View Full Version : Processing Key, Media Key and Volume ID found!!!
XStylus
13th February 2007, 19:15
Wooow. I think I did it :).
Processing Key found!!!
Arnezami, I'll tell you the same thing I told muslix64. Unless you're DVD Jon's neighbor in Norway, PROTECT YOUR IDENTITY. Fixing these DRM crippled technologies is only 75% of the victory. The remaining 25% is in making sure you don't become a martyr.
The greatest victories against the rights-thieving media industries are ones where they are denied their pound of flesh.
I'm also mildly curious as to what Doom9's policies are in case it was ever subpoenaed for IP address info. I know it'd certainly be the toughest decision they'd ever have to make.
Electrox3d
13th February 2007, 19:19
Arnezami, I'll tell you the same thing I told muslix64. Unless you're DVD Jon's neighbor in Norway, PROTECT YOUR IDENTITY. Fixing these DRM crippled technologies is only 75% of the victory. The remaining 25% is in making sure you don't become a martyr.
The greatest victories against the rights-thieving media industries are ones where they are denied their pound of flesh.
There's no law against opening up a .aacs or .inf file on a disc and looking around. Or looking at what your computer is putting into memory... or what information is streaming across usb...
XStylus
13th February 2007, 19:30
There's no law against opening up a .aacs or .inf file on a disc and looking around. Or looking at what your computer is putting into memory... or what information is streaming across usb...
For the purpose of argument, I will agree. However, if the information you discover is disseminated and implemented for the purpose of circumventing a copy protection measure, it is illegal in countries with DMCA-like legislation.
Doom9
13th February 2007, 19:37
didn't we head down that road again before and didn't I put up a hefty roadblock?
bob0r
13th February 2007, 19:45
So for the retards like me:
I have a movie, encrpyted, copied via the PS3 on my HDD, no computer hddvd player or bluray player, only a computer with software.
I have mkb.exe and BackupBluRay, can one now make a working copy on a computer using just this software, or do i still need a hddvd player or in this case bluray player?
Electrox3d
13th February 2007, 19:58
fyi, anydvd hd is in beta... http://forum.doom9.org/showthread.php?t=122174
XStylus
13th February 2007, 20:24
didn't we head down that road again before and didn't I put up a hefty roadblock?
I'll have to plead felony stupid on this one and ask which/when/where/what you're referring to. ^^;;;
arnezami
13th February 2007, 20:57
Yup, I opened Unit_Key_RO.inf and found that CPS Unit Key.
81 9C CC E5 F7 FC F2 C8 F3 0F D5 59 F0 DD CA 0E
Awesome!
Great! No Bus decryption on Blu-ray drives yet and its confirmed Blu-ray uses the same Processing Key as HD DVD. :D
Very good news indeed :).
@FoxDisc: i'm working on something. Please have patience. I need to take time to put it all together and make it comprehensible for everyone (given my available time this could take a couple of days). You've got pretty much everything right. The role of the Processing Key will be explained ;).
hd1080p
13th February 2007, 21:11
Arnezami did no wrong. He studied the publicly available AACS specs and really understood them in and out. And then he knew when, where and when to look. There is no law against someone who looked and he didn't steal anything. He just found the keys under the doormat and he didn't go in. Arnezami has nothing to worry about and he didn't violate any copyright laws. He did it for the challenge and the thrill of discovery.
Arnezami, I'll tell you the same thing I told muslix64. Unless you're DVD Jon's neighbor in Norway, PROTECT YOUR IDENTITY. Fixing these DRM crippled technologies is only 75% of the victory. The remaining 25% is in making sure you don't become a martyr.
The greatest victories against the rights-thieving media industries are ones where they are denied their pound of flesh.
I'm also mildly curious as to what Doom9's policies are in case it was ever subpoenaed for IP address info. I know it'd certainly be the toughest decision they'd ever have to make.
Doom9
13th February 2007, 21:13
For those who didn't catch my hint: stay on topic. Stuff about "protect your identity", and legal discussion don't belong neither in this thread nor in this subforum. I've warned people about that in the backuphddvd thread a while back and I'm very disappointed that I have to sing the same song again so soon.
Founditalso
13th February 2007, 22:14
Please post Volume IDs of this type (if you find any)
Appollo 13:
Hex: 40 00 04 06 32 04 20 11 57 47 48 44 56 4D 00 00
Ascii: W G H D V M
Batman Begins:
Hex: 40 00 40 06 26 08 10 15 57 47 48 44 56 4D 00 00
Ascii: W G H D V M
Please help us here. :)
This could be very useful in determining a way of guessing the Volume IDs for HD DVDs (which might be the reason AnyDVD is only supporting HD DVD atm ;)).
Are you still interested in HD DVD Volume ID's?
Name and file date and time (mm/dd/yyyy hh:mm):
VID:
Constantine 05/12/2006 5:05
40 00 30 06 53 05 16 11 57 47 48 44 56 4d 00 00
16 Blocks 05/18/2006 2:48
40 00 07 06 02 05 17 17 57 47 48 44 56 4d 00 00
Kiss Kiss Bang Bang 05/25/2006 4:07
40 00 12 06 51 05 15 24 57 47 48 44 56 4d 00 00
Lady in the Water 10/19/2006 8:36
40 00 08 06 16 10 23 18 57 47 48 44 56 4d 00 00
MI3 10/03/2006 15:34
40 00 20 06 10 03 07 19 00 20 20 20 20 20 00 00
Miami Vice 11/17/2006 8:13
40 00 11 16 20 06 08 28 00 20 20 20 20 20 00 00
Swordfish 04/15/2006 2:10
40 00 53 57 4f 52 44 46 49 53 48 20 20 20 00 00
The Matador 10/19/2006 20:41
40 00 ba be 00 00 00 00 00 00 00 00 00 1c 00 00
Enjoy!
melakai
13th February 2007, 22:26
Are you still interested in HD DVD Volume ID's?
Yes, we've got a sticky for them: http://forum.doom9.org/showthread.php?t=120611
FoxDisc
13th February 2007, 22:36
@FoxDisc: i'm working on something. Please have patience. I need to take time to put it all together and make it comprehensible for everyone (given my available time this could take a couple of days). You've got pretty much everything right. The role of the Processing Key will be explained ;).
@arnezami: Thanks for the quickie reply - it's truly appreciated. There's certainly no hurry - take your time. Do whatever you think is most important first. I'm just trying to understand the whole picture.
Founditalso
13th February 2007, 22:38
Yes, we've got a sticky for them: http://forum.doom9.org/showthread.php?t=120611
The sticky is for VUK's.
Mine are VID's ;)
arnezami
13th February 2007, 23:01
@Founditalso: Thanks. I'm just looking if there is an easy way to predict these Volume IDs. Maybe there are too many types and we have to find and reveal the private host key (or just accept sniffing as part of the process).
Constantine 05/12/2006 5:05
Hex: 40 00 30 06 53 05 16 11 57 47 48 44 56 4d 00 00
Ascii: W G H D V M
16 Blocks 05/18/2006 2:48
Hex: 40 00 07 06 02 05 17 17 57 47 48 44 56 4d 00 00
Ascii: W G H D V M
Kiss Kiss Bang Bang 05/25/2006 4:07
Hex: 40 00 12 06 51 05 15 24 57 47 48 44 56 4d 00 00
Ascii: W G H D V M
Lady in the Water 10/19/2006 8:36
Hex: 40 00 08 06 16 10 23 18 57 47 48 44 56 4d 00 00
Ascii: W G H D V M
Appollo 13:
Hex: 40 00 04 06 32 04 20 11 57 47 48 44 56 4D 00 00
Ascii: W G H D V M
Batman Begins:
Hex: 40 00 40 06 26 08 10 15 57 47 48 44 56 4D 00 00
Ascii: W G H D V M
The 06 is very likely YY. So I suspect the other numbers have something to do with time/date or something aswell. The last two bolded ones look like HHMM.
MI3 10/03/2006 15:34
40 00 20 06 10 03 07 19 00 20 20 20 20 20 00 00
This is YYYYMMDD HHMM probably (ISO format).
Miami Vice 11/17/2006 8:13
40 00 11 16 20 06 08 28 00 20 20 20 20 20 00 00
This is MMDDYYYY HHMM probably (US format).
Swordfish 04/15/2006 2:10
40 00 53 57 4f 52 44 46 49 53 48 20 20 20 00 00
Simple: SWORDFISH
The Matador 10/19/2006 20:41
40 00 ba be 00 00 00 00 00 00 00 00 00 1c 00 00
This seems to be a new type. Are you really sure this one is correct?
FoxDisc
13th February 2007, 23:03
I'm just trying to understand the whole picture.
I realized that I had been looking at the wrong part of the AACS specs. I was looking at the HD-DVD recorded specs, when I needed to look at the introduction and common crypto specs. Section 3.2.4 tells how to calculate the Media key:
Once the device has the correct Device Key D, it calculates a Processing Key K using AES-G3 as described
above. Using that Processing Key K and the appropriate 16 bytes of encrypted key data C, the device calculates
the 128-bit Media Key Km as follows:
Km = AES-128D(K, C) ⊕ (00000000000000000000000016 || uv)
The appropriate encrypted key data C is found in the Media Key Data Record in the Media Key Block.
This gives me the big picture - we don't have a device key, but we've got an intermediate key that the device key gives us that is disk independent and leads to the same answer as the device key would get us. Of course, I'd still love to read arnezami's description later. I'm still working on the whole leaf/node business.
SvT
13th February 2007, 23:20
[code]Constantine 05/12/2006 5:05
Hex: 40 00 30 06 53 05 16 11 57 47 48 44 56 4d 00 00
16 Blocks 05/18/2006 2:48
Hex: 40 00 07 06 02 05 17 17 57 47 48 44 56 4d 00 00
Kiss Kiss Bang Bang 05/25/2006 4:07
Hex: 40 00 12 06 51 05 15 24 57 47 48 44 56 4d 00 00
Lady in the Water 10/19/2006 8:36
Hex: 40 00 08 06 16 10 23 18 57 47 48 44 56 4d 00 00
The 06 is very likely YY. So I suspect the other numbers have something to do with time/date or something aswell. The last two bolded ones look like HHMM.
The 2 before that look like MM or is that just luck ?
Founditalso
13th February 2007, 23:24
The Matador 10/19/2006 20:41
40 00 ba be 00 00 00 00 00 00 00 00 00 1c 00 00[/code]
This seems to be a new type. Are you really sure this one is correct?
Matador is a special case. The disc doesn't play with WinDVD 8 HD. WinDVD stops working and I do not even see the black screen. I do have a log file with the VID however.
When I play it with PowerDVD 7.1 HD it starts but then I get a screen that says that because of parental settings of the player the disc does not play. When I sniff PowerDVD I get the same VID however.
BTW Did you know that the VID's can be found with WinDVD as wel as with PowerDVD? I checked with King Kong and it works (but maybe that is normal).
So with respect to The Matador, as PowerDVD and WinDVD give the same VID, I guess that is what it is?
If you want me to check other things, I have both HD and BD, just let me know.
salkku
13th February 2007, 23:43
Great work indeed :) ( tho I don't have either of those players )
I wonder why some people don't want to "reveal the cards". I mean, in general sense, nothing gets done if we keep postponing things.
I also wonder why the media corporations try to produce some naive protection technology on audio and/or video at all, because the protections can and and will be broken. If nothing else helps, one can just record the HD-show with his HD-videocam.
He-Man
14th February 2007, 01:07
@Founditalso: Thanks. I'm just looking if there is an easy way to predict these Volume IDs. Maybe there are too many types and we have to find and reveal the private host key (or just accept sniffing as part of the process).
Constantine 05/12/2006 5:05
Hex: 40 00 30 06 53 05 16 11 57 47 48 44 56 4d 00 00
Ascii: W G H D V M
16 Blocks 05/18/2006 2:48
Hex: 40 00 07 06 02 05 17 17 57 47 48 44 56 4d 00 00
Ascii: W G H D V M
Kiss Kiss Bang Bang 05/25/2006 4:07
Hex: 40 00 12 06 51 05 15 24 57 47 48 44 56 4d 00 00
Ascii: W G H D V M
Lady in the Water 10/19/2006 8:36
Hex: 40 00 08 06 16 10 23 18 57 47 48 44 56 4d 00 00
Ascii: W G H D V M
Appollo 13:
Hex: 40 00 04 06 32 04 20 11 57 47 48 44 56 4D 00 00
Ascii: W G H D V M
Batman Begins:
Hex: 40 00 40 06 26 08 10 15 57 47 48 44 56 4D 00 00
Ascii: W G H D V M
The 06 is very likely YY. So I suspect the other numbers have something to do with time/date or something aswell. The last two bolded ones look like HHMM.
Blue = YY (year)
Red = MM (month)
Orange = DD minus 1 (date)
I guess the two bytes in between YY, MM & DD are mm (minute) and hh (hour) respectively and the byte before YY is probably ss (second).
So the embedded time and date stamp is probably in this order: 40 00 ss YY mm MM hh DD 57 47 48 44 56 4D 00 00
melakai
14th February 2007, 01:34
The sticky is for VUK's.
Mine are VID's ;)
terribly sorry, i stand corrected!
xyz987
14th February 2007, 02:39
So for the retards like me:
I have a movie, encrpyted, copied via the PS3 on my HDD, no computer hddvd player or bluray player, only a computer with software.
I have mkb.exe and BackupBluRay, can one now make a working copy on a computer using just this software, or do i still need a hddvd player or in this case bluray player?
Nowadays you still need an USB BluRay player, an USB sniffer, and an authorized BluRay soft player (WinDVD or alike).
However, it is just a cuestion of time (probably months) you will just need the PS3 conected to your PC through home network, with appropiate programs running on both sides.
Basically what you need is an "USB sniffer and network redirector". In fact two: a host version for PC and a client version for PS3.
jokin
14th February 2007, 02:49
Nowadays you still need an USB BluRay player, an USB sniffer, and an authorized BluRay soft player (WinDVD or alike).
However, it is just a cuestion of time (probably months) you will just need the PS3 conected to your PC through home network, with appropiate programs running on both sides.
Basically what you need is an "USB sniffer and network redirector". In fact two: a host version for PC and a client version for PS3.
Theoretically you can put any IDE / SATA Blu-Ray drive in an external USB case.
xyz987
14th February 2007, 02:55
Theoretically you can put any IDE / SATA Blu-Ray drive in an external USB case.
So it becomes an USB BluRay player ;-)
jokin
14th February 2007, 04:33
Just found a little tidbit of information on the 360 HD drive. My friend installed my HD drive on his 360 a week or so ago to try it out. He then returned it to me and borrowed it again yesterday and it still worked without installing the software again. Today he bought his drive and plugged it in. It asked for the install disc to update the software. Could this be installing the device keys on the drive or the 360 itself with the included disc?
arnezami
14th February 2007, 05:55
Blue = YY (year)
Red = MM (month)
Orange = DD minus 1 (date)
I guess the two bytes in between YY, MM & DD are mm (minute) and hh (hour) respectively and the byte before YY is probably ss (second).
So the embedded time and date stamp is probably in this order: 40 00 ss YY mm MM hh DD 57 47 48 44 56 4D 00 00
Just Brilliant. I think you nailed that one :).
Founditalso
14th February 2007, 07:25
Just Brilliant. I think you nailed that one :).
Does anybody know the date and time of the files on Batman Begins and Apollo 13?
HD Hell
14th February 2007, 07:30
Congratulations, arnezami (and others!) - stunning!
Exiton
14th February 2007, 13:07
So will this make a stand alone app to retrieve keys? Or still work with a software player and get the key from an error memory dump?
FoxDisc
14th February 2007, 15:47
So will this make a stand alone app to retrieve keys? Or still work with a software player and get the key from an error memory dump?
I'm going to take a shot at answering this. I'm nowhere near to fully understanding the whole system, so take this for what it's worth - and wait for someone to correct me if I'm wrong.
I think the answer is yes, this could make a stand alone app. I think there's enough here for someone to make a software player.
I think the app would stop working if and when the AACSLA changes the MKB.
Obviously, the app would have to read data off the disk. I'm assuming that's possible IOW, I'm assuming that there is nothing in the firmware of the drives being sold that reads an HD or BD disk and says to itself "I'm not authorized to tell the PC what's in the MKB of this disk" or that if there is such a thing that the drive firmware could be cracked/hacked to allow the MKB to be read. I've read the AACS specs about Drive Revocation Lists (drive=the optical drive) and Host Revocation Lists (host=the software player) and I'm not fully certain of the implications of those lists.
I'm also assuming that the Processing Key we have now would not equal a new Processing Key calculated from a future disk released with a new MKB. After a drive revocation and new MKB, someone would again have to find the new Processing Key/Device Key. (It would be stupid to design AACS so that a revoked device key could not calculate the Processing key from the new MKB, but if it could calculate it, the answer would be the same as it would have gotten by calculating the processing key from an older MKB with the revoked device key. Of course, I can't really say with any authority how stupid/smart the AACS system might be.)
brand1130x
14th February 2007, 17:47
how impossible would it be to find the master key? and what could you do with it?
evdberg
14th February 2007, 17:59
As far as I know there is no such thing as a 'master key', so it will be very hard to find ...
brand1130x
14th February 2007, 18:12
so is this processing key the "holy grail" of keys?
SBeaver
14th February 2007, 18:30
so is this processing key the "holy grail" of keys?
A complete list of device keys would be great aswell
xdvst8x
14th February 2007, 18:51
i have both a sony internal blu-ray drive and a plextor drive.
it will not let me watch the movie.. i have both win dvd bd and power dvd bd neither will even try to play the disc.
i can read the drive contents though my computer.
and i have copied Mission Impossible. but i am unable to get win dvd bd to open the disc so i can extract keys.. i have about 64 bd titles now.. please advise.
Electrox3d
14th February 2007, 18:54
So, after more research, I found that a month ago there was a post here at doom9 ( http://forum.doom9.org/showthread.php?t=120988 )with tons of blu-ray keys, and even a program that pulls the keys automatically if you have WinDVD. Why did we do this all over again in this thread?
BTW- using the keys already found in the other thread I was able to get a 1080p blu-ray preview playing in WMV on the Xbox 360... next to try it with H.264 for PS3...
madshi
14th February 2007, 19:15
So, after more research, I found that a month ago there was a post here at doom9 ( http://forum.doom9.org/showthread.php?t=120988 )with tons of blu-ray keys, and even a program that pulls the keys automatically if you have WinDVD. Why did we do this all over again in this thread?
Perhaps you should reread this thread.
FoxDisc
14th February 2007, 19:24
As far as I know there is no such thing as a 'master key', so it will be very hard to find ...
Your posts demonstrate a high level of knowledge, so I'm reluctant to disagree, but the AACS LA has the ability to generate a new MKB that revokes some device keys, but not others, and they can generate new device keys that will work with new and old MKBs. No one here can do any of this. The AACS LA has secret keys that are used to perform those functions. If people here had the key(s) they have locked in their vaults, they could generate device keys, new MKBs, etc. and the system would be forever broken.
That's why no one here can say that the AES/AACS system has been cracked - it's only been bypassed. Getting the secret keys stored in the AACS LA vault will be very very very hard. Cryptographically, the AES/AACS system is very very good and not likely to be broken soon.
It was bypassed because the whole concept of encrypting something that you have to let the recipient decrypt is a fundamentally flawed concept. They have to give out the keys to millions of people so they can watch the encrypted movies - how can they expect to keep them secret? The only thing they can keep secret is how to make the keys they give out.
FoxDisc
14th February 2007, 19:52
so is this processing key the "holy grail" of keys?
No. It's a key derived from a device key and other information on a disk that allows other keys to be calculated, ultimately leading to the final title key that decrypts the video data. It appears to have the advantage that every device key currently issued (these are in the players) when used with the current MKB on every disc currently issued (BuRay and HD-DVD) results in this same Processing Key, which then leads to the correct Title Key. If I understand it correctly, this Processing Key will no longer work with new disks if the new disks are provided with a new MKB.
There are currently two AACS bypass methods. One is this Processing Key, which works for all disks and comes from sniffing the USB connection, and one is the Title Key/Volume Unique Key which works for only the specific disk it was obtained from and comes from the memory dump of a player while playing that disk.
What can they do to stop future bypasses? I don't honestly know for sure, and I'd trust Arnezami's analysis, more than anything I say here, but I'll take a stab at it:
To stop the first method (described in this thread), they will have to make the Processing Key that is currently being calculated from the current device keys and MKBs not work. I think that means they have to change the MKB on new disks (this is a fairly big deal, but it's part of their designed in system). Second, they'll have to try to prevent the new Processing Key from being sniffed as this one was.
To stop the second method (title key from mem dump), they could simply have the offending software rewritten to try to make it harder to locate the title key.
I suppose they could stop allowing software players altogether, making it harder to implement either method, as hardware extraction is more difficult than hacking a PC. The battle goes on, but I'm putting my money on the people here who don't want DRM and do want to make fair use of what they buy. Either way, it's interesting to watch.
Electrox3d
14th February 2007, 19:52
Perhaps you should reread this thread.
I have been following this thread... I in fact tested if Blu-ray worked the same as HD-DVD... but I guess I needed to learn more about what happened a month ago before I really understood what we were doing here.
From what I understand a month ago every movie had a different key, but now we've found a type of universal key that both hd-dvd and blu-ray use? Hope thats close.
EDIT: FoxDisc, your post above mine really helped me to understand this thread better. Thanks!
oddball
14th February 2007, 19:54
Which is why it's probably worthless even trying. Just bypass it altogether like it is now and wait for updates once/if they change things. They are probably relying on this fact to slowdown the process.
FoxDisc
14th February 2007, 20:26
EDIT: FoxDisc, your post above mine really helped me to understand this thread better. Thanks!
You are welcome, but I've tried to emphasize that I do not see the entire picture yet, and what I do see is not all that clear. I hope this isn't just thread clutter. There are lots of things I said that are perhaps not true, and lots of details I glossed over that might change things. For example, I said the Processing Key works with all disks and all device keys used with all MKBs to end up with the same processing key. I really doubt that all disks have been checked - This thread only seems to list a dozen or so. Perhaps it won't work with some.
Also, there are lots of details in the whole chain of decryption from device keys to title keys via the MKB. Device Keys are used to calculate Subsidiary Device Keys and Processing Keys. The Processing Key is used with the encrypted key data C (found in the MKB) to create the Media Key....etc.
I think they can make the Processing Key invalid without revoking any Device Keys, simply by changing the MKB (maybe changing the key data C), but I'm not sure. I think they have some options with encrypting the USB communication, but I'm not sure. I think they have some options relating to interaction between the optical drive and the disk before any data gets delivered by the drive to the PC via the USB bus, but I'm not sure. You get the idea. As I said, it will be interesting to see how this all plays out.
guile
14th February 2007, 22:02
Silly question. I am VERY interested in this amazing development and have been following this thread. My question is with regards to Blu Ray. I do NOT have a hdcp compliant rig but do in fact have a Blu Ray drive (which I plan on housing in an external usb enclosure for experimenting). Powerdvd blu ray will not play but....will play for about 5 seconds (as we all know) before giving me the usuall "Non compliant setup" message.
Will this few seconds of playback be enough to extract anything? Or would it actually have to be the "Movie" (rather then the FBI warning that is usually in the first few seconds of playback). Thanks
g
Electrox3d
14th February 2007, 22:26
Silly question. I am VERY interested in this amazing development and have been following this thread. My question is with regards to Blu Ray. I do NOT have a hdcp compliant rig but do in fact have a Blu Ray drive (which I plan on housing in an external usb enclosure for experimenting). Powerdvd blu ray will not play but....will play for about 5 seconds (as we all know) before giving me the usuall "Non compliant setup" message.
Will this few seconds of playback be enough to extract anything? Or would it actually have to be the "Movie" (rather then the FBI warning that is usually in the first few seconds of playback). Thanks
g
This is probably enough to sniff, I only had the movie play for about 1 second before I closed the program.
Also, if it ends up it doesn't work, then you could always just plug in a VGA monitor, HDCP doesn't activate with VGA cause its analog.
Multiplex
14th February 2007, 22:39
Q. Will this few seconds of playback be enough to extract anything?
A. Yes. By the time you see video, the VID is posted to the bus.
Q. What about non-usb connections?
A. Two words: Bus Hound.
Q. Can the drive read the MKB?
A. If I read AACS correctly, part of the MKB can live in the disc lead-in. That is outside file space, so it could be tricky on the host end to get at that part. Still, a read is a read. It's not like CSS, where you can't even read the sectors without a encrypted handshake.
Q. I hate searching gobs and gobs of bus traces
A. The VID is returned in response to a READ DVD STRUCTURE command AD 01 00 00 00 00 00 80. Find that going to the drive, and the data back contains the VID. There are maybe 7 total AD 01 commands in a whole disk trace.
Q. Can somebody just write a utility to grab a media VID from the drive?
A. Yes. It's trivial. Just send around 8 ATAPI commands in a row. The difficulty is that you'll need a trusted player key to establish a bus handshake before READ DVD STRUCTURE will give you a key back. Exposing a trusted player key this way will lead to its being killed sooner than later.
xyz987
15th February 2007, 01:06
Q. Can the drive read the MKB?
A. If I read AACS correctly, part of the MKB can live in the disc lead-in. That is outside file space, so it could be tricky on the host end to get at that part. Still, a read is a read. It's not like CSS, where you can't even read the sectors without a encrypted handshake.
No, MBK is entirely on a file. VolumeID is outside file space.
Note VolumeID is not encrypted. If you hack your device firmware you don't need USB sniffing, neither bus handshake.
Xbox HD-DVD drive and PS3 are good candidates for firmware hacking. It is necessary a hight level to hack a firmware, but not so hight to "update" firmware to a hacked one.
xyz987
15th February 2007, 02:09
As far as I know there is no such thing as a 'master key', so it will be very hard to find ...
You are probably right (I am still trying to understand AACS).
Note however there are just 253 Device Keys per product (a BluRay home theater, for instance). As far as i can see, if there is no such "master key", after 253 Device Key revocations some legitime players will stop playing newly released movies.
Is it so easy?. Do we need just to get 253 Device Keys from different players to break the revocation system?
arnezami
15th February 2007, 07:15
You guys are asking all the right questions ;).
Because you are so eager I will give you a little sneak peak of what is to come:
http://img264.imageshack.us/img264/9025/tst7iu8.png
Thats a blue truck with a looong trailer and no reverse... (and some Parking spots)
Regards,
arnezami
PS. I will have lots of time tomorrow (and in the weekend) so hopefully you won't have to wait too long :).
jokin
15th February 2007, 07:20
Lol , ok looks good but I hope the truck has brakes to keep from rolling back down the hill.
xyz987
15th February 2007, 14:22
I think I am starting to understand how this thing works. AACS LA gives each player manufacturer a set of Device Keys (probably just ramdom keys). Each time a movie is printed AACS LA gives disk replicator a Media Key (a ramdom key) and a MKB, i.e. a set of copies of the encrypted Media Key. Each copy is just the Media Key encrypted with a different Device Key. AACS LA chooses the Device Keys to generate MKB in a way that any non-revoked player has at least one Device Key that can decrypt one of the copies of the encrypted Media Key.
Disk replicator combine Media Key with a VolumeID they choose (VolumeID is just to avoid bit-per-bit home disk copying) to produce Volume Key. The movie is encrypted using a random key (Title Key) and the Title Key is encrypted with the Volume Key.
Players just read MKB, look for the fist copy of the encrypted Media Key they can decrypt (because player has the Device Key it was used to encrypt this copy of the Media Key), and get it decrypted. Then they read VolumeID (with a previous cryptographic handshake in case of soft players), calculate Volume Key, use it to decrypt Title Key, and decrypt the movie.
However, I still don't understand the role of the Processing Key. It seems that the Processing Key is just a Device Key. Why it is named differently?
vBulletin® v3.8.11, Copyright ©2000-2026, vBulletin Solutions Inc.