Centralized Key Management for Secure Video Subsystems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing graphics and video subsystems face security challenges in protecting premium content due to difficulties in ensuring unique encryption counters across separate key management systems on multiple processing units, particularly when replicating key management systems for independent content streams.
Innovation Solution
A central key management subsystem is implemented, comprising a scheduler, a security processor, and central crypto circuitry, which assigns AppIDs to processing engines, manages cryptographic keys, and ensures secure decryption and encryption across multiple processing engines, allowing independent processing of multiple video streams while preventing reuse of encryption counters.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If key management systems are replicated on each processing unit to support multiple independent content streams, then processing capability and parallelism are improved, but security reliability deteriorates due to difficulty in ensuring unique encryption counters
Solution Approach 1:
The patent merges multiple replicated key management systems into a single centralized key management system that services all processing engines. This centralization ensures that encryption counters are uniquely managed across all content streams while maintaining the ability to process multiple independent streams in parallel, thus resolving the contradiction between improved productivity and maintained security reliability.
2Reliability
If a centralized key management system is used to ensure unique encryption counters, then security reliability is improved, but device complexity increases due to centralization of key management functions
Solution Approach 1:
The centralized key management system is designed with multi-functional capabilities to handle key generation, distribution, and encryption counter management for multiple processing engines simultaneously. This universal design consolidates security functions into a single system that serves all content streams, improving security reliability while managing complexity through functional integration rather than proliferation of separate systems.
3Speed
If multiple independent key management systems are deployed for parallel processing, then processing speed is improved, but encryption counter uniqueness cannot be guaranteed
Solution Approach 1:
The patent introduces a centralized key management system as an intermediary between multiple processing engines and the DRM infrastructure. This intermediary maintains and distributes unique encryption counters to each processing engine, enabling parallel processing at high speed while ensuring that each engine receives distinct, non-repeating encryption counters for its assigned content streams.
Data Source
AI summary
Apparatus and method for scalable content protection. For example, one embodiment of an apparatus comprises: cryptographic management circuitry to securely store one or more keys associated with one or more media apps/applications; a plurality of processing engines, each processing engine comprising circuitry to process media content of the one or more media apps/applications; and a scheduler to schedule processing of the media content by the processing engines; wherein the cryptographic management circuitry is to restore a first cryptographic state including a first key associated with a first media app/application and/or first media content responsive to a request to process the first media content on a first processing engine.


