Manifest-Based Entitlement Enforcement for OTT Media

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional Conditional Access systems in Set Top Boxes only support basic ON/OFF entitlements for media delivery, whereas over-the-top (OTT) media delivery requires a wide array of entitlements to be configured and enforced for various users, devices, and media combinations, along with secure handling and storage, which is not effectively addressed by existing technologies.

Innovation Solution

A method for enforcing a wide variety of entitlements in real-time OTT video delivery involves configuring entitlements at a server, determining applicable combinations for client requests, securely sending and handling entitlement information on client devices, storing it securely for offline use, and enforcing these entitlements on multiple devices using a system comprising a workflow manager, packaging servers, rights server, content delivery network, and proxy server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional Conditional Access systems are used in Set Top Boxes, then basic ON/OFF entitlement enforcement is achieved, but the system cannot support a wide array of entitlements required for OTT media delivery across multiple devices and user groups

Engineering Contradiction:
Improveentitlement varietyVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments entitlement management into distinct components: entitlement configuration at the server, secure transmission to client devices, local storage on devices, and runtime enforcement. This segmentation allows the system to support diverse entitlements without overwhelming complexity at any single point.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a proxy server as an intermediary between the content delivery network and client devices. This proxy handles entitlement verification and manifest file modification, offloading complexity from both the core CDN and client devices while enabling sophisticated entitlement enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If entitlement information is transmitted securely to client devices, then secure handling is achieved, but real-time processing and enforcement across multiple devices becomes more challenging

Engineering Contradiction:
ImprovesecurityVSAvoidreal-time processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs preliminary actions by configuring entitlements at the server before distribution and pre-storing them securely on client devices. This allows runtime enforcement to be highly efficient since the entitlement data is already prepared and available locally, eliminating the need for real-time server verification while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Client devices are equipped with the capability to autonomously enforce entitlements using locally stored entitlement information. The devices can independently determine whether playback conditions are satisfied without requiring continuous server communication, enabling real-time enforcement while improving processing efficiency.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If manifest files are used to convey encoding information and segment retrieval locations, then HTTP adaptive streaming is enabled, but integrating entitlement enforcement into the manifest processing increases system complexity

Engineering Contradiction:
Improvestreaming flexibilityVSAvoidmanifest processing complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges entitlement information with the existing manifest file structure. The proxy server modifies manifest files to include entitlement-related data alongside encoding and segment information, allowing clients to retrieve both streaming and entitlement information in a single operation. This integration adds entitlement enforcement capability without requiring separate processing streams.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If entitlements are enforced on multiple client devices with different capabilities, then broad device support is achieved, but ensuring consistent entitlement application across diverse platforms becomes more difficult

Engineering Contradiction:
Improvedevice compatibilityVSAvoidentitlement enforcement consistency
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The patent creates a universal entitlement enforcement mechanism that operates consistently across diverse client devices. The proxy server implements a standardized approach to manifest modification and entitlement verification that works regardless of the specific client device capabilities. Entitlement conditions are defined in a platform-agnostic manner, ensuring consistent application across smartphones, tablets, PCs, and other devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11777906B2Media distribution system with manifest-based entitlement enforcement
Publication Date: 2023.10.03 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US11777906B2 patent drawing
  • US11777906B2 patent drawing
  • US11777906B2 patent drawing

AI summary

A method for enforcing entitlements includes configuring a wide variety of entitlements at a server; determining applicable combination of entitlements for a given client request; sending entitlements to the requesting client securely; handling entitlement information securely on a plurality of client devices at run time; storing entitlement information securely on a plurality of client devices for offline use; and enforcing entitlements on a plurality of client devices. The method employs manipulation of manifest files by a proxy that may be included in the client device or located in the network.