Multimedia Interface Protection Control via TEE Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital systems and signals, particularly in on-demand multimedia services, face challenges in protecting against malicious attacks due to the need for robust multimedia interface protections that require significant processing power and are difficult to modify, especially when implementing Conditional Access Systems (CAS) and Digital Rights Management (DRM) in systems-on-a-chip (SoC).

Innovation Solution

A method and device for controlling the application of multimedia output interface protections by verifying compliance with security rules, allowing enabling or disabling of interface protections based on the required degree of protection, which can be applied to outgoing signals from multimedia systems, thereby ensuring that the protection level meets the specified security standards.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multimedia interface protections are implemented in the Rich Execution Environment (REE), then the system can control and apply protections to outgoing signals, but the system becomes vulnerable to malicious attacks due to the REE's exposure to external attacks

Engineering Contradiction:
Improveprotection control reliabilityVSAvoidmalicious attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides protection control into two segments: the REE handles high-level protection policy decisions and authorization, while the TEE executes the actual protection application and verification. This segmentation allows the REE to maintain control functionality while the TEE provides security isolation against malicious attacks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The TEE acts as an intermediary between the REE and the multimedia output interface protection hardware. The REE sends protection commands to the TEE, which verifies them against security rules and then applies the appropriate protection level to the outgoing signal, mediating between control and execution while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the Trusted Execution Environment (TEE) has high processing capacity to directly control multimedia output interface protection, then security verification can be performed, but the system complexity and modification constraints increase

Engineering Contradiction:
Improvesecurity verification capabilityVSAvoidsystem modification constraints
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The TEE performs partial verification by checking protection level compliance rather than implementing the entire protection control stack. The REE handles authorization and policy decisions, while the TEE focuses specifically on verifying that the selected protection level meets security requirements, dividing the workload appropriately.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The TEE is designed to handle multiple protection protocols and verification scenarios through a universal security rule checking mechanism. Rather than requiring separate hardware blocks for each protection type, the TEE provides a multi-functional security verification layer that can adapt to different protection requirements without major system modifications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If existing hardware blocks are modified to implement TEE-based protection control, then security is improved, but severe modifications or new designs are required

Engineering Contradiction:
Improveprotection securityVSAvoidhardware modification difficulty
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The security verification functionality is extracted from the existing REE-based protection control and placed into a separate TEE environment. This extraction allows the core security checking logic to be isolated in a secure, dedicated processing area without requiring modification of the existing multimedia protection hardware blocks, which continue to operate as before but under TEE-verified control.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10419434B2Method and device for improving the protection of a multimedia signal against a malicious attack
Publication Date: 2019.09.17 STMICROELECTRONICS FRANCE
  • US10419434B2 patent drawing
  • US10419434B2 patent drawing

AI summary

A device protects an incoming multimedia signal with a protection that is controllable and configured for enabling or disabling an application for an interface protection on an outgoing signal coming from the incoming signal. An output interface is configured for delivering the outgoing signal on an output. An authorization process is performed for authorizing or otherwise a control over the enabling or disabling of the interface protection application depending on security rules.