TH66596A - Systems and methods for securing video card output - Google Patents

Systems and methods for securing video card output

Info

Publication number
TH66596A
TH66596A TH301001924A TH0301001924A TH66596A TH 66596 A TH66596 A TH 66596A TH 301001924 A TH301001924 A TH 301001924A TH 0301001924 A TH0301001924 A TH 0301001924A TH 66596 A TH66596 A TH 66596A
Authority
TH
Thailand
Prior art keywords
data
video card
secure
key
video
Prior art date
Application number
TH301001924A
Other languages
Thai (th)
Inventor
เอฟ อีแวนส์ กลีนน์
อิงค์แลนด์ พอล
Original Assignee
นายธีรพล สุวรรณประทีป
นายมนูญ ช่างชำนิ
ไมโครซอฟต์ คอร์ปอเรชั่น
Filing date
Publication date
Application filed by นายธีรพล สุวรรณประทีป, นายมนูญ ช่างชำนิ, ไมโครซอฟต์ คอร์ปอเรชั่น filed Critical นายธีรพล สุวรรณประทีป
Publication of TH66596A publication Critical patent/TH66596A/en

Links

Abstract

DC60 (18/08/46) หลากหลายวิธีการและระบบที่อธิบายในที่นี้ มีจุดมุ่งหมายสำหรับการจัดเตรียมช่อง ทางที่ปลอดภัยของการใช้งาน ของซอฟท์แวร์บนคอมพิวเตอร์แม่ข่าย วิธีการและระบบได้ระบุ และจัดเตรียมวิธีการแก้ปัญหาสำหรับแบบจำลองการจู่โจมซึ่ง ซอฟท์แวร์ที่มีกลโกงที่ปฏิบัติงาน บนคอมพิวเตอร์แม่ข่าย พยายามที่จะได้ไปซึ่งข้อมูลหรือทำการปรับเปลี่ยนข้อมูล อย่างมิควร การประดิษฐ์บางอย่างสามารถจัดเตรียมข้อมูลพิกเซล ที่สามารถเก็บเป็นความลับ (หมายความ ว่าโปรแกรมประยุกต์ที่ ไว้วางใจไม่ได้ จะไม่สามารถอ่านข้อมูลที่ปรากฏอยู่บนจอภาพ ได้) นอก จากนี้ การประดิษฐ์อื่น ๆก็สามารถรักษาไว้ซึ่งความ มั่นคงของข้อมูลภาพ ด้วยการตรวจจับว่า ข้อมูลพิกเซลได้ถูก ปรับ เปลี่ยนอย่างไม่เหมาะสมหรือไม่ การประดิษฐ์หลายๆแบบนั้น มี อยู่บน พื้นฐานของกลไกในการถอดรหัสบนวีดีโอการ์ด ที่มักจะ อยู่ตอนท้าย ๆของกลุ่มการประมวลผล วีดีโอเพื่อที่การเข้าถึง ข้อมูลพิกเซลที่ถอดรหัสแล้วด้วยโปรแกรมจะถูกปฏิเสธ หลากหลายวิธีการและระบบที่อธิบายในที่นี้ มีจุดมุ่งหมายสำหรับการจัดเตรียมช่อง ทางที่ปลอดภัยของการใช้งาน ของชอฟท์แวร์บนคอมพิวเตอร์แม่ข่าย วิธีการและระบบได้ระบุ และจัดเตรียมวิธีการแก้ปัญหาสำหรับแบบจำลองการจู่โจมซึ่ง ซอฟท์แวร์ที่มีกลโกงที่ปฏิบัติงาน บนคอมพิวเตอร์แม่ข่าย พยายามที่จะได้ไปซึ่งข้อมูลหรือทำการปรับเปลี่ยนข้อมูล อย่างมิควร การประดิษฐ์บางอย่างสามารถจัดเตรียมข้อมูลพิกเซล ที่สามารถเก็บเป็นความลับ (หมายความ ว่าโปรแกรมประยุกต์ที่ ไว้วางใจไม่ได้ จะไม่สามารถอ่านข้อมูลที่ปรากฏอยู่บนจอภาพ ได้) นอก จากนี้ การประดิษฐ์อื่นๆ ก็สามารถรักษาไว้ซึ่งความ มั่นคงของข้อมูลภาพ ด้วยการตรวจจับว่า ข้อมูลพิกเซลได้ถูก ปรับ เปลี่ยนอย่างไม่เหมาะสมหรือไม่ การประดิษฐ์หลายๆแบบนั้น มี อยู่บน พื้นฐานของกลไกในการถอดรหัสบนวีดีโอการ์ด ที่มักจะ อยู่ตอนท้ายๆของกลุ่มการประมวลผล วีดีโอเพื่อที่การเข้าถึง ข้อมูลพิกเซลที่ถอดรหัสแล้วด้วยโปรแกรมจะถูกปฏิเสธDC60 (18/08/46) The various methods and systems described herein aim to provide a secure pathway for the execution of software on a server. These methods and systems identify and provide solutions to attack models in which malicious software running on the server attempts to obtain or modify data improperly. Some inventions can provide pixel data that can be kept confidential (meaning that untrusted applications cannot read the information displayed on the screen). Other inventions maintain the integrity of image data by detecting whether the pixel data has been improperly modified. Many of these inventions are based on decoding mechanisms on the video card, often located at the end of the video processing group, so that programmatic access to the decoded pixel data is denied. The various methods and systems described herein aim to provide a secure pathway for the execution of software on a server. These methods and systems identify and provide solutions to attack models in which malicious software running on the server attempts to obtain or modify data improperly. Some inventions can provide pixel data... This allows for the data to be kept confidential (meaning that untrusted applications cannot read the information displayed on the screen). Furthermore, other inventions can maintain the integrity of image data by detecting whether pixel data has been improperly altered. Many of these inventions are based on decoding mechanisms on the video card, often located at the end of the video processing unit, so that programmatic access to the decoded pixel data is denied.

Claims (59)

1. วิธีการซึ่งประกอบไปด้วย การจัดเตรียมข้อมูลวีดีโอที่เข้ารหัส บนวีดีโอการ์ด และ การถอดรหัสข้อมูลวีดีโอที่ถูกเข้ารหัสมาที่ตำแหน่งในการ ประมวลผลข้อมูลซึ่งไม่มี โปรแกรมใด ๆเข้าถึงข้อมูลวีดีโอที่ ถอดรหัสแล้วได้1. A method consisting of preparing encoded video data on the video card and decoding the encoded video data to a processing location that is inaccessible to any program. 2. วิธีการของข้อถือสิทธิข้อ 1 ซึ่งการกระทำการถอดรหัส จะ ถูกกระทำก่อนการส่งข้อ มูลวีดีโอที่ถูกถอดรหัสแล้ว ไปยังตัว แปลงผันการแสดงผลที่อยู่บนวีดีโอการ์ด2. According to the method of claim 1, the decoding operation is performed before the decoded video data is sent to the display converter on the video card. 3. วิธีการของข้อถือสิทธิข้อ 1 ซึ่งการกระทำการถอดรหัส จะ ถูกกระทำก่อนการส่งข้อ มูลวีดีโอที่ถูกถอดรหัสแล้ว ไปยัง RAMDAC บนวีดีโอการ์ด3. According to the method of claim 1, the decryption operation is performed before the decoded video data is sent to the RAMDAC on the video card. 4. วิธีการของข้อถือสิทธิข้อ 1 ซึ่งการกระทำการถอดรหัสจะ ถูกกระทำโดยตัวถอดรหัส ฮาร์ดแวร์ที่อยู่บนวีดีโอการ์ด4. The method of claim 1 in which decryption is performed by a hardware decoder located on the video card. 5. วิธีการของข้อถือสิทธิข้อ 1 ซึ่งการกระทำการถอดรหัส จะ ถูกกระทำโดยตัวถอดรหัส ที่อยู่ระหว่าง GPU ของวีดีโอการ์ด และ RAMDAC บนวีดีโอการ์ด5. The method of claim 1 in which decoding is performed by a decoder located between the video card's GPU and the video card's RAMDAC. 6. หนึ่งหรือหลาย ๆ ชุดคำสั่งบนนั้นที่คอมพิวเตอร์สามารถ อ่านได้นั้น เมื่อมีการปฏิบัติ การโดยคอมพิวเตอร์จำนวน หนึ่งตัวหรือหลาย ๆ ตัว จะเป็นสาเหตุให้คอมพิวเตอร์จำนวน หนึ่ง ตัวหรือหลาย ๆ ตัวนั้น มีการใช้วิธีการตามข้อถือสิทธิ ข้อ 16. One or more instructions therein that are readable by computers, when executed by one or more computers, cause one or more computers to use the methods under Claim 1. 7. ระบบซึ่งประกอบไปด้วย วิถีทางสำหรับการตระเตรียมการถอดรหัสข้อมูลวีดีโอ บนวีดี โอการ์ด วิถีทางสำหรับการถอดรหัสข้อมูลวีดีโอที่ถูกเข้ารหัส บนวี ดีโอการ์ด และ วิถีทางสำหรับการปฏิเสธการเข้าถึงข้อมูลวีดีโอที่ถอดรหัส แล้ว ของซอฟท์แวร์7. A system comprising pathways for preparing video data decoding on the video card, pathways for decoding encrypted video data on the video card, and pathways for denying access to the decrypted video data by the software. 8. ระบบของข้อถือสิทธิข้อ 7 ซึ่งวิถีทางสำหรับการตระ เตรียมการเข้ารหัสข้อมูลวีดีโอ ดังกล่าวนั้น ประกอบด้วยการ เข้ารหัสแบบกระแส (stream cipher)8. The system of claims in Article 7, which outlines the method for preparing the encryption of such video data, consists of stream cipher. 9. ระบบของข้อถือสิทธิข้อ 7 ซึ่งวิถีทางสำหรับการตระ เตรียมการเข้ารหัสข้อมูลวีดีโอ ดังกล่าวนั้น ประกอบด้วยการ เข้ารหัสแบบล็อก (block cipher)9. The system of claim number 7, which outlines the method for preparing the encryption of such video data, consists of a block cipher. 10. ระบบของข้อถือสิทธิข้อ 7 ซึ่งวิถีทางสำหรับการถอดรหัส ดังกล่าวนั้น ประกอบด้วย ตัวถอดรหัสแบบฮาร์ดแวร์บนวีดีโอ การ์ด10. The system of claims in clause 7, the method for such decoding, consists of a hardware decoder on the video card. 11. ระบบซึ่งประกอบด้วย หน่วยประมวลผลกราฟิกสำหรับประมวลผลข้อมูลวีดีโอที่จะนำไป แสดงภาพบนจอ แสดงผลภาพ หน่วยความจำที่มีการจัดการร่วมกันได้ กับหน่วยประมวลผลกรา ฟิก สำหรับการเก็บ รักษาข้อมูลที่จะถูกประมวลผลหรือที่ได้ รับการประมวลผลแล้วโดยหน่วยประมวลผลกราฟิก ตัวแปลงผันการแสดงผล สำหรับการแปลงข้อมูลดิจิตอลให้เป็น สัญญาณที่จะใช้สำหรับ การแสดงข้อมูลบนจอแสดงผลภาพ และ ตัวถอดรหัสที่ถูกจัดโครงสร้างให้ถอดรหัสข้อมูลพิกเซลเพื่อ การเตรียมข้อมุลให้ตัว แปลงผันการแสดงผล โดยตัวถอดรหัสนี้จะ ถูกใช้สานที่ตำแหน่งของการประมวลผลข้อมูลที่ซึ่ง การเข้าถึง ข้อมูลโดยโปรแกรมไม่อาจทำได้11. The system comprises a graphics processing unit (GPU) for processing video data to be displayed on a screen; shared memory managed by the GPU for storing data to be processed or already processed by the GPU; a display converter (DC) for converting digital data into signals for display on the screen; and a decoder structured to decode pixel data in preparation for the DC converter. This decoder is used at the data processing location where program access to the data is not possible. 12. ระบบของข้อถือสิทธิข้อ 11 ซึ่งหน่วยความจำประกอบด้วย พื้นผิวปฐมภูมิที่บรรจุ ข้อมูลสำหรับใช้ในการแสดงภาพบนจอ แสดงผลภาพ พื้นผิวปฐมภูมินี้ประกอบด้วย บริเวณที่ ปลอดภัย หนึ่งที่หรือหลายๆที่ ซึ่งสามารถนำข้อมุลที่เข้ารหัสแล้ว ไปวางไว้ได้12. The system of claim 11, in which memory consists of a primary surface containing data for use in displaying an image on a display screen, contains one or more secure regions where encrypted data can be placed. 13. ระบบของข้อถือสิทธิข้อ 11 ซึ่งยังประกอบไปด้วยตัว ประมวลผลควบคุม บนข้อ กำหนดของวีดีโอการ์ด ที่จะบอกถึงความ สามารถของการถอดรหัสให้กับตัวถอดรหัส13. The system of claim number 11, which also includes the control processor on the video card specifications, will indicate the decoding capability to the decoder. 14. ระบบของข้อถือสิทธิข้อ 13 ซึ่งตัวประมวลผลควบคุมมีตัว จัดการคีย์ สำหรับการ บริหารจัดการคีย์หนึ่งตัวหรือหลายๆตัว ที่สามารถนำไปป้อนให้กับตัวถอดรหัส สำหรับการ ถอดรหัสข้อ มูลพิกเซลที่ถูกเข้ารหัสมาแล้ว14. The system of claim 13, in which the control processor has a key manager for managing one or more keys that can be fed to the decoder for decrypting encrypted pixel data. 15. ระบบของข้อถือสิทธิข้อ 13 ซึ่งยังประกอบไปด้วยช่องทาง การสื่อสารที่ปลอดภัย ในการเชื่อมต่อส่วนประมวลผลควบคุมและ ส่วนถอดรหัส15. The system of claims under Article 13, which also includes a secure communication channel for connecting the control and decoding processing units. 16. ระบบของข้อถือสิทธิข้อ 13 ซึ่งตัวประมวลผลควบคุม ประกอบด้วย ชิปวงจรรวมที่ แยกต่างหากบนวีดีโอการ์ด16. The system of claim number 13, in which the control processor consists of a separate integrated circuit chip on the video card. 17. ระบบของข้อถือสิทธิข้อ 11 ซึ่งตัวถอดรหัสประกอบด้วย ส่วนประกอบที่แยกต่าง หาก บนวีดีโอการ์ด17. The system of claim number 11, in which the decoder consists of separate components on the video card. 18. ระบบซึ่งประกอบไปด้วย วิถีทางของหน่วยประมวลผลบนวีดีโอการ์ด สำหรับการประมวลผล ข้อมูลวีดีโอที่จะนำ ออกมาแสดงบนจอแสดงผลภาพ วิถีทางของหน่วยความจำบนวีดีโอการ์ด เป็นหน่วยความจำที่มี การจัดการร่วมกันได้ กับวิถีทางของหน่วยประมวลผล สำหรับการ เก็บรักษาข้อมูลที่จะนำมาประมวลผลหรือข้อมูลที่ ประมวลผล แล้ว โดยวิถีทางของหน่วยประมวลผล วิถีทางของตัวแปลงผันบนวีดีโอการ์ด สำหรับการแปลงข้อมูลดิ จิตอลให้เป็นสัญญาณที่ จะใช้สำหรับการแสดงข้อมูลบนจอแสดงผล ภาพ วิถีทางของตัวถอดรหัสบนวีดีโอการ์ด เพื่อการถอดรหัสข้อ มูลพิกเซลเพื่อป้อนให้กับวิถี ทางของตัวแปลงผัน และ วิถีทางบนวีดีโอการ์ด สำหรับการปฏิเสธโปรแกรมประยุกต์ หนึ่งหรือหลายๆโปรแกรม ที่จะเข้าถึงข้อมูลพิกเซลที่ถอดรหัส แล้ว18. The system comprises: video card processor paths for processing video data to be displayed on the screen; video card memory paths, which are shared memory with the processor paths for storing data to be processed or data already processed by the processor paths; video card converter paths for converting digital data into signals for display; video card decoder paths for decoding pixel data to feed to the converter paths; and video card paths for rejecting one or more applications from accessing the decoded pixel data. 19. ระบบซึ่งประกอบไปด้วย วีดีโอการ์ด หน่วยความจำบนวีดีโอการ์ด โดยที่ส่วนหนึ่งจะประกอบด้วย พื้นผิวปฐมภูมิที่บรรจุข้อ มูลที่จะนำไปแสดงผลบนจอแสดงผลภาพ หนึ่งหรือหลายๆบริเวณที่ปลอดภัยบนพื้นผิวปฐมภูมิ ใช้ในการ เก็บข้อมูลพิกเซลที่เข้า รหัสแล้ว และ อย่างน้อยมีคีย์หนึ่งตัวที่เกี่ยวเนื่องกับบริเวณหนึ่ง หรือหลายๆบริเวณ และถูกตั้งให้ สามารถทำให้ข้อมูลที่ผ่านการ เข้ารหัสแล้วถูกถอดรหัสได้19. A system consisting of a video card and video card memory, which includes a primary surface containing data to be displayed on the screen; one or more secure areas on the primary surface are used to store encrypted pixel data; and at least one key is associated with one or more areas and is configured to enable the decryption of the encrypted data. 20. ระบบของข้อถือสิทธิข้อ 19 ซึ่งบริเวณที่ปลอดภัยแต่ละ บริเวณ ตรงกันกับวินโดว์ที่ ปลอดภัย ซึ่งสามารถแสดงให้เห็น บนจอแสดงผลภาพ20. The system of claims under clause 19, in which each secure area corresponds to a secure window that can be displayed on the screen. 21. ระบบของข้อถือสิทธิข้อ 19 ซึ่งบริเวณที่ปลอดภัยแต่ละ บริเวณ มีคีย์ที่สอดคล้อง กับมันโดยเฉพาะ21. The system of claims under Article 19, in which each secure area has a key that corresponds specifically to it. 22. ระบบของข้อถือสิทธิข้อ 21 ซึ่งมีบริเวณที่ปลอดภัย หลายๆบริเวณ โดยแต่ละ บริเวณจะมีคีย์ที่ต่างกัน22. The system of claim 21 consists of multiple secure areas, each with a different key. 23. ระบบของข้อถือสิทธิข้อ 19 ซึ่งยังประกอบไปด้วย ตัวถอด รหัสบนวีดีโอการ์ด ซึ่ง ถูกจัดโครงสร้างให้ถอดรหัสข้อมูลพิก เซลที่เข้ารหัส โดยการใช้คีย์ที่สัมพันธ์กัน23. The system of claim 19, which also includes a decoder on the video card, is structured to decode encrypted pixel data using its associated key. 24. ระบบของข้อถือสิทธิข้อ 23 ซึ่งตัวถอดรหัสทำการถอดรหัส ข้อมูลพิกเซลที่เข้ารหัส มา ที่ตำแหน่งการประมวลซึ่งไม่มีการ เข้าถึงข้อมูลพิกเซลที่ถอดรหัสแล้ว โดยโปรแกรม24. The system of claim 23, whereby the decoder decodes the encoded pixel data to a processing location where the decoded pixel data is not accessed by the program. 25. ระบบของข้อถือสิทธิข้อ 23 ซึ่งตัวถอดรหัสประกอบด้วย ตัวถอดรหัสแบบฮาร์ดแวร์25. The system of claims under Article 23, in which the decoder consists of a hardware decoder. 26. ระบบของข้อถือสิทธิข้อ 19 ที่ซึ่งวีดีโอการ์ดมีสามารถ พิสูจน์ตัวจริงได้26. The system of claims under Article 19, in which the video card has the ability to verify its authenticity. 27. ระบบของข้อถือสิทธิข้อ 26 ซึ่งวีดีโอการ์ดประกอบด้วย ใบรับรองดิจิตอล ที่ใช้ สำหรับการพิสูจน์ตัวจริง27. The system of claims in Article 26, in which the video card contains a digital certificate used for authentication. 28. ระบบของข้อถือสิทธิข้อ 26 ซึ่งวีดีโอการ์ดถูกปรับโครง สร้างให้ตอบสนองต่อการ ท้าทายในการพิสูจน์ตัวจริง28. The system of claims in clause 26, in which the video card is restructured to respond to the challenges of authentication. 29. ระบบของข้อถือสิทธิข้อ 19 ซึ่งวีดีโอการ์ดประกอบด้วย คีย์สำหรับการเข้ารหัสการ สื่อสารกับโปรแกรมประยุกต์ที่ปลอด ภัยหนึ่งหรือหลายๆโปรแกรม29. The system of claims under Article 19, which states that the video card contains a key for encrypting communication with one or more secure application programs. 30. วิธีการที่ประกอบด้วย การกำหนดบริเวณที่ปลอดภัยหนึ่งหรือหลายๆบริเวณของพื้นผิว ปฐมภูมิในหน่วย ความจำของวีดีโอการ์ด การเชื่อมโยงคีย์อย่างน้อยหนึ่งคีย์ กับบริเวณที่ปลอดภัย หนึ่งหรือหลายๆบริเวณดัง กล่าว ที่มีความเหมาะสมในการใช้ สำหรับการเข้ารหัสข้อมูลพิกเซลที่ถูกเก็บไว้ในบริเวณที่ ปลอดภัยหนึ่งหรือหลายๆบริเวณ ดังกล่าว การเข้ารหัสข้อมูลพิกเซลกับอย่างน้อยหนึ่งคีย์ที่กล่าวมา และ การป้อนส่งข้อมูลพิกเซลที่เข้ารหัสแล้ว ให้กับบริเวณที่ ปลอดภัยหนึ่งหรือหลาย ๆ บริเวณ ดังกล่าว30. A procedure consisting of: defining one or more secure regions of the primary surface in the video card's memory; associating one or more keys with one or more such secure regions, suitable for encrypting pixel data stored in those secure regions; encrypting the pixel data with at least one of the aforementioned keys; and feeding the encrypted pixel data to one or more such secure regions. 31. ระบบของข้อถือสิทธิข้อ 30 ซึ่งบริเวณที่ปลอดภัยหนึ่ง หรือหลายๆบริเวณ มีรูป ร่างเป็นแบบสี่เหลี่ยมผืนผ้า31. The system of claims under Article 30 in which one or more safe areas are rectangular in shape. 32. ระบบของข้อถือสิทธิข้อ 30 ซึ่งคีย์ประกอบดวยสิ่งที่ สามารถนำไปใช้ในการเข้า รหัส ด้วยการเข้ารหัสแบบกระแส (stream cipher)32. A system of claims in clause 30 whose key contains something that can be used to encrypt using a stream cipher. 33. ระบบของข้อถือสิทธิข้อ 30 ซึ่งคีย์ประกอบด้วยสิ่งที่ สามารถนำไปใช้ในการเข้า รหัส ด้วยการเข้ารหัสแบบบล็อก (block cipher)33. A system of claims in clause 30, whose key contains something that can be used to encrypt using a block cipher. 34. วิธีการของข้อถือสิทธิข้อ 30 ซึ่ง การกระทำการกำหนดนั้น ได้กำหนดบริเวณที่ปลอดภัยหลายบริเวณ และ การกระทำการสร้างความสัมพันธ์นั้นได้ ในสร้างความสัมพันธ์ กับแต่ละบริเวณที่ปลอด ภัยด้วยคีย์ที่แตกต่างกัน34. The method of claim 30, in which the defining action defines multiple secure areas, and the relationship action establishes relationships with each secure area using a different key. 35. วิธีการของข้อถือสิทธิข้อ 30 ซึ่งการกระทำการเข้ารหัส ได้ถูกดำเนินการ โดยอาศัย การเข้ารหัสแบบกระแส ที่ถูกกำหนด ขอบเขตไว้กับบริเวณที่ปลอดภัยหนึ่งหรือหลายๆบริเวณ35. The method of claim 30, in which the encryption action is performed, relies on stream encryption that is confined to one or more secure areas. 36. หนึ่งหรือหลายๆ ชุดคำสั่งบนนั้นที่คอมพิวเตอร์สามารถ อ่านได้ ซึ่งเมื่อมีการปฏิบัติ การดดยคอมพิวเตอร์จำนวน หนึ่งตัวหรือหลายๆตัว จะเป็นสาเหตุให้คอมพิวเตอร์จำนวน หนึ่ง ตัวหรือหลายๆตัวนั้น มีการใช้งานตามวิธีการตามข้อถือ สิทธิข้อ 3036. One or more sets of instructions therein that are readable by computers which, when executed by one or more computers, cause one or more computers to operate in the manner described in Copyright 30. 37. ระบบที่ประกอบด้วย วิถีทางของการกำหนด บริเวณที่ปลอดภัยหนึ่งหรือหลายๆบริเวณ ของพื้นผิวปฐมภูมิ ในหน่วยความจำของวีดีโอการ์ด วิถีทางการเกี่ยวข้องของอย่างน้อยหนึ่งคีย์ กับบริเวรที่ ปลอดภัยหนึ่งหรือหลาย ๆ บริเวณดังกล่าว ที่ความเหมาะสมในการ ใช้สำหรับการเข้ารหัสข้อมูลพิกเซลที่ถูกเก็บไว้ ใน บริเวณ ที่ปลอดภัยหนึ่งหรือหลายๆบริเวณ ดังกล่าว วิถีทางเข้ารหัสข้อมูลพิกเซลโดยใช้อย่างน้อยหนึ่งคีย์ที่ กล่าวมา และ วิถีทางในการป้อนส่งข้อมูลพิกเซลที่เข้ารหัสแล้ว ให้กับ บริเวณที่ปลอดภัยหนึ่งหรือ หลายๆบริเวณ ดังกล่าว37. A system comprising a pathway for defining one or more secure regions of the primary surface in the video card's memory; a pathway for associating at least one key with one or more such secure regions, suitable for encrypting pixel data stored in those secure regions; a pathway for encrypting pixel data using at least one of the aforementioned keys; and a pathway for feeding the encrypted pixel data to one or more such secure regions. 38. วิธีการที่ประกอบด้วย การจัดเตรียมข้อมูลที่เข้ารหัสแล้วในบริเวณที่ปลอดภัยของ พื้นผิวปฐมภูมิบนวีดีโอ การ์ด การจัดเตรียมคีย์ที่สัมพันธ์กับบริเวณที่ปลอดภัย ที่ สามารถใช้สำหรับการถอดรหัสข้อ มูลที่เข้ารหัสแล้ว และ การใช้คีย์ในการถอดรหัสข้อมูลที่เข้ารหัสแล้ว ในบริเวณที่ ปลอดภัยของพื้นผิวปฐมภูมิ38. The procedure consists of: preparing the encrypted data in a secure region of the primary surface on the video card; preparing a key associated with the secure region that can be used to decrypt the encrypted data; and using the key to decrypt the encrypted data in the secure region of the primary surface. 39. วิธีการของข้อถือสิทธิข้อ 38 ซึ่งการดำเนินการใช้คีย์ เกิดขึ้นที่ ที่ตำแหน่งประมวล ผลที่ซึ่งไม่มีการเข้าถึงข้อ มูลพิกเซลที่เข้ารหัสแล้วโดยโปรแกรม39. The method of claim 38 in which key operation occurs at a processing location where the program does not have access to the encrypted pixel data. 40. วิธีการของข้อถือสิทธิข้อ 38 ซึ่งการกระทำการจัด เตรียมการป้อนคีย์ ได้กระทำ โดยหน่วยประมวลผลควบคุม บนวีดี โอการ์ด40. The method of claim 38 in which the key preparation is performed by the control unit on the video card. 41. วิธีการของข้อถือสิทธิข้อ 38 ซึ่งดำเนินการการใช้คีย์ สำหรับการถอดรหัสข้อมูลที่ เข้ารหัส ได้ถูกกระทำโดยตัวถอด รหัสแบบฮาร์ดแวร์ บนวีดีโอการ์ด41. The method of claim 38, which involves the use of a key for decrypting encrypted data, is performed by a hardware decoder on the video card. 42. วิธีการของข้อถือสิทธิข้อ 38 ซึ่งการดำเนินการใช้คีย์ สำหรับการถอดรหัสข้อมูลที่ เข้ารหัส ได้ถูกกระทำโดยตัวถอด รหัสบนวีดีโอการ์ด ที่สามารถลงรายละเอียดเกี่ยวกับรูปร่าง ทางเรขาคณิตของบริเวณที่ปลอดภัย42. The method of claim 38, in which the decryption key for encrypted data is operated by a decryptor on the video card capable of describing the geometric shape of the secure area. 43. วิธีการของข้อถือสิทธิข้อ 38 ซึ่งยังประกอบด้วยการ ป้อนส่งข้อมูลที่ถอดรหัสแล้ว ให้กับตัวแปลงผันการแสดงผล สำหรับการแสดงผลบนจอแสดงผลภาพ43. The method of claim 38, which also involves feeding the decoded data to the display converter for display on the display screen. 44. วิธีการของข้อถือสิทธิข้อ 38 ซึ่งมีบริเวณที่ปลอดภัย แตกต่างกันหลายบริเวณ และ การกระทำการป้อนส่งคีย์ ได้เตรียม คีย์ที่จะถูกสัมพันธ์กับบริเวณที่ปลอดภัยแต่ละบริเวณ44. The method of claim 38, which involves multiple secure areas and key input operations, provides keys that are associated with each secure area. 45. วิธีการของข้อถือสิทธิข้อ 38 ซึ่งมีบริเวณที่ปลอดภัย แตกต่างกันหลายบริเวณ และ การกระทำการป้อนส่งคีย์ประกอบด้วย การจัดเตรียมคีย์เพื่อส่งต่อหลายคีย์ โดยที่แต่ละ บริเวณที่ ปลอดภัยจะสัมพันธ์กับคีย์ที่แตกต่างกัน45. The method of claim 38, which involves multiple secure areas and key transmission operations, involves the provision of multiple keys for transmission, with each secure area associated with a different key. 46. วิธีการของข้อถือสิทธิข้อ 38 ซึ่งการกระทำการใช้คีย์ ถอดรหัส ถูกกระทำโดยการ ใช้การเข้ารหัสแบบกระแส46. The method of claim 38, in which the decryption key is executed, is by using stream encryption. 47. วิธีการของข้อถือสิทธิข้อ 38 ซึ่งการกระทำการใช้คีย์ ถอดรหัส ถูกกระทำโดยการ ใช้การเข้ารหัสแบบกระแสที่มีขอบเขต จำกัด47. The method of claim 38, in which the decryption key is executed, is by using bounded stream encryption. 48. วิธีการของข้อถือสิทธิข้อ 38 ซึ่งการกระทำการใช้คีย์ ถอดรหัส ถูกกระทำโดยการ ใช้เข้ารหัสแบบบล็อก48. The method of claim 38, in which the decryption key is executed, is by using block encryption. 49. หนึ่งหรือหลายๆ ชุดคำสั่งบนนั้นที่คอมพิวเตอร์สามารถ อ่านได้ ซึ่งเมื่อมีการปฏิบัติ การโดยคอมพิวเตอร์จำนวนหนึ่ง เครื่องหรือหลายๆเครื่อง จะเป็นสาเหตุให้คอมพิวเตอร์ จำนวน หนึ่งเครื่องหรือหลายๆเครื่องนั้น มีการวิธีการใช้งานตาม ข้อถือสิทธิข้อ 3849. One or more sets of instructions therein that are readable by computers which, when executed by one or more computers, cause one or more of those computers to use the methods specified in Claim 38. 50. ระบบซึ่งประกอบไปด้วย วิถีทางจัดเตรียมข้อมูลที่เข้ารหัสแล้วในบริเวณที่ปลอดภัย ของพื้นผิวปฐมภูมิบนวีดีโอ การ์ด วิถีทางจัดเตรียมคีย์ที่มีสัมพันธ์กับบริเวณที่ปลอดภัย ที่สามารถใช้สำหรับการถอดรหัส ข้อมูลที่เข้ารหัสแล้ว และ วิถีทางอาศัยคียืในการถอดรหัสข้อมูลที่เข้ารหัสแล้ว ใน บริเวณที่ปลอดภัยของพื้นผิว ปฐมภูมิ50. A system comprising a pathway for providing encrypted data in a secure region of the primary surface on the video card, a pathway for providing a secure region-associated key that can be used for decrypting the encrypted data, and a pathway relying on the key to decrypt the encrypted data in the secure region of the primary surface. 51. วิธีการซึ่งประกอบด้วย การจัดเตรียมข้อมูลที่เข้ารหัสแล้วในบริเวณที่ปลอดภัยของ พื้นผิวปฐมภูมิของวีดีโอ การ์ด บริเวณที่ปลอดภัยจะมีรูปร่าง ทางเรขาคณิตที่สัมพันธ์กัน การจัดเตรียมคีย์ที่มีส่วนร่วมกับบริเวณที่ปลอดภัย ที่ สามารถใช้สำหรับการถอดรหัส ข้อมูลที่เข้ารหัสแล้ว การแจ้งรูปร่างทางเรขาคณิตของบริเวณที่ปลอดภัยให้ตัวถอด รหัสบนวีดีโอการ์ดทราบ จัดเตรียมคีย์ให้แก่ตัวถอดรหัส และ ทำการถอดรหัสข้อมูลที่เข้ารหัสแล้วในบริเวณที่ปลอดภัยของ พื้นผิวปฐมภูมิ ด้วยการ ใช้ตัวถอดรหัส51. The process involves: preparing encrypted data in a secure region of the video card's primary surface (the secure region has a specific geometric shape); providing a key associated with the secure region that can be used to decrypt the encrypted data; informing the video card's decoder of the secure region's geometric shape; providing the key to the decoder; and decrypting the encrypted data in the secure region of the primary surface using the decoder. 52. วิธีการของข้อถือสิทธิข้อ 51 ซึ่งการกระทำการแจ้งให้ ทราบ ได้ถูกกระทำเพื่อตอบ สนองกับวินโดว์ที่แสดงผลบนจอภาพ และสอดคล้องกับบริเวณที่ปลอดภัยที่กำลังถูกลากและ วางไว้ที่ ตำแหน่งใหม่บนจอภาพ52. The method of claim 51 in which the notification action is performed in response to the window displayed on the screen and in accordance with the safe area being dragged and dropped to a new position on the screen. 53. หนึ่งหรือหลายๆ ชุดคำสั่งบนนั้นที่คอมพิวเตอร์สามารถ อ่านได้ ซึ่งเมื่อมีการปฏิบัติ การโดยคอมพิวเตอร์จำนวนหนึ่ง เครื่องหรือหลายๆเครื่อง จะเป็นสาเหตุให้คอมพิวเตอร์ จำนวน หนึ่งเครื่องหรือหลายๆเครื่องนั้น มีการใช้งานตามข้อถือ สิทธิข้อ 5153. One or more sets of instructions therein that are readable by computers which, when executed by one or more computers, cause one or more of those computers to use the rights under claim 51. 54. วิธีการซึ่งประกอบด้วย การจัดเตรียมข้อมูลที่เข้ารหัสแล้ว ในบริเวณที่ปลอดภัยของ พื้นผิวปฐมภูมิบนวีดีโอ การ์ด การจัดเตรียมคีย์ที่สัมพันธ์กับบริเวณที่ปลอดภัย ที่ สามารถใช้สำหรับการถอดรหัสข้อ มูลที่เข้ารหัสแล้ว การใช้คีย์ในการถอดรหัสข้อมูลที่เข้ารหัสแล้ว ในบริเวณที่ ปลอดภัยของพื้นผิวปฐมภูมิ และ ทำการตรวจจับว่ามีข้อมูลใดถูกปรับเปลี่ยนหรือไม่54. The procedure consists of: preparing the encrypted data in a secure region of the primary surface on the video card; preparing a key associated with the secure region that can be used to decrypt the encrypted data; using the key to decrypt the encrypted data in the secure region of the primary surface; and detecting whether any data has been modified. 55. วิธีการของข้อถือสิทธิข้อ 54 ซึ่งการกระทำการตรวจจับ ได้ถูกจัดเตรียมไว้ ก่อนที่ จะมีการแสดงผลข้อมูลที่ไม่เข้า รหัส บนจอภาพ55. The method of claim 54, in which the detection action is performed, is prepared before the unencoded information is displayed on the screen. 56. วิธีการของข้อถือสิทธิข้อ 54 ซึ่งการกระทำการตรวจจับ ได้ถูกกระทำโดยอาศัยข้อ มูลการพิสูจน์ตัวจริงที่เกี่ยวข้อง กับข้อมูลซึ่งเข้ารหัสมาแล้ว56. The method of claim 54, in which the detection action is performed, relies on the authentication information associated with the encrypted data. 57. วิธีการของข้อถือสิทธิข้อ 56 ซึ่งข้อมูลการพิสูจน์ตัว จริง ประกอบด้วยรูปแบบข้อ มูลความปลอดภัยที่พิกเซลที่ได้ กำหนดไว้เบื้องต้นจะต้องมีค่าที่กำหนดไว้เบื้องต้น57. The method of claim 56, in which the authentication information consists of a security data format in which the predefined pixels must have a predefined value. 58. วิธีการของข้อถือสิทธิข้อ 54 ซึ่งการกระทำการตรวจจับ ได้ถูกกระทำ โดยการ เปรียบเทียบแฮซข้อมูลที่ยังไม่เข้ารหัส58. The method of claim 54, in which the detection action is performed, is by comparing the hash of the unencrypted data. 59. วิธีการของข้อถือสิทธิข้อ 54 ซึ่งมีการแจ้งกลับมาผ่าน ช่องทางที่ปลอดภัย ให้แก่ ส่วนเข้ารหัส59. The method of claiming clause 54, which involves notification via a secure channel to the encryption component.
TH301001924A 2003-05-27 Systems and methods for securing video card output TH66596A (en)

Publications (1)

Publication Number Publication Date
TH66596A true TH66596A (en) 2005-01-21

Family

ID=

Similar Documents

Publication Publication Date Title
TWI406569B (en) Unit for managing audio/video data and access control method for said data
CA2434328C (en) Methods and systems for cryptographically protecting secure content
RU2310227C2 (en) Methods and systems for authentication of components in graphic system
CN101719205B (en) Digital copyright management method and system
KR101055091B1 (en) Computer-implemented methods, apparatus, information processing systems, and computer readable recording media
US12200279B2 (en) Content protection
RU2003118753A (en) SYSTEMS AND METHODS FOR PROTECTING THE VIDEO PAYMENT OUTPUT SIGNAL
CN101448127B (en) Secure information storage system and method
MXPA03004371A (en) Systems and methods for securing video card output.
CN115811416B (en) Systems used for decrypting and presenting content
TW201404123A (en) Systems, methods and apparatuses for the secure transmission of media content
US7636441B2 (en) Method for secure key exchange
CN101296226B (en) Method of sharing bus key and apparatus thereof
CN101009549B (en) Decoding device for digital rights management
US8452986B2 (en) Security unit and protection system comprising such security unit as well as method for protecting data
CN120335750A (en) A secure encrypted display system and display method
BRPI0205818B1 (en) Method, medium and device to cryptographically protect security content