Virtualized Media Storage via Segmented VMs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Consumer electronic devices face challenges in protecting media content from unauthorized redistribution and hacking, as downloaded files stored on general-purpose PCs are vulnerable to misuse, despite encryption and Digital Rights Management efforts.
Innovation Solution
A virtualized platform is used to create a secure, closed environment on a general-purpose PC, where media content is stored in a virtual disk partition accessible only to a special purpose virtual machine, preventing user access and enabling secure streaming without exposing the content to the general-purpose operating system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If media content is downloaded into files on a general purpose PC, then users can access and store the content locally, but the content becomes vulnerable to unauthorized redistribution and hacking
Solution Approach 1:
The system segments the PC into two distinct virtual machines: a special purpose VM that downloads and stores media content in an isolated secure environment, and a general purpose VM that users interact with for authorized content access. This segmentation prevents direct user access to the content files while maintaining local storage capabilities, thereby eliminating the vulnerability to unauthorized redistribution.
Solution Approach 2:
The patent introduces an intermediary streaming mechanism that allows the general purpose VM to access media content stored in the special purpose VM without direct file system access. The content is streamed through a controlled interface that enforces license terms and prevents unauthorized copying, thus maintaining ease of operation while protecting against harmful factors.
2Reliability
If encryption and Digital Rights Management are used to protect media content, then content security is improved, but these schemes are broken by determined hackers
Solution Approach 1:
The system separates the content storage function into a dedicated special purpose virtual machine that runs a simplified operating system designed specifically for secure content storage. This segmentation isolates the content from the complex general purpose OS that users interact with, maintaining security through architectural simplicity rather than complex encryption schemes that can be broken by hackers.
Solution Approach 2:
The patent creates a virtual copy of the PC environment that is functionally equivalent for content storage purposes but architecturally isolated. The special purpose VM is a simplified copy that lacks the complexity and vulnerabilities of a full general purpose OS, making it inherently more secure while maintaining the necessary content storage and streaming functions.
3Object-affected harmful factors
If media content is stored in a virtual disk partition accessible only to a special purpose virtual machine, then unauthorized access is prevented, but system complexity increases
Solution Approach 1:
The virtualized platform, while adding architectural layers, provides multi-functionality that justifies the complexity: it enables secure content storage, enforced license compliance, controlled streaming, and user interaction all within a unified system. The virtual machine monitor manages multiple virtual machines with different security requirements, making the complexity manageable and the system versatile.
Solution Approach 2:
The virtual machine monitor acts as an intermediary layer that manages the complexity of virtualization. It handles the isolation between the special purpose VM and general purpose VM, manages resource allocation, and enforces access controls, thereby abstracting the complexity from the user while maintaining secure content protection.
Data Source
AI summary
A method and system for the protected storage of downloaded media content via a virtualized platform. A method comprises downloading content to a special purpose virtual machine and then storing the downloaded content at a location, where the location is only accessible via the special purpose virtual machine. The stored content is then streamed over a virtual network to a general purpose virtual machine, where the special purpose virtual machine and the general purpose virtual machine exist on the same personal computer (PC).


