Headend system for downloadable conditional access service and method of operating the same
    2.
    发明授权
    Headend system for downloadable conditional access service and method of operating the same 有权
    用于可下载条件访问服务的头端系统及其操作方法

    公开(公告)号:US08533458B2

    公开(公告)日:2013-09-10

    申请号:US12246663

    申请日:2008-10-07

    IPC分类号: H04L29/06

    摘要: A method of operating a headend system for a downloadable conditional access service, the method including: receiving, by an Authentication Proxy (AP) server, basic authentication information from a Downloadable Conditional Access System (DCAS) host, the basic authentication information being required to authenticate the DCAS host; transmitting, by the AP server, the basic authentication information to an external trusted authority device which authenticates the DCAS host; generating, by the AP server, a session key for encrypting/decrypting a secure micro client using a session key sharing factor; obtaining, by the AP server, download-related information of the secure micro client from a DCAS Provisioning Server (DPS); and commanding, by the AP server, an Integrated Personalization System (IPS) server to download the secure micro client to the DCAS host based on the download-related information, the secure micro client being encrypted by the session key.

    摘要翻译: 一种操作用于可下载条件访问服务的头端系统的方法,所述方法包括:由认证代理(AP)服务器从可下载条件访问系统(DCAS)主机接收基本认证信息,所述基本认证信息需要 验证DCAS主机; 由AP服务器将基本认证信息发送给认证DCAS主机的外部可信管理设备; 由AP服务器生成用于使用会话密钥共享因子加密/解密安全微客户端的会话密钥; 由AP服务器从DCAS配给服务器(DPS)获取安全微客户端的下载相关信息; 并且由AP服务器命令集成个性化系统(IPS)服务器,以便基于下载相关信息将安全微客户端下载到DCAS主机,安全微客户端被会话密钥加密。

    Method and apparatus for mutual authentication in downloadable conditional access system
    3.
    发明授权
    Method and apparatus for mutual authentication in downloadable conditional access system 有权
    用于可下载条件访问系统中相互认证的方法和装置

    公开(公告)号:US08621218B2

    公开(公告)日:2013-12-31

    申请号:US12330729

    申请日:2008-12-09

    IPC分类号: H04L9/32 G06F7/04

    摘要: Disclosed is a mutual authentication method and apparatus in a CAS including a headend system and DCAS host. In particular, example embodiments relate to a mutual authentication method and apparatus in DCAS, wherein the mutual authentication is performed between an authentication server of the headend system and an SM of a DCAS host, and then CAS software is downloaded to the SM. According to the example embodiments, there is provided a mutual authentication protocol between the authentication server of the headend and the SM of the DCAS host in a cable network, and also provided a mutual authentication method and apparatus in the DCAS where a substantial authentication based on a hardware, such as a smart card or a cable card, is not needed.

    摘要翻译: 公开了一种包括前端系统和DCAS主机的CAS中的相互认证方法和装置。 特别地,示例性实施例涉及DCAS中的相互认证方法和装置,其中在头端系统的认证服务器和DCAS主机的SM之间执行相互认证,然后将CAS软件下载到SM。 根据示例性实施例,在有线网络中提供前端的认证服务器和DCAS主机的SM之间的相互认证协议,并且还提供了在DCAS中的相互认证方法和装置,其中基于 不需要诸如智能卡或有线卡的硬件。

    Re-authentication apparatus and method in downloadable conditional access system
    6.
    发明授权
    Re-authentication apparatus and method in downloadable conditional access system 有权
    可下载条件访问系统中的重新认证装置和方法

    公开(公告)号:US08539236B2

    公开(公告)日:2013-09-17

    申请号:US12692266

    申请日:2010-01-22

    IPC分类号: H04L29/06

    摘要: Provided is a re-authentication apparatus in a Downloadable Conditional Access System (DCAS), the re-authentication apparatus includes: a receiving unit to receive a key request message from a Secure Micro (SM); a determination unit to determine whether to perform re-authentication depending on downloading of SM client image; an identification unit to identify an SM identifier using the key request message, when the re-authentication is performed as a result of the determination; an extraction unit to retrieve previous session information corresponding to the SM identifier and to extract keying information about the previous session information; and an encryption unit to control an encryption key about the SM client image to be reused, the SM client image being encrypted in a previous session based on the previous session information using the keying information.

    摘要翻译: 提供了一种可下载条件接入系统(DCAS)中的重认证装置,重认证装置包括:接收单元,用于从安全微(SM)接收密钥请求消息; 确定单元,用于根据SM客户端图像的下载来确定是否执行重新认证; 当作为所述确定的结果执行所述重新认证时,使用所述密钥请求消息来识别SM标识符的识别单元; 提取单元,用于检索与所述SM标识符相对应的先前会话信息,并提取关于所述先前会话信息的密钥信息; 以及加密单元,用于基于使用所述密钥信息的先前会话信息来控制关于要再次使用的SM客户端图像的加密密钥,所述SM客户端图像在先前会话中被加密。

    Method and apparatus of managing entitlement management message for supporting mobility of DCAS host
    7.
    发明授权
    Method and apparatus of managing entitlement management message for supporting mobility of DCAS host 有权
    管理授权管理消息以支持DCAS主机的移动性的方法和装置

    公开(公告)号:US08689314B2

    公开(公告)日:2014-04-01

    申请号:US12144749

    申请日:2008-06-24

    摘要: A method of supporting a mobility of a Downloadable Conditional Access System (DCAS) host is provided. The method includes: by the second authentication proxy server: performing mutual authentication with a secure micro of the host to generate a session key; requesting an integrated personalization system to download a secure micro client to the host, wherein the secure micro client is encoded using the session key; and transmitting, to a DPS, mapping information between the second authentication proxy server and the secure micro of the host, wherein, in response to receiving the mapping information, the DPS instructs a CAS server to transmit an entitlement management message to the network of the second authentication proxy server without transmitting the entitlement management message to the network of the first authentication proxy server.

    摘要翻译: 提供了一种支持可下载条件访问系统(DCAS)主机的移动性的方法。 该方法包括:由第二认证代理服务器执行与主机的安全微处理器的相互验证以产生会话密钥; 请求集成个性化系统将安全的微客户端下载到所述主机,其中所述安全微客户端使用会话密钥进行编码; 以及向所述第二认证代理服务器和所述主机的安全微系统之间传送DPS映射信息,其中响应于接收到所述映射信息,所述DPS指示CAS服务器向所述主机的网络发送授权管理消息 第二认证代理服务器,而不向第一认证代理服务器的网络发送授权管理消息。

    Method of preventing unauthenticated viewing using unique information of secure micro
    8.
    发明授权
    Method of preventing unauthenticated viewing using unique information of secure micro 有权
    使用安全微型的独特信息来防止未认证的观看的方法

    公开(公告)号:US08694773B2

    公开(公告)日:2014-04-08

    申请号:US12546859

    申请日:2009-08-25

    IPC分类号: H04L9/32 H04L29/06 H04N21/45

    摘要: A method of verifying a validity of a Secure Micro (SM) is provided. The method of verifying a validity of an SM, the method including: storing and maintaining a validity verification message used to verify the validity of the SM, the validity verification message being generated by a Trusted Authority (TA) based on unique information of the SM, and the SM and the TA sharing the unique information of the SM; and verifying the validity of the SM using the validity verification message and the unique information shared by the SM, when an SM client is executed.

    摘要翻译: 提供了一种验证安全Micro(SM)的有效性的方法。 验证SM的有效性的方法,该方法包括:存储和维护用于验证SM的有效性的有效性验证消息,该有效性验证消息是由可信管理机构(TA)根据SM的唯一信息生成的 ,SM和TA共享SM的独特信息; 并且当执行SM客户端时,使用有效性验证消息和SM共享的唯一信息来验证SM的有效性。

    Method and apparatus for detecting downloadable conditional access system host with duplicated secure micro
    9.
    发明授权
    Method and apparatus for detecting downloadable conditional access system host with duplicated secure micro 有权
    用于检测具有重复安全微处理器的可下载条件访问系统主机的方法和装置

    公开(公告)号:US08490155B2

    公开(公告)日:2013-07-16

    申请号:US12256599

    申请日:2008-10-23

    IPC分类号: G06F7/04 G06F17/30 G06F15/16

    CPC分类号: G06F21/554

    摘要: A method where a Downloadable Conditional Access System Provisioning Server (DPS) detects a duplicated secure micro is provided. A method of detecting a duplicated secure micro, the method including: generating authentication time difference information associated with a value of a difference between a time when a host is finally authenticated in a first address and a time when the host is authenticated in a second address; comparing the authentication time difference information with a first reference value and a second reference value, the second reference value being less than the first reference value; and determining whether the secure micro is duplicated based on a result of the comparing.

    摘要翻译: 提供了可下载条件访问系统供应服务器(DPS)检测到重复的安全微服务器的方法。 一种检测重复的安全微机的方法,所述方法包括:生成与主机在第一地址中最终被认证的时间与主机在第二地址中认证的时间之间的差的值相关联的认证时差信息 ; 将所述认证时间差信息与第一参考值和第二参考值进行比较,所述第二参考值小于所述第一参考值; 以及基于所述比较的结果来确定所述安全微数据是否被复制。

    Method of controlling download load of secure micro client in downloadable conditional access system
    10.
    发明授权
    Method of controlling download load of secure micro client in downloadable conditional access system 有权
    控制可下载条件访问系统中安全微客户端下载负载的方法

    公开(公告)号:US08260919B2

    公开(公告)日:2012-09-04

    申请号:US12546851

    申请日:2009-08-25

    IPC分类号: G06F15/173

    摘要: A method of controlling a download load of a Secure Micro (SM) client in a Downloadable Conditional Access System (DCAS) is provided. The method of controlling a download load of an SM client including: analyzing version information of SMs and version information of SM clients to control the download load generated in the DCAS, the version information of the SMs and the version information of the SM clients being provided from an Authentication Proxy (AP) server, and the SM clients being installed in the SMs; determining a download policy associated with a download time of a target SM client for the SMs based on a result of the analysis; and providing the AP server with the determined download policy.

    摘要翻译: 提供了一种在可下载条件访问系统(DCAS)中控制安全微服务(SM)客户端的下载负载的方法。 控制SM客户端的下载负载的方法包括:分析SM的版本信息和SM客户端的版本信息,以控制DCAS中生成的下载负载,SM的版本信息和提供的SM客户端的版本信息 来自认证代理(AP)服务器和SM中安装的SM客户端; 基于所述分析的结果,确定与所述SM的目标SM客户端的下载时间相关联的下载策略; 以及向AP服务器提供所确定的下载策略。