Broadcast Receiver Authentication via Dual-Network Synchronization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital broadcast networks cannot efficiently manage user subscriptions, data transmission, and content access, as they lack bidirectional communication capabilities and effective mechanisms for authentication and decryption, leading to inefficiencies and increased costs.

Innovation Solution

A receiving device configured with both broadcast and second network capabilities, allowing for automatic authentication and decryption using a request generation mechanism that incorporates authentication information and rights objects, enabling secure and efficient access to broadcast data while synchronizing service information across networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is used to restrict access to content, then security is improved, but transmission efficiency deteriorates due to individual key distribution requirements

Engineering Contradiction:
Improvecontent access securityVSAvoidtransmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The decryption key is segmented into two parts: a broadcast component transmitted to all terminals and a terminal-specific component stored locally in each terminal's secure memory. This segmentation allows efficient broadcast transmission while maintaining individualized security control, resolving the contradiction between security and transmission efficiency.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If manual authentication information entry is required, then authentication accuracy is improved, but user convenience deteriorates

Engineering Contradiction:
Improveauthentication accuracyVSAvoiduser convenience
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The terminal automatically retrieves and transmits its own authentication information (such as IMEI or MSISDN) without requiring manual user input. The system self-services the authentication process by extracting credentials from its own identity components, ensuring both accuracy and convenience simultaneously.

Inventive Principle:
Principle #25Self-service

3Manufacturing precision

If service information is synchronized across networks, then service accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveservice information accuracyVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

A dedicated synchronization module acts as an intermediary between the broadcast network and packet-switched network, managing the exchange and alignment of service information. This intermediary handles the complexity of cross-network synchronization internally, presenting a simplified interface to other system components while ensuring accurate service information alignment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7583801B2Apparatus, system, method and computer program product for distributing service information and digital rights for broadcast data
Publication Date: 2009.09.01 NOKIA TECHNOLOGIES OY
  • US7583801B2 patent drawing
  • US7583801B2 patent drawing
  • US7583801B2 patent drawing

AI summary

An apparatus, system method and computer program product configured to transmit data over a broadcast network. The data is encrypted and decoded using a decryption key available to terminals in combination with a digital rights object. A media guide is broadcast to the terminals. Information from the media guide is also stored by a request handling means in order to ensure that information, such as pricing information, broadcast to the terminals is synchronized with information used to register a terminal as a subscriber. A request is sent from a terminal to the broadcast network through a second network. Authentication information identifying the terminal may be included in the request without manual input from a user of the terminal. Authentication information is extracted from a component or added to the message by a component of the second network. The digital rights object is then sent to the terminal via the second network.