Adaptive Streaming Segment Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current ISO/IEC 23009-4 solutions for out-of-band segment integrity verification in adaptive streaming do not effectively allow for attack detection and localization in open or attack-prone networks, as they require a trusted server setup and lack reporting and isolation mechanisms.

Innovation Solution

The proposed systems and methods enhance ISO/IEC 23009-4 by enabling clients to compute and report security or authentication hashes, allowing for attack detection and localization by comparing client-computed hashes with server-stored reference hashes, and using diagnostic parameters to identify attack locations within the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ISO/IEC 23009-4 out-of-band validation is implemented, then segment integrity verification capability is improved, but attack detection and localization effectiveness deteriorates due to lack of reporting mechanisms

Engineering Contradiction:
Improvesegment integrity verificationVSAvoidattack detection and localization
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where clients send reports containing segment hashes and diagnostic parameters back to servers. This allows the system to detect and localize attacks by comparing client-computed hashes with server-stored reference hashes, and using diagnostic parameters to identify attack locations in the network

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary validation server that receives hash reports from multiple clients, compares them against reference hashes, and coordinates attack detection across the network. This intermediary enables centralized analysis of segment integrity without requiring direct trusted relationships between all servers

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a trusted server setup is required for segment verification, then security validation capability is improved, but system complexity and deployment difficulty worsens

Engineering Contradiction:
Improvesecurity validationVSAvoidtrusted server setup
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses cryptographic hash copies of segment data as verification tokens. Instead of requiring trusted server setups with direct access to original content, the system distributes hash copies that clients can compute and compare, enabling verification without complex trusted infrastructure

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent enables clients to independently compute segment hashes and perform integrity verification themselves using received reference hashes. This self-service approach eliminates the need for complex trusted server configurations, as each client autonomously validates segment authenticity

Inventive Principle:
Principle #25Self-service

3Difficulty of detecting and measuring

If client-computed hashes are reported to servers, then attack detection capability is improved, but network communication overhead increases

Engineering Contradiction:
Improveattack detectionVSAvoidnetwork communication overhead
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of energy

Solution Approach 1:

The patent extracts only the essential verification data (segment hashes and diagnostic parameters) from full segment content for network transmission. By sending only these compact hash values rather than complete media segments, the system achieves effective attack detection while minimizing network communication overhead

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12021883B2Detecting man-in-the-middle attacks in adaptive streaming
Publication Date: 2024.06.25 INTERDIGITAL VC HOLDINGS INC
  • US12021883B2 patent drawing
  • US12021883B2 patent drawing
  • US12021883B2 patent drawing

AI summary

Systems and methods for adaptively streaming video content to a wireless transmit/receive unit (WTRU) or wired transmit/receive unit may comprise obtaining a media presentation description that comprises a content authenticity, requesting a key for a hash-based message authentication code; receiving the key for the hash-based message authentication code, determining a determined hash for a segment of the media presentation description, requesting a reference hash for the segment from a server, receiving the reference hash for the segment from the server, and comparing the reference hash to the determined hash to determine whether the requested hash matches the determined hash.