bus 54.
  • the display screen 51 is set to display a user guidance interface preset in the initial setting mode.
  • Communication interface 53 can transmit information.
  • Processor 50 can invoke logic instructions in memory 52 to perform the methods in the above-described embodiments.
  • logic instructions in the memory 52 described above may be implemented in the form of software functional units and sold or used as separate products, and may be stored in a computer readable storage medium.
  • the memory 52 is a computer readable storage medium, and can be configured to store a software program, a computer executable program, a program instruction or a module corresponding to the method in the embodiment of the present disclosure.
  • the processor 50 executes the functional application and data processing by executing software programs, instructions or modules stored in the memory 52, i.e., implements the methods of the above embodiments.
  • the memory 52 may include a storage program area and a storage data area, wherein the storage program area may store an operating system, an application required for at least one function; the storage data area may store data created according to usage of the terminal device, and the like. Further, the memory 52 may include a high speed random access memory, and may also include a nonvolatile memory.
  • All or part of the steps of the above embodiments may be completed by hardware, or may be executed by a program to execute related hardware.
  • the program may be stored in a computer readable storage medium, and the storage medium may be a non-transitory storage medium, including a USB flash drive. , mobile hard disk, read-only memory (ROM), random access memory (RAM), magnetic A medium such as a disk or an optical disk that can store program code, or a temporary storage medium.
  • the present disclosure provides a method and system for dynamically configuring a multiple CA in a set top box.
  • the method includes: creating a CA software manager, the CA software manager communicating with a dynamic CA adapter library; acquiring an operator certificate and a certificate of the dynamic CA adaptation library; detecting that the certificate of the operator and the certificate of the dynamic CA adaptation library are legal, loading and starting the dynamic CA adaptation library; according to the dynamic CA adaptation library Dynamically switching the multiple CAs.
  • the set top box can perform the request of the corresponding CA adaptation library according to the information description of each place and download to the set top box.
  • the set top box uses the downloaded adaptation library to perform normal program descrambling work, which reduces resource consumption and reduces configuration cost.

Landscapes

  • Engineering & Computer Science (AREA)
  • Signal Processing (AREA)
  • Multimedia (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Databases & Information Systems (AREA)
  • Library & Information Science (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Stored Programmes (AREA)
  • Storage Device Security (AREA)

Abstract

本公开涉及了一种机顶盒动态配置多CA的方法及系统,方法包括:创建CA软件管理器,所述CA软件管理器与动态CA适配库通信;获取运营商的证书和所述动态CA适配库的证书;判断所述运营商的证书和所述动态CA适配库的证书是否合法,若所述运营商的证书和所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库;根据所述动态CA适配库进行动态切换所述多CA。

Description

机顶盒动态配置多CA的方法及系统 技术领域
本公开涉及机顶盒技术领域,例如涉及一种机顶盒动态配置多CA的方法及系统。
背景技术
随着三网融合的演变,各个有线电视采用不同的技术标准,给前端的统一带来了不少问题,若直接整合全部前端,需要花费大量的人力和物力,同时也需要时间,都给前端统一带来了不小的阻碍。
CA是Conditional Access的缩写,中文为条件接收,简称CA。CA是一种技术手段,它只允许被授权的用户使用某一业务,未经授权的用户不能使用这一业务。目前,同一个机顶盒内置多种CA,多种CA同时工作,但机顶盒只根据插卡类型来使用相应的CA对频道进行解扰,从而正常观看节目。机顶盒虽然能够同时在不同的前端下工作,但是如果不同地方使用同一种CA,功能和版本不同,无法保证多CA的机顶盒在这两种前端同时工作。另外,对于无卡CA方案,该技术也无法解决。同时一个机顶盒内置多个CA,一来机顶盒的资源消耗过大(CA线程的优先级必须很高),二来内置多个CA,成本太高。
因此,现有技术还有待于改进和发展。
公开内容
鉴于现有技术的不足,本公开目的在于提供一种机顶盒动态配置多CA的方法及系统,旨在解决现有技术中一个机顶盒内置多个CA,一来机顶盒的资源消耗过大(CA线程的优先级必须很高),二来内置多个CA,成本太 高的缺陷。
本公开的技术方案如下:
一种机顶盒动态配置多CA的方法,方法包括:
创建CA软件管理器,所述CA软件管理器与动态CA适配库通信;
获取运营商的证书和所述动态CA适配库的证书;
判断所述运营商的证书和所述动态CA适配库的证书是否合法,若所述运营商的证书和所述动态CA适配库的证书合法,则加载并启动动态CA适配库;
根据所述动态CA适配库进行动态切换所述多CA。
可选的,判断所述运营商的证书和所述动态CA适配库的证书是否合法,若所述运营商的证书和所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库,具体包括:
判断所述运营商的证书是否合法,若所述运营商的证书合法;
利用所述运营商的证书检验所述动态CA适配库的证书是否合法,若所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库;若所述动态CA适配库的证书不合法则,重新申请所述动态CA适配库;
若所述运营商的证书不合法时,重新下载所述运营商的证书。
可选的,通过芯片对所述运营商的证书进行解密以及校验,判断所述运营商的证书是否合法。
可选的,判断所述运营商的证书和所述动态CA适配库的证书是否合法,若所述运营商的证书和所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库,具体包括:
判断所述运营商的证书是否合法,若所述运营商的证书合法;
利用所述运营商的证书检验所述动态CA适配库的证书是否合法,若所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库;若所述动态CA适配库的证书不合法则,重新申请所述动态CA适配库;
若所述运营商的证书不合法时,重新下载所述运营商的证书。
可选的,所述创建CA软件管理器,所述CA软件管理器与动态CA适配库通信,具体包括:
创建管理CA的CA软件管理器,所述CA软件管理器通过公共接口与动态CA适配库通信;
其中,所述公共接口是指在所述动态CA适配库中定义函数指针,所述函数指针将对应的函数句柄传递给CA软件管理器,CA软件管理器通过所述函数句柄与动态CA适配库通信。
可选的,所述获取运营商的证书和所述动态CA适配库的证书具体包括:
初始化CA软件管理器,CA软件管理器检测机顶盒闪存中是否存在动态CA适配库;
若检测到闪存中存在动态CA适配库,从闪存中的指定文件夹中获取运营商的证书和所述动态CA适配库的证书。
可选的,所述根据所述动态CA适配库进行动态切换所述多CA之后还包括:
检测CA版本号是否有变化;
若检测CA版本号有变化时,则判断机顶盒是否适合升级动态CA适配库,若适合则下载并升级动态CA适配库。
可选的,检测CA版本号是否有变化,若检测CA版本号有变化时,则判断机顶盒是否适合升级所述动态CA适配库,若适合则下载并升级所述动态CA适配库,具体包括:
监控NIT表的描述符descriptor_tag:0x**,检测动态CA适配库版本号与机顶盒本地上次保存的不一致或是机顶盒本地没有保存上次版本,则判断机顶盒是否适合升级所述动态CA适配库,若适合则下载并并升级所述动态CA适配库。
可选的,所述根据所述动态CA适配库进行动态切换所述多CA之后还包括:
检测到更换智能卡,获取更换后的所述智能卡的类型;
根据所述智能卡的类型及机顶盒信息,获取动态CA适配库的下载地址;
根据所述下载地址下载动态CA适配库。
一种机顶盒动态配置多CA的系统,系统包括:
创建模块,设置为创建CA软件管理器,所述CA软件管理器与动态CA适配库通信;
证书获取模块,设置为获取运营商的证书和所述动态CA适配库的证书;
证书校验模块,设置为判断所述运营商的证书和所述动态CA适配库的证书是否合法,若所述运营商的证书和所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库;
控制模块,设置为根据所述动态CA适配库进行动态切换所述多CA。
可选的,所述证书校验模块具体包括:
证书判断单元,设置为判断所述运营商的证书是否合法,若所述运营商的证书合法;
检验及加载单元,设置为利用所述运营商的证书检验所述动态CA适配库的证书是否合法,若所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库;
申请单元,设置为若所述动态CA适配库的证书不合法则,重新申请所述动态CA适配库;
证书下载单元,设置为若所述运营商的证书不合法时,重新下载所述运营商的证书。
可选的,所述创建模块具体:
设置为创建管理CA的CA软件管理器,所述CA软件管理器通过公共接口与动态CA适配库通信;其中,所述公共接口是指在所述动态CA适配库中定义函数指针,所述函数指针将对应的函数句柄传递给CA软件管理器,CA软件管理器通过所述函数句柄与所述动态CA适配库通信。
可选的,所述证书获取模块具体包括:
检测单元,设置为初始化CA软件管理器,所述CA软件管理器检测机 顶盒闪存中是否存在所述动态CA适配库;
证书获取单元,设置为若检测到闪存中存在动态CA适配库,从闪存中的指定文件夹中获取运营商的证书和所述动态CA适配库的证书。
可选的,所述系统还包括判断与下载模块,其中判断与下载模块具体包括:
判断单元,设置为检测CA版本号是否有变化;
第一下载单元,设置为若检测CA版本号有变化时,则判断机顶盒是否适合升级所述动态CA适配库,若适合则下载并升级所述动态CA适配库。
可选的,所述系统还包括智能卡更换与下载模块,智能卡更换与下载模块具体包括:
智能卡类型获取单元,设置为检测到更换智能卡,获取更换后的所述智能卡的类型;
下载方式及地址获取单元,设置为根据所述智能卡的类型及机顶盒信息,获取动态CA适配库的下载地址;
第二下载单元,设置为根据所述下载地址下载动态CA适配库。
一种非暂态计算机可读存储介质,存储有计算机可执行指令,所述计算机可执行指令设置为执行上述任一项所述的方法。
一种电子设备,包括:
至少一个处理器;以及
与所述至少一个处理器通信连接的存储器;其中,
所述存储器存储有可被所述至少一个处理器执行的指令,所述指令被所述至少一个处理器执行,以使所述至少一个处理器执行上述任一项的方法。
有益效果:本公开提供了一种机顶盒动态配置多CA的方法及系统,本公开中机顶盒可根据各地方的信息描述进行对应CA适配库的请求并下载到机顶盒,机顶盒使用下载来的适配库进行正常的节目解扰工作,减少了资源消耗,降低了配置成本。
附图说明
为了清楚地说明本公开实施例中的技术方案,下面将对本公开实施例描述中使用的附图进行介绍。
图1为本公开提供的的一种机顶盒动态配置多CA的方法实施例一的流程图;
图2为为实施例一公开的步骤200的流程图;
图3为本公开提供的一种机顶盒动态配置多CA的方法实施例二的流程图;
图4为本公开提供的一种机顶盒动态配置多CA的方法实施例三的流程图;
图5为本公开提供的一种机顶盒动态配置多CA的方法实施例四的CA软件管理器与动态CA适配库交互的时序图;
图6为本公开提供的一种机顶盒动态配置多CA的方法的实施例五的动态CA适配库启动的流程图;
图7为本公开提供的一种机顶盒动态配置多CA的方法实施例六的卡识别程序与CA软件管理器、以及前端交互的时序图;
图8为本公开提供的一种机顶盒动态配置多CA的系统的功能原理框图;
图9为本公开提供的一种机顶盒动态配置多CA的系统的公共接口创建模块的功能原理框图;
图10为本公开提供的一种机顶盒动态配置多CA的系统的证书获取模块的功能原理框图;
图11为本公开提供的一种机顶盒动态配置多CA的系统的判断与下载模块的功能原理框图;
图12为本公开提供的一种机顶盒动态配置多CA的系统的智能卡更换与下载模块的功能原理框图;以及
图13为本公开提供的电子设备的硬件结构示意图。
具体实施方式
为使本公开采用的技术方案更加清楚,下面将结合附图对本公开实施例的技术方案作详细描述,所描述的实施例仅仅是本公开一部分实施例,而不是全部的实施例。在不冲突的情况下,以下实施例以及实施例中的技术特征可以相互任意组合。
实施例一
本公开提供的一种机顶盒动态配置多CA的方法实施例一的流程图,如图1所示,方法包括:
步骤100、创建CA软件管理器,所述CA软件管理器与动态CA适配库通信。
步骤200、获取运营商的证书和所述动态CA适配库的证书。
步骤300、判断所述运营商的证书和所述动态CA适配库的证书是否合法,若所述运营商的证书和所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库。
步骤400、根据所述动态CA适配库进行动态切换所述多CA。
具体实施时,步骤100中要求同一个终端机顶盒软件能够同时支持不同前端动态CA适配库,终端机顶盒要创建一个新的模块,称为CA软件管理器(以下简称DOWNCA),DOWNCA为了同时可以让多CA动态切换,采用动态加载的方式,这样DOWNCA与动态CA适配库通信。
步骤200中,盒子启机之后,DOWNCA先去检测flash闪存中是否有动态CA适配库,当发现有动态CA适配库之后,然后从flash指定地方找到运营商的License证书和对应动态CA适配库的License证书。
步骤300,通过芯片对运营商的证书进行解密以及校验,看其是否合法,然后用运营商的License去校验动态CA适配库的license是否合法,如果license合法,就去加载并启动对应的动态CA适配库,如果不合法,就去根据对应的机顶盒识别码stbid,根据插卡情况,区域id,CA版本等机顶盒相关信息到省网服务器上去请求对应的动态CA适配库。机顶盒获取请求的 动态适配库后,继续对运营商及动态CA适配库的证书进行校验,直到检测运营商证书和动态CA适配库的证书都是合法的,则加载并启动对应的动态CA适配库。
步骤400中各地方机顶盒根据动态CA适配库启动后的数据,从而根据需要进行多个CA的切换。
进一步的实施例中,步骤100中具体包括:
创建管理CA的CA软件管理器,所述CA软件管理器通过公共接口与动态CA适配库通信;其中,所述公共接口是指在所述动态CA适配库中定义函数指针,所述函数指针将对应的函数句柄传递给所述CA软件管理器,所述CA软件管理器通过所述函数句柄与所述动态CA适配库通信。具体实施时,同一个终端机顶盒软件能够同时支持不同前端动态CA适配库,所以要封装一套统一的接口。DOWNCA为了同时可以让多CA动态切换,采用动态加载的方式,这样需要在DOWNCA与动态CA适配库之间建立一个公共的接口。
具体实施时,采用的方式是在动态库里面使用函数指针,动态CA适配库被加载并初始化的时候,初始化函数指针,并把对应的函数句柄传递给DOWNCA,然后通过函数句柄与动态库动态交互。
类似的接口如下:
Figure PCTCN2017093071-appb-000001
动态适配库初始化接口参考代码:
Figure PCTCN2017093071-appb-000002
进一步的,如图2所示,步骤200具体包括:
步骤201、初始化CA软件管理器,所述CA软件管理器检测机顶盒闪存中是否存在动态CA适配库。
步骤202、若检测到闪存中存在所述动态CA适配库,从所述闪存中的指定文件夹中获取运营商的证书和所述动态CA适配库的证书。
具体实施时,机顶盒开机之后,首先初始化DOWNCA,DOWNCA先去检测flash闪存中是否有动态CA适配库(空盒子里面默认是没有动态CA适配库的),当发现有动态CA适配库之后,然后从flash指定地方找到运营商的License证书和对应动态CA适配库的License证书。
实施例二
进一步地,如图3所示,步骤400之后还包括:
步骤511、检测CA版本号是否有变化。
步骤512、若检测CA版本号有变化时,则判断机顶盒是否适合升级动态CA适配库,若适合则下载并升级动态CA适配库。
具体实施时,机顶盒在运行时,监控NIT表的描述符descriptor_tag:0x**, 查看动态CA适配库版本号对比本地上次保存的是否有变化,如果与上次保存的不一致或者上次版本没有保存,则根据机顶盒ID、软件版本号以及区域ID,OUI,序列号等信息,OUI为机顶盒厂家给予的组织号,确认当前的机顶盒是否适合升级DOWNCA动态库,如果符合,则去查看描述符中的下载方式去触发下载更新,如果不符合则什么都不做。下载方式为IP升级。IP升级就是网络协议升级,通过因特网的连接,去访问前端服务器来获取资源。其中IP升级中MPEG-2协议传输层定义的一种用于传输的数据的格式,NIT表描述了整个传输网络的信息。在本公开中NIT新增描述符定义如表1所示:
表1
Syntax语法 No.of.bits字节数 Identifier标识符
*_*_descriptor(){    
descriptor_tag=0x** 8 uimsbf
descriptor_length 8 uimsbf
version 8 uimsbf
Download_Type 8 uimsbf
STB_id 32 uimsbf
OUI 32 uimsbf
serialNumber_start 128 uimsbf
serialNumber_end 128 uimsbf
CA_name 128 uimsbf
}    
表1中各参数定义如下:descriptor_tag---8位字段,用于标识各描述符。
descriptor_length---8位字段,用于指明紧接在此字段后的描述符的字节数量。
download_mode---下载方式,4位字段,0:表示oc;1表示ip;
Version---CA动态适配库的版本;
STB_ID---机顶盒;其中0xFFFF表示所有终端软件版本;
OUI---机顶盒厂家给予的组织号;
serialNumber_start---下载更新终端的起始序列号;
serialNumber_end---下载更新终端的结束序列号;
CA_name:描述对应的CA名称。其中uimsbf为无符号整数。
实施例三
再进一步的实施例,如图4所示,步骤400之后还包括:
步骤521、检测到更换智能卡,获取更换后的所述智能卡的类型。
步骤522、根据所述智能卡的类型及机顶盒信息,获取动态CA适配库的下载地址。
步骤523、根据所述下载地址下载动态CA适配库。
具体实施时,当机顶盒正在运行时,此时机顶盒插入的智能卡是A类型的卡。这个时候更换一种类型,例如B卡,根据ATR(Answer to Reset,自动复位响应)和机顶盒与智能卡通讯信息判断B卡类型,然后获取机顶盒ID,区域ID,OUI信息等信息,接着从flash中获取下载方式(下载方式是NIT触发下载时候写入的下载方式,如果没有NIT触发或者NIT触发没有写入下载方式,默认采用IP下载)。将CA名称与这些信息打包成一条加密的命令发往前端,前端根据相应的算法解密并解读命令,从而从数据库中找到对应的动态CA适配库的下载地址,传回给机顶盒,机顶盒根据下载地址去下载动态CA适配库。然后去校验判断动态CA适配库的正确性。校验方法如上述步骤200和步骤300。
实施例四
本公开还提供了一种机顶盒动态配置多CA的方法实施例四的CA软件管理器与动态CA适配库交互的时序图,如图5所示,具体时序如下:
初始化CA软件管理器。
CA软件管理器通过dlopen加载动态CA适配库,其中dlopen用于加载程序的语句。
动态CA适配库返回动态CA适配库的句柄。
CA软件管理器通过dlsym(handle,symbol_name)根据动态库的句柄找到对应的初始化接。
在动态CA适配库的初始化接口里面初始化函数指针,并返回对应的句柄。
当播放节目时,CA软件管理器调用module->strat_service去通知动态CA适配库CA解扰。
当停止节目时,CA软件管理器调用module->stopservice去通知动态CA适配库停止解扰。
当获取CA信息时,CA软件管理器调用module->Itocl去动态CA适配库获取信息,并返回信息。
动态CA适配库返回CA提示信息,错误信息,业务信息弹出。
页面显示对应信息。
实施例五
本公开还提供了一种机顶盒动态配置多CA的方法实施例五的动态CA适配库启动的流程图,如图6所示,方法包括:
步骤1、检测机顶盒中是否存在动态CA适配库,若是,则执行步骤2,若否,则执行步骤3。
步骤2、从flash中读取运营商的License和对应动态CA适配库。
步骤3、需要重新申请并下载动态CA适配库。
步骤4、校验运营商的License是否合法,若是,则执行步骤5,若否,则执行步骤6。
步骤5、利用合法的运营商License去校验对应动态CA适配库的License。
步骤6、向前端申请对应的运营商License。
步骤7、是否成功下载,若是,则执行步骤4,若否,则执行步骤8。
步骤8、联系工作人员上门更新运营商Lisence。
步骤9、检验动态CA适配库License是否合法,若是,则执行步骤21, 若否,则执行步骤10。
步骤10、重新申请和下载对应的动态CA适配库和相关的License。
步骤11、往前端发送去请求对应的动态CA适配库和License。
步骤12、是否出现异常,若是,则执行步骤13,若否,则执行步骤14。
步骤13、多次请求。
步骤14、首先根据前面的4个字节进行md5算法算出签名与末尾签名比较。
步骤15、判断多次请求的结果是否正常,若是,则执行步骤14,若否,则执行步骤16。
步骤16、弹出错误提示并提示打客服电话求助。
步骤17、校验签名是否成功,若是,则执行步骤18,若否,则执行步骤11。
步骤18、对包进行解包生成对应的动态CA适配库和相应的License。
步骤19、利用合法的运营商License去校验CA动态适配库的License。
步骤20、签名是否合法,若是,则执行步骤21,若否,则执行步骤11。
步骤21、正常加载并运行CA软件管理器。
实施例六
本公开还提供了一种机顶盒动态配置多CA的方法实施例六的卡识别程序与CA软件管理器、以及前端交互的时序图,如图7所示,具体时序如下:
检测到有卡插入。
判断卡识别程序能否识别,若能识别,根据ATR以及机卡通讯正确识别卡,CA软件管理器获取机顶盒ID,区域ID,OUI信息将其于CA名称一起拼起来发送前端;若多次仍无法识别,判定无效卡,弹出提示。
若没有识别到卡,加载一个默认的动态CA适配库;判断是否存在默认的动态适配库,若不存在,则CA软件管理器获取机顶盒ID,区域ID,OUI信息将其于CA名称一起拼起来发送前端;若存在,则CA软件直接加载运 行。
前端根据机顶盒的请求,到数据库中去寻找对应的动态CA适配库的地址,并发送给机顶盒。
CA软件管理器根据对应的地址去请求下载。
前端把打包好的文件下发到终端软件。
CA软件管理器对下载的的打包文件进行校验然后动态加载。
NIT表监控收到对应的NIT描述子,解析描述子获取对应的版本,序列号,CA名称等其他信息;判断比较是否通过,若通过,则将这些信息传递到CA软件管理器;若不通过,NIT版本较小或者序列号不在范围,stbid或其他信息不对,NIT表监控丢弃这个描述子。
CA软件管理器获取机顶盒ID,区域ID,OUI信息将其于CA名称一起拼起来发送前端。
前端根据机顶盒的请求,到数据库中去寻找对应的动态CA适配库的地址,并发送给机顶盒。
机顶盒CA软件管理器根据对应的地址去请求下载。
前端把打包好的文件下发到CA软件管理器。
CA软件管理器对下载的的打包文件进行校验然后动态加载。
本公开还提供了一种机顶盒动态配置多CA的系统的功能原理框图,如图8所示,系统包括:
创建模块01,设置为创建CA软件管理器,所述CA软件管理器与动态CA适配库通信;具体如方法实施例所述。
证书获取模块02,设置为获取运营商的证书和所述动态CA适配库的证书;具体如方法实施例所述。
证书校验模块03,设置为判断所述运营商的证书和所述动态CA适配库的证书是否合法,若所述运营商的证书和所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库;具体如方法实施例所述。
控制模块04,设置为根据所述动态CA适配库进行动态切换所述多CA; 具体如方法实施例所述。
进一步地,如图9所示,所述公共接口创建模块01具体包括:
第一创建单元011,设置为创建管理CA的CA软件管理器,所述CA软件管理器通过公共接口与动态CA适配库通信;其中,所述公共接口是指在所述动态CA适配库中定义函数指针,所述函数指针将对应的函数句柄传递给所述CA软件管理器,所述CA软件管理器通过所述函数句柄与所述动态CA适配库通信;;具体如方法实施例所述。
进一步地,如图10所示,所述证书获取模块02具体包括:
检测单元021,设置为初始化CA软件管理器,所述CA软件管理器检测机顶盒闪存中是否存在所述动态CA适配库;具体如方法实施例所述。
证书获取单元022,设置为若检测到闪存中存在动态CA适配库,从闪存中的指定文件夹中获取运营商的证书和所述动态CA适配库的证书;具体如方法实施例所述。
进一步地,所述系统还包括判断与下载模块,如图11所示,其中判断与下载模块具体包括:
判断单元0511,设置为检测到当前CA版本号是否有变化;具体如方法实施例所述。
第一下载单元0512,设置为若检测CA版本号有变化时,则判断机顶盒是否适合升级所述动态CA适配库,若适合则下载并升级动态CA适配库;具体如方法实施例所述。
进一步的实施例中,所述系统还包括智能卡更换与下载模块,如图12所示,智能卡更换与下载模块具体包括:
智能卡类型获取单元0521,设置为机顶盒在运行时,检测到更换智能卡,获取更换后的所述智能卡的类型;具体如方法实施例所述。
下载方式及地址获取单元0522,设置为根据所述智能卡的类型及机顶盒信息,获取动态CA适配库的下载地址;具体如方法实施例所述。
第二下载单元0523,设置为根据所述下载地址下载动态CA适配库; 具体如方法实施例所述。
本公开还提供了一种非暂态计算机可读存储介质,存储有计算机可执行指令,所述计算机可执行指令设置为执行上述任一实施例中的方法。
本公开还提供了一种电子设备的硬件结构示意图。该电子设备可以执行相应的方法步骤,作为上述实施例提供的机顶盒。如图13所示,该电子设备(机顶盒)包括:
至少一个处理器(processor)50,图13中以一个处理器50为例;显示屏51;以及存储器(memory)52,还可以包括通信接口(Communications Interface)53和总线54。其中,处理器50、显示屏51、存储器52和通信接口53可以通过总线54完成相互间的通信。显示屏51设置为显示初始设置模式中预设的用户引导界面。通信接口53可以传输信息。处理器50可以调用存储器52中的逻辑指令,以执行上述实施例中的方法。
此外,上述的存储器52中的逻辑指令可以通过软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。
存储器52作为一种计算机可读存储介质,可设置为存储软件程序、计算机可执行程序,如本公开实施例中的方法对应的程序指令或模块。处理器50通过运行存储在存储器52中的软件程序、指令或模块,从而执行功能应用以及数据处理,即实现上述实施例中的方法。
存储器52可包括存储程序区和存储数据区,其中,存储程序区可存储操作系统、至少一个功能所需的应用程序;存储数据区可存储根据终端设备的使用所创建的数据等。此外,存储器52可以包括高速随机存取存储器,还可以包括非易失性存储器。
上述实施例的全部或部分步骤可以通过硬件来完成,也可以通过程序来指令相关的硬件完成,该程序可以存储于一计算机可读存储介质中,存储介质可以是非暂态存储介质,包括U盘、移动硬盘、只读存储器(Read-Only Memory,ROM)、随机存取存储器(Random Access Memory,RAM)、磁 盘或光盘等等多种可以存储程序代码的介质,也可以是暂态存储介质。综上所述,本公开提供了一种机顶盒动态配置多CA的方法及系统,方法包括:创建CA软件管理器,所述CA软件管理器与动态CA适配库通信;获取运营商的证书和所述动态CA适配库的证书;检测到所述运营商的证书和所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库;根据所述动态CA适配库进行动态切换所述多CA。本公开中机顶盒可根据各地方的信息描述进行对应CA适配库的请求并下载到机顶盒,机顶盒使用下载来的适配库进行正常的节目解扰工作,减少了资源消耗,降低了配置成本。
应当理解的是,本公开的应用不限于上述的举例,对本领域普通技术人员来说,可以根据上述说明加以改进或变换,所有这些改进和变换都应属于本公开所附权利要求的保护范围。

Claims (16)

  1. 一种机顶盒动态配置多CA的方法,所述方法包括:
    创建CA软件管理器,所述CA软件管理器与动态CA适配库通信;
    获取运营商的证书和所述动态CA适配库的证书;
    判断所述运营商的证书和所述动态CA适配库的证书是否合法,若所述运营商的证书和所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库;
    根据所述动态CA适配库进行动态切换所述多CA。
  2. 根据权利要求1所述的机顶盒动态配置多CA的方法,判断所述运营商的证书和所述动态CA适配库的证书是否合法,若所述运营商的证书和所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库,具体包括:
    判断所述运营商的证书是否合法,若所述运营商的证书合法;
    利用所述运营商的证书检验所述动态CA适配库的证书是否合法,若所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库;若所述动态CA适配库的证书不合法则,重新申请所述动态CA适配库;
    若所述运营商的证书不合法时,重新下载所述运营商的证书。
  3. 根据权利要求2所述的机顶盒动态配置多CA的方法,通过芯片对所述运营商的证书进行解密以及校验,判断所述运营商的证书是否合法。
  4. 根据权利要求1所述的机顶盒动态配置多CA的方法,所述创建CA软件管理器,所述CA软件管理器与动态CA适配库通信,具体包括:
    创建管理CA的所述CA软件管理器,所述CA软件管理器通过 公共接口与动态CA适配库通信;
    其中,所述公共接口是指在所述动态CA适配库中定义函数指针,所述函数指针将对应的函数句柄传递给所述CA软件管理器,所述CA软件管理器通过所述函数句柄与所述动态CA适配库通信。
  5. 根据权利要求4所述的机顶盒动态配置多CA的方法,所述获取运营商的证书和所述动态CA适配库的证书具体包括:
    初始化所述CA软件管理器,所述CA软件管理器检测机顶盒闪存中是否存在所述动态CA适配库;
    若检测到所述闪存中存在所述动态CA适配库,从所述闪存中的指定文件夹中获取运营商的证书和所述动态CA适配库的证书。
  6. 根据权利要求5所述的机顶盒动态配置多CA的方法,所述根据所述动态CA适配库进行动态切换所述多CA之后还包括:
    检测CA版本号是否有变化;
    若检测CA版本号有变化时,则判断机顶盒是否适合升级所述动态CA适配库,若适合则下载并升级所述动态CA适配库。
  7. 根据权利要求6所述的机顶盒动态配置多CA的方法,检测CA版本号是否有变化,若检测CA版本号有变化时,则判断机顶盒是否适合升级所述动态CA适配库,若适合则下载并升级所述动态CA适配库,具体包括:
    监控NIT表的描述符descriptor_tag:0x**,检测动态CA适配库版本号与机顶盒本地上次保存的不一致或是机顶盒本地没有保存上次版本,则判断机顶盒是否适合升级所述动态CA适配库,若适合则下载并并升级所述动态CA适配库。
  8. 根据权利要求5所述的机顶盒动态配置多CA的方法,所述根据所述动态CA适配库进行动态切换所述多CA之后还包括:
    检测到更换智能卡,获取更换后的所述智能卡的类型;
    根据所述智能卡的类型及机顶盒信息,获取所述动态CA适配库 的下载地址;
    根据所述下载地址下载所述动态CA适配库。
  9. 一种机顶盒动态配置多CA的系统,系统包括:
    创建模块,设置为创建CA软件管理器,所述CA软件管理器与动态CA适配库通信;
    证书获取模块,设置为获取运营商的证书和所述动态CA适配库的证书;
    证书校验模块,设置为判断所述运营商的证书和所述动态CA适配库的证书是否合法,若所述运营商的证书和所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库;
    控制模块,设置为根据所述动态CA适配库进行动态切换所述多CA。
  10. 根据权利要求9所述的机顶盒动态配置多CA的系统,所述证书校验模块具体包括:
    证书判断单元,设置为判断所述运营商的证书是否合法,若所述运营商的证书合法;
    检验及加载单元,设置为利用所述运营商的证书检验所述动态CA适配库的证书是否合法,若所述动态CA适配库的证书合法,则加载并启动所述动态CA适配库;
    申请单元,设置为若所述动态CA适配库的证书不合法则,重新申请所述动态CA适配库;
    证书下载单元,设置为若所述运营商的证书不合法时,重新下载所述运营商的证书。
  11. 根据权利要求9所述的机顶盒动态配置多CA的系统,所述创建模块具体包括:
    第一创建单元,设置为创建管理CA的所述CA软件管理器,所述CA软件管理器通过公共接口与动态CA适配库通信;其中,所述 公共接口是指在所述动态CA适配库中定义函数指针,所述函数指针将对应的函数句柄传递给所述CA软件管理器,所述CA软件管理器通过所述函数句柄与所述动态CA适配库通信。
  12. 根据权利要求11所述的机顶盒动态配置多CA的系统,所述证书获取模块具体包括:
    检测单元,设置为初始化所述CA软件管理器,所述CA软件管理器检测机顶盒闪存中是否存在所述动态CA适配库;
    证书获取单元,设置为若检测到所述闪存中存在所述动态CA适配库,从所述闪存中的指定文件夹中获取运营商的证书和所述动态CA适配库的证书。
  13. 根据权利要求12所述的机顶盒动态配置多CA的系统,所述系统还包括判断与下载模块,其中判断与下载模块具体包括:
    判断单元,设置为检测到当前CA版本号是否有变化;
    第一下载单元,设置为若检测CA版本号有变化时,则判断机顶盒是否适合升级所述动态CA适配库,若适合则下载并升级所述动态CA适配库。
  14. 根据权利要求13所述的机顶盒动态配置多CA的系统,所述系统还包括智能卡更换与下载模块,智能卡更换与下载模块具体包括:
    智能卡类型获取单元,设置为机顶盒在运行时,检测到更换智能卡,获取更换后的所述智能卡的类型;
    下载方式及地址获取单元,设置为根据所述智能卡的类型及机顶盒信息,获取所述动态CA适配库的下载地址;
    第二下载单元,设置为根据所述下载地址下载所述动态CA适配库。
  15. 一种非暂态计算机可读存储介质,存储有计算机可执行指令,所述计算机可执行指令设置为执行权利要求1-8中任一项所述的方法。
  16. 一种电子设备,包括:
    至少一个处理器;以及
    与所述至少一个处理器通信连接的存储器;其中,
    所述存储器存储有可被所述至少一个处理器执行的指令,所述指令被所述至少一个处理器执行,以使所述至少一个处理器执行权利要求1-8中任一项的方法。
PCT/CN2017/093071 2016-07-18 2017-07-17 机顶盒动态配置多ca的方法及系统 WO2018014798A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201610563692.XA CN106210827B (zh) 2016-07-18 2016-07-18 一种动态配置机顶盒多ca的方法及系统
CN201610563692.X 2016-07-18

Publications (1)

Publication Number Publication Date
WO2018014798A1 true WO2018014798A1 (zh) 2018-01-25

Family

ID=57476010

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2017/093071 WO2018014798A1 (zh) 2016-07-18 2017-07-17 机顶盒动态配置多ca的方法及系统

Country Status (2)

Country Link
CN (1) CN106210827B (zh)
WO (1) WO2018014798A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114245211A (zh) * 2021-11-24 2022-03-25 广东九联科技股份有限公司 一种兼容双管理平台的机顶盒运行方法及机顶盒

Families Citing this family (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN106210827B (zh) * 2016-07-18 2019-06-11 深圳创维数字技术有限公司 一种动态配置机顶盒多ca的方法及系统
CN108574865A (zh) * 2018-03-30 2018-09-25 青岛海信电器股份有限公司 终端的解扰处理方法、装置及终端
CN110913252B (zh) * 2018-09-18 2023-06-20 深圳市茁壮网络股份有限公司 一种条件接收的切换方法及系统
CN110719528A (zh) * 2019-10-18 2020-01-21 重庆空间视创科技有限公司 一种iptv终端热更新系统及方法
CN111131869B (zh) * 2019-12-31 2021-12-28 国微集团(深圳)有限公司 多个ca系统实时动态切换的方法及系统

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2001026372A1 (en) * 1999-10-06 2001-04-12 Thomson Licensing S.A. Method and system for handling two ca systems in a same receiver
CN1455590A (zh) * 2003-06-23 2003-11-12 于劲飞 一种实现数字电视/数字电视机顶盒机卡分离的方法
CN1642266A (zh) * 2004-01-18 2005-07-20 北京中电华大电子设计有限责任公司 一种实现数字电视机顶盒机卡分离的技术方法
CN101365047A (zh) * 2008-09-09 2009-02-11 南京瑞晶集成电路设计有限公司 实现数字电视机顶盒机卡分离的方法
CN103297816A (zh) * 2013-05-08 2013-09-11 深圳创维数字技术股份有限公司 一种安全下载方法及数字电视接收终端
CN103607613A (zh) * 2013-11-21 2014-02-26 四川九洲电器集团有限责任公司 一种数字多媒体终端ca模块系统及其工作方法
CN106210827A (zh) * 2016-07-18 2016-12-07 深圳创维数字技术有限公司 一种动态配置机顶盒多ca的方法及系统

Family Cites Families (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CA2536103C (en) * 2003-09-05 2017-05-23 Comcast Cable Holdings, Llc Method and system for internet protocol provisioning of customer premises equipment

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2001026372A1 (en) * 1999-10-06 2001-04-12 Thomson Licensing S.A. Method and system for handling two ca systems in a same receiver
CN1455590A (zh) * 2003-06-23 2003-11-12 于劲飞 一种实现数字电视/数字电视机顶盒机卡分离的方法
CN1642266A (zh) * 2004-01-18 2005-07-20 北京中电华大电子设计有限责任公司 一种实现数字电视机顶盒机卡分离的技术方法
CN101365047A (zh) * 2008-09-09 2009-02-11 南京瑞晶集成电路设计有限公司 实现数字电视机顶盒机卡分离的方法
CN103297816A (zh) * 2013-05-08 2013-09-11 深圳创维数字技术股份有限公司 一种安全下载方法及数字电视接收终端
CN103607613A (zh) * 2013-11-21 2014-02-26 四川九洲电器集团有限责任公司 一种数字多媒体终端ca模块系统及其工作方法
CN106210827A (zh) * 2016-07-18 2016-12-07 深圳创维数字技术有限公司 一种动态配置机顶盒多ca的方法及系统

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN114245211A (zh) * 2021-11-24 2022-03-25 广东九联科技股份有限公司 一种兼容双管理平台的机顶盒运行方法及机顶盒

Also Published As

Publication number Publication date
CN106210827A (zh) 2016-12-07
CN106210827B (zh) 2019-06-11

Similar Documents

Publication Publication Date Title
WO2018014798A1 (zh) 机顶盒动态配置多ca的方法及系统
US9965270B2 (en) Updating computer firmware
US10127057B2 (en) Method and apparatus for dynamically implementing application function
US20180373523A1 (en) Application update method and apparatus
US10148731B2 (en) Methods, systems, and computer readable media for on-boarding virtualized network function (VNF) packages in a network functions virtualization (NFV) system
US8978024B2 (en) Federated system automatic update communication to enable selective update of critical firmware elements
US10042651B2 (en) Techniques to configure multi-mode storage devices in remote provisioning environments
US9342696B2 (en) Attesting use of an interactive component during a boot process
CN108351923B (zh) 与统一可扩展固件接口系统可执行的脚本有关的阈值
US20160087801A1 (en) Cryptographically enforcing strict separation of environments
US9100696B2 (en) System and method for upgrading a multiprocessor set-top box device with a monolithic firmware image
US10838751B1 (en) Virtual machine configuration
JP7021239B2 (ja) 初期オペレーティングシステム・セットアップ・オプションのリモート管理
CN106940651A (zh) Pos终端软件升级方法和装置
US20170124339A1 (en) Implementing method for javacard application function expansion
CN111259364B (zh) 一种使用国密加密卡的方法、装置、设备及存储介质
CN112835628A (zh) 一种服务器操作系统引导方法、装置、设备及介质
CN111176685A (zh) 一种升级方法及装置
CN111417927B (zh) 资源权限处理方法、装置、存储介质及芯片
CN108021801B (zh) 基于虚拟桌面的防泄密方法、服务器及存储介质
KR101461319B1 (ko) 셋탑박스의 펌웨어 업그레이드 방법 및 펌웨어 업그레이드 장치
WO2021036625A1 (zh) 机顶盒升级方法、机顶盒升级装置、机顶盒及存储介质
WO2017220014A1 (zh) 系统权限管理方法、装置及智能终端
WO2016127587A1 (zh) 一种实现软件版本升级的方法和装置
US20220413936A1 (en) Software containers

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 17830432

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 17830432

Country of ref document: EP

Kind code of ref document: A1