Layered Display Architecture for Secure Digital Content Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Software applications running on operating systems are vulnerable to security breaches, leading to increased risk exposure, particularly in scenarios where the operating system is compromised, and existing security measures fail to effectively isolate layers and prevent data exposure.
Innovation Solution
A method involving a reference patch with encoded data is embedded in displayed data, allowing a server to identify authorized users and transmit secondary digital content to a specific layer of an electronic device, while maintaining an air gap between layers to prevent data exposure in case of OS compromise.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If software applications run directly on the operating system, then ease of operation is improved, but security reliability deteriorates due to potential OS compromise
Solution Approach 1:
The patent divides the software stack into distinct isolated layers: a first layer for displaying application data and a second layer for processing digital content. This segmentation prevents direct access between layers, so that even if the OS is compromised, the application layer remains protected. The server also segments user identification and authorization processes from the application layer, further enhancing security isolation.
2Reliability
If the operating system is compromised, then security vulnerability increases, but existing security measures fail to isolate layers effectively
Solution Approach 1:
The patent introduces a server as an intermediary between the application layer and the digital content processing layer. The server handles user identification, authorization, and content delivery without allowing direct communication between the electronic device layers. This intermediary architecture provides robust security isolation even when the OS is compromised, as the attack surface is limited to the server interface rather than direct layer-to-layer access.
3Reliability
If application layers are isolated from the operating system, then security reliability is improved, but device complexity increases due to layered architecture
Solution Approach 1:
The patent adds a temporal and architectural dimension to security isolation by implementing distinct display layers (first layer for application data, second layer for processed content) that operate in sequence rather than direct interaction. The server operates in a separate dimensional space, receiving requests from the first layer and delivering content to the second layer without direct device-layer access. This dimensional separation achieves strong security isolation while maintaining a relatively simple user-facing interface.
Data Source
AI summary
A method that includes receiving, via processing circuitry of a server, a unique identifier having encoded data included in a reference patch embedded in displayed data received by an electronic device, the electronic device being instructed to display the displayed data in a first layer of the electronic device, the server being inaccessible by the first layer of the electronic device; identifying an identity of a user based on the unique identifier of the reference patch; upon determining the user is authorized to receive the secondary digital content, transmitting the secondary digital content to the electronic device; and instructing the electronic device to display the secondary digital content in a second layer of the electronic device, the server being accessible by the second layer of the electronic device, the first layer of the electronic device being different from the second layer of the electronic device.


