Video Pump Session-Based Encryption for VOD Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Video-on-Demand (VOD) systems lack encryption capabilities at the video pump level, making high-value content vulnerable to unauthorized access and theft, especially as video pumps are placed further away from the edge, increasing the risk due to greater access by more individuals.

Innovation Solution

Implementing a system and method for session-based encryption within the VOD pump, where a session and resource manager negotiates encryption keys from a headend controller and provides them to the video pump to encrypt content before transmission, eliminating the need for encryption-capable edge devices and ensuring secure delivery.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is implemented at the video pump level, then content security is improved, but device complexity increases

Engineering Contradiction:
Improvecontent securityVSAvoidvideo pump complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A session and resource manager acts as an intermediary between the headend controller and the video pump. This manager handles the complex key negotiation and encryption key distribution, allowing the video pump to implement encryption without bearing the full complexity burden. The intermediary manages the cryptographic protocols and key lifecycle, simplifying the video pump's role while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The encryption functionality is segmented into separate components: the headend controller generates and manages encryption keys, the session and resource manager handles key distribution and session management, and the video pump performs the actual content encryption. This segmentation allows each component to be optimized independently, reducing the complexity burden on any single device while achieving comprehensive security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption-capable edge devices are used, then content security is improved, but device cost increases

Engineering Contradiction:
Improvecontent securityVSAvoiddevice cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The session and resource manager serves as a centralized intermediary that provides encryption key management services to multiple video pumps. Instead of requiring each edge device to be independently encryption-capable, the intermediary centralizes the cryptographic functionality, allowing the use of simpler, less expensive video pump devices while maintaining strong security through centralized key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The session and resource manager provides universal encryption key management services that can serve multiple video pumps and multiple content sessions. This multi-functional approach consolidates encryption capabilities into a shared resource, eliminating the need for each edge device to have dedicated encryption hardware, thereby reducing overall system cost while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If video pumps are placed further from the edge, then network flexibility is improved, but security risk increases due to greater access

Engineering Contradiction:
Improvenetwork flexibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Encryption is applied preliminarily at the video pump before content enters the distribution network. By encrypting content at the source (the video pump), the system proactively prevents unauthorized access throughout the entire distribution path. This preliminary security measure counteracts the increased risk associated with placing video pumps further from the edge, as the content remains encrypted even when traversing through more access points in the network.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The session and resource manager acts as a secure intermediary that manages encryption keys and ensures that only authorized devices can decrypt content. This intermediary layer provides security oversight throughout the distribution network, allowing video pumps to be placed flexibly throughout the network while maintaining security through centralized key management and authentication mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9729902B2System and method for providing session based encryption from a video pump
Publication Date: 2017.08.08 COX COMMUNICATIONS INC
  • US9729902B2 patent drawing
  • US9729902B2 patent drawing
  • US9729902B2 patent drawing

AI summary

A system includes a session and resource manager and a video pump. The session and resource manager negotiates encryption keys from a headend controller and provides the encryption keys to a video pump. The video pump uses the encryption keys from the session and resource manager to encrypt content. Thus, the video pump uses encryption keys to encrypt the content so that it is encrypted right from the video pump prior to transmission over the entire transport system. A generic modulation device may thus be used to modulate the encrypted content over the delivery network.