Secure Display Buffer Differentiation for Spoofing Resistance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data processing systems that display both secure and non-secure data simultaneously lack intuitive methods for users to distinguish between secure and non-secure information, making it difficult for users to trust the authenticity of displayed data, as security indicators can be easily spoofed by untrusted processes.
Innovation Solution
A data processing apparatus with a secure user input that is inaccessible to untrusted processes, allowing users to transform secure and non-secure data elements differently for visual differentiation, ensuring that secure data is clearly distinguishable from non-secure data, thereby preventing spoofing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate secure displays are used to display only secure data, then security reliability is improved, but device complexity and cost increase
Solution Approach 1:
The patent combines secure and non-secure display capabilities into a single display device. The display controller integrates multiple functions including secure buffer management, non-secure buffer management, and merging logic that combines secure and non-secure pixel data into a single output stream, eliminating the need for separate secure and non-secure display hardware while maintaining security guarantees.
Solution Approach 2:
The single display device is designed to perform multiple functions: displaying secure data, displaying non-secure data, and merging both types of data simultaneously. The display controller acts as a universal interface that handles both secure and non-secure data streams and combines them into a unified display output, making the system more versatile while reducing hardware complexity.
2Ease of operation
If conventional security indicators such as padlock pictures are used, then ease of operation is improved, but reliability deteriorates because they are easy to spoof
Solution Approach 1:
Instead of using generic security indicators that appear throughout the interface, the patent implements security-specific display elements at the pixel level. Each secure pixel data element is individually marked with security information, allowing the system to differentiate secure from non-secure content at the most granular level. This local quality approach ensures that security properties are embedded directly in the display data rather than added as separate indicator layers that can be spoofed.
Solution Approach 2:
The patent introduces a secure buffer and display controller as intermediary components between the secure data source and the display output. The secure buffer stores secure pixel data separately from non-secure data, and the display controller acts as a mediator that reads from both secure and non-secure buffers, merges the data streams, and outputs combined display data. This intermediary architecture provides a trusted path that prevents spoofing while maintaining ease of use.
3Ease of operation
If all pixels are displayed homogenously without security differentiation, then ease of operation is improved, but reliability deteriorates as users cannot distinguish secure from non-secure data
Solution Approach 1:
The patent applies local quality by embedding security information directly into individual pixel data elements in the secure buffer. Each secure pixel data element contains or is associated with security information that identifies it as secure. This allows the display system to differentiate secure from non-secure content at the pixel level while maintaining a unified display appearance, resolving the contradiction between simplicity and authenticity.
Data Source
AI summary
A data processing apparatus is disclosed that comprises: at least one processor; a display for displaying data processed by said at least one processor; at least one display buffer for storing an array of display elements for subsequent output to said display, said display elements being secure display elements for displaying secure data and non-secure display elements; and a user interface; wherein said at least one processor is operable to execute at least one untrusted process and at least one secure process, said at least one secure process having access to secure data; said data processing apparatus further comprising: a secure user input for receiving a user input, said received user input not being accessible to said at least one untrusted process; and said data processing apparatus being responsive to an input received at said secure user input to transform data to be displayed on said display such that said secure display elements and said non-secure display elements are transformed differently to each other.


