BIOS Secure Wireless Display Connection via HDCP Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies lack secure methods for connecting to wireless displays during the pre-boot process and ensuring High-Bandwidth Digital Content Protection (HDCP) compliance, leading to vulnerabilities in video content transmission and unauthorized access to BIOS settings.
Innovation Solution
A secure wireless display connect module within the BIOS authenticates HDCP-compliant wireless displays, generates a shared session key, and encrypts video frames using an ACPI secure blob, ensuring secure and HDCP-compliant video content transmission during the boot process without external hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Miracast is used to send video content to a wireless display, then wireless display functionality is achieved, but security is compromised because HDCP cannot be implemented without separate hardware
Solution Approach 1:
The patent merges the HDCP encryption functionality directly into the BIOS firmware, combining what were previously separate components (Miracast wireless display capability and HDCP security hardware) into a unified solution. The BIOS now contains both the wireless display protocol implementation and the HDCP encryption engine, eliminating the need for separate hardware dongles while maintaining security.
Solution Approach 2:
The patent replaces the mechanical hardware-based HDCP implementation (separate HDCP hardware dongle and driver) with a firmware-based implementation. The HDCP encryption and authentication functions are now executed as software routines within the BIOS, substituting physical hardware components with virtualized firmware functionality while preserving the security protocol.
2Ease of operation
If video content is sent without HDCP when BIOS does not support HDCP hardware, then wireless display connectivity is achieved, but content protection is lost
Solution Approach 1:
The patent performs HDCP authentication and establishes encryption keys during the BIOS boot phase, before the operating system loads. This preliminary action ensures that HDCP protection is already in place and active before any video content transmission begins, preventing the scenario where content is sent unprotected due to delayed or missing HDCP initialization.
3Productivity
If a computing system is resumed, then system operation is restored, but HDCP protection may be lost allowing unauthorized display on non-HDCP-compliant displays
Solution Approach 1:
The patent maintains HDCP protection continuously across system resume operations by preserving the encrypted video output path and authentication state through the resume process. The BIOS-level HDCP implementation ensures that when the system resumes, the protected video channel is re-established automatically without requiring re-authentication or risking fallback to unprotected output, thereby maintaining uninterrupted security coverage.
4Adaptability or versatility
If wireless displays are placed in public areas, then accessibility is improved, but vulnerability to unauthorized access increases
Solution Approach 1:
The patent introduces HDCP encryption as an intermediary layer between the computing system and the wireless display. This cryptographic mediator ensures that even if unauthorized users physically access the wireless display in public areas, they cannot view or capture the protected video content without the proper decryption keys, which are only provided to authenticated HDCP-compliant displays.
Data Source
AI summary
During the boot process, a secure wireless display connect module of the BIOS can authenticate a wireless display and determine whether the wireless display can comply with the HDCP. When the secure wireless display connect module determines that the wireless display is HDCP compliant, the secure wireless display connect module can create an ACPI secure blob in which is stored a shared session key generated as part of determining that the wireless display is HDCP compliant. A video authentication session module of the BIOS can then retrieve this shared session key from the ACPI secure blob and use it to encrypt video frames that are to be sent to the wireless display. The video authentication session module may additionally embed a session ID and a timeout into each video frame which the wireless display can employ to detect when the video frame should no longer be displayed.


