Enhanced Data Stream Security via Stuffing Packet Obfuscation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital multimedia communication systems face challenges in securely transmitting encrypted content, as third parties can potentially intercept and decrypt data despite encryption, due to the indistinguishability of stuffing and content packets.

Innovation Solution

The method involves generating enhanced data streams with stuffing and content enhanced packets, each having an enhanced header and payload, where the enhanced headers are indistinguishable from standard packets, and the payloads include tags to identify packet types, making it difficult for unauthorized entities to differentiate between them, thereby increasing transmission efficiency and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If standard data packets are used for transmission, then the transmission format is simple and compatible, but unauthorized entities can easily intercept and decrypt the content

Engineering Contradiction:
ImprovesecurityVSAvoidpacket structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data stream is segmented into alternating content packets and stuffing packets. This segmentation allows the system to maintain simple standard packet structures while implementing a complex security protocol through the pattern and content of individual packets, thereby improving security without permanently increasing packet structure complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Stuffing packets act as intermediaries between content packets. These dummy packets with valid headers obscure the actual content packets from unauthorized entities, providing a protective layer that enhances security while maintaining compatibility with standard packet formats

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If stuffing packets are used to maintain synchronization, then packet alignment is maintained, but unauthorized entities can still identify and target content packets

Engineering Contradiction:
ImprovesynchronizationVSAvoidpacket identification
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

Both content packets and stuffing packets use identical standard packet formats with valid headers. This homogeneity makes all packets appear indistinguishable to unauthorized entities, preventing them from easily identifying which packets contain actual content while maintaining synchronization through the regular pattern

Inventive Principle:
Principle #33Homogeneity

3Reliability

If encryption is applied to the data stream, then content security is improved, but the data can still be intercepted and potentially decrypted by determined third parties

Engineering Contradiction:
Improvecontent securityVSAvoidinterception risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary obfuscation by inserting stuffing packets before transmission. This preliminary anti-action prevents unauthorized entities from easily identifying and targeting content packets for interception, adding a layer of protection before the actual decryption process occurs at the receiver end

Inventive Principle:
Principle #9Preliminary anti-action

4Difficulty of detecting and measuring

If enhanced packets with tags are used to identify packet types, then unauthorized entities cannot differentiate between packet types, but the packet structure becomes more complex

Engineering Contradiction:
Improvepacket differentiationVSAvoidenhanced packet structure
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The enhanced packet structure segments information into standard headers (for compatibility) and enhanced payloads (containing tags). This segmentation allows the system to maintain simple external interfaces while implementing complex identification mechanisms internally, improving packet differentiation difficulty without permanently increasing overall system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The enhancement is applied locally only where needed - the payload portion contains tags for identification while the header remains standard. This local quality approach allows differentiated treatment of packet components, making packet type identification difficult for unauthorized entities while maintaining compatibility with standard packet processing

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9131113B2Method for creating an enhanded data stream
Publication Date: 2015.09.08 NAGRAVISION SA
  • US9131113B2 patent drawing
  • US9131113B2 patent drawing

AI summary

The present invention provides a method for secure communication of digital information between a transmission entity and at least one reception entity. The method may be applied in the domain of audio/video data transmission, where stuffing data packets comprising random payloads are inserted into a transport stream along with true data packets comprising the audio/video data. The dummy data packets are detectable by an authorized reception entity but not detectable by unauthorized reception entities. A large number of stuffing data packets are included in the transmission to occupy bandwidth and to further render the job difficult for an unauthorized reception entity which tries to intercept the transmission.