Sign In to Follow Application
View All Documents & Correspondence

Signature Validation Information Transmission Method Information Processing Device Information Processing Method And Broadcast Transmission Device

Abstract: To improve the quality of services which utilize an application capable of processing broadcast data and an application information table for managing operations of the application. [Solution] Validation information for validating an electronic signature attached either to an application capable of processing broadcast first data or to an application information table for managing operations of the application is transmitted by means of a data carousel method said application and application information table being transmitted over a network to an information processing device.

Get Free WhatsApp Updates!
Notices, Deadlines & Correspondence

Patent Information

Application #
Filing Date
03 February 2015
Publication Number
01/2016
Publication Type
INA
Invention Field
COMMUNICATION
Status
Email
ipo@knspartners.com
Parent Application

Applicants

SONY CORPORATION
1 7 1 Konan Minato ku Tokyo 1080075

Inventors

1. KITAHARA Jun
c/o SONY CORPORATION1 7 1 Konan Minato ku Tokyo 1080075
2. KITAZATO Naohisa
c/o SONY CORPORATION1 7 1 Konan Minato ku Tokyo 1080075

Specification

FORM 2
THE PATENTS ACT, 1970
(39 of 1970)
&
THE PATENTS RULES, 2003
COMPLETE SPECIFICATION
(See section 10, rule 13)
“SIGNATURE VALIDATION INFORMATION
TRANSMISSION METHOD, INFORMATION
PROCESSING DEVICE, INFORMATION PROCESSING
METHOD, AND BROADCAST TRANSMISSION
DEVICE”
SONY CORPORATION, of 1-7-1, Konan, Minato-ku, Tokyo
108-0075, Japan
The following specification particularly describes the invention and the manner in
which it is to be performed.
2
DESCRIPTION
SIGNATURE VALIDATION INFORMATION TRANSMISSION METHOD,
INFORMATION PROCESSING APPARATUS, INFORMATION
PROCESSING METHOD, AND BROADCAST DELIVERY APPARATUS
5
Technical Field
[0001] The present technique relates to a signature
validation information transmission method, an
information processing apparatus, an information
10 processing method, and a broadcast delivery apparatus.
Background Art
[0002] In recent years, a technique that enables an
application delivered via a network such as the
Internet to be executed simultaneous with a
15 reproduction of a broadcast content has been known. As
such a technique, a technique called hybrid broadcast
broadband TV (hereinafter, referred to as “HbbTV”) is
known. As a standard of HbbTV, “ETSI TS 102 796” (see
Non Patent Document 1) has been developed in Europe.
20 Further, the standard “ARIB STD-B23” (see Non Patent
Document 2) conforming thereto has been developed also
in our country.
[0003] For example, in a system in which an
application is executed simultaneous with a
25 reproduction of a broadcast content as in HbbTV, a life
cycle of an application from an activation to an end is
3
managed by a data structure called AIT (Application
Information Table) section superimposed on a broadcast
content. An information terminal that has acquired the
AIT section controls the application based on an
application control code included in 5 the AIT section.
[0004] Moreover, there is an XML-AIT described in an
XML format as a format optimal for providing
information related to an application to a receiver
using a communication network such as the Internet, the
10 XML-AIT including information equivalent to a broadcast
AIT section.
[0005] Non Patent Document 1: ETSI (European
Telecommunications Standards Institute) “ETSI TS 102
796 V1.1.1 (2010-06)”
15 http://www.etsi.org/deliver/etsi_ts/102700_102799/10279
6/01.01.01_60/ts_102796v010101p.pdf (browsed on October
21, 2011)
Non Patent Document 2: Association of Radio
Industries and Businesses “Application execution
20 environment standard ARIB STD-B23 1.2 in digital
broadcast”
http://www.arib.or.jp/english/html/overview/doc/2-STDB23v1_
2.pdf (browsed on October 21, 2011)
Summary of Invention
25 Problem to be solved by the Invention
[0006] In the future, a service that provides an
4
application not directly related to broadcast
(broadcast-unlinked application) in addition to an
application executed in link with a broadcast program
of digital terrestrial broadcast or the like
(broadcast-linked application) 5 is expected to be
started. However, in actually operating a service that
uses a broadcast-unlinked application, there are still
various problems to be solved, and countermeasures are
desired.
10 [0007] It is an object of the present technology to
provide a signature validation information transmission
method, an information processing apparatus, an
information processing method, and a broadcast delivery
apparatus with which a quality of a service that uses
15 and an application capable of processing broadcast data
and an application information table that manages an
operation of the application can be improved.
Means for solving the Problem
[0008] To solve the problems described above, a
20 signature validation information transmission method
according to the present technology includes
transmitting, by a data carousel method, validation
information for validating an electronic signature
attached to either one of an application capable of
25 processing first data to be broadcasted and an
application information table that manages an operation
5
of the application, which are transmitted to an
information processing apparatus via a network.
[0009] In the signature validation information
transmission method, the validation information may be
placed in component_tag = 0x40 5 as a module, and
information for causing the information processing
apparatus to detect update of the transmitted
validation information may be placed in DII.
[0010] In the signature validation information
10 transmission method, the validation information may be
stored in a route certificate descriptor and
transmitted.
[0011] In the signature validation information
transmission method, a value indicating transmission of
15 the validation information may be stored as a value of
root_certificate_type in the route certificate
descriptor.
[0012] In the signature validation information
transmission method, the validation information may be
20 stored in a predetermined storage area of storage
areas, to which a public key certificate for data
broadcast can be transmitted, in the route certificate
descriptor, and flag information indicating that the
validation information is transmitted may be placed in
25 the route certificate descriptor.
[0013] An information processing apparatus based on
6
another viewpoint of the present technology includes:
an acquisition unit that acquires an application
capable of processing first data to be broadcasted and
an application information table that manages an
operation of the application via 5 a network; and a
controller that acquires validation data that is used
for validating an electronic signature attached to
either one of the acquired application and application
information table and transmitted by a data carousel,
10 and validates the electronic signature.
[0014] An information processing method based on
another viewpoint of the present technology includes:
acquiring, by an acquisition unit, an application
capable of processing first data to be broadcasted and
15 an application information table that manages an
operation of the application via a network; and
acquiring, by a controller, validation data that is
used for validating an electronic signature attached to
either one of the acquired application and application
20 information table and transmitted by a data carousel,
and validating the electronic signature.
[0015] A broadcast delivery apparatus based on
another viewpoint of the present technology includes a
transmission unit that transmits, by a data carousel
25 method, validation information for validating an
electronic signature attached to either one of an
7
application capable of processing first data to be
broadcasted and an application information table that
manages an operation of the application, which are
transmitted to an information processing apparatus via
5 a network.
Effect of the Invention
[0016] As described above, according to the present
technology, a quality of a service that uses an
application capable of processing broadcast data and an
10 application information table that manages an operation
of the application can be improved.
Brief Description of Drawings
[0017] [Fig. 1] A diagram showing a general outline
of an information processing system of this embodiment.
15 [Fig. 2] A diagram showing a data structure
of an XML-AIT of this embodiment.
[Fig. 3] A diagram showing an example of an
XML schema defining a logical structure of an
application identification descriptor.
20 [Fig. 4] A diagram showing an example of the
XML schema defining the logical structure of the
application identification descriptor.
[Fig. 5] A diagram showing a specific
example of the application identification descriptor
25 created using the XML schemas shown in Figs. 3 and 4.
[Fig. 6] A diagram showing definitions of
8
application control codes stored in the XML-AIT.
[Fig. 7] A block diagram showing a structure
of an information processing apparatus in the system of
Fig. 1.
[Fig. 8] A sequence diagram 5 showing a flow
of exchanges among a broadcast station, an application
server, an XML-AIT server, and the information
processing apparatus in the system of Fig. 1.
[Fig. 9] A flowchart showing a processing
10 procedure of the information processing apparatus in
the system of Fig. 1.
[Fig. 10] A flowchart showing an operation of
a case where a direct tuning operation occurs in the
information processing apparatus of this embodiment.
15 [Fig. 11] A flowchart showing an operation of
a case where a shift of a broadcast linked application
occurs in the information processing apparatus of this
embodiment.
[Fig. 12] A block diagram for explaining a
20 mechanism of the generation and validation of an
electronic signature.
[Fig. 13] A conceptual diagram of a dedicated
module method of transmitting a broadcast station
public key certificate from the broadcast station to
25 the information processing apparatus.
[Fig. 14] A diagram showing a structure of a
9
broadcast station public key certificate descriptor.
[Fig. 15] A flowchart regarding the
acquisition and update of the broadcast station public
key certificate according to a dedicated module method.
[Fig. 16] A diagram showing 5 a structure of a
route certificate descriptor according to a data
broadcast extension method (Part I).
[Fig. 17] A flowchart regarding the
acquisition and update of the broadcast station public
10 key certificate according to the data broadcast
extension method (Part I).
[Fig. 18] A diagram showing a structure of a
route certificate descriptor according to a data
broadcast extension method (Part II).
15 [Fig. 19] A flowchart regarding the
acquisition and update of the broadcast station public
key certificate according to the data broadcast
extension method (Part II).
[Fig. 20] A diagram showing a conceptual
20 structure of an XML-AIT of a second embodiment of the
present technology.
[Fig. 21] A sequence diagram showing a flow
of exchanges among a broadcast station, an application
server, and an XML-AIT server, and an information
25 processing apparatus in an information processing
system of the second embodiment.
10
[Fig. 22] A flowchart showing a processing
procedure of the information processing apparatus of
the second embodiment.
[Fig. 23] A diagram for explaining a
mechanism of the generation of an electronic 5 signature
and a hash value and validation of them in the second
embodiment.
Mode(s) for Carrying Out the Invention
[0018] Hereinafter, embodiments of the present
10 technology will be described with reference to the
drawings.

[Information Processing System]
Fig. 1 is a diagram showing a general outline of
15 an information processing system of this embodiment.
The information processing system 1 of this
embodiment includes a broadcast station 100, a first
network 200 such as the Internet, an application server
300, an XML-AIT server 400, an edge router 500, a
20 second network 600 such as a LAN (Local Area Network),
and an information processing apparatus 700 as a
broadcast receiver.
[0019] The broadcast station 100 transmits digital
broadcast signals via a communication medium such as
25 terrestrial, satellite, and IP (Internet Protocol)
networks. The broadcast station 100 transmits a so11
called broadcast stream obtained by superimposing an AV
stream in which transport streams of a video, audio,
subtitle, and the like are multiplexed, data
accompanying the AV stream, and the like. The data
accompanying the AV stream includes, 5 for example, a
markup language such as HTML and BML.
[0020] The application server 300 is connectable to
the first network 200 and provides a broadcast-unlinked
application not directly related to the broadcast to
10 the information processing apparatus 700 via the first
network 200. The broadcast-unlinked application is an
application created by those other than the creator of
a broadcast resource, and while processing of acquiring
various types of broadcast resources of a video, audio,
15 subtitle, SI information, data broadcast, and the like
from the broadcast and presenting them, for example,
can be carried out, it is desirable to require a
certain authentication on whether the broadcast
resource can actually be accessed.
20 [0021] The XML-AIT server 400 is connectable to the
first network 200 and delivers an XML-AIT (Extensible
Markup Language-Application Information Table) for
managing a broadcast-unlinked application provided from
the application server 300 to the information
25 processing apparatus 700 via the first network 200.
[0022] It should be noted that the application
12
server 300 and the XML-AIT server 400 may be
constituted as a single server. The application server
300 and the XML-AIT server 400 each include a CPU, a
main memory, a data storage unit, a user interface, and
the like and have a typical computer 5 structure.
[0023] The edge router 500 is a router for
connecting the first network 200 and the second network
600. The second network 600 may either be in a wired or
wireless manner.
10 [0024] The information processing apparatus 700 is,
for example, a personal computer, a cellular phone, a
smartphone, a television apparatus, a game device, a
tablet terminal, and an audio/video reproduction
apparatus, though a product form thereof is not
15 specifically limited.
[0025] The information processing apparatus 700
receives digital broadcast signals from the broadcast
station 100 and demodulates the signals to acquire a
transport stream. The information processing apparatus
20 700 is capable of separating a broadcast stream from
the transport stream, decoding it, and outputting it to
a display unit (not shown) and speaker unit (not shown)
connected to the information processing apparatus 700
or a recording apparatus (not shown).
25 [0026] It should be noted that the display unit, the
speaker unit, and the recording apparatus may be
13
integrated with the information processing apparatus
700, or they may be directly connected or indirectly
connected to the information processing apparatus 700
via the second network 600 as independent apparatuses.
Alternatively, an apparatus (not shown) 5 including the
display unit and the speaker unit may be directly
connected or indirectly connected to the information
processing apparatus 700 via the second network 600.
[0027] The information processing apparatus 700 is
10 capable of acquiring an XML-AIT file from the XML-AIT
server 400, interpreting it, acquiring a broadcastunlinked
application from the application server 300,
and performing activation control and the like.
[0028] [Broadcast-Unlinked Application]
15 Here, a complementary explanation will be given on
the broadcast-unlinked application. The broadcastunlinked
application is provided to the information
processing apparatus 700 from the application server
300. The broadcast-unlinked application is constituted
20 of, for example, an HTML (Hyper Text Markup Language)
document, a BML (Broadcast Markup Language) document,
an MHEG (Multimedia and Hypermedia information coding)
document, a Java (registered trademark) script, a still
image file, and a moving image file.
25 [0029] Attached to the broadcast-unlinked
application is an electronic signature for detecting a
14
falsification. An XML signature is used as the
electronic signature, for example. The format of the
XML signature may be any of a detached signature
independent from a substance of the broadcast-unlinked
application, an enveloping signature 5 having a format
including the substance of the broadcast-unlinked
application, and an enveloped signature in a format
included in the substance of the broadcast-unlinked
application.
10 [0030] An application controller 708 of the
information processing apparatus 700 validates the XML
signature according to a procedure for a core
validation (Core-Validation) including a reference
validation (Reference-Validation) and a signature
15 validation (Signature-Validation).
The reference validation is a method of validating
a reference (Reference) digest value (DigestValue) by
applying a normalization transformation process
(Transform) and a digest calculation algorithm
20 (DigestMethod) to a resource (substance of broadcastunlinked
application). A result obtained by the
reference validation and the registered digest value
(DigestValue) are compared, and when the values do not
match, the validation becomes a failure.
25 The signature validation is a method of
serializing signature information (SignatureInfo)
15
elements by a normalization method designated by an XML
normalization algorithm (CanonicalizationMethod),
acquiring key data using key information (KeyInfo) and
the like, and validating a signature using a method
designated by a signature algorithm (5 SignatureMethod).
[0031] In order to attach the electronic signature
to the broadcast-unlinked application, an application
creator requests the broadcast station 100 to
authenticate a pair of the broadcast-unlinked
10 application and the XML-AIT. The broadcast station 100
carefully checks a content of the broadcast-unlinked
application and the XML-AIT and when there is no
problem in the content, sends the broadcast-unlinked
application to which the electronic signature is
15 attached to the application creator as a response.
Further, the broadcast station 100 transmits a
broadcast station public key certificate including a
public key necessary for validating the electronic
signature by a data carousel corresponding to a
20 broadcast channel or an event (program) accessed by the
broadcast-unlinked application.
[0032] [Data Structure of XML-AIT]
Next, a data structure of the XML-AIT will be
described.
25 Fig. 2 is a diagram showing the data structure of
the XML-AIT of this embodiment.
16
The XML-AIT stores, for each application, an
application name, an application identifier, an
application descriptor, an application type, an
application control code 21, an application visibility,
a flag indicating whether an application 5 is effective
in only the current service, an application priority,
an application version, a version according to platform
profile, an icon, storage function performance, a
transport protocol descriptor, an application location
10 descriptor, an application boundary descriptor, an
application specific descriptor, an application usage
descriptor, an application mode descriptor, an
application identification descriptor 23, and the like.
[0033] [Details of Application Identification
15 Descriptor 23]
Next, details of the application identification
descriptor 23 will be described.
As the application identification descriptor 23,
the following is included.
20 1. Information defining a broadcast unit
accessible by a broadcast-unlinked application, such as
a broadcast station affiliation, a broadcast station, a
channel, and an event (program) (third definition
information)
25 2. Information defining a type of media
information (video, audio, SI information, subtitle,
17
data broadcast, etc.) constituting a broadcast resource
that can be used by a broadcast-unlinked application
(hereinafter, referred to as "access permission
information") (first definition information)
3. Information that limits 5 an operation of a
broadcast-unlinked application using a broadcast
resource (hereinafter, referred to as "rendering
permission information") (second definition
information)
10 The access permission information and the
rendering permission information are collectively
referred to as "resource permission information".
[0034] Figs. 3 and 4 are diagrams each showing an
example of the XML schema defining a logical structure
15 of the application identification descriptor 23
(ApplicationIdDescriptor).
[0035] In the XML schema, an ApplicationIdDescriptor
element is declared as the complexType element.
Subservient to the sequence element as a sub20
element of the ApplicationIdDescriptor element, a
grant_application_access_flag element, an affiliation
element, a terrestrial_broadcaster element, a
broadcaster element, and an event element are declared.
[0036] The ApplicationIdDescriptor element is an
25 element that stores an acceptance application access
flag. The acceptance application access flag takes a
18
value of either "0" or "1". When the acceptance
application access flag is "0", a content described in
the application identification descriptor 23 is
interpreted as a condition for prohibiting a
simultaneous presentation with 5 an application
(blacklist). When the acceptance application access
flag is "1", the content described in the application
identification descriptor 23 is interpreted as a
condition for permitting the simultaneous presentation
10 with an application (whitelist).
[0037] The affiliation element includes, subservient
thereto, an element that declares a name and form of an
affiliation_name element storing a name of the
broadcast affiliation station, an element that declares
15 a name and form of an attribute storing an identifier
(id) of the broadcast affiliation station, and an
element that indicates, as a reference destination,
another element defining a structure of resource
permission information (resouce_permission) of the
20 broadcast affiliation station.
[0038] The terrestrial_broadcaster element includes,
subservient thereto, an element that declares a name
and form of a terrestrial_broadcaster_name element
storing a name of a digital terrestrial broadcast
25 station, an element that declares a name and form of an
attribute storing an identifier (id) of the digital
19
terrestrial broadcast station, and an element that
indicates, as a reference destination, another element
defining a structure of the resource permission
information (resouce_permission) of the digital
terrestrial broadcast 5 station.
[0039] The broadcaster element includes, subservient
thereto, an element that declares a name and form of a
broadcaster_name element storing a name of the BS/CS
broadcast station, an element that declares a name and
10 form of an attribute storing an identifier (id) of the
BS/CS broadcast station, and an element that indicates,
as a reference destination, another element defining a
structure of the resource permission information
(resouce_permission) of the BS/CS broadcast station.
15 [0040] The event element includes, subservient
thereto, an element that indicates, as a reference
destination, another element defining a structure of
information for designating an event
(attributeGroup_name element).
20 [0041] The attributeGroup_name element includes,
subservient thereto, an element that declares a name
and form of an event_name element storing a name of an
event, an element that defines a name and form of a
network_id attribute storing a network ID, an element
25 that defines a name and form of a transport_stream_id
attribute storing a transport stream ID, an element
20
that defines a name and form of a service_id attribute
storing a service ID, an element that defines a name
and form of an event_id attribute storing an event ID,
and an element that indicates, as a reference
destination, another element declaring 5 a structure of
the resource permission information
(resouce_permission) of the event.
Here, the network_id attribute, the
transport_stream_id attribute, and the service_id
10 attribute are information for identifying a channel.
Further, the value of the attribute defining the
name and form of the event_id attribute does not need
to be described. When there is no description, only the
channel has been designated.
15 [0042] In the XML schema, as another complexType
element, a resouce_permission element is declared. The
resouce_permission element includes, subservient
thereto, an element that defines a name and form of an
access_permision element storing the access permission
20 information, an element that defines a name and form of
a rendering_permission element storing the rendering
permission information, and an element that declares a
name and form of an attribute storing an identifier
(id) of the resource permission information
25 (resouce_permission).
[0043] Fig. 5 is a diagram showing a specific
21
example of the application identification descriptor 23
created using the XML schemas shown in Figs. 3 and 4.
The specific example of the application
identification descriptor 23 shows a case where the
resource permission information 5 is designated as a
whitelist with respect to the broadcast unit of the
broadcast affiliation station and the BS/CS broadcast
station.
[0044] Specifically, with respect to a broadcast
10 affiliation station whose acceptance application access
flag is "1", identifier is "00000001", and name is
"affiliation_A", the resource permission information
(resouce_permission) whose identifier is "01", value of
the access permission information (access_permission)
15 is "10", and value of the rendering permission
information (rendering_permission) is "20" is
designated. Moreover, with respect to a BS/CS broadcast
station whose identifier is "00000002" and name is
"broadcaster_B", the resource permission information
20 (resouce_permission) whose identifier is "02", value of
the access permission information (access_permission)
is "30", and value of the rendering permission
information (rendering_permission) is "40" is
designated.
25 The meanings allocated to the value of the access
permission information (access_permission) and the
22
value of the rendering permission information
(rendering_permission) are determined arbitrarily in a
service.
[0045] [Definitions of Application Control Codes]
A life cycle of an application 5 is dynamically
controlled by the information processing apparatus 700
based on the application control code 21 stored in the
XML-AIT.
[0046] Fig. 6 is a diagram showing definitions of
10 the application control codes 21 stored in the XML-AIT.
As shown in the figure, as the application control
codes, there are "AUTOSTART", "PRESENT", "DESTROY",
"KILL", "PREFETCH", "REMOTE", "DISABLED", and
"PLAYBACK_AUTOSTART" as the standard. The definitions
15 of the application control codes are as follows.
[0047] "AUTOSTART" is a code that instructs to
automatically activate an application along with a
service selection, provided that the application is not
yet executed.
20 "PRESENT" is a code that instructs to set an
application to an executable state while the service is
being selected. It should be noted that a target
application is not automatically activated along with
the service selection and is activated upon reception
25 of an activation instruction from the user.
"DESTROY" is a code that instructs to permit an
23
end of an application.
"KILL" is a code that instructs to forcibly end an
application.
"PREFETCH" is a code that instructs to cache an
5 application.
"REMOTE" is a code indicating that an application
is an application that cannot be acquired in a current
transport stream. Such an application becomes usable
when acquired from another transport stream or a cache.
10 "DISABLED" is a code indicating that an
application activation is prohibited.
"PLAYBACK_AUTOSTART" is a code for activating an
application along with a reproduction of a broadcast
content recoded onto a storage (recording apparatus).
15 [0048] [Structure of Information Processing
Apparatus]
Fig. 7 is a block diagram showing a structure of
the information processing apparatus 700 of this
embodiment.
20 The information processing apparatus 700 includes
a broadcast interface 701, a demultiplexer 702, an
output processing unit 703, a video decoder 704, an
audio decoder 705, a subtitle decoder 706, a
communication interface 707 (acquisition unit), and an
25 application controller 708 (controller).
[0049] The broadcast interface 701 includes an
24
antenna and a tuner and uses them to receive digital
broadcast signals selected by the user. The broadcast
interface 701 outputs a transport stream acquired by
carrying out demodulation processing on the received
digital broadcast signals to the 5 demultiplexer 702.
[0050] The demultiplexer 702 separates a stream
packet of a broadcast content, an application packet,
and an AIT section packet from the transport stream.
The demultiplexer 702 separates a video ES (Elementary
10 Stream), an audio ES, and a subtitle ES from the stream
packet of the broadcast content. The demultiplexer 702
distributes the video ES to the video decoder 704, the
audio ES to the audio decoder 705, the subtitle ES to
the subtitle decoder 706, and the application packet
15 and a PSI/SI (Program Specific Information/Service
Information) packet including the AIT section to the
application controller 708.
[0051] The video decoder 704 decodes the video ES to
generate a video signal and outputs the generated video
20 signal to the output processing unit 703. The audio
decoder 705 decodes the audio ES to generate an audio
signal and outputs the generated audio signal to the
output processing unit 703.
The subtitle decoder 706 decodes the subtitle ES
25 to generate a subtitle signal and outputs the generated
subtitle signal to the output processing unit 703.
25
[0052] The broadcast interface 701, the
demultiplexer 702, the output processing unit 703, the
video decoder 704, the audio decoder 705, and the
subtitle decoder 706 constitute a broadcast processing
unit that receives and processes a 5 broadcast content.
[0053] The communication interface 707 is an
interface for establishing communication with an
external apparatus via the second network 600 such as a
LAN. The communication interface 707 may take either
10 wireless communication or wired communication.
[0054] The application controller 708 is a
controller that carries out processing related to
control of applications.
[0055] The output processing unit 703 synthesizes
15 the video signal from the video decoder 704, the audio
signal from the audio decoder 705, the subtitle signal
from the subtitle decoder 706, the video signal and
audio signal from the application controller 708, and
the like and outputs the resultant to the recording
20 apparatus (not shown), display unit, and speaker unit
(not shown) connected to the information processing
apparatus 700.
[0056] A part or all of the structure including at
least the application controller 708 of the information
25 processing apparatus 700 can be provided by a computer
including a CPU (Central Processing Unit) and a memory
26
and a program that causes the computer to function as
the broadcast processing unit, the application
controller 708, and the like.
[0057] [Operation of Information Processing System
5 1]
Next, an operation of the information processing
system 1 of this embodiment will be described.
[0058] (1. Control of Use of Broadcast Resource by
Broadcast-unlinked application)
10 Fig. 8 is a sequence diagram showing a flow of
exchanges among the broadcast station 100 (broadcast
deliver apparatus), the application server 300, the
XML-AIT server 400, and the information processing
apparatus 700. Fig. 9 is a flowchart showing a
15 processing procedure of the information processing
apparatus 700.
[0059] The information processing apparatus 700
displays an application launcher selected by the user
using a remote controller, for example (Step S101). The
20 application launcher is realized by, for example, a socalled
resident application mounted on the information
processing apparatus 700, HTML 5 (Hyper Text Markup
Language 5) presented by an HTML browser, or BML
(Broadcast Markup Language). The application launcher
25 displays a menu of a broadcast-unlinked application.
[0060] The user can select a broadcast-unlinked
27
application to be activated using a remote controller,
for example. In the menu of the broadcast-unlinked
application of the menu displayed in the application
launcher, a script for causing the information
processing apparatus 700 to acquire 5 an XML-AIT for a
broadcast-unlinked application or the like is
incorporated.
[0061] As an arbitrary broadcast-unlinked
application is selected by an operation of the user
10 using the remote controller on the menu of the
broadcast-unlinked application displayed in the
application launcher (Step S102), a script
corresponding to the broadcast-unlinked application is
executed, and thus the application controller 708 of
15 the information processing apparatus 700 acquires an
XML-AIT for the broadcast-unlinked application from the
XML-AIT server 400 (Step S103).
[0062] The application controller 708 of the
information processing apparatus 700 acquires an
20 electronic signature-attached broadcast-unlinked
application from the application server 300 based on
application location information described in the
acquired XML-AIT (Step S104) and immediately activates
the acquired broadcast-unlinked application (Step S105).
25 [0063] The application controller 708 monitors a
broadcast resource access request from the broadcast28
unlinked application (Step S106). When detecting the
access request of a broadcast resource from the
broadcast-unlinked application (Y in Step S107), the
application controller 708 checks whether or not the
broadcast station public key certificate 5 corresponding
the broadcast resource is stored in the memory of the
information processing apparatus 700 (Step S107).
[0064] If the broadcast station public key
certificate is not stored in the memory of the
10 information processing apparatus 700, the application
controller 708 of the information processing apparatus
700 waits for a target broadcast station public key
certificate to be transmitted by a data carousel. When
receiving the target broadcast station public key
15 certificate transmitted by the data carousel, the
application controller 708 stores it in the memory
(Step S108).
[0065] The application controller 708 validates the
electronic signature attached to the broadcast-unlinked
20 application being executed, using the broadcast station
public key certificate stored in the memory (Step S110).
When failing in the validation of the electronic
signature (N in Step S111), the application controller
708 makes a setting so that an access to all broadcast
25 resources by the broadcast-unlinked application is
prohibited (Step S112).
29
[0066] After setting the access prohibition or when
succeeding in the validation of the electronic
signature (Y in Step S111), the application controller
708 refers to access permission information
(access_permission) described 5 in the XML-AIT and
accesses the broadcast resource in a range permitted to
the broadcast-unlinked application (Step S113). At this
time, there is also a case where the access to all the
broadcast resources is not permitted. In this case, the
10 access to the broadcast resources is not carried out
and only the broadcast-unlinked application is
displayed.
[0067] For example, the application identification
descriptor 23 shown in Fig. 5 is acquired, and the
15 value "10" as the access permission information
(access_permission) means that all broadcast resources
can be used. Here, the expression "all broadcast
resources" refers to all types of media information to
be broadcasted (video, audio, SI information, subtitle,
20 data broadcast, etc.).
[0068] In this assumption, when a broadcast resource
for which an access has been requested by the executed
broadcast-unlinked application is a broadcast resource
from a broadcast station belonging to a broadcast
25 affiliation station "affiliation_A", it is judged that
the broadcast resource can be accessed by the
30
broadcast-unlinked application.
[0069] Further, when a broadcast resource for which
an access has been requested by the executed broadcastunlinked
application is a broadcast resource from a
broadcast station not belonging 5 to the broadcast
affiliation station "affiliation_A", and is a broadcast
resource from a broadcast station other than the BS/CS
broadcast station "affiliation_B", it is judged that
the broadcast resource cannot be accessed by the
10 broadcast-unlinked application.
[0070] After that, when an application end
instruction or a shift to another application occurs by
an operation of the user using a remote controller, for
example (YES in Step S114), the application controller
15 708 of the information processing apparatus 700 ends
the broadcast-unlinked application (Step S115).
[0071] Further, when an application control code
other than "AUTOSTART", "DESTROY", and "KILL" is
described in an XML-AIT newly acquired while the
20 broadcast-unlinked application is being executed, the
application controller 708 of the information
processing apparatus 700 carries out processing of, for
example, shifting the state of the broadcast-unlinked
application according to the application control code
25 (Step S116) and stands by for the next XML-AIT after
that.
31
[0072] There is a case where an operation of
switching a broadcast channel (direct tuning operation)
is carried out by a manual operation of the user while
the broadcast-unlinked application is being executed,
5 for example.
[0073] Fig. 10 is a flowchart showing an operation
of a case where a direct tuning operation occurs.
When a direct tuning operation occurs (Step S201),
the application controller 708 of the information
10 processing apparatus 700 checks whether the broadcast
station public key certificate corresponding to the
broadcast channel selected by the direct tuning
operation is stored in the memory of the information
processing apparatus 700 (Step S202).
15 [0074] If the broadcast station public key
certificate is not stored in the memory of the
information processing apparatus 700, the application
controller 708 of the information processing apparatus
700 waits for a target broadcast station public key
20 certificate to be transmitted by a data carousel of the
switched broadcast channel and, when receiving the
target broadcast station public key certificate
transmitted by the data carousel, stores it in the
memory (Step S203).
25 [0075] The application controller 708 validates the
electronic signature attached to the broadcast-unlinked
32
application being executed, using the broadcast station
public key certificate stored in the memory (Step S205).
When failing in the validation of the electronic
signature (N in Step S206), the application controller
708 ends the broadcast-unlinked application 5 (Step S210).
[0076] When succeeding in the validation of the
electronic signature (Y in Step S206), the application
controller 708 refers to the access permission
information (access_permission) described in the XML10
AIT and accesses broadcast resources of the broadcast
channel switched by the direct tuning operation in a
range permitted to the broadcast-unlinked application
(Step S207). At this time, there is also a case where
the access to all the broadcast resources is not
15 permitted. In this case, the access of the broadcast
resources is not carried out and only the broadcastunlinked
application is displayed.
The subsequent operations (operations from Steps
S208 to S210) are similar to the operations shown in
20 Fig. 8 (operations from Steps S114 to S115).
[0077] Next, an operation of a case where a shift of
a broadcast-unlinked application occurs will be
described with reference to Figs. 8 and 11.
An operation of a case where an instruction to
25 shift a broadcast-unlinked application occurs by an
execution of a script incorporated into a broadcast33
unlinked application being executed or a manual
operation or the like of the user (Step S301 of Fig.
12) is similar to an operation of a case where a
broadcast-unlinked application is selected by the user
from the above-mentioned application 5 launcher.
[0078] (2. Generation and Validation of Electronic
Signature)
Next, the generation and validation of an
electronic signature will be described.
10 Fig. 12 is a block diagram for explaining a
mechanism of the generation and validation of an
electronic signature.
[0079] The XML-AIT server 400 and the application
server 300 may be a single server that possessed by an
15 application creator or may be different servers. Here,
the XML-AIT server 400 and the application server 300
are collectively referred to as "server". The server is
an apparatus having a typical computer structure, which
is constituted of a CPU, a main memory, a storage
20 device such as an HDD, an input apparatus such as a
mouse and a keyboard, a display unit such as a liquid
crystal display, and the like. The main memory and the
storage device store an OS (Operating System), software
such as a server application program, a broadcast25
unlinked application to be provided to the information
processing apparatus 700, an XML-AIT file for each
34
application, a signature generation key, and the like.
[0080] The server includes a signature-attached
application generation unit 350. Specifically, the
signature-attached application generation unit 350 is
realized by a program loaded to the main 5 memory and the
CPU that executes the program.
[0081] The application creator requests the
broadcast station 100 to authenticate an application
351 and an XML-AIT 355.
10 Also as shown in Fig. 1, the broadcast station 100
carefully checks a content of the application 351 and
the XML-AIT 355 as targets of the authentication
requested by the application creator and when there is
no problem in the content, sets a secret key of a pair
15 of the secret key and the broadcast station public key
certificate that are issued by a route CA 800 as a
signature generation key 357 in a signature generator
356. The signature generator 356 generates a digest
using a hash function for a signature with respect to
20 the application 351 and encrypts the digest using the
signature generation key (secret key) 357 to generate
an XML signature 358. The broadcast station 100 sends
the generated XML signature 358 to the server as a
response. The signature-attached application generation
25 unit 350 adds the XML signature 358 as the response
from the broadcast station 100 to the application 351
35
to generate an electronic signature-attached
application 360, and delivers it to the information
processing apparatus 700.
[0082] The application controller 708 of the
information processing apparatus 700 5 extracts an XML
signature by a signature generator 753 from the
electronic signature-attached application 360 acquired
from the server and acquires a signature validation
result 755 by validating the XML signature using a
10 public key 754 that is a signature validation key taken
from the broadcast station public key certificate.
[0083] Next, a method of transmitting the broadcast
station public key certificate from the broadcast
station 100 to the information processing apparatus 700
15 will be described.
The method of transmitting the broadcast station
public key certificate from the broadcast station 100
to the information processing apparatus 700 includes a
dedicated module method, a data broadcast extension
20 method (Part I), and a data broadcast extension method
(Part II), etc.
[0084] (1. Dedicated Module Method)
Fig. 13 is a schematic diagram of the dedicated
module method.
25 In the dedicated module method, in component_tag =
0x40 that is a module including a start document that
36
should be first activated when a data broadcast program
is selected by the user, a dedicated module (for
example, module_id = 0xFFFE) 42 for transmitting a
broadcast station public key certificate 41 is newly
5 placed.
Further, in order to inform the information
processing apparatus 700 of the update of the broadcast
station public key certificate delivered by the
dedicated module, the broadcast station public key
10 certificate descriptor is placed in DII (Download Info
Indication).
[0085] Fig. 14 is a diagram showing a structure of a
broadcast station public key certificate descriptor.
The broadcast station public key certificate
15 descriptor (broadcast certificate_descriptor) includes
an ID (broadcaster_certificate_id) for identifying the
broadcast station public key certificate and a version
of the broadcast station public key certificate
(broadcaster_certificate_version).
20 [0086] Fig. 15 is a flowchart regarding the
acquisition and update of the broadcast station public
key certificate by the dedicated module method.
[0087] First, a controller 708 of the information
processing apparatus 700 monitors DII module
25 information transmitted by a data carousel (Step S401).
When detecting that the DII module information includes
37
a broadcast station public key certificate descriptor
(Y in Step S402), the controller 708 of the information
processing apparatus 700 analyzes the broadcast station
public key certificate descriptor and extracts an ID
and a version from the broadcast 5 station public key
certificate descriptor (Step S403).
[0088] The application controller 708 compares the
IDs of the broadcast station public key certificates
already stored in the memory with the ID acquired at
10 this time and checks whether or not the broadcast
station public key certificate including a matched ID
is stored in the memory (Step S404). If the
corresponding broadcast station public key certificate
is not stored (N in Step S405), the application
15 controller 708 acquires a broadcast station public key
certificate transmitted by the data carousel and stores
it in the memory (Step S406). After that, the
application controller 708 returns to the state of
monitoring the DII module information.
20 [0089] If the corresponding broadcast station public
key certificate is stored (Y in Step S405), the
application controller 708 checks the version of the
broadcast station public key certificate stored in the
memory (Step S407). The application controller 708
25 compares the checked version of the broadcast station
public key certificate with the version of the
38
broadcast station public key certificate that is
acquired at this time and judges whether or not a
version-up of the broadcast station public key
certificate has occurred (Step S408).
[0090] If judging that the 5 version-up of the
broadcast station public key certificate has not
occurred (N in Step S408), the application controller
708 returns to the state of monitoring the DII module
information.
10 [0091] If judging that the version-up of the
broadcast station public key certificate has occurred
(N in Step S408), the application controller 708
acquires a broadcast station public key certificate
transmitted by the data carousel and stores it in the
15 memory (Step S409). After that, the application
controller 708 returns to the state of monitoring the
DII module information.
[0092] As described above, the information
processing apparatus 700 can acquire one or more types
20 of broadcast station public key certificates of the
latest version with different IDs and stores them in
the memory.
[0093] (2. Data Broadcast Extension Method (Part I))
Fig. 16 is a diagram showing a structure of a
25 route certificate descriptor by the data broadcast
extension method (Part I).
39
In the data broadcast extension method (Part I),
extension for transmitting a public key certificate of
a new service is performed on root_certificate_type of
the route certificate descriptor and an ID
(broadcaster_certificate_id) for 5 identifying the
broadcast station public key certificate and a version
(broadcaster_certificate_version) of the broadcast
station public key certificate are described there.
[0094] Fig. 17 is a flowchart regarding the
10 acquisition and update of the broadcast station public
key certificate by the data broadcast extension method
(Part I).
[0095] First, the application controller 708 of the
information processing apparatus 700 monitors a route
15 certificate descriptor of the DII transmitted by a data
carousel (Step S501). When detecting the route
certificate descriptor of the DII (Y in Step S502), the
controller 708 of the information processing apparatus
700 analyzes the route certificate descriptor and
20 judges whether or not a value (root_certificate_type =
2) indicating a new service is described in the route
certificate descriptor (Step S503). If the value
(root_certificate_type = 2) indicating the new service
is not described, the application controller 708
25 processes the data broadcast (Step S504), and then
returns to the state of monitoring the route
40
certificate descriptor of the DII.
[0096] If the value (root_certificate_type = 2)
indicating the new service is described in the route
certificate descriptor, the application controller 708
extracts an ID and a version of the 5 broadcast station
public key certificate from the route certificate
descriptor (Step S505). The subsequent operations from
Steps S506 to S511 are the same as Steps S404 to S409
of the dedicated module method, and hence descriptions
10 thereof will be omitted.
[0097] The application controller 708 compares the
IDs of the broadcast station public key certificates
already stored in the memory with the ID acquired at
this time and checks whether or not the broadcast
15 station public key certificate including a matched ID
is stored in the memory (Step S404). If the
corresponding broadcast station public key certificate
is not stored (N in Step S405), the application
controller 708 acquires a broadcast station public key
20 certificate transmitted by the data carousel and stores
it in the memory (Step S406). After that, the
application controller 708 returns to the state of
monitoring the route certificate descriptor of the DII.
[0098] If the corresponding broadcast station public
25 key certificate is stored (Y in Step S405), the
application controller 708 checks the version of the
41
broadcast station public key certificate stored in the
memory (Step S407). The application controller 708
compares the checked version of the broadcast station
public key certificate with the version of the
broadcast station public key certificate 5 that is
acquired at this time and judges whether or not a
version-up of the broadcast station public key
certificate has occurred (Step S408).
[0099] If judging that the version-up of the
10 broadcast station public key certificate has not
occurred (N in Step S408), the application controller
708 returns to the state of monitoring the DII module
information.
[0100] If judging that the version-up of the
15 broadcast station public key certificate has occurred
(N in Step S408), the application controller 708
acquires a broadcast station public key certificate
transmitted by the data carousel and stores it in the
memory (Step S409). After that, the application
20 controller 708 returns to the state of monitoring the
DII module information.
[0101] As described above, the information
processing apparatus 700 can acquire one or more types
of broadcast station public key certificates of the
25 latest version with different IDs and store them in the
memory.
42
[0102] (3. Data Broadcast Extension Method (Part
II))
In the data broadcast extension method (Part II),
one fixed storage area of storage areas, to which a
public key certificate for data 5 broadcast can be
transmitted, in a route certificate descriptor is
allocated for a new service and an ID
(broadcaster_certificate_id) for identifying the
broadcast station public key certificate and a version
10 (broadcaster_certificate_version) of the broadcast
station public key certificate are described there.
Further, for example, as shown in Fig. 18, a new flag
(broadcaster_certificate_flag) is placed in the route
certificate descriptor. For example, if the value of
15 the flag is ”1”, it indicates that the broadcast
station public key certificate is to be transmitted,
and if the value of the flag is ”0”, it indicates that
the broadcast station public key certificate is not to
be transmitted.
20 [0103] Fig. 19 is a flowchart regarding the
acquisition and update of the broadcast station public
key certificate by the data broadcast extension method
(Part II).
First, the application controller 708 of the
25 information processing apparatus 700 monitors a route
certificate descriptor of the DII transmitted by a data
43
carousel (Step S601). If detecting the route
certificate descriptor of the DII (Y in Step S502), the
controller 708 of the information processing apparatus
700 analyzes the route certificate descriptor and
checks the 5 value of the flag
(broadcaster_certificate_flag). If the value of the
flag is ”0”, the application controller 708 processes
the data broadcast (Step S504) and then returns the
state of monitoring the route certificate descriptor of
10 the DII.
[0104] If the value of the flag is ”0”, the
application controller 708 extracts an ID and a version
of the broadcast station public key certificate from a
predetermined storage area of a plurality of storage
15 areas, to which the public key certificate for data
broadcast can be transmitted, in the route certificate
descriptor (Step S605). The subsequent operations from
Steps S606 to S611 are the same as Steps S404 to S409
of the dedicated module method, and hence descriptions
20 thereof will be omitted.
[0105] As described above, the information
processing apparatus 700 can acquire one or more types
of broadcast station public key certificates of the
latest version with different IDs and store them in the
25 memory.
[0106] [Effects, etc. of First Embodiment]
44
In this embodiment, the following effects can be
obtained.
1. According to this embodiment, an electronic
signature-attached application is transmitted from the
application server 300 to the information 5 processing
apparatus 700, and hence it is possible to prevent a
falsification of the application.
2. The data carousel transmission can be used for
transmitting, in the existing digital broadcast, a
10 broadcast station public key certificate used for
signature verification of an application. Therefore,
the application can be securely transmitted to the
information processing apparatus 700 with minimum
change points of the existing digital broadcast.
15 3. A point that resources of the existing digital
broadcast for transmitting a route certificate can be
used for transmitting the broadcast station public key
certificate by the data carousel transmission is also
advantageous for minimizing the change points.
20 4. It is possible to perform a new service that
can be authenticated by the application while avoiding
a so-called legacy problem, such as an erroneous
operation to a digital broadcast receiver already sold
in an already started digital broadcast.
25 [0107]
Although the electronic signature is attached to
45
the application in the first embodiment, the electronic
signature may be attached to the XML-AIT. According to
this method, for example, as shown in Fig. 20, a
plurality of broadcast stations (broadcast station A,
broadcast station B) permit one application 5 to use a
broadcast resource, and electronic signatures 61 and 62
of all the broadcast stations (broadcast station A and
broadcast station B) that permit to use the broadcast
resource are attached to the XML-AIT.
10 [0108] Fig. 21 is a sequence diagram showing a flow
of exchanges among a broadcast station 100A, an
application server 300A, an XML-AIT server 400A, and an
information processing apparatus 700A in an information
processing system according to a second embodiment. Fig.
15 22 is a flowchart showing a processing procedure of the
information processing apparatus 700A.
Hereinafter, points of the information processing
system according to the second embodiment that are
different from those of the information processing
20 system 1 according to the first embodiment will be
mainly described.
[0109] When, in a menu of a broadcast-unlinked
application displayed by an application launcher, an
arbitrary broadcast-unlinked application is selected by
25 an operation of the user using a remote controller
(Steps S701 and S702), a script corresponding to the
46
broadcast-unlinked application is executed and thus an
application controller 708AA of the information
processing apparatus 700A acquires an electronic
signature-attached XML-AIT for the broadcast-unlinked
application from the XML-AIT server 5 400A (Step S703).
[0110] The application controller 708AA of the
information processing apparatus 700 acquires an
electronic signature-attached broadcast-unlinked
application from the application server 300A based on
10 application location information described in the
acquired XML-AIT (Step S704) and activates it (Step
S705).
[0111] The application controller 708A monitors an
access request of a broadcast resource from the
15 broadcast-unlinked application (Step S706). If
detecting the access request of the broadcast resource
from the broadcast-unlinked application (Y in Step
S707), the application controller 708A checks whether
or not the broadcast station public key certificate
20 corresponding to the broadcast resource is stored in
the memory of the information processing apparatus 700
(Step S707).
[0112] If the broadcast station public key
certificate is not stored in the memory of the
25 information processing apparatus 700A, the application
controller 708A of the information processing apparatus
47
700A waits for a target broadcast station public key
certificate to be transmitted by a data carousel. Here,
the data carousel transmission of the broadcast station
public key certificate is realized by the dedicated
module method, the data broadcast 5 extension method
(Part I), the data broadcast extension method (Part II),
or the like.
[0113] When receiving the target broadcast station
public key certificate transmitted by the data carousel,
10 the application controller 708A stores it in the memory
(Step S708).
[0114] The application controller 708A validates an
electronic signature attached to the acquired XML-AIT
using the broadcast station public key certificate
15 stored in the memory (Step S710). The subsequent
operations are the same as those in the first
embodiment, and hence descriptions thereof will be
omitted.
[Effects, etc. of Second Embodiment]
20 In this embodiment, the following effects can be
obtained.
1. According to this embodiment, an electronic
signature-attached XML-AIT is transmitted from a server
400 to the information processing apparatus 700, and
25 hence it is possible to prevent a falsification of the
XML-AIT.
48
2. The data carousel transmission can be used for
transmitting, in the existing digital broadcast, the
broadcast station public key certificate used for the
signature validation of the XML-AIT. Therefore, it is
possible to prevent a falsification of 5 the XML-AIT with
the minimum change points of the existing digital
broadcast.
3. A point that a resource of the existing digital
broadcast for transmitting a route certificate can be
10 used for transmitting the broadcast station public key
certificate by the data carousel transmission is also
advantageous for minimizing the change points.
4. It is possible to perform a new service that
can be authenticated by the application while avoiding
15 a so-called legacy problem, such as an erroneous
operation to a digital broadcast receiver already sold
in an already started digital broadcast.
[0115]
By the way, in the method of the second embodiment,
20 the falsification of the application cannot be directly
detected. In this context, a hash value of the
application is embedded in the XML-AIT and thus it is
possible to indirectly detect the falsification of the
application by comparing a hash value calculated by a
25 substance of the application and the hash value
embedded in the XML-AIT and notified in the information
49
processing apparatus. Hereinafter, such a method will
be described.
[0116] Next, the generation and validation of the
electronic signature and the hash value will be
5 described.
[0117] Fig. 23 is a diagram for explaining a
mechanism of the generation of an electronic signature
and a hash value and validation of them.
The server includes a signature-attached AIT
10 generation unit 350A. Specifically, the signatureattached
AIT generation unit 350A is realized by a
program for generating an electronic signature and a
hash value that is loaded to a main memory and a CPU
that executes the program.
15 [0118] The signature-attached AIT generation unit
350A calculates a hash value 353A using a predetermined
hash computing unit 352A based on a substance of an
application 351A (binary code). As a hash algorithm,
there are SHA-1, SHA-2, and the like standardized by
20 FIPS-PUB-180-1, 180-2, for example.
[0119] The signature-attached AIT generation unit
350A synthesizes the hash value 353A with an XML-AIT
362A of the application 351A and generates a hash
value-attached XML-AIT 355A.
25 [0120] The application creator requests the
broadcast station 100A to authenticate the application
50
351A and the XML-AIT 355A.
[0121] The broadcast station 100 carefully checks a
content of the application 351A and the XML-AIT 355A as
targets of the authentication requested by the
application creator and when there is 5 no problem in the
content, sets a secret key of a pair of the secret key
and the broadcast station public key certificate that
are issued by the route CA 800 (see Fig. 1) as a
signature generation key 357A in a signature generator
10 356A. The signature generator 356A generates a digest
using a hash function for a signature with respect to
the XML-AIT 355A and encrypts the digest using the
signature generation key (secret key) 357A to generate
an XML signature 358A. The broadcast station 100A sends
15 the generated XML signature 358A to the server as a
response.
[0122] The signature-attached AIT generation unit
350A of the server adds the XML signature 358A as the
response from the broadcast station 100A to the hash
20 value-attached XML-AIT 355A to generate an electronic
signature-attached XML-AIT 360A, and delivers it to the
information processing apparatus 700A.
[0123] The application controller 708A of the
information processing apparatus 700 calculates a hash
25 value 752A using a predetermined hash computing unit
751A (hash function) from a substance of the
51
application 351A (binary code) acquired from the server.
The hash function used herein needs to be the same as
that of the hash computing unit 352A of the signatureattached
AIT generation unit 350A of the server. In
this regard, the application controller 5 708A checks the
hash algorithm described in the electronic signatureattached
XML-AIT 360A acquired from the server and
judges whether it is consistent with the hash algorithm
of the hash computing unit 751A (hash function). If
10 judging that the hash algorithms are inconsistent, the
application controller 708A switches the hash computing
unit 751A (hash function) and matches it with that of
the hash computing unit 352A of the AIT generation unit
350A of the server.
15 [0124] The application controller 708A uses a hash
comparator 756A to compare the hash value 353A and the
hash value 752A extracted from the electronic
signature-attached XML-AIT 360A acquired from the
server and acquires a matched/unmatched result 757A.
20 [0125] The application controller 708A extracts an
XML signature from the electronic signature-attached
XML-AIT 360A acquired from the server in a signature
generator 753A and acquires a signature validation
result 755A obtained by validating the XML signature
25 using a signature validation key (public key) 754A.
[0126] According to the modified example, the
52
information processing apparatus 700 is provided with
the application to which the hash value is added, and
hence the information processing apparatus 700 can
compare the hash value calculated with respect to the
application acquired from the application 5 server 300
with the hash value transmitted by the XML-AIT, to
thereby judge the validity of the application.
[0127] Although the embodiments presupposing the
HbbTV standard have been described, the present
10 technology is not necessarily limited to such a
presupposition.
[0128] In addition, the present technology is not
limited to the embodiments above and can be variously
modified without departing from the gist of the present
15 invention.
Description of Numerals
[0129] 1 information processing system
100 broadcast station
200 first network
20 300 application server
400 XML-AIT server
700 information processing apparatus
701 broadcast interface
702 demultiplexer
25 703 output processing unit
704 video decoder
53
705 audio decoder
706 subtitle decoder
707 communication interface
708 application controller
800 broadcast 5 station CA
54
Claims
[1] A signature validation information transmission
method, comprising
transmitting, by a data carousel method,
validation information for validating 5 an electronic
signature attached to either one of an application
capable of processing first data to be broadcasted and
an application information table that manages an
operation of the application, which are transmitted to
10 an information processing apparatus via a network.
[2] The signature validation information transmission
method according to claim 1, wherein
the validation information is placed in
component_tag = 0x40 as a module, and
15 information for causing the information processing
apparatus to detect update of the transmitted
validation information is placed in DII.
[3] The signature validation information transmission
method according to claim 1, wherein
20 the validation information is stored in a route
certificate descriptor and transmitted.
[4] The signature validation information transmission
method according to claim 3, wherein
a value indicating transmission of the validation
25 information is stored as a value of
root_certificate_type in the route certificate
55
descriptor.
[5] The signature validation information transmission
method according to claim 3, wherein
the validation information is stored in a
predetermined storage area of storage 5 areas, to which a
public key certificate for data broadcast can be
transmitted, in the route certificate descriptor, and
flag information indicating that the validation
information is transmitted is placed in the route
10 certificate descriptor.
[6] An information processing apparatus, comprising:
an acquisition unit that acquires an application
capable of processing first data to be broadcasted and
an application information table that manages an
15 operation of the application via a network; and
a controller that acquires validation data that is
used for validating an electronic signature attached to
either one of the acquired application and application
information table and transmitted by a data carousel,
20 and validates the electronic signature.
[7] An information processing method, comprising:
acquiring, by an acquisition unit, an application
capable of processing first data to be broadcasted and
an application information table that manages an
25 operation of the application via a network; and
acquiring, by a controller, validation data that
56
is used for validating an electronic signature attached
to either one of the acquired application and
application information table and transmitted by a data
carousel, and validating the electronic signature.
[8] A broadcast delivery apparatus, 5 comprising
a transmission unit that transmits, by a data
carousel method, validation information for validating
an electronic signature attached to either one of an
application capable of processing first data to be
10 broadcasted and an application information table that
manages an operation of the application, which are
transmitted to an information processing apparatus via
a network.

Documents