Secure Digital Media Platform with Isolated Application Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The transition of television from a broadcast to an interactive two-way approach has increased the complexity of content delivery, with existing systems struggling to provide a secure and managed environment for multimedia content and applications, particularly in preventing piracy and malware while enabling innovation and differentiation in consumer electronics.
Innovation Solution
A secure connected digital media platform is introduced, featuring a system-on-a-chip (SoC) with a hypervisor creating isolated secure application environments, where multimedia content and applications are processed only if they include a security code corresponding to a security key stored in the device, managed by a third-party clearinghouse, ensuring secure and exclusive access to portals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If television transitions to an interactive two-way approach with connected digital media devices, then the function and type of content available to consumers is dramatically expanded, but the risk of piracy and malware increases
Solution Approach 1:
The system segments the digital media device into distinct secure application environments that are operationally isolated from one another. Each environment can process different types of content (broadcast, internet, local) with appropriate security controls, allowing expanded content availability while containing security risks within isolated segments.
Solution Approach 2:
A security module acts as an intermediary between the secure application environments and the network/broadcast interfaces. This intermediary enforces security policies, validates content, and controls access to protected content, thereby enabling expanded content delivery while preventing piracy and malware execution.
2Reliability
If security measures are implemented to prevent piracy and malware in connected digital media devices, then content security is improved, but device complexity increases
Solution Approach 1:
The security module serves multiple functions: it manages security keys, creates security codes, validates content, controls access to secure application environments, and interfaces with both broadcast and network content sources. This multi-functionality provides comprehensive security without proportionally increasing device complexity.
Solution Approach 2:
The secure application environments are nested within the digital media device, with each environment containing isolated applications and content. The security module nests within the device architecture to provide centralized security control. This nested structure organizes complexity hierarchically, making the system more manageable while maintaining strong security.
3Adaptability or versatility
If multiple secure application environments are created for different content sources, then content processing capability is improved, but operational isolation complexity increases
Solution Approach 1:
The security module provides universal security services to all secure application environments through standardized interfaces. It manages security keys and creates security codes that can be used across different content sources (broadcast, internet, local), simplifying the management of multiple isolated environments while maintaining their operational independence.
Data Source
AI summary
An embodiment of the invention provides a method including accessing a portal pursuant to instructions from a digital media device and identifying the digital media device to the portal to enable the portal to obtain a security code. Information having the security code is received; and, it is confirmed that the security code corresponds to a security key stored in the digital media device. The information is provided to a secure application environment in the digital media device if the security code corresponds to the security key. A copy of the security key is sent to a clearinghouse; and, the security code is received from the clearinghouse. The security code is sent to a provider of the information if the information satisfies a predetermined criteria.


