Secure Mode Indicator Preventing Phishing via OS Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are unable to distinguish between a counterfeit and a valid secure desktop, leading to potential unauthorized access and theft of privileged information due to malicious applications mimicking legitimate display areas, which compromises security.

Innovation Solution

Implementing a system that automatically alerts users when the operating system transitions to a secure mode through an indicator device, ensuring that only the operating system can control the indicator, thereby preventing malicious applications from intercepting privileged information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If malicious applications render display areas that appear similar to legitimate secure desktops, then users can be prompted to provide privileged information, but users cannot distinguish counterfeit from valid secure desktops

Engineering Contradiction:
Improveability to render similar display areasVSAvoiduser ability to distinguish valid from counterfeit
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary indicator device (such as an LED light) that is exclusively controlled by the operating system to provide visual feedback about secure mode status. This intermediary element serves as a trusted mediator between the system state and the user, allowing users to reliably distinguish valid secure desktops from counterfeit ones without requiring complex visual verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent utilizes color changes in the indicator device to communicate system state information. The indicator changes its visual state (e.g., illumination color or presence) to indicate whether the system is in a secure mode, providing an intuitive and reliable visual cue that users can easily understand to differentiate between safe and unsafe display environments.

Inventive Principle:
Principle #32Color changes

2Reliability

If the operating system transitions to secure mode to prevent application interception, then privileged information is protected, but users need visual indication to know when secure mode is active

Engineering Contradiction:
Improveprotection of privileged informationVSAvoiduser awareness of secure mode status
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The indicator device acts as an intermediary that bridges the gap between the secure mode mechanism and user awareness. It provides a simple, direct visual indication that allows users to easily understand when secure mode is active without complicating the user interface or requiring technical knowledge of system states.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback by having the indicator device respond to secure mode transitions. When the operating system enters or exits secure mode, the indicator visually reflects this state change, providing real-time feedback to users about the current security status and enabling informed user behavior.

Inventive Principle:
Principle #23Feedback

3Reliability

If only the operating system can control the indicator device, then malicious applications cannot fake secure mode indication, but the indicator control mechanism must be secure and reliable

Engineering Contradiction:
Improveauthenticity of secure mode indicationVSAvoidindicator control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The indicator device serves as a trusted intermediary that is exclusively controlled by the operating system through secure pathways. This intermediary is protected from manipulation by malicious applications, ensuring that only authentic secure mode indications can be displayed, thereby maintaining high reliability without requiring overly complex control mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8793786B2User indicator signifying a secure mode
Publication Date: 2014.07.29 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8793786B2 patent drawing
  • US8793786B2 patent drawing
  • US8793786B2 patent drawing

AI summary

Computer-readable media, computerized methods, and computer systems for alerting a user that an operating system has entered a secure mode is provided. Initially, inputs are received at an operating system residing in a default mode. Typically, the default mode allows applications running on the operating system to access the inputs. If the inputs are identified as a call to perform a protected operation, the operating system is transitioned from the default mode to the secure mode. Typically, the secure mode restricts the applications from intercepting the inputs. The transition to the secure mode is automatically communicated to the user via an indicator device. Generally, automatic communication includes providing a message from the operating system to the indicator device over a secure pathway that triggers the indicator device to generate a user-perceivable output. Accordingly, the operating system exerts exclusive control over the operation of the indicator device.