Help! New Mystery Encryption Scheme

KenSoftTH

Registered
Messages
36
If I look into 12276000-V-7032-2019-06-09 17-22-28.ts then I do not see any 00 93 content nor any static areas when browsing trough the file so I have hard to believe it's the same content
compared to the 12402000-V-12222-2019-06-09 19-47-38.ts
then also have different time in filename

This file, "12276000-V-7032-2019-06-09 17-22-28.ts", is in BISS and broadcast on 144E and is intended for international broadcasting. On the other hand, "12402000-V-12222-2019-06-09 19-47-38.ts" is intended for Japanese broadcaster and was transmitted using 162E.

So, I don't think you will find any 00 93 in "12276000-V-7032-2019-06-09 17-22-28.ts" as this is BISS.

I believe it's different time, but was told that it was the same. However, it's the same concert for sure.
 
Last edited:

barney115

Donating Member
Staff member
Administrator
Messages
24,761
This file, "12276000-V-7032-2019-06-09 17-22-28.ts", is in BISS and broadcast on 144E and is intended for international broadcasting
Yes its BISS and Decrypted just fine CW is found in V1 03000h Table

Filescccc\12276000-V-7032-2019-06-09 17-22-28_decrypted.ts
trying to sync...
sync at packet 11. using CW #0 "0 0A 22 AA D6 D8 23 81 7C"

 

KenSoftTH

Registered
Messages
36
Yes its BISS and Decrypted just fine CW is found in V1 03000h Table




Right, so we know that C2 144E is BISS, but B3 162E that they are switching to is encrypted with this. I don't think the encryption scheme is related to the satellite, but seems like this is the case here...

I'm going to try Multi2 descrambler, which is what their satelite TV is using. Since their smartcard keys always leak, will try those keys and see how it goes.
 

KenSoftTH

Registered
Messages
36
Yes its BISS and Decrypted just fine CW is found in V1 03000h Table




But just to make sure that this is the case, where can I find ts file encrypted with Multi2 (ARIB STD-B25)?

This guy seems to talk about it...

I'm taking another look at this after a year or so. To summarise:

1. Anubis_Ir reversed this D5/T3 style EC tag ECM, and with the AES keys that were/are available, we are able to see an encouraging cycling pattern of odd/even CWs.
2. Anubis_Ir was the first to point out that the supplied AES IV might be wrong, and we'd still see the CW cycling pattern. Where did that IV come from? And why the doubt - the rest of the reversing appears perfect?
3. The AV (elementary) streams are not crypted with DVB-CSA / 48 bit key - other cyphers must be tried.



Of those candidate cyphers - and there may be others - 3DES & AES can be rejected as their key is > 64 bits.

I'm assuming that the IV *is* correct, then testing different cyphers on the stream. Test method:

1. I've logged ecms covering one crypto period, and captured payloads marked with the PUSI bit set for the same period.
2. After applying the correct key / cypher, the first 3 bytes of those payloads with PUSI bit set should decrypt to known plaintext 00 00 01.

I've tried CSA with uncorrected checksums, both enc & dec. I've tried DES, enc & dec, ecb & cbc. Doesn't seem to be those, but I might be wrong.

Multi2 is new to me, used in the Japanese digital TV standard ARIB B25. There' a variable number of rounds (but it appears 32 are used in Japan). And an extra system_key, quoted in some literature as the same across all DVB usage (or at least that's how I read it).

Anyone know what the needed multi2 DVB system_key might be?
 

fiji

Member
Messages
1,086
Weak signal in dvbcard channel's id called (Nameless)
record .ts file again with strong signal only 5 minuts for analyse .ts file

hers is 12401V12222's weak signal or Nameless result
NWR-12401-V-12222.jpg


hers is 12276V7032's good signal result
wr-12276.jpg


this is cw 12276V7032
12276.jpg


work fine .ts file video decrypt in smartdvb
12276-W.jpg
 

KenSoftTH

Registered
Messages
36
Weak signal in dvbcard channel's id called (Nameless)
record .ts file again with strong signal only 5 minuts for analyse .ts file

hers is 12401V12222's weak signal or Nameless result
NWR-12401-V-12222.jpg


hers is 12276V7032's good signal result
wr-12276.jpg


this is cw 12276V7032
12276.jpg


work fine .ts file video decrypt in smartdvb
12276-W.jpg


The signal is strong, but 12401V12222 probably not BISS. I asked other people to record this TP at different place, but they also get the same result.
 
Top