SESAME: A Layered Security Framework for SCTE 130 ESAM with Sub-Millisecond Overhead

Authors

  • Bo Kelleher Techex, Ltd.

Keywords:

SCTE 130, ESAM, POIS, SESAME, HMAC-SHA256, AES-256-GCM, Ad insertion security, SCTE-35, Message authentication

Abstract

The SCTE 130 suite defines the architecture for digital program insertion, but its real-time Event Signaling and Management (ESAM) interface has no standardized security mechanism — a measurable liability as ad insertion infrastructure migrates to multi-tenant cloud environments. This paper introduces SESAME (Secure ESAM Authentication and Message Encryption), a layered security framework proposed as SCTE 130-9. SESAME defines three additive tiers — HMAC-SHA256 authentication, channel-scoped authorization, and AES-256-GCM payload encryption — conveyed through standard HTTP headers without modifying ESAM XML schemas. An open-source Rust reference implementation demonstrates sub-millisecond per-request overhead on commodity hardware. We present the threat model, protocol design, performance results, and proposed standardization path within SCTE 130.

Downloads

Download data is not yet available.

Downloads

Published

2026-09-30

How to Cite

Kelleher, B. (2026). SESAME: A Layered Security Framework for SCTE 130 ESAM with Sub-Millisecond Overhead. SET INTERNATIONAL JOURNAL OF BROADCAST ENGINEERING, 12. Retrieved from https://revistaeletronica.set.org.br/ijbe/article/view/342

Issue

Section

Production, Workflows, and Audiovisual Infrastructure