Hardware Root of Trust for Secure Ad Insertion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Open computing platforms face security weaknesses in digital rights management and key management, leading to instances of pirated content and revenue loss, as premium content is not well-protected due to software-based security schemes being vulnerable to hacking.

Innovation Solution

A hardware-based root of trust (HW ROT) system is implemented, where security is rooted in hardware and firmware mechanisms within the client computing system, independent of the operating system or software, enabling dynamic, real-time ad insertion and end-to-end protection of digital content through cryptographic processing and secure key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based digital rights management is used in open computing platforms, then ease of operation is improved, but security and reliability deteriorate due to vulnerability to hacking and pirated content

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a secure enclave as an intermediary component that mediates between the software-based DRM system and the hardware layer. This secure enclave provides a trusted execution environment that protects cryptographic keys and sensitive operations from software-based attacks while maintaining compatibility with existing software DRM implementations. The secure enclave acts as a mediator that allows software to operate conveniently while preventing unauthorized access through hardware-enforced security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If premium content is distributed to open computing platforms with software-based security, then adaptability and versatility are improved, but security and protection deteriorate leading to revenue loss

Engineering Contradiction:
ImproveadaptabilityVSAvoidprotection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a nested security architecture where a secure enclave (hardware-based protection layer) is embedded within the open computing platform (software-based environment). This nested structure allows premium content to be distributed widely across diverse platforms while maintaining security through the inner hardened layer. The secure enclave contains cryptographic operations and key management, creating a protected core within the larger software ecosystem, thereby enabling both adaptability and protection simultaneously.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Ease of operation

If content is played back in system memory with software-based DRM, then ease of operation is improved, but security deteriorates as content can be stolen through software-based and hardware-based attacks

Engineering Contradiction:
Improveease of operationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the most critical security functions (cryptographic key storage and management, authentication operations) from the general-purpose processor and places them into a dedicated secure enclave. This extraction removes the vulnerability of having sensitive operations performed in the clear within system memory by the main processor. The secure enclave provides a physically isolated environment that prevents both software-based and hardware-based attacks from accessing cryptographic materials, while the rest of the system continues to operate with full functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11580570B2Method and apparatus for dynamic, real-time ad insertion based on meta-data within a hardware based root of trust
Publication Date: 2023.02.14 INTEL CORP
  • US11580570B2 patent drawing
  • US11580570B2 patent drawing
  • US11580570B2 patent drawing

AI summary

A client computing system inserts selected advertising into digital content. Ads may be inserted into content based on a dynamic advertising matching process that is securely implemented within a hardware-based root of trust. User profiles used in ad matching may be privacy protected and maintained with confidentiality protection in the client computing system and/or a service provider server, respectively. When a client computing system makes a request to the service provider server for content with specified ad slots, the request may be made with the client's EPID signature, which is inherently privacy protected. The hardware-based root of trust protects insertion of selected ads into the linear rendering flow of the content.