Hardware User Interface Firewall for Pixel-Level Security Separation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for securing private information on user devices compromise between usability and security, as they either reduce ease of use or increase cost, and fail to effectively protect sensitive data from unauthorized access.

Innovation Solution

A hardware controller that separates the user interface into secure and non-secure areas at a pixel level, using a hardware module to manage communications between processors and the user interface, ensuring seamless operation and security without compromising usability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate display and user interface or standalone hardware device is used, then security is improved, but ease of use deteriorates and cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidease of use
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The display is segmented into secure and non-secure areas, allowing different security levels to coexist on the same device. The hardware firewall controller divides the display output into distinct regions that can be accessed by different security domains, enabling secure information to be displayed without compromising overall system usability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hardware firewall controller is introduced as an intermediary component between the secure and non-secure processing domains. This controller manages the boundary between different security levels, allowing controlled information flow while maintaining security isolation, thus eliminating the need for separate hardware devices.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate display and user interface or standalone hardware device is used, then security is improved, but cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The secure and non-secure processing domains are merged into a single integrated device with a unified display. The hardware firewall controller enables both security domains to share the same display and user interface resources, eliminating the need for separate hardware devices and reducing overall system cost.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The display and user interface are designed to serve multiple security domains simultaneously. The same display hardware can display both secure and non-secure information, and the user interface can interact with both domains, making the system more versatile and cost-effective.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If the main screen is connected through nonsecure chip and OS, then ease of use is maintained, but security deteriorates

Engineering Contradiction:
Improveease of useVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A hardware firewall controller is positioned as an intermediary between the non-secure main screen and secure processing domains. This intermediary enforces security policies at the hardware level, allowing the main screen to remain accessible and easy to use while preventing unauthorized access to secure information through the display.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Different security qualities are applied to different regions of the display. The hardware firewall controller assigns specific security attributes to different display areas, allowing secure and non-secure content to be displayed simultaneously with appropriate security protections applied locally to each region.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12353611B2Hardware user interface firewall
Publication Date: 2025.07.08 HUB DATA SECURITY LTD
  • US12353611B2 patent drawing
  • US12353611B2 patent drawing
  • US12353611B2 patent drawing

AI summary

A hardware controller for securing one or more parts of an MMI, the hardware controller may include a MMI interface configured to communicate with the MMI; a first security level (SL) processor interface configured to communicate with a first SL processor while maintaining the first SL; a second SL processor interface configured to communicate with a second SL processor while maintaining the second SL; wherein the second SL differs from the first SL; a configuration interface configured to receive configuration information that divides the MMI to one or first SL MMI areas and to one or more second SL MMI areas; and a controller core configured to control, based on the configuration information, (a) a communication between the first SL processor and the one or first SL MMI areas, and (b) a communication between the second SL processor and the one or second SL MMI areas.