Authenticated Service Locator Using Broadcast Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Content and service providers face increased production and licensing costs due to the need for secure distribution of high-quality content over networks, requiring effective encryption methods that manage data security and access while ensuring compliance with security policies and privacy requirements.
Innovation Solution
The implementation of an enhanced management key block (eMKB) using broadcast encryption, which is digitally signed to authenticate service providers and allows devices to securely locate and access trusted services within a network, utilizing a trusted service locator (TSL) to identify and connect to authorized services.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If broadcast encryption is used for secure content distribution, then data security and access control are improved, but device complexity and overhead increase
Solution Approach 1:
The patent segments the service location information into authenticated service identifiers that can be independently verified. Devices only need to verify the authenticity of service locations rather than managing complex encryption keys for service discovery, reducing device overhead while maintaining security through segmented verification responsibilities
Solution Approach 2:
The patent introduces an intermediary mechanism where service location information is authenticated by a trusted authority before being distributed to devices. This intermediary layer handles the complex cryptographic operations centrally, allowing devices to simply verify authenticated service locations without bearing the full cryptographic overhead, thus resolving the contradiction between security and device complexity
2Device complexity
If traditional service location methods are used without authentication, then device complexity is reduced, but security and compliance with privacy requirements deteriorate
Solution Approach 1:
The patent applies preliminary action by pre-authenticating service location information before devices need to use it. Service identifiers are authenticated in advance by a trusted authority and embedded in the service location data structure. When devices need to locate services, they simply verify the pre-authenticated identifiers rather than performing complex security checks, maintaining system simplicity while ensuring security compliance
Solution Approach 2:
The patent enables self-service authentication where service location information contains embedded cryptographic proofs that allow devices to independently verify service authenticity without requiring continuous interaction with authentication servers. The authenticated service identifiers carry their own verification credentials, allowing devices to autonomously confirm security compliance while maintaining simple system architecture
Data Source
AI summary
Provided are techniques to enable, using broadcast encryption, a device to locate a service offered by a server with the knowledge that the service offered by the server is a trusted service. A signed enhanced Management Key Block (eMKB) includes a trusted service locator (TSL) that includes one or more records, or “trusted service data records” (TSDRs), each identifying a particular service and a corresponding location of the service is generated and transmitted over a network. Devices authorized to access a particular service parse the eMKB for the end point of the service, connect to the appropriate server and transmit a request.


