SESAME: A Layered Security Framework for SCTE 130 ESAM with Sub-Millisecond Overhead
Keywords:
SCTE 130, ESAM, POIS, SESAME, HMAC-SHA256, AES-256-GCM, Ad insertion security, SCTE-35, Message authenticationAbstract
The SCTE 130 suite defines the architecture for digital program insertion, but its real-time Event Signaling and Management (ESAM) interface has no standardized security mechanism — a measurable liability as ad insertion infrastructure migrates to multi-tenant cloud environments. This paper introduces SESAME (Secure ESAM Authentication and Message Encryption), a layered security framework proposed as SCTE 130-9. SESAME defines three additive tiers — HMAC-SHA256 authentication, channel-scoped authorization, and AES-256-GCM payload encryption — conveyed through standard HTTP headers without modifying ESAM XML schemas. An open-source Rust reference implementation demonstrates sub-millisecond per-request overhead on commodity hardware. We present the threat model, protocol design, performance results, and proposed standardization path within SCTE 130.
Downloads
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 SET INTERNATIONAL JOURNAL OF BROADCAST ENGINEERING

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
The "Copyright Transfer Agreement - Cover Letter" must be submitted together with the article.
The Corresponding Author must, on behalf of all co-authors, complete all the required information, check the boxes, print, SIGN and scan the (signed) document.
The "Copyright Transfer Agreement - Cover Letter" must also be forwarded in PDF format. Template available at: