There has been a persistent round of rumors stating that upcoming Intel
processors come with an additional, unwelcome feature: hardware digital
restrictions management (DRM) capabilities. According to some, this
built-in DRM is the motivating force behind Apple's just-announced switch
to Intel processors. If Intel is to be believed, the reality of the
situation is not as bad as one might fear.
According to Donald Whiteside, an Intel VP,
there is no secret DRM in Intel's chips:
The rights management technology referred to in the article was not
a secret DRM from Intel, but the DTCP-IP technology publicly
offered by the 5C Entity; which Intel is a Founder. Intel believes
that the DTCP-IP technology is an important element in enabling
protected transport of compressed content within the home network,
and we continue to promote DTCP-IP for this application which
enables greater consumer flexibility & use of premium
entertainment content.
The DTCP web site has some information
on this technology - though one must pay significant money and sign some
highly restrictive documents to get the full scoop. Essentially, DTCP is a
way for devices to talk over local links - an IEEE1394 connection or home
wireless network, for example - without creating fears that somebody's
Valuable Intellectual Property will leak out into the world and bring an
end to civilization. It's a fairly straightforward combination of
encryption and remote attestation protocols.
Essentially, a DTCP-enabled device has, buried within it, a signed
certificate identifying it as being approved by the powers that be. When
two such devices communicate, they send challenges and check certificates
to ensure that they are both approved; if the authentication step fails, no
content will be exchanged. Assuming the authentication succeeds, encrypted
content can be sent in one direction or the other; this content includes a
set of flags specifying the rules which are to apply to the copying of that
content. Anybody who makes an approved device must, of course, promise to
implement those rules.
The DTCP designers have not left things to chance; each device includes
within it a "revoked certificates" list. When somebody's gadget is shown
to be insufficiently attentive to the restrictions applied to Valuable
Intellectual Property, its certificate can be added to that list. Every
device, and every piece of content as well, carries a copy of the list, and
devices will update their list when a newer version comes along. So your
compromised video player may well make copies for a while, until you bring
in a disk with a new revocation list; after that, none of your other
gadgets will talk to it any more.
It is still not clear what features Intel has added to its chips to support
DTCP. It is unlikely to be anything which will be useful to Linux users.
But, at least, it does not appear to be a system to lock "unauthorized"
operating systems out of the processor. And certainly none of us expected
any sort of free multimedia software to get a stamp of approval from the
entertainment industry anyway.
Comments (9 posted)