Transmitting device and receiving device

The integration of an ECM generation unit in the transmission device and a key management system in the reception device allows devices without communication functions to decrypt CENC-encrypted content in ARIB-standard digital broadcasting systems, addressing the challenge of key acquisition and ensuring system compatibility.

JP7688987B2Active Publication Date: 2025-06-05NIPPON HOSO KYOKAI
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
JP2021033909
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-03-03
Publication Date
2025-06-05
Estimated Expiration
2041-03-03

AI Technical Summary

Technical Problem

In digital broadcasting systems based on the ARIB standard, devices without communication functions cannot decrypt content encrypted using the CENC method, as they cannot obtain the necessary encryption keys from a license server.

Method used

A transmission device and a reception device are designed to include an ECM generation unit that generates and multiplexes an ECM containing a set of encryption keys and key identification information with the encrypted content, allowing devices without communication functions to decrypt the content.

Benefits of technology

This solution enables devices without communication functions to decrypt CENC-encrypted content in digital broadcasting systems based on the ARIB standard, ensuring compatibility and accessibility across various receiving devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007688987000001
    Figure 0007688987000001
  • Figure 0007688987000002
    Figure 0007688987000002
  • Figure 0007688987000003
    Figure 0007688987000003
Patent Text Reader

Abstract

To allow even a receiver without communication function to decrypt content encrypted by the CENC method in a digital broadcasting system based on the ARIB standard.SOLUTION: A transmitter 100 for a digital broadcasting system includes: an ECM generation unit 122 that generates an ECM including a set of a content key Kc for encrypting content and key identification information KID indicating the content key Kc; and a multiplexing unit 140 that multiplexes and transmits encrypted content which is content encrypted with the content key Kc and to which the key identification information KID is assigned and the ECM generated by the ECM generation unit 122.SELECTED DRAWING: Figure 4
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a transmission device and a reception device for a digital broadcast system.

Background Art

[0002] In conventional digital broadcasting, a limited reception method for limiting reception of broadcasts only to subscribers in pay broadcasting and a content protection method for free broadcasting are used. In these access control methods, broadcast content is encrypted. As a mechanism for securely delivering an encryption key for decrypting the encrypted content, a related information subsystem (triple key method) that delivers the encryption key using key-related information is used (see Non-Patent Documents 1 and 2).

[0003] In the related information subsystem, an encrypted encryption key is transmitted with key-related information common to receiving devices called ECM (Entitlement Control Message). The format of this ECM and the encryption method for the encryption key are determined for each access control method. For example, CAS (Conditional Access System) is used for pay broadcasting and RMP (Rights Management and Protection) is used for free broadcasting.

[0004] On the other hand, as DRM (Digital Rights Management) known as a technology for protecting communication content, mainly Microsoft's PlayReady, Google's Widevine, Apple's Fairplay, etc. are known. As a content encryption method for realizing compatibility with various client terminals that support these different DRM technologies, a method called CENC (Common Encryption) of MPEG (Moving Picture Experts Group) is known (see Non-Patent Document 3).

[0005] This CENC method is an international standard technology that enables the same encrypted content to be decrypted by different DRM and key management systems. Specifically, by attaching corresponding information for multiple DRMs to the header part of the encrypted content, any client terminal that supports a certain DRM can obtain the corresponding license including the encryption key of the content from the license server, and then decrypt and play the encrypted content.

Prior Art Documents

Patent Documents

[0006]

Patent Document 1

Non-Patent Documents

[0007]

Non-Patent Document 1

Non-Patent Document 2

Non-Patent Document 3

Summary of the Invention

Problems to be Solved by the Invention

[0008] In the future, not only television receivers equipped with tuners, but also various client terminals such as smartphones and tablet terminals are assumed to transmit content via broadcasting. In this case, since the content protection technologies supported by client terminals are different, it is considered effective to transmit encrypted content in the CENC format that supports multiple DRM systems via broadcasting.

[0009] However, since the CENC system is premised on the client terminal that receives encrypted content obtaining a license from the license server via communication, there is a problem that a television receiver without a communication function cannot decrypt the encrypted content.

[0010] Regarding such problems, Patent Document 1 proposes a technique related to a DRM license acquisition method in a receiver compliant with the ATSC 3.0 standard, but a license acquisition method in a broadcasting system compliant with the ARIB standard has not necessarily been established.

[0011] Therefore, an object of the present invention is to provide a transmission device and a reception device that enable a reception device without a communication function to decrypt content encrypted in the CENC format in a digital broadcasting system based on the ARIB standard.

Means for Solving the Problems

[0012] The transmission device according to the first aspect is a transmission device for a digital broadcasting system. The transmission device includes an ECM generation unit that generates an ECM including a set of an encryption key for encrypting content and key identification information indicating the encryption key, and multiplexes and transmits the encrypted content encrypted by the encryption key and to which the key identification information is added, and the ECM generated by the ECM generation unit.

[0013] The receiving apparatus according to the second aspect is a receiving apparatus for a digital broadcast system. The receiving apparatus includes a separating unit that separates, from a reception stream, encrypted content encrypted with an encryption key and to which key identification information indicating the encryption key is attached, and an ECM including a set of the encryption key and the key identification information; a key management unit that acquires the set from the ECM and holds the acquired set; a key specifying unit that specifies and acquires, from the key management unit, the encryption key corresponding to the key identification information attached to the encrypted content; and a content decryption unit that decrypts the encrypted content using the encryption key acquired by the key specifying unit.

Advantages of the Invention

[0014] According to the present invention, in a digital broadcast system based on the ARIB standard, it is possible to provide a transmission apparatus and a receiving apparatus that enable a receiving apparatus without a communication function to decrypt content encrypted by the CENC method.

Brief Description of the Drawings

[0015]

Figure 1

Figure 2

Figure 3

Figure 4

Figure 5

Figure 6

Figure 7

Figure 8

Figure 9

Best Mode for Carrying Out the Invention

[0016] With reference to the drawings, a transmission device and a reception device according to an embodiment will be described.

[0017] (Digital Broadcasting System) First, the digital broadcasting system according to this embodiment will be described. FIG. 1 is a diagram showing the configuration of the digital broadcasting system 1 according to this embodiment.

[0018] As shown in FIG. 1, the digital broadcasting system 1 is a broadcasting system based on the ARIB standard, and includes a transmission device 100, a reception device 200, and a license server 300.

[0019] The transmission device 100 is a device that transmits encrypted content. The transmission device 100 is provided, for example, at a broadcasting station. In this embodiment, the transmission device 100 transmits a stream including content encrypted by the CENC method (hereinafter referred to as "CENC-encrypted content").

[0020] The reception device 200 is a device that receives encrypted content. The reception device 200 is, for example, a television receiving device (television tuner), a PC (Personal Computer), a smartphone, or a tablet terminal. In FIG. 1, reception devices 200a to 200c are exemplified as the reception device 200. The reception devices 200a and 200b have a communication function and are connected to the communication network 10 by wire or wirelessly. On the other hand, the reception device 200c does not have a communication function and has no connection to the communication network 10.

[0021] The communication network 10 includes the Internet. The communication network 10 may include a LAN (Local Area Network) or a cellular communication network. The LAN may be a wired LAN or a wireless LAN.

[0022] The license server 300 is a device that is connected to the communication network 10 and issues and manages keys (hereinafter referred to as "encryption keys") for decrypting CENC-encrypted content. In FIG. 1, one license server 300 is illustrated, but different license servers 300 may be provided for each DRM system (business entity). In the CENC method, such an encryption key is called a content key Kc.

[0023] FIG. 2 is a diagram showing the configuration of CENC-encrypted content according to the present embodiment.

[0024] As shown in FIG. 2, the CENC-encrypted content has a header part and a payload part. The header part includes additional information (meta information) in the CENC-encrypted content. The payload part includes encrypted content data obtained by encrypting content such as video and audio with the content key Kc.

[0025] In the present embodiment, the header part of the CENC-encrypted content includes key identification information KID, which is information indicating the content key Kc of the content and is defined by the CENC method, and the system ID of the DRM system. The system ID is a unique identifier for identifying the DRM system (method).

[0026] In FIG. 1, the receiving device 200a receives CENC-encrypted content from the transmitting device 100 via the communication network 10. The receiving device 200a acquires the key identification information KID and the system ID from the header part of the received CENC-encrypted content, transmits the key identification information KID to the license server 300 corresponding to this system ID, and can acquire the content key Kc corresponding to this key identification information KID from the license server 300.

[0027] The receiving device 200b receives CENC-encrypted content from the transmitting device 100 via the broadcast transmission path 20. The broadcast transmission path 20 is a transmission path such as terrestrial broadcast, satellite broadcast, or cable broadcast. Since the receiving device 200b has a communication function, it is possible to obtain the content key Kc from the license server 300 in the same manner as the receiving device 200a.

[0028] The receiving device 200c receives CENC-encrypted content from the transmitting device 100 via the broadcast transmission path 20. Since the receiving device 200c does not have a communication function, it cannot obtain the content key Kc from the license server 300.

[0029] Thus, in order to transmit content via broadcast to various receiving devices 200, although it is effective to transmit content encrypted by the CENC method, a receiving device 200 that does not have a communication function cannot obtain the content key Kc from the license server 300 and cannot decrypt the CENC-encrypted content.

[0030] Therefore, in the present embodiment, the transmitting device 100 multiplexes and transmits an ECM including a set of the content key Kc and key identification information KID indicating this content key Kc with the CENC-encrypted content. The ECM is a kind of key-related information defined by the ARIB standard. The multiplexing method may be MMT (MPEG Media Transport) or MPEG2-TS (Transport Stream).

[0031] Thereby, the receiving device 200 can obtain the content key Kc corresponding to the key identification information KID attached to the received CENC-encrypted content from the ECM. Therefore, even a receiving device 200 that does not have a communication function can obtain the content key Kc and decrypt the CENC-encrypted content. Thus, in the digital broadcast system 1 based on the ARIB standard, even a receiving device 200c that does not have a communication function can decrypt the content encrypted by the CENC method.

[0032] FIG. 3 is a diagram showing an example of a sequence in the digital broadcast system 1 according to the present embodiment.

[0033] As shown in FIG. 3, in step S1, the transmission device 100 transmits a control message to the reception device 200. The transmission device 100 may transmit the control message periodically. The control message includes a package configuration description table for the reception device 200 to receive key-related information.

[0034] In step S2, the transmission device 100 transmits key-related information to the reception device 200. The transmission device 100 may transmit the key-related information periodically. The key-related information includes an EMM (Entitlement Management Message) and an ECM. The ECM includes a set of a content key Kc and key identification information KID.

[0035] In step S3, the transmission device 100 transmits CENC-encrypted content to the reception device 200. The CENC-encrypted content is content encrypted with the content key Kc. The CENC-encrypted content is provided with the key identification information KID of this content key Kc. The reception device 200 acquires the content key Kc corresponding to the key identification information KID provided in the CENC-encrypted content from the ECM received in step S2, and decrypts the CENC-encrypted content using the acquired content key Kc.

[0036] (Transmission device) Next, the transmission device 100 according to the present embodiment will be described. FIG. 4 is a diagram showing the configuration of the transmission device 100 according to the present embodiment.

[0037] As shown in FIG. 4, the transmission device 100 includes an encrypted content generation unit 110, a key-related information generation unit 120, a control message generation unit 130, and a multiplexing unit 140.

[0038] The encryption content generation unit 110 encrypts video and audio file content in the ISO-BMFF (ISO-Base Media File Format) format using the content key Kc to generate CENC encrypted content. The configuration of the CENC encrypted content is as per the standard specification of Non-Patent Document 3. Meta information indicating encryption parameters (such as the system ID indicating the DRM system and the KID indicating key identification information) is described at least within the Content Protection Descriptor of the MPEG-DASH manifest MPD (Media Presentation Description), or within the pssh box of the moov / moof box, and also within the tenc box of the moov box and the sgpd box of the moof box.

[0039] The key-related information generation unit 120 generates key-related information such as ECM and EMM, and generates a section encapsulating them. The key-related information generation unit 120 includes an EMM generation unit 121 and an ECM generation unit 122.

[0040] The EMM generation unit 121 generates EMM, which is key-related information for each receiving device 200 or for each type of receiving device 200 (such as by manufacturer). In the case of each individual receiving device 200, the key-related information (working key Kw) is encrypted using a different key (master key Km) for each receiving device 200 and sent out. Also, in the case of each type of receiving device 200, the key-related information (working key Kw) is encrypted using a different key (device key Kd) for each type of receiving device 200 and sent out.

[0041] The ECM generation unit 122 generates ECM, which is key-related information common to the receiving devices 200. The ECM generation unit 122 encrypts and sends out an ECM including at least a set (corresponding relationship) of the content key Kc of the CENC encrypted content and the key identification information KID using the working key Kw. An example of the configuration of the ECM will be described later.

[0042] The control message generation unit 130 generates various control messages. The control message generation unit 130 generates a package configuration description table transmitted by the control message, specifically, a table indicating a packet of information on content constituting a package (program) and key-related information related to its encryption. For example, in the case of MMT, the package configuration and the packet ID of ECM are specified in the MMT package table (MPT), and the packet ID of EMM is specified in the CA table (CAT). In the case of MPEG2-TS, the stream information of the program and the packet ID of ECM are specified in the PMT, and the packet ID of EMM is specified in the CAT.

[0043] The multiplexing unit 140 multiplexes the CENC encrypted content generated by the encrypted content generation unit 110, the key-related information (EMM and ECM) generated by the key-related information generation unit 120, and the control message generated by the control message generation unit 130 by MMT or MPEG2-TS and outputs a stream.

[0044] (First Configuration Example of ECM) Next, a first configuration example of ECM according to the present embodiment will be described. FIG. 5 is a diagram showing the first configuration example of ECM according to the present embodiment.

[0045] In the configuration example shown in FIG. 5, ECM has a protocol number, business identification information, work key identification information, key identification information KID, content key Kc, expiration date information, and forgery detection.

[0046] The protocol number is information that identifies the ECM format and includes parameters of the encryption / decryption algorithm. When ECM includes a set of key identification information KID and content key Kc, a special value indicating that it includes the set of key identification information KID and content key Kc may be set as the protocol number.

[0047] The entity identification information is information indicating the entity that issues the content key Kc. Note that different entities may use the same key identification information KID. Therefore, by associating the entity identification information with the key identification information KID in the ECM, the receiving device 200 can easily identify the correct content key Kc. Specifically, even if content keys Kc associated with duplicate key identification information KID are issued by different entities, the receiving device 200 can identify the correct content key Kc based on the entity identification information and the key identification information KID.

[0048] The work key identification information is information indicating the work key Kw used for decrypting the ECM.

[0049] The key identification information KID is information indicating the content key Kc. The key identification information KID is stored in the ECM in association with the content key Kc.

[0050] The expiration date information is information indicating the expiration date of the set of the key identification information KID and the content key Kc included in this ECM. The expiration date may be specified by an absolute time described in the form of an NTP (Network Time Protocol) timestamp or the like, or may be specified by a relative time such as a timer value counted down from the time of receiving the ECM. By transmitting such expiration date information, the period during which the set of the content key Kc and the key identification information KID is valid can be set.

[0051] The forgery detection is information for detecting forgery of the ECM.

[0052] Among these pieces of information, the key identification information KID, the content key Kc, and the expiration date information are encrypted with the work key Kw.

[0053] (Second Configuration Example of ECM) Next, a second configuration example of the ECM according to the present embodiment will be described. FIG. 6 is a diagram showing the second configuration example of the ECM according to the present embodiment.

[0054] In the configuration example shown in FIG. 6, a set of key identification information KID, content key Kc, and expiration date information is included in a plurality (three sets) in the same ECM. As a result, a plurality of content keys Kc can be transmitted collectively.

[0055] For example, when the transmission device 100 frequently switches the content key Kc used for content encryption, by having the receiving device 200 hold a plurality of content keys Kc in advance, it becomes possible for the receiving device 200 to quickly decrypt the content when the content key Kc is switched.

[0056] (Receiving device) Next, the receiving device 200 according to the present embodiment will be described. FIG. 7 is a diagram showing the configuration of the receiving device 200 according to the present embodiment.

[0057] As shown in FIG. 7, the receiving device 200 includes a separation unit 210, a key-related information specifying unit 220, a key-related information processing unit 230, a key management unit 240, a key specifying unit 250, a content decryption unit 260, a content playback unit 270, and a playback control unit 280.

[0058] The separation unit 210 separates a control message, key-related information (EMM and ECM), and CENC-encrypted content from the received stream. The separation unit 210 outputs a control message (package configuration description table) to the key-related information specifying unit 220, outputs the key-related information to the key-related information processing unit 230, and outputs the CENC-encrypted content to the key specifying unit 250.

[0059] The key-related information specifying unit 220 specifies the packet IDs of the ECM and EMM from the package configuration description table, and outputs the specified packet IDs to the key-related information processing unit 230.

[0060] The key-related information processing unit 230 extracts the ECM and EMM from the key-related information based on the packet IDs specified by the key-related information specifying unit 220, and processes the key-related information. The key-related information processing unit 230 includes an EMM processing unit 231 and an ECM processing unit 232.

[0061] The EMM processing unit 231 decrypts the encrypted part of the EMM using a pre-embedded key (master key Km / device key Kd), extracts the working key Kw, and outputs the working key Kw to the ECM processing unit 232.

[0062] The ECM processing unit 232 decrypts the encrypted part of the ECM using the working key Kw obtained from the EMM processing unit 231, and obtains a set of key identification information KID and content key Kc. At this time, the ECM processing unit 232 also obtains expiration date information, business entity identification information, etc., and outputs them to the key management unit 240.

[0063] The key management unit 240 holds a set of key identification information KID and content key Kc. FIG. 8 is a diagram showing an example of the information managed by the key management unit 240.

[0064] As shown in FIG. 8, the key management unit 240 associates and holds business entity identification information indicating a code for identifying the business entity that issued the key, key identification information KID, content key Kc, and expiration date information. The key management unit 240 deletes or invalidates information (key identification information KID and content key Kc) that has passed the expiration date indicated by the expiration date information. To invalidate means to make the information unusable without deleting it.

[0065] By the management method as shown in FIG. 8, the key management unit 240 can hold a plurality of sets (associations between key identification information KID and content key Kc) at the same time, and can delete and invalidate some sets according to the expiration date set from the transmission device 100, so that more flexible operation becomes possible. For example, depending on the setting of the expiration date, it is also possible to keep a specific set valid for a long period of time. Therefore, even in use cases such as rebroadcasting a certain protected content, accumulating it for re-watching, etc., it is possible to watch the protected content without changing the content key Kc.

[0066] Returning to FIG. 7, the key identification unit 250 refers to the information described in the tenc box included in the moov box storing the meta information of the CENC encrypted content, or the sgpd box included in the moof box, to determine the key identification information KID, and specifies and acquires the content key Kc corresponding to this key identification information KID from the key management unit 240. At this time, by combining the key identification information KID and the business entity identification information and making an inquiry to the key management unit 240, even when the same key identification information KID is used by different business entities, a unique content key Kc can be specified. Here, the key identification unit 250 specifies the business entity identification information (business entity) used for the inquiry to the key management unit 240 based on the system ID assigned to the CENC encrypted content, control in the application, or settings by user operations, etc., combines the specified business entity identification information and the key identification information KID, and makes an inquiry to the key management unit 240. When business entity identification information is assigned to the CENC encrypted content, the key identification unit 250 may use this business entity identification information to make an inquiry to the key management unit 240.

[0067] The content decryption unit 260 decrypts the CENC encrypted content using the content key Kc specified by the key identification unit 250, and outputs the decrypted content to the content playback unit 270.

[0068] The content playback unit 270 plays back the content decrypted by the content decryption unit 260.

[0069] The playback control unit 280 performs playback control of the CENC encrypted content. This playback control may be control by user operations via the user interface, or control in an application programmed to perform automatic playback.

[0070] FIG. 9 is a diagram showing the operation flow of the receiving apparatus 200 according to the present embodiment.

[0071] As shown in FIG. 9, in step S11, the separation unit 210 and the key-related information identification unit 220 refer to the package configuration description table to extract key-related information (EMM and ECM), and output the extracted key-related information to the key-related information processing unit 230.

[0072] In step S12, the key-related information processing unit 230 processes the key-related information. Here, the ECM processing unit 232 extracts a set of key identification information KID and content key Kc from the ECM.

[0073] In step S13, the key management unit 240 stores the set of key identification information KID and content key Kc. The key management unit 240 may also store the business entity identification information and expiration date information together.

[0074] In step S14, the key identification unit 250 acquires the CENC encrypted content based on the reproduction trigger from the reproduction control unit 280.

[0075] In step S15, the key identification unit 250 identifies the key identification information KID by referring to the meta information included in the header portion of the CENC encrypted content.

[0076] In step S16, the key identification unit 250 makes an inquiry to the key management unit 240 based on the key identification information KID, and acquires the content key Kc.

[0077] In step S17, the content decryption unit 260 decrypts the CENC encrypted content using the acquired content key Kc.

[0078] In step S18, the content reproduction unit 270 reproduces the decrypted content.

[0079] (Other embodiments) In the above-described embodiment, an example of transmitting content encrypted by the CENC method (CENC-encrypted content) from the transmitting device 100 to the receiving device 200 has been described. However, any method of transmitting encrypted content to which key identification information is attached may be used, and the method is not limited to the CENC method.

[0080] In the above-described embodiment, the receiving device 200 mainly assumed was the receiving device 200c that does not have a communication function. However, the configurations and operations according to the above-described embodiment may also be applied to the receiving devices 200a and 200b that have a communication function.

[0081] The programs that cause a computer to execute each process performed by the transmitting device 100 may be provided. Also, the programs that cause a computer to execute each process performed by the receiving device 200 may be provided. The programs may be recorded on a computer-readable medium. By using a computer-readable medium, it is possible to install the program in a computer. Here, the computer-readable medium on which the program is recorded may be a non-transitory recording medium. The non-transitory recording medium is not particularly limited, and for example, a recording medium such as a CD-ROM or a DVD-ROM may be used.

[0082] The circuits that execute each process performed by the transmitting device 100 may be integrated, and the transmitting device 100 may be configured by a semiconductor integrated circuit (chipset, SoC). The circuits that execute each process performed by the receiving device 200 may be integrated, and the receiving device 200 may be configured by a semiconductor integrated circuit (chipset, SoC).

[0083] As described above, the embodiments have been described in detail with reference to the drawings. However, the specific configuration is not limited to the above, and various design changes and the like can be made without departing from the gist.

Description of Reference Numerals

[0084] 1: Digital broadcast system 10: Communication network 20: Broadcast transmission path 100: Transmitting device 110: Encrypted content generation unit 120: Key-related information generation unit 121: EMM generation unit 122: ECM generation unit 130: Control message generation unit 140: Multiplexing unit 200: Receiving device 210: Separation unit 220: Key-related information identification unit 230: Key-related information processing unit 231: EMM processing unit 232: ECM processing unit 240: Key management unit 250: Key identification unit 260: Content decryption unit 270: Content playback unit 280: Playback control unit 300: License server

Claims

1. A transmitting apparatus for a digital broadcast system, comprising: an ECM generation unit that generates an ECM including a set of an encryption key for encrypting content and key identification information indicating the encryption key; a multiplexing unit that multiplexes and transmits encrypted content encrypted with the encryption key and provided with the key identification information and the ECM generated by the ECM generation unit; wherein: the encrypted content is encrypted by the CENC method; the encryption key is a content key Kc defined by the CENC method; the key identification information is key identification information KID defined by the CENC method. The transmitting apparatus is characterized by the above.

2. The transmitting apparatus according to claim 1, wherein the ECM generation unit generates the ECM further including expiration information indicating an expiration date of the encryption key in the set.

3. The transmitting apparatus according to claim 1 or 2, wherein the ECM generation unit generates the ECM including a plurality of the sets.

4. The transmitting apparatus according to any one of claims 1 to 3, wherein the ECM generation unit generates the ECM including entity identification information indicating an entity that issues the encryption key.

5. A receiving apparatus for a digital broadcast system, comprising: a separation unit that separates, from a received stream, encrypted content encrypted with an encryption key and provided with key identification information indicating the encryption key and an ECM including a set of the encryption key and the key identification information; a key management unit that acquires the set from the ECM and holds the acquired set; a key specifying unit that specifies and acquires, from the key management unit, the encryption key corresponding to the key identification information given to the encrypted content; a content decryption unit that decrypts the encrypted content using the encryption key acquired by the key specifying unit; wherein: the encrypted content is encrypted by the CENC method; the encryption key is a content key Kc defined by the CENC method; the key identification information is key identification information KID defined by the CENC method. The receiving apparatus is characterized by the above.

6. The set included in the ECM further includes expiration information indicating an expiration date of the encryption key, and the key management unit deletes or invalidates the set including the encryption key that has passed the expiration date. The receiving apparatus according to claim 5 is characterized by the above.

7. The receiving apparatus according to claim 5 or 6, wherein the ECM includes a plurality of the sets.

8. A receiving apparatus for a digital broadcast system, a separating unit that separates, from a reception stream, encrypted content encrypted with an encryption key and having key identification information indicating the encryption key, and an ECM including a set of the encryption key and the key identification information; a key management unit that acquires the set from the ECM and holds the acquired set; a key specifying unit that specifies and acquires, from the key management unit, the encryption key corresponding to the key identification information given to the encrypted content; a content decryption unit that decrypts the encrypted content using the encryption key acquired by the key specifying unit; comprising: the ECM further includes business entity identification information indicating a business entity that issues the encryption key; the key management unit manages the set in association with the business entity identification information; the key specifying unit specifies a business entity for which the encryption key is to be acquired, and acquires, from the key management unit, the encryption key corresponding to the business entity identification information of the specified business entity and the key identification information given to the encrypted content. The receiving apparatus is characterized by this.

9. The set included in the ECM further includes expiration date information indicating an expiration date of the encryption key, The receiving apparatus according to claim 8, wherein the key management unit deletes or invalidates the set including the encryption key that has passed the expiration date.

10. The receiving apparatus according to claim 8 or 9, wherein the ECM includes a plurality of the sets.

Citation Information

Patent Citations

  • IEC23001-07

  • Reception method

    JP2002101086A

  • Broadcasting device and receiver providing storage type service

    JP2002247547A

  • Mobile communication terminal, communication system, and method for supplying decoding key

    JP2004236136A

  • System and method for storing / distributing broadcast content and program

    JP2010161505A