Content-Bound Executables in Trusted Execution Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing content delivery and protection systems, such as those using self-protecting Blu-ray technology, are vulnerable and less effective on modern devices with Trusted Execution Environments (TEEs), which can execute software without visibility to the untrusted Operating System environment.
Innovation Solution
Implementing a content-bound executable application that executes in a trusted execution environment, performs integrity checks, and manages content access according to a license, ensuring robust content delivery and protection by updating the local environment and decrypting content data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If self-protecting content using virtual machine is implemented, then content protection is provided on multiple platforms, but the solution is defeated and becomes less useful
Solution Approach 1:
The patent introduces a Trusted Execution Environment (TEE) as an intermediary layer between the content and the untrusted OS environment. The TEE acts as a secure mediator that executes content-bound executables in isolation, preventing the OS from accessing or compromising the content protection mechanisms. This resolves the contradiction by providing robust protection while maintaining platform versatility through standardized TEE interfaces.
Solution Approach 2:
The system segments the execution environment into trusted and untrusted zones. The content-bound executable is separated into a protected TEE segment that cannot be accessed by the untrusted OS, while the OS segment handles general operations. This segmentation ensures that even if the OS is compromised, the content remains protected, resolving the vulnerability issue while maintaining multi-platform adaptability.
2Reliability
If integrity check and update verification are performed using content-bound executable, then content protection is strengthened, but processing time and complexity increase
Solution Approach 1:
The patent implements preliminary integrity checks and update verifications that are performed automatically as part of the content-bound executable initialization process. By performing these checks upfront before content execution, the system ensures strong protection without adding significant overhead during actual content playback, as the verification is integrated into the startup sequence rather than being a separate ongoing process.
3Reliability
If content-bound executable is executed in trusted execution environment, then content security is improved, but device complexity increases
Solution Approach 1:
The content-bound executable is designed to be self-contained with all necessary protection logic, integrity check routines, and update verification mechanisms embedded within it. This self-service approach eliminates the need for complex external protection systems, as the executable independently manages its own security requirements within the TEE, thereby improving security without proportionally increasing overall system complexity.
Data Source
AI summary
Delivering, protecting, and playing content, including: executing a content-bound executable application in a trusted execution environment by a player device; performing an integrity check of the player device using the content-bound executable application; sending a request from the player device for update information to at least one of the license server and the content server using the content-bound executable application; receiving update information at the player device from the at least one of the license server and the content server; updating local environment of the player device using the content-bound executable application; and decrypting the content data by the content-bound executable application. Key words include content-bound and executable.


