Secure Module for Obfuscated Data Transmission on Untrusted Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The variability in operating environments across different mobile devices hinders the rapid development and secure deployment of security-sensitive applications, as devices often lack support for desired security functions, making security-sensitive tasks on mobile devices insecure and risky.

Innovation Solution

A secure module is implemented above the operating system to generate obfuscated user interfaces and track user input data, ensuring that only the secure module can process and verify the authenticity of user inputs, thereby maintaining data integrity even on untrusted devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure module is implemented above the operating system to generate obfuscated user interfaces and track user input data, then security and data integrity are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the computing device into a trusted secure module and an untrusted operating system. The secure module is isolated from the OS and directly interfaces with hardware components (display, input devices), creating a security boundary that prevents the OS from accessing or corrupting sensitive user input data while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure module acts as an intermediary layer between the untrusted operating system and the hardware components. It receives user input directly from hardware, generates obfuscated user interfaces, and tracks data flow without exposing sensitive information to the OS, thereby mediating security concerns while preserving system operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the secure module processes all user input data directly without OS involvement, then data integrity is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata integrityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The secure module is designed to be self-sufficient in processing user input data. It independently receives input from hardware, tracks the complete data flow through the system, generates obfuscated interfaces, and de-obfuscates input values without requiring trust or cooperation from the operating system, thereby maintaining data integrity while operating autonomously.

Inventive Principle:
Principle #25Self-service

3Reliability

If obfuscated user interface data is provided to the operating system, then security is improved, but measurement precision of user input deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidaccuracy of user input
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies different quality requirements to different parts of the system. The secure module maintains high precision in tracking and de-obfuscating user input data locally, while the operating system receives only obfuscated data that appears random or meaningless to it. This local differentiation allows the secure module to preserve measurement precision where needed while providing security to the OS.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The secure module dynamically changes the parameter representation of user input data by obfuscating it before passing to the OS and de-obfuscating it when needed. The same data is represented in different forms (obfuscated vs. clear text) depending on the context and recipient, allowing the system to simultaneously achieve security and precision by changing data parameters rather than compromising either requirement.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9807066B2Secure data transmission and verification with untrusted computing devices
Publication Date: 2017.10.31 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US9807066B2 patent drawing
  • US9807066B2 patent drawing
  • US9807066B2 patent drawing

AI summary

Techniques from the proposed invention relate to providing enhanced security. For example, techniques described herein allow a computer system, such as a mobile device, to support a wide variety of security functions and security sensitive applications on a mobile device by providing enhanced security via secure input and output data transmission and verification through a secure module. The secure module may cause user interfaces to be provided to users by providing obfuscated user interface data to the operating system that do not reveal elements that are part of the user interfaces. The secure module may receive obfuscated user input values representing user input values, and de-obfuscate these user input values, whereby the actual input values are not exposed to the underlying operating system. The secure module may track the flow of user input/output data through the computing device to ensure the integrity and authenticity of this data.