Blockchain Access Control for Encrypted Broadcast Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control techniques for broadcasted data, such as pay TV services, are vulnerable to interception and illicit sharing due to the potential fraudulent use of authentic smartcards and decoders, which can be cloned or used in unauthorized conditions, leading to unauthorized access.

Innovation Solution

Implementing a blockchain-based access control system where validator devices validate access requests and update the blockchain with new blocks, ensuring that only authorized access devices receive cryptographic information for decrypting the data, thereby preventing unauthorized access and reducing the need for frequent key changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If smartcards and decoders are used for access control in broadcast systems, then authorized users can decrypt and access the data, but the system becomes vulnerable to cloning and fraudulent use

Engineering Contradiction:
Improveaccess control securityVSAvoidcloning and fraudulent access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a blockchain-based intermediary system that acts as a trusted mediator between the broadcast provider and access devices. Instead of relying solely on vulnerable smartcards, the system uses a distributed ledger where access rights are verified through cryptographic proofs and validator consensus. This intermediary layer prevents cloning by ensuring that each access request is independently validated against the immutable blockchain records, thereby maintaining security while eliminating the single-point-of-failure vulnerability of traditional smartcard systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the physical smartcard mechanism with a cryptographic system based on blockchain technology. Instead of relying on physical cards that can be cloned or stolen, the system uses digital signatures, public-key cryptography, and distributed consensus mechanisms. Access rights are represented as cryptographic tokens on the blockchain rather than physical credentials, fundamentally substituting the mechanical/card-based access control system with a software-based cryptographic verification system that is inherently more resistant to cloning.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If control words are changed frequently to prevent piracy, then security is improved, but the complexity and frequency of key management increases

Engineering Contradiction:
Improvepiracy preventionVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-generating and storing multiple control words and their corresponding cryptographic proofs on the blockchain before they are needed. When a control word change is required, the system has already prepared the next control word and its validation mechanism in advance, recorded on the immutable ledger. This eliminates the complexity of real-time key generation and distribution, as all necessary cryptographic materials are prepared beforehand and made available through the decentralized blockchain network, reducing both complexity and transmission overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing access devices to autonomously retrieve and validate control words directly from the blockchain without requiring centralized key distribution infrastructure. Each access device maintains its own cryptographic keys and can independently verify control word changes by checking the blockchain records. This self-service mechanism eliminates the need for complex centralized key management systems and reduces the frequency of manual key updates, as the system automatically manages control word rotation through the decentralized ledger.

Inventive Principle:
Principle #25Self-service

3Device complexity

If centralized access control systems are used, then key management is simplified, but centralized vulnerabilities create security risks

Engineering Contradiction:
Improvekey management simplicityVSAvoidsystem vulnerability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent applies segmentation by dividing the centralized key management function into multiple distributed validator nodes that collectively maintain the blockchain. Instead of a single centralized authority holding all keys, the system segments the trust model across multiple independent validators who each hold portions of the cryptographic infrastructure. Access control decisions are made through consensus among these segmented validators rather than by a single point of control. This segmentation eliminates the centralized vulnerability while distributing the management complexity across the network, achieving both security and manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11968291B2Access to data broadcast in encrypted form based on blockchain
Publication Date: 2024.04.23 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11968291B2 patent drawing
  • US11968291B2 patent drawing
  • US11968291B2 patent drawing

AI summary

A solution is proposed for controlling access to data that are broadcast over a telecommunication medium. A corresponding method comprises validating by a plurality of validator devices an access request that is submitted by an access device for accessing the data. The validator devices update a blockchain by adding a new block comprising an indication of the access request in response to a positive result of its validation. A provider system transmits cryptographic information for decrypting the data to the access device in response to the new block. A corresponding method for broadcasting data by a provider system and a corresponding method for accessing broadcast data by an access device are proposed. Corresponding computer programs and computer program products for performing the methods are also proposed. Moreover, corresponding structure, provider system and access device are proposed.