Secure Virtual Machine Hardware Segmentation for Confidential Content Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional content processing in computing environments faces challenges such as security vulnerabilities, inefficiencies, and power wastage due to reliance on central processing units for handling licensee keys and algorithms, which compromises confidentiality and battery life during premium audio/video content playback.

Innovation Solution

A secure virtual machine system is implemented on a processor to abstract underlying hardware, constrain programmable operations, and execute programs within a secure environment, preventing potential security leaks and ensuring confidentiality by processing content using a graphics processing unit (GPU) instead of a central processing unit, thereby avoiding exposure of confidential information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If content processing is carried out using a central processing unit (CPU), then content can be processed and output, but confidential information such as licensee keys and algorithms is exposed inside the processor, creating security vulnerabilities

Engineering Contradiction:
ImprovesecurityVSAvoidprocessor architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the processor into two distinct contexts: a secure context for handling confidential content processing operations and a non-secure context for general application execution. This segmentation prevents exposure of confidential information by isolating it within the secure context, resolving the contradiction between security and processor complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure context acts as an intermediary between the confidential content processing operations and the non-secure application environment. This intermediary provides controlled access mechanisms that allow content processing while preventing unauthorized exposure of confidential information, thus improving security without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If tamper resistance technologies are used within a central processor designed for virtualization, then some security is provided, but the ability to guarantee a robust tamper-proof execution environment is lost due to hypervisors and higher priority execution contexts

Engineering Contradiction:
Improvetamper-proof execution environmentVSAvoidvirtualization compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements local quality by providing different security characteristics to different parts of the processor system. The secure context offers strong tamper resistance and guaranteed execution environment, while the non-secure context maintains virtualization compatibility. This localized approach resolves the contradiction between tamper-proof execution and virtualization adaptability.

Inventive Principle:
Principle #3Local quality

3Productivity

If general purpose central processing units are used for content processing, then content can be processed, but efficiency is reduced and power is wasted leading to reduction in battery life

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidpower consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The system implements dynamic context switching between secure and non-secure contexts based on the specific processing requirements. When confidential content processing is needed, the system dynamically transitions to the secure context with optimized processing capabilities, improving efficiency while consuming power only when necessary, thus resolving the contradiction between productivity and energy usage.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8868925B2Method and apparatus for the secure processing of confidential content within a virtual machine of a processor
Publication Date: 2014.10.21 NVIDIA CORP
  • US8868925B2 patent drawing
  • US8868925B2 patent drawing
  • US8868925B2 patent drawing

AI summary

A secure virtual machine system, method, and computer program product implemented on a processor are provided for processing a third party's content for output. At least one processor is provided. Additionally, at least one secure virtual machine implemented on the processor is provided for interpreting a second party's program that processes and outputs a third party's content. The virtual machine system abstracts the underlying processor hardware allowing implementation variations across products to execute the same program identically. Furthermore, the scope of the programmable operations, the types of input & output variables, and execution of programs within the processor, is deliberately constrained within the virtual machine environment, in order to mitigate potential security leaks by programs, and to ensure confidentiality of second party's secrets, and third party's content as managed by the second party's program.