Platform-Hardened DRM Key Provisioning via Secure Enclave
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing digital rights management (DRM) systems face challenges in securely provisioning and storing keys for secure communication between content servers and clients, particularly in ensuring the security and integrity of audio and video content transmission.
Innovation Solution
The implementation of a platform-hardened approach using a processor's security features, including a secure enclave unit, to securely generate, store, and manage key pairs, such as EPID keys, within a client's system memory, ensuring that provisioning information is encrypted and protected from unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional software-based key management is used, then ease of operation is improved, but security and reliability deteriorate due to tampering and unauthorized access
Solution Approach 1:
The patent replaces software-based key management with hardware-based security features of the processor, specifically using a secure enclave unit. This substitution moves key storage and management from the software layer to the hardware layer, providing tamper-resistant security while maintaining ease of operation through automated hardware-assisted key provisioning.
2Reliability
If repeated provisioning requests are made, then security is improved through verification, but loss of time increases due to repeated communication overhead
Solution Approach 1:
The patent implements pre-provisioning of keys into the secure enclave unit before actual content transmission occurs. By performing key provisioning in advance and storing it securely in hardware, the system eliminates the need for repeated provisioning requests during content transmission, reducing time loss while maintaining security through the pre-verified keys.
3Reliability
If tamper-resistant software is used, then security is improved, but device complexity increases due to multiple software layers
Solution Approach 1:
The patent replaces complex tamper-resistant software implementations with the processor's built-in secure enclave hardware unit. This approach achieves tamper resistance through hardware design rather than software complexity, reducing the number of software layers while providing equivalent or superior security guarantees through the hardware's physical security features.
Data Source
AI summary
Embodiments of an invention for platform-hardened digital rights management key provisioning are disclosed. In one embodiment, a processor includes an execution unit to execute one or more instructions to create a secure enclave in which to run an application to receive digital rights management information from a provisioning server in response to authentication of the application by a verification server.


