Platform-Hardened DRM Key Provisioning via Secure Enclave

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital rights management (DRM) systems face challenges in securely provisioning and storing keys for secure communication between content servers and clients, particularly in ensuring the security and integrity of audio and video content transmission.

Innovation Solution

The implementation of a platform-hardened approach using a processor's security features, including a secure enclave unit, to securely generate, store, and manage key pairs, such as EPID keys, within a client's system memory, ensuring that provisioning information is encrypted and protected from unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional software-based key management is used, then ease of operation is improved, but security and reliability deteriorate due to tampering and unauthorized access

Engineering Contradiction:
Improveease of key provisioningVSAvoidsecurity of key storage
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-based key management with hardware-based security features of the processor, specifically using a secure enclave unit. This substitution moves key storage and management from the software layer to the hardware layer, providing tamper-resistant security while maintaining ease of operation through automated hardware-assisted key provisioning.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If repeated provisioning requests are made, then security is improved through verification, but loss of time increases due to repeated communication overhead

Engineering Contradiction:
Improvesecurity verificationVSAvoidprovisioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements pre-provisioning of keys into the secure enclave unit before actual content transmission occurs. By performing key provisioning in advance and storing it securely in hardware, the system eliminates the need for repeated provisioning requests during content transmission, reducing time loss while maintaining security through the pre-verified keys.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If tamper-resistant software is used, then security is improved, but device complexity increases due to multiple software layers

Engineering Contradiction:
Improvetamper resistanceVSAvoidsoftware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces complex tamper-resistant software implementations with the processor's built-in secure enclave hardware unit. This approach achieves tamper resistance through hardware design rather than software complexity, reducing the number of software layers while providing equivalent or superior security guarantees through the hardware's physical security features.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9436812B2Platform-hardened digital rights management key provisioning
Publication Date: 2016.09.06 INTEL CORP
  • US9436812B2 patent drawing
  • US9436812B2 patent drawing
  • US9436812B2 patent drawing

AI summary

Embodiments of an invention for platform-hardened digital rights management key provisioning are disclosed. In one embodiment, a processor includes an execution unit to execute one or more instructions to create a secure enclave in which to run an application to receive digital rights management information from a provisioning server in response to authentication of the application by a verification server.