Video Packet Encryption With Confidentiality Metadata Streams
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection methods are network-centric and lack flexibility in managing data confidentiality levels, particularly for video streams, failing to adapt to the sensitivity and access rights of individual consumers.
Innovation Solution
A method and device for multi-level protection of video streams, involving disassembly, encryption, and assembly of video packets with confidentiality metadata, using session and encryption keys to create an outgoing stream compatible with MPEG-TS protocol, ensuring appropriate confidentiality levels based on indicators.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network-level protection with homogeneous confidentiality levels is used, then network security is simplified, but data-centric flexibility and adaptability to individual consumer rights are lost
Solution Approach 1:
The patent segments the video stream into individual packets and assigns different confidentiality levels to each packet based on consumer rights. Each packet is encrypted independently with appropriate keys, allowing fine-grained control over data access while maintaining system manageability through modular processing.
Solution Approach 2:
The patent applies different confidentiality levels and encryption methods to different portions (packets) of the video stream according to local consumer rights requirements. Each packet receives the specific protection level needed for its content and intended consumer, rather than applying a uniform protection level throughout.
2Adaptability or versatility
If binary encoding/decoding protection is used, then implementation is simple, but flexibility in protection levels and granularity is limited
Solution Approach 1:
The patent changes the parameter of protection from binary (encoded/decoded) to multi-level by introducing different confidentiality levels (e.g., L1, L2, L3) and corresponding encryption keys. This allows flexible adjustment of protection strength based on consumer rights while maintaining implementation feasibility through systematic key management.
3Reliability
If multi-level encryption with session keys and metadata is implemented, then data-centric security and flexibility are improved, but processing complexity and computational overhead increase
Solution Approach 1:
The patent performs preliminary actions by pre-establishing session keys and confidentiality metadata before actual data transmission. The metadata is generated and attached to each packet in advance, and keys are prepared beforehand, which streamlines the encryption process and reduces real-time computational complexity.
Solution Approach 2:
The patent introduces confidentiality metadata as an intermediary element that carries key information and confidentiality level indicators. This metadata acts as a mediator between the encryption system and the consumer, enabling flexible access control without requiring complex direct authentication mechanisms for each packet.
4Reliability
If systematic encryption of all video packets is applied, then data security is maximized, but processing time and system resources increase
Solution Approach 1:
The patent applies partial encryption by encrypting only the necessary portions of the video stream based on confidentiality requirements. Not all packets require the same level of encryption, allowing the system to apply encryption selectively to maintain security while reducing overall processing time and resource consumption.
Data Source
AI summary
A method of protecting an incoming stream, the incoming stream including at least one incoming elementary video stream, the incoming elementary video stream including a succession of incoming video packets, the method characterized by the disassembling of the incoming stream for separating a current packet; the encryption of the current packet with a session key, the building of a confidentiality metadata packet including a time stamp field corresponding to a time stamp of the current packet and a confidentiality field containing the session key, the encryption of the confidentiality data packet with an encryption key, and the assembling of an outgoing stream including an outgoing elementary stream grouping together the encrypted current packets and an elementary confidentiality metadata stream including the encrypted confidentiality metadata packets.


