会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 3. 发明公开
    • Process for managing a symmetric key in a communication network and devices for the implementation of this process
    • 用于在通信网络中管理的对称密钥和用于实施该方法的方法的装置
    • EP1253762A1
    • 2002-10-30
    • EP02006985.2
    • 2002-03-27
    • Thomson Licensing S.A.
    • Andreaux, Jean-PierreDiehl, Eric M.Durand, Alain M.
    • H04L29/06
    • H04L63/0435H04L12/2803H04L63/0457H04L63/062H04N21/23476
    • The communication network comprises a device of a first type (1) furnished with a source of data to be broadcast over the network and at least one device of a second type (2) intended to receive the said data. The symmetric key management process comprises the following steps:

      the source device (1) determines a first symmetric key (Kc) and transmits it securely (E1{PUB2}(Kc)) to at least one receiver device (2);
      a receiver device (2) receives the first symmetric key (Kc), encrypts it (E2) with the aid of a second symmetric key (Kn), known to the receiver devices (2) of the network and transmits it to the source device;
      the source device (1) recovers the encryption (E2{Kn}(Kc)) of the first symmetric key (Kc) and stores it.

      Before transmitting the data (CW) to at least one reception device (2), the source device (1) encrypts (E3) these data with the aid of the first symmetric key (Kc), then it transmits these encrypted data (E3{Kc}(CW)), accompanied by the first encrypted symmetric key (E2{Kn}(Kc)), to at least one receiver device (2).
      The receiver device (2) decrypts the first symmetric key (Kc) with the aid of the second key (Kn) which it possesses, then it decrypts the encrypted data with the aid of the first symmetric key thus recovered.
      The invention also pertains to devices for implementing the process.
    • 所述通信网络包括配备有数据的源的第一类型(1)的装置将被广播通过网络和用于接收所述数据的第二类型(2)中的至少一个设备。 对称密钥管理过程包括如下步骤:源设备(1)bestimmt一个第一对称密钥(KC),安全地发送它(E1äPUB2ü(KC))到至少一个接收机设备(2); 接收机设备(2)接收第一对称密钥(KC),与第二对称密钥的帮助(KN),已知的接收器装置加密它(E2)(2)所述网络的,并将其发送到信源装置 ; 源装置(1)回收第一对称密钥(KC),并将其存储的加密(E2äKnü(KC))。 与所述第一对称密钥(KC)的辅助数据(CW)发送到至少一个接收装置(2),源设备(1)加密(E3)合成数据之前,然后将其发送论文加密数据(E3äKcü( CW))由所述第一加密的对称密钥(E2äKnü(KC))陪同到至少一个接收机设备(2)。 接收机设备(2)解密所述第一对称密钥(KC)与所述第二密钥(Kn)的哪它具有,那么它解密与所述第一对称密钥的辅助下加密数据由此回收的帮助。 因此,本发明涉及一种用于实施该方法的设备。
    • 5. 发明公开
    • Device pairing
    • 设备配对
    • EP1626579A1
    • 2006-02-15
    • EP04300532.1
    • 2004-08-11
    • Thomson Licensing
    • Diehl, EricAndreaux, Jean-PierreCarbonnel, Louis-XavierDurand, Alain
    • H04N7/16
    • H04N21/43615H04N7/163H04N21/44227H04N21/4623
    • The invention relates to pairing a slave device with a master device, for example decoders in a conditional access system. There is provided a security module (30, 43, 44) that stores a device state that indicates whether a decoder shall be a master or a slave decoder. There is also provided a method in a conditional access system of providing a device (41, 42) with a device state (CAM_STATE) stored on a security module (30, 43, 44). It is detected that the security module is in connection with the device and the device state is transferred from the security module to the device. There is further provided a method of pairing a slave device (42) with a master device (41). The slave device asks (601) the master device to identify itself, the master device returns (602) an identification, and if the slave device has not yet been paired with a master device, it checks (604) the identity of the master device and, if the identity is verified pairs (607) with the master device. There is also provided a first, slave, device (42) for pairing with a second, master, device (41). The first device comprises an interface (27) for sending an identification command to and receiving an identification message from the master device, and a processor (24) for checking the identity of the second device and pairing the first device with the second device.
    • 本发明涉及将从设备与主设备配对,例如条件接入系统中的解码器。 提供了安全模块(30,43,44),其存储指示解码器应该是主解码器还是从解码器的设备状态。 还提供了一种在条件访问系统中提供具有存储在安全模块(30,43,44)上的设备状态(CAM_STATE)的设备(41,42)的方法。 检测到安全模块与设备连接并且设备状态从安全模块传输到设备。 还提供了一种将从设备(42)与主设备(41)配对的方法。 从设备请求(601)主设备标识自身,主设备返回(602)标识,并且如果从设备还没有与主设备配对,则它检查(604)主设备的标识 并且如果身份被验证与主设备配对(607)。 还提供了用于与第二主设备(41)配对的第一从设备(42)。 第一设备包括用于向主设备发送识别命令并从主设备接收识别消息的接口(27),以及用于检查第二设备的身份并将第一设备与第二设备配对的处理器(24)。
    • 8. 发明公开
    • Secure authenticated channel
    • Sicherer,鉴定者Kanal
    • EP1906587A2
    • 2008-04-02
    • EP08100504.3
    • 2004-10-29
    • Thomson Licensing, Inc.
    • Durand, AlainAndreaux, Jean-PierreSirvent, Thomas
    • H04L9/32
    • H04L9/0844H04L9/3236H04L9/3263H04L2209/60
    • Protocols (i.e. methods) and corresponding apparatuses for verifying a hash value. Two peers with knowledge of a common Diffie-Hellman permanent key, K perm , and the identity and public key of the other peer. A first peer chooses a first ephemeral private key x and calculates the first corresponding ephemeral public key g x , which is sent to the second peer. The second peer calculates a second ephemeral public key g y in the same manner, and an ephemeral shared key K eph, hashes g y , K eph, K perm, and its identity, and sends g y and the hash to the first peer. The first peer calculates K eph , verifies the hash, and hashes g x , K eph , K perm , and its identity, and sends it to the second peer that verifies this hash.
    • 用于验证哈希值的协议(即方法)和相应的装置。 具有普通Diffie-Hellman永久密钥,K perm的知识的两个对等体,以及另一个对等体的身份和公钥。 第一对等体选择第一短暂私钥x并计算发送给第二对等体的第一对应临时公钥g x。 第二对等体以相同的方式计算第二临时公钥gy,并且短暂共享密钥K eph,哈希g y,K eph,K perm及其身份,并将g y和散列发送到第一对等体。 第一个对等体计算K eph,验证散列,并且哈希值为g x,K eph,K perm和其身份,并将其发送到验证此散列的第二个对等体。
    • 10. 发明公开
    • Device pairing
    • Vorrichtungspaarbildung
    • EP1628481A1
    • 2006-02-22
    • EP05105420.3
    • 2005-06-20
    • Thomson Licensing
    • Diehl, EricAndreaux, Jean-PierreCarbonnel, Louis-XavierDurand, Alain
    • H04N7/16
    • H04N21/4181H04N7/163H04N21/4367H04N21/4623
    • The invention relates to pairing a slave device with a master device, for example decoders in a conditional access system. There is provided a security module (30, 43, 44) that stores a device state that indicates whether a decoder shall be a master or a slave decoder. There is also provided a method in a conditional access system of providing a device (41, 42) with a device state (CAM_STATE) stored on a security module (30, 43, 44). It is detected that the security module is in connection with the device and the device state is transferred from the security module to the device. There is further provided a method of pairing a slave device (42) with a master device (41). The slave device asks (601) the master device to identify itself, the master device returns (602) an identification, and if the slave device has not yet been paired with a master device, it checks (604) the identity of the master device and, if the identity is verified pairs (607) with the master device. There is also provided a first, slave, device (42) for pairing with a second, master, device (41). The first device comprises an interface (27) for sending an identification command to and receiving an identification message from the master device, and a processor (24) for checking the identity of the second device and pairing the first device with the second device.
    • 本发明涉及从属设备与主设备的配对,例如条件访问系统中的解码器。 提供了一种存储指示解码器是主器件还是从器件解码器的器件状态的安全模块(30,43,44)。 还提供了一种在条件访问系统中提供具有存储在安全模块(30,43,44)上的设备状态(CAM_STATE)的设备(41,42)的方法。 检测到安全模块与设备连接,并且设备状态从安全模块传送到设备。 还提供了一种将从设备(42)与主设备(41)配对的方法。 从设备请求(601)主设备识别自身,主设备返回(602)标识,如果从设备尚未与主设备配对,则检查(604)主设备的身份 并且,如果身份与主设备的验证对(607)。 还提供了用于与第二主设备(41)配对的第一从设备(42)。 第一设备包括用于向主设备发送识别命令并从主设备接收标识消息的接口(27),以及用于检查第二设备的身份并将第一设备与第二设备配对的处理器(24)。