IP Library Granted Patent US 9,124,770
Granted Patent B2
US 9,124,770 · App. 14/017,016 · Granted Sep 1, 2015

Method and system for prevention of control word sharing

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,124,770
App. No.
14/017,016
Granted
Sep 1, 2015
Kind
B2
Abstract

A method and system of preventing control word sharing, the method and system including receiving a temporal key, denoted TK i , at a removable security element, receiving an entitlement control message (ECM), the ECM including a control word derivable by the removable security element, deriving the control word from the ECM at the removable security element, combining at least the control word and a value associated with an ID of the removable security element, thereby producing combined control word and removable security element ID data, encrypting the combined control word and removable security element ID data according to an encryption function, wherein the encrypting includes using TK i as an encryption key, and at a time after a removable security element interface has received TK i , but prior to a start of a crypto period with which the control word is associated, sending the encrypted combined control word and removable security element ID data to the removable security element interface. Related apparatus, methods and systems are also described.

Claims (56)

1. A method of preventing control word sharing, the method comprising:

receiving an entitlement control message (ECM), the ECM comprising a temporal key, denoted TK i , at a removable security element, the ECM further comprising a control word derivable by the removable security element;

deriving the control word from the ECM at the removable security element;

combining at least the control word and a value associated with an ID of the removable security element, thereby producing combined control word and removable security element ID data;

encrypting the combined control word and removable security element ID data according to an encryption function, wherein the encrypting comprises using TK i , as an encryption key; and

at a time after a removable security element interface has received TK i , in the ECM, but prior to a start of a crypto period with which the control word is associated, sending the encrypted combined control word and removable security element ID data to the removable security element interface.

2. The method according to claim 1 wherein the removable security element comprises one of: a smart card; a secure chip; and an embedded security element.

3. The method according to claim 1 wherein the removable security element interface comprises a smart card-interface module comprised in a set top box.

4. The method according to claim 1 wherein the value associated with the removable security element ID comprises at least one of:

the removable security element ID number;

a hash of the removable security element ID number; and

an encrypted value resulting from encrypting the removable security element ID number.

5. The method according to claim 1 wherein the combining operation comprising at least one of:

an output of XORing the control word with the value associated with the removable security element ID;

a concatenation of the control word with the value associated with the removable security element ID;

a hash of the control word with the value associated with the removable security element ID; and

an encrypted value resulting from the control word with the value associated with a removable security element ID.

6. A method of preventing control word sharing, the method comprising:

receiving an entitlement control message (ECM), the ECM comprising a temporal key, denoted TK i at a removable security element interface;

receiving a value comprising an encrypted combined control word and removable security element ID data;

decrypting the encrypted combined control word and removable security element ID data according to the temporal key TK i ;

performing a decombining operation to decombine the control word from the removable security element ID data, thereby producing the control word and removable security element ID data; and

utilizing the decrypted decombined control word to decrypt video.

7. The method according to claim 6 wherein the removable security element interface comprises a module in a set top box.

8. The method according to claim 6 wherein the removable security element comprises one of: a smart card; a secure chip; and an embedded security element.

9. The method according to claim 6 wherein the value associated with the removable security element ID comprises at least one of:

the removable security element ID number;

a hash of the removable security element ID number; and

an encrypted value resulting from encrypting the removable security element ID number.

10. The method according to claim 6 wherein the combining operation comprising at least one of:

an output of XORing the control word with the value associated with the removable security element ID;

a concatenation of the control word with the value associated with the removable security element ID;

a hash of the control word with the value associated with the removable security element ID; and

an encrypted value resulting from the control word with the value associated with a removable security element ID.

11. A method of preventing control word sharing in a video distribution system , the method comprising:

prior to a start of a crypto period with which a control word is associated, receiving a value comprising an encrypted combined control word and removable security element ID data at a security element, wherein the received value is shared in order to enable control word sharing;

receiving a temporal key in an entitlement control message (ECM), denoted TK i , at the security element;

decrypting the encrypted combined control word and removable security element ID data according to the temporal key TK i ;

performing a decombining operation to decombine the control word from the removable security element ID data, thereby producing the control word and removable security element ID data; and

utilizing the decrypted decombined removable security element ID data to determine the ID of the removable security element at which originated the received value that was shared in order to enable control word sharing.

12. The method according to claim 11 wherein the removable security element comprises one of: a smart card; a secure chip; and an embedded security element.

13. The method according to claim 11 wherein the removable security element interface comprises a module in a set top box.

14. The method according to claim 11 wherein the value associated with the removable security element ID comprises at least one of:

the removable security element ID number;

a hash of the removable security element ID number; and

an encrypted value resulting from encrypting the removable security element ID number.

15. The method according to claim 11 wherein the combining operation comprising at least one of:

an output of XORing the control word with the value associated with the removable security element ID;

a concatenation of the control word with the value associated with the removable security element ID;

a hash of the control word with the value associated with the removable security element ID; and

an encrypted value resulting from the control word with the value associated with a removable security element ID.

16. A system of preventing control word sharing, the system comprising:

a removable security element which receives an entitlement control message (ECM), the ECM comprising a temporal key, denoted TK i , the ECM further comprising a control word derivable by the removable security element, the removable security element being operative to derive the control word from the ECM;

a combiner which combines at least the control word and a value associated with an ID of the removable security element, thereby producing combined control word and removable security element ID data;

a crypto engine which encrypts the combined control word and removable security element ID data according to an encryption function, wherein the encrypting comprises using TK i , as an encryption key; and

at a time after a removable security element interface has received TK i , in the ECM, but prior to a start of a crypto period with which the control word is associated, the encrypted combined control word and removable security element ID data is sent to the removable security element interface.

Assignments (5)
CORRECTIVE ASSIGNMENT TO CORRECT THE 26 APPLICATION NUMBERS ERRONEOUSLY RECORDED AGAINST ON THE ATTACHED LIST PREVIOUSLY RECORDED AT REEL: 048513 FRAME: 0297. ASSIGNOR(S) HEREBY CONFIRMS THE CHANGE OF NAME. Recorded Mar 18, 2021
From: NDS LIMITED
To: SYNAMEDIA LIMITED
Reel/Frame 056623/0708 →
CHANGE OF NAME Recorded Mar 6, 2019
From: NDS LIMITED
To: SYNAMEDIA LIMITED
Reel/Frame 048513/0297 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 5, 2018
From: BEAUMARIS NETWORKS LLC; CISCO SYSTEMS INTERNATIONAL S.A.R.L.; CISCO TECHNOLOGY, INC.; CISCO VIDEO TECHNOLOGIES FRANCE
To: NDS LIMITED
Reel/Frame 047420/0600 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2013
From: WAISBARD, EREZ
To: CISCO TECHNOLOGY INC.
Reel/Frame 031326/0380 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 23, 2013
From: SOLOW, HILLEL
To: CISCO TECHNOLOGY INC.
Reel/Frame 031326/0414 →