Hardware Decoder Accelerator Security via Software Intermediary

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hardware decoder accelerators, used in video processing, are vulnerable to security attacks due to their privileged access to user memory and system registers, potentially leading to unauthorized access and system compromise.

Innovation Solution

A software security enhancement layer is implemented to protect the hardware decoder accelerator by controlling memory access, verifying buffer sizes, and checking data integrity, thereby preventing malicious attacks and minimizing potential damage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If hardware decoder accelerator is given higher process privilege to access user memory and system registers, then decoding performance and efficiency are improved, but security vulnerability increases

Engineering Contradiction:
Improvedecoding performanceVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

A software security enhancement layer is introduced as an intermediary between the hardware decoder accelerator and the system resources it accesses. This layer includes security checks that verify buffer sizes, validate memory access requests, and ensure data integrity without preventing the accelerator from performing its decoding function efficiently.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software security enhancement layer is added to protect hardware decoder accelerator, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Security checks are performed in advance before the hardware decoder accelerator accesses memory or system registers. The software enhancement layer validates buffer sizes, checks memory addresses, and verifies data integrity beforehand, preventing potential security issues before they can affect system stability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If memory access is restricted and buffer size verification is performed, then security against attacks is improved, but processing speed may be reduced

Engineering Contradiction:
Improvesecurity against attacksVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

Buffer size verification and memory access restrictions are established beforehand through software configuration and validation. Once verified, the hardware decoder accelerator can operate with these constraints in place without requiring continuous security checks during the decoding process, minimizing impact on processing speed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2973178B1Enhanced security for hardware decoder accelerator
Publication Date: 2025.01.22 SONY INTERACTIVE ENTERTAINMENT LLC
  • EP2973178B1 patent drawingFigure 1
  • EP2973178B1 patent drawingFigure 2
  • EP2973178B1 patent drawingFigure 3

AI summary

A software security layer may be used to protect a system against exploitation of a hardware encoder accelerator by malicious data embedded in the one or more frames of encoded digital streaming data. It is emphasized that this abstract is provided to comply with the rules requiring an abstract that will allow a searcher or other reader to quickly ascertain the subject matter of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims.