Secure Workspace for Transparent Secret Content Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Content providers face challenges in protecting proprietary content from being usurped by users, as traditional methods like legal agreements and encryption are either costly to enforce or vulnerable to hacking, and remote execution solutions impose high processing burdens on content providers.

Innovation Solution

A system that allows secret portions of content to be executed on a user device within a secure workspace inaccessible to the operating system and users, using a director module to direct content to a secure workspace for execution, with the content presentation module interacting with the secure workspace without direct access, employing technologies like Software Guard Extensions (SGX) for secure execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is used to protect proprietary content, then content security is improved, but it becomes a target for hackers to circumvent, ultimately rendering the encryption useless

Engineering Contradiction:
Improvecontent securityVSAvoidvulnerability to hacking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the secret portions of content from the general content delivery system and places them in a secure workspace that is inaccessible to the operating system, applications, and users. This separation removes the vulnerable encrypted content from the attack surface, as the secure workspace cannot be accessed or manipulated by external entities including hackers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments content into regular portions and secret portions, directing only the secret portions to the secure workspace. This segmentation allows the system to maintain standard content delivery for most content while providing enhanced protection only where needed, without making the entire system a target for cryptographic attacks.

Inventive Principle:
Principle #1Segmentation

2Reliability

If remote execution is used to avoid placing data on user devices, then content security is improved, but processing burden on content providers increases substantially

Engineering Contradiction:
Improvecontent securityVSAvoidprocessing burden
Core Design Contradiction:
ReliabilityVSPower

Solution Approach 1:

The patent implements local secure execution on the user device rather than remote execution. The secure workspace is created locally on the user device with hardware-based protection, allowing secret content to be executed in a secure environment without requiring continuous remote processing. This shifts the processing burden from content providers to user devices while maintaining security.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If proprietary content is placed on user devices for digital delivery, then content accessibility is improved, but content protection becomes difficult

Engineering Contradiction:
Improvecontent accessibilityVSAvoidcontent protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a secure workspace as an intermediary layer between the user device operating system and the proprietary content. This intermediary provides a protected environment where secret content can reside and execute, mediating between the need for local accessibility and the need for strong protection. The secure workspace acts as a buffer that allows content to be present on the device while preventing unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9767324B2Transparent execution of secret content
Publication Date: 2017.09.19 INTEL CORP
  • US9767324B2 patent drawing
  • US9767324B2 patent drawing
  • US9767324B2 patent drawing

AI summary

The present application is directed to transparent execution of secret content. A device may be capable of downloading content that may include at least one secret portion, wherein any secret portions of the content may be directed to a secure workplace in the device not accessible to device operating system components, applications, users, etc. The device may then present the content in a manner that allows secret portions of the content to be executed without direct access. For example, the device may download content, and a director module in the device may direct any secret portions of the downloaded content to a secure workspace. During execution of the content, any inputs required by the secret portions may be provided to the secure workspace, and any resulting outputs from the secret portions may then be used during content presentation.