Centralized DRM Bridge for Legacy Set-Top Box Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cable MVPDs face challenges in securely delivering high-value digital content to set-top devices due to the computational limitations of legacy set-top boxes, which cannot run robust DRM applications, and existing DRM bridge solutions expose content to security breaches during decryption and re-encryption.
Innovation Solution
A centralized DRM solution that decrypts and processes encrypted content in a secure environment, re-encrypting it for MVPD's CA system to maintain end-to-end encryption and prevent piracy, using a virtual set-top application and secure data links to ensure secure delivery to set-top devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If legacy set-top boxes are used to deliver content, then device compatibility and ease of operation are improved, but computational power and security capability deteriorate
Solution Approach 1:
A DRM bridge server is introduced as an intermediary component between the content source and the legacy set-top box. The bridge server performs DRM license verification and content decryption, then delivers the decrypted content to the set-top box for re-encryption and distribution. This intermediary approach allows legacy devices with limited computational power to deliver protected content without requiring them to run complex DRM software locally.
2Reliability
If DRM bridge solution is implemented, then content protection is improved, but security gap during decryption and re-encryption deteriorates
Solution Approach 1:
The system creates a secure, isolated environment for content decryption using a trusted execution environment or secure processing unit within the DRM bridge server. This secure environment acts as an 'inert atmosphere' where content is decrypted and processed without exposure to potential security threats from the external network or unauthorized access. The content remains protected during the vulnerable decryption phase by maintaining it within this secure boundary.
3Reliability
If robust DRM software is deployed, then content security is improved, but computational complexity and processing requirements deteriorate
Solution Approach 1:
The DRM protection functionality is segmented and separated from the legacy set-top box hardware. Instead of requiring the set-top box to run complex DRM software, the DRM verification and decryption functions are extracted and consolidated into a centralized DRM bridge server. This segmentation allows the set-top box to remain simple while the complex security processing is handled by specialized infrastructure.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Encrypted content from a content provider is received at a central location of a multichannel video programming distributor (MVPD). The content provider is distinct from the MVPD. The content is decrypted and processed in a virtual set-top application associated with a set- top of a customer of the MVPD. The set-top of the customer is located in a customer premises remote from the central location. The processed content is provided over a secure data link to a conditional-access encoder at the central location. The conditional-access encoder encrypts the processed content, which is then transmitted to the set-top of the customer.