Secure Lock Screen Graphics Context Entitlements
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional lock screens on computing devices are vulnerable to circumvention, allowing malicious access despite being engaged, which compromises the security of sensitive data stored on these devices.
Innovation Solution
Implementing a secure lock screen system by assigning entitlements to graphics contexts of applications, determining whether they can be displayed when the device is locked, and managing these entitlements through an application manager and rendering server to control access and visibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a conventional lock screen is implemented to prevent unauthorized access, then security is improved, but the lock screen can be circumvented by malicious techniques, reducing reliability
Solution Approach 1:
The patent segments the lock screen functionality by creating separate graphics contexts for different applications with distinct entitlement levels. Instead of a single monolithic lock screen, the system divides access control into multiple independent contexts (e.g., full-screen lock screen, picture-in-picture lock screen, notification lock screen), each with its own security rules and entitlement assignments. This segmentation prevents circumvention techniques from affecting the entire system, as compromising one graphics context does not compromise others.
Solution Approach 2:
The patent applies local quality by assigning different entitlement levels and security properties to specific graphics contexts based on their functional requirements. Each graphics context receives customized security attributes (e.g., some allow picture-in-picture display, others require full-screen mode, some permit notifications while others block them). This localized security approach ensures that each application's graphics context has the precise security properties needed for its specific use case, rather than applying uniform security rules across all contexts.
2Reliability
If the lock screen is made more restrictive to prevent circumvention, then security is improved, but user functionality is reduced, worsening ease of operation
Solution Approach 1:
The patent implements dynamics by making the lock screen behavior adaptive based on the entitlement level of each graphics context. Different graphics contexts dynamically exhibit different functional characteristics: some allow picture-in-picture display for video playback, others permit notifications to display, some enable camera access, and others require full-screen mode. This dynamic configuration allows the system to provide appropriate functionality for each use case while maintaining security, rather than applying static restrictive rules to all contexts.
Solution Approach 2:
The patent applies universality by designing a single entitlement assignment mechanism that controls multiple aspects of graphics context behavior simultaneously. The entitlement system serves multiple functions: it controls display mode (full-screen vs. picture-in-picture), notification visibility, camera access, and other functional characteristics. This multi-functional approach allows one security mechanism to manage diverse operational requirements across different applications and contexts, improving ease of operation while maintaining security.
3Reliability
If all applications are blocked during locked mode to ensure security, then security is improved, but legitimate application access is prevented, reducing productivity
Solution Approach 1:
The patent applies preliminary action by pre-assigning entitlement levels to graphics contexts before the lock screen is engaged. The system proactively configures which applications are permitted to display during locked mode based on their entitlement assignments. This preliminary configuration allows the system to quickly determine which applications should remain accessible (e.g., camera, notes, picture-in-picture video) without requiring real-time security evaluations when the lock screen is activated, thereby maintaining both security and productivity.
4Ease of operation
If the lock screen allows picture-in-picture display for certain applications, then ease of operation is improved, but security vulnerabilities increase, worsening reliability
Solution Approach 1:
The patent applies local quality by assigning picture-in-picture display permission as a specific entitlement property to individual graphics contexts based on their functional requirements. Not all graphics contexts receive this entitlement; only those specifically designated for video playback or similar use cases are granted picture-in-picture capability. This localized entitlement assignment allows picture-in-picture functionality to be available where needed for ease of operation while maintaining security by restricting it to approved contexts with appropriate entitlements.
Data Source
AI summary
Disclosed herein is a technique for implementing a secure lock screen on a computing device. The secure lock screen is configured to permit particular applications to display their content—such as main user interfaces (UIs)—while maintaining a desired overall level of security on the computing device. Graphics contexts, which represent drawing destinations associated with the applications, are tagged with entitlement information that indicates whether or not each graphics context should be displayed on the computing device when the computing device is in a locked-mode. Specifically, an application manager tags each application that is initialized, where the tagging is based on a level of entitlement possessed by the application. In turn, a rendering server that manages the graphics contexts can identify the tagged entitlement information and display or suppress the content of the applications in accordance with their entitlements.


