Broadcast Encryption Key Management for Device Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service and content providers face increased production, distribution, and licensing costs due to the growing complexity of networked services, necessitating effective security measures to manage and protect high-quality content while ensuring compliance with security policies and privacy requirements.

Innovation Solution

The implementation of broadcast encryption using a Management Key Block (MKB) and Device Keys (KD) to derive Management Keys (KM), which are used to decrypt Content Keys, allowing secure delivery of services to devices with varying security classes, while reducing overhead and costs through efficient key management and authentication processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption and key management systems are used to protect content and services, then security is maintained, but device overhead and infrastructure costs increase significantly

Engineering Contradiction:
ImprovesecurityVSAvoiddevice overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the key management structure into hierarchical levels: root keys at the service level, derived keys at the device level, and content-specific encryption keys. This segmentation allows each device to manage only its relevant subset of keys rather than the entire key space, reducing device overhead while maintaining security through the hierarchical structure

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hierarchical dimension to key management, organizing keys in multiple levels (service-level root keys, device-level derived keys, content-level encryption keys). This dimensional organization reduces the complexity each device must handle by allowing them to operate at their appropriate level in the hierarchy rather than managing all keys flatly

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Adaptability or versatility

If multiple devices are authorized to receive services, then service accessibility is improved, but key management complexity and re-encryption requirements increase

Engineering Contradiction:
Improveservice accessibilityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The service-level root key serves multiple functions: it can derive keys for any authorized device, authenticate service requests, and encrypt content for distribution. This universal key enables the system to support multiple devices and services without requiring separate key management infrastructure for each, reducing overall complexity while maintaining accessibility

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system performs preliminary key derivation by generating device-specific keys from the service-level root key before content distribution. This preliminary action establishes the authorization relationship in advance, allowing multiple devices to be authorized without requiring re-encryption or complex key management during content delivery

Inventive Principle:
Principle #10Preliminary action

3Reliability

If content is encrypted for secure distribution, then security is maintained, but production and distribution costs increase

Engineering Contradiction:
ImprovesecurityVSAvoidproduction and distribution costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Instead of creating and managing separate encryption keys for each device or content instance, the system creates a single service-level root key that can be copied and derived to generate keys for multiple devices. This copying approach at the root key level significantly reduces production costs compared to traditional methods that would require separate key generation for each authorization

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8862878B2Authentication and authorization of a device by a service using broadcast encryption
Publication Date: 2014.10.14 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8862878B2 patent drawing
  • US8862878B2 patent drawing
  • US8862878B2 patent drawing

AI summary

Provided are techniques to enable a device that provides a service to authorize a second device for receiving the service and the delivery of the service to the second device and other devices within a trusted network. A signed Management Key Block (MKB) is generated and transmitted over a network. Devices authorized to access a particular service parse the MKB and transmit a request. A server associated with the service determines whether or not the device is authorized to access the service based upon data included in the request. The first device may issue a challenge to the second device for authentication purposes. If service is approved, service is initiated, either from the first device or another authorized device. Devices may be organized into classes such that devices of a specific class are authorized to access the service.