MULTIPLE LEVEL PUBLIC KEY HIERARCHY FOR PERFORMANCE AND HIGH SECURITY
    1.
    发明申请
    MULTIPLE LEVEL PUBLIC KEY HIERARCHY FOR PERFORMANCE AND HIGH SECURITY 审中-公开
    多层次的公共关键层次性能和高安全性

    公开(公告)号:WO0045546A8

    公开(公告)日:2002-08-01

    申请号:PCT/US0002170

    申请日:2000-01-28

    Abstract: Multiple public/private key pairs of varying levels of security are used to provide a high level of security while still allowing fast processing of encrypted information. The lower-security level includes keys which are small in length, which are changed relatively often, and which require less or fewer resources to implement their functions (130), (134). When it is required to change key pairs of low security, a key pair at a higher security level (i.e, longer length keys) than the lower-security level keys is used to transfer the new lower-security public keys to devices using those keys. The higher-security keys can, in turn, be changed at a frequency lower than the lower-security keys. The higher-security keys require a higher level of resources to perform their coding operations (120), (124). This approach of using keys of escalating levels of security to replace lower-security keys, where the higher-security keys require more resources, are more secure, and are replaced less often than the lower-security keys, can be followed as many times as is desired to create a hierarchy of public key uses with the result that the lower-security operations can be performed quickly while the overall system security is high.

    Abstract translation: 使用不同级别的安全性的多个公钥/私钥对来提供高水平的安全性,同时仍然允许加密信息的快速处理。 较低的安全级别包括长度较小的密钥,这些密钥相对频繁地改变,并且需要较少或较少的资源来实现其功能(130),(134)。 当需要更改低安全性的密钥对时,使用比较低安全级别密钥更高的安全级别的密钥对(即较长的密钥)将新的较低安全性的公钥传输到使用这些密钥的设备 。 更高安全性的密钥又可以以低于较低安全密钥的频率进行更改。 更高安全性的密钥需要更高级别的资源来执行其编码操作(120),(124)。 使用升级级别的安全性的密钥替代较低安全性密钥(其中较高安全性密钥需要更多资源)的方法更安全,并且被替换的次数低于较低安全密钥,可以跟随多次 需要创建公共密钥使用的层次结构,结果是可以在整个系统安全性较高的情况下快速执行较低安全性的操作。

    KEY MANAGEMENT PROTOCOL AND AUTHENTICATION SYSTEM FOR SECURE CONTENT DELIVERY OVER THE INTERNET
    2.
    发明申请
    KEY MANAGEMENT PROTOCOL AND AUTHENTICATION SYSTEM FOR SECURE CONTENT DELIVERY OVER THE INTERNET 审中-公开
    关键管理协议和互联网安全内容传送的认证系统

    公开(公告)号:WO03045036A3

    公开(公告)日:2003-07-31

    申请号:PCT/US0236806

    申请日:2002-11-15

    Abstract: A digital rights management architecture for securely delivering content to authorized consumers. The architecture includes a content provider (202) and a consumer system (216) for requesting content from the content provider. The content provider generates a session rights object (202B) having purchase options selected by the consumer. A KDC (204) thereafter provides authorization data to the consumer system. Also, a caching server (215) is provided for comparing the purchase options with the authorization data. The caching server (215) forwards the requested content to the consumer system (216) if the purchase options match the authorization data. Note that the caching (215) server employs real time streaming for securely forwarding the encrypted content, and the requested content is encrypted for forwarding to the consumer system (216). Further, the caching server (215) and the consumer system (216) exchange encrypted control messages (and authenticated) for supporting transfer of the requested content. In this manner, all interfaces between components are protected by encryption and/authenticated.

    Abstract translation: 数字版权管理架构,用于将权限安全地传递给授权消费者。 该架构包括用于从内容提供商请求内容的内容提供者(202)和消费者系统(216)。 内容提供商生成具有由消费者选择的购买选项的会话权限对象(202B)。 之后,KDC(204)向消费者系统提供授权数据。 而且,缓存服务器(215)被提供用于将购买选项与授权数据进行比较。 如果购买选项匹配授权数据,则高速缓存服务器(215)将所请求的内容转发到消费者系统(216)。 注意,高速缓存(215)服务器采用实时流传输来安全转发加密的内容,并且所请求的内容被加密以转发到消费者系统(216)。 此外,高速缓存服务器(215)和消费者系统(216)交换加密的控制消息(并被认证)以支持所请求的内容的传送。 以这种方式,组件之间的所有接口都受到加密和/或认证的保护。

    ERROR DETECTION AND RECOVERY FOR HIGH SPEED ISOCHRONOUS DATA IN MPEG-2 DATA STREAM

    公开(公告)号:JPH10136355A

    公开(公告)日:1998-05-22

    申请号:JP15423497

    申请日:1997-05-09

    Abstract: PROBLEM TO BE SOLVED: To provide a means for error detection and recovery in the processing of isochronous data in a decoder. SOLUTION: An isochronous data transfer packet is monitored to retrieve an isochronous data presentation time stamp PTSs. In the presentation of the isochronous data from a reception buffer, timing information extracted from the stamp PTSs is used to be synchronized by a decoder 108 with a system time clock STC. When discontinuous error between isochronous data transfer packets is identified and discontinuity of one packet is identified, while keeping the synchronization of the presentation with respect to the STC, a write pointer in a buffer is advanced by a proper number of bits to compensate the discontinuity. As the additional error detection and recovery technology, e.g. PTS extension to ensure an output timing, use of a PTS offset, provision of a couple of PTS pointers, and use of count of packet elementary stream PES are used.

    CONDITIONAL ACCESS SYSTEM PROVIDING ACCESS TO MULTIPLE PROGRAMS OR SERVICES
    5.
    发明申请
    CONDITIONAL ACCESS SYSTEM PROVIDING ACCESS TO MULTIPLE PROGRAMS OR SERVICES 审中-公开
    提供访问多个程序或服务的条件访问系统

    公开(公告)号:WO2006071394A3

    公开(公告)日:2007-07-26

    申请号:PCT/US2005041629

    申请日:2005-11-17

    Inventor: MORONEY PAUL

    Abstract: A conditional access subsystem is proved which is to reside with an end-user for receiving, decrypting and decoding all programs distributed by a content provider that the end user is entitled to access so that the decrypted and decoded programs are available for display on one or more display devices without use of a set-top terminal dedicated to each of the display devices. The subsystem includes a receiver for receiving and demodulating a multi-program transport (MPTS) stream distributed by the content provider. The MPTS includes a plurality of packets constituting a plurality of programs using one of N different encryption schemes each associated with one of N service tiers, wherein N is an integer greater than one. Each of the N different encryption schemes has a different encryption/decryption key associated therewith. The packet identifiers for the packets associated with programs in any given one of the service tiers are in a consecutive sequence. A decryptor is provided for decrypting each of the programs associated with each of the N service tiers that the end user is entitled to access. A decoder is also provided for decoding each of the decrypted programs.

    Abstract translation: 证明条件访问子系统与终端用户一起驻留,用于接收,解密和解码由最终用户有权访问的内容提供商分发的所有程序,使得解密和解码的程序可用于一个或多个 更多的显示设备,而不使用专用于每个显示设备的机顶终端。 子系统包括用于接收和解调由内容提供商分发的多节目传输(MPTS)流的接收机。 MPTS包括使用N个不同加密方案中的一个与N个服务层中的一个相关联的多个程序组,其中N是大于1的整数。 N个不同加密方案中的每一个具有与其相关联的不同的加密/解密密钥。 与任何一个服务层中的程序相关联的分组的分组标识符是连续的顺序。 提供解密器用于解密与最终用户有权访问的N个服务层中的每一个相关联的每个程序。 还提供了解码器来解码每个解密的程序。

    SECURITY SYSTEM FOR DIGITAL CINEMA
    7.
    发明申请
    SECURITY SYSTEM FOR DIGITAL CINEMA 审中-公开
    数字电影安全系统

    公开(公告)号:WO03047255A2

    公开(公告)日:2003-06-05

    申请号:PCT/US0238212

    申请日:2002-11-25

    Inventor: MORONEY PAUL

    Abstract: A system and method for secure delivery and playback of content at a theater complex domain. The domain receives encrypted and compressed content from a studio domain. The theater complex domain comprises at least a projection unit operable to render decompressed digital video content, and a security module removably coupled to the projection unit. The security module includes at least a decompression unit operable to produce decompressed digital video content. The security module further includes a decryption unit coupled to the decompression unit that is operable to produce unencrypted compressed digital video content that is then processed by the decompression unit. The security module further includes a watermark unit coupled to the decompression unit operable to produce the decompressed digital video content rendered by the projection unit that includes a watermark embedded therein. The watermark is used to uniquely identify the projection unit to which the security module is removably coupled, or alternatively, to uniquely identify the security module itself. The security module is physically locked in a tamper resistant container, and is preferably physically locked inside or onto the projection unit to which it is removably coupled. A receiver is coupled to the security module in order to receive the compressed digital video content from the content source or studio domain. The receiver is coupled to the security module, for example, by an internet protocol network. The receiver may receive the compressed digital video content from the studio domain in real-time, or alternatively, a file server may store the compressed digital video content and later provide it to the security module when it is to be rendered. A connection path to the content source may be provided in order to periodically report back to the content source.

    Abstract translation: 一种用于在剧院复杂领域安全传送和回放内容的系统和方法。 该域从工作室域接收加密和压缩的内容。 影院复合域包括至少一个可操作以提供解压缩的数字视频内容的投影单元,以及可拆卸地耦合到投影单元的安全模块。 安全模块至少包括解压缩单元,其可操作以产生解压缩的数字视频内容。 安全模块还包括耦合到解压缩单元的解密单元,其可操作以产生然后由解压缩单元处理的未加密的压缩数字视频内容。 安全模块还包括耦合到解压缩单元的水印单元,该解压缩单元可操作以产生由投影单元呈现的包括嵌入其中的水印的解压缩数字视频内容。 该水印用于唯一地识别安全模块可移除地耦合到的投影单元,或者替代地唯一地识别安全模块本身。 安全模块物理地锁定在防篡改容器中,并且优选物理地锁定在可拆卸地联接到其上的投影单元的内部或之上。 接收机被耦合到安全模块以便从内容源或演播室领域接收压缩的数字视频内容。 接收机例如通过因特网协议网络耦合到安全模块。 接收机可以实时地从演播室领域接收压缩的数字视频内容,或者文件服务器可以存储压缩的数字视频内容,并且随后在安全模块被呈现时将其提供给安全模块。 可以提供到内容源的连接路径,以便周期性地向内容源报告。

    PERSONAL IDENTIFICATION NUMBER (PIN) GENERATION BETWEEN TWO DEVICES IN A NETWORK
    10.
    发明申请
    PERSONAL IDENTIFICATION NUMBER (PIN) GENERATION BETWEEN TWO DEVICES IN A NETWORK 审中-公开
    网络中的两个设备之间的个人识别号码(PIN)生成

    公开(公告)号:WO2010077514A3

    公开(公告)日:2010-09-16

    申请号:PCT/US2009066174

    申请日:2009-12-01

    Abstract: A method of generating a Personal Identification Number (PIN) between a first device and a second device in a network is provided. The method includes securely receiving information of input choices of the second device and random numbers assigned to the input choices at the first device. At the first device, the PIN is generated from the random numbers, and instructions are provided directing an entry of the input choices on the second device. At the second device, the input choices are entered. The second device is operable to generate the PIN from the input choices and the random numbers if the input choices are entered as instructed.

    Abstract translation: 提供了一种在网络中的第一设备和第二设备之间生成个人识别码(PIN)的方法。 该方法包括安全接收第二设备的输入选择信息和分配给第一设备上的输入选择的随机数。 在第一设备处,从随机数生成PIN,并且提供指令,以将输入选择的条目引导到第二设备上。 在第二个设备上输入输入选项。 如果按照指示输入输入选项,则第二设备可操作以从输入选项和随机数生成PIN。

Patent Agency Ranking