Apparatus and method for content protection using one-way buffers
Abstract
Method and apparatus for content protection using one-way buffers. In one embodiment, the method includes storage of content decrypted by a host processor within a reserved range of memory. In one embodiment, a peripheral device requires the host processor to decrypt the received content for playback by the peripheral device. The decrypted content is stored within a reserved range of memory that is not accessible by malicious software. Hence, content is transferred from the reserved range of memory to a device driver of the peripheral device. In one embodiment, access to the reserved range of memory consists of write-only access by the host processor and read-only access by the peripheral device. In one embodiment, prior to storage of the content within the reserved range of memory, the content is re-encrypted prior to storage and decryption prior to transfer to the peripheral device. Other embodiments are described and claimed.
Claims
exact text as granted — not AI-modified1 . An apparatus, comprising:
a controller to redirect a host agent transfer of decrypted content from an assigned portion of a memory address space to a buffer within a reserved range of memory if the assigned portion of the memory address space is mapped to the reserved range of memory and to transfer content from the buffer to a request agent.
2 . The apparatus of claim 1 , wherein the controller is to encrypt the decrypted content prior to storage within the reserved range of memory.
3 . The apparatus of claim 1 , wherein the controller is to detect a direct memory access request issued by the request agent and to decrypt encrypted content read from the reserved range of memory prior to transfer of the content to the request agent if the request agent is assigned read-only access to the reserved range of memory.
4 . The apparatus of claim 1 , wherein the controller is to detect a memory allocation request issued by the request agent, to map memory allocated to the request agent to the reserved range of memory, to grant read-only access of the reserved range of memory to the request agent and to grant write-only access to the reserved range of memory to the host agent.
5 . The apparatus of claim 2 , wherein the controller is to generate a session key to encrypt the decrypted content received from the host agent.
6 . The apparatus of claim 1 , wherein the apparatus is a chipset, the host agent is a host processor, the request agent is a peripheral device and the controller is a memory controller.Join the waitlist — get patent alerts
Track US2011213990A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.