Secure Lock Screen Graphics Context Entitlements

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional lock screens on computing devices are vulnerable to circumvention, allowing malicious access despite being engaged, which compromises the security of sensitive data stored on these devices.

Innovation Solution

Implementing a secure lock screen system by assigning entitlements to graphics contexts of applications, determining whether they can be displayed when the device is locked, and managing these entitlements through an application manager and rendering server to control access and visibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a conventional lock screen is implemented to prevent unauthorized access, then security is improved, but the lock screen can be circumvented by malicious techniques, reducing reliability

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to circumvention
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the lock screen functionality by creating separate graphics contexts for different applications with distinct entitlement levels. Instead of a single monolithic lock screen, the system divides access control into multiple independent contexts (e.g., full-screen lock screen, picture-in-picture lock screen, notification lock screen), each with its own security rules and entitlement assignments. This segmentation prevents circumvention techniques from affecting the entire system, as compromising one graphics context does not compromise others.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by assigning different entitlement levels and security properties to specific graphics contexts based on their functional requirements. Each graphics context receives customized security attributes (e.g., some allow picture-in-picture display, others require full-screen mode, some permit notifications while others block them). This localized security approach ensures that each application's graphics context has the precise security properties needed for its specific use case, rather than applying uniform security rules across all contexts.

Inventive Principle:
Principle #3Local quality

2Reliability

If the lock screen is made more restrictive to prevent circumvention, then security is improved, but user functionality is reduced, worsening ease of operation

Engineering Contradiction:
ImprovesecurityVSAvoiduser functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamics by making the lock screen behavior adaptive based on the entitlement level of each graphics context. Different graphics contexts dynamically exhibit different functional characteristics: some allow picture-in-picture display for video playback, others permit notifications to display, some enable camera access, and others require full-screen mode. This dynamic configuration allows the system to provide appropriate functionality for each use case while maintaining security, rather than applying static restrictive rules to all contexts.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies universality by designing a single entitlement assignment mechanism that controls multiple aspects of graphics context behavior simultaneously. The entitlement system serves multiple functions: it controls display mode (full-screen vs. picture-in-picture), notification visibility, camera access, and other functional characteristics. This multi-functional approach allows one security mechanism to manage diverse operational requirements across different applications and contexts, improving ease of operation while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If all applications are blocked during locked mode to ensure security, then security is improved, but legitimate application access is prevented, reducing productivity

Engineering Contradiction:
ImprovesecurityVSAvoidapplication access
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by pre-assigning entitlement levels to graphics contexts before the lock screen is engaged. The system proactively configures which applications are permitted to display during locked mode based on their entitlement assignments. This preliminary configuration allows the system to quickly determine which applications should remain accessible (e.g., camera, notes, picture-in-picture video) without requiring real-time security evaluations when the lock screen is activated, thereby maintaining both security and productivity.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If the lock screen allows picture-in-picture display for certain applications, then ease of operation is improved, but security vulnerabilities increase, worsening reliability

Engineering Contradiction:
Improvepicture-in-picture functionalityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by assigning picture-in-picture display permission as a specific entitlement property to individual graphics contexts based on their functional requirements. Not all graphics contexts receive this entitlement; only those specifically designated for video playback or similar use cases are granted picture-in-picture capability. This localized entitlement assignment allows picture-in-picture functionality to be available where needed for ease of operation while maintaining security by restricting it to approved contexts with appropriate entitlements.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11574066B2Methods and system for implementing a secure lock screen
Publication Date: 2023.02.07 APPLE INC
  • US11574066B2 patent drawing
  • US11574066B2 patent drawing
  • US11574066B2 patent drawing

AI summary

Disclosed herein is a technique for implementing a secure lock screen on a computing device. The secure lock screen is configured to permit particular applications to display their content—such as main user interfaces (UIs)—while maintaining a desired overall level of security on the computing device. Graphics contexts, which represent drawing destinations associated with the applications, are tagged with entitlement information that indicates whether or not each graphics context should be displayed on the computing device when the computing device is in a locked-mode. Specifically, an application manager tags each application that is initialized, where the tagging is based on a level of entitlement possessed by the application. In turn, a rendering server that manages the graphics contexts can identify the tagged entitlement information and display or suppress the content of the applications in accordance with their entitlements.