|

Protection for Premium Content for Mobile, TV, and STB

November 11, 2015, ARM TechCon, Santa Clara, CA—Henk Pruim from Inside Secure described the issues and challenges of the premium content industry. The various delivery options are in a flux as viewers move from tethered connections to IP delivery technologies.

IP and Internet video are growing at a very high rate. Various pundits are forecasting ongoing high growth rates for video as a total entity and as a percentage of all Web traffic. The advent of UHD TV sets will exacerbate the problems of bandwidth congestion. One important issue in this dynamic environment is security for the content .

Currently, most over the top (OTT) content uses software digital rights management tools for protection. These tools protect the licenses, session keys, and the crypto computations. Future protection will have to address many more issues including higher resolutions, multiple playback modes, and a need to cover more content with increasing value.

The studios are working on new specifications for UHD content and the DRM providers like Microsoft, Google, Vidity, etc. are updating their specs to follow. The growing modes and platforms call for full, consistent protection from end-end with system-level certification and good DRM that are efficient and transparent to the user.

The advent of UHD content will require changes in the way that protection schemes are implemented. See figure.


The important characteristics for different levels of video require different approaches

The DRM flow for SD content has a license server deliver license and keys to the player which then gets the encrypted content from a content server. The player applies the key and license to the content and decrypts the content for display processing.

 

The SD flow uses a software-based implementation and provides flexibility and cross-platform compatibility. The software can also accept over-the-air enhancements and upgrades and a software base allows for relatively easy and fast delivery of new features. Implementations are studio approved with possible third party certifications.

HD content requires a hybrid approach with both hardware and software. This mix of rich unsecured OS functions is coupled with trusted applications for crypto and other security functions. the whole environment uses something like the ARM TrustZone technologies to protect against attacks. The keys are stored and protected in the trust zone, and all crypt happens in the trusted zone. In addition, the systems have protected video paths to protect the plain content after decryption and before display. Standards, trusted app managers, and trusted app stores allow similar flexibility as a full software solution. Certifications is required for the platform.

For the future of 4k and UHD content, even more security comes into play. More of the system needs protection from software and hardware attacks, including the secure video path. Other technologies like watermarking and data bus scrambling or encryption are necessary to shield the video paths from hackers. Full certification for the platform and the underlying software is necessary.

A possible architecture for end-to-end protection must meet all the requirements to protect the content as well as the internal systems.  A variation is to put all of the crypto and security functions into hardware to make it harder to breach the system. The final system needs many paths for licenses, keys, encrypted and clear content that must all work together to get the content to the display. Even though the system needs full certification, a lower risk approach to the certifications might be in layers at the module, SoC and device levels.
 

Similar Posts