Movatterモバイル変換


[0]ホーム

URL:


Jump to content
WikipediaThe Free Encyclopedia
Search

Conditional access

From Wikipedia, the free encyclopedia
System used to prevent non-paying customers from accessing content that requires payment
This article has multiple issues. Please helpimprove it or discuss these issues on thetalk page.(Learn how and when to remove these messages)
This articlemay containunverified orindiscriminate information inembedded lists. Please helpclean up the lists by removing items or incorporating them into the text of the article.(January 2015)
This articlemay containoriginal research. Pleaseimprove it byverifying the claims made and addinginline citations. Statements consisting only of original research should be removed.(January 2015) (Learn how and when to remove this message)
Globe icon.
The examples and perspective in this articlemay not represent aworldwide view of the subject. You mayimprove this article, discuss the issue on thetalk page, orcreate a new article, as appropriate.(January 2015) (Learn how and when to remove this message)
icon
This articleneeds additional citations forverification. Please helpimprove this article byadding citations to reliable sources. Unsourced material may be challenged and removed.
Find sources: "Conditional access" – news ·newspapers ·books ·scholar ·JSTOR
(March 2008) (Learn how and when to remove this message)
(Learn how and when to remove this message)

Conditional access (CA) is a term commonly used in relation tosoftware and todigital television systems. Conditional access is an evaluation to ensure the person who is seeking access to content is authorized to access the content. Access is managed by requiring certain criteria to be met before granting access to the content.

In software

[edit]

Conditional access is a function that lets an organization manage people's access to the software in question, such as email, applications, and documents. It is usually offered asSaaS (Software-as-a-Service) and deployed in organizations to keep company data safe. By setting conditions on the access to this data, the organization has more control over who accesses the data and where and in what way the information is accessed.

When setting up conditional access, access can be limited to or prevented based on the policy defined by the system administrator. For example, a policy might require that access is available from certain networks, or access is blocked when a specificweb browser is requesting the access.

In digital television

[edit]

Under theDigital Video Broadcasting (DVB) standard, conditional access system (CAS) standards are defined in the specification documents for DVB-CA (conditional access),DVB-CSA (the commonscrambling algorithm) andDVB-CI (theCommon Interface).[1] These standards define a method by which one can obfuscate a digital-television stream, with access provided only to those with valid decryptionsmart-cards. The DVB specifications for conditional access are available from thestandards page on the DVB website.

This is achieved by a combination ofscrambling andencryption. The data stream is scrambled with a 48-bit secret key, called thecontrol word. Knowing the value of the control word at a given moment is of relatively little value, as under normal conditions, content providers will change the control word several times per minute. The control word is generated automatically in such a way that successive values are not usually predictable; the DVB specification recommends using a physical process for that.

In order for the receiver to unscramble the data stream, it must be permanently informed about the current value of the control word. In practice, it must be informed slightly in advance, so that no viewing interruption occurs.Encryption is used to protect the control word during transmission to the receiver: the control word is encrypted as anentitlement control message (ECM). The CA subsystem in the receiver will decrypt the control word only when authorised to do so; that authority is sent to the receiver in the form of anentitlement management message (EMM). The EMMs are specific to eachsubscriber, as identified by the smart card in his receiver, or to groups of subscribers, and are issued much less frequently than ECMs, usually at monthly intervals. This being apparently not sufficient to prevent unauthorized viewing,TPS has lowered this interval down to about 12 minutes. This can be different for every provider,BSkyB uses a term of 6 weeks. WhenNagravision 2 was hacked,Digital+ started sending a new EMM every three days to make unauthorized viewing more cumbersome.

The contents of ECMs and EMMs are not standardized and as such they depend on the conditional access system being used.[2]

The control word can be transmitted through different ECMs at once. This allows the use of several conditional access systems at the same time, a DVB feature calledsimulcrypt, which saves bandwidth and encourages multiplex operators to cooperate.DVB Simulcrypt is widespread in Europe; some channels, like theCNN International Europe from theHot Bird satellites, can use seven different CA systems in parallel.

The decryption cards are read, and sometimes updated with specific access rights, either through aconditional-access module (CAM), aPC card-format card reader meeting DVB-CI standards, or through a built-inISO/IEC 7816 card reader, such as that in theSky Digibox.

Several companies provide competing CA systems; ABV,VideoGuard, Irdeto,Nagravision,Conax,Viaccess,Synamedia,Mediaguard (a.k.a.SECA) are among the most commonly used CA systems.

Due to the common usage of CA in DVB systems, many tools to aid in or evendirectly circumvent encryption exist. CAM emulators and multiple-format CAMs exist which can either read several card formats or even directly decrypt a compromised encryption scheme. Most multiple format CAMs and all CAMs that directly decrypt a signal are based onreverse engineering of the CA systems. A large proportion of the systems currently in use for DVB encryption have been opened to full decryption at some point, including Nagravision, Conax, Viaccess, Mediaguard (v1) as well as the first version of VideoGuard.

Conditional access in North America

[edit]

In Canada and the United States, the standard for conditional access is provided withCableCARDs whose specification was developed by the cable company consortiumCableLabs.

Cable companies in the United States are required by theFederal Communications Commission to support CableCARDs. Standards exist for two-way communication (M-card), butsatellite television has separate standards. Next-generation approaches in the United States eschew such physical cards and employ schemes using downloadable software for conditional access such asDCAS.

The main appeal of such approaches is that theaccess control may be upgraded dynamically in response to security breaches without requiring expensive exchanges of physical conditional-access modules.

Conditional access systems

[edit]

Conditional access systems include:

Analog systems

[edit]

Digital systems

[edit]
CA IDNameDeveloped byIntroduced (year)SecurityNotes
0x4AEBAbel QuinticAbel DRM Systems2009Secure
0x4A64, 0x4AF0, 0x4AF2, 0x4B4B, 0x4B4CABV CASABV International Pte. Ltd2006Secure (Farncombe Certified)CA, DRM, Middleware & Turnkey Solution Provider For DTH, DVBT/T2, DVBC, OTT, IPTV, VOD, Catchup TV, Audience Measurement System, EAD etc.
0x4AFCPanaccessPanaccess Systems GmbH2010Secure (Farncombe Certified)CA for DVB-S/S2, DVB-T/T2, DVB-C, DVB-IP, OTT, VOD, Catchup etc.
0x4B19RCAS or RIDSYS casRIDSYS, INDIA2012SecureCA for DVB-C, IPTV, OTT, VOD, Catchup etc.
0x4B30, 0x4B31ViCASVietnam Multimedia Corporation (VTC)UnknownSecure (Farncombe Certified)
0x4800AccessgateTelemannUnknown
0x4A20AlphaCryptAlphaCryptUnknown
N/AB-CAS ARIB STD-B25 (Multi-2)Association of Radio Industries and Businesses (ARIB)2000CA for ISDB. Used in Japan only
0x1702, 0x1722, 0x1762reserved for various non-BetaResearch CA systemsFormally owned by BetaTechnik/Beta Research (subsidiary of KirchMedia). Handed over to TV operators to handle with their CA systems.Unknown
0x1700 – 0x1701, 0x1703 – 0x1721, 0x1723 – 0x1761, 0x1763 – 0x17ff, 0x5601 – 0x5604VCAS DVBVerimatrix Inc.2010
0x2600

0x2610

BISS

BISS-E

European Broadcasting Union2002

2018

Compromised, BISS-E secure
0x27A0-0x27A4ICAS (Indian CAS)ByDesign India Private Limited2015Advanced Embedded Secure
0x4900China CryptCrytoWorks (China) (Irdeto)Unknown
0x22F0CodicryptScopus Network Technologies (now part of Harmonic)UnknownSecure
0x4AEACryptoguardCryptoguard AB2008Secure
0x0B00Conax ContegoConax ASUnknownSecure
0x0B00Conax CAS 5Conax ASUnknownCompromisedPirate cards has existed
0x0B00Conax CAS 7.5Conax ASUnknownSecure
0x0B00, 0x0B01, 0x0B02, 0x0BAAConax CAS 7Conax ASUnknownCompromisedCardsharing
0x0B01, 0x0B02, 0x0B03, 0x0B04, 0x0B05, 0x0B06, 0x0B07Conax CAS 3Conax ASUnknownCompromisedPirate cards has existed
0x4AE4CoreCryptCoreTrust(Korea)2000S/W & H/W SecurityCA for IPTV, Satellite, Cable TV and Mobile TV
0x4347CryptOnCryptOnUnknown
0x0D00, 0x0D02, 0x0D03, 0x0D05, 0x0D07, 0x0D20CryptoworksPhilips CryptoTecUnknownPartly compromised (older smartcards)
0x4ABFCTI-CASBeijing Compunicate Technology Inc.Unknown
0x0700DigiCipher and DigiCipher IIJerrold/GI/Motorola 4DTV1997CompromisedDVB-S2 compatible, used for retail BUD dish service and for commercial operations as source programming for cable operators.

Despite the Programming Center shutting down its consumer usage of DigiCipher 2 (as 4DTV) on August 24, 2016, it is still being used for cable headends across the United States, as well as on Shaw Direct in Canada.

0x4A70DreamCryptDream Multimedia2004Proposed conditional access system used for Dreambox receivers.
0x4A10EasyCasEasycasUnknown
0x2719,0xEAD0InCrypt CasS-Curious Research & Technology Pvt. Ltd., Equality Consultancy ServicesUnknown
0x0464EuroDecEurodecUnknown
0x5448,0x6448Gospell VisionCryptGOSPELL DIGITAL TECHNOLOGY CO., LTD.UnknownSecure
0x5501GriffinNucleus Systems, Ltd.Unknown
0x5581BulcryptBulcrypt2009Used in Bulgaria and Serbia
0x0606Irdeto 1Irdeto1995Compromised (Cardsharing and MOSC available)
0x0602, 0x0604, 0x0606, 0x0608, 0x0622, 0x0626, 0x0664, 0x0614Irdeto 2Irdeto2000
0x0624, 0x0648, 0x0650, 0x0639Irdeto 3Irdeto2010Compromised (Cardsharing available)
0x0692, 0x06A4, 0x06B6, 0x069F, 0x06AB, 0x06F1Irdeto CloakedIrdetoUnknownSecure
0x4AA1KeyFlySIDSA2006Partly compromised (v. 1.0)
0x0100SecaMediaguard 1SECA1995Compromised
0x0100SecaMediaguard 2 (v1+)SECA2002Partly compromised (MOSC available)
0x0100SecaMediaguard 3SECA2008
0x1800, 0x1801, 0x1810, 0x1830NagravisionNagravision2003Compromised
0x1801Nagravision CarmageddonNagravisionUnknownCombination of Nagravision with BetaCrypt
0x1702, 0x1722, 0x1762, 0x1801Nagravision AladinNagravisionUnknown
0x1801Nagravision 3 - MerlinNagravision2007Secure
0x1801Nagravision - ELKNagravisionCirca 2008IPTV
0x4A02TongfangTsinghua Tongfang Company2007Secure
0x4AD4OmniCryptWidevine Technologies2004
0x0E00PowerVuScientific Atlanta1998CompromisedProfessional system widely used by cable operators for source programming
0x0E00PowerVu+Scientific Atlanta2009
0x1000RAS (Remote Authorisation System)Tandberg TelevisionUnknownProfessional system, not intended for consumers.
0x4AC1Latens SystemsLatens2002
0xA101RosCrypt-MNIIR2006
0x4A60, 0x4A61, 0x4A63SkyCrypt/Neotioncrypt/Neotion SHLAtSky/Neotion[3]2003
UnknownT-cryptTecsysUnknown
0x4A80ThalesCryptThales Broadcast & Multimedia[4]UnknownViaccess modification. Was developed after TPS-Crypt was compromised.[5]
0x0500TPS-CryptFrance TelecomUnknownCompromisedViaccess modification used with Viaccess 2.3
0x0500Viaccess PC2.3, or Viaccess 1France Telecom1996
0x0500Viaccess PC2.4, or Viaccess 2France Telecom2002
0x0500Viaccess PC2.5, or Viaccess 2France Telecom2003
0x0500Viaccess PC2.6, or Viaccess 3France Telecom2005
0x0500Viaccess PC3.0France Telecom2007
0x0500Viaccess PC4.0France Telecom2008
UnknownViaccess PC5.0France Telecom2011Secure
UnknownViaccess PC6.0France Telecom2015
0x0930, 0x0942SynamediaVideoGuard 1NDS (now part of Synamedia)1994Partly compromised (older smartcards)
0x0911, 0x0960SynamediaVideoGuard 2NDS (now part of Synamedia)1999Secure
0x0919, 0x0961, 0x09AC, 0x09C4, 0x091F, 0x0944, 0x09AASynamediaVideoGuard 3NDS (now part of Synamedia)2004Secure
0x0927, 0x09BF, 0x0910, 0x0913, 0x098C, 0x098D, 0x098E, 0x0911, 0x0950, 0x09BB, 0x0987, 0x0963, 0x093B, 0x09CDSynamediaVideoGuard 4NDS (now part of Synamedia)2009Secure
0x56D0Onnet CA/DRMOnnet Systems India Pvt. Ltd.2021SecureCA/DRM, IPTV Middleware, OTT, Interactive Services, STB Middleware, AR/VR
0x4AD0, 0x4AD1X-CryptXCrypt Inc.2010Secure
0x4AE0, 0x4AE1, 0x7be1DRE-CryptCifra2004Secure
UnknownPHI CASRSCRYPTO2016Secure

See also

[edit]

References

[edit]
  1. ^"Security".DVB.Archived from the original on 2022-12-05. Retrieved2022-12-05.
  2. ^Conditional-access systems for digital broadcasting 2016-10Archived 2023-03-01 at theWayback Machine
  3. ^"Skycrypt". 2008-01-17.Archived from the original on 2022-11-26. Retrieved2008-08-28.
  4. ^"What means ThalesCrypt? - AfterDawn".www.afterdawn.com.Archived from the original on 2023-06-19. Retrieved2020-02-14.
  5. ^"TPSCrypt". 2008-01-17.Archived from the original on 2022-11-26. Retrieved2008-08-28.

External links

[edit]
Conditional access
DVB
Smart cards andencryption
Digital video disc
DRM
Data security
Analogue broadcast encoding
Retrieved from "https://en.wikipedia.org/w/index.php?title=Conditional_access&oldid=1286630621"
Categories:
Hidden categories:

[8]ページ先頭

©2009-2026 Movatter.jp