Conditional Access & SimulCrypt
Conditional access is two systems, not one: a standardised layer that scrambles payloads, and a proprietary layer that distributes the keys. Separate those and everything else follows. The values, the tables and the failure modes, without the prose.
The split that explains everything
Scrambling layer
Standardised. One algorithm, fully interoperable. Encrypts payloads with a control word. ETSI TS 100 289, TS 103 127.
Conditional access layer
Proprietary. Delivers that control word only to entitled receivers. TS 103 197 standardises the interfaces, never the system.
Scrambling control bits — the whole signalling
| Bits | Meaning |
|---|---|
| 00 | Not scrambled at this level (MPEG-2 compliant) |
| 01 | Reserved for future DVB use |
| 10 | Scrambled with the even key |
| 11 | Scrambled with the odd key |
00 at TS level does not prove clear content — PES-level scrambling may still apply.
Why two keys
A crypto period is the span during which one control word is in use. With a single key register, the changeover would be a race the receiver has to win with no tolerance. Two registers remove the race: while the even key is scrambling, the next control word is already loaded into the odd register, and the parity bit in each packet header says which to use.
Never scrambled
| Element | Why it stays clear |
|---|---|
| TS packet header | Holds the PID and the scrambling bits themselves |
| Adaptation field | Carries the PCR — clock lock must work without any key |
| PES header | Required clear by ISO/IEC 13818-1; PTS/DTS must be readable |
| PSI / SI sections | PAT, PMT, CAT must be readable to find anything at all |
| ECM / EMM streams | Carry their own CA encryption — scrambling them would be circular |
| Null packets | Stuffing carries no information |
The four algorithms
| Algorithm | Key | Built from |
|---|---|---|
| DVB-CSA v1 | 64-bit | Block + stream cipher. The default when no scrambling_descriptor is present |
| DVB-CSA v2 | 64-bit | As v1, revised key schedule. The long-standing broadcast workhorse |
| DVB-CSA v3 | 128-bit | AES′ (an AES-128 variant per FIPS 197) + XRC, which is DVB-confidential |
| DVB-CISSA v1 | 128-bit | Plain AES-128-CBC, constant IV. Fully public — and the scrambler in BISS2 |
scrambling_mode coding
| Value | Algorithm |
|---|---|
| 0x01 | DVB-CSA v1 — assumed when the descriptor is absent |
| 0x02 | DVB-CSA v2 |
| 0x03 | DVB-CSA v3 |
| 0x04 – 0x05 | User defined, for CSA v3 |
| 0x70 – 0x7F | ATIS defined |
| 0x80 – 0xFE | User defined |
| 0x00, 0x06–0x6F, 0xFF | Reserved |
ECM vs EMM
| ECM | EMM | |
|---|---|---|
| Carries | The control word + access criteria | Subscriber entitlements |
| Addressed to | Everyone watching the service | One receiver, or a group |
| Timescale | Seconds | Hours to weeks |
| Found via | CA_descriptor in the PMT | CA_descriptor in the CAT |
| Scope | Per service, sometimes per component | Multiplex-wide |
| If missing | Nothing descrambles, at once | Works until entitlements expire, then stops |
SimulCrypt in one paragraph
Content is scrambled once, with one control word. That control word is handed to every participating CA system, and each generates its own ECM stream carrying it under its own keys. The multiplex carries parallel ECM and EMM streams — one set per CA system — all describing the same scrambled payload. A receiver finds the CA_system_ID it knows and ignores the rest.
Head-end components (the names in vendor logs)
| Acronym | Role |
|---|---|
| SCS | SimulCrypt Synchronizer — the orchestrator. Talks to every ECMG, allocates ECM stream IDs, syncs ECMs to crypto periods, feeds the scrambler |
| ECMG | Takes a control word + access criteria, returns an ECM. Supplied by the CA vendor |
| EMMG | Produces EMMs from the subscriber database |
| CWG | Control Word Generator — one per crypto period |
| EIS / ACG | Event scheduler and access-criteria generator |
| C(P)SIG | Lets a CA system insert its own PSI/SI descriptors |
0x03. The two messages that carry real work: CW_provision (0x0201) and ECM_response (0x0202).
BISS — for contribution, not distribution
| Mode | Key handling |
|---|---|
| Mode 0 | No scrambling |
| Mode 1 | Session word (SW) sent out of band. For short-term events |
| Mode E | SW encrypted with a fixed session key → ESW, still out of band. Backward compatible with Mode 1 |
| Mode CA | ESW + key management travel in the stream, via ECM/EMM |
Where descrambling happens
| Placement | Trade-off |
|---|---|
| CI/CI+ slot at the tuner | Simple, but the module must be physically at the tuner. One or two services typically |
| DDCI (decoupled CI) | CAM addressable independently of the receiving tuner — breaks the adjacency requirement |
| Professional multi-CAM farm | Descrambles an incoming MPTS centrally. Scales; higher capital cost |
| Software client to a card server | Most flexible, no per-stream hardware. Needs a software descrambler |
The five that most often bite
Check ECM insertion timing against the crypto period, and whether one parity's ECM is being filtered out somewhere. Not a signal problem.
Entitlements expiring with no refresh. Failure order follows expiry dates, not the fault. Monitor EMM continuity, not just ECM presence.
ECM generation is missing the parity flip. Shortening the crypto period makes this worse, not better — it cuts the time available for the round trip.
Many clients reject a service whose PMT names a CA system they cannot see. Strip CA information from the PSI — that is what --cleanpsi does.
Check scrambling_mode. With no scrambling_descriptor present, a receiver must assume CSA v1 — which is often not what is actually in use.
transport_scrambling_control bits. They are in the clear in every packet header, and they settle whether the content is scrambled at all — and on which parity — before any deeper investigation.