Layered Display Architecture for Secure Digital Content Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software applications running on operating systems are vulnerable to security breaches, leading to increased risk exposure, particularly in scenarios where the operating system is compromised, and existing security measures fail to effectively isolate layers and prevent data exposure.

Innovation Solution

A method involving a reference patch with encoded data is embedded in displayed data, allowing a server to identify authorized users and transmit secondary digital content to a specific layer of an electronic device, while maintaining an air gap between layers to prevent data exposure in case of OS compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software applications run directly on the operating system, then ease of operation is improved, but security reliability deteriorates due to potential OS compromise

Engineering Contradiction:
Improveease of operationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the software stack into distinct isolated layers: a first layer for displaying application data and a second layer for processing digital content. This segmentation prevents direct access between layers, so that even if the OS is compromised, the application layer remains protected. The server also segments user identification and authorization processes from the application layer, further enhancing security isolation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the operating system is compromised, then security vulnerability increases, but existing security measures fail to isolate layers effectively

Engineering Contradiction:
Improvesecurity vulnerabilityVSAvoidlayer isolation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a server as an intermediary between the application layer and the digital content processing layer. The server handles user identification, authorization, and content delivery without allowing direct communication between the electronic device layers. This intermediary architecture provides robust security isolation even when the OS is compromised, as the attack surface is limited to the server interface rather than direct layer-to-layer access.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If application layers are isolated from the operating system, then security reliability is improved, but device complexity increases due to layered architecture

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent adds a temporal and architectural dimension to security isolation by implementing distinct display layers (first layer for application data, second layer for processed content) that operate in sequence rather than direct interaction. The server operates in a separate dimensional space, receiving requests from the first layer and delivering content to the second layer without direct device-layer access. This dimensional separation achieves strong security isolation while maintaining a relatively simple user-facing interface.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20220353078A1Integrating digital content into displayed data on an application layer via processing circuitry of a server
Publication Date: 2022.11.03 MOBEUS IND INC
  • US20220353078A1 patent drawing
  • US20220353078A1 patent drawing
  • US20220353078A1 patent drawing

AI summary

A method that includes receiving, via processing circuitry of a server, a unique identifier having encoded data included in a reference patch embedded in displayed data received by an electronic device, the electronic device being instructed to display the displayed data in a first layer of the electronic device, the server being inaccessible by the first layer of the electronic device; identifying an identity of a user based on the unique identifier of the reference patch; upon determining the user is authorized to receive the secondary digital content, transmitting the secondary digital content to the electronic device; and instructing the electronic device to display the secondary digital content in a second layer of the electronic device, the server being accessible by the second layer of the electronic device, the first layer of the electronic device being different from the second layer of the electronic device.