Audio Video Security Monitoring via Trusted Processor Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current broadband audio and video processing devices, such as set-top boxes, face challenges in maintaining security due to their complex and flexible nature, making it difficult to detect and prevent data piracy and unauthorized access, as existing countermeasures are insufficient in determining legitimate software actions and may not have enough data or processing power to ensure content security.

Innovation Solution

A system-on-chip (SoC) security monitoring system that collects, tags, and monitors security parameters associated with data streams, using trusted processors to detect suspicious behaviors and attacks, including key sharing, fishing expeditions, and content piracy, by combining security and non-security analytics to identify both persistent and non-persistent attacks, and applies countermeasures locally or through a cloud-based server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the device allows multiple degrees of freedom and runs applications from multiple parties to enhance user experience, then adaptability is improved, but security and reliability deteriorate

Engineering Contradiction:
Improveuser experience flexibilityVSAvoidcontent security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system is divided into two separate execution environments: a Rich Execution Environment (REE) for running applications and a Secure Execution Environment (SEE) for security-critical operations. This segmentation allows the device to maintain flexibility in the REE while ensuring security through the isolated SEE, which monitors and controls access to protected resources independently of application behavior.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure monitor acting as an intermediary is introduced between applications in the REE and security-sensitive resources. This intermediary validates all access requests, enforces security policies, and mediates interactions without requiring trust in the application software, thus maintaining security while allowing flexible application execution.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If prevention countermeasures are implemented to stop key or content leakage, then security is improved, but the system lacks sufficient data and processing power to determine legitimate software actions, reducing adaptability

Engineering Contradiction:
Improvesecurity protectionVSAvoidsoftware legitimacy determination
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The secure monitor serves as an intermediary that collects comprehensive security-relevant data from various system components and makes authorization decisions based on this data. This intermediary approach provides both the security protection needed and the centralized processing capability to determine software legitimacy, eliminating the need for individual components to have sufficient processing power independently.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements continuous monitoring and feedback mechanisms where the secure monitor observes system state, application behavior, and resource access patterns. This feedback loop enables the system to adapt security decisions based on actual runtime conditions while maintaining protection, allowing the system to determine software legitimacy through ongoing observation rather than static prevention rules.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If the system uses native device software to detect content-piracy activities, then ease of operation is improved, but security deteriorates because the native software itself may not be secure

Engineering Contradiction:
Improvepiracy detection capabilityVSAvoiddetection security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Instead of using the potentially compromised native device software to detect piracy, the system inverts the approach by using a secure, isolated execution environment (SEE) with a secure monitor to perform detection. The secure monitor, running in a trusted environment, monitors the native software and applications for piracy activities, ensuring that the detection mechanism itself cannot be compromised by the software it is monitoring.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11070876B2Security monitoring with attack detection in an audio/video processing device
Publication Date: 2021.07.20 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US11070876B2 patent drawing
  • US11070876B2 patent drawing
  • US11070876B2 patent drawing

AI summary

A security-monitoring system includes a data-collection module, a security-monitoring module and an attack-detection module. The data-collection module can collect data associated with a data stream. The security-monitoring module monitors a number of activities within a device. The attack-detection module can detect one or more attacks on the device based on the monitored plurality of activities by using one or more trusted processors. The collected data includes one or more security parameters associated with the data stream. The attack-detection module identifies the attacks based on the security parameters and data from the one or more trusted processors.