Set Top Box Mixed Secure Unsecure Media Pathways
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing media processing systems face challenges in integrating untrusted software frameworks and applications with secure operating system environments while maintaining compliance with industry certification standards and ensuring security, as unsecured components can compromise the security of secure pathways.
Innovation Solution
A media processing device with a key management and certification support system that establishes secure and unsecure media pathways using multiple hardware accelerated and software elements, dynamically adapting components based on security levels to isolate trusted and untrusted components and manage access, ensuring end-to-end security and compliance.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If untrusted software frameworks and applications are integrated with secure operating system environments, then functionality and adaptability are improved, but security and certification compliance deteriorate
Solution Approach 1:
The system is divided into multiple security domains including a secure domain with a secure operating system and an unsecure domain with untrusted frameworks. These domains are isolated through hardware boundaries and virtualization technologies, allowing untrusted applications to run without compromising the secure environment. The segmentation enables both security and functionality by containing potential threats within specific domains while preserving trusted operations in isolated secure zones.
Solution Approach 2:
A hypervisor or virtualization layer acts as an intermediary between untrusted frameworks and the secure operating system environment. This intermediary manages and controls access between domains, filtering and validating interactions to prevent unauthorized access to secure resources. The intermediary enables functionality from untrusted components while maintaining security boundaries, resolving the contradiction between adaptability and reliability.
2Reliability
If hardware boundaries are created to separate secure and untrusted components, then security is improved, but device complexity increases
Solution Approach 1:
Multiple security domains and isolation mechanisms are merged into a single integrated system managed by a hypervisor. Instead of implementing separate physical systems for secure and unsecure operations, the patent combines them into one device with logical separation through virtualization. This merging reduces overall device complexity while maintaining security boundaries, as the hypervisor consolidates management functions and resource allocation across domains.
Solution Approach 2:
The secure operating system and hypervisor infrastructure provide multi-functional capabilities that serve both secure and unsecure domains. A single hardware platform supports multiple security levels, certification compliance, and diverse application frameworks through universal abstractions and standardized interfaces. This universality reduces complexity by avoiding the need for separate dedicated hardware for each security domain while maintaining appropriate isolation and security controls.
Data Source
AI summary
A media processing device, such as a set top box, having a plurality of selectable hardware and software components for supporting multiple media pathways providing differing levels of security. In general, each security level corresponds to a particular certification service boundary definition(s) or key/authentication and security management scheme for managing resources such as hardware acceleration blocks and software interfaces. Different sets of components may be adaptively employed to ensure composited compliance with one or more security constraints and to address component unavailability. Security constraints may be applied, for example, on a source or media specific basis, and different versions of a media item may be provided over multiple pathways providing corresponding levels of security. In one embodiment, a service operator or content provider may provide requisite certification or security requirements, or otherwise assist in selection of pathway components.


