Multicast Security Intermediary for Unauthorized Access Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting multicast services in computer networks, such as those in the Internet or UMTS networks, fail to effectively restrict media data reception to authorized receivers and do not allow for flexible device usage or optimal transmission link selection, leading to security and cost inefficiencies.

Innovation Solution

A method where media data from a multicast service is transmitted using a security process that allows for secure reception on multiple devices without re-registration, enabling the selection of different devices and transmission links for optimal quality and cost-effectiveness, with security data exchanged between a server, a mobile device, and a receiving device to ensure authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption keys are distributed to authorized receivers to prevent unauthorized reception, then security is improved, but device complexity increases due to key management requirements

Engineering Contradiction:
ImprovesecurityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A third apparatus (mobile device) is introduced as an intermediary between the first apparatus (server) and second apparatuses (receiving devices). The mobile device performs security processes and stores security data, acting as a mediator that simplifies key management by centralizing security functions rather than requiring direct key distribution to each receiving device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The mobile device serves multiple functions: it acts as a security server for authentication, stores security data for multiple receiving devices, and enables re-registration without requiring re-transmission of security data. This multi-functionality reduces overall system complexity by consolidating security management.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If re-registration is required for each receiving device to ensure security, then security is improved, but loss of time increases due to repeated authentication processes

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security data is exchanged and stored in advance during the initial registration process between the first apparatus and the mobile device. This preliminary action allows subsequent receiving devices to access security data without requiring re-registration, as the mobile device retains the security information for future use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The mobile device creates and stores copies of security data that can be reused by multiple receiving devices. Instead of requiring unique security authentication for each device, the system uses copied security data from the mobile device's storage, enabling fast re-registration without time-consuming re-authentication.

Inventive Principle:
Principle #26Copying

3Reliability

If security data is transmitted to each receiving device individually, then security is improved, but loss of energy increases due to repeated transmission operations

Engineering Contradiction:
ImprovesecurityVSAvoidtransmission energy
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The security data transmission process is merged into a single operation during initial registration between the first apparatus and the mobile device. Instead of transmitting security data separately to each receiving device, the system combines this operation once, and the mobile device reuses the transmitted security data for all subsequent receiving devices, significantly reducing transmission energy consumption.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If a single subscription allows access to multicast services on multiple devices, then adaptability is improved, but security risks increase due to shared access

Engineering Contradiction:
Improvedevice flexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The mobile device serves as a security intermediary that manages authentication and security data for multiple receiving devices. It verifies the identity and authorization of each receiving device before allowing access to multicast services, thereby maintaining security despite shared access across multiple devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the mobile device receives and processes authentication information from receiving devices, verifies their authorization status, and provides feedback on whether they should be granted access. This feedback loop ensures that shared subscription access is controlled and monitored, preventing unauthorized access while maintaining device flexibility.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8745382B2Method, apparatus, computer program, data storage medium and computer program product for preventing reception of media data from a multicast service by an unauthorized apparatus
Publication Date: 2014.06.03 SIEMENS AG
  • US8745382B2 patent drawing
  • US8745382B2 patent drawing
  • US8745382B2 patent drawing

AI summary

The method for the transmission of media data from a multicast service by a first apparatus to a plurality of second apparatuses is suitable for preventing reception of the media data by an unauthorized second apparatus using a security process. A first apparatus is provided which can be used to provide the media data protected by a security process. A third apparatus is provided which can be used to perform the security process with the first apparatus, performance of the security process between the first apparatus and the third apparatus and, on the basis of this, interchange of at least security data between the first apparatus and the third apparatus in order to provide the media data. A second apparatus is selected which can be used to perform at least one reception process for receiving the media data. A first data transmission link is selected which can be used to couple the first apparatus and the second apparatus at least for the purpose of transmitting the media data. The provided media data is received using the second apparatus via the first data transmission link.