Remote Trusted Execution Environment for Set-Top Box DRM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital-rights management (DRM) systems struggle to provide robust security for content distribution on legacy set-top boxes, which lack the computational power to run complex DRM applications, leading to vulnerabilities in content protection and potential piracy.

Innovation Solution

A remotely managed trusted execution environment (TEE) is implemented within the set-top box, which communicates with a secure server to authenticate customers and decrypt content, offloading non-secure DRM functions to the cloud to maintain security while reducing the computational burden on the client.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex DRM applications are run on legacy set-top boxes, then content security is improved, but device complexity and computational requirements worsen

Engineering Contradiction:
Improvecontent securityVSAvoidcomputational power
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A trusted execution environment (TEE) acts as an intermediary between the legacy set-top box and the content decryption module. The TEE provides a secure isolated environment that enables robust DRM functionality without requiring the entire set-top box to have high computational power. The TEE handles the complex cryptographic operations while the main system remains simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is segmented into two parts: a simple legacy set-top box for basic functionality and a trusted execution environment for complex DRM operations. This segmentation allows the main device to remain computationally simple while delegating security-critical functions to a specialized secure module.

Inventive Principle:
Principle #1Segmentation

2Reliability

If robust DRM safeguards are implemented, then content protection is improved, but device complexity worsens

Engineering Contradiction:
Improvecontent protectionVSAvoidDRM application complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted execution environment serves as a mediator that implements the complex DRM safeguards without requiring the main set-top box to be complex. The TEE encapsulates the DRM logic and cryptographic functions, providing robust protection while keeping the overall device architecture simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The complex DRM application logic is extracted from the legacy set-top box and placed into a separate trusted execution environment. This extraction allows the main device to remain simple while the TEE handles the sophisticated content protection requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If full DRM functionality is implemented on set-top box, then content security is improved, but ease of operation worsens

Engineering Contradiction:
Improvecontent securityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trusted execution environment acts as a universal intermediary that enables multiple DRM systems (PlayReady, WideVine, etc.) to operate on legacy set-top boxes without requiring each device to be specially configured for specific DRM protocols. The TEE handles the complexity of different DRM implementations, making the system easier to operate across diverse devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trusted execution environment provides universal support for multiple DRM standards and content protection schemes. This multi-functionality allows a single legacy set-top box architecture to operate with various content providers and DRM systems without requiring device-specific modifications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12341762B2Remotely managed trusted execution environment for digital-rights management in a distributed network with thin clients
Publication Date: 2025.06.24 ACTIVEVIDEO NETWORKS INC
  • US12341762B2 patent drawing
  • US12341762B2 patent drawing
  • US12341762B2 patent drawing

AI summary

A client device receives media content from a server remote from the client device. During playback of the media content, the client device transmits, to a player proxy remote from the client device, a play position of the media content. The play position of the media content is used by the player proxy at the application server to continue providing the media content. The play position is transmitted repeatedly to the player proxy while playback of the media content continues. The client device transmits the media content for display at a display device that is coupled to the client device.