IPTV Security via Authentication Proxy Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In IPTV security, existing technologies face challenges in authenticating User Equipment (UE) before starting a session, particularly in Mobile TV environments, where the Mobile TV Application Server (MTV AS) lacks access to the Bootstrapping Transaction Identifier (BTID) and key material necessary for encrypting long-term content keys, leading to inefficient key protection and increased signaling requirements.
Innovation Solution
The method involves an Application Server receiving an invite message with a BTID from an IPTV receiving node, sending an authentication request to a Service Access Protection Server to obtain a long-term key, and using this key to encrypt a media encryption key, which is then sent to the IPTV content provider, allowing secure media encryption and decryption for the UE.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the MTV AS uses conventional authentication procedures, then authentication can be performed, but the MTV AS lacks access to BTID and key material necessary for encrypting long-term content keys
Solution Approach 1:
The patent introduces an Authentication Proxy as an intermediary component that mediates between the MTV AS and the authentication infrastructure. The proxy stores the BTID and long-term keys, and selectively provides them to the MTV AS when needed for content key encryption, without requiring the MTV AS to have direct access to these sensitive materials. This resolves the contradiction by enabling secure key management while maintaining authentication reliability.
2Productivity
If the MTV AS retrieves keys through existing procedures, then key retrieval is possible, but excessive signaling is required and efficiency is reduced
Solution Approach 1:
The patent implements preliminary action by having the Authentication Proxy pre-store the BTID and long-term keys before they are needed for content delivery. When the MTV AS requires these keys for encrypting content, the proxy can provide them immediately without requiring extensive real-time signaling or key retrieval procedures. This eliminates the need for repeated authentication handshakes and reduces signaling overhead significantly.
3Reliability
If the MTV AS acts as a Network Application Function in the GBA architecture, then secure sessions can be established, but the AS must obtain and manage BTID and key material
Solution Approach 1:
The Authentication Proxy serves as an intermediary that handles the complexity of BTID and key material management on behalf of the MTV AS. The proxy maintains secure storage of these materials and provides them to the MTV AS through controlled interfaces when needed for session establishment and content protection. This allows the MTV AS to function as a Network Application Function with full security capabilities while avoiding the operational burden of direct key management.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A method of setting up a secure IPTV session. An Application Server (AS) receives an invite message from an IPTV receiving node such as a mobile telephone or a Set Top Box (STB) to set up an IPTV session. The invite message includes a Bootstrapping Transaction Identifier (BTID) associated with the receiving node. The AS sends an authentication request to a Service Access Protection Server, the authentication request including the BTID. The AS then receives from the Service Access Protection Server an authentication response, which includes a long term key associated with the IPTV receiving node, the long term key having been previously provided to the IPTV receiving node. A request is sent to an IPTV content provider node, the request identifying the IPTV receiving node. The AS then encrypts a media encryption key that is used to encrypt the media sent by the IPTV content provider, using the received long term key. An invite response is then sent to the IPTV receiving node, the response including the encrypted media encryption key.