System for decrypting and rendering content
By introducing a detachable decryption device into the digital media player to securely communicate with the host device, collaboratively handle content decryption and encryption, and use a shared root key to transmit security conditions, the problem of insufficient security of the USB interface in the prior art is solved, and content presentation with high security and legal consumption is achieved.
Patent Information
- Application Number
- CN202211358292.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2016-09-09
- Filing Date
- 2017-09-08
- Publication Date
- 2026-02-27
- Estimated Expiration
- 2037-09-08
AI Technical Summary
In existing technologies, it is difficult to effectively ensure compliance with security conditions and the legitimate consumption of content during the decryption and presentation of digital media content, especially given the insufficient security of USB interfaces.
By providing a detachable external decryption device, utilizing a secure communication channel with the host device, the decryption and re-encryption of content are collaboratively processed, and security conditions are included in the messages. Encrypted transmission is performed using a shared root key, ensuring that the host device complies with the content presentation conditions.
It enables highly secure decryption and presentation of digital media content via a USB interface, ensuring legitimate consumption of content and compliance with security conditions, and preventing unauthorized use and tampering.
Smart Images

Figure CN115811416B_ABST
Abstract
Description
[0001] This application is a divisional application of Chinese Patent Application No. 201780055133.0, filed on September 8, 2017, entitled "System for Decryption and Rendering of Content". TECHNICAL FIELD
[0002] The present disclosure relates generally to the field of secure digital media content decryption, and more particularly to a system for operators of conditional access content to ensure that a media player implements any conditions associated with the rendering of such content. BACKGROUND
[0003] In the prior art, systems are known for restricting access to certain digital media content to only those who have obtained the right to do so. These systems include systems having a host device for receiving content and a conditional access module (CAM) which, when inserted into or otherwise connected to the host device, decrypts the content received from the host device under the condition that the CAM has access to the necessary rights to prove that the right has been obtained, and returns the decrypted content to the host device for rendering.
[0004] Host devices in the form of digital televisions (TVs) are known. These devices typically have a standard interface at the end of a slot known as the Common Interface (CI) into which a conditional access module or Common Interface Conditional Access Module (CICAM) can be inserted. The CICAM can be used to receive a smart card or secure module in which the rights obtained by a user for a pay TV service are stored. The CICAM and its secure module control the decryption of the services to which the user has subscribed. The decrypted content is returned to the host via the common interface.
[0005] It is also possible in the prior art to use a system known as CI Plus (CI Plus). This system is similar to the CI system except that the decrypted content is re-encrypted by the CICAM before being sent back to the host device, thereby preventing an unscrupulous party from intercepting the decrypted content on its way back to the host device and using it or distributing it illegally. The key used by the CICAM to re-encrypt the content is sent from the CICAM to the host via a secure channel formed between the host device and the CICAM on the common interface.
[0006] The CI and CI Plus standards make use of a physical interface between the host and the CICAM based on a standard introduced by the Personal Computer Memory Card International Association known as PCMCIA. Other physical interfaces have been proposed, such as USB, which offers the advantage of higher data transfer rates. However, the USB standard is not specifically designed for conditional access applications and care must be taken to maintain the required level of security. BRIEF DESCRIPTION OF DRAWINGS
[0007] The accompanying drawings illustrate the present written disclosure:
[0008] Figure 1 Components used in embodiments of the present invention;
[0009] Figure 2 Further components that can be used in another embodiment of the present invention. DETAILED DESCRIPTION
[0010] According to a first aspect, there is provided a digital media player, such as a digital TV, which plays media content that is encrypted and associated with certain security requirements or conditions. This is achieved by providing a detachable external device that can be attached to the media player, which is used to decrypt, re-encrypt the content before sending it back to the host TV, and to ensure that the TV complies with any conditions associated with the presentation of the content. The security requirements associated with the content are received by the external device together with the encrypted content to which they are associated, which are encrypted by the external device and sent back to the host device in a secure message. The security requirements or conditions can be, for example, a set of usage rules (e.g. unauthorised analogue output), or a visible marker such as an identification that must be displayed together with the content, or an invisible marker such as a watermark that must be inserted into the content after it has been decoded by the host TV (or in some cases before it has been decoded).
[0011] It can be said that the content is decrypted in the external device (the decryption device) and consumed in the host device, with any security conditions associated with the content being handled by the host device. It is therefore important that the decryption device and the host cooperate to ensure that the security conditions are enforced when the content is consumed (e.g. presented). The decryption device decrypts the content in accordance with the rights associated with the content, which are stored in the decryption device, as is normal in the art of pay TV. According to embodiments of the present invention, any security conditions associated with the consumption of the content are appropriately handled by the host device to which the decryption device is connected.
[0012] Accordingly, there is provided a system for decrypting and presenting content, the presentation of the content complying with at least one predetermined condition, the system comprising:
[0013] a host device for presenting the decrypted content; and
[0014] a decryption device connectable to the host device via a communication interface between the two devices;
[0015] the decryption device is for:
[0016] decrypting the content received from the host device via the communication interface using a decryption key provided within the encrypted content;
[0017] creating, in cooperation with the host device, a secure communication channel between the two devices on the communication interface;
[0018] re-encrypting the content using the locally generated content key; and
[0019] returning the re-encrypted content to the host device via the communication interface;
[0020] transmitting, to the host device via the secure communication channel, a message comprising the content key;
[0021] characterized in that:
[0022] the decryption device is further configured to:
[0023] include in the message a predetermined condition associated with the content; and
[0024] encrypt the message using a root key shared with the host device between transmitting the message to the host device; and
[0025] the host device is configured to:
[0026] decrypt the message using the root key to reveal the content key and the condition associated with the content;
[0027] decrypt the re-encrypted content using the content key; and
[0028] present the content while enforcing the predetermined condition associated with the content.
[0029] According to another aspect, there is provided a host device for presenting content, the presentation of the content being subject to at least one predetermined condition, the host device comprising:
[0030] a decoder;
[0031] a decryption module;
[0032] a communication module for communicating with the decryption device;
[0033] the host device is configured to:
[0034] send the received encrypted content to the decryption device for decryption;
[0035] receive the decrypted content in a re-encrypted version via the communication interface;
[0036] establish a secure communication channel with the decryption device on the communication interface;
[0037] receiving a message from the decryption device, the message comprising a content key for decrypting the re-encrypted version of the content; and
[0038] decrypting, encrypting and rendering the re-encrypted message;
[0039] characterized in that the host device further comprises a secure memory for storing a root key, the received message being encrypted under the root key and further comprising a predetermined condition for rendering the content, the host device being further operative to:
[0040] decrypting the message using the root key to reveal the content key and the condition associated with the content;
[0041] decrypting the re-encrypted content using the content key; and
[0042] implementing the condition associated with the content while rendering the content.
[0043] According to yet another aspect, there is provided a decryption device for decrypting content received from a host device and returning the decrypted content to the host device, the decryption device comprising:
[0044] a communication interface module having a port for connecting to a compatible port on the host device;
[0045] a cryptographic module for computing cryptographic keys and for performing encryption and decryption functions;
[0046] a secure memory for storing cryptographic keys;
[0047] wherein the secure module is operative to:
[0048] re-encrypt the decrypted content under a locally generated content key before returning the re-encrypted content to the host device via the port; and
[0049] transmitting a message to the host device via the port over a secure communication channel, the message comprising the content key;
[0050] characterized in that the decryption device is further operative to:
[0051] include a condition in the message, the condition being received with the content received from the host device, the condition specifying one or more rules that the host is to fulfill when rendering the content, the message being encrypted under a root key before being sent to the host device, the root key being shared with the host device.
[0052] Figure 1Some components that can be used in a system according to an embodiment of the application are shown. A host device, such as a digital television, personal video recorder or media player, is capable of receiving conditional access content from a source, such as a satellite or from the Internet, and can have a cable connection, USB port or HDMI port, etc. The content is typically received in an encrypted format, including an encrypted control word for encrypting the content, which is encrypted by a transmission key. In addition to the encrypted control word, the encrypted content includes one or more conditions that the host device presenting the content must fulfill.
[0053] The host device has a port to which an external device can be attached, such as a USB or HDMI port. The external device is also provided with a port that is compatible with the port of the host device. The external device has a cryptographic function and can therefore also be referred to as a decryption device (security device). The decryption device can come in the form of a dongle. The decryption device receives the encrypted content from the host device via the port and uses the transmission key, which can be stored in a secure memory, to find the control word. The security module uses the control word to decrypt the content. Next, the decrypted content is re-encrypted using a content key that is generated locally by the decryption device and the re-encrypted content is sent back to the host device via the port, so that the host device is responsible for presenting the content.
[0054] In order for the host device to be able to decrypt the re-encrypted content, the decryption device sends a message to the host device, which message includes the local content key. In order to do this in a secure manner, a secure communication channel is established over the communication interfaces of the two devices. Over this secure channel, the devices are able to authenticate each other and exchange messages in a secure and authenticated manner.
[0055] The presentation of the content must be made in accordance with certain conditions set by the supplier of the content. The conditions are conditions that are transmitted in the encrypted content, which the presentation device, in this case the host device, must comply with. The conditions can for example be that the host device is not allowed to provide an analog version of the digital content. Another condition can be that a visible mark, such as a logo, must be displayed together with the content in a certain location. Yet another example of a condition that needs to be implemented is an invisible mark, such as a watermark, that is to be inserted in the content after it has been decoded and before it is displayed. Other conditions associated with the presentation of the content are also possible, the object of the present application being to provide a guarantee that the host device complies with the conditions when presenting the content.
[0056] According to an embodiment, in order to ensure that the host device receives the conditions associated with the presentation of the content, or security conditions, the message sent by the decryption device to the host device further comprises the security conditions. In order to ensure that the security conditions remain bound to the local content key, and thus guarantee that the security conditions cannot be modified, the message generated by the decryption device is then encrypted (by the decryption device) using the root key shared with the host device.
[0057] In the computing field, operations are performed using a combination of hardware, firmware and software using various abstraction layers. In the field of secure processing, security functions can be rooted in software, however the trust in such software- implanted functions is relatively low due to the fact that software is more susceptible to tampering than hardware. Therefore, there is a hardware root of trust, on which the trustworthiness of security mechanisms can be based. A hardware root of trust is a highly reliable piece of hardware that serves as a foundation for critical security functions. Hardware roots of trust are designed to be secure, so that they cannot be tampered with by malicious software, thus providing a solid basis for building security and trust.
[0058] According to a preferred embodiment providing maximum security, the host device comprises a hardware root of trust, and the root key is shared between the security module and the hardware root of trust. In some embodiments, the security module can also comprise a hardware root of trust for this purpose.
[0059] When the security module is plugged into the host device, a security protocol is run between the two devices, preferably involving the hardware root of trust, in order to be able to exchange security credentials and authentication information, thus enabling the creation of a secure channel between the host device and the decryption device.
[0060] When the host device receives the encrypted message from the decryption device, the decryption device decrypts the message using the root key, thus recovering the local content key and the conditions associated with the presentation of the content, which are securely bound to the content key. The host device then decrypts the re-encrypted content using the local content key, and presents the decrypted content while enforcing the condition(s) associated with the presentation of the content.
[0061] Whenever the decryption device detects a change in the security conditions accompanying the encrypted content from the host device, the decryption device then generates a new local content key for re-encrypting the corresponding content. The local content key can thus be said to be a volatile key. The security module then creates a new message for the host device comprising the new local content key and the new security conditions, encrypts the message using the root key shared with the host device, and sends the message to the host device. This guarantees that the new security conditions are enforced due to the new content key, so that if the new information is tampered with or otherwise removed, the host device will not get the correct content key and will not be able to decrypt the re-encrypted content.
[0062] The host device preferably has a hardware root of trust (HWRT), thus allowing a high level of security to implement the security conditions of the companion content according to embodiments of the application. However, according to another embodiment, this objective can still be achieved when the host device does not have a hardware root of trust as described above. The host device typically has some built-in security. In general, it can be said that the host device has a trusted execution environment (TEE). The TEE is a secure, fully protected processing environment consisting of processing, storage and storage capabilities. It is isolated from the "normal" processing environment, sometimes referred to as the rich execution environment (REE), in which the device operating system and applications run. The term "rich" refers to the extended functionality in today's mass-market operating systems, thus increasing the attack surface. By ensuring that sensitive operations are restricted to the TEE, the TEE is able to improve the security and availability of REE applications, and sensitive data such as cryptographic keys never leave the TEE. In a host device without a HWRT, the implementation of the security conditions is ensured at the level of the TEE. Finally, for a host device without a TEE, appropriately adapted security software can be used to ensure the implementation of the security conditions.
Claims
1. A host device for rendering content, the rendering of the content being subject to at least one predetermined condition, the host device comprising: a decoder; a decryption module; a communication module for communicating with a decryption device; the host device being configured to: send received encrypted content to the decryption device for decryption; receive a re-encrypted version of the decrypted content via a communication interface; establish a secure communication channel with the decryption device over the communication interface; receive a message from the decryption device, the message comprising a content key for decrypting the re-encrypted version of the decrypted content; and decrypt, decode and render the message; characterized in that the host device further comprises a secure memory for storing a root key, the received message being encrypted under the root key and further comprising a predetermined condition for rendering the content, the host device being further configured to: decrypt the received message using the root key to reveal the content key and the condition associated with the content; decrypt the re-encrypted content using the content key; and implement the condition associated with the content while rendering the content.
2. A decryption device for decrypting content received from a host device and returning the decrypted content to the host device, the decryption device comprising: a communication interface module having a port for connecting to a compatible port on the host device; an encryption module for computing encryption keys and for performing encryption and decryption functions; a secure memory for storing encryption keys; and a security module; wherein the security module is configured to: re-encrypt the decrypted content under a locally generated content key and return the re-encrypted content to the host device via the port; and send a message to the host device via the port over a secure communication channel, the message comprising the content key; characterized in that the decryption device is further configured to: include a condition in the message, the condition being received with the content from the host device, the condition specifying one or more rules to be satisfied by the host when rendering the content, the message being encrypted under a root key prior to being sent to the host device, the root key being shared with the host device.
3. A system for decrypting and rendering content, the rendering of the content being subject to at least one predetermined condition, the system comprising: a host device, the host device being configured to render decrypted content; and a decryption device, the decryption device being connectable to the host device via a communication interface between the two devices; the decryption device being configured to: decrypt content received from the host device via the communication interface using a decryption key provided within the encrypted content; create a secure communication channel between the two devices over the communication interface in cooperation with the host device; re-encrypt the content using a locally generated content key; and return the re-encrypted content to the host device via the communication interface; transmit a message to the host device via the secure communication channel, the message comprising the content key; characterized in that: the decryption device is further configured to: including in said message a predetermined condition associated with the content; and encrypting said message using a root key shared with said host device, between transmitting said message to said host device; and said host device is configured to: decrypt said message using said root key to reveal said content key and the condition associated with the content; decrypt the re-encrypted content using said content key; and present the content while enforcing the predetermined condition associated with the content.
4. The system of claim 3, wherein said predetermined condition is included in the encrypted content and discovered by said decryption device during said decryption of the content.
5. The system of claim 3 or 4, wherein said decryption device is further configured to cause the decryption performed therein to comply with availability of one or more predetermined rights for decrypting the content in said decryption device.
6. The system of claim 3 or 4, said decryption device and said host device both include ports for establishing said communication interface, the ports being compliant with one of the USB standard or the HDMI standard.
7. The system of claim 3 or 4, wherein said secure communication channel is an authenticated channel.
8. The system of claim 3 or 4, wherein said host device further includes a hardware root of trust, said hardware root of trust being configured to store the root key or to perform decryption or enforce the predetermined condition.
9. The system of claim 8, wherein said decryption device further includes a hardware root of trust, establishment of said secure communication channel being negotiated by the respective hardware roots of trust.
10. The system of claim 3 or 4, wherein said predetermined condition is that the content is to be presented with a visible mark, said host device being further configured to insert said visible mark when presenting the content.
11. The system of claim 3 or 4, wherein said predetermined condition is that the content is to be presented with an invisible mark, said host device being further configured to insert said invisible mark after the content is decoded.
12. The system of claim 3 or 4, wherein said decryption device is further configured to generate a new content key whenever a new predetermined condition is received, thereby providing said host device with a new encrypted message including said new content key and said new predetermined condition.
Citation Information
Patent Citations
Methods and Apparatuses for Securing Playback Content
US20110299680A1
Hardware-Assisted Content Protection for Graphics Processor
US20120079270A1