Bridge Security Engine Offloads CPU Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Digital content protection schemes, such as DTCP, are vulnerable to theft at internal data buses and impose a significant burden on CPUs due to encryption and decryption processes, especially for high-definition video, which can consume a substantial portion of CPU clock cycles.
Innovation Solution
A digital content system with a security engine disposed in a bridge that offloads cryptographic services, such as encryption and decryption, from the central processing unit (CPU) to the bridge, allowing clear text data to be encrypted and transferred over unsecured paths as cipher text, reducing CPU load and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital content protection schemes (such as DTCP) are used to encrypt content on inter-device system buses, then content transmission security is improved, but clear text data becomes susceptible to theft at internal data buses and memory
Solution Approach 1:
The patent divides the content protection function into separate modules: a security engine disposed in the bridge that handles encryption/decryption operations, separate from the CPU and memory subsystems. This segmentation ensures that clear text content never resides in general-purpose memory, eliminating the vulnerability to memory bus theft while maintaining secure transmission protection.
Solution Approach 2:
The security engine acts as an intermediary component between the CPU and external devices. It receives encrypted content from the CPU, decrypts it in a secure environment, and outputs clear text only to authorized devices through the bridge, preventing exposure to internal data buses and memory while maintaining system functionality.
2Reliability
If the CPU performs encryption and decryption of high definition video, then digital content protection is provided, but the CPU experiences significant burden and consumes majority of CPU clock cycles
Solution Approach 1:
The patent extracts the cryptographic service functions (encryption and decryption) from the CPU and relocates them to a dedicated security engine disposed in the bridge. This extraction offloads the computationally intensive AES encryption/decryption operations from the CPU, reducing CPU cycle consumption from approximately 800 MHz to minimal overhead, thereby significantly improving CPU productivity while maintaining robust digital content protection.
3Ease of operation
If clear text data is written to system memory for decryption and re-encryption by the CPU, then processing is enabled, but the content is susceptible to theft at the memory bus
Solution Approach 1:
The patent segments the data processing architecture so that the security engine operates as a separate processing unit with its own secure data path through the bridge. This eliminates the need to write clear text to system memory, as decryption and re-encryption operations occur in the security engine's protected environment, preventing memory bus theft vulnerabilities while maintaining full processing capability.
Solution Approach 2:
The security engine serves as an intermediary that handles all clear text processing operations without requiring memory storage. It receives encrypted data from the CPU, performs decryption in a secure environment, and immediately outputs the clear text to the destination device through the bridge, eliminating the intermediate memory storage step that creates security vulnerabilities.
Data Source
AI summary
A digital content system is disclosed. A security engine disposed in a bridge provides cryptographic services. Clear text digital data received from a central processing unit is encrypted and transferred via the bridge over unsecured data paths as cipher text.


