METHOD AND APPARATUS OF MUTUAL AUTHENTICATION AND KEY DISTRIBUTION FOR DOWNLOADABLE CONDITIONAL ACCESS SYSTEM IN DIGITAL CABLE BROADCASTING NETWORK
First Claim
Patent Images
1. A method of controlling a downloadable Conditional Access (CA) Secure Micro (SM) in a mutual authentication method in a digital cable broadcasting network, the method comprising:
- generating, by the downloadable CA SM, a public key and a private key as one pair, using a specific algorithm;
requesting a Trusted Authority (TA) to issue an SM certificate via a secure communication channel of an Authentication Proxy (AP) Server using the generated keys;
verifying whether the SM certificate issued from the TA via the secure communication channel is forged or altered using a TA certificate included in the downloadable CA SM;
transmitting an SM authentication request message to the AP server based on the SM certificate for which the verifying is completed; and
comparing first AP server identification information and second AP server identification information included in the SM certificate issued from the TA and verifying whether the first and second AP server identification information are the same using an SM authentication response message received from the AP server.
1 Assignment
0 Petitions
Accused Products
Abstract
A method and apparatus of X.509 certificate-based mutual authentication and key distribution for a Downloadable Conditional Access System (DCAS) in a digital cable broadcasting network is provided for composing a software-based secure DCAS in various Conditional Access Systems (CASs) based on an embodiment form of Conditional Access (CA) application for CA of digital cable broadcasting.
66 Citations
16 Claims
-
1. A method of controlling a downloadable Conditional Access (CA) Secure Micro (SM) in a mutual authentication method in a digital cable broadcasting network, the method comprising:
-
generating, by the downloadable CA SM, a public key and a private key as one pair, using a specific algorithm; requesting a Trusted Authority (TA) to issue an SM certificate via a secure communication channel of an Authentication Proxy (AP) Server using the generated keys; verifying whether the SM certificate issued from the TA via the secure communication channel is forged or altered using a TA certificate included in the downloadable CA SM; transmitting an SM authentication request message to the AP server based on the SM certificate for which the verifying is completed; and comparing first AP server identification information and second AP server identification information included in the SM certificate issued from the TA and verifying whether the first and second AP server identification information are the same using an SM authentication response message received from the AP server. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A method of controlling an AP server, the method comprising:
-
generating, by the AP server, a secure communication channel with a TA; verifying validity of an SM certificate received from a downloadable CA SM, and authenticating an SM; generating a session key being a symmetric key for secure communication of a corresponding downloadable CA SM when SM authentication of the SM certificate is completed; and transmitting an SM authentication response using the generated session key. - View Dependent Claims (9, 10, 11, 12)
-
-
13. A method of controlling a TA in a mutual authentication method in a digital cable broadcasting network, the method comprising:
-
issuing, by the TA, an SM certificate with respect to a downloadable CA SM, and storing list information about the downloadable CA SM in a downloadable CA SM key pairing database (DB); receiving an SM certificate request message from the downloadable CA SM; searching for the downloadable CA SM key pairing DB based on the received message, and verifying validity of a requested downloadable CA SM; and issuing the SM certificate signed by a private key of a TA to the downloadable CA SM based on a result of the verifying. - View Dependent Claims (14, 15, 16)
-
Specification