Broadcast receiver, net distribution server device, system, and program
The system automatically generates and verifies access tokens for internet distribution services based on valid broadcast reception contracts, addressing the laborious and time-consuming issues of existing methods by enhancing efficiency and legitimacy in service access.
Patent Information
- Application Number
- JP2023189893
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-11-07
- Publication Date
- 2025-05-19
AI Technical Summary
The existing methods for issuing accounts for internet distribution services based on broadcast reception contracts are laborious for broadcasting stations, requiring manual confirmation, and time-consuming for users, with separate account management adding to the burden.
A broadcast receiver and network distribution server system that automatically generates and verifies access tokens based on the presence of a valid broadcast reception contract, eliminating the need for manual labor and streamlining the account management process.
This solution enables broadcasting stations to efficiently manage and control access to internet distribution services, ensuring legitimate users receive content while reducing operational burdens and time delays.
Smart Images

Figure 2025077588000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a broadcast receiver, a network distribution server device, a system, and a program.
Background Art
[0002] In recent years, services such as distributing video content simultaneously with broadcasting (simultaneous broadcast distribution) via a communication network or distributing a broadcast program that a user has missed in response to a request (catch-up distribution) have been provided by broadcasting stations. These services are collectively called network distribution services.
[0003] Among these network distribution services, there are services provided only to users who have concluded a broadcast reception contract, such as "NHK Plus". In that case, when registering for the service, in order to confirm the existence of a broadcast reception contract, the user is asked to input information such as the name and address of the contract holder, and the existence of the contract is manually confirmed and an account is issued. Note that NHK's broadcast reception contract is made on a household basis. Reference URL: [https: / / plus.nhk.jp / info / id / ]
[0004] On the one hand, in the currently operating terrestrial and BS digital broadcasts, broadcast programs are provided only to specific users through a limited reception system, and as one of the methods, the ARIB limited reception method (B-CAS) is adopted. In this method, the broadcasting station broadcasts encrypted video and audio signals together with encrypted signals called EMM (Entitlement Management Message) and ECM (Entitlement Control Message). The receiver on the receiving side decrypts the EMM using the master key (Km) included in the inserted IC card (B-CAS card). The EMM is sent for each broadcasting station and includes the contract information of the B-CAS card and the working key (Kw) for decrypting the ECM. The receiver decrypts the ECM using the Kw included in the EMM. The ECM is sent for each program and includes the scramble key (Ks) for decrypting the video and audio signals. The receiver decrypts the video and audio signals using the Ks included in the ECM.
[0005] Normally, the user (viewer) cannot know the content of the Kw. In the event of a leakage of the Kw or the like, it is stipulated in the standard ARIB STD-B25 "Access Control Method in Digital Broadcasting" that the broadcasting station side can change the Kw.
[0006] Patent Document 1 describes a content viewing method, and the method describes a process of issuing an account for playing back content. In the method described in Patent Document 1, the portable information terminal transmits user identification information and a user password to the content distribution server. The content distribution server performs authentication based on the received user identification information and user password. The portable information terminal requests the content distribution server to issue an account for playing back the desired content. Based on this request, the content distribution server issues an account and transmits the account to the portable information terminal. The portable information terminal transmits the account to the viewing device via short-range wireless communication. The viewing device stores the received account and uses the account to play back the desired content.
Prior Art Documents
Patent Documents
[0007]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0008] However, in the method of issuing an account for an Internet distribution service based on a broadcast reception contract, it is very laborious for a broadcasting station, such as requiring manual confirmation of the existence of a broadcast reception contract. Also, for users, there is a problem that it takes a predetermined time until an account is issued. Further, the fact that the management of an account for an Internet distribution service has to be separately performed apart from the broadcast reception contract is also a heavy burden for the broadcasting station.
[0009] Also, in the technology described in Patent Document 1, there is a problem that the content distribution server has to separately manage user identification information and a password for authentication for its system.
[0010] The present invention has been made based on the above recognition of problems, and provides a broadcast receiver, an Internet distribution server device, a system, and a program for enabling a broadcasting station to perform control based on a broadcast reception contract regarding the use of an Internet distribution service provided by the broadcasting station, and for automatically managing the legitimacy of users who receive content delivery without relying on manual labor.
Means for Solving the Problems
[0011] [1] To solve the above problems, a broadcast receiver according to an aspect of the present invention includes a broadcast signal receiving unit that receives a broadcast signal, an identification information reading unit that reads the identification information from a recording medium that records identification information for limited reception, an EMM (Entitlement Management Message) included in the received broadcast signal, and based on the identification information read from the recording medium, a contract existence determination unit that determines whether there is a valid contract associated with the identification information, an access token issuance request receiving unit that receives an access token issuance request from an external device, and when receiving the access token issuance request, an access token generation unit that generates an access token only when the contract existence determination unit determines that there is a valid contract, and transmits the generated access token to the external device.
[0012] [2] Further, in an aspect of the present invention, in the broadcast receiver of [1] above, the contract existence determination unit determines whether there is a valid contract according to whether the identification information is included in the EMM (Entitlement Management Message), and determines that there is a valid contract if and only if the identification information is included in the EMM (Entitlement Management Message).
[0013] [3] Further, in an aspect of the present invention, in the broadcast receiver of [1] or [2] above, the access token generation unit generates the access token including the identification information, expiration date information indicating the expiration date of the access token to be generated, and a hash function value calculated based on the identification information, the expiration date information, and a working key extracted from the EMM (Entitlement Management Message).
[0014] [4] Further, a network distribution server device according to an aspect of the present invention, when receiving a content request from an external device, includes a verification unit that verifies the validity of an access token included in the content request, and when the verification unit confirms that the access token is a valid access token, a content providing unit that provides the content specified in the content request to the external device that is the request source. The access token is generated by a broadcast receiver that receives a broadcast signal, and the access token is generated only when it is determined that there is a valid contract associated with the identification information based on the identification information read by the broadcast receiver from a recording medium that records identification information for limited reception and an EMM (Entitlement Management Message) included in the received broadcast signal, and is then passed to the external device.
[0015] [5] Further, in the network distribution server device according to the above [4] of the present invention, the access token includes the identification information, expiration date information indicating the expiration date of the generated access token, and a first hash function value calculated based on the identification information, the expiration date information, and a work key extracted by the broadcast receiver from the EMM (Entitlement Management Message). The verification unit at least confirms based on the expiration date information whether the current time has not exceeded the expiration date, and also confirms whether a second hash function value calculated by the device itself based on the identification information, the expiration date information, and a work key previously held by the device itself matches the first hash function value included in the access token.
[0016] [6] Further, one aspect of the present invention is a system configured to include a network distribution server device, a broadcast receiver, and a terminal device, wherein the broadcast receiver includes a broadcast signal receiving unit that receives a broadcast signal, an identification information reading unit that reads out the identification information for limited reception from a recording medium that records the identification information, an EMM (Entitlement Management Message) included in the received broadcast signal, and a contract presence / absence determination unit that determines whether or not there is a valid contract associated with the identification information based on the identification information read from the recording medium, an access token issuance request receiving unit that receives an access token issuance request from the terminal device, and an access token generation unit that generates an access token only when the contract presence / absence determination unit determines that there is a valid contract upon receiving the access token issuance request, and transmits the generated access token to the terminal device. The terminal device transmits an access token issuance request to the broadcast receiver, holds the access token transmitted from the broadcast receiver based on the access token issuance request, and transmits a content request including the access token to the network distribution server device. The network distribution server device includes a verification unit that verifies the validity of the access token included in the content request when receiving the content request from the terminal device, and a content providing unit that provides the content specified in the content request to the terminal device that is the request source when the verification unit confirms that the access token is a valid access token. The access token is generated by a broadcast receiver that receives a broadcast signal, and the access token is generated only when it is determined that there is a valid contract associated with the identification information based on the identification information read by the broadcast receiver from a recording medium that records the identification information for limited reception and the EMM (Entitlement Management Message) included in the received broadcast signal, and is passed to the terminal device. The terminal device receives the content provided from the network distribution server device in response to the content request.is a system as described above.
[0017] [7] Further, one aspect of the present invention is a computer included in a broadcast receiver having a broadcast signal receiving unit that receives a broadcast signal, and an identification information reading unit that reads the identification information from a recording medium that records identification information for limited use. Based on the EMM (Entitlement Management Message) included in the received broadcast signal and the identification information read from the recording medium, a contract existence determination unit that determines whether there is a valid contract associated with the identification information, an access token issuance request receiving unit that receives an access token issuance request from an external device, and when the access token issuance request is received, an access token generation unit that generates an access token only when the contract existence determination unit determines that there is a valid contract, and transmits the generated access token to the external device. It is a program for executing the functions.
[0018] [8] Further, one aspect of the present invention is a verification unit that verifies the validity of an access token included in the content request when a content request is received from an external device, and when the verification unit confirms that the access token is a valid access token, a content providing unit that provides the content specified in the content request to the external device that is the request source. The access token is generated by a broadcast receiver that receives a broadcast signal, and the access token is generated only when it is determined that there is a valid contract associated with the identification information based on the identification information read from a recording medium that records identification information for limited use by the broadcast receiver and the EMM (Entitlement Management Message) included in the received broadcast signal, and is a program for causing a computer to function as a network distribution server device that has been passed to the external device.
Advantages of the Invention
[0019] According to the present invention, a broadcast receiver can automatically generate an access token based on the presence or absence of a contract (such as a broadcast reception contract) without relying on manual operation. A network distribution server device can distribute content only to users based on a legitimate contract by verifying such an access token.
Brief Description of the Drawings
[0020]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Modes for Carrying Out the Invention
[0021] Next, an embodiment of the present invention will be described with reference to the drawings.
[0022] In this embodiment, according to the determination of whether broadcast reception is possible by a limited reception method such as B-CAS, the broadcast receiver is caused to generate an access token for the network distribution service. The determination of whether broadcast reception is possible by a limited reception method such as B-CAS has the same meaning as checking the presence or absence of a broadcast reception contract.
[0023] FIG. 1 is a block diagram showing the configuration of devices and the like of the system according to the present embodiment. As shown in the figure, the system 1 includes a broadcast transmission device 21, a network distribution server device 22, a broadcast receiver 23, a terminal device 24, and a communication network 31. Note that the number of each of the broadcast transmission device 21, the network distribution server device 22, the broadcast receiver 23, and the terminal device 24 constituting the system 1 may be any number of one or more. In particular, the number of each of the broadcast receiver 23 and the terminal device 24 may be on the order of tens of millions or hundreds of millions, or more.
[0024] The broadcast transmission device 21 is a device that transmits a broadcast signal. Technical requirements and the like of the broadcast signal are defined by standards and the like. The broadcast signal can be transmitted as a radio wave (terrestrial wave) or an electrical signal on a metal cable. The information transmitted by the broadcast signal includes video (moving images and audio) content. Note that the broadcast transmission device 21 can communicate with the network distribution server device 22. The broadcast transmission device 21 is operated by a broadcasting company (broadcast station).
[0025] The network distribution server device 22 is a device that distributes video content via the communication network 31 (such as the Internet). The network distribution server device 22 distributes video content using standard technologies (including de facto standards). The network distribution server device 22 of the present embodiment may distribute video content to the terminal device 24 based on a request from the individual terminal device 24. Note that the network distribution server device 22 can also communicate with the broadcast transmission device 21. The network distribution server device 22 is operated by a broadcasting company (broadcast station) or its agent.
[0026] The network distribution server device 22 may distribute the video content (program) transmitted by the broadcast transmission device 21 to the terminal device 24 via the communication network 31 simultaneously or almost simultaneously with the broadcast. Also, the network distribution server device 22 may distribute the video content (program) transmitted in the past by the broadcast transmission device 21 to the terminal device 24 via the communication network 31 in response to a request or the like from the terminal device 24. Alternatively, the network distribution server device 22 may distribute video content (program) that has not been broadcast to the terminal device 24 via the communication network 31.
[0027] The broadcast receiver 23 is a device that receives the broadcast signal transmitted from the broadcast transmission device 21. The broadcast receiver 23 may be a device called a "television receiver" or "TV". The broadcast receiver 23 demodulates the received broadcast signal and extracts data by performing decoding as necessary. The broadcast signal received by the broadcast receiver 23 includes content data (video, audio, subtitle text, etc.) and control information. The broadcast receiver 23 has a function of presenting the content obtained from the broadcast signal to the user. The user can view the video content received by the broadcast receiver 23 using the broadcast receiver 23. Note that the broadcast receiver 23 is configured so that a B-CAS card can be inserted. That is, the broadcast receiver 23 can determine whether or not the B-CAS card is associated with a valid broadcast reception contract according to the B-CAS method. The broadcast receiver 23 can communicate with the terminal device 24 via, for example, short-range wireless communication means or a communication network such as the Internet.
[0028] The terminal device 24 is an information terminal device used by the user. The terminal device 24 can be realized by using computer technology. The terminal device 24 may be, for example, a personal computer (PC), a tablet terminal, a smartphone, a wristwatch-type terminal, or other devices. The terminal device 24 can communicate with the above-described broadcast receiver 23 via, for example, short-range wireless communication means or via a communication network such as the Internet.
[0029] The terminal device 24 has an environment in which an app (application program) operates. Specifically, under the management of the OS (operating system), the terminal device 24 provides CPU resources to the app, provides a memory space for the app, and provides various services to the app via an API (application program interface). As one of the apps, an app for viewing Internet distribution can be operated. The functions of the terminal device 24 described with reference to FIG. 4 and the like may be functions realized by the operation of this app for viewing Internet distribution on the terminal device 24.
[0030] Communication between the app for viewing Internet distribution operating on the terminal device 24 and the broadcast receiver 23 may be realized by using a known TV-smartphone cooperation technology such as a hybrid cast connect.
[0031] The terminal device 24 transmits an access token issuance request to the broadcast receiver 23 and holds the access token transmitted from the broadcast receiver 23 based on the access token issuance request. The terminal device 24 transmits a content request including the access token to the Internet distribution server device 22. The terminal device 24 receives the content provided from the Internet distribution server device 22 in response to the content request. The user of the terminal device 24 can view the content distributed from the Internet distribution server device 22.
[0032] The communication network 31 is a network that enables communication between the network distribution server device 22 and the terminal device 24. The communication network 31 may further be connected to the broadcast receiver 23. The communication network 31 is realized by appropriately combining wired or wireless transmission media. The communication network 31 may be the so-called "Internet".
[0033] At least a part of the functions of each of the broadcast transmission device 21, the network distribution server device 22, the broadcast receiver 23, and the terminal device 24 can be realized by, for example, a computer and a program. Also, each of these devices may have storage means as necessary. The storage means is, for example, a variable in a program or a memory allocated by the execution of the program. Also, if necessary, non-volatile storage means such as a magnetic hard disk device or a solid state drive (SSD) may be used. Also, at least a part of the functions of each functional unit may be realized as a dedicated electronic circuit instead of a program.
[0034] Next, a configuration example of the internal functions of each of the network distribution server device 22 and the broadcast receiver 23 among the devices described above will be described.
[0035] FIG. 2 is a block diagram showing an example of a configuration for realizing the functions of the broadcast receiver 23 described as an embodiment. As shown in the figure, the broadcast receiver 23 may include a broadcast signal receiving unit 231, an identification information reading unit 232, an EMM extraction unit 2331, a contract presence / absence determination unit 2332, an access token issuance request receiving unit 2333, and an access token generation unit 2334. Note that the broadcast receiver 23 has a function of decrypting the ECM using the working key (Kw) and a function of decrypting video and audio signals using the scrambling key (Ks) included in the ECM. As will be described later, the contract presence / absence determination unit 2332 extracts the working key (Kw) by decrypting the EMM using the master key (Km) included in the B-CAS card.
[0036] Among these functions of the broadcast receiver 23, the EMM extraction unit 2331, the contract existence determination unit 2332, the access token issuance request reception unit 2333, and the access token generation unit 2334 may be realized as functions of a program operating on the computer 233. The computer 233 included in the broadcast receiver 23 has, for example, an environment for executing a program having the functions of the EMM extraction unit 2331, the contract existence determination unit 2332, the access token issuance request reception unit 2333, and the access token generation unit 2334. Although various implementation methods are conceivable for these elements of the broadcast receiver 23 (particularly, the access token generation unit 2334), as an example, it can be implemented as a part of the B-CAS decoding function of the middleware in the broadcast receiver 23.
[0037] The broadcast signal reception unit 231 receives a broadcast signal. The broadcast signal reception unit 231 can demodulate the received broadcast signal and pass the information (signals, data, etc.) obtained from the broadcast signal to the computer 233. In particular, the broadcast signal reception unit 231 passes the broadcast signal to the EMM extraction unit 2331 in order to extract an EMM (Entitlement Management Message).
[0038] The identification information reading unit 232 reads the identification information from a recording medium that records the identification information for limited reception. Here, the recording medium is, for example, an IC card. Specifically, the recording medium may be a B-CAS card. Also, the identification information is information for uniquely identifying the recording medium (such as a B-CAS card). This identification information may be the B-CAS card unique ID described above.
[0039] The EMM extraction unit 2331 extracts an EMM from the broadcast signal. The EMM extraction unit 2331 passes the EMM to the contract existence determination unit 2332 and the access token generation unit 2334. The EMM extraction unit 2331 may pass only the necessary information included in the EMM to the contract existence determination unit 2332 and the access token generation unit 2334.
[0040] Based on the EMM included in the received broadcast signal and the identification information read from the recording medium, the contract existence determination unit 2332 determines whether there is a valid contract associated with the identification information.
[0041] Note that the contract existence determination unit 2332 may determine whether there is a valid contract according to whether the identification information is included in the EMM. That is, the contract existence determination unit 2332 may perform a process of determining whether the identification information read by the identification information reading unit 232 of the own device from the recording medium is included in the list of identification information (B-CAS card unique ID) in the EMM. The contract existence determination unit 2332 determines that there is a valid contract if and only if the identification information is included in the EMM.
[0042] Note that the contract existence determination unit 2332 has a function of extracting a working key (Kw) by decrypting the EMM using the master key (Km) included in the B-CAS card.
[0043] The access token issuance request receiving unit 2333 receives an access token issuance request from the terminal device 24. The access token issuance request receiving unit 2333 passes the received access token issuance request to the access token generation unit 2334. Note that the terminal device 24 is an external device as viewed from the broadcast receiver 23. Therefore, the terminal device 24 may be referred to as an "external device".
[0044] When the access token issuance request receiving unit 2333 receives the access token issuance request, the access token generation unit 2334 generates an access token only when the contract existence determination unit 2332 determines that a valid contract exists. The access token generation unit 2334 transmits the generated access token to the terminal device 24 of the request source. The access token is generated only when it is determined that a valid contract associated with the identification information exists, based on the identification information read from the recording medium that records the identification information for restricted reception by the broadcast receiver 23 and the EMM included in the received broadcast signal. The access token may be configured to include the items shown in Table 1 below.
[0045]
Table 1
[0046] The first item shown in Table 1 is the B-CAS card unique ID. The B-CAS card unique ID can be used as information for identifying a broadcast reception contract. Note that, in some cases, an access token can be issued for a plurality of terminal devices 24 under one broadcast reception contract. Specifically, when one subscriber is a user of a plurality of terminal devices 24, it is possible that an access token based on the broadcast reception contract is issued for those plurality of terminal devices 24. Also, when a broadcast reception contract is concluded at the household unit instead of the individual unit (in this case, the user representing the household becomes the subscriber), it is possible that it is issued for each of the terminal devices 24 of a plurality of users belonging to the household. In these cases, the access token generation unit 2334 generates an access token for each of the access token issuance requests from a plurality of terminal devices 24 based on one B-CAS card. As a result, it may occur that a plurality of terminal devices 24 simultaneously and in parallel request the distribution of content to the network distribution server device 22. In this case, it is a desirable form that the network distribution server device 22 can control the number of simultaneous accesses per one broadcast reception contract. In order to perform such control of the number of simultaneous accesses, it is necessary to include information that can identify the broadcast reception contract in the access token.
[0047] The second item shown in Table 1 is the access token expiration date. The access token expiration date may be, for example, date information represented in the format of "year / month / day". Further, the access token expiration date may further have time information of "hour:minute:second". The access token expiration date may alternatively have information on the expiration (a point on the time axis) as data in another format. The access token expiration date may be, for example, after a predetermined time set by the broadcaster from the time of access token generation. Specifically, the expiration time of the access token may be, for example, 7 days later, or 1 month later, or 2 months later from the time of access token generation. Alternatively, when the broadcast receiver 23 can obtain information on the end time of the broadcast reception contract, the broadcast receiver 23 may use the end time of the contract as the access token expiration date. This access token expiration date can be used by the network distribution server device 22 that has received a content request from the terminal device 24 to determine whether the access token is a valid token at that time. In the method of this embodiment, after the arrival of the access token expiration date, the access token generation unit 2334 can generate and transmit an access token again to the terminal device 24 that has transmitted the access token within the access token expiration date. Specifically, when the access token issuance request reception unit 2333 receives an access token issuance request from the terminal device 24 after the arrival of the access token expiration date, the access token generation unit 2334 generates an access token and transmits it to the terminal device 24 that is the request source. Or, when the access token expiration date arrives, even if no access token issuance request is received, the access token generation unit 2334 can automatically generate an access token and transmit it again to the terminal device 24 that has transmitted the access token within the access token expiration date.
[0048] The third item shown in Table 1 is the hash value (the first hash function value). Specifically, for example, a hash value obtained by applying a predetermined hash function to the combined information of the above-mentioned B-CAS card unique ID (the first item), the above-mentioned access token expiration date (the second item), and the work key (Kw) extracted from the EMM may be used. By sharing the method of calculating the hash value in advance between the broadcast receiver 23 side (the side that generates the access token) and the network distribution server device 22 side (the side that verifies the access token), it becomes possible to detect forgery or unauthorized copying of the access token. That is, unauthorized access to network-distributed content can be prevented.
[0049] These pieces of information included in the access token are used when the network distribution server device 22 side confirms the validity of the access token.
[0050] FIG. 3 is a block diagram showing an example of a configuration for realizing the functions of the network distribution server device 22 described as an embodiment. As shown in the figure, the network distribution server device 22 may be configured to include a verification unit 221, a content providing unit 222, a work key storage unit 223, and a clock 224.
[0051] When the verification unit 221 receives a content request from an external device (terminal device 24), it verifies the legitimacy of the access token included in the content request.
[0052] The verification process performed by the verification unit 221 is as follows. That is, the access token includes the identification information (specifically, the B-CAS card unique ID, etc.), the expiration date information indicating the expiration date of the access token, and the first hash function value calculated based on the identification information, the expiration date information, and the working key extracted from the EMM extracted from the broadcast signal received by the broadcast receiver 23. The verification unit 221 at least confirms based on the expiration date information whether the current time has exceeded the expiration date, and also checks whether the second hash function value calculated by the own device based on the identification information, the expiration date information, and the working key (Kw) previously held by the working key storage unit 223 of the own device matches the first hash function value included in the access token.
[0053] Note that the verification unit 221 can obtain information regarding the current date and time from the clock 224. The verification unit 221 can obtain the working key from the working key storage unit 223.
[0054] When the verification unit 221 determines that the access token is valid, the content providing unit 222 provides the content specified in the content request to the external device (terminal device 24) of the request source.
[0055] The working key storage unit 223 receives and stores the working key (Kw) from the broadcast transmission device 21. The working key storage unit 223 has storage means (for example, a non-volatile semiconductor memory, etc.) for storing the working key (Kw). The working key storage unit 223 delivers the working key (Kw) to the verification unit 221 in response to a request. When the broadcast transmission device 21 updates the working key (Kw), the working key storage unit 223 receives and stores the updated working key (Kw) from the broadcast transmission device 21.
[0056] The clock 224 has a clock function and can provide information regarding the current date and time at that point to the verification unit 221 as necessary. The information regarding the current date and time may be only the date (year, month, day), or information on the date and time (year, month, day, and hour, minute, second, etc.).
[0057] Figure 4 is a sequence diagram showing the processing sequence when the system 1 operates. The figure shows the processing focused on one set of broadcast receivers 23 and terminal devices 24. In reality, a large number of terminal devices 24 may access the network distribution server device 22 simultaneously and in parallel. Also, a large number of broadcast receivers 23 can receive the broadcast signals transmitted from the broadcast transmission device 21 simultaneously and in parallel. Note that in the operation procedure of the figure, the broadcast transmission device 21 and the network distribution server device 22 are pre-associated and can communicate with each other. Also, pairing has been established in advance between the broadcast receivers 23 and the terminal devices 24 using some existing technology method.
[0058] Hereinafter, the operation procedure will be described step by step. Note that from step S1 to step S7 are the processes in the preparation phase (the processes until the terminal device 24 has a valid access token). Also, from step S8 to step S10 are the processes in the viewing phase (the processes in which the terminal device 24 receives the provision of content using the access token acquired in the preparation phase).
[0059] First, in step S1, the broadcast transmission device 21 transmits a work key (Kw) to the network distribution server device 22. The network distribution server device 22 receives this work key (Kw). The work key (Kw) is not user-dependent and is a key common to all users.
[0060] Next, in step S2, the network distribution server device 22 accumulates (saves) the work key (Kw) received in step S1 in the storage means within its own device. The network distribution server device 22 uses this work key (Kw) later when verifying the access token.
[0061] Next, in step S3, the broadcast transmission device 21 transmits an EMM (Entitlement Management Message) on the broadcast signal. The EMM includes a working key (Kw). The broadcast receiver 23 receives the broadcast signal transmitted from the broadcast transmission device 21 and acquires the EMM. The broadcast receiver 23 can hold the working key (Kw) extracted from the EMM.
[0062] On the other hand, in step S4, the terminal device 24 transmits an access token issuance request to the broadcast receiver 23 based on a user operation or the like. The access token is token information used when the terminal device 24 accesses the network distribution server device 22. The broadcast receiver 23 receives this access token issuance request.
[0063] Next, in step S5, the broadcast receiver 23 determines whether the B-CAS card held by the broadcast receiver 23 is associated with a valid broadcast reception contract. Specifically, the broadcast receiver 23 determines whether the B-CAS card has a valid broadcast reception contract based on whether the number of the B-CAS card of its own device (the broadcast receiver 23) is included in the EMM received in step S3. In other words, the broadcast receiver 23 attempts to decrypt the data received as a broadcast signal in accordance with the B-CAS decryption procedure, and if the decryption is successful, it determines that there is a valid broadcast reception contract for the broadcast station. If the decryption of the data in accordance with the B-CAS decryption procedure fails, the broadcast receiver 23 determines that there is no valid broadcast reception contract.
[0064] If the broadcast receiver 23 determines that there is no valid broadcast reception contract, it does not generate an access token and aborts the process. At this time, the broadcast receiver 23 may return a response indicating that the access token cannot be issued to the terminal device 24.
[0065] Next, in step S6, the broadcast receiver 23 generates an access token. The broadcast receiver 23 generates an access token only when it determines in the above step S5 that there is a valid broadcast reception contract. In other words, the broadcast receiver 23 acts on behalf of issuing an access token based on a valid broadcast reception contract. The access token generated by the broadcast receiver 23 is configured to include the items shown in Table 1 above.
[0066] Next, in step S7, the broadcast receiver 23 transmits the data of the access token generated in step S6 to the terminal device 24 that is the request source. The terminal device 24 receives the access token transmitted from the broadcast receiver 23.
[0067] Next, in step S8, the terminal device 24 stores the access token received in step S7 in the storage means (e.g., non-volatile semiconductor memory, etc.) within its own device.
[0068] The processing up to step S8 above is the processing of the preparation phase. The processing from step S9 below is the processing of the viewing phase.
[0069] In step S9, the terminal device 24 transmits a content request to the network distribution server device 22 based on an operation by the user or the like. When the terminal device 24 requests content from the network distribution server device 22, it attaches the access token saved in step S8 above. The network distribution server device 22 receives the content request transmitted from the terminal device 24.
[0070] Next, in step S10, the network distribution server device 22 verifies the validity of the access token included in the content request received in step S9. The specific verification content is as follows.
[0071] As a first verification, the Internet distribution server device 22 checks whether this content request violates the limit on the number of simultaneous accesses based on the same broadcast reception contract. Specifically, it refers to the B-CAS card unique ID which is the first item of the access token, and checks whether the number of content requests being accepted using that B-CAS card unique ID at that time is less than the upper limit value. If the number of requests already accepted has reached the upper limit value, the Internet distribution server device 22 aborts the process for providing content for the content request received in step S9 (including the second and third verifications described below). Note that the upper limit value of the number of simultaneous accesses may be common to all broadcast reception contract holders (B-CAS card unique IDs), or may vary according to the broadcast reception contract holders (B-CAS card unique IDs). For example, the Internet distribution server device 22 may determine the upper limit value of the number of simultaneous accesses as a set value.
[0072] Also, as a second verification, the Internet distribution server device 22 checks whether this content request does not use an expired access token. Specifically, it refers to the access token expiration date which is the second item of the access token, and checks whether this expiration date has passed at the time when the content request is received. If the current date and time has passed the expiration date, the Internet distribution server device 22 aborts the process for providing content for the content request received in step S9.
[0073] Also, as a third verification, the network distribution server device 22 checks the validity of the hash value of the access token. Specifically, the network distribution server device 22 calculates the hash value in the same manner as when the broadcast receiver 23 generates the access token in step S6. For example, the network distribution server device 22 applies the same hash function as that on the broadcast receiver 23 side to the information obtained by combining the B-CAS card unique ID (the first item) included in the received access token, the access token expiration date (the second item) included in the received access token, and the work key (Kw) saved in step S2, to calculate the hash value. Then, the network distribution server device 22 checks whether the hash value calculated here is equal to the hash value (the third item) included in the access token. If the two hash values are not equal, the network distribution server device 22 aborts the process for providing the content for the content request received in step S9.
[0074] If the validity of the access token can be confirmed in all of the above first, second, and third verifications, the network distribution server device 22 determines that this content request is accompanied by a correct access token and proceeds to the content provision in the next step. Note that the order of the first, second, and third verifications is not particularly specified, and they may also be performed in parallel.
[0075] If the validity of the access token is not confirmed in at least any one of the first, second, and third verifications, the network distribution server device 22 determines that the access token is not valid and does not respond to the content request accompanied by the access token. Then, the network distribution server device 22 may return a rejection response, for example, a response indicating that content distribution is not possible, to the terminal device 24. Note that the network distribution server device 22 also does not respond to a content request that does not include an access token and returns a rejection response. The rejection response may include a reason (the number of simultaneous accesses has reached the upper limit, the access token has expired, the access token is not valid or does not exist).
[0076] In step S11, assuming that the validity of the access token has been confirmed in the verification of the access token in step S10, the network distribution server device 22 provides content to the terminal device 24. The content provided by the network distribution server device 22 is the content requested in the content request received in step S9. The terminal device 24 can receive and play back the content provided by the network distribution server device 22. The user of the terminal device 24 can view the video content distributed from the network distribution server device 22 on the terminal device 24. Note that an existing standard streaming protocol (for example, MPEG-DASH, etc.) can be used for providing video content from the network distribution server device 22 to the terminal device 24.
[0077] If the expiration date of the access token stored in the terminal device 24 has passed, the procedures from step S4 or step S5 to step S8 in the processing sequence described above may be executed again. Even after the expiration date of the once-issued access token has passed, if the broadcast reception contract is in an effective state, the broadcast receiver 23 generates a new access token with a new expiration date. Specifically, after the arrival of the access token expiration date, when the terminal device 24 transmits an access token issuance request to the broadcast receiver 23 in step S4 based on a user operation or the like, the procedures up to step S8 are executed. Alternatively, when the expiration date of the access token held by the terminal device 24 arrives, the terminal device 24 may automatically transmit an access token issuance request. Alternatively, when the expiration date of the access token transmitted to the terminal device 24 by the broadcast receiver 23 arrives, the broadcast receiver 23 may automatically execute the procedures from step S5 to step S7 and transmit the access token to the same terminal device 24 again. Alternatively, after the arrival of the access token expiration date, when the terminal device 24 transmits a content request to the network distribution server device 22 in step S9 based on a user operation or the like and as a result receives a rejection response including information that the access token has expired, the terminal device 24 may automatically transmit an access token issuance request to the broadcast receiver 23. Further, when the terminal device 24 stores the access token reissued in step S8, the terminal device 24 may automatically attach this access token in step S9 and transmit the content request again. Thereby, the terminal device 24 can acquire content using the reissued access token. Also, before the expiration date of the access token passes, the procedures from step S4 or step S5 to step S8 may be executed again. For example, the procedures from step S4 to step S8 may be executed at predetermined intervals (e.g., every week or every month) to update the access token. Also, the procedures from step S4 to step S8 may be executed at a predetermined timing within the expiration date (e.g., one month before or one week before the expiration date) to update the access token.
[0078] Also, when the work key (Kw) is changed on the broadcast station side (the broadcast transmission device 21 side), the access token also becomes invalid. Similarly in this case, by executing the procedures from step S4 to step S8, the terminal device 24 can acquire an access token based on the new work key (Kw) after the change.
[0079] FIG. 5 is a block diagram showing an example of at least a part of the internal configuration of each device constituting the system 1 of the embodiment. Each device (each of the broadcast transmission device 21, the network distribution server device 22, the broadcast receiver 23, and the terminal device 24) can be realized using a computer. As shown in the figure, the computer includes a central processing unit 901, a RAM 902, an input / output port 903, input / output devices 904 and 905, etc., and a bus 906. The computer itself can be realized using existing technologies. The central processing unit 901 executes instructions included in a program read from the RAM 902 or the like. The central processing unit 901 writes data to the RAM 902, reads data from the RAM 902, and performs arithmetic operations and logical operations according to each instruction. The RAM 902 stores data and programs. Each element included in the RAM 902 has an address and can be accessed using the address. Note that RAM is an abbreviation for "random access memory". The input / output port 903 is a port for the central processing unit 901 to exchange data with external input / output devices and the like. The input / output devices 904 and 905 exchange data with the central processing unit 901 via the input / output port 903. The bus 906 is a common communication path used inside the computer. For example, the central processing unit 901 reads and writes data in the RAM 902 via the bus 906. Also, for example, the central processing unit 901 accesses the input / output port 903 via the bus 906.
[0080] Note that at least some of the functions of the broadcast transmission device 21, the network distribution server device 22, the broadcast receiver 23, and the terminal device 24 in the above-described embodiment can be realized by a computer and a program. In that case, a program for realizing this function may be recorded on a computer-readable recording medium, and the program recorded on this recording medium may be read into a computer system and executed. Here, the "computer system" is assumed to include hardware such as an OS and peripheral devices. Further, the "computer-readable recording medium" refers to a portable medium such as a flexible disk, a magneto-optical disk, a ROM, a CD-ROM, a DVD-ROM, a USB memory, or a storage device such as a hard disk incorporated in a computer system. That is, the "computer-readable recording medium" may be a non-transitory computer-readable recording medium. Furthermore, the "computer-readable recording medium" also includes, like a communication line when transmitting a program via a network such as the Internet or a communication line such as a telephone line, a medium that temporarily and dynamically holds a program, and in that case, a volatile memory inside a computer system serving as a server or a client that holds a program for a certain period of time. Also, the above program may be for realizing a part of the aforementioned functions, and furthermore, it may be possible to realize the aforementioned functions in combination with a program already recorded in the computer system.
[0081] As described above, the embodiments have been explained, but the present invention can also be implemented in the following modified examples.
[0082] [Modified Example] For example, in the above-described embodiment, the explanation was made on the premise of the use of B-CAS. However, instead, for example, ACAS, which is a restricted reception method used in advanced BS / CS broadcasting, may be used. In any case of using either method, a mechanism similar to that of the above-described embodiment can be constructed using the identification information of the broadcast receiver individual (or an individual such as an IC card attached to the broadcast receiver) in the restricted reception method.
[0083] As described above, according to the above-described embodiment (including the modified example), the above-described problem can be solved, and a mechanism for automatically issuing an access token to the network distribution service provided by the broadcasting station without manual operation can be realized.
[0084] Also, in the above-described embodiment (including the modified example), since the existing broadcast reception contract mechanism (restricted reception method) is used, it is not necessary to separately manage the accounts for the network distribution service. That is, the above-described embodiment is more advantageous than the invention described in Patent Document 1.
[0085] Although the embodiments of the present invention have been described in detail with reference to the drawings, the specific configuration is not limited to this embodiment, and designs and the like within the scope not departing from the gist of the present invention are also included.
Industrial Applicability
[0086] The present invention can be used, for example, in the industries of content distribution (provision) (including the broadcasting business). However, the scope of use of the present invention is not limited to those exemplified here.
Explanation of Signs
[0087] 1 System 21 Broadcast Transmission Device 22 Network Distribution Server Device 23 Broadcast Receiver 24 Terminal Device 31 Communication Network 221 Verification Unit 222 Content Provision Unit 223 Work Key Storage Unit 224 Clock 231 Broadcast signal receiving unit 232 Identification information reading unit 233 Computer 901 Central processing unit 902 RAM 903 Input / output port 904, 905 Input / output device 906 Bus 2331 EMM extraction unit 2332 Contract existence / absence determination unit 2333 Access token issuance request receiving unit 2334 Access token generation unit
Claims
1. a broadcast signal receiving unit for receiving a broadcast signal; an identification information reading unit that reads out identification information for conditional access from a recording medium on which the identification information is recorded; a contract existence determination unit that determines whether or not a valid contract associated with the identification information exists based on an EMM (Entitlement Management Message) included in the received broadcast signal and the identification information read from the recording medium; an access token issuance request receiving unit that receives an access token issuance request from an external device; an access token generation unit that, upon receiving the access token issuance request, generates an access token only if the contract existence determination unit determines that a valid contract exists, and transmits the generated access token to the external device; A broadcast receiver comprising:
2. the contract existence determination unit determines whether or not a valid contract exists depending on whether or not the identification information is included in the EMM (Entitlement Management Message), and determines that a valid contract exists if and only if the identification information is included in the EMM (Entitlement Management Message); The broadcast receiver according to claim 1.
3. The access token generation unit, The identification information; Expiration date information indicating the expiration date of the access token to be generated; a hash function value calculated based on the identification information, the expiration date information, and a work key extracted from the EMM (Entitlement Management Message); generating the access token including The broadcast receiver according to claim 1.
4. a verification unit that, when receiving a content request from an external device, verifies the validity of an access token included in the content request; a content providing unit that provides the content specified in the content request to the external device that is a request source when the verification unit confirms that the access token is a valid access token; Equipped with the access token is generated by a broadcast receiver that receives a broadcast signal; The access token is generated and passed to the external device only when the broadcast receiver determines that a valid contract associated with the identification information exists based on the identification information read from a recording medium that records the identification information for conditional access and an EMM (Entitlement Management Message) included in the received broadcast signal. Internet distribution server device.
5. The access token is The identification information; Expiration date information indicating the expiration date of the access token to be generated; a first hash function value calculated based on the identification information, the expiration date information, and a work key extracted by the broadcast receiver from the EMM (Entitlement Management Message); and The verification unit includes at least Checking whether the current time has passed the expiration date based on the expiration date information; and confirming whether a second hash function value calculated by the device itself based on the identification information, the expiration date information, and a work key previously stored in the device itself matches the first hash function value included in the access token.
5. The network distribution server device according to claim 4.
6. A system including a network distribution server device, a broadcast receiver, and a terminal device, The broadcast receiver comprises: a broadcast signal receiving unit for receiving a broadcast signal; an identification information reading unit that reads out identification information for conditional access from a recording medium on which the identification information is recorded; a contract existence determination unit that determines whether or not a valid contract associated with the identification information exists based on an EMM (Entitlement Management Message) included in the received broadcast signal and the identification information read from the recording medium; an access token issuance request receiving unit that receives an access token issuance request from a terminal device; an access token generation unit that, upon receiving the access token issuance request, generates an access token only if the contract existence determination unit determines that a valid contract exists, and transmits the generated access token to the terminal device; Equipped with the terminal device transmits an access token issuance request to the broadcast receiver, retains the access token transmitted from the broadcast receiver based on the access token issuance request, and transmits a content request including the access token to the Internet distribution server device; The network distribution server device includes: a verification unit that, when receiving a content request from a terminal device, verifies the validity of an access token included in the content request; a content providing unit that provides the content specified in the content request to the terminal device that is a request source when the verification unit confirms that the access token is a valid access token; Equipped with the access token is generated by a broadcast receiver that receives a broadcast signal; The access token is generated and passed to the terminal device only when the broadcast receiver determines that a valid contract associated with the identification information exists based on the identification information read from a recording medium that records the identification information for conditional reception and an EMM (Entitlement Management Message) included in the received broadcast signal. A net distribution server device, the terminal device receives the content provided by the network distribution server device in response to the content request; system.
7. a broadcast signal receiving unit for receiving a broadcast signal; an identification information reading unit that reads out identification information for conditional access from a recording medium on which the identification information is recorded; A computer in a broadcast receiver having the a contract existence determination unit that determines whether or not a valid contract associated with the identification information exists based on an EMM (Entitlement Management Message) included in the received broadcast signal and the identification information read from the recording medium; an access token issuance request receiving unit that receives an access token issuance request from an external device; an access token generation unit that, upon receiving the access token issuance request, generates an access token only if the contract existence determination unit determines that a valid contract exists, and transmits the generated access token to the external device; A program for executing the functions of.
8. a verification unit that, when receiving a content request from an external device, verifies the validity of an access token included in the content request; a content providing unit that provides the content specified in the content request to the external device that is a request source when the verification unit confirms that the access token is a valid access token; Equipped with the access token is generated by a broadcast receiver that receives a broadcast signal; The access token is generated and passed to the external device only when the broadcast receiver determines that a valid contract associated with the identification information exists based on the identification information read from a recording medium that records the identification information for conditional access and an EMM (Entitlement Management Message) included in the received broadcast signal. A program that enables a computer to function as an internet distribution server device.
Citation Information
Patent Citations
Content viewing method and mobile information terminal used for same
WO2018225209A1