Short Term Key Message Generation for Mobile Broadcast Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The current mobile broadcast system lacks a detailed method for generating and transmitting encryption keys and messages to securely transmit broadcast services and content between network entities.

Innovation Solution

A method and system for generating a Traffic Encryption Key (TEK) and a Short Term Key Message (STKM) are introduced, where the BCAST Service Distribution/Adaptation (BSD/A) generates a partially created STKM, which is then processed by the BCAST Subscription Management (BSM) to include the TEK and perform Message Authentication Code (MAC) processing, resulting in a completed STKM for secure broadcast service transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a mobile broadcast system transmits encrypted service data to terminals, then service protection and content protection are improved, but the system lacks detailed methods for generating and transmitting encryption keys and messages, resulting in security vulnerabilities

Engineering Contradiction:
Improveservice protectionVSAvoidencryption key management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption key management is segmented into multiple components: Service Encryption Authentication Key (SEAK) for encrypting the Traffic Encryption Key (TEK), and Short Term Key Message (STKM) for distributing the TEK to terminals. This segmentation allows each component to have a specific security function, improving overall system security while maintaining manageable complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism where the SEAK acts as a mediator between the content provider and terminals. The SEAK is used to encrypt the TEK, which is then transmitted through the STKM. This intermediary layer ensures that even if the TEK transmission channel is compromised, the actual content remains protected by the SEAK

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system uses a Service Encryption Authentication Key (SEAK) to encrypt the Traffic Encryption Key (TEK), then security is improved, but the complexity of key generation and message authentication increases

Engineering Contradiction:
Improvecontent protectionVSAvoidkey generation process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The SEAK is generated and stored in advance in both the content protection management component and the terminals before actual content transmission. This preliminary action allows the encryption framework to be established beforehand, so that when content needs to be transmitted, the encryption process can proceed efficiently without ad-hoc key generation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The terminal is equipped with the capability to self-generate or receive the SEAK and automatically perform the encryption of TEK and verification of STKM using Message Authentication Code (MAC). This self-service approach reduces the burden on the content provider and simplifies the overall key management architecture

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9800358B2Method and system for protecting broadcast service/content in a mobile broadcast system, and method for generating short term key message threfor
Publication Date: 2017.10.24 SAMSUNG ELECTRONICS CO LTD
  • US9800358B2 patent drawing
  • US9800358B2 patent drawing
  • US9800358B2 patent drawing

AI summary

A system and method are provided for generating a Short Term Key Message (STKM) for protection of a broadcast service being broadcasted to a terminal in a mobile broadcast system. The method includes transmitting, by a Broadcast Service Subscription Management (BSM) for managing subscription information, at least one key information for authentication of the broadcast service to a Broadcast Service Distribution/Adaptation (BSD/A) for transmitting the broadcast service, generating, by the BSD/A, a Traffic Encryption Key (TEK) for deciphering of the broadcast service in the terminal and inserting the TEK into a partially created STKM, and performing, by the BSD/A, Message Authentication Code (MAC) processing on the TEK-inserted STKM using the at least one key information, thereby generating a completed STKM.