Audio Video Security Monitoring via Trusted Processor Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current broadband audio and video processing devices, such as set-top boxes, face challenges in maintaining security due to their complex and flexible nature, making it difficult to detect and prevent data piracy and unauthorized access, as existing countermeasures are insufficient in determining legitimate software actions and may not have enough data or processing power to ensure content security.
Innovation Solution
A system-on-chip (SoC) security monitoring system that collects, tags, and monitors security parameters associated with data streams, using trusted processors to detect suspicious behaviors and attacks, including key sharing, fishing expeditions, and content piracy, by combining security and non-security analytics to identify both persistent and non-persistent attacks, and applies countermeasures locally or through a cloud-based server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the device allows multiple degrees of freedom and runs applications from multiple parties to enhance user experience, then adaptability is improved, but security and reliability deteriorate
Solution Approach 1:
The system is divided into two separate execution environments: a Rich Execution Environment (REE) for running applications and a Secure Execution Environment (SEE) for security-critical operations. This segmentation allows the device to maintain flexibility in the REE while ensuring security through the isolated SEE, which monitors and controls access to protected resources independently of application behavior.
Solution Approach 2:
A secure monitor acting as an intermediary is introduced between applications in the REE and security-sensitive resources. This intermediary validates all access requests, enforces security policies, and mediates interactions without requiring trust in the application software, thus maintaining security while allowing flexible application execution.
2Reliability
If prevention countermeasures are implemented to stop key or content leakage, then security is improved, but the system lacks sufficient data and processing power to determine legitimate software actions, reducing adaptability
Solution Approach 1:
The secure monitor serves as an intermediary that collects comprehensive security-relevant data from various system components and makes authorization decisions based on this data. This intermediary approach provides both the security protection needed and the centralized processing capability to determine software legitimacy, eliminating the need for individual components to have sufficient processing power independently.
Solution Approach 2:
The system implements continuous monitoring and feedback mechanisms where the secure monitor observes system state, application behavior, and resource access patterns. This feedback loop enables the system to adapt security decisions based on actual runtime conditions while maintaining protection, allowing the system to determine software legitimacy through ongoing observation rather than static prevention rules.
3Ease of operation
If the system uses native device software to detect content-piracy activities, then ease of operation is improved, but security deteriorates because the native software itself may not be secure
Solution Approach 1:
Instead of using the potentially compromised native device software to detect piracy, the system inverts the approach by using a secure, isolated execution environment (SEE) with a secure monitor to perform detection. The secure monitor, running in a trusted environment, monitors the native software and applications for piracy activities, ensuring that the detection mechanism itself cannot be compromised by the software it is monitoring.
Data Source
AI summary
A security-monitoring system includes a data-collection module, a security-monitoring module and an attack-detection module. The data-collection module can collect data associated with a data stream. The security-monitoring module monitors a number of activities within a device. The attack-detection module can detect one or more attacks on the device based on the monitored plurality of activities by using one or more trusted processors. The collected data includes one or more security parameters associated with the data stream. The attack-detection module identifies the attacks based on the security parameters and data from the one or more trusted processors.


