Mobile Broadcast Encryption Key Management via Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The mobile broadcast system lacks a defined encryption method for service protection between entities and interfaces, necessitating an improved method for transmitting and receiving encryption information to ensure secure service delivery.
Innovation Solution
A method and system for transmitting and receiving encryption information in a mobile broadcast system, involving a BCAST Subscription Management (BSM) for managing subscriber information and generating encryption keys, and a BCAST Service Distribution/Adaptation (BSD/A) for transmitting these keys, including Registration Key Material (RKM), Long-Term Key Message (LTKM), and Short-Term Key Message (STKM) for secure decryption of services and content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption methods are not defined between entities in mobile broadcast system, then system flexibility is maintained, but service protection reliability is insufficient
Solution Approach 1:
The encryption system is segmented into distinct key types (RKM, LTKM, STKM) with specific functions. RKM is used for initial registration, LTKM for long-term service access, and STKM for short-term content decryption. This segmentation allows each component to have a dedicated purpose, improving reliability without requiring a completely new complex system.
Solution Approach 2:
The BSM performs preliminary actions by pre-generating and managing encryption keys (RKM, LTKM) before service delivery. The registration key material is prepared in advance during terminal registration, and long-term key messages are pre-configured for future service access, ensuring reliable service protection is already in place before content broadcast occurs.
2Adaptability or versatility
If multiple encryption keys are transmitted between BSM and BSD/A, then service decryption capability is improved, but information transmission security requirements increase
Solution Approach 1:
The BSM acts as an intermediary between the key generation authority and the BSD/A. It securely manages and distributes multiple encryption keys (RKM, LTKM, STKM) to the BSD/A, which then delivers them to terminals. This intermediary structure enables versatile decryption capability while maintaining security through controlled key distribution.
Solution Approach 2:
Different encryption keys are assigned to different functional requirements: RKM for registration phase, LTKM for authenticated service access, and STKM for content decryption. Each key type has localized quality characteristics suited to its specific purpose, allowing terminals to decrypt various services appropriately while maintaining overall security.
3Reliability
If encryption key management protocol is established, then service protection is improved, but system implementation complexity increases
Solution Approach 1:
The system uses parameter changes in message structures to convey different key types. Request and response messages between BSM and BSD/A include specific parameters indicating the type of key material being transmitted (RKM, LTKM, STKM). This allows the system to manage multiple encryption keys through a unified protocol framework, improving service protection without requiring entirely separate implementation systems.
Data Source
AI summary
A system and method for transmitting/receiving encryption information in a mobile broadcast system supporting broadcast service (BCAST) are provided. In the mobile broadcast system, a BCAST Subscription Management (BSM) manages subscriber information of a terminal, and transmits to a BCAST Service Distribution/Adaptation (BSD/A) a first delivery message including a Registration Key Material (RKM) provided for registration of the broadcast service of the terminal and including at least one service or content's identifier. The BSD/A transmits to the BSM a first delivery confirmation message including information indicating success/fail in receipt of the first delivery message, and transmits the RKM to the terminal.


