Hardware Root of Trust for Secure Content Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Open computing platforms face security weaknesses in digital rights management and key management, leading to piracy and revenue loss, as premium content is not adequately protected, with software-based solutions being vulnerable to attacks.
Innovation Solution
A hardware-based root of trust is established using firmware and hardware mechanisms in a client computing system, independent of the operating system, to create an end-to-end protected media processing pipeline, utilizing a Security Processor and Protected Audio Video Path for secure content handling and playback.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software-based DRM processing is used in open computing platforms, then ease of operation is improved, but security and reliability deteriorate due to vulnerability to hacking and piracy
Solution Approach 1:
A security processor is introduced as an intermediary component between the software application and the content processing pipeline. This dedicated hardware module handles DRM operations and key management, isolating security-critical functions from the general-purpose CPU and software layer, thereby preventing software-based attacks while maintaining ease of use through automated processing.
Solution Approach 2:
The patent replaces software-based DRM processing with hardware-based implementation. The security processor and protected media path provide cryptographic operations and content protection in hardware, making it significantly more resistant to attacks compared to software-only solutions, while maintaining system usability.
2Reliability
If content is processed in hardware for secure playback, then security is improved, but device complexity increases due to additional security processors and protected paths
Solution Approach 1:
The security processor is designed to handle multiple functions including DRM key management, cryptographic operations, and secure content processing. By consolidating these security-related functions into a single multi-functional component, the patent reduces overall system complexity compared to having separate dedicated hardware for each function.
Solution Approach 2:
The patent merges the security processing functions with the existing media processing pipeline through the protected audio video path. The security processor integrates with the graphics and audio subsystems to provide end-to-end protection without requiring completely separate hardware pathways, thereby reducing complexity.
3Reliability
If cryptographic keys are kept encrypted throughout processing, then security is improved, but processing speed may deteriorate due to continuous encryption/decryption operations
Solution Approach 1:
Cryptographic keys are pre-loaded into the security processor in an encrypted state from secure storage. The security processor maintains these keys in encrypted form throughout processing and only decrypts them internally for necessary operations. This preliminary encryption approach allows continuous processing without repeated encryption/decryption cycles, maintaining both security and speed.
Solution Approach 2:
The security processor performs self-service cryptographic operations internally without requiring external encryption/decryption for each processing step. The protected media path ensures that content remains encrypted throughout the pipeline, with decryption occurring only within the secure boundaries of the security processor itself, eliminating the need for repeated cryptographic operations that would slow down processing.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system architecture provides a hardware-based root of trust solution for supporting distribution and playback of premium digital content. In an embodiment, hardware root of trust for digital content and services is a solution where the basis of trust for security purposes is rooted in hardware and firmware mechanisms in a client computing system, rather than in software. From this root of trust, the client computing system constructs an entire media processing pipeline that is protected for content authorization and playback. In embodiments of the present invention, the security of the client computing system for content processing is not dependent on the operating system (OS), basic input/output system (BIOS), media player application, or other host software.