A procedure is described for establishing trust between a computerized device (also called a “client device”) and a server system for digital rights management (DRM) (also referred to as a DRM server or “backend”). The technique is applicable to devices such as mobile smartphones or tablets (more generally mobile devices) as well as fixed devices such as set top boxes. In one embodiment the device may utilize a specialized processing chipset, referred to as “system-on-chip” or SoC, that incorporates several hardware components such as processor(s), WiFi and network interface controller, content decryption and decoding, etc.
The techniques herein utilize a processing arrangement including a secure execution environment such as the arrangement known by the name TrustZone. Such an arrangement generally requires some level of specific hardware support in any physical implementation. The arrangement includes two execution environments, one being the secure environment and the other referred to as the non-secure or “normal” environment. With the exception of a secure communication channel, the normal environment does not have access to resources of the secure environment, but the secure environment has full access to all resources including secure as well as non-secure resources.
The DRM client utilizes the backend to help bootstrap a chain of trust to the backend, so that DRM licenses can be served to enable protected content to be played. Key aspects of establishing the root of trust of the device and the application to the backend are described.
The foregoing and other objects, features and advantages will be apparent from the following description of particular embodiments of the invention, as illustrated in the accompanying drawings in which like reference characters refer to the same parts throughout the different views. The drawings are not necessarily to scale, emphasis instead being placed upon illustrating the principles of various embodiments of the invention.
The components in the secure environment 30 are responsible for establishing a root of trust with the backend 10 (
The non-secure DRM client 42 is mainly an interface (via the API component 40) between the content player 38 and the secure DRM client 50. In particular, the non-secure DRM client 42 only sends requests to the latter to register the device 12, obtain a rights object for a particular media object, and enable decryption and playing of the media object. The DRM Agent 48 is an API layer to access the backend servers 10.
In one embodiment, the secure environment 30 may employ components of the so-called TrustZone family, including the secure processor 20-S realized according to the ARM architecture, as well as the secure kernel 44 and secure file system 46 which are specially tailored for security-related uses. Establishing a root of trust is based on security features offered by the hardware (SOC chipset) that is embedded in a circuit board used to build a device (e.g., mobile phone handset). While the chipset manufacturer provides the hardware, the device manufacturer (OEM) loads firmware (code) such as the DRM client and DRM agent 48.
The initial step is device authentication 60 in which it is established that the device 12 is an authentic device running an unmodified version of the device O/S 36, the DRM Client (portions 42 and 44) as well as DRM agent 50. The approach used is to begin with a secure boot process involving two levels of boot using a signature scheme such as RSA-PSS (Probabilistic Signature Scheme) to verify the authenticity of the signatures of boot loaders and the DRM client. The DRM client is distributed as firmware and resides in flash memory of the device 12, not ROM. It is included in the second level boot, and thus it is necessary to authenticate the DRM client code by a process as described below. The device manufacturer uses a private key PrK to generate a signature of the firmware in the factory. This signature is verified at each boot. The DRM client is verified as part of the firmware. The device 12 also contains the manufacturer's public key PuK to verify that the binary has not been modified. This verification code is stored in SoC ROM. The PuK must not be modifiable even if it is not confidential.
Next, this root of trust is extended to include the backend 10. This involves securely sending a secret back to the backend 10. At this point, the backend 16 has verified the authenticity of the device 12 and indirectly the authenticity of the client software. An application client that authenticates to its application backend server can subsequently use the DRM agent 48 to request a media play. The DRM agent 48 uses client-certificates for mutual authentication when talking to the backend 10 for verifying trust and obtaining rights object containing licenses pertaining to the specific device and the media selected. A content key is securely conveyed to the hardware player and the media is decrypted and rendered on the screen of the device 12. This workflow is shown in
Establishing a root of trust begins with a secure boot procedure. This is implemented using the secure execution environment 30 (e.g., ARM TrustZone) in addition to some hardware mechanisms that may be manufacturer-specific.
For the secure boot process, in one embodiment a manufacturer-specific private key PvK is used to generate a signature of the firmware at its creation point. The DRM client may be deployed in this manner. The chain of trust begins with one component—SoC ROM. Ideally, the corresponding public key PuK is burnt into the ROM and used to authenticate the first bootloader. However, putting the PuK on the SoC ROM means it is the same for the class of devices. To prevent class-hacks, OTP (One Time Programmable) poly-silicon fuses may be used to store unique values in each SoC during device manufacture. For example, a 256-bit hash of a 2,048-bit PuK can be stored. Thus, the PuK is individualized to some collection of devices 12 and its verification is via the hash burned into the OTP fuses. The PuK itself can be loaded from flash memory. The flash would contain all PuKs that may be usable, and the specific one in use is identified by the hash.
For the code authentication, the following steps are taken at boot time (all operations in the secure environment 30):
Note that all communication between the secure and non-secure environments 30, 32 are via a secure API, which in the case of TrustZone is referred to as TZ-API. This communication is necessary to allow the content player 38 to communicate with the DRM agent 48.
Thus far, it has been verified that the boot loaders and the DRM client code are genuine. It is still necessary to perform device-level verification to establish for the backend 10 that the device 12 is a genuine device running a genuine O/S 36. Device authentication includes communicating certain sensitive information to the backend 10 in a secure manner. This step applies to each backend. Thus, it is required to register the device 12 for each different app 38. The device 12 is validated through a secret value by a device validation service 10-DV. The registration process is initiated by the app 38 calling a “register” API with 2 arguments: a URL pointing to the app's service backend 10-AB, and an opaque user authentication token that the app has obtained from the app's subscriber management server 10-SN (typically after a user authentication step done in the app). This triggers the authentication steps described below.
All further client communication to the app's service backend 10-AB are via the mutually-authenticated SSL using the client certificate. The service backend 10-AB can verify the signature using the DRM system public key DPuK.
Rights objects are sent over an SSL connection and stored encrypted in the secure file system 48 (e.g., using AES encryption or public-key encryption, in which case the client's public key is stored with the encrypted rights objects). Media keys are stored in the secure file system 48 and provided to the media player in the secure environment 30. Media playback is via a hardware-based decrypt and decode mechanism.
The DT stored in the secure file system 48 may need to be renewed in the event of a security incident. This is achieved by using a revocation procedure where the old DT is renewed with a new one sent down to the device 12 after establishment of trust. In step 2 of the Device Authentication, the old DT is no longer accepted by the backend 10-DV and an error is returned with a condition that rejects the old DT. In this event, the secure DRM client 50 retries with the backup DT. After the successful acceptance of the backup DT, trust is established and a new DT is transmitted encrypted with the backup DT using AES-128. This new DT is then installed as the primary DT.
After the DT is renewed, all old client certificates issued based on this must be renewed. This is achieved by forcing a new device registration. The process may be controlled so that not all clients are forced to renew at the same time.
While various embodiments of the invention have been particularly shown and described, it will be understood by those skilled in the art that various changes in form and details may be made therein without departing from the spirit and scope of the invention as defined by the appended claims.
Number | Name | Date | Kind |
---|---|---|---|
20080082828 | Jennings et al. | Apr 2008 | A1 |
20120096560 | Selander et al. | Apr 2012 | A1 |
20120303951 | Medvinsky et al. | Nov 2012 | A1 |
Entry |
---|
ARM TrustZone Security Whitepaper. ARM. Apr. 16, 2010. |
Messerges, T. S., & Dabbish, E. A. (Oct. 2003). Digital rights management in a 3G mobile phone and beyond. In Proceedings of the 3rd ACM workshop on Digital rights management (pp. 27-38). ACM. |
Stumpf, Frederic. “Trusted and Secure Mobile Platforms.” (Jun. 24, 2010). |
Anand, V., Saniie, J., & Oruklu, E. (Nov. 2011). Trusted computing architectures for a mobile IT infrastructure. In Proceedings of the 39th ACM annual conference on SIGUCCS (pp. 73-78). ACM. |
Wikipedia, ARM architecture, as revised by 99.90.241.80 (talk) at 10:54, Dec. 3, 2011, downloaded on Nov. 18, 2013. |
Number | Date | Country | |
---|---|---|---|
20130152180 A1 | Jun 2013 | US |
Number | Date | Country | |
---|---|---|---|
61568032 | Dec 2011 | US |