Centralized Key Management for Secure Video Subsystems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing graphics and video subsystems face security challenges in protecting premium content due to difficulties in ensuring unique encryption counters across separate key management systems on multiple processing units, particularly when replicating key management systems for independent content streams.

Innovation Solution

A central key management subsystem is implemented, comprising a scheduler, a security processor, and central crypto circuitry, which assigns AppIDs to processing engines, manages cryptographic keys, and ensures secure decryption and encryption across multiple processing engines, allowing independent processing of multiple video streams while preventing reuse of encryption counters.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If key management systems are replicated on each processing unit to support multiple independent content streams, then processing capability and parallelism are improved, but security reliability deteriorates due to difficulty in ensuring unique encryption counters

Engineering Contradiction:
Improveprocessing capabilityVSAvoidsecurity reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent merges multiple replicated key management systems into a single centralized key management system that services all processing engines. This centralization ensures that encryption counters are uniquely managed across all content streams while maintaining the ability to process multiple independent streams in parallel, thus resolving the contradiction between improved productivity and maintained security reliability.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If a centralized key management system is used to ensure unique encryption counters, then security reliability is improved, but device complexity increases due to centralization of key management functions

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The centralized key management system is designed with multi-functional capabilities to handle key generation, distribution, and encryption counter management for multiple processing engines simultaneously. This universal design consolidates security functions into a single system that serves all content streams, improving security reliability while managing complexity through functional integration rather than proliferation of separate systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If multiple independent key management systems are deployed for parallel processing, then processing speed is improved, but encryption counter uniqueness cannot be guaranteed

Engineering Contradiction:
Improveprocessing speedVSAvoidencryption counter uniqueness
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The patent introduces a centralized key management system as an intermediary between multiple processing engines and the DRM infrastructure. This intermediary maintains and distributes unique encryption counters to each processing engine, enabling parallel processing at high speed while ensuring that each engine receives distinct, non-repeating encryption counters for its assigned content streams.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10915608B2System and method for content protection in a graphics or video subsystem
Publication Date: 2021.02.09 INTEL CORP
  • US10915608B2 patent drawing
  • US10915608B2 patent drawing
  • US10915608B2 patent drawing

AI summary

Apparatus and method for scalable content protection. For example, one embodiment of an apparatus comprises: cryptographic management circuitry to securely store one or more keys associated with one or more media apps/applications; a plurality of processing engines, each processing engine comprising circuitry to process media content of the one or more media apps/applications; and a scheduler to schedule processing of the media content by the processing engines; wherein the cryptographic management circuitry is to restore a first cryptographic state including a first key associated with a first media app/application and/or first media content responsive to a request to process the first media content on a first processing engine.