Protected Data Path Validation for DRM Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current digital rights management (DRM) schemes are susceptible to being broken, allowing unauthorized access and copying of copyrighted media content, as they rely on software implementations that can be circumvented.

Innovation Solution

Implementing a protected data path within computing platforms that isolates copyrighted content from application programs and operating systems, using a media processor with dedicated circuitry to process and render media without exposing encrypted data to system interconnects, and employing validation processes to ensure the integrity of this protected path.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based DRM schemes are used, then media content can be accessed and processed by application programs, but the DRM schemes are susceptible to being broken and circumvented

Engineering Contradiction:
Improvemedia content accessibilityVSAvoidDRM scheme security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the media processing architecture into distinct protected and unprotected zones. A dedicated media processor handles encrypted media content in an isolated environment, while the main CPU and application programs operate in an unprotected environment. This segmentation prevents application programs from accessing encrypted media data, thereby maintaining DRM security while enabling media playback functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The media processor acts as an intermediary between the storage device and the system bus. It receives encrypted media data, processes it in an isolated environment, and outputs only decrypted audio/video signals to display and audio devices. This intermediary prevents direct access to encrypted data by the main system, securing DRM content while enabling media playback.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If encrypted media data is exposed to system interconnects and processors, then media processing can be performed, but unauthorized access and copying become possible

Engineering Contradiction:
Improvemedia processing capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system creates a segmented architecture where encrypted media data remains isolated in a protected zone handled by the media processor. The main CPU and system interconnects are separated from encrypted data paths. This segmentation enables media processing functionality while preventing unauthorized access to copyrighted content.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts the encrypted media processing functionality from the main system into a separate media processor. This extracted component handles all operations on encrypted data in isolation, removing the security vulnerability of exposing encrypted data to the general system interconnects while maintaining full media processing capability.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If a protected data path is implemented, then copyrighted content is isolated from application programs, but system complexity increases

Engineering Contradiction:
Improvecontent protection integrityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the media processing functions and DRM protection mechanisms into a single integrated media processor. This merging eliminates the need for separate complex protection layers and interfaces, reducing overall system complexity while maintaining content protection integrity. The media processor handles both media playback and security functions in one unified component.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8291501B2Validation of protected intra-system interconnects for digital rights management in electrical computers and digital data processing systems
Publication Date: 2012.10.16 CHENG HLDG
  • US8291501B2 patent drawing
  • US8291501B2 patent drawing
  • US8291501B2 patent drawing

AI summary

Embodiments for validating protected data paths for digital rights management of digital objects are disclosed. Some embodiments disclosed herein may comprise processes or apparatus for transferring data from one or more peripherals to one or more computers or digital data processing systems for the latter to process, store, and/or further transfer and/or for transferring data from the computers or digital data processing systems to the peripherals. Some embodiments disclosed herein may comprise processes or apparatus for interconnecting or communicating between two or more components connected to an interconnection medium within a single computer or digital data processing system.