Screen Data Interception for Protected Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for blocking access to protected applications on computing devices are inadequate in preventing malicious programs from obtaining sensitive information displayed on screens, as they fail to effectively intercept and analyze access to screen data, leading to potential data theft.

Innovation Solution

A system and method that intercepts access to screen information, determines the region of interest, analyzes intersections with graphic interfaces, calculates importance and danger ratings, and blocks access based on these ratings to prevent malicious applications from accessing confidential data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus applications intercept access to screen data using known methods, then some protection is provided, but malicious applications can still obtain sensitive information displayed on the screen

Engineering Contradiction:
Improveprotection effectivenessVSAvoiddata theft risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional mechanical interception methods with a graphical interface-based analysis system. Instead of simply blocking access to screen data, the system analyzes graphical representations of application windows, determines their spatial relationships with sensitive regions, and makes intelligent blocking decisions based on visual information rather than raw data interception.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary graphical interface analysis layer between the malicious application and the sensitive screen data. The system creates graphical representations of application windows and uses these as intermediaries to determine whether blocking is necessary, rather than directly intercepting and analyzing raw screen data or process information.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system blocks all access to screen data to prevent data theft, then security is improved, but legitimate applications cannot access information they need to display

Engineering Contradiction:
Improvesecurity levelVSAvoidapplication functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by treating different regions of the screen differently. Instead of uniformly blocking all screen data access, the system identifies specific sensitive regions (where confidential information is displayed) and only blocks access to those particular areas. Legitimate applications can continue to access and display information in non-sensitive regions without interference.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If the system analyzes all process access requests to determine legitimacy, then accuracy of blocking decisions is improved, but system performance and processing speed decrease

Engineering Contradiction:
Improveblocking accuracyVSAvoidprocessing speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent extracts only the essential visual features needed for security decision-making from complete screen data. Instead of analyzing all process access requests in full detail, the system creates simplified graphical representations of application windows and extracts key spatial relationship information, discarding unnecessary data while retaining the critical information needed to make accurate blocking decisions.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentEP3276522B1System and method of blocking access to protected applications
Publication Date: 2020.04.15 AO KASPERSKY LAB
  • EP3276522B1 patent drawingFigure 1
  • EP3276522B1 patent drawingFigure 2
  • EP3276522B1 patent drawingFigure 3

AI summary

Disclosed are systems and methods for blocking access to protected applications. An exemplary method includes: intercepting access by a process of first information to be displayed on the user's device; determining second information based on the interception of the access by the process, the second information associated with the process; determining a region on a display of the user's device associated with the first information; analyzing one or more intersections between the region and at least one graphic interface associated with the process; and blocking the access by the process to the first information based on the analysis of the one or more intersections between the region and the at least one graphic interface associated with the process.