Adaptive Streaming Segment Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current ISO/IEC 23009-4 solutions for out-of-band segment integrity verification in adaptive streaming do not effectively allow for attack detection and localization in open or attack-prone networks, as they require a trusted server setup and lack reporting and isolation mechanisms.
Innovation Solution
The proposed systems and methods enhance ISO/IEC 23009-4 by enabling clients to compute and report security or authentication hashes, allowing for attack detection and localization by comparing client-computed hashes with server-stored reference hashes, and using diagnostic parameters to identify attack locations within the network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ISO/IEC 23009-4 out-of-band validation is implemented, then segment integrity verification capability is improved, but attack detection and localization effectiveness deteriorates due to lack of reporting mechanisms
Solution Approach 1:
The patent implements feedback mechanisms where clients send reports containing segment hashes and diagnostic parameters back to servers. This allows the system to detect and localize attacks by comparing client-computed hashes with server-stored reference hashes, and using diagnostic parameters to identify attack locations in the network
Solution Approach 2:
The patent introduces an intermediary validation server that receives hash reports from multiple clients, compares them against reference hashes, and coordinates attack detection across the network. This intermediary enables centralized analysis of segment integrity without requiring direct trusted relationships between all servers
2Reliability
If a trusted server setup is required for segment verification, then security validation capability is improved, but system complexity and deployment difficulty worsens
Solution Approach 1:
The patent uses cryptographic hash copies of segment data as verification tokens. Instead of requiring trusted server setups with direct access to original content, the system distributes hash copies that clients can compute and compare, enabling verification without complex trusted infrastructure
Solution Approach 2:
The patent enables clients to independently compute segment hashes and perform integrity verification themselves using received reference hashes. This self-service approach eliminates the need for complex trusted server configurations, as each client autonomously validates segment authenticity
3Difficulty of detecting and measuring
If client-computed hashes are reported to servers, then attack detection capability is improved, but network communication overhead increases
Solution Approach 1:
The patent extracts only the essential verification data (segment hashes and diagnostic parameters) from full segment content for network transmission. By sending only these compact hash values rather than complete media segments, the system achieves effective attack detection while minimizing network communication overhead
Data Source
AI summary
Systems and methods for adaptively streaming video content to a wireless transmit/receive unit (WTRU) or wired transmit/receive unit may comprise obtaining a media presentation description that comprises a content authenticity, requesting a key for a hash-based message authentication code; receiving the key for the hash-based message authentication code, determining a determined hash for a segment of the media presentation description, requesting a reference hash for the segment from a server, receiving the reference hash for the segment from the server, and comparing the reference hash to the determined hash to determine whether the requested hash matches the determined hash.


