Set Top Box Security Pathway Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing media processing systems face challenges in integrating untrusted software frameworks with secure operating systems while maintaining compliance with industry certification standards and security measures, particularly in devices like set top boxes, where unsecured components can compromise the security of secure pathways.

Innovation Solution

A method and apparatus that utilize application-based security definitions to dynamically establish and manage media pathways with varying security levels, employing key management and certification support systems to segregate trusted and untrusted components, allowing for adaptive construction of secure or unsecure pathways based on security requirements, and enabling flexible compliance with certification procedures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If untrusted software frameworks are integrated into set top boxes to provide application programming interface functionality and platform independence, then adaptability and functionality are improved, but security compliance and certification reliability deteriorate

Engineering Contradiction:
Improveplatform independenceVSAvoidsecurity compliance
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the media pathway into multiple components with different security levels. Trusted components (secure OS, certified modules) are separated from untrusted components (software frameworks, applications). Each component is certified independently according to its security level, allowing the overall system to achieve certification while supporting untrusted frameworks.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security management intermediary is introduced that mediates between untrusted software frameworks and the secure operating system. This intermediary enforces security policies, controls access between trusted and untrusted zones, and ensures that framework operations comply with certification requirements without compromising the secure pathway.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a single secure and certified pathway is designed through all components of the set top box, then security compliance is improved, but adaptability and functionality deteriorate

Engineering Contradiction:
Improvesecurity complianceVSAvoidfunctionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Different parts of the media pathway are assigned different security qualities. The secure pathway components maintain high security certification, while framework components operate at lower security levels. Each component's security level matches its actual trust requirements, allowing the system to achieve certification for critical pathways while enabling flexible functionality in non-critical areas.

Inventive Principle:
Principle #3Local quality

3Reliability

If hardware boundaries are created to separate certified pathways from untrusted components, then security compliance is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of creating complex hardware boundaries, a software-based security management intermediary is used to separate trusted and untrusted components. This intermediary layer provides the necessary isolation and security enforcement through software mechanisms, reducing hardware complexity while maintaining security compliance.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If digital certificates are embedded in devices at manufacture to authenticate devices and prevent pirating, then security compliance is improved, but manufacturing complexity and cost increase

Engineering Contradiction:
Improvedevice authenticationVSAvoidmanufacturing process
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The authentication mechanism is segmented into hardware-embedded certificates for critical device identity and software-based security management for operational authentication. This allows essential authentication functionality to be manufactured simply while maintaining security compliance through software certification of the media pathway components.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2723094B1Set top box architecture with application based security definitions
Publication Date: 2019.08.21 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • EP2723094B1 patent drawingFigure 1
  • EP2723094B1 patent drawingFigure 2
  • EP2723094B1 patent drawingFigure 3A

AI summary

A media processing device, such as a set top box, having selectable hardware and software components for forming media pathways compliant with security definitions provided by downloaded or preinstalled software applications. Such applications may include, for example, a downloadable conditional access security or DRM element/definition. A corresponding certification process can entail certifying a portion of an overall secure pathway, with one or more applications providing the final portion of the certification. Alternatively, predefined conditional access mechanisms are provided, with an application establishing which mechanism is to be used. In various embodiments, a set top box or resident software application may exchange capabilities with other devices in a media consumption network to compare against the requirements of the software application. Once the information exchange is complete, the software application may select which one or more modes of operation or media pathways, if any, that it will permit.