Jump to content

High-bandwidth Digital Content Protection: Difference between revisions

From Wikipedia, the free encyclopedia
Content deleted Content added
Added a hatnote template for clarification between DHCP and HDCP
No edit summary
Line 1: Line 1:

{{Distinguish|DHCP}}
{{Distinguish|DHCP}}
'''High-bandwidth Digital Content Protection''' ('''HDCP'''; commonly, though incorrectly, referred to as ''High-Definition Copy(right) Protection'') is a form of digital [[copy protection]] developed by [[Intel|Intel Corporation]]<ref>{{cite web| title = Digital Content Protection - About DCP | url = http://www.digital-cp.com/about_dcp}}</ref> to prevent copying of digital audio and video content as it travels across connections. Types of connections include [[DisplayPort]] (DP), [[Digital Visual Interface]] (DVI), and [[High-Definition Multimedia Interface]] (HDMI), as well as less popular, or now defunct, protocols like [[Gigabit Video Interface]] (GVIF) and [[Unified Display Interface]] (UDI).
'''High-bandwidth Digital Content Protection''' ('''HDCP'''; commonly, though incorrectly, referred to as ''High-Definition Copy(right) Protection'') is a form of digital [[copy protection]] and [[Digital Restrictions Management]] developed by [[Intel|Intel Corporation]]<ref>{{cite web| title = Digital Content Protection - About DCP | url = http://www.digital-cp.com/about_dcp}}</ref> to prevent copying of digital audio and video content as it travels across connections. Types of connections include [[DisplayPort]] (DP), [[Digital Visual Interface]] (DVI), and [[High-Definition Multimedia Interface]] (HDMI), as well as less popular, or now defunct, protocols like [[Gigabit Video Interface]] (GVIF) and [[Unified Display Interface]] (UDI).


The system is meant to stop HDCP-encrypted content from being played on unauthorized devices or devices which have been modified to copy HDCP content.<ref>HDCP specification 1.3. Page 31 0x15, Page 35</ref><ref>{{cite web|title=HD DVD Glossary|url=http://www.hddvd-faq.com/glossary.asp}} 080509 hddvd-faq.com</ref> Before sending data, a transmitting device checks that the receiver is authorized to receive it. If so, the transmitter encrypts the data to prevent eavesdropping as it flows to the receiver.<ref name=autogenerated1 />
The system is meant to stop HDCP-encrypted content from being played on unauthorized devices or devices which have been modified to copy HDCP content.<ref>HDCP specification 1.3. Page 31 0x15, Page 35</ref><ref>{{cite web|title=HD DVD Glossary|url=http://www.hddvd-faq.com/glossary.asp}} 080509 hddvd-faq.com</ref> Before sending data, a transmitting device checks that the receiver is authorized to receive it. If so, the transmitter encrypts the data to prevent eavesdropping as it flows to the receiver.<ref name=autogenerated1 />
Line 6: Line 7:
In order to make a device that plays material protected by HDCP, the manufacturer must obtain a license from Intel subsidiary Digital Content Protection LLC, pay an annual fee, and submit to various conditions.<ref name=HDCP_1.3>{{cite web |url=http://www.digital-cp.com/files/static_page_files/8006F925-129D-4C12-C87899B5A76EF5C3/HDCP_Specification%20Rev1_3.pdf |format=pdf |title=HDCP v1.3 specification |work=Digital Content Protection|date=2006-12-21|accessdate=2008-05-08}}</ref><ref>{{cite web|url=http://www.digital-cp.com/home |title=Digital Content Protection LLC |accessdate=2008-01-24 }}</ref><ref name=HDCP_clique>{{cite news | first= | last= | coauthors= | title=HDCP License Agreement | date=2008-01-16 | publisher=Digital Content Protection, LLC. | url =http://www.digital-cp.com/files/static_page_files/D6724AFD-9B02-A253-D8D2FE5B1A10F7F7/HDCP_License_Agreement_082207.pdf | work = | pages = | accessdate = 2008-01-24 | language = }}</ref> For example, the device cannot be designed to copy; it must "frustrate attempts to defeat the content protection requirements";<ref name=HDCP_clique/> it must not transmit high definition protected video to non-HDCP receivers; and DVD-Audio material can be played only at [[Compact Disc|CD]]-audio quality<ref name=HDCP_clique/> by non-HDCP digital audio outputs (analog audio outputs have no quality limits). HDCP does not allow copying permitted by [[fair use]] laws.
In order to make a device that plays material protected by HDCP, the manufacturer must obtain a license from Intel subsidiary Digital Content Protection LLC, pay an annual fee, and submit to various conditions.<ref name=HDCP_1.3>{{cite web |url=http://www.digital-cp.com/files/static_page_files/8006F925-129D-4C12-C87899B5A76EF5C3/HDCP_Specification%20Rev1_3.pdf |format=pdf |title=HDCP v1.3 specification |work=Digital Content Protection|date=2006-12-21|accessdate=2008-05-08}}</ref><ref>{{cite web|url=http://www.digital-cp.com/home |title=Digital Content Protection LLC |accessdate=2008-01-24 }}</ref><ref name=HDCP_clique>{{cite news | first= | last= | coauthors= | title=HDCP License Agreement | date=2008-01-16 | publisher=Digital Content Protection, LLC. | url =http://www.digital-cp.com/files/static_page_files/D6724AFD-9B02-A253-D8D2FE5B1A10F7F7/HDCP_License_Agreement_082207.pdf | work = | pages = | accessdate = 2008-01-24 | language = }}</ref> For example, the device cannot be designed to copy; it must "frustrate attempts to defeat the content protection requirements";<ref name=HDCP_clique/> it must not transmit high definition protected video to non-HDCP receivers; and DVD-Audio material can be played only at [[Compact Disc|CD]]-audio quality<ref name=HDCP_clique/> by non-HDCP digital audio outputs (analog audio outputs have no quality limits). HDCP does not allow copying permitted by [[fair use]] laws.


Cryptanalysis researchers demonstrated flaws in HDCP as early as 2001. In September 2010, a HDCP master key that allows for the generation of valid device keys—rendering the key revocation feature of HDCP useless—was released to the public.<ref name="Lawler">{{cite web |url=http://www.engadget.com/2010/09/14/hdcp-master-key-supposedly-released-unlocks-hdtv-copy-protect/ |title=HDCP 'master key' supposedly released, unlocks HDTV copy protection permanently |first=Richard |last=Lawler |publisher=Engadget |accessdate=September 14, 2010}}</ref><ref>{{cite news|author=Peter Bright|title=Intel confirms HDCP key is real, can now be broken at will|publisher=[[Ars Technica]]|date=2010-09-17|accessdate=2010-09-17|url=http://arstechnica.com/tech-policy/news/2010/09/intel-confirms-the-hdcp-key-is-real-can-now-be-broken-at-will.ars}}</ref> Intel has confirmed that the crack is real,<ref>[http://www.theinquirer.net/inquirer/news/1733749/intel-confirms-hdcp-cracked Intel confirms that HDCP has been cracked- The Inquirer<!-- Bot generated title -->]</ref> and believes the master key was [[Reverse engineering|reverse engineered]] rather than leaked.<ref name=w2/> In practical terms, the impact of the crack has been described as "the digital equivalent of pointing a video camera at the TV", and of limited importance for pirates because the encryption of high-definition discs has been [[AACS encryption key controversy|attacked directly]], without the loss of interactive features like menus.<ref>[http://news.cnet.com/8301-27080_3-20016768-245.html HDCP antipiracy leak opens doors for black boxes | InSecurity Complex - CNET News<!-- Bot generated title -->]</ref> Intel threatened to sue anyone producing an unlicensed device.<ref name=w2>Wired. "[http://www.wired.com/threatlevel/2010/09/intel-threatens-consumers/ Intel Threatens to Sue Anyone Who Uses HDCP Crack]".</ref>
Cryptanalysis researchers demonstrated flaws in HDCP as early as 2001. In September 2010, a HDCP master key that allows for the generation of valid device keys—rendering the key revocation feature of HDCP useless—was released to the public.<ref name="Lawler">{{cite web |url=http://www.engadget.com/2010/09/14/hdcp-master-key-supposedly-released-unlocks-hdtv-copy-protect/ |title=HDCP 'master key' supposedly released, unlocks HDTV copy protection permanently |first=Richard |last=Lawler |publisher=Engadget |accessdate=September 14, 2010}}</ref><ref>{{cite news|author=Peter Bright|title=Intel confirms HDCP key is real, can now be broken at will|publisher=[[Ars Technica]]|date=2010-09-17|accessdate=2010-09-17|url=http://arstechnica.com/tech-policy/news/2010/09/intel-confirms-the-hdcp-key-is-real-can-now-be-broken-at-will.ars}}</ref> Intel has confirmed that the crack is real,<ref>[http://www.theinquirer.net/inquirer/news/1733749/intel-confirms-hdcp-cracked Intel confirms that HDCP has been cracked- The Inquirer<!-- Bot generated title -->]</ref> and believes the master key was [[Reverse engineering|reverse engineered]] rather than leaked.<ref name=w2/> In practical terms, the impact of the crack has been described as "the digital equivalent of pointing a video camera at the TV", and of limited importance for copyright infringers because the encryption of high-definition discs has been [[AACS encryption key controversy|attacked directly]], without the loss of interactive features like menus.<ref>[http://news.cnet.com/8301-27080_3-20016768-245.html HDCP antipiracy leak opens doors for black boxes | InSecurity Complex - CNET News<!-- Bot generated title -->]</ref> Intel threatened to sue anyone producing an unlicensed device.<ref name=w2>Wired. "[http://www.wired.com/threatlevel/2010/09/intel-threatens-consumers/ Intel Threatens to Sue Anyone Who Uses HDCP Crack]".</ref>


== Specification ==
== Specification ==

Revision as of 16:13, 17 September 2013

High-bandwidth Digital Content Protection (HDCP; commonly, though incorrectly, referred to as High-Definition Copy(right) Protection) is a form of digital copy protection and Digital Restrictions Management developed by Intel Corporation[1] to prevent copying of digital audio and video content as it travels across connections. Types of connections include DisplayPort (DP), Digital Visual Interface (DVI), and High-Definition Multimedia Interface (HDMI), as well as less popular, or now defunct, protocols like Gigabit Video Interface (GVIF) and Unified Display Interface (UDI).

The system is meant to stop HDCP-encrypted content from being played on unauthorized devices or devices which have been modified to copy HDCP content.[2][3] Before sending data, a transmitting device checks that the receiver is authorized to receive it. If so, the transmitter encrypts the data to prevent eavesdropping as it flows to the receiver.[4]

In order to make a device that plays material protected by HDCP, the manufacturer must obtain a license from Intel subsidiary Digital Content Protection LLC, pay an annual fee, and submit to various conditions.[5][6][7] For example, the device cannot be designed to copy; it must "frustrate attempts to defeat the content protection requirements";[7] it must not transmit high definition protected video to non-HDCP receivers; and DVD-Audio material can be played only at CD-audio quality[7] by non-HDCP digital audio outputs (analog audio outputs have no quality limits). HDCP does not allow copying permitted by fair use laws.

Cryptanalysis researchers demonstrated flaws in HDCP as early as 2001. In September 2010, a HDCP master key that allows for the generation of valid device keys—rendering the key revocation feature of HDCP useless—was released to the public.[8][9] Intel has confirmed that the crack is real,[10] and believes the master key was reverse engineered rather than leaked.[11] In practical terms, the impact of the crack has been described as "the digital equivalent of pointing a video camera at the TV", and of limited importance for copyright infringers because the encryption of high-definition discs has been attacked directly, without the loss of interactive features like menus.[12] Intel threatened to sue anyone producing an unlicensed device.[11]

Specification

HDCP uses three systems:[5]

  1. Authentication prevents non-licensed devices from receiving content.
  2. Encryption of the data sent over DisplayPort, DVI, HDMI, GVIF, or UDI interfaces prevents eavesdropping of information and man-in-the-middle attacks.
  3. Key revocation prevents devices that have been compromised and cloned from receiving data.

Each HDCP-capable device has a unique set of 40 56-bit keys. Failure to keep them secret violates the license agreement. For each set of values, a special public key called a KSV (Key Selection Vector) is created. Each KSV consists of 40 bits (one bit for each HDCP key), with 20 bits set to 0 and 20 bits set to 1.

During authentication, the parties exchange their KSVs under a procedure called Blom's scheme. Each device adds (unsigned addition modulo 256) its own secret keys together according to a KSV received from another device. Depending on the order of the bits set to 1 in the KSV, a corresponding secret key is used or ignored in the addition. The generation of keys and KSVs gives both devices the same 56-bit number, which is later used to encrypt data.

Encryption is done by a stream cipher. Each decoded pixel is encrypted by applying an XOR operation with a 24-bit number produced by a generator. The HDCP specifications ensure constant updating of keys after each encoded frame.

If a particular set of keys is compromised, their corresponding KSV is added to a revocation list burned onto new discs in the DVD and Blu-ray formats. (The lists are signed with a DSA digital signature, which is meant to keep malicious users from revoking legitimate devices.) During authentication, the transmitting device looks for the receiver's KSV on the list, and if it is there, will not send protected content to the revoked device.

Uses

HDCP devices are generally divided into three categories:

Source
The source sends the content to be displayed. Examples include set-top boxes, DVD, HD DVD and Blu-ray Disc players, and computer video cards. A source has only an HDCP/HDMI transmitter.[4]
Sink
The sink renders the content for display so it can be viewed. Examples include TVs and digital projectors. A sink has one or more HDCP/HDMI receivers.[4]
Repeater
A repeater accepts content, decrypts it, then re-encrypts and retransmits the data. It may perform some signal processing, such as upconverting video into a higher-resolution format, or splitting out the audio portion of the signal. Repeaters have HDMI inputs and outputs. Examples include home theater audio-visual receivers that separate and amplify the audio signal, while re-transmitting the video for display on a TV. A repeater could also simply send the input data stream to multiple outputs for simultaneous display on several screens.[4]

Each device may contain one or more HDCP transmitters and/or receivers. (A single transmitter or receiver chip may combine HDCP and HDMI functionality.)[4]

In the United States, the Federal Communications Commission (FCC) approved HDCP as a "Digital Output Protection Technology" on August 4, 2004.[13] The FCC's Broadcast flag regulations, which were struck down by the United States Court of Appeals for the District of Columbia Circuit, would have required DRM technologies on all digital outputs from HDTV signal demodulators. Congress is still considering legislation that would implement something similar to the Broadcast Flag. The HDCP standard is more restrictive than the FCC's Digital Output Protection Technology requirement. HDCP bans compliant products from converting HDCP-restricted content to full-resolution analog form, presumably in an attempt to reduce the size of the analog hole.

On January 19, 2005, the European Information, Communications, and Consumer Electronics Technology Industry Associations (EICTA) announced that HDCP is a required component of the European "HD ready" label.[14]

Microsoft Windows Vista and Windows 7 both use HDCP in computer graphics cards and monitors.[15][16]

Circumvention

HDCP strippers remove HDCP information from the video signal in order to allow the data to flow freely to a non-HDCP display. It is currently unclear whether such devices would remain working if the HDCP licensing body issued key-revocation lists, which may be installed via new media (e.g. newer Blu-ray Discs) played-back by another device (e.g. a Blu-ray Disc player) connected to it.[17]

Cryptanalysis

In 2001, Scott Crosby of Carnegie Mellon University wrote a paper with Ian Goldberg, Robert Johnson, Dawn Song, and David Wagner called "A Cryptanalysis of the High-bandwidth Digital Content Protection System", and presented it at ACM-CCS8 DRM Workshop on November 5.[18]

The authors concluded that HDCP's linear key exchange is a fundamental weakness, and discussed ways to:

  • Eavesdrop on any data.
  • Clone any device with only its public key.
  • Avoid any blacklist on devices.
  • Create new device key vectors.
  • In aggregate, usurp the authority completely.

They also said the Blom's scheme key swap could be broken by a so-called conspiracy attack: obtaining the keys of at least 40 devices and reconstructing the secret symmetrical master matrix that was used to compute them.

Around the same time, Niels Ferguson independently claimed to have broken the HDCP scheme, but he did not publish his research, citing legal concerns arising from the controversial Digital Millennium Copyright Act.[19]

In November 2011 Professor Tim Güneysu of Ruhr-Universität Bochum revealed he had broken the HDCP 1.3 encryption standard.[20]

Master key release

On September 14, 2010, the Engadget website reported the release of a possible genuine HDCP master key which can create device keys that can authenticate with other HDCP compliant devices without obtaining valid keys from The Digital Content Protection LLC. This master key would neutralize the key revocation feature of HDCP, because new keys can be created when old ones are revoked.[8] It was not immediately clear who discovered the key or how they discovered it, though the discovery was announced via a Twitter update which linked to a Pastebin snippet containing the key and instructions on how to use it. Engadget said the attacker may have used the method proposed by Crosby in 2001 to retrieve the master key, although they cited a different researcher. On September 16, Intel confirmed that the code had been cracked.[21][22] Intel has threatened legal action against anyone producing hardware to circumvent the HDCP, possibly under the Digital Millennium Copyright Act.[11]

Problems

HDCP can cause problems for users who want to connect multiple screens to a device; for example, a bar with several televisions connected to one satellite receiver or when a user has a closed laptop and uses an external display as his only monitor. HDCP devices can create multiple keys, allowing each screen to operate, but the number varies from device to device; e.g., a Dish or Sky satellite receiver can generate 16 keys.[23] The technology sometimes causes handshaking problems where devices cannot establish a connection, especially with older high-definition displays.[24][25][26]

Edward Felten wrote "the main practical effect of HDCP has been to create one more way in which your electronics could fail to work properly with your TV," and concluded in the aftermath of the master key fiasco that HDCP has been "less a security system than a tool for shaping the consumer electronics market."[27]

Additional issues arise with interactive media (i.e. video games) from control latency due to the additional processing (encoding/decoding) required. Further, use cases such as live streaming or capture of game play, are also adversely affected.[28]

There is also the problem that all Apple laptop products, presumably to reduce switch time, when confronted with a HDCP compliant device switches all output from the DVI / Mini DisplayPort / Thunderbolt connector port to HDCP compliant. This is a problem if you wish to record or use video conferencing facilities further down the chain, which are inherently forbidden by HDCP. This applies even if the output is not HDCP material, like a powerpoint presentation.[citation needed]

Versions Highlights

HDCP revision Supported interfaces
1.0 DVI
1.1 DVI, HDMI
1.2 DVI, HDMI
1.3 DVI, HDMI, DP, GVIF, UDI
1.4
2.0
  • Interface Independent Adaptation, Any IP based interface
  • Compressed or uncompressed video (Specifically only specified for compressed over PES)
2.1
  • New mechanism to manage (mysterious) Type 1 content
  • Resolve addition of device without full tree re-auth by allowing ReceiverID_List to be asynchronous

HDCP v2.x

The 2.x version of HDCP is not a continuation of HDCPv1, and is rather a completely different link protection. While all of the HDCP v1.x specifications support backwards compatibility to previous versions of the specification, HDCPv2 devices may interface with HDCPv1 hardware only by natively supporting HDCPv1, or by using a dedicated converter device. As a result, there is currently no deployment plan for v2 to replace v1 in existing systems. This means that HDCPv2 is only applicable to new technologies. It has been selected for the WirelessHD and Miracast (formerly WiFi Display) standards.

HDCP 2.x features a new authentication protocol, and a locality check to ensure the receiver is relatively close (it must respond to the locality check within 20 ms on a normal (DVI/HDMI link [29]). Version 2.1 of the specification was recently cryptanalyzed and found to have several flaws, including the ability to recover the session key.[30]

There are still few commonalities between HDCP v2 and v1

  1. Both are under DCP LLC authority
  2. Both share same license agreement, compliance rules and robustness rules
  3. Both share same revocation system and same device ID formats

References

  1. ^ "Digital Content Protection - About DCP".
  2. ^ HDCP specification 1.3. Page 31 0x15, Page 35
  3. ^ "HD DVD Glossary". 080509 hddvd-faq.com
  4. ^ a b c d e (2008, July). HDCP deciphered: white paper. Retrieved July 22, 2008, from DCP, LLC. Web site: http://www.digital-cp.com/files/documents/04A897FD-FEF1-0EEE-CDBB649127F79525/HDCP_deciphered_070808.pdf
  5. ^ a b "HDCP v1.3 specification" (pdf). Digital Content Protection. 2006-12-21. Retrieved 2008-05-08.
  6. ^ "Digital Content Protection LLC". Retrieved 2008-01-24.
  7. ^ a b c "HDCP License Agreement" (PDF). Digital Content Protection, LLC. 2008-01-16. Retrieved 2008-01-24. {{cite news}}: Cite has empty unknown parameter: |coauthors= (help)
  8. ^ a b Lawler, Richard. "HDCP 'master key' supposedly released, unlocks HDTV copy protection permanently". Engadget. Retrieved September 14, 2010.
  9. ^ Peter Bright (2010-09-17). "Intel confirms HDCP key is real, can now be broken at will". Ars Technica. Retrieved 2010-09-17.
  10. ^ Intel confirms that HDCP has been cracked- The Inquirer
  11. ^ a b c Wired. "Intel Threatens to Sue Anyone Who Uses HDCP Crack".
  12. ^ HDCP antipiracy leak opens doors for black boxes | InSecurity Complex - CNET News
  13. ^ "FCC Approves Digital Output Protection Technologies and Recording Method Certifications" (PDF) (Press release). Federal Communications Commission. 2004-08-04. Retrieved 2006-12-28.
  14. ^ "EICTA announces "Conditions for High Definition Labelling of Display Devices" (PDF) (Press release). EICTA. 2005-01-19. Retrieved 2006-12-28.
  15. ^ Output Content Protection and Windows Vista
  16. ^ The Clicker: Microsoft's OPM for the masses - Engadget
  17. ^ Ryan Block (2005-07-21). "The Clicker: HDCP's Shiny Red Button". Engadget. Retrieved 2006-12-28.
  18. ^ Scott Crosby, Ian Goldberg, Robert Johnson, Dawn Song, David Wagner (2001-11-05). "A Cryptanalysis of the High-bandwidth Digital Content Protection System". ACM-CSS8 DRM Workshop. Retrieved 2006-12-28. {{cite conference}}: Unknown parameter |booktitle= ignored (|book-title= suggested) (help)CS1 maint: multiple names: authors list (link)
  19. ^ Niels Ferguson, DMCA Censorship, August 15, 2001
  20. ^ Intel's HDCP gets cracked - German boffin says encryption flawed | TechEye
  21. ^ "HDTV Code Crack Is Real, Intel Confirms". Fox News. 2010-09-16.
  22. ^ Intel Confirms That HDCP Master Key is Cracked
  23. ^ http://www.crestron.com/downloads/pdf/misc/third_party_hdcp_limits.pdf
  24. ^ PS3 Blinking Mystery Deepens—Westinghouse: "Our TVs Not the Problem" - Popular Mechanics
  25. ^ HDCP "Handshake" A Big Problem For Many Legacy DVI-Based HDTVs
  26. ^ EETimes | HDMI/DVI HDCP handshake problems & how to avoid them
  27. ^ Understanding the HDCP Master Key Leak
  28. ^ recording - How do you capture video of your PS3 gameplay? - Arqade
  29. ^ "High-bandwidth Digital Content Protection System, Revision 2.2 13 February, 2013 section 2.3, page 16" (PDF).
  30. ^ Green, Matthew. "An Analysis of HDCP Version 2". Retrieved May 9, 2013.