Secure Coprocessor for Encrypted Program Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional approaches for protecting multimedia content from unauthorized access and piracy are inadequate due to the open environment of personal computers, where software code can be dissected and analyzed, exposing decryption keys and allowing unauthorized access.
Innovation Solution
A system comprising a host and a secure coprocessor that receives and decrypts an encrypted program, with the decrypted program executed in restricted access RAM, ensuring secure execution and communication of output, while preventing unauthorized access through proprietary instruction sets and restricted access memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software applications are used to control access to encrypted content, then content protection is implemented, but the software can be accessed and reversed-engineered, exposing decryption keys
Solution Approach 1:
The patent extracts the decryption and program execution functions from the host computer's software environment and relocates them to a dedicated secure coprocessor. This separation removes the vulnerable software layer that can be reverse-engineered, while preserving the content protection capability through hardware-based security.
Solution Approach 2:
The secure coprocessor acts as an intermediary between the host computer and the encrypted content. It receives encrypted programs from the host, decrypts them securely, executes them in an isolated environment, and returns results to the host. This intermediary layer prevents direct access to decryption keys while maintaining functionality.
2Ease of operation
If decryption keys are stored in computer memory, then content access is enabled, but memory can be examined to gain unauthorized access to protected content
Solution Approach 1:
The patent extracts decryption key storage from the host computer's accessible memory and relocates it to the secure coprocessor's protected memory space. This ensures that even if the host computer's memory is examined, the decryption keys remain secure and inaccessible to unauthorized users.
Solution Approach 2:
The secure coprocessor employs temporary, non-persistent memory for storing decryption keys and program code. After execution, these sensitive data are destroyed and not retained in any accessible form. This disposable approach ensures that even if memory is examined during operation, no lasting harm can be inflicted on the system.
3Reliability
If a secure coprocessor is used to decrypt and execute encrypted programs, then unauthorized access is prevented, but device complexity increases
Solution Approach 1:
The patent segments the system into two distinct components: a host computer for general operations and a dedicated secure coprocessor for security-critical functions. This segmentation isolates the complexity of security mechanisms to a separate module, allowing the host to remain relatively simple while achieving robust protection.
Solution Approach 2:
The secure coprocessor contains a copy of the decryption algorithms and security functions that mirrors the host's software capabilities but implements them in hardware with enhanced security. This copying approach allows the host to maintain software flexibility while the coprocessor provides hardware-level security, balancing complexity with functionality.
Data Source
AI summary
Systems and methods for secure program execution are described. At least one embodiment includes a system for securely executing software comprising a host configured to accept a disc containing encrypted content to be accessed and store an encrypted program used to access the content on the disc. The system further comprises a secure coprocessor communicatively coupled to the host and configured to receive the encrypted program, decrypt and execute the encrypted program, and communicate an output generated by the program back to the host.


