Screen Region Blocking for Sensitive Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for blocking access to sensitive information displayed on computing devices are inadequate in effectively preventing malicious applications from obtaining and stealing confidential data, as they fail to accurately intercept and block access to protected applications.

Innovation Solution

A system and method that intercepts access to displayed information, determines the region associated with the access, analyzes intersections with graphic interfaces, calculates importance and danger ratings, and blocks access based on these ratings to prevent malicious applications from accessing sensitive data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If antivirus applications intercept access to screen data to block malicious programs, then protection against screenshot theft is improved, but false blocking of legitimate applications occurs

Engineering Contradiction:
Improveprotection effectivenessVSAvoidlegitimate application access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system assigns different security attributes to different regions of the screen by determining confidentiality coefficients for specific display regions. Each region is evaluated independently based on its association with protected applications, allowing selective blocking only where confidential information is displayed while permitting legitimate access to other regions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The screen display is divided into multiple regions, and the system calculates importance ratings and confidentiality coefficients for each region separately. This segmentation enables the security system to make granular blocking decisions for individual regions rather than blocking entire applications or the whole screen, thus preventing false positives.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the system blocks all access to screen data to prevent malicious access, then data security is improved, but user accessibility to legitimate information is reduced

Engineering Contradiction:
Improvedata securityVSAvoiduser access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically evaluates each access request by calculating importance ratings and confidentiality coefficients in real-time based on the specific process, region, and graphic interface elements involved. This dynamic assessment allows the system to adaptively permit or block access on a per-request basis, maintaining security while ensuring legitimate user productivity is not hindered.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the security parameters (importance rating, confidentiality coefficient, danger rating) based on the specific context of each access request. By adjusting these parameters dynamically according to the process identity, display region, and graphic interface analysis, the system achieves fine-grained control that balances security with user productivity.

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If the system analyzes all graphic interfaces to accurately identify protected content, then blocking precision is improved, but system complexity increases

Engineering Contradiction:
Improveblocking accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system performs partial analysis by focusing only on the specific graphic interface elements that intersect with the region containing confidential information. Rather than analyzing the entire application interface comprehensively, the system examines only the relevant portions that overlap with protected display regions, reducing computational complexity while maintaining blocking accuracy.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10210348B2System and method of blocking access to protected applications
Publication Date: 2019.02.19 AO KASPERSKY LAB
  • US10210348B2 patent drawing
  • US10210348B2 patent drawing
  • US10210348B2 patent drawing

AI summary

Disclosed are systems and methods for blocking access to protected applications. An exemplary method includes: intercepting access by a process of first information to be displayed on the user's device; determining second information based on the interception of the access by the process, the second information associated with the process; determining a region on a display of the user's device associated with the first information; analyzing one or more intersections between the region and at least one graphic interface associated with the process; and blocking the access by the process to the first information based on the analysis of the one or more intersections between the region and the at least one graphic interface associated with the process.