The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate various aspects of the invention and together with the description, serve to explain its principles. Wherever convenient, the same reference numbers will be used throughout the drawings to refer to the same or like elements.
The present invention relates to Internet Protocol Television (IPTV) in that it contemplates a platform with an IPTV transport architecture that is flexible and thus compatible with the various tiers of service providers. In particular, the present invention breaks new ground with an IPTV-based system platform having an IPTV transport architecture that includes double layer encryption and bulk decryption.
Generally speaking, IPTV-based systems deliver packetized video and broadband data services with one-way, two-way, point-to-multipoint, and point-to-point distribution capabilities. This service is often provided in conjunction with live TV (multicasting) and stored video (video on demand or VoD). Such systems typically use multicasting with Internet group management protocol (IGMP) for live video content distribution and real-time streaming protocols (RTSP) for the VoD. For increased use of the bandwidth, compatible data compression standards use various data transform and coding techniques. Data compression standards include MPEG (moving picture expert group) and H.264 standards for digital video and audio compression. The playback of IPTV content requires a set-top box connected to a television set (TV) or a computer with compatible digital data decompression tools.
IPTV-based systems allow more than live TV and VoD service over the broadband IP networks in that they enable Internet services such Web access and VoIP (voice over IP). This so-called triple play service delivers to consumers a bundled service of telephony, data and video. Because service providers of various types tend to occupy the triple play service space, either alone or in aggregation with counterparts, IPTV has emerged as a technology of choice for providing these types of services. For this reason an IPTV-based system designed in accordance with principles of the present invention provides a scalable flexible platform which is compatible with established large operators, the so-called tier-1 service providers, as well as small operators and new corners, the so-called tier-2 and tier-3 service providers.
Accordingly,
As illustrated, the content providers send video content to a receiving satellite dish antenna 22 associated with a network operations center 23. In this particular instance, the network operations center 23 is a fully integrated satellite broadcast center that includes an IPTV-based satellite acquisition and distribution hub with as many as 1000 channels per satellite or more, IPTV software, encoding system (e.g., MPEG-4 part 10), conditional access system (using encryption and/or scrambling methods) and network monitoring center. For triple play service, say, from a cable MSO operator or a telco, the system would also have a high-speed Internet infrastructure and VoIP (telephony) infrastructure (not shown). For simplicity, the various types of service providers (e.g., cable-MSO, common carriers, satellite operators, etc.) are collectively referred to as ‘service providers’ where high tier service providers are generically referred to as ‘tier-1 service providers’ and low tier service providers are generically referred to as ‘tier-2,3 service providers.’
From the network operations center 23 the video content is carried over satellite 24. The satellite in orbit relays data to locations around the globe in encapsulated double encrypted form. The double-layer encryption (inner and outer layer encryptions 34, 36) and the encapsulation 38 are performed in the network operations center prior to transmitting the signals via the satellite 24.
Typically, the video content transport stream delivered via the IP multicast to the set-top boxes of subscribers is in MPEG-4 part 10 or H.264 format. In standards-based IPTV systems, an underlying protocol for the transport stream of live TV is, for instance, version 2 of the aforementioned IGMP and for transport stream of VoD the protocol is RTSP. Thus, with encryption and end-to-end conditional access, the video content can be transported seamlessly to the set-top boxes 32 via the operator's network or the central office head-end 28 outer layer decryption 40a.
At the central office head-end 28 there is a satellite dish antenna 26 (part of a service operator's national network of satellite dish antennas) for receiving the incoming video content. Incidentally, when a cable company provides also broadband Internet and VoIP service to subscribers, the central office head-end includes cable modem termination system and a computer system and databases. From the head-end, the video content (or programming) is carried over a local network of antennas 30 and it is then passed on, simultaneously via IP multicast, to the many set-top boxes (STB) 32 of subscribers downstream.
As mentioned, the video content is transported to the central office head-end or the set-top boxes. Before that, a decryption engine 40a performs outer-layer decryption of the incoming content, and for high tier operators a second decryption engine performs bulk inner-layer decryption before the content is securely handed off to the operator's network for subsequent encryption and distribution to its subscribers, using its proprietary conditional access system. In other words, the IPTV transport architecture includes a decryption engine for performing the outer-layer decryption and a decryption engine for the inner-layer decryption in order to accommodate the tier-1 service provider. Otherwise, for tier-2,3 service provider, the second decryption engine can be bypassed or turned off and, instead, the inner-layer decryption is performed by the set-top boxes at the subscribers' end. This is because not all service providers have the same physical infrastructure in that not all of them have the necessary encoding/decoding and other access management capability. Thus a single transport architecture accommodates both tier-1 and tier-2,3 service providers.
Further shown in
In other words, from end to end, the IPTV-based system covers the content providers, the satellite communication or fiber transmission from the content providers to the network operations center, the global satellite communications from the network operations center, the central office head-ends, the local reception and distribution via service provider networks and reception by set-top boxes connected to TV sets. Accordingly, the end-to-end system can be viewed as a platform having segments upstream and downstream the transport platform. The transport architecture covers the network operations center with satellite acquisition and distribution hub, the global satellite network and satellite receiving head-ends. The upstream segment covers the content providers and link to the network operations center, and the downstream segment covers the central office head-ends, service provider networks and set-top boxes.
To safeguard the video content data the transport architecture provides data encryption at the IP packet level. Specifically, the encoded (compressed) video within the IP streams (IP packets) is passed on to an encryption engine 208 for inner-layer (IP) encryption of individual IP packets. A number of encryption method are possible, including symmetric (shared secret key with DES or AES) or asymmetric (RSA-public-private key pair) encryption methods. IP packet encryption prevents eavesdroppers from viewing the video that is being transmitted. When inner layer encryption is used, IP packets can be seen during transmission, but the IP packet contents (payload) cannot be read.
From this point the inner-layer-encrypted packets can move across one of two paths in the transport. We refer to these paths: (1) the satellite communications path, and (2) the fiber optics path, respectively.
When distributing the IP packets through the satellite communications path, the encrypted IP packets are encapsulated for satellite transmission 212. The encapsulated packets are compatible with ASI (asynchronous serial interface) standard that define the way devices interact with the physical and data link layers of the satellite distribution system. In this implementation, the data can be transmitted in MPEG-2 transport stream packets.
Encapsulation inserts an outer MPEG-2 Transport Stream and Multiprotocol Encapsulation header before the original IP header to create MPEG-2 TS streams. An MPEG-2 TS stream is identified by a Program Identifier (PID). IP multicast streams can be mapped one-to-one onto MPEG-2 transport streams, or bundled in groups such that many IP multicast streams are mapped onto a single MPEG-2 transport stream, say 5 bundles each with 20 channels for a total of 100 channels. Decapsulation yields the original (inner) IP destination address.
For the outgoing encapsulated IP packets the second encryption is the outer layer encryption 214. Each IP multicast stream may be encrypted as one unit when one IP multicast stream is mapped to one MPEG-2 transport stream, or IP multicast streams may be encrypted as a bundle when many IP multicast streams are mapped onto a single MPEG-2 transport stream, such that the decryption engine in the receiver at the other end of the satellite relay does not need to know how many channels are bundled in each group. Note that if the inner and outer layer encryptions are similar symmetric encryption methods they each use a different encryption key. The encryption keys for both would be automatically generated and rotated periodically for additional protection.
Preferably, the outer layer encryption is a scrambling algorithm for conditional access associated with digital video broadcasting (DVB) standards. The outer-layer encryption involves DVB-S and DVB-S2 standards for digital television satellite broadcasting. DVB is a suite of internationally adopted operating standards for digital television published by the European Telecommunications Standards Institute (ETSI) and others. Among these standards, the conditional access system (DVB-CA) defines a common scrambling algorithm (DVB-CSA) and a common interface (DVB-CI) for accessing scrambled content. DVB system providers develop their proprietary conditional access systems within these specifications. DVB transports include metadata called service information (DVB-SI) that links the various elementary streams into coherent programs and provides human-readable descriptions for electronic program guides.
Again, the transport architecture includes the double layer encryption and bulk decryption features in order to accommodate the tier-1 service providers and lower tier service providers (tier-2,3 service providers) without customizing the architecture for each type of service provider. This way, lower tier service providers can take advantage of the conditional access capability offered by the IPTV-based transport architecture while high tier service providers can use this transport architecture and still use their proprietary infrastructure.
To this end, from the network operations center, the satellite in orbit 220 relays signals modulated with the double-encrypted IP packets to the satellite receiving head-end 232. At the head-end, the received signals are demodulated to yield the double-encrypted packets. Also at the head-end, the double-encrypted IP packets undergo decryption which ‘peels off’ the outer layer encryption from the incoming IP packets.
For tier-1 service providers, the path on the left branch will pass on the resulting inner-layer-encrypted IP-packets to a bulk decryptor 222. The bulk inner-layer decryption will expose the IP packets, which are then securely handed off to the tier-1 telco (high tier service provider) network 224. Then, the exposed IP packets can be encrypted again by the tier-1 service provider using whatever proprietary methods it has for controlled access. As noted before, each of the IP packets can actually include bundled streams from a group of channels. Therefore, the tier-1 service provider can distribute individual IP streams from the different channels by unraveling the bundles of incoming IP packets and distributing each of the IP streams at a time using a multiplexing scheme 240. The IP packets are then relayed via the tier-1 service provider network to the set-top boxes 242 and their associated TV sets. The controlled access is achieved with the set-top boxes being able to decrypt only those of the incoming IP packets which they are authorized by the service provider to receive.
Indeed, the tier-1 service provider system is set up so that along the entire path from the content providers (programmers) to its subscribers' set-top boxes the video content is protected and never stored or distributed in the clear. After bulk encryption and secure handoff, the video content is encrypted at the content provider head-end and only decrypted at the viewer's home.
As for tier-2 and tier-3 service providers, the path on the right branch leads directly to the service provider's network 234 without any intervening bulk decryption (namely, the bulk encryption is off). This is because the lower tier service providers do not have their own encryption and secure handoff facility and the only way to keep the content protected is to transport it through the network in encrypted form. The encryption is ‘peeled off’ by the set-top boxes 236 before they reach the TV 238 but only if they are subscribers and authorized to receive and descramble the TV programs. Here too the content is protected along the entire path from the programmers to the set-top boxes except that in the case of lower tier service providers the inner layer encryption was applied at the network operations center before the satellite relay and it is retained until the content 238 reaches the set-top boxes.
Along the aforementioned fiber path (2), there are again two branches, one (upper) for tier-1 and another (lower) for the tier-2 and tier-3 service providers. The difference, of course, is the means (fiber) of transporting the IP packets from the network operations center to the service providers' head-end. As before, the bulk decryption 216 and secure hand off 226 are suitable for the tier-1 service provider (upper branch). Then again, the direct handoff to the operator's network (in encrypted form) is suited for the lower tier service providers (lower branch).
To further illustrate the foregoing,
Again, for tier-1 service provider bulk decryption is applied to the incoming IP packets (multi-channel bundles) and the service provider's own proprietary encryption is then applied. For tier-2,3 service providers, the bulk decryption is off (or bypassed). Either way, the IP packets are distributed through the operator's network in encrypted form. Local stations programming 358, community content 354 and advertising 346, however, are free and provided in the clear. For VoD, the catcher 350 receives the incoming multicast IP packets and assembles the video files. The VoD servers 274 handle the storage and distribution of these files to subscribers through the network. For distribution, the various signals are multiplexed 362 and passed on to the service provider's network 382 and eventually, the IP packets arrive at the set-top boxes 376a-b. The transport server 356 controls the inner-layer decryption at the set-top boxes in conjunction with the subscriber management as well service, set-top boxes, channel and billing management services 366, 368, 370. The network quality of service (QoS) server 360 checks integrity of the incoming IP packets.
Incidentally, for monitoring the system integrity, the signals relayed by the satellite in orbit 340 are received also at the network operations center via antenna 331. The double-layer-encrypted IP packets are decrypted and decoded 338, 336 and passed on to the video monitoring system 312, 314. In addition to the video monitoring, the management and control systems 316, 318 perform the network operations control and management functions.
In sum, the present invention contemplates an IPTV-based system with a new transport architecture that includes double-layer encryption and bulk decryption. The new transport architecture accommodates the various types of service provides without having to customize the system for each individual type of service provider. Although the present invention has been described in considerable detail with reference to certain preferred versions thereof, other versions are possible. Therefore, the spirit and scope of the appended claims should not be limited to the description of the preferred versions contained herein.
This application is a continuation-in-part of and incorporates herein by reference U.S. patent application Ser. No. 11/511,932, filed Aug. 28, 2006 entitled “IPTV Blackout Management.”
| Number | Date | Country | |
|---|---|---|---|
| Parent | 11511932 | Aug 2006 | US |
| Child | 11544394 | US |