IP Library › Granted Patent US 9,888,283
Granted Patent B2
US 9,888,283 · App. 13/799,891 · Granted Feb 6, 2018

Systems and methods for performing transport I/O

Inventors: William Michael Beals (Englewood, CO); Nicolas Fischer (Versoix, CH); Benjamin Brian Ellis (Denver, CO); Gregory Duval (Englewood, CO)
Assignee: Nagrastar LLC
H04N21/44004H04L9/14H04N21/23406H04N21/2401H04N21/4181H04N21/4367H04N21/4623H04N21/64715H04N21/835H04L2209/16H04N21/4405H04N21/4408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,888,283
App. No.
13/799,891
Granted
Feb 6, 2018
Kind
B2
Abstract

Systems and methods for implementing a Transport I/O system are described. Network encrypted content may be received by a device. The device may provide the network encrypted content to a secure processor, such as, for example, a smart card. The secure processor obtains a network control word that may be used to decrypt the network encrypted content. The secure processor may decrypt the network encrypted content to produce clear content. In embodiments, the secure processor may then use a local control word to generate locally encrypted content specific to the device. The device may then receive the locally encrypted content from the secure processor and proceed to decrypt the locally encrypted content using a shared local encryption key. The Transport I/O system ensures the protection of the network control word by maintaining the network control word on the secure processor.

Claims (81)

1. A removable security device comprising:

at least one processor; and

memory encoding computer executable instructions that, when executed by the at least one processor, performs a method comprising:

receiving a signal during initialization;

based upon the signal, determining whether the removable security device is operating in a legacy mode;

when the removable security device is not operating in the legacy mode, performing, by the removable security device, operations comprising:

receiving, from a head-end, at least one network control word;

maintaining the at least one network control word on the removable security device such that the at least one network control word is not transmitted from the removable security device;

receiving a first network encrypted elementary stream;

receiving a second network encrypted elementary stream;

decrypting the first and second network encrypted elementary streams using the at least one network control word to generate first and second clear content streams;

obtaining at least one local control word, wherein the at least one local control word is generated by the removable security device;

encrypting the first and second clear content streams by the removable device to produce first and second locally encrypted content streams, wherein the first and second locally encrypted content streams are produced using the at least one local control word;

multiplexing the first and second locally encrypted content streams to produce an output stream; and

providing the output stream to a video processing device.

2. The removable security device of claim 1 , wherein the removable security device is a smart card in a set-top-box.

3. The removable security device of claim 1 , wherein the removable security device supports a legacy form factor.

4. The removable security device of claim 3 , wherein the legacy form factor is compatible with the ISO-7816 standard.

5. The removable security device of claim 1 , wherein encrypting the first and second clear content streams utilizes a transport mode encryption.

6. The removable security device of claim 1 , wherein encrypting the first and second clear content streams utilizes a bulk mode encryption.

7. The removable security device of claim 1 , wherein the removable security device and the video processing device communicate using LVDS signaling.

8. The removable security device of claim 1 , wherein a first network control word is used to decrypt the first network encrypted elementary stream and second network control word is used to decrypt the second network encrypted elementary stream, and wherein the first and second network control words are different.

9. The removable security device of claim 1 , wherein the at least one local control word is generated by the removable security device.

10. The removable security device of claim 1 , wherein the local control word is obtained from a key ladder.

11. The removable security device of claim 1 , wherein the operations further comprise:

receiving at least one additional network encrypted elementary stream;

decrypting the at least one additional network encrypted elementary stream using at least one additional network control word to generate at least one additional clear content stream;

encrypting the at least one additional clear content stream to produce at least one additional locally encrypted content stream; and

wherein multiplexing further comprises multiplexing the first, second, and at least one additional locally encrypted content stream into the output stream.

12. The removable security device of claim 1 , wherein the operations further comprise:

obtaining a first local control word, wherein the first clear content stream is encrypted using the first local control word; and

obtaining optional additional local control word(s), wherein the optional additional network content stream(s) are encrypted using the optional additional local control word(s), and wherein some or all of the local control words are different.

13. A method comprising:

receiving a signal during initialization;

based upon the signal, determining whether the removable security device is operating in a legacy mode;

when the removable security device is not operating in the legacy mode, performing, by the removable security device, operations comprising:

receiving, from a head-end, at least one network control word;

maintaining the at least one network control word on the removable security device such that the at least one network control word is not transmitted from the removable security device;

receiving a first network encrypted elementary stream;

receiving a second network encrypted elementary stream;

decrypting the first and second network encrypted elementary streams using the at least one network control word to generate first and second clear content streams;

obtaining at least one local control word, wherein the at least one local control word is generated by the removable security device;

encrypting the first and second clear content streams by the removable device to produce first and second locally encrypted content streams, wherein the first and second locally encrypted content streams are produced using the at least one local control word;

multiplexing the first and second locally encrypted content streams to produce an output stream; and

providing the output stream to a video processing device.

14. The method of claim 13 , wherein the removable security device is a smart card.

15. The method of claim 13 , wherein encrypting the first and second clear content streams utilizes a transport mode encryption.

16. The method of claim 13 , wherein encrypting the first and second clear content streams utilizes a bulk mode encryption.

17. The method of claim 13 , wherein the removable security device and the video processing device communicate using LVDS signaling.

18. The method of claim 13 , further comprising:

receiving at least one additional network encrypted elementary stream;

decrypting the at least one additional network encrypted elementary stream using at least one additional network control word to generate at least one additional clear content stream;

encrypting the at least one additional clear content stream to produce at least one additional locally encrypted content stream; and

wherein multiplexing further comprises multiplexing the first, second, and at least one additional locally encrypted content stream into the output stream.

19. The method of claim 13 , wherein the operations further comprising:

obtaining a first local control word, wherein the first clear content stream is encrypted using the first local control word; and

obtaining optional additional local control word(s), wherein the optional additional network content stream(s) are encrypted using the optional additional local control word(s), and wherein some or all of the local control words are different.

20. A system comprising:

a set-top-box; and

a smart card connected to the set-top-box, the smart card performing a method comprising:

receiving, at the smart card, a signal from the set-top-box during initialization;

based upon the signal, determining whether the smart card is operating in a legacy mode;

when the smart card is not operating in the legacy mode, performing, by the smart card, operations comprising:

receiving, from a head-end, at least one network control word;

maintaining the at least one network control word on the smart card such that the at least one network control word is not transmitted from the smart card;

receiving a first network encrypted elementary stream;

receiving a second network encrypted elementary stream;

decrypting the first and second network encrypted elementary streams using the at least one network control word to generate first and second clear content streams;

obtaining at least one local control word, wherein the at least one local control word is generated by the smart card;

encrypting the first and second clear content streams by the removable device to produce first and second locally encrypted content streams, wherein the first and second locally encrypted content streams are produced using the at least one local control word;

multiplexing the first and second locally encrypted content streams to produce an output stream; and

providing the output stream to a video processing device.

21. The system of claim 20 , wherein the operations further comprise:

receiving at least one additional network encrypted elementary stream;

decrypting the at least one additional network encrypted elementary stream using at least one additional network control word to generate at least one additional clear content stream;

encrypting the at least one additional clear content stream to produce at least one additional locally encrypted content stream; and

wherein multiplexing further comprises multiplexing the first, second, and at least one additional locally encrypted content stream into the output stream.

22. The system of claim 20 , wherein the operations further comprise:

obtaining a first local control word, wherein the first clear content stream is encrypted using the first local control word; and

obtaining optional additional local control word(s), wherein the optional additional network content stream(s) are encrypted using the optional additional local control word(s), and wherein some or all of the local control words are different.

23. The system of claim 20 , wherein the smart card and the set-top-box communicate using LVDS signaling.

Assignments (5)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 13, 2016
From: ECHOSTAR TECHNOLOGIES L.L.C.
To: NAGRASTAR, LLC
Reel/Frame 039718/0282 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2015
From: DUVAL, GREGORY; ELLIS, BENJAMIN BRIAN
To: NAGRASTAR LLC
Reel/Frame 037099/0018 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2015
From: BEALS, WILLIAM MICHAEL
To: ECHOSTAR TECHNOLOGIES L.L.C.
Reel/Frame 037099/0059 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2015
From: FISCHER, NICOLAS
To: NAGRAVISION SA
Reel/Frame 037099/0162 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2015
From: NAGRAVISION SA
To: NAGRASTAR LLC
Reel/Frame 037099/0267 →
Continuity (1)
Related Publication 20140282685A1 · Sep 18, 2014