Broadcast Encryption Key Management for Device Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service and content providers face increased production, distribution, and licensing costs due to the growing complexity of networked services, necessitating effective security measures to manage and protect high-quality content while ensuring compliance with security policies and privacy requirements.
Innovation Solution
The implementation of broadcast encryption using a Management Key Block (MKB) and Device Keys (KD) to derive Management Keys (KM), which are used to decrypt Content Keys, allowing secure delivery of services to devices with varying security classes, while reducing overhead and costs through efficient key management and authentication processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encryption and key management systems are used to protect content and services, then security is maintained, but device overhead and infrastructure costs increase significantly
Solution Approach 1:
The system segments the key management structure into hierarchical levels: root keys at the service level, derived keys at the device level, and content-specific encryption keys. This segmentation allows each device to manage only its relevant subset of keys rather than the entire key space, reducing device overhead while maintaining security through the hierarchical structure
Solution Approach 2:
The patent introduces a hierarchical dimension to key management, organizing keys in multiple levels (service-level root keys, device-level derived keys, content-level encryption keys). This dimensional organization reduces the complexity each device must handle by allowing them to operate at their appropriate level in the hierarchy rather than managing all keys flatly
2Adaptability or versatility
If multiple devices are authorized to receive services, then service accessibility is improved, but key management complexity and re-encryption requirements increase
Solution Approach 1:
The service-level root key serves multiple functions: it can derive keys for any authorized device, authenticate service requests, and encrypt content for distribution. This universal key enables the system to support multiple devices and services without requiring separate key management infrastructure for each, reducing overall complexity while maintaining accessibility
Solution Approach 2:
The system performs preliminary key derivation by generating device-specific keys from the service-level root key before content distribution. This preliminary action establishes the authorization relationship in advance, allowing multiple devices to be authorized without requiring re-encryption or complex key management during content delivery
3Reliability
If content is encrypted for secure distribution, then security is maintained, but production and distribution costs increase
Solution Approach 1:
Instead of creating and managing separate encryption keys for each device or content instance, the system creates a single service-level root key that can be copied and derived to generate keys for multiple devices. This copying approach at the root key level significantly reduces production costs compared to traditional methods that would require separate key generation for each authorization
Data Source
AI summary
Provided are techniques to enable a device that provides a service to authorize a second device for receiving the service and the delivery of the service to the second device and other devices within a trusted network. A signed Management Key Block (MKB) is generated and transmitted over a network. Devices authorized to access a particular service parse the MKB and transmit a request. A server associated with the service determines whether or not the device is authorized to access the service based upon data included in the request. The first device may issue a challenge to the second device for authentication purposes. If service is approved, service is initiated, either from the first device or another authorized device. Devices may be organized into classes such that devices of a specific class are authorized to access the service.


