Low-Level Visual Data Filtering for Secure Window Capture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies lack effective methods to limit the sharing of visual data accessed by processes such as display output, employee monitoring software, and screen sharing processes, necessitating a need for secure control over visual data transmission.
Innovation Solution
A low-level engine within the computing machine, such as a kernel, driver, or desktop window manager, determines whether to include visual data in computing data based on identifiers of windows and capturing processes, using security policies to control data transmission and optionally replacing sensitive data with preset visual signals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If visual data is freely accessed by capturing processes, then ease of operation is improved, but data security deteriorates
Solution Approach 1:
A low-level engine acts as an intermediary between capturing processes and visual data. This engine receives requests from capturing processes, evaluates security policies, and selectively provides or blocks access to visual data. The intermediary mechanism enables controlled access where legitimate processes can obtain visual data while unauthorized access is prevented, thus maintaining both ease of operation for legitimate uses and data security.
2Loss of information
If all visual data is transmitted to capturing processes, then completeness of information is improved, but privacy protection deteriorates
Solution Approach 1:
The system applies different quality levels of data transmission to different regions or types of visual data. Security policies specify which portions of visual data should be transmitted完整地 and which should be obscured or blocked. For example, sensitive windows may have their content obscured while non-sensitive areas remain visible, achieving local differentiation in data transmission quality to protect privacy while maintaining information completeness where appropriate.
Solution Approach 2:
The system dynamically changes parameters of visual data transmission based on security policies. Instead of transmitting all visual data uniformly, the low-level engine modifies transmission parameters such as visibility, opacity, or access permissions for different data elements. This selective parameter modification allows the system to maintain completeness of non-sensitive information while protecting sensitive data, thus balancing information completeness with privacy protection.
3Reliability
If visual data access is restricted to protected processes only, then data security is improved, but device complexity increases
Solution Approach 1:
The low-level engine implements self-service by automatically evaluating security policies and making access decisions without requiring manual intervention or complex external control systems. The engine autonomously determines whether capturing processes should access visual data based on pre-configured security policies, reducing the need for additional complexity in access control mechanisms while maintaining strong security protections.
Data Source
AI summary
A computer receives, at a low-level engine or using software that communicates with the low-level engine, a request for computing data associated with a capturing process. The low-level engine comprises at least one of a kernel, a driver, or a desktop window manager. The computer generates the computing data for provision to the capturing process responsive to the request. Generating the computing data comprises determining to include visual data associated with a window in the computing data based on at least one of an identifier of the window or an identifier of the capturing process. The computer displays a visual indicator to indicate that the visual data associated with the window is being transmitted to the capturing process. The computer provides the computing data to the capturing process.


