Trusted Execution Environment for Secure Display Content
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The display of protected content, such as security-critical or digitally rights-managed information, is vulnerable to various threats between computing systems and display devices, necessitating secure processing and authentication protocols to ensure integrity and access control.
Innovation Solution
A system utilizing a trusted execution environment (TEE) for authentication, key exchange, and encryption of protected content, which includes secure encryption and decryption circuitry, secure storage, and manufacturer-agnostic management to reduce the trusted computing base and mitigate attacks, employing technologies like Software Guard Extensions (SGX) and Management Engine (ME) for secure processing and display.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If protected content is transmitted from computing system to display device, then content display functionality is enabled, but security vulnerabilities and attack surfaces are introduced
Solution Approach 1:
A trusted execution environment (TEE) acts as an intermediary between the computing system and display device. The TEE establishes secure authentication and key exchange protocols, generating session-specific cryptographic keys that protect content during transmission. This intermediary layer prevents direct vulnerable connections while enabling content display through secure channels.
Solution Approach 2:
The system segments security functions into a separate trusted execution environment isolated from the main computing system. The TEE handles authentication, key generation, and content protection independently, creating distinct security zones that reduce overall attack surface while maintaining content display capabilities.
2Reliability
If authentication and encryption protocols are implemented for protected content, then security and integrity are improved, but system complexity increases
Solution Approach 1:
Multiple security functions including authentication, key exchange, and content encryption are merged into a single trusted execution environment. This consolidation manages complexity by providing a unified security architecture rather than separate distributed security mechanisms, while maintaining comprehensive content protection.
Solution Approach 2:
The trusted execution environment autonomously performs authentication and key generation without requiring external security management infrastructure. The TEE self-manages cryptographic operations and security protocols, reducing the complexity burden on the overall system while ensuring reliable content protection.
3Reliability
If proprietary management engines are used for content protection, then security control is maintained, but trusted computing base size increases creating larger attack targets
Solution Approach 1:
Security control functions are extracted from proprietary management engines and relocated to a standardized trusted execution environment. This extraction reduces the trusted computing base to essential security functions only, minimizing the attack surface while maintaining reliable security control through standardized, auditable TEE mechanisms.
Data Source
AI summary
The present disclosure is directed to secure processing and display of protected content. The use of a trusted execution environment (TEE) to handle authentication and session key negotiation in accordance with a selected content protection protocol may reduce any trusted computing base (TCB) needed for such operations, and thereby present a smaller target for potential attackers. Techniques are presented in which a session key negotiated via such a TEE is securely provided to output circuitry such as a display controller, which may encrypt protected content that has been requested for viewing on a protocol-compliant display device communicatively coupled to a device comprising the TEE and/or the output circuitry. The output circuitry may then provide the encrypted protected content to the protocol-compliant display device, such as for compliant display of the protected content.


