Secure Display Buffer for Payment Terminal Mode Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing equipment used for confidential actions, such as financial or medical transactions, faces limitations in flexibility and security due to the trade-off between openness to user-friendly applications and security, where malicious applications can compromise the secure mode display, leading to uncertainty for users.
Innovation Solution
A secure display method that allocates separate areas of the screen to information from open and secure operating systems, with exclusive control by the secure operating system to ensure a secure visualization, using filtering and virtual or real video memory to prevent corruption and deception.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the equipment uses an open operating system to provide flexibility and user-friendly applications, then adaptability and ease of operation are improved, but security deteriorates because malicious applications can spy on and betray security processes
Solution Approach 1:
The patent divides the equipment into two distinct modes: open mode for general applications and secure mode for confidential operations. This segmentation allows the system to provide flexibility through open mode while ensuring security through secure mode, resolving the contradiction between adaptability and reliability.
Solution Approach 2:
The patent introduces a secure element as an intermediary component that acts as a trusted mediator between the open operating system and security-critical operations. This secure element isolates security processes from malicious applications while still enabling secure functionality, thus maintaining both flexibility and security.
2Reliability
If the equipment restricts execution to only signed applications to ensure security, then reliability is improved, but adaptability deteriorates because legitimate unsigned applications are also prevented from running
Solution Approach 1:
The patent applies different quality requirements to different parts of the system: signed applications are required for security-critical operations, while unsigned applications are allowed for general-purpose tasks. This localized approach to application signing maintains security where needed without restricting overall system openness and adaptability.
3Ease of operation
If the equipment uses a graphic screen with displayed information to improve ease of operation, then ease of operation is improved, but security deteriorates because malicious applications can corrupt the display to deceive users about the active mode
Solution Approach 1:
The patent introduces a secure display buffer as an intermediary between the open operating system and the physical display. This buffer is exclusively controlled by the secure element, preventing malicious applications from corrupting security-related display information while still allowing rich graphical visualization for user interaction.
Solution Approach 2:
The patent adds a new dimension to display control by introducing a secure display buffer that operates at a different level than the standard display buffer. This additional layer ensures that security-critical information cannot be corrupted by applications running in open mode, while maintaining full graphical capabilities.
4Reliability
If the equipment uses two separate screens for open mode and secure mode to ensure security, then reliability is improved, but device complexity and cost increase
Solution Approach 1:
The patent makes a single graphic screen multi-functional by implementing mode-dependent display rules. The same physical display is used for both open mode and secure mode, with the secure element controlling what information is displayed in secure mode. This eliminates the need for separate screens while maintaining security through exclusive control of security-related display content.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The method involves allocating two zones of a screen of a payment terminal to two sets of information using filters and a direct memory access (30), independently from an open operating system e.g. UNIX(RTM: powerful multitasking operating system), where one set of information is edited by a secured operating system. The two sets of information are transferred to the screen under an exclusive control of the secured operating system to produce a security visualization of the set of information. The two sets of information are combined using a real video RAM (34). An independent claim is also included for a device for securely visualizing information on a screen of a payment terminal.