hsy75的个人空间 https://blog.eetop.cn/vivilife [收藏] [复制] [分享] [RSS]

空间首页 动态 记录 日志 相册 主题 分享 留言板 个人资料

日志

NDS CA 系统初探

已有 9415 次阅读| 2008-8-27 16:00 |个人分类:STB Research

NDS 作为首个被中央电视台数字电视引进的广播网络安全解决方案商,在中国已经有了一定的市场,此次,项目就是要用到NDS CA system ,这里列举了网上查到一些资料

1. The Hathway Partners With NDS (News Datacom Security) (这里是一个NDS广播合作商Hathway 对NDS的一个小结)
Hathway has selected NDS, a world leader of open end-to-end digital pay TV services for a secure system of deployment of digital and pay TV Conditional Access system. There are three main areas:

NDS systems.
Systems integration.
Interactive TV applications.
 
 1.1 NDS Systems
Hathway has selected NDS to provide NDS end-to-end systems, including StreamServer, VideoGuard conditional access and NDS Core middleware. These systems are integral to protecting digital broadcasting signals and pay-TV revenue, and to enabling interactive TV functionality.(NDS显然提供的是一个系统级别的点到点加密服务)

VideoGuard?? is the world's leading conditional access system because it is the most secure solution.
Hathway will benefit from the security and flexibility of VideoGuard. Deployed in over 30 million homes worldwide,
 

  •  NDS smart cards use custom-designed chips and include unique security algorithms for each customer. A central element of NDS security is its use of proprietary one-way algorithms (一个可以分析需要多少服务密匙的算法)that eliminate the need for service keys.
  •  Algorithm-based (hsy75案: Not a Key base,这个后面会说明)conditional access ensures maximum security and bandwidth efficiency. NDS systems are not key based, as they are inherently insecure in broadcast environments. Key based systems have to broadcast the control word.
  • Entitlement information (EMM,ECM)is securely delivered to subscribers in digitally signed packets.
  • Full integration with the EPG gives subscribers seamless navigation for purchasing, booking and viewing PPV content.
  • A secure return path ensures the privacy and integrity of data transferred between viewers and the headend.(交互有利)
  • Copy protection mechanisms and fingerprinting features help prevent illegal redistribution of content.
  • NDS ensures that your business remains secure with extensive operational security activities. NDS knows that you can not just rely on the technical aspects of security to protect your system. This must be supported by proactive security measures.
 1.2  NDS Core middleware
    NDS Core is the fully-featured middleware that helps network operators deploy cost-effective set-top boxes quickly and easily. For operators looking to minimize costs, NDS Core offers the ideal way to set up digital TV services without compromising on functionality or the platform's evolutionary path.
    Deployed in over 2.8 million homes worldwide, NDS Core closely integrates with other NDS solutions to maximize performance, support all conditional access functions and provide a launching pad to other interactive applications.

NDS Core Technical Features

    * Small set-top box memory footprint
    * Interactive delivery using DVB DSM-CC
    * Industry standard HTML presentation engine and Java support
    * Supports multiple languages
    * Rich graphics capabilities for On Screen display and dynamic video scaling.

 1.3 NDS Systems Integration

NDS was also selected to act as systems integrator and technology provider for Hathway's digital network upgrade. In this capacity, NDS is overseeing the integration of the Humax set-top box, Barco compression and Miindport subscriber management system.

Integrating these systems from NDS and other third party vendors for the Hathway network is quite a complex task. Deploying an end-to-end digital pay TV system requires a considerable investment as well as expert knowledge about the many components that make up the system. These include compression, scheduling, set-top boxes, middleware and, of course, conditional access.

NDS has helped operators worldwide to successfully deploy digital pay TV services than anyone else. Their customers have come to rely on the experience and expertise offered by their Professional Services team, from planning through deployment and service launch.

NDS has the experience and the delivery team is on site at the Hathway operations now. In addition, NDS integration facilities in the UK and Seoul are working with the set-top box vendor to test the set-top boxes sent to India , which has saved substantial time for Hathway.

NDS supports the use of open standard interfaces and implements these in its headend systems and components. This results in a significant benefit for Hathway, because it can select from a wide variety of solutions and systems components not supplied by NDS. This will enable Hathway to choose the best technical and operational solutions for their overall requirements.
 
 Interactive TV Apllication

The first interactive TV service to be deployed on the Hathway network is an electronic program guide designed by NDS. An EPG is the window through which viewers access this content while Hathway can also use it to promote revenue generating services.
As a pioneer in EPG development, NDS fully integrates the program guide with VideoGuard?? conditional access, NDS Core middleware and other NDS systems to provide a consistent, logical subscriber interface for viewing schedules and up to date programming information.

爱迪德CA系统与NDS CA系统对比分析(一)
两 个典型CA系统,前者是基于密钥(Key-based)CA系统,后者是基于算法(Algorithm-based)CA系统。
在这里,从终端(Client)即客户端方面先谈起,也就是说从机 顶盒集成这两个主流CA的技术方面进行对比分析。 

列举两大主流CA的典型CA厂商,不用说大家都知道,一个是在国内发展势头迅猛,国内市场占有量目前第一的荷兰爱迪德(Irdeto)公司,其采用的是基 于密钥加密的条件接收技术;另外一个就是全球市场老大,英国新闻集团旗下的NDS公司,其采用的是基于算法加密的条件接收技术。虽然这两家的定位不是在一 个层次上(NDS比Irdeto高端),但作为技术研究点来说,我们关心的不是其市场份额,而是这两家的主流CA技术。我们首先从机顶盒集成CA方面说 起。

1. 芯片组相对于NDS CA集成,Irdeto的CA集成的门槛要低得多。也许这就是决定两者市场定位的主要因素之一。Irdeto对于芯片组的要求不高,相信做过其CA的朋友 们都知道,只要芯片组支持基本的流解复用和解扰,以及支持Smart Card解密技术即可。而现在的芯片都支持这些功能,所以现有市面上的解码芯片在技术理论上均能集成Irdeto CA功能,不论是32位机、16位机还是8位机。对于Irdeto来说,要做的仅是在这些不同的平台不同的编译环境下build适合这些平台使用的lib 库即可,剩余的所有工作均由机顶盒厂商来做。反之对于机顶盒厂商来说,他们对于方案选择的余地比较大,需要考虑的仅是方案的成本哪个更低,带来的利润哪个 更丰厚,性价比哪个更好。 NDS对于芯片组的要求比较高,不仅要求芯片的主频需要达到一定的速度,而且还要嵌入ICAM硬件技术。所谓ICAM即为Integrated Conditional Access Module集成条件接收模块,它的主要功能是实现EMM、ECM等私有数据的过滤以及对码流的解扰。这么做的主要原因就是基于安全的考虑,防止黑客恶意 破解。
【hsy75案,确切的说这条是不对的,NDS也提供不含ICAM的解决方案】
现在能够提供该项功能芯片组的公司主要有ST、Fujitsu、Broadcom和NEC等。在国内已经集成了NDS CA技术的机顶盒采用的芯片方案主要是ST和Fujitsu。由此比较可知,机顶盒厂商选择芯片的自由度还是做Irdeto CA集成的要大。这也是为什么Irdeto在国内市场扩张比较块的原因之一。

2. 成本这里说的成本仅是CA集成需要的付费成本。不用说大家都知道,Irdeto的CA集成付费要低得多,这也是市场定位的战略之一。




点赞

评论 (0 个评论)

facelist

您需要登录后才可以评论 登录 | 注册

  • 关注TA
  • 加好友
  • 联系TA
  • 0

    周排名
  • 0

    月排名
  • 0

    总排名
  • 0

    关注
  • 2

    粉丝
  • 1

    好友
  • 2

    获赞
  • 14

    评论
  • 3241

    访问数
关闭

站长推荐 上一条 /1 下一条

小黑屋| 关于我们| 联系我们| 在线咨询| 隐私声明| EETOP 创芯网
( 京ICP备:10050787号 京公网安备:11010502037710 )

GMT+8, 2024-4-25 19:36 , Processed in 0.018959 second(s), 7 queries , Gzip On, Redis On.

eetop公众号 创芯大讲堂 创芯人才网
返回顶部