0% found this document useful (0 votes)
37 views8 pages

Conditional Access Irdeto

Irdeto's Conditional Access System (CAS) offers a scalable solution to protect content on broadcast and IPTV networks, addressing the growing threat of digital piracy and the need for operators to maintain competitive pricing. The system provides renewable security technology, flexible deployment options, and a rich feature set to support various business models while minimizing costs. With advanced anti-piracy measures and the ability to rapidly update security features, Irdeto CAS enables operators to enhance their service offerings and improve customer satisfaction.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
37 views8 pages

Conditional Access Irdeto

Irdeto's Conditional Access System (CAS) offers a scalable solution to protect content on broadcast and IPTV networks, addressing the growing threat of digital piracy and the need for operators to maintain competitive pricing. The system provides renewable security technology, flexible deployment options, and a rich feature set to support various business models while minimizing costs. With advanced anti-piracy measures and the ability to rapidly update security features, Irdeto CAS enables operators to enhance their service offerings and improve customer satisfaction.
Copyright
© © All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 8

Solution

Overview

Irdeto
Conditional Access

A fully renewable and scalable solution for protecting content and business models
on broadcast and IPTV networks

Digital content piracy is a advanced hacking attacks at traceable security is increasingly


worldwide issue. Well-funded all points along the media central to operator growth
criminal organizations are pipeline. strategies because it is a key
constantly looking to exploit condition of agreements with
security systems and the To protect their revenue licensing authorities such
explosion of illegal content and reputation, operators as sports rights holders and
streaming websites in recent need uncompromising and Hollywood studios. To win
years means this threat is now sophisticated conditional access the desirable, high-quality
stronger than ever. Once the solutions that are constantly content that differentiates
danger was limited to control evolving to address the latest them from competitors,
word sharing and smart card threats. Preventing piracy is attracts subscribers and builds
tampering on managed STBs, essential, but so is the ability brand loyalty, operators must
but today’s consumers view to recover swiftly if a breach demonstrate continuing
digital video on a wide variety does occur, and to track down commitment to combating
of unmanaged devices. This and shut off the source of any piracy.
leaves content vulnerable to content leaks. Such renewable,
www.irdeto.com © 2022 Irdeto. All Rights Reserved. 1
FOCUS ON COST-EFFICIENCY
In addition to the threat from pirates and pay TV rivals, operators also face a battle for subscribers with
over-the-top (OTT) players and direct-to-consumer offerings from content owners. To counter the effects
of so-called “cord cutting”, operators must keep prices low at the same time as adding value. Typically,
this means investing in their own multiscreen services. For many operators, the adoption of software-
based (cardless) conditional access in place of smart cards is an obvious choice as it reduces procurement,
distribution and management expenses as well as STB hardware costs, without impacting security.

A sharp focus on operational efficiency is also necessary as the number of screens grows, to eliminate
duplication of effort and technology across broadcast and OTT. Many pay TV companies are looking for
ways to simplify security management in a multiscreen world, adopting unified processes for all content,
whether the protection mechanism is CA or Digital Rights Management (DRM).

FLEXIBILITY FOR THE FUTURE


While piracy and cost control are a common concern to all operators, the specifics of the services they run
can vary widely from one market to another and over time. To stay ahead of their competition, operators
need the flexibility to test and implement new business models and features that may appeal to their
unique customer base. This can range from subscription and pay-per-view VOD (whether streamed,
downloaded or pushed to the STB) to home networking, PVR functionality, or tie-ins with third parties
such as OTT-services. All of these have implications for content security. To offer a truly dynamic, tailored
service to their subscribers, operators need a CA system that supports a rich feature set and the ability to
add these new capabilities quickly and easily over-the-air.

The Irdeto Conditional Access System (CAS), a solution in the Irdeto 360 Security portfolio, provides the
most stringent content security for pay TV operations. It also enables pay TV operators and broadcasters
to offer more services, payment options and device support. This equates to more choice, flexibility and
convenience for their customers. Whether via cable, satellite, terrestrial or IPTV, Irdeto Conditional Access
gives broadcasters the flexibility to easily deploy new TV services without interrupting existing subscriber
services or compromising their digital assets.

KEY BENEFITS
Stay ahead of evolving security threats with renewable, uncompromising security
To protect your investments, Irdeto Conditional Access offers renewable security technology. This enables
operators to remotely update both software-based and smart card security clients quickly and easily in
the event of a piracy incident, without costly card swaps. An on-going roadmap of security enhancements
ensures Irdeto CAS protects against the latest threat trends and is compliant with the changing
requirements of all major content licensing authorities.

www.irdeto.com © 2022 Irdeto. All Rights Reserved. 2


Drive ARPU with attractive new features that can Introduce 4K Ultra HD (UHD) services with more
be added over the air control
Irdeto CAS is a fully-featured solution that includes To obtain rights to early release movies or other
a large number of modules and client options to premium content, operators must comply with
support advanced functionalities such as VOD, MovieLabs’ Enhanced Content Protection (ECP)
home-networking and PVR. Over-the-Air updates requirements for Secure Media Pipeline (SMP) to
give operators the flexibility to test and rapidly enforce output control. However, SMP must not
deploy new services to existing STBs in the field, be implemented simply as an on/off switch to
improving the offering to their subscribers and allow 4K UHD content only on 4K TVs with HDCP
creating an opportunity for the operator to raise 2.2 or above. Such an approach would severely
ARPU. limit operators’ support for subscribers since most
devices in the home today do not support HDCP
Minimize costs with flexible deployment options 2.2. To give operators more control, Irdeto CAS
Available as either a smart card or software-based allows operators to define granular enforcement
security client to dramatically reduce the total cost profiles to maximize their business models.
of ownership (TCO), Irdeto CAS can be configured For example, 4K UHD content not subject to
to meet the needs of each specific market. Suitable MovieLabs ECP, such as sports or TV programs can
for protecting content for broadcast or IPTV be viewed on 4K TVs with HDCP 1.4. Operators
delivery to managed devices such as STBs, it can can also maximize their 4K content investment by
be tailored from small or medium-sized networks, providing a lower resolution version of the content
to large-scale networks with millions of subscribers to HD, SD and analog TVs, enabled by the SMP
in a fully redundant setup. Also available as a implementation in Irdeto CAS.
managed service, Irdeto CAS is compatible
with a wide range of set-top boxes, client 4K UHD early 4K UHD and Catch-up & Free to air
release, box office premium content VOD library content
devices, compression equipment and subscriber
SMP SMP SMP No
management systems. This open approach allows w/exceptions w/exceptions SMP

operators to select the components of their choice


or rely on Irdeto for a pre-integrated, end-to-end
4K TV with HDCP 2.2
solution.
4K TV with HDCP 1.4+

SD & HD TV Down-res

Mobile devices Down-res

Analog TV Down-res

DELIVERING CHOICE, FLEXIBILITY AND CONVENIENCE


Irdeto CAS enables pay TV operators to offer the system. These enhancements help operators
a wide range of services, payment options and respond quickly to new threats and ensure rapid
supported devices. This in turn allows them to offer recovery.
increased choice, flexibility and convenience to
their customers. To effectively utilize these tools, Irdeto offers a
suite of services to help operators manage security
Effective And Vigilant Anti-Piracy Efforts over the lifecycle of the content. These services
Operators can’t afford to rely entirely on measures range from ensuring site security and auditing
and technologies aimed at preventing piracy. They operator platforms and devices, to watching and
must respond effectively when piracy does occur. defending on an on-going basis and keeping
In addition to the best-in-class security technology security up-to-date to stay ahead of ever-evolving
at the core of Irdeto CAS, Irdeto continuously security threats.
provides advanced countermeasures as plug-ins to

www.irdeto.com © 2022 Irdeto. All Rights Reserved. 3


Renewable Security enables operators to provide more flexibility to
The cornerstone of Irdeto’s security strategy is subscribers and increase ARPU. Supported services
renewability, enabling operators to update the include:
headend and deployed clients quickly and easily.
This renewability is powered by Irdeto’s unique • 4K Ultra HD MovieLabs support with secure
FlexiFlash mechanism which is integrated into media pipeline.
both the Irdeto software-based and smart card • Home network sharing.
clients, ensuring an end to costly card swaps. • Video on demand (Subscription or pay per
FlexiFlash is used to introduce new features and view).
piracy countermeasures as plug-ins to the system, • Impulse pay per view (PPV).
resulting in shorter development, test and release • Personal video recorder (PVR).
times and faster response and recovery when new • Digital rights management (requires PVR).
threats and incidents arise. • CI+ Conditional Access Module (CAM).
• Proximity control.
Future-proof cryptography • Remote ECM generator.
The Irdeto Key Management System (KMS) uses
the latest advances in cryptography to create Flexible Deployment models
Irdeto-specific algorithms and an operator-unique The Irdeto CAS can be deployed in multiple
cryptographic layer, resulting in: different configurations and across a variety of
client devices to address unique business, security
• No single point of security failure. and operational requirements. It can also be
• Higher resistance against attacks with proven provided as a managed service. Irdeto’s solutions
cryptographic strength and indefinitely are compliant with industry standards, enabling
updateable algorithms. interoperability and ease of integration with third-
• Reduced impact from any individual threat – the party products to provide maximum choice to
use of diverse primary keys across each device operators.
type and model ensures that in the event of a
key being compromised, only a small subset CI+ CAM for integrated digital television (iDTV)
of devices can be affected. The risk cannot be A variety of pay TV services, such as home network
spread to other devices or operators. support and PVR, can be delivered directly to the
iDTV set without the need for an STB.
The KMS is an essential component of the Irdeto
Integrated Management System (IMS) which allows Home networking
operators to centralize administration of content Controlled sharing and distribution of subscriber
security across both CA and DRM. content across multiple screens (both secondary
TVs and unmanaged consumer devices) within a
Countermeasures against control word sharing household. This also includes options for Download
(CWS) & Go on specific devices. For further information,
Irdeto CAS provides effective defense against please visit Irdeto.com to see the Irdeto Home
CWS, including: Networking Security solution overview.

A heuristic algorithm to detect smart cards used for Multiroom


control word redistribution. Content viewing in multiple rooms within a
An improved communications interface layer with household from a single subscription.
intellectual property rights (IPR) support to enable
prosecution when a smart card is used in emulation Proximity control
STBs. A cost-effective implementation to share content
on the PVR via the home network while preventing
A variety of pay TV options STBs – and the content - from moving outside the
Irdeto CAS offers a large number of optional home.
modules to support advanced functionalities. This

www.irdeto.com © 2022 Irdeto. All Rights Reserved. 4


Content Distribution Consumer

Subscription,
pre-paid,
pre-enabled,
preview,
Irdeto Key Server PPV, PVR,
catch-up TV, VOD, Irdeto Smart Card
home networking etc.

Content

Irdeto Key Management


System Irdeto Cloaked CA

Broadcast or
IPTV network

Irdeto DVB Streamer or Irdeto-approved STB or CI+ CAM


other headend equipment with Secure Chipset

Figure 1. A flexible, renewable security solution that adapts to the demands of any pay TV market

GROUND-BREAKING TECHNOLOGY
Flexible Security Client Update redistribution and device software tampering.
Irdeto Conditional Access is based on industry Irdeto’s secure chipset solution is based on:
leading technology allowing smart card and
software-based clients to be securely updated • The presence of an advanced security
in the field. This feature, called FlexiFlash, is descrambler chip in the STB or CAM.
unique to Irdeto and allows for major security and • The unique personalization of this chip during
functionality updates to the subscriber devices. production.
Operators can use FlexiFlash to renew the • A pairing relationship between the security
complete CA client. client and the chip integrated into the device.

In Irdeto’s customer networks, FlexiFlash has been These attributes enable the smart card or
proven to speed up the upgrade of functionality software-based client to be securely bound to a
and enable proactive security updates and rapid device. In this solution, control word messages
response to piracy attacks. FlexiFlash helps are uniquely encrypted as they pass between the
operators to maximize their return on investment Irdeto CA client and an advanced security chipset
by extending the effectiveness of their CA solution, in the device. They can only be decrypted by the
and renew security clients without disrupting authorized STB chip which is paired to that card or
subscribers’ viewing experience. client. This unique pairing between the device and
the CA client ensures that targeted downloads can
Secure Chipset only be received by the intended device. Enhanced
The Irdeto Secure Chipset solution is the ideal protection of the flash memory prevents attacks on
response to the challenges of securing a STB or services processed by the device.
CAM against two forms of piracy: control word

www.irdeto.com © 2022 Irdeto. All Rights Reserved. 5


A Choice Of Hardware And Software-Based CA Architecture And Components
Client Solutions Each Irdeto CAS deployment consists of the
Irdeto offers its customers the CA solution that best following components:
suits their content protection and business model
requirements using both hardware and software- Irdeto Key Management System (KMS).
based security clients. Both solutions, when used Irdeto Key Server.
with Irdeto’s Secure Chipset technology, provide
the same level of uncompromising protection Depending on the operator’s requirements, the
against the latest forms of piracy and are fully following components may also be deployed to
upgradable while in the field. A unified headend create a custom solution:
system enables the operator to easily manage both
clients, making a mixed-based deployment simple • Irdeto Rights – provides multi-DRM protection
and cost effective. for OTT and home networking to unmanaged
devices.
Each security client uses a “secure container” to • Irdeto DVB Streamer – supports EPG services
ensure it is highly robust against hacking, reverse and STB updates by injecting CA messages into
engineering and tampering. Irdeto smart cards transport streams.
use the latest silicon technology available from • Irdeto Pre-Encryption Server (PES) – enables
leading manufacturers, while Irdeto Cloaked VOD services by encrypting VOD assets with
CA is protected by Irdeto’s innovative security CA protection.
technology for source code obfuscation, data
transformations and white box cryptography. This
results in “cloaked” code that is meaningless to
anyone who should attempt to reverse-engineer it.

GROUND-BREAKING TECHNOLOGY
CAS-Related Services Training
Irdeto has an expert team of professionals to On-site operational and intensive product training
support a global customer base. A full range to ensure the maintainability of the system.
of professional services is available to meet Introductory and Foundation courses on CA are
customers’ needs; including: also available. Customized training programs can
be developed on request.
Integration and customization services
Requirements analysis for the design and Testing and field trial support
development of the project, integration support for Develop tests and scripts, manage regression and
Irdeto components to manufacturers and partners, extensive systems testing, reporting progress using
and technical integration consultancy to help Irdeto quality software tools to deliver results to all levels
customers develop strategies and innovative ideas of audiences within or outside the organization.
for their business. STB and device verification testing is available, with
associated device manufacturer support.
Headend implementation services
System preparation of the Irdeto headend STB security evaluation service
equipment and on-site installation services to help Provide operators with a comprehensive
operators install and integrate equipment with assessment of their integrated 4K Ultra HD STB in
minimal interruption to their services, and support the context of the MovieLabs’ ECP requirements.
operators with acceptance testing. The service outlines how well the STB measures
up and recommends any improvements that can

www.irdeto.com © 2022 Irdeto. All Rights Reserved. 6


be made to maximize the operators’ chance of Managed services
securing premium content. It can be performed Provision of 24x7 Security Operations Center
on all set-top boxes with Irdeto-certified secure (SOC) for 1st line support, off-air CA broadcast and
chipsets. For more information, please refer to the platform monitoring.
STB Security Evaluation Service overview.
Security lifecycle services audit, update and Customer support services
implementation services 24x7 SOC for 1st line support, 2nd line support
for more complex problem analysis, bug fix
Conduct an audit of the CAS location, configuration implementation, system upgrades and updates.
and management processes based on CA Site Piracy control and cybercrime management
Security Certification requirements, help operators For more information on this end-to-end suite of
mitigate the risk of piracy and fraud resulting from services for brand and revenue protection, please
incorrect and unsafe operation of the CAS, reduce see the Piracy Control & Cybercrime Management
vulnerability to social engineering attacks. solution overview.

CA system optimization service


Provide an assessment of customer’s content
protection system and its environment in order
to give appropriate recommendations for
configuration, tuning, system implementation,
security improvement and to support
implementation of such recommendations.

SUMMARY
Irdeto CAS is a secure, flexible and cost-effective
CA System that addresses the full range of
security challenges faced by pay TV operators in
the modern market. It can be deployed as either
a cardless or smart card-based solution. The
software-based implementation, Irdeto Cloaked
CA, is the most advanced and widely deployed
cardless conditional access system for broadcast
operators worldwide. It has been independently protect the operator’s content investments,
audited and certified. It is most recently audited by revenue, and reputation. With approval from
Farncombe (Cartesian) in July 2017 for compliance leading licensing authorities such as Hollywood
to MovieLabs’ ECP requirements, where it received Studios and sports rights owners, the solution is
the highest possible score for enforcing the an integral part of negotiations to secure the most
stringent usage rules for 4K UHD premium content. attractive content including 4K Ultra HD.

In addition to uncompromised security based on Selecting Irdeto CAS can deliver significant savings
a hardware root of trust, Irdeto CAS is regularly on both capital and operational expenditure. Irdeto
enhanced with new plug-ins that guard against Cloaked CA can reduce total cost of ownership
the latest content security threats. And if the by as much as 40% through lower hardware,
worst does happen, built-in renewability ensures distribution and management costs.
operators can rapidly and effectively recover
from any piracy incident. Together, these features

www.irdeto.com © 2022 Irdeto. All Rights Reserved. 7


Operators naturally keep their market under constant review because consumer demands are always
changing. To help our customers stay agile and fit for whatever the future brings, Irdeto CAS has built-
in support for a full range of business models and advanced features to suit developing business plans.
From home networking and PVR capabilities to pre-pay models or VOD streaming and downloads, over-
the-air deployment capabilities mean operators can develop, test and roll-out these new services quickly
and efficiently.

Irdeto is the world leader in digital platform cybersecurity, empowering businesses to innovate for a secure,
connected future. Building on over 50 years of expertise in security, Irdeto’s services and solutions protect revenue,
enable growth and fight cybercrime in video entertainment, video games, and connected industries including
transport, health and infrastructure. With teams around the world, Irdeto’s greatest asset is its people and diversity
is celebrated through an inclusive workplace, where everyone has an equal opportunity to drive innovation and
support Irdeto’s success. Irdeto is the preferred security partner to empower a secure world where people can
connect with confidence.

Last modification: 15-02-2022 / 11:40 am GMT+01:00

www.irdeto.com © 2022 Irdeto. All Rights Reserved. 8

You might also like