Transport Encryptor for Real-Time VOD Content Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing video on-demand systems face complexity in implementing real-time encryption due to the need for additional processing and management of encryption keys, which requires enhanced resource management and coordination between VOD servers, encryptors, and set-top boxes, leading to delays in feature implementation and vendor dependency.

Innovation Solution

A system architecture that employs a transport encryptor to encrypt content in real-time without the need for communication with the Session Resource Manager, using common tier encryption and reducing the complexity of protocols between VOD servers, encryptors, and set-top boxes, allowing for efficient delivery of encrypted content directly to subscribers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If real-time encryption is implemented in VOD systems, then content security is improved, but system complexity increases due to enhanced resource management and coordination requirements

Engineering Contradiction:
Improvecontent securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the encryption function from the complex coordination system by implementing a transport encryptor that operates independently of the Session Resource Manager. This separates the encryption task from the resource management complexity, allowing encryption to be handled as a standalone function that does not require continuous communication or coordination between multiple system components.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The transport encryptor performs self-contained encryption operations without requiring external coordination. It receives content from the VOD server, applies encryption using keys from the conditional access system, and outputs encrypted streams independently. This self-service approach eliminates the need for complex inter-component coordination while maintaining secure content delivery.

Inventive Principle:
Principle #25Self-service

2Reliability

If pre-encryption is used to store encrypted content on VOD servers, then content access control is improved, but processing requirements and memory cache needs increase

Engineering Contradiction:
Improvecontent access controlVSAvoidprocessing requirements
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by having the transport encryptor prepare and insert encryption information (such as ECMs - Encryption Control Messages) into the content stream before delivery to the set-top box. This preliminary encryption preparation occurs at the point of transmission rather than requiring pre-processing and storage of encrypted content, reducing the memory cache requirements while maintaining access control.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The transport encryptor acts as an intermediary between the VOD server and the set-top box. It receives unencrypted content from the server, applies encryption using conditional access system keys, and delivers the encrypted stream to the subscriber's device. This intermediary role enables content access control without requiring the VOD server to store or process encrypted content, thereby reducing processing and memory requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If application-specific protocols are used for encryption coordination, then encryption control precision is improved, but protocol complexity and integration difficulty increase

Engineering Contradiction:
Improveencryption control precisionVSAvoidintegration difficulty
Core Design Contradiction:
Manufacturing precisionVSEase of manufacture

Solution Approach 1:

The patent applies universality by implementing a standardized transport encryptor interface that can work with different VOD servers and conditional access systems without requiring application-specific protocols. The transport encryptor uses standard transport stream protocols and receives encryption keys through conventional means, making it universally applicable across different system configurations. This multi-functionality maintains encryption control precision while significantly reducing integration difficulty and vendor dependency.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8885823B2Method and apparatus for delivering encrypted on-demand content without use of an application defined protocol
Publication Date: 2014.11.11 ARRIS ENTERPRISES LLC
  • US8885823B2 patent drawing
  • US8885823B2 patent drawing
  • US8885823B2 patent drawing

AI summary

A method for delivering encrypted content to a subscriber terminal on-demand through a communication network is provided. The method begins when SRM receives a request for content from the subscriber terminal. In response to the request, the SRM directs a video server to transmit the content as an unencrypted transport stream to an encryptor. The packets in the unencrypted transport stream include a header with a destination address associated with the subscriber terminal. The encryptor encrypts the content in the unencrypted transport stream to generate an encrypted transport stream. The encryptor also inserts in the packet headers of the packets in the encrypted transport stream the destination address associated with the subscriber terminal obtained from the packet headers in the unencrypted transport stream. Finally, the encrypted transport stream is transmitted to the subscriber terminal over the communication network.