Secure Desktop Interface Spoofing Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing devices are vulnerable to interface spoofing attacks, where malicious entities deceive users into performing sensitive acts by altering or spoofing the access interface, making it difficult to distinguish between legitimate and malicious applications.

Innovation Solution

The method involves executing the access interface on a secure desktop, where it is visually coupled with the requesting user application, ensuring that the interface is presented in an aesthetically pleasing and expected manner, and automatically switching from the user desktop to the secure desktop to prevent spoofing attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the access interface is displayed on the user desktop, then the user can interact with the requesting application, but the interface may be spoofed by malicious applications

Engineering Contradiction:
Improveinterface authenticityVSAvoidspoofing attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure desktop as an intermediary environment between the user and the access interface. Instead of displaying the interface directly on the vulnerable user desktop, the system switches to a secure desktop that is isolated from malicious applications. This mediator protects the interface from spoofing while maintaining user interaction capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the desktop environment into two distinct parts: a user desktop for normal application execution and a secure desktop for displaying sensitive access interfaces. This segmentation isolates the critical authentication interface from the untrusted user desktop environment, preventing malicious applications from spoofing the interface while preserving normal user workflow.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the system switches to secure desktop to prevent spoofing, then interface authenticity is guaranteed, but user interaction complexity increases

Engineering Contradiction:
Improveinput authenticityVSAvoiddesktop switching operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by automatically switching to the secure desktop and displaying the access interface without requiring explicit user commands. The transition is triggered automatically when an application requests sensitive operations, eliminating the need for users to manually navigate to secure environments and simplifying the interaction flow.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides self-service by automatically managing the secure desktop transition and interface display. The operating system detects when sensitive operations are needed and autonomously switches to the secure desktop environment, presenting the access interface ready for user input without requiring users to understand or manage the security mechanism themselves.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7832004B2Secure privilege elevation by way of secure desktop on computing device
Publication Date: 2010.11.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7832004B2 patent drawing
  • US7832004B2 patent drawing
  • US7832004B2 patent drawing

AI summary

A computing device has a user desktop on which a relatively less-secure user application is executed and a secure desktop elevated from the user desktop on which a relatively more-secure secure application is executed upon a request thereto from the user application. To securely collect information from a user at the computer device with regard to the secure application at the secure desktop, an access interface is securely executed on the secure desktop and is visually presented in conjunction with the requesting user application of the user desktop such that the access interface is visually coupled to the requesting user application and is visually perceived by the user along with such requesting user application.