Secure Data Display via Filter Module Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In online payments, there is a security risk where hackers can hijack the main processor, causing 'what you see is not what you sign for' due to tampered transaction data being processed and signed, rather than the original data displayed to the user.

Innovation Solution

A method and device that enter a security display state, where a control filter module obtains and processes data packets to ensure that only security data is displayed at a fixed address, preventing tampering by controlling the display module and security module to confirm and process the correct data, thus ensuring 'what you see is what you sign for'.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the main processor processes transaction data for display, then the payment process is efficient and simple, but hackers can hijack the processor to tamper with data, causing 'what you see is not what you sign for'

Engineering Contradiction:
Improvedata integrityVSAvoiddata processing architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the data processing architecture into separate modules: a first processor dedicated to security processing and a second processor dedicated to display processing. This segmentation ensures that the security module processes the original transaction data while the display module shows the same data, preventing tampering and ensuring 'what you see is what you sign for' without requiring a complete system redesign

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a filter module as an intermediary between the display module and security module. This filter module verifies that the data sent to the security module matches the data being displayed, acting as a mediator to ensure data consistency and prevent hackers from substituting tampered data for the original transaction data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate security module and display module are used, then data security is improved, but it is difficult to guarantee that the signed data matches the displayed data

Engineering Contradiction:
Improvedata securityVSAvoiddata consistency
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the filter module continuously monitors and verifies that the data flowing to the security module is identical to the data being displayed to the user. This feedback loop ensures real-time data consistency, allowing the system to maintain separate security and display modules while guaranteeing that 'what you see is what you sign for'

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The filter module serves as an intermediary that bridges the security module and display module, verifying data consistency between them. This intermediary ensures that even though the modules are separate, the data processed for signing matches the data displayed, preventing information loss or inconsistency

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11438308B2Method and device for securely displaying data
Publication Date: 2022.09.06 TENDYRON CORP
  • US11438308B2 patent drawing

AI summary

A method and device for securely displaying data are displayed. The method includes the following. A security display state is entered after an instruction used for starting the security display state is received. A current data packet to be displayed is obtained. If a display address includes a security display address, security data corresponding to the security display address is obtained from current data to be displayed. The security data is securely processed. The security data is displayed at the security display address. A security processing result of the security data is obtained. The security display address is a fixed address.