Interfacing Application Mediates Normal and Secured Software Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing devices restrict normal software applications from accessing the functionality of trusted applications, which are secured and cannot be extended or modified, limiting their capabilities and compatibility.

Innovation Solution

A method allows a first software application to indirectly access a secured software application through an interfacing application, enabling the use of security infrastructure and secured peripherals, and a method for generating an encrypted image using pre-encrypted blocks of data to create a DRM-protected version.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If normal software applications are restricted from accessing secured software application functionality, then security is improved, but adaptability and versatility deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidaccessibility to secured functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a client application as an intermediary between normal applications and secured applications. The client application runs in the secured processing module and provides controlled access to secured functionality through defined interfaces. This mediator allows normal applications to utilize secured resources (display, keyboard, mouse, etc.) without compromising the security isolation, as all interactions are mediated through the client application which enforces security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If trusted applications cannot be extended or modified, then security is improved, but adaptability deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidfunctionality extension
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the system into three distinct components: secured applications (immutable and security-critical), client applications (interface layer with controlled flexibility), and normal applications (unmodified but extended capability). This segmentation allows the secured application to remain unchanged and secure while the client application layer provides adaptability and extended functionality through configuration and interface design without modifying the core secured code.

Inventive Principle:
Principle #1Segmentation

3Reliability

If secured processing module functionality is limited to specific applications, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal client application interface that can serve multiple normal applications while maintaining security. The client application in the secured processing module provides a standardized interface layer that any normal application can use to access secured functionality. This multi-functional approach allows a single client application implementation to support numerous different normal applications, reducing overall system complexity compared to having dedicated secured applications for each normal application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3183681B1Accessing a secured software application
Publication Date: 2021.06.09 IRDETO BV
  • EP3183681B1 patent drawingFigure 1
  • EP3183681B1 patent drawingFigure 2~3
  • EP3183681B1 patent drawingFigure 4~5

AI summary

There is described a method for a first software application to access a secured software application on a computing device. The first software application is not configured to interface with the secured software application. The computing device includes an interfacing application configured to interface with the secured software application. The method comprises the first software application interfacing with the interfacing application to thereby cause the interfacing application to access the secured software application. The first software application is configured to interface with the interfacing application. There is also described a method of generating an encrypted version of an image using a library of pre-encrypted blocks of data, the same content encryption key having been used to encrypt each of the pre-encrypted blocks of data. The method comprises forming the encrypted version of the image from an ordered sequence of pre-encrypted blocks of data from the library, wherein each pre-encrypted block of data in the ordered sequence corresponds to a respective sub-image of a plurality of sub-images making up the image. There are also described corresponding computing devices, computer programs and computer-readable media.