Secure Workspace for Transparent Secret Content Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Content providers face challenges in protecting proprietary content from being usurped by users, as traditional methods like legal agreements and encryption are either costly to enforce or vulnerable to hacking, and remote execution solutions impose high processing burdens on content providers.
Innovation Solution
A system that allows secret portions of content to be executed on a user device within a secure workspace inaccessible to the operating system and users, using a director module to direct content to a secure workspace for execution, with the content presentation module interacting with the secure workspace without direct access, employing technologies like Software Guard Extensions (SGX) for secure execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption is used to protect proprietary content, then content security is improved, but it becomes a target for hackers to circumvent, ultimately rendering the encryption useless
Solution Approach 1:
The patent extracts the secret portions of content from the general content delivery system and places them in a secure workspace that is inaccessible to the operating system, applications, and users. This separation removes the vulnerable encrypted content from the attack surface, as the secure workspace cannot be accessed or manipulated by external entities including hackers.
Solution Approach 2:
The patent segments content into regular portions and secret portions, directing only the secret portions to the secure workspace. This segmentation allows the system to maintain standard content delivery for most content while providing enhanced protection only where needed, without making the entire system a target for cryptographic attacks.
2Reliability
If remote execution is used to avoid placing data on user devices, then content security is improved, but processing burden on content providers increases substantially
Solution Approach 1:
The patent implements local secure execution on the user device rather than remote execution. The secure workspace is created locally on the user device with hardware-based protection, allowing secret content to be executed in a secure environment without requiring continuous remote processing. This shifts the processing burden from content providers to user devices while maintaining security.
3Ease of operation
If proprietary content is placed on user devices for digital delivery, then content accessibility is improved, but content protection becomes difficult
Solution Approach 1:
The patent introduces a secure workspace as an intermediary layer between the user device operating system and the proprietary content. This intermediary provides a protected environment where secret content can reside and execute, mediating between the need for local accessibility and the need for strong protection. The secure workspace acts as a buffer that allows content to be present on the device while preventing unauthorized access.
Data Source
AI summary
The present application is directed to transparent execution of secret content. A device may be capable of downloading content that may include at least one secret portion, wherein any secret portions of the content may be directed to a secure workplace in the device not accessible to device operating system components, applications, users, etc. The device may then present the content in a manner that allows secret portions of the content to be executed without direct access. For example, the device may download content, and a director module in the device may direct any secret portions of the downloaded content to a secure workspace. During execution of the content, any inputs required by the secret portions may be provided to the secure workspace, and any resulting outputs from the secret portions may then be used during content presentation.


