SoC Authentication Processor Hardware Key Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Digital Rights Management (DRM) and Conditional Access (CA) technologies in system-on-a-chip (SoC) devices are vulnerable to unauthorized access due to software-based key storage, making them susceptible to hacking by malware or spyware.

Innovation Solution

Incorporating an authentication processor and a decryption processor within the SoC receiver, where the decryption key is generated and stored at a hardware level, preventing exposure to software codes and ensuring secure key exchange and decryption operations through a backdoor key loading technique.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based key storage is used in SoC devices, then ease of operation and implementation is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improveease of implementationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the software-based key storage system with a hardware-based security processor that physically isolates decryption keys from the main processor and software environment. This substitution moves the security function from a software layer (vulnerable to malware and spyware) to a dedicated hardware component with physical access controls, thereby maintaining ease of implementation while dramatically improving security against unauthorized access.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If decryption keys are exposed to software codes for processing, then ease of operation is improved, but vulnerability to hacking by malware or spyware increases

Engineering Contradiction:
Improvesoftware accessibilityVSAvoidvulnerability to hacking
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the decryption key from the software environment and places it in a separate, dedicated hardware security processor. The key never enters the software code space or main processor memory, eliminating the attack surface that malware and spyware would exploit. This extraction maintains the functional capability of decryption while removing the vulnerability to software-based attacks.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If hardware-level key storage is implemented, then security against malware or spyware is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security processor with the existing SoC device architecture, integrating it as a co-processor rather than a separate external component. This integration allows the security functions to be embedded within the existing device footprint, sharing physical packaging and interconnect resources, thereby improving security while minimizing the increase in overall device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2917867B1An improved implementation of robust and secure content protection in a system-on-a-chip apparatus
Publication Date: 2019.04.17 INTEL CORP
  • EP2917867B1 patent drawingFigure 1
  • EP2917867B1 patent drawingFigure 2
  • EP2917867B1 patent drawingFigure 3

AI summary

A content processing integrated circuit includes a system-on-a-chip (SoC) that further includes a processor to receive an authentication request from an external device for authenticating if the SoC is permitted to receive encrypted content from the external device, and to receive the encrypted content once the SoC is authenticated. An authentication processor is provided and coupled to the processor to authenticate the SoC to the external device when the processor receives the authentication request, and to generate a decryption key for decrypting the encrypted content. A decryption processor is provided and coupled to the processor and the authentication processor to receive the decryption key from the authentication processor and to decrypt the encrypted content with the decryption key. A wireless display system with such SoC is also described. A method of implementing a secure and robust content protection in a SoC is also described.