Security Processor Isolating Content During Transcoding
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current communication devices, such as Set-Top Boxes (STBs), are vulnerable to hacking and unauthorized access due to their increased connectivity to the Internet, which compromises the security of streamed audio and video content, allowing hackers to bypass code updates and intercept protected content for resale.
Innovation Solution
Implementing a multi-stage encryption system that includes a security CPU to verify the correct software version and restrict access to protected content, ensuring that only authorized content is made available to the central CPU during transcoding, and using a code version message that is inseparable from the encryption process to prevent hacking attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If STBs are connected to open networks like the Internet to enable applications, then versatility and functionality are improved, but security and protection of streamed content deteriorate
Solution Approach 1:
The patent divides the STB into two separate processing units: a central CPU for running applications and a security processor for handling content protection. This segmentation isolates the security-critical functions from the application execution environment, allowing the STB to access open networks while maintaining robust content security through dedicated hardware enforcement.
2Adaptability or versatility
If code updates are made accessible to the central CPU for application execution, then functionality is improved, but security against code tampering deteriorates
Solution Approach 1:
The patent extracts the security verification function from the central CPU and places it in a dedicated security processor. The security processor independently verifies code signatures and enforcement messages, separating the trust verification process from the application execution path. This extraction ensures that even if the central CPU executes untrusted code, the security processor maintains independent verification capabilities.
3Productivity
If the transcoder has access to unprotected digital content for processing, then transcoding functionality is improved, but risk of content interception deteriorates
Solution Approach 1:
The patent introduces a memory interface and direct memory access (DMA) mechanism as intermediaries between the secure memory containing unprotected content and the transcoder. The security processor controls access through this intermediary layer, allowing the transcoder to process content efficiently while preventing the central CPU from directly accessing or intercepting the content in memory.
4Reliability
If encryption is applied to digital content, then content protection is improved, but complexity of the system deteriorates
Solution Approach 1:
The patent merges the decryption and security verification functions into a single integrated security processor. This processor simultaneously handles decryption of scrambled content, verification of code signatures, validation of enforcement messages, and control of memory access. By combining these functions, the system achieves robust content protection without proportionally increasing complexity, as the security processor operates as a unified security management unit.
Data Source
AI summary
A Set Top Box (STB) or client computer includes a communication interface operable to receive digital messages and digital content, memory, a transcoder, a central processing unit, and security processing circuitry. The security processor (or other components of the STB) is operable to identify protected digital content of the digital content that is to be isolated from the central processing unit during transcoding and to isolate the protected digital content from the central processing unit during the transcoding. The CPU may be denied access to a protected portion of the memory during the transcoding in which the transcoder stores non-scrambled protected digital content. The protected portion of the memory may be buffer memory accessible by the transcoder and not accessible by the central processing unit. The protected digital content may be identified from the digital message.


