WO2014099028A1 - Platform-hardened digital rights management key provisioning - Google Patents

Platform-hardened digital rights management key provisioning Download PDF

Info

Publication number
WO2014099028A1
WO2014099028A1 PCT/US2013/048513 US2013048513W WO2014099028A1 WO 2014099028 A1 WO2014099028 A1 WO 2014099028A1 US 2013048513 W US2013048513 W US 2013048513W WO 2014099028 A1 WO2014099028 A1 WO 2014099028A1
Authority
WO
WIPO (PCT)
Prior art keywords
client
provisioning
key
rights management
processor
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/US2013/048513
Other languages
French (fr)
Inventor
Siddhartha CHHABRA
Reshma LAL
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Intel Corp
Original Assignee
Intel Corp
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Intel Corp filed Critical Intel Corp
Priority to CN201380060355.3A priority Critical patent/CN104813336A/en
Publication of WO2014099028A1 publication Critical patent/WO2014099028A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/10Protecting distributed programs or content, e.g. vending or licensing of copyrighted material ; Digital rights management [DRM]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/08Key distribution or management, e.g. generation, sharing or updating, of cryptographic keys or passwords
    • H04L9/0816Key establishment, i.e. cryptographic processes or cryptographic protocols whereby a shared secret becomes available to two or more parties, for subsequent use
    • H04L9/0819Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s)
    • H04L9/0825Key transport or distribution, i.e. key establishment techniques where one party creates or otherwise obtains a secret value, and securely transfers it to the other(s) using asymmetric-key encryption or public key infrastructure [PKI], e.g. key signature or public key certificates

Definitions

  • the presem disclosure pertains to the field of information processing, and mote particularly, to the field of security in information processing systems. 2. Description of Related Art
  • Figure 1 illustrates a ystem, which ma include, enable, or participate in digital rights management key ro isi ing according to an embodiment of the present invention.
  • figure 2 illustrates an architecture for digital rights management key provisioning according to an embodiment of the present invention.
  • Figure 3 illustrates a method for pre-provisioning according to an embodiment of the present invention.
  • Figure 4 illustrated a method for provisioning according to an embodiment ofth present invention. Detailed Description
  • Embodiments of ao invention for platform-hardened digital rights management (DRM) key provisioning are described, in this description, numerous specific details, such as component and system confignrations, may be set forth in order to provide a more thorough understanding of the present invention. It will be appreciated, however, by one skilled in the art, that the invention may be practiced without, such specific details. Additionally, some well- known structures, circuits, and other features have not been shown in detail, to avoid
  • references to "one embodiment,” “an em o iment” “example embodiment” “ “various embodiments ' etc., indicate that the embodiment ⁇ ) of the invention so described may include particular features, structures, or characteristics, but more than one embodiment may and not every embodiment necessarily does include the particular .features, structures, or characteristics. Further, some embodiments may .have some, ail or none of the features described for other embodiments.
  • DRM Digital. Transmission Content Protection
  • DTCP Digital. Transmission Content Protection
  • DTCP Digital. Transmission Content Protection
  • .Embodiments of the present invention provide tor the use of security features of a processor to ensure that this set of keys and related information may be securely provided to and. then securely stored by the client so that the . provisioning need not be repealed.
  • a platform-hardened approach provided by an embodiment of the present invention may be preferable to an alternative approach such as one using tamper resistant software o another obfuscaiion technique.
  • Figure 1 illustrates system 100, an information processing system in which an embodiment of the present, invention may be present and/or operate or which may be a part of an embodiment of the present in vention.
  • System 100 may represent any type of information processing system, such as a server,, a desktop computer, a portable, computer, a set-top box, a hand-held device, or an embedded control system.
  • System 100 includes processor 1 10, system memor 130, and information storage device 140.
  • Systems embodying the present invention may include an number of each of these components and any other components or other elements, such as information storage devices, peripherals, and input/output devices.
  • System memory 130 may be dynamic random, access memory or any other type of medium readable by processor i 10.
  • Information storage device 140 may include any type of persistent or son- volatile -memory or storage, such as a flash memory and/or a solid state, magnetic, or optica! disk drive.
  • Processor 1 10 may -represent one or more processors integrated on a single substrate or packaged within a s ingle package, each of which ma include multiple threads and/or multiple execution cores, in any combination.
  • Each processor represented as processor 1 10 may be any type of processor, including a general purpose microprocessor, such as a processor in. the In tel® Core® Processor Family, Intel® Atom® Processor Family, or other processor family .from Intel® Corporation, or another processor from another company, or a special purpose processor or microcontroller.
  • Processor f may be any type of processor, including a general purpose microprocessor, such as a processor in. the In tel® Core® Processor Family, Intel® Atom® Processor Family, or other processor family .from Intel® Corporation, or another processor from another company, or a special purpose processor or microcontroller.
  • Processor i 1.0 may include instruction unit i l l, execution unit 1 1 2, processing storage 1 13, interface unit .1 14, processor conirof unit 1.15, cache memory 1 16, random .number generator ( NG) 1 17, and secure enclave unit 120.
  • Processor i 1.0 may also include any other circuitry, structures, or logic not shown in Figure 1 , and/or any circuitry, structures, or logic shown or described as elsewhere in Figure f .
  • Instruction unit i f. 1. may represent any circuitry, structure, or other hardware, such as an instruction decoder, for fetching, receiving, decoding, and or scheduling instructions.
  • Arty instruction ormat may be used within the scope o the present, in vention; for example, an instruction may include an opcode and one or more operands, where the opcode may be decoded into one or more micro-instructions or micro-operations for execution by execution unit i 12,
  • Execution unit 1.12 may include any circuitry, structure, or other hardware, such as an arithmetic unit, logic unit, floating point unit, shi fter, etc, for processing data and executing instructions, micro-instructious, and/or micro-operations.
  • Processing storage 1 13 may represent any type of storage usable for any purpose within processor 1 10; for example, it may include any number of data registers, instruction registers, statu registers, configuration registers, control registers, other programmable or hard-coded registers or register files, or any other storage structures.
  • Interface unit 1. 1.4 may represent any circuitry, structure, or ther hardware, such as a bus unit, messaging unit, or any other unit, port, or interface, to allow processor 1 10 So communicate wi th o ther components in system 1.00 through an type of bus, point to point or other connection, directly or through any oilier component, such as a memory controller or a bus bridge.
  • Processor control unit 1 15 may include any logic, microcode, circuitry, or other hardware to control the operation of the units and other elements of processor 1 1 and the transfer of data s within, into, and out of processor 1 10.
  • Processor control unit 115 may cause processor 1 10 to perform or participate in (he performance of method embodiments of the present invention, such as the method embodiments described below, tor example, by causing processor HO to execute instructions received by instruction unit 1 1 1 and micro-instructions or micro-operations derived from instructions received by instruction unit 1 i 1 .
  • Cache memory I 16 " may represent any one or more levels of cache memory in a memory hierarchy of information processing system 100. implemented in static random access memory or any other memory technology.
  • Cache memory 1.1.6 may include any combination of cache memories dedicated to or shared among any one or more execution cores or processors wi hin processor 1 10 according to any known approaches to caching in information processing systems
  • RNG 1 17 may include any circuitry, structure, or other hardware to generate random numbers or pseudo-random numbers according to any known technique.
  • RNG ⁇ 7 is a digital RNG within processor 1 10; however, in other embodiments, RNG 1 1 7 may be any type of RNG separate from processor 1 10.
  • Secure enclave unit 120 may represent any logic, circuitry, hardware, or other structures for creating and maintaining a secured, protected, or isolated environment; such as a secure enclave as described herein, in which an application or other software may run, execute, be loaded, or otherwise be present within an information processing system such, as system 1.00.
  • a secure enclave each instance of such an environment may be referred to as a secure enclave, although embodiments of the present invention are not limited to those using a secure enclave as the secured, protected, or isolated en vironment, hi one embodiment, a secure enclave may be created and maintained using instructions in the instruction set of a processor in the Intel® Core® Processor Family or other processor family from Intel® Corporation .
  • Ail or part of secure enclave unit .120 may he included within, any one or more other units of processor 1 10, such as instruction unit 11 1 , execution unit 1 12, processor storage 1 13, and processor control unit S.1.5.
  • Secure enclave unit 120 may include encryption unit 1.22, which, may include any logic, circuitry, or other hardware to execute one or more encryption algorithms and the corresponding decryption algorithms, and may include logic, circuitry, or other hardware shared with another encryption unit in processor 1 1 .
  • Each secure enclave created within system 1 0 may be allocated a secure or protected space within the system memory space supported by system memory 130.
  • Secure memory 132 represents one or more such secure or protected memory spaces.
  • Each such memory apace may be created, allocated, and maintained using known virtual memory, secure enclave, or other system memory addressing techniques such that the information within each such memory space may at various times be stored within any combination of information storage device 140, system memory 130, cache memory 1 16, processing storage 1 13, and/or any other memory or storage area within information processing system 100.
  • Secure memory 132 may include one or more physically contiguous ranges of memory called processor reserved memory (PRM).
  • PRM processor reserved memory
  • a PRM is naturally aligned and has a size that is an integer power of two.
  • System firmware such as a basic input output system may reserve a PRM, for example by setting a pair of model-specific registers (MSRs), collectively known as a PRM range register (PRMRR),
  • PRMRR PRM range register
  • secure enclave logic 320 may include PRMRR 124. PRMRR 124 may be used to reserve PRM 134 for processor 1 1 in secure memory 132.
  • Secure enclave unit 120 may also include access control unit 126, which may include any logic, circuitry, hardware, or other structures to enforce load and access restrictions using PRMRR 124 such that the information within the memory space of a secure enclave is accessible only to the application running in mat secure enclave.
  • access control unit 126 may include any logic, circuitry, hardware, or other structures to enforce load and access restrictions using PRMRR 124 such that the information within the memory space of a secure enclave is accessible only to the application running in mat secure enclave.
  • the information on a memory page allocated to a secure enclave may be encrypted by encryption unit 122 before being stored in system memory 130, information storage device 1 0, or any other memory or storage external to processor 1 10. While stored external to processor 1 10, the information is protected by encryption and integrity check techniques.
  • the memory page When the memory page is loaded into cache memory 1 1.6 by an application or process running on processor 1 10 within the secure enclave to which the page is allocated, it is decrypted by encryption unit 122, then the unencrypted information is accessible only by an. application or process running within the secure enclave.
  • FIG. 2 illustrates architecture 200 for DRM key provisioning according to an embodiment, of the present invention.
  • Architecture 200 includes client platform 210, key issuer 220, verifier 230, provisioning server 240, and content server 250.
  • Client platform 210 represents a system or plat.fo.mi to run ' n application to use content to be provided by content server 250.
  • the content may be, for example, any t pe of audio, visual, or other media content.
  • Client platform 21 may be implemented as an embodiment of s information processing system 100. Therefore, secure enclave 212 may be created and maintained on client platform 210, and the application, cheat 21.4, which may be, for example, a DTCP media player, may ran within secure enclave 212,
  • Key issuer 220 represents an application., system, platform, or other entity to issue public/private key pairs which may be used for a third party verifier to remotely verify the authenticity of a hardware platform s «ch as client platform 10. in one embodiment, this verification may be performed without revealing the identity of the hardware platform bein authenticated, for example, according to the Intel® Enhanced. Privacy identification (EP!D) scheme.
  • EP!D Intel® Enhanced. Privacy identification
  • Verifier 230 represents an application, system, platform, or other entity to verily the au hent city of a hardware platform according to the approach, supported by key issuer 220.
  • Provisioning server 240 represents an application, system, platform, or other entity to provide a key or ' keys and/or other information to establish a client as a consumer of secure transmissions of content.
  • server 240 may be a DTCP provisioning server according to the Digital Transmission Licensing Admini trator.
  • Content server 250 represents an application, system, platform, or other entity to provide content and/or other information through a secure transmission.
  • content server 250 may be a DTCP content server.
  • Figure 3 illustrates method 300 for pre-provisioning according to an embodiment of th present invention
  • Figure 4 illustrates method 400 for provisioning according to an embodiment of the present invention.
  • Method 300 may be performed to enable the platform security features used in method 400 or another method for provisioning according to an embodiment, of the present invention.
  • method, embodiments of the invention are not limited in this respect, reference may be made to elements of Figures I and 2 to help describe the method embodiments of Figures 3 and 4.
  • provisioning information is provided to provisioning server 240.
  • the provisioning information may he the provisioning information that the DTLA specifies to be used by a DTCP client to obtain content from a DTCP content provider.
  • This DTCP provisioning information is a unique device identifier, a public/private key pair (a DTCP key pair), a device certificate, and a revocation mechanism. The first three of these will be referred to collectively as the DTCP provisioning information 242.
  • DTCP provisioning information 242 may be provided by the DTLA in plaintext on media such as a DVD-ROM.
  • hi box 312 public key certificates of verifier 230 are provided to provisioning server 240. These may be provided by a third, part certificate authority.
  • secure enclave 212 is created on client platform 210.
  • clien 214 is initiated within secure enclave 2.12.
  • key issuer 220 In box 330, key issuer 220 generates EPl ' D public key 222 to be used with an EPID private key as pan of a. key pair for authentication of hardware. This key pair may be referred to as an EPID key pair, although other authentication schemes may he used within the scope of the present invention, in box 332, key issuer 220 generates unique EPID private key 224 for the EPID key pair. Note that other unique private keys may also be generated and used for authentication of other hardware with EPID public key 222.
  • key issuer 220 provides EPID private key 224 to client 214.
  • key issuer 220 provides EPID pubic key 222 to verifier 230,
  • an independent software vendor i fS generates a report or measurement of the unmodified software of client 214.
  • the IS V sends the measurement of unmodified software to verifier 230, for verifier 230 to use during provisioning to verify the authenticity of client 21 .
  • provisioning server 240 a provisioning request.
  • provisioning server 240 receives the provisioning request from client 21 .
  • provisioning server 240 generates a first, key component CB 5 ) that may be used to generate a shared secret key, for example, through a Diffie-Helfman (DH) key exchange, Therefore, box 422 may be performed by the operation 'B-g3 ⁇ 4iod ' where 5 b' is private to provisioning server 240 and ' g and ' ' are public.
  • the Diffi -Heli an key exchange may use the SIGMA protocol io avoid maiwn-the-ntiddie attacks. However, any key exchange protocol may be used with, the scope of the present, invention.
  • provisioning server 240 sends to client 214 a challenge for client 214 to prove its authenticity. Sending the challenge may include sending the identity of a verifier to use to pro vide proof of authenticity (e.g., verifier 230). In box 426, provisioning server 240 sends to client 2.14 the first key component.
  • client 214 receives the identity of verifier 230 from provisioning sa ver 240.
  • client 214 receives the first key component from provisioning server 240.
  • client 2.14 in box 440, client 2.14 generates a report or measurement of its identity, which may be performed, for example, within secure enclave 212 by using the EREPORT instruction, which is a leaf of the E CLU instruction.
  • client 214 signs the report using EPID private key 224.
  • client 214 uses the identity information provided by provisioning server 240 to identify verifier 230.
  • client 214 initiates a verification request to verifier 230.
  • client 214 sends its signed identity report to verifier 230, and may also send other information such an ISV certificate and a security version number.
  • verifier 230 receives the signed identity report from client 214.
  • verifier 230 attempts to verify the signed identity report using unmodified software measurement 216 and EPID public key 222. if the verification is successful, then, in box 454. verifier 230 sends an authentication certificate to client 2 14, and method.400 continues in box 460. If the verification is not successful, method 400 does not continue.
  • client 214 receives the authentication certificate from verifier 230, in box 460.
  • client 214 generates a second key component C A') that may be used to generate the shared secret key, for example, through a Diffie-He!lman (DH) key exchange. Therefore, box 462 may be performed by the operation 'A-g ⁇ raod p * where "a' is private to client 214. In box 464, client.
  • client 214 sends its authentication certificate to provisioning server 240.
  • client 214 sends the second key component to provisioning server 240.
  • client 214 generates the shared secret key using the first ke component and the second key component.
  • provisioning server 240 receives the authentication certificate from client
  • provisioning server 240 receives the second key component from, client 214.
  • provisioning server 240 determines whether the authentication certificate is valid, in so, then method 400 continues in box 480. If not, then method.400 does not continue.
  • provisioning server 240 in box 480, provisioning server 240 generates the shared secret key using the first key component and the second key component In box 482, provisioning server 240 uses the shared secret key to encrypt the provisioning information (e.g., DTCP provisioning information 242).
  • provisioning information e.g., DTCP provisioning information 242.
  • provisioning server 240 sends the encrypted provisioning information to client 214.
  • client 21 receives the encrypted provisioning information from provisioning server 240.
  • client 214 decrypts the provisioning information using the shared secret key.
  • client 214 seals the provisioning information to secure enclave 212, for example using the ESEAL Instruction to provide for storing the provisioning information with confidentiality and integrity.
  • the SEAL instruction uses the secure enclave's unique key to encrypt data such that the UNSEAL feature may use the same secure enclave's unique key to decrypt the data and detect my changes to the data, ensuring confidentiality and integrity of the data.
  • the sealed provisioning information may be stored in storage device 140. Therefore, the provisioning information may now be made ready for use by client 21.4 in secure enclave 212, using the UNSEAL feature, such that client 214 rnsy use content from content server 250 without repeating the provisioning request to provisioning server 240.
  • the methods illustrated in Figures 3 and 4. may be performed in a different order, with illustrated boxes combined or omitted, with additional ' boxes added, or with a combination of reordered, combined, omitted, or additional boxes, furthermore, many other method embodiments are possible within the scope of the present invention.
  • Embodiments or portions of embodiments of the present, invention may be stored on any form of a machine-readable medium.
  • all or part of methods 300 or 400 may be embodied in software or firmware instructions that are stored on a medium, readable by processor 1 10, which when executed by processor ⁇ it), cause processor ! i 0 to execute an embodiment of the present invention.
  • aspects of the present invention may be embodied in data stored on a machine-readable medium, where the data represents a design or other information, usable to fabricate all or pan of processor 1.10,

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • Software Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Multimedia (AREA)
  • Technology Law (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Storage Device Security (AREA)

Abstract

Embodiments of an invention for platform-hardened digital rights management key provisioning are disclosed. In one embodiment, a processor includes an execution unit to execute one or more instructions to create a secure enclave in which to run an application to receive digital rights management information from a provisioning server in response to authentication of the application by a verification server.

Description

PLATFORM-HARDENED
DIGITAL RIGHTS MANAGEMENT KEY PROVISIONING BACKGROUND
1 . Field
The presem disclosure pertains to the field of information processing, and mote particularly, to the field of security in information processing systems. 2. Description of Related Art
Many applications of information processing systems require provisioning of a key or keys to a content consumer in order to initiate secure communication with a content server. For example, some approaches to digital rights management require the use of one or more keys to protect the transmission of audio and video content. The secure provisioning of these keys is important to ensuring the security of this approach.
Brief Description of the Figures
The present invention is illustrated by-way of example and not limitation in the accompanying figures.
Figure 1 illustrates a ystem, which ma include, enable, or participate in digital rights management key ro isi ing according to an embodiment of the present invention.
figure 2 illustrates an architecture for digital rights management key provisioning according to an embodiment of the present invention.
Figure 3 illustrates a method for pre-provisioning according to an embodiment of the present invention.
Figure 4 illustrated a method for provisioning according to an embodiment ofth present invention. Detailed Description
Embodiments of ao invention for platform-hardened digital rights management (DRM) key provisioning are described, in this description, numerous specific details, such as component and system confignrations, may be set forth in order to provide a more thorough understanding of the present invention. It will be appreciated, however, by one skilled in the art, that the invention may be practiced without, such specific details. Additionally, some well- known structures, circuits, and other features have not been shown in detail, to avoid
unnecessarily obscuring the present invention.
In the following description, references to "one embodiment," "an em o iment" "example embodiment " "various embodiments ' etc., indicate that the embodiment^) of the invention so described may include particular features, structures, or characteristics, but more than one embodiment may and not every embodiment necessarily does include the particular .features, structures, or characteristics. Further, some embodiments may .have some, ail or none of the features described for other embodiments.
As used in the claims, unless otherwise specified the use of the ordinal, adjectives "first," "second," "third," etc. to describe an element merely i ndicate thai a particular instance of an element or different instances of like elements are being referred to, and is not intended to imply thai the elements so described must be in a particular sequence, either temporally, spatially, in ranking, or in any other manner.
As described in the background section, some approaches to DRM, such as Digital. Transmission Content Protection (DTCP), require the use of a pair of keys to protect the transmission of audio and video content from a server to a clien t. .Embodiments of the present invention provide tor the use of security features of a processor to ensure that this set of keys and related information may be securely provided to and. then securely stored by the client so that the .provisioning need not be repealed. A platform-hardened approach provided by an embodiment of the present invention may be preferable to an alternative approach such as one using tamper resistant software o another obfuscaiion technique.
Figure 1 illustrates system 100, an information processing system in which an embodiment of the present, invention may be present and/or operate or which may be a part of an embodiment of the present in vention. System 100 may represent any type of information processing system, such as a server,, a desktop computer, a portable, computer, a set-top box, a hand-held device, or an embedded control system. System 100 includes processor 1 10, system memor 130, and information storage device 140. Systems embodying the present invention may include an number of each of these components and any other components or other elements, such as information storage devices, peripherals, and input/output devices. Any or ail of the components or other elements in this or any system embodiment, may be connected, coupled, or otherwise in communication with each other through any number of buses, point-to- point, or other wired or wireless interfaces or connections, unless specified, otherwise. System memory 130 may be dynamic random, access memory or any other type of medium readable by processor i 10. Information storage device 140 may include any type of persistent or son- volatile -memory or storage, such as a flash memory and/or a solid state, magnetic, or optica! disk drive.
Processor 1 10 may -represent one or more processors integrated on a single substrate or packaged within a s ingle package, each of which ma include multiple threads and/or multiple execution cores, in any combination. Each processor represented as processor 1 10 may be any type of processor, including a general purpose microprocessor, such as a processor in. the In tel® Core® Processor Family, Intel® Atom® Processor Family, or other processor family .from Intel® Corporation, or another processor from another company, or a special purpose processor or microcontroller. Processor f. 1.0 may include instruction unit i l l, execution unit 1 1 2, processing storage 1 13, interface unit .1 14, processor conirof unit 1.15, cache memory 1 16, random .number generator ( NG) 1 17, and secure enclave unit 120. Processor i 1.0 may also include any other circuitry, structures, or logic not shown in Figure 1 , and/or any circuitry, structures, or logic shown or described as elsewhere in Figure f .
Instruction unit i f. 1. may represent any circuitry, structure, or other hardware, such as an instruction decoder, for fetching, receiving, decoding, and or scheduling instructions. Arty instruction ormat may be used within the scope o the present, in vention; for example, an instruction may include an opcode and one or more operands, where the opcode may be decoded into one or more micro-instructions or micro-operations for execution by execution unit i 12, Execution unit 1.12 may include any circuitry, structure, or other hardware, such as an arithmetic unit, logic unit, floating point unit, shi fter, etc, for processing data and executing instructions, micro-instructious, and/or micro-operations.
Processing storage 1 13 may represent any type of storage usable for any purpose within processor 1 10; for example, it may include any number of data registers, instruction registers, statu registers, configuration registers, control registers, other programmable or hard-coded registers or register files, or any other storage structures.
Interface unit 1. 1.4 may represent any circuitry, structure, or ther hardware, such as a bus unit, messaging unit, or any other unit, port, or interface, to allow processor 1 10 So communicate wi th o ther components in system 1.00 through an type of bus, point to point or other connection, directly or through any oilier component, such as a memory controller or a bus bridge.
Processor control unit 1 15 may include any logic, microcode, circuitry, or other hardware to control the operation of the units and other elements of processor 1 1 and the transfer of data s within, into, and out of processor 1 10. Processor control unit 115 may cause processor 1 10 to perform or participate in (he performance of method embodiments of the present invention, such as the method embodiments described below, tor example, by causing processor HO to execute instructions received by instruction unit 1 1 1 and micro-instructions or micro-operations derived from instructions received by instruction unit 1 i 1 .
Cache memory I 16" may represent any one or more levels of cache memory in a memory hierarchy of information processing system 100. implemented in static random access memory or any other memory technology. Cache memory 1.1.6 may include any combination of cache memories dedicated to or shared among any one or more execution cores or processors wi hin processor 1 10 according to any known approaches to caching in information processing systems, RNG 1 17 may include any circuitry, structure, or other hardware to generate random numbers or pseudo-random numbers according to any known technique. In this embodiment, RNG Π 7 is a digital RNG within processor 1 10; however, in other embodiments, RNG 1 1 7 may be any type of RNG separate from processor 1 10.
Secure enclave unit 120 may represent any logic, circuitry, hardware, or other structures for creating and maintaining a secured, protected, or isolated environment; such as a secure enclave as described herein, in which an application or other software may run, execute, be loaded, or otherwise be present within an information processing system such, as system 1.00. For purposes of this description, each instance of such an environment may be referred to as a secure enclave, although embodiments of the present invention are not limited to those using a secure enclave as the secured, protected, or isolated en vironment, hi one embodiment, a secure enclave may be created and maintained using instructions in the instruction set of a processor in the Intel® Core® Processor Family or other processor family from Intel® Corporation .
Although there are multiple embodiments of multiple aspects of the invention, the co-pending U.S. Patent Application entitled "Method and Apparatus to Provide Secure Application
Execution," filed June 1 , 2012, Serial No. 1 3/527,547, is hereby incorporated by reference as an example of at least one embodiment of a secure enclave. However, the incorporated reference is not intended to limit the scope of embodiments of the invention in any way and other embodiments may be used while remaining within the spirit and scope of the invention.
Ail or part of secure enclave unit .120 may he included within, any one or more other units of processor 1 10, such as instruction unit 11 1 , execution unit 1 12, processor storage 1 13, and processor control unit S.1.5. Secure enclave unit 120 may include encryption unit 1.22, which, may include any logic, circuitry, or other hardware to execute one or more encryption algorithms and the corresponding decryption algorithms, and may include logic, circuitry, or other hardware shared with another encryption unit in processor 1 1 .
Each secure enclave created within system 1 0 may be allocated a secure or protected space within the system memory space supported by system memory 130. Secure memory 132 represents one or more such secure or protected memory spaces. Each such memory apace may be created, allocated, and maintained using known virtual memory, secure enclave, or other system memory addressing techniques such that the information within each such memory space may at various times be stored within any combination of information storage device 140, system memory 130, cache memory 1 16, processing storage 1 13, and/or any other memory or storage area within information processing system 100.
Secure memory 132 may include one or more physically contiguous ranges of memory called processor reserved memory (PRM). In one embodiment, a PRM is naturally aligned and has a size that is an integer power of two. System firmware such as a basic input output system may reserve a PRM, for example by setting a pair of model-specific registers (MSRs), collectively known as a PRM range register (PRMRR), In the embodiment of Figure .1 , secure enclave logic 320 may include PRMRR 124. PRMRR 124 may be used to reserve PRM 134 for processor 1 1 in secure memory 132.
Secure enclave unit 120 may also include access control unit 126, which may include any logic, circuitry, hardware, or other structures to enforce load and access restrictions using PRMRR 124 such that the information within the memory space of a secure enclave is accessible only to the application running in mat secure enclave. .For example, the information on a memory page allocated to a secure enclave may be encrypted by encryption unit 122 before being stored in system memory 130, information storage device 1 0, or any other memory or storage external to processor 1 10. While stored external to processor 1 10, the information is protected by encryption and integrity check techniques. When the memory page is loaded into cache memory 1 1.6 by an application or process running on processor 1 10 within the secure enclave to which the page is allocated, it is decrypted by encryption unit 122, then the unencrypted information is accessible only by an. application or process running within the secure enclave.
Figure 2 illustrates architecture 200 for DRM key provisioning according to an embodiment, of the present invention. Architecture 200 includes client platform 210, key issuer 220, verifier 230, provisioning server 240, and content server 250.
Client platform 210 represents a system or plat.fo.mi to run' n application to use content to be provided by content server 250. The content may be, for example, any t pe of audio, visual, or other media content. Client platform 21 may be implemented as an embodiment of s information processing system 100. Therefore, secure enclave 212 may be created and maintained on client platform 210, and the application, cheat 21.4, which may be, for example, a DTCP media player, may ran within secure enclave 212,
Key issuer 220 represents an application., system, platform, or other entity to issue public/private key pairs which may be used for a third party verifier to remotely verify the authenticity of a hardware platform s«ch as client platform 10. in one embodiment, this verification may be performed without revealing the identity of the hardware platform bein authenticated, for example, according to the Intel® Enhanced. Privacy identification (EP!D) scheme.
Verifier 230 represents an application, system, platform, or other entity to verily the au hent city of a hardware platform according to the approach, supported by key issuer 220.
Provisioning server 240 represents an application, system, platform, or other entity to provide a key or 'keys and/or other information to establish a client as a consumer of secure transmissions of content. For example, server 240 may be a DTCP provisioning server according to the Digital Transmission Licensing Admini trator.
Content server 250 represents an application, system, platform, or other entity to provide content and/or other information through a secure transmission. For example, content server 250 may be a DTCP content server.
Figure 3 illustrates method 300 for pre-provisioning according to an embodiment of th present invention, and Figure 4 illustrates method 400 for provisioning according to an embodiment of the present invention. Method 300 may be performed to enable the platform security features used in method 400 or another method for provisioning according to an embodiment, of the present invention. Although method, embodiments of the invention are not limited in this respect, reference may be made to elements of Figures I and 2 to help describe the method embodiments of Figures 3 and 4.
hi box 31 , provisioning information is provided to provisioning server 240. in one embodiment, the provisioning information may he the provisioning information that the DTLA specifies to be used by a DTCP client to obtain content from a DTCP content provider. This DTCP provisioning information is a unique device identifier, a public/private key pair (a DTCP key pair), a device certificate, and a revocation mechanism. The first three of these will be referred to collectively as the DTCP provisioning information 242. DTCP provisioning information 242 may be provided by the DTLA in plaintext on media such as a DVD-ROM. hi box 312, public key certificates of verifier 230 are provided to provisioning server 240. These may be provided by a third, part certificate authority. s In box 320, secure enclave 212 is created on client platform 210. In box 322, clien 214 is initiated within secure enclave 2.12.
In box 330, key issuer 220 generates EPl'D public key 222 to be used with an EPID private key as pan of a. key pair for authentication of hardware. This key pair may be referred to as an EPID key pair, although other authentication schemes may he used within the scope of the present invention, in box 332, key issuer 220 generates unique EPID private key 224 for the EPID key pair. Note that other unique private keys may also be generated and used for authentication of other hardware with EPID public key 222.
In box 340, key issuer 220 provides EPID private key 224 to client 214.
In box 350, key issuer 220 provides EPID pubic key 222 to verifier 230,
in box 360, an independent software vendor i fS ) generates a report or measurement of the unmodified software of client 214. In box 362. the IS V sends the measurement of unmodified software to verifier 230, for verifier 230 to use during provisioning to verify the authenticity of client 21 .
in box 410 of Figure 4, client 21.4 running inside secure enclave 12 sends to
provisioning server 240 a provisioning request.
In box 420, provisioning server 240 receives the provisioning request from client 21 . In box 422, provisioning server 240 generates a first, key component CB5) that may be used to generate a shared secret key, for example, through a Diffie-Helfman (DH) key exchange, Therefore, box 422 may be performed by the operation 'B-g¾iod ' where 5b' is private to provisioning server 240 and 'g and ' ' are public. The Diffi -Heli an key exchange may use the SIGMA protocol io avoid maiwn-the-ntiddie attacks. However, any key exchange protocol may be used with, the scope of the present, invention.
In box 424, provisioning server 240 sends to client 214 a challenge for client 214 to prove its authenticity. Sending the challenge may include sending the identity of a verifier to use to pro vide proof of authenticity (e.g., verifier 230). In box 426, provisioning server 240 sends to client 2.14 the first key component.
In box 430, client 214 receives the identity of verifier 230 from provisioning sa ver 240. In box 432, client 214 receives the first key component from provisioning server 240.
in box 440, client 2.14 generates a report or measurement of its identity, which may be performed, for example, within secure enclave 212 by using the EREPORT instruction, which is a leaf of the E CLU instruction. In box 442, client 214 signs the report using EPID private key 224. In box 444, client 214 uses the identity information provided by provisioning server 240 to identify verifier 230. in box 446, client 214 initiates a verification request to verifier 230. In box 448, client 214 sends its signed identity report to verifier 230, and may also send other information such an ISV certificate and a security version number.
In box 450, verifier 230 receives the signed identity report from client 214. In box 452, verifier 230 attempts to verify the signed identity report using unmodified software measurement 216 and EPID public key 222. if the verification is successful, then, in box 454. verifier 230 sends an authentication certificate to client 2 14, and method.400 continues in box 460. If the verification is not successful, method 400 does not continue.
in box 460, client 214 receives the authentication certificate from verifier 230, in box
462, client 214 generates a second key component C A') that may be used to generate the shared secret key, for example, through a Diffie-He!lman (DH) key exchange. Therefore, box 462 may be performed by the operation 'A-g^raod p* where "a' is private to client 214. In box 464, client.
214 sends its authentication certificate to provisioning server 240. In box 466, client 214 sends the second key component to provisioning server 240. In box 468, client 214 generates the shared secret key using the first ke component and the second key component.
In box 4 /0, provisioning server 240 receives the authentication certificate from client
214. in box 472, provisioning server 240 receives the second key component from, client 214.
In box 474, provisioning server 240 determines whether the authentication certificate is valid, in so, then method 400 continues in box 480. If not, then method.400 does not continue.
in box 480, provisioning server 240 generates the shared secret key using the first key component and the second key component In box 482, provisioning server 240 uses the shared secret key to encrypt the provisioning information (e.g., DTCP provisioning information 242).
In box 484, provisioning server 240 sends the encrypted provisioning information to client 214.
In box 490, client 21 receives the encrypted provisioning information from provisioning server 240. In box 492, client 214 decrypts the provisioning information using the shared secret key. In box 494, client 214 seals the provisioning information to secure enclave 212, for example using the ESEAL Instruction to provide for storing the provisioning information with confidentiality and integrity. The SEAL instruction uses the secure enclave's unique key to encrypt data such that the UNSEAL feature may use the same secure enclave's unique key to decrypt the data and detect my changes to the data, ensuring confidentiality and integrity of the data.
In box 496, the sealed provisioning information may be stored in storage device 140. Therefore, the provisioning information may now be made ready for use by client 21.4 in secure enclave 212, using the UNSEAL feature, such that client 214 rnsy use content from content server 250 without repeating the provisioning request to provisioning server 240. In various embodiments of the present invention, the methods illustrated in Figures 3 and 4.may be performed in a different order, with illustrated boxes combined or omitted, with additional 'boxes added, or with a combination of reordered, combined, omitted, or additional boxes, furthermore, many other method embodiments are possible within the scope of the present invention.
Embodiments or portions of embodiments of the present, invention, as described above, may be stored on any form of a machine-readable medium. For example, all or part of methods 300 or 400 may be embodied in software or firmware instructions that are stored on a medium, readable by processor 1 10, which when executed by processor ί it), cause processor ! i 0 to execute an embodiment of the present invention. Also, aspects of the present invention may be embodied in data stored on a machine-readable medium, where the data represents a design or other information, usable to fabricate all or pan of processor 1.10,
Thus, embodiments of an invention for platform-hardened DRM key provisioning have been described. While certain embodiments have been described, and shown in the
accompanying drawings, it is to be understood that such embodiments are merely illustrative and not restrictive of the broad invention, and that this invention not be limited to the specific constructions and arrangements shown and described, since various other modifications may occur to those ordinarily skilled in the art upon studying this disclosure. In an area of technology such as this, where growth is fast and further advancements are not easily foreseen, the disclosed embodiments may be readily modifiable in arrangement and detail as facilitated by enabling technological advancements without departing from the principles of the present disclosure or the scope of the accompanying claims.

Claims

What is claimed is:
1 . A processor comprising;
an execution unit to execute one or more instructions to create a secure enclave in which to run an application to receive digital rights management information from a provisioning server in response to authentication of the application by a verification server.
2. The processor of claim Ϊ , wherein the digital rights management information includes a
Digital Transmission Content Protection key.
3. The processor of claim 1 , wherein the authentication involves an Enhanced. Protection ID algorithm.
4. A method comprising:
initiating a client in a secure enclave;
requesting, by the client, digital rights management (DRM) provisioning information from a provisioning server;
requesting, by the client authentication by a verification server;
providing, by the client, proof of authen ication to the provisioning server; and receiving, by the client, the DR provisioning information.
5. The method of claim 4, wherein the digital rights management information includes a Digital
Transmission Content Protection key.
6. The method of claim 4, wherein the authentication i nvolves an Enhanced. Protection ID- algorithm.
7. The method of claim 4, further comprising sealing the DRM. provisioning information to the secure enclave.
8. The method of claim 7, further comprising storing the sealed DRM provisioning information, in a non-volatile memory.
ID
9. The method of claim 4, further comprising generating, by the client, an identity report,
10. The method of claim 9, further comprising signing, by the client using an Enhanced
Protection I'D f EPID) private key, the identity report.
1 1. The method of claim 10, wherein requesting authentication includes sending the signed identity report to the verification server.
12. The method of claim 1 i , further comprising receiving, by the client from the verification server, proof of authentication, wherein the authentication involves verifying the signed identit report. , The method of claim 12, wherein verifying the signed identity report uses an EPID public key corresponding to the EPID private key.
14. The method of claim 4, further comprising receiving, by the client from the provisioning server, a first key component.
15. The method of claim 14, further comprising generating, by the client, a second key
component,
16. The method of claim 15, further comprising sending, by the client to the provisioning serve the second key component,
17. The method of claim 16, further comprising generating, by the client, a shared secret key.
18. The method of claim 17, farther comprising decrypting, by the client, the DRM provistonim information using the shared secret key .
19. A system comprising:
a processor having an execution unit to execute one or more instructions to create a secure enclave in which to run an application to receive digital rights management information from a provisioning server in response to authentication of the application by a verification server; and
a nonvolatile memory in which to store the digital rights management information.
20. The system of claim 1 wherein the digital rights management information includes a
Digital Transmission Content Protection key.
PCT/US2013/048513 2012-12-19 2013-06-28 Platform-hardened digital rights management key provisioning Ceased WO2014099028A1 (en)

Priority Applications (1)

Application Number Priority Date Filing Date Title
CN201380060355.3A CN104813336A (en) 2012-12-19 2013-06-28 Platform-hardened digital rights management key provisioning

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
US13/719,907 2012-12-19
US13/719,907 US9009854B2 (en) 2012-12-19 2012-12-19 Platform-hardened digital rights management key provisioning

Publications (1)

Publication Number Publication Date
WO2014099028A1 true WO2014099028A1 (en) 2014-06-26

Family

ID=50932647

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/US2013/048513 Ceased WO2014099028A1 (en) 2012-12-19 2013-06-28 Platform-hardened digital rights management key provisioning

Country Status (3)

Country Link
US (2) US9009854B2 (en)
CN (1) CN104813336A (en)
WO (1) WO2014099028A1 (en)

Families Citing this family (22)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
FR3030827B1 (en) 2014-12-19 2017-01-27 Stmicroelectronics (Grenoble 2) Sas METHOD AND DEVICE FOR SECURE PROCESSING OF CRYPTED DATA
US10083291B2 (en) 2015-02-25 2018-09-25 Verisign, Inc. Automating internet of things security provisioning
US10248791B2 (en) * 2015-07-20 2019-04-02 Intel Corporation Technologies for secure hardware and software attestation for trusted I/O
US20170093572A1 (en) * 2015-09-25 2017-03-30 Mcafee, Inc. Systems and methods for utilizing hardware assisted protection for media content
US10790978B2 (en) * 2016-05-25 2020-09-29 Intel Corporation Technologies for collective authorization with hierarchical group keys
US10135622B2 (en) * 2016-06-03 2018-11-20 Intel Corporation Flexible provisioning of attestation keys in secure enclaves
US10068068B2 (en) 2016-12-30 2018-09-04 Intel Corporation Trusted timer service
US11438155B2 (en) * 2017-01-24 2022-09-06 Microsoft Technology Licensing, Llc Key vault enclave
US10911451B2 (en) 2017-01-24 2021-02-02 Microsoft Technology Licensing, Llc Cross-platform enclave data sealing
US10530777B2 (en) 2017-01-24 2020-01-07 Microsoft Technology Licensing, Llc Data unsealing with a sealing enclave
US10664591B2 (en) 2017-05-11 2020-05-26 Microsoft Technology Licensing, Llc Enclave pools
US10740455B2 (en) 2017-05-11 2020-08-11 Microsoft Technology Licensing, Llc Encave pool management
US11488121B2 (en) 2017-05-11 2022-11-01 Microsoft Technology Licensing, Llc Cryptlet smart contract
US10637645B2 (en) 2017-05-11 2020-04-28 Microsoft Technology Licensing, Llc Cryptlet identity
US10528722B2 (en) 2017-05-11 2020-01-07 Microsoft Technology Licensing, Llc Enclave pool shared key
US10747905B2 (en) 2017-05-11 2020-08-18 Microsoft Technology Licensing, Llc Enclave ring and pair topologies
US10833858B2 (en) 2017-05-11 2020-11-10 Microsoft Technology Licensing, Llc Secure cryptlet tunnel
US10238288B2 (en) 2017-06-15 2019-03-26 Microsoft Technology Licensing, Llc Direct frequency modulating radio-frequency sensors
FR3079638B1 (en) * 2018-03-29 2021-04-09 Airtag PROCESS FOR IMPLEMENTING A CRYPTOGRAPHIC FUNCTION FOR A SECRET KEY
US11386187B2 (en) * 2019-06-18 2022-07-12 Comcast Cable Communications, Llc Systems and methods for securely processing content
CN111815814B (en) * 2020-06-22 2022-06-10 合肥智辉空间科技有限责任公司 Electronic lock security system and binding authentication method thereof
EP4256439B1 (en) * 2020-12-01 2026-04-22 Lockheed Martin Corporation Digital content management through on-die cryptography and remote attestation

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2006034151A2 (en) * 2004-09-17 2006-03-30 Inventec Appliances Corporation Digital rights management system based on hardware identification
US20070157295A1 (en) * 2005-12-30 2007-07-05 Geetha Mangalore Method and apparatus for provisioning a device to access digital rights management (DRM) services in a universal plug and play (UPnP) network
US20070226492A1 (en) * 1999-03-27 2007-09-27 Microsoft Corporation Secure processor architecture for use with a digital rights management (drm) system on a computing device
KR20090132715A (en) * 2008-06-23 2009-12-31 경북대학교 산학협력단 Delivery system to the designated recipient of the content containing the restrictions provided by the client through the DRM method
US20120163589A1 (en) * 2010-12-22 2012-06-28 Johnson Simon P System and method for implementing a trusted dynamic launch and trusted platform module (tpm) using secure enclaves

Family Cites Families (27)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7073063B2 (en) * 1999-03-27 2006-07-04 Microsoft Corporation Binding a digital license to a portable device or the like in a digital rights management (DRM) system and checking out/checking in the digital license to/from the portable device or the like
US7010808B1 (en) * 2000-08-25 2006-03-07 Microsoft Corporation Binding digital content to a portable storage device or the like in a digital rights management (DRM) system
US20030063750A1 (en) * 2001-09-26 2003-04-03 Alexander Medvinsky Unique on-line provisioning of user terminals allowing user authentication
US7373515B2 (en) * 2001-10-09 2008-05-13 Wireless Key Identification Systems, Inc. Multi-factor authentication system
SE0202451D0 (en) * 2002-08-15 2002-08-15 Ericsson Telefon Ab L M Flexible Sim-Based DRM agent and architecture
US8364951B2 (en) * 2002-12-30 2013-01-29 General Instrument Corporation System for digital rights management using distributed provisioning and authentication
US7194756B2 (en) * 2003-06-20 2007-03-20 N2 Broadband, Inc. Systems and methods for provisioning a host device for enhanced services in a cable system
KR101244308B1 (en) * 2003-12-08 2013-03-18 삼성전자주식회사 Encoding Method for moving picture file and the Digital right management using the same
US20060036554A1 (en) * 2004-08-12 2006-02-16 Microsoft Corporation Content and license delivery to shared devices
US20060047976A1 (en) * 2004-08-25 2006-03-02 General Instrument Corporation Method and apparatus for generating a decrpytion content key
US7865723B2 (en) * 2004-08-25 2011-01-04 General Instrument Corporation Method and apparatus for multicast delivery of program information
JP4856081B2 (en) * 2004-10-08 2012-01-18 コーニンクレッカ フィリップス エレクトロニクス エヌ ヴィ User-based content key encryption for DRM systems
US7430664B2 (en) * 2005-02-02 2008-09-30 Innomedia Pte, Ltd System and method for securely providing a configuration file over and open network
EP1880506A1 (en) * 2005-05-09 2008-01-23 Nokia Corporation System and method for efficient encryption and decryption of drm rights objects
CN100592785C (en) * 2005-05-30 2010-02-24 Ut斯达康通讯有限公司 Digital rights management system and network TV operation system
US8194859B2 (en) * 2005-09-01 2012-06-05 Qualcomm Incorporated Efficient key hierarchy for delivery of multimedia content
CN1851608A (en) * 2005-09-28 2006-10-25 华为技术有限公司 Method and system for cancelling RO for DRM system
CN100454921C (en) * 2006-03-29 2009-01-21 华为技术有限公司 A digital copyright protection method and system
EP1855438A1 (en) * 2006-05-09 2007-11-14 THOMSON Licensing Device, system and method for service delivery with anti-emulation mechanism
US7712143B2 (en) * 2006-09-27 2010-05-04 Blue Ridge Networks, Inc. Trusted enclave for a computer system
US8438618B2 (en) * 2007-12-21 2013-05-07 Intel Corporation Provisioning active management technology (AMT) in computer systems
US8413256B2 (en) * 2008-08-26 2013-04-02 Cox Communications, Inc. Content protection and digital rights management (DRM)
US8812959B2 (en) * 2009-06-30 2014-08-19 International Business Machines Corporation Method and system for delivering digital content
US8739177B2 (en) * 2010-06-21 2014-05-27 Intel Corporation Method for network interface sharing among multiple virtual machines
US8644515B2 (en) * 2010-08-11 2014-02-04 Texas Instruments Incorporated Display authenticated security association
US9578041B2 (en) * 2010-10-25 2017-02-21 Nokia Technologies Oy Verification of peer-to-peer multimedia content
US20140007087A1 (en) * 2012-06-29 2014-01-02 Mark Scott-Nash Virtual trusted platform module

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20070226492A1 (en) * 1999-03-27 2007-09-27 Microsoft Corporation Secure processor architecture for use with a digital rights management (drm) system on a computing device
WO2006034151A2 (en) * 2004-09-17 2006-03-30 Inventec Appliances Corporation Digital rights management system based on hardware identification
US20070157295A1 (en) * 2005-12-30 2007-07-05 Geetha Mangalore Method and apparatus for provisioning a device to access digital rights management (DRM) services in a universal plug and play (UPnP) network
KR20090132715A (en) * 2008-06-23 2009-12-31 경북대학교 산학협력단 Delivery system to the designated recipient of the content containing the restrictions provided by the client through the DRM method
US20120163589A1 (en) * 2010-12-22 2012-06-28 Johnson Simon P System and method for implementing a trusted dynamic launch and trusted platform module (tpm) using secure enclaves

Also Published As

Publication number Publication date
US9009854B2 (en) 2015-04-14
US20150178481A1 (en) 2015-06-25
CN104813336A (en) 2015-07-29
US20140173756A1 (en) 2014-06-19
US9436812B2 (en) 2016-09-06

Similar Documents

Publication Publication Date Title
US9009854B2 (en) Platform-hardened digital rights management key provisioning
CN105745661B (en) Policy-based trusted detection of rights-managed content
AU2017396530B2 (en) Addressing a trusted execution environment using encryption key
US10972265B2 (en) Addressing a trusted execution environment
CN101490689B (en) Content control system and method using certificate chains
AU2017396531B2 (en) Addressing a trusted execution environment using signing key
CN116886356B (en) Chip-level transparent file encryption storage system, method and equipment
US8266707B2 (en) Tamper resistant method, apparatus and system for secure portability of digital rights management-protected content
TW201502847A (en) Systems, methods and apparatuses for using a secure non-volatile storage with a computer processor
US12210658B2 (en) Executing entity-specific cryptographic code in a cryptographic
US10897360B2 (en) Addressing a trusted execution environment using clean room provisioning
CN101019368B (en) Method of delivering direct proof private keys to devices using a distribution CD
Noubir et al. Trusted code execution on untrusted platforms using Intel SGX
US20210111901A1 (en) Executing entity-specific cryptographic code in a trusted execution environment
US8245307B1 (en) Providing secure access to a secret
CN107911221A (en) The key management method of solid-state disk data safety storage
JP7385025B2 (en) Execution of Entity-Specific Cryptographic Code in a Cryptographic Coprocessor
Mohanty et al. Media data protection during execution on mobile platforms–A review
Shimizu et al. Cell Broadband Engine™ processor security architecture and digital content protection
Ding et al. DRMIBT: A New DRM Implementation Based on Virtual Machine
HK40008560A (en) Addressing a trusted execution environment using encryption key
NZ754540B2 (en) Addressing a trusted execution environment using signing key
BR112019013584B1 (en) SYSTEM, METHOD FOR PROVIDING PROTECTED DATA TO A NESTED TRUSTED EXECUTION ENVIRONMENT AND COMPUTER-READABLE STORAGE MEDIUM
BR112019013398B1 (en) COMPUTING SYSTEM, METHOD FOR PROVIDING PROTECTED DATA TO AN EMBEDDED TRUSTED EXECUTION ENVIRONMENT, AND COMPUTER-READABLE STORAGE MEDIUM
HK40011857A (en) Addressing a trusted execution environment using signing key

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 13865199

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 13865199

Country of ref document: EP

Kind code of ref document: A1