Claims
- 1. A method for authenticating information in a conditional access cable television system comprising head-end equipment and a plurality of set-top terminals in communication therewith, the head-end equipment including a controller and a plurality of transaction encryption devices associated with a plurality of entitlement agents for providing information to the plurality of set-top terminals, the controller controlling access to the conditional access cable television system, the method comprising:processing at least a segment of downloadable information provided from a source to generate a digest thereof, wherein the downloadable information includes a logic segment; associating a source identifier with the downloadable information, wherein the source identifier is associated with the provider providing the downloadable information; and transmitting a message to at least one set-top terminal, the message including the downloadable information, the digest and the source identifier.
- 2. The method of claim 1, further including the step of:using a key to make a processed digest, wherein the key is a private key of a public key-private key pair for the provider of the downloadable information, and wherein the processed digest is included in the transmitted message.
- 3. The method of claim 2, wherein the digest of the segment of downloadable information is an output of a hash function having the segment of downloadable information as an input to the hash function.
- 4. The method of claim 2, further including the steps of:generating the public key-private key pair for the provider of the downloadable information in a transaction encryption device associated with the provider of the downloadable information; storing the private key in the transaction encryption device associated with the provider of the downloadable information; and providing the public key for the provider of the downloadable information to at least one set-top terminal in the conditional access cable television system; and wherein the processed digest is made in the transaction encryption device associated with the provider of the downloadable information.
- 5. The method of claim 4, wherein the transaction encryption device associated with the provider of the downloadable information is accessible only to the controller.
- 6. The method of claim 4, wherein the logic segment includes a data segment for use in at least one set-top terminal.
- 7. The method of claim 4, wherein the logic segment includes a code segment for execution in at least one set-top terminal.
- 8. The method of claim 4, wherein an entitlement agent that provides a service instance to the conditional access cable television system for display at entitled set-top terminals in the conditional access cable television system is the provider of the downloadable information, and wherein the digest is made in the transaction encryption device associated with the entitlement agent.
- 9. The method of claim 4, wherein the public key for the provider of the downloadable information is provided to the at least one set-top terminal in a second message transmitted to the at least one set-top terminal.
- 10. A method for authenticating a message received in a set-top terminal in a conditional access cable television system comprising head-end equipment and a plurality of set-top terminals, the head-end equipment in communication with a plurality of entitlement of agents that provide downloadable information, the method comprising:storing in a memory of the set-top terminal a public key associated with a provider of downloadable information; receiving a message having an authentication token and downloadable information, the downloadable information including a logic segment, the authentication token including a processed digest and a source identifier that is associated with the provider of the downloadable information, and wherein the processed digest is a digest of a given portion of the downloadable information that was processed using a private key of a public key-private key pair associated with the provider.
- 11. The method of claim 10, further including the steps of:making a first digest using the given portion of the downloadable information; processing the received processed digest with the public key associated with the provider to make a second digest; comparing the first digest with the second digest; and authenticating the source of the downloadable information as the provider associated with the source identifier when the first digest is the same as the second digest.
- 12. The method of claim 11, wherein the first digest is an output of a hash function having the given portion of the downloadable information as an input to the hash function.
- 13. The method of claim 11, wherein the memory of the set-top terminal includes a plurality of public keys stored therein; and prior to the processing step, further including the steps of:using the source identifier to identify the public key of the provider; and retrieving the identified public key of the provider from the memory.
- 14. The method of claim 13, prior to the step of storing a public key, further including the steps of:receiving a first message at the set-top terminal, the first message including a first public key; and associating the first public key with the provider of the downloadable information.
- 15. The method of 11, wherein downloadable information is authenticated as valid when the first digest is the same as the second digest.
- 16. The method of claim 15, wherein the set-top terminal includes flash memory and a portion of the logic segment is stored in the flash memory after the downloaded information has been authenticated as valid.
- 17. The method of claim 16, wherein the logic segment included in the downloadable information includes a code segment that is for execution in the set-top terminal, and wherein after the downloadable information has been authenticated as valid the code segment is stored in the flash memory and executed in the set-top terminal.
- 18. The method of claim 16, wherein the logic segment included in the downloadable information includes a data segment that is for use by an executable code in the set-top terminal, and wherein after the downloadable information has been authenticated as valid the data segment is stored in the flash memory.
- 19. The method of claim 10, wherein the memory having the public key stored therein is included in a secure element having a processor, and the memory is accessible to only the processor included in the secure element.
- 20. A set-top terminal that is in communication with head-end equipment included in a cable television system, the head-end equipment comprising a plurality of transaction encryption devices, the set-top terminal comprising:a port adapted to receive a message having an authentication token from a transaction encryption device of the plurality of transaction encryption devices and downloadable information, the downloadable information including a logic segment, wherein the authentication token includes a processed digest and a source identifier that indicates the provider of the downloadable information; a memory having at least three public keys stored therein, wherein the at least three public keys includes a first key of a public key-private key pair associated with the set-top, a second key associated with the source identifier and a first transaction encryption device of the plurality of transaction encryption devices, and a third public key associated with a second transaction encryption device of the plurality of transaction encryption devices; and a processor coupled to the port and the memory, the processor adapted to make a first digest of a first portion of the received downloaded information and to process the received processed digest with the public key associated with source identifier thereby making a second digest, and the processor adapted to compare the first digest with the second digest and authenticate the downloadable information when the first digest and the second digest are the same.
- 21. The set-top terminal of claim 20, wherein the logic segment of the authenticated downloaded information is stored in a portion of the memory.
- 22. The set-top terminal of claim 21, wherein the portion of the memory having the logic segment of the authenticated downloadable information stored therein is a flash memory.
- 23. The set-top terminal of claim 21, wherein the logic segment includes a segment of code that is for execution in the set-top terminal.
- 24. The set-top terminal of claim 21, wherein the logic segment includes a segment of data that is for use by an executable code in the set-top terminal.
- 25. The set-top terminal of claim 20, wherein the first digest is an output of a hash function having the first portion of the downloadable information as an input to the hash function.
- 26. The set-top terminal of claim 20, wherein the memory and the processor are included in a secure element, and the memory is accessible only to the processor of the secure element.
- 27. An apparatus for providing authenticatable downloadable information to a plurality of set-top terminals in a cable television system, the apparatus comprising:a transaction encryption device including a digest maker that receives an input and produces a digest therefrom, a key generator that generates a public key-private key pair, a memory having the private key stored therein, and a processor that processes the digest with the private key, and wherein the input to the digest maker includes a logic segment, a controller adapted to generate a message that includes the logic segment, the processed digest and a source identifier, wherein the source identifier is associated with the public key corresponding to the private key that processed the digest; and means for providing a secure communication link between the transaction encryption device and the controller.
- 28. The apparatus of claim 27, wherein the logic segment includes a code segment that is for execution in the at least one set-top terminal.
- 29. The apparatus of claim 27, wherein the logic segment includes a data segment that is used by an executable code in the at least one set-top terminal.
- 30. The apparatus of claim 27, wherein the means for providing a secure communication link is a dedicated direct communication link extending between transaction encryption device and the controller, and wherein the transaction encryption device is located in a physically secure area.
- 31. The apparatus of claim 30, further including:a second transaction encryption device including a digest maker that receives an input and produces a digest therefrom, a key generator that generates a public key-private key pair, a memory having the private key stored therein, and a processor that processes the digest with the private key, and wherein the input to the digest maker includes a logic sediment, wherein the second transaction encryption device is associated with an entitlement agent that provides service instances to the cable television system, and the second transaction encryption device generates entitlements for the service instances from the first entitlement agent; wherein the first transaction encryption device further includes a conditional access authority adapted to enable each set-top terminal of the plurality of set-top terminals to process messages associated with the second transaction encryption device, only set-top terminals enabled to process messages from the second transaction encryption device can use the entitlements therefrom to access the service instances provided by the entitlement agent, and further adapted to remove enablement from each enabled set-top terminal, whereby a given set-top terminal having enablement for processing messages associated with the second transaction encryption device removed therefrom can no longer process messages associated with the second transaction encryption device.
CROSS-REFERENCE TO RELATED APPLICATIONS
This is a continuation of application Ser. No. 09/488.104, filed Jan. 20, 2000 now U.S. Pat. No. 6,246,767, presently allowed, which is a continuation of U.S. application Ser. No. 09/127,152, filed Jul. 31, 1998 abandoned, which claims the benefit of U.S. Provisional Application No. 60/054,575, filed Aug. 1, 1997, and is a CIP of application Ser. No. 09/111,958, filed Jul. 8, 1998, now abandoned, which claims the benefit of U.S. Provisional Application No. 60/054,578, filed Aug. 1, 1997, and is CIP of application Ser. No. 08/767,535, filed Dec. 16, 1996, U.S. Pat. No. 6,005,938, and is a CIP of application Ser. No. 08/580,759 filed Dec. 29, 1995, U.S. Pat. No. 5,870,474, which claims the benefit of U.S. Provisional Application No. 60/007,962, filed Dec. 4, 1995, and is CIP of application Ser. No. 08/415,617, filed Apr. 3, 1995, U.S. Pat. No. 5,742,677.
The present application descends from an application which was one of seven original applications with identical Detailed Descriptions. All of these applications have the same filing date and the same assignee. The serial numbers and filing dates of the six applications follow:
Ser. No. 09/126,783, filed Jul. 31, 1998, presently abandoned, for which a continuation Ser. No. 09/487,076 was filed on Jan. 19, 2000; Ser. No. 09/126,921, filed Jul. 31, 1998, issued as U.S. Pat. No. 6,157,719; Ser. No. 09/127,273, filed Jul. 31, 1998, presently abandoned, for which a continuation Ser. No. 09/493,409 was filed on Jan. 28, 2000; Ser. No. 09/127,352, filed Jul. 31, 1998, presently abandoned, for which a continuation Ser. No. 09/488,230 was filed on Jan. 20, 2000 now U.S. Pat. No. 6,252,964; Ser. No. 09/126,888, filed Jul. 31, 1998, presently abandoned, for which a continuation Ser. No. 09/464,794 now U.S. Pat. No. 6,424,717 was filed on Dec. 16, 1999; and Ser. No. 09/126,795, filed Jul. 31, 1998, issued as U.S. Pat. No. 6,105,134.
US Referenced Citations (91)
Foreign Referenced Citations (4)
| Number |
Date |
Country |
| 0 723 371 |
Jul 1996 |
EP |
| 0 752 786 |
Jan 1997 |
EP |
| WO 9413107 |
Jun 1994 |
WO |
| WO 9529560 |
Nov 1995 |
WO |
Non-Patent Literature Citations (10)
| Entry |
| ISO/IEC 13818-1, “Information Technology—Generic Coding of Moving Pictures and Associated Audio Systems,” Draft of: Nov. 13, 1994. |
| ISO/IEC JTC1/SC29/WG11, “Universal Multi-Program and Transport for MPEG-2 Systems,” Jan. 1993. |
| ISO/IEC JTC1/SC29/WG11, “An MGEG-2 Multi-Program Multiplex Syntax,” Jan. 1993. |
| ISO/IEC JTC1/SC2/WG11, “Requirements and Method for High-Level Multiplexing of MPEG and Other Digital Service Bitstreams with Universal Transport Layer,” Nov. 1992. |
| Whitfield, Diffie, “Authentication and Authenticated Key Exchanges,” Designs, Codes and Cryptography, An International Journal, vol. 2, No. 2, Jun. 1992, pp. 107-125. |
| Schneier, Bruce, “Applied Cryptography Second Edition: Protocols, Algorithms and Source Code in C,” pp. 357-363. |
| Menezes, Alfred J., “Handbook of Applied Cryptography,” pp. 506-525. |
| TM-1244 Rev. 4, “Final Technical Report of the Conditional Access Specialist Group,” Nov. 17, 1994. |
| Coutrot et al., “A Single Conditional Access System for Satellite-Cable and Terrestrial TV,” IEEE Transactions on Consumer Electronics, vol. 35, No. 3, Aug. 1989, pp. 464-468. |
| Louis Claude Guillou and Jean-Luc Giachetti, “Encipherment and Conditional Access,” SMPTE Journal, 103 (1994) Jun., No. 6, White Plains, NY. |
Provisional Applications (3)
|
Number |
Date |
Country |
|
60/054575 |
Aug 1997 |
US |
|
60/054578 |
Aug 1997 |
US |
|
60/007962 |
Dec 1995 |
US |
Continuations (2)
|
Number |
Date |
Country |
| Parent |
09/488104 |
Jan 2000 |
US |
| Child |
09/748313 |
|
US |
| Parent |
09/127152 |
Jul 1998 |
US |
| Child |
09/488104 |
|
US |
Continuation in Parts (4)
|
Number |
Date |
Country |
| Parent |
09/111958 |
Jul 1998 |
US |
| Child |
09/127152 |
|
US |
| Parent |
08/767535 |
Dec 1996 |
US |
| Child |
09/111958 |
|
US |
| Parent |
08/580759 |
Dec 1995 |
US |
| Child |
08/767535 |
|
US |
| Parent |
08/415617 |
Apr 1995 |
US |
| Child |
08/580759 |
|
US |