Authenticated Service Locator Using Broadcast Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content and service providers face increased production and licensing costs due to the need for secure distribution of high-quality content over networks, requiring effective encryption methods that manage data security and access while ensuring compliance with security policies and privacy requirements.

Innovation Solution

The implementation of an enhanced management key block (eMKB) using broadcast encryption, which is digitally signed to authenticate service providers and allows devices to securely locate and access trusted services within a network, utilizing a trusted service locator (TSL) to identify and connect to authorized services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If broadcast encryption is used for secure content distribution, then data security and access control are improved, but device complexity and overhead increase

Engineering Contradiction:
Improvedata securityVSAvoiddevice overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the service location information into authenticated service identifiers that can be independently verified. Devices only need to verify the authenticity of service locations rather than managing complex encryption keys for service discovery, reducing device overhead while maintaining security through segmented verification responsibilities

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where service location information is authenticated by a trusted authority before being distributed to devices. This intermediary layer handles the complex cryptographic operations centrally, allowing devices to simply verify authenticated service locations without bearing the full cryptographic overhead, thus resolving the contradiction between security and device complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional service location methods are used without authentication, then device complexity is reduced, but security and compliance with privacy requirements deteriorate

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity compliance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-authenticating service location information before devices need to use it. Service identifiers are authenticated in advance by a trusted authority and embedded in the service location data structure. When devices need to locate services, they simply verify the pre-authenticated identifiers rather than performing complex security checks, maintaining system simplicity while ensuring security compliance

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables self-service authentication where service location information contains embedded cryptographic proofs that allow devices to independently verify service authenticity without requiring continuous interaction with authentication servers. The authenticated service identifiers carry their own verification credentials, allowing devices to autonomously confirm security compliance while maintaining simple system architecture

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9755836B2Identifying and locating authenticated services using broadcast encryption
Publication Date: 2017.09.05 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9755836B2 patent drawing
  • US9755836B2 patent drawing
  • US9755836B2 patent drawing

AI summary

Provided are techniques to enable, using broadcast encryption, a device to locate a service offered by a server with the knowledge that the service offered by the server is a trusted service. A signed enhanced Management Key Block (eMKB) includes a trusted service locator (TSL) that includes one or more records, or “trusted service data records” (TSDRs), each identifying a particular service and a corresponding location of the service is generated and transmitted over a network. Devices authorized to access a particular service parse the eMKB for the end point of the service, connect to the appropriate server and transmit a request.