Local Server Secure Content Delivery Without Decryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing content delivery systems in hospitality settings, such as hotels, face inefficiencies due to the need for decryption and re-encryption of media content, which increases costs and complexity, especially when handling conditional access (CA) protected content from satellite systems.
Innovation Solution
A local server system that receives encrypted media content and provides it to multiple client devices without decrypting or re-encrypting it, relying on client devices to authenticate and obtain decryption keys from content service providers, thus eliminating the need for a trusted execution environment and reducing hardware and operational costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If decryption and re-encryption processes are implemented at the local server, then content security is improved, but device complexity and operational costs increase
Solution Approach 1:
The patent extracts the decryption and re-encryption functions from the local server, eliminating the need for a trusted execution environment at the server. Instead, client devices perform decryption locally using keys obtained from the server, thereby reducing server complexity while maintaining content security through client-side security mechanisms
Solution Approach 2:
Client devices are empowered to autonomously decrypt content using decryption keys obtained from the server. Each client device independently manages its own decryption process without requiring the server to perform complex cryptographic operations, thereby reducing server complexity while maintaining security through distributed client-side authentication and decryption
2Reliability
If decryption and re-encryption processes are implemented at the local server, then content security is improved, but operational costs increase
Solution Approach 1:
The patent extracts the costly decryption and re-encryption operations from the local server to client devices. By eliminating the need for expensive hardware security modules and trusted execution environments at the server, operational costs are reduced while content security is maintained through client-side cryptographic operations
Solution Approach 2:
The patent replaces expensive, complex server-side security infrastructure with simpler, more cost-effective client-side decryption mechanisms. The server provides decryption keys without performing actual decryption, using computationally inexpensive operations that reduce operational costs while maintaining security through distributed client authentication
3Productivity
If encrypted content is delivered to multiple client devices without decryption, then processing efficiency is improved, but client device complexity increases
Solution Approach 1:
The patent segments the content delivery process by having the server deliver encrypted content to multiple client devices simultaneously without decryption. Each client device independently handles decryption locally, which improves server processing efficiency by eliminating repeated decryption operations while distributing the cryptographic processing burden to individual client devices
4Reliability
If a trusted execution environment is implemented at the local server, then content security is improved, but hardware costs increase
Solution Approach 1:
The patent extracts the trusted execution environment requirement from the local server, eliminating the need for expensive hardware security modules and specialized cryptographic processors. Content security is maintained through software-based cryptographic operations at client devices, significantly reducing server hardware costs while preserving security through distributed client-side authentication and decryption
Data Source
AI summary
Aspects of the subject disclosure may include, for example, a local server coupled to a plurality of client devices. The local server may receive encrypted content from one or more content sources and provide the content to the client devices. The local server and client devices may be part of a multi-client environment such as a hotel or conference center. The local server does not decrypt and re-encrypt content, thereby allowing the use of low cost equipment. Other embodiments are disclosed.


