Selective Encryption for VOD Content Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Video on Demand (VOD) systems face inefficiencies in storage and complexity due to the need for multiple encryption systems, particularly when transitioning from analog to digital cable systems, leading to storage space inefficiencies and compatibility issues with different conditional access methods.
Innovation Solution
Implementing a hybrid composite storage architecture that selectively encrypts 'critical' packets using a legacy conditional access system, while leaving non-critical packets unencrypted, allowing for dual encryption support without replicating entire content streams, and using an Offline Selective Encryption Processor to manage and remap packet identifiers for seamless decryption across multiple systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple separate encrypted copies of content are stored for different conditional access systems, then compatibility with multiple CA systems is achieved, but storage space efficiency deteriorates
Solution Approach 1:
The content stream is segmented into critical packets (encrypted) and non-critical packets (unencrypted). Only critical packets are encrypted with legacy CA systems, while non-critical packets remain in clear form. This segmentation allows a single composite stream to serve multiple CA systems without storing multiple complete encrypted copies, resolving the contradiction between multi-system compatibility and storage efficiency.
Solution Approach 2:
The patent merges encrypted critical packets with unencrypted non-critical packets into a single hybrid composite content stream. This merged stream can be decrypted and played back by both legacy CA-equipped set-top boxes (which decrypt critical packets) and non-legacy set-top boxes (which use unencrypted packets), eliminating the need for separate storage of multiple encrypted versions and achieving both multi-system compatibility and storage efficiency.
2Reliability
If entire content streams are encrypted for legacy conditional access systems, then security is maintained, but storage and processing complexity increases
Solution Approach 1:
Instead of uniformly encrypting entire content streams, the patent applies encryption selectively only to critical packets that require security protection. Non-critical packets are left unencrypted. This local differentiation reduces the amount of data requiring encryption processing and storage, thereby reducing complexity while maintaining security for essential content elements.
Solution Approach 2:
The patent applies partial encryption to only the necessary critical portions of the content stream rather than encrypting everything. This partial action approach maintains adequate security for critical data while avoiding the excessive complexity and resource consumption that would result from encrypting entire content streams, thus resolving the contradiction between security and complexity.
3Adaptability or versatility
If separate encrypted streams are maintained for different CA systems, then system compatibility is achieved, but data overhead increases
Solution Approach 1:
The content stream is segmented into critical and non-critical packets, with only critical packets being encrypted. This segmentation eliminates the need to duplicate entire content streams for different CA systems, thereby reducing data overhead while maintaining support for multiple conditional access systems through the hybrid composite stream architecture.
Solution Approach 2:
The patent combines encrypted critical packets and unencrypted non-critical packets into a single hybrid stream that serves multiple CA systems. This merging eliminates the redundancy of maintaining separate encrypted streams for each CA system, significantly reducing data overhead while preserving compatibility with both legacy and non-legacy set-top boxes.
Data Source
AI summary
A method of processing content in a video on demand (VOD) system consistent with certain embodiments of the invention, wherein the content is identified by a first set of packet identifiers (PIDs), involves receiving content, the content having marked packets designating packets that are to be encrypted by a first encryption system by setting an encryption flag for all packets designated to be encrypted. Packets are selected in the content according to a selective encryption selection criterion to produce selected packets. The selected packets are duplicated to produce duplicate copies of the selected packets and these duplicate copies are identified using a second set of PIDs. The duplicate copies identified by the second set of PIDs are inserted into the content. All encryption flags in the content are cleared except for the selected packets having the first set of PIDs, so the encryption to follow is selective. This abstract is not to be considered limiting, since other embodiments may deviate from the features described in this abstract.


