Secure Runtime Environment Display Data Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in distinguishing between trustworthy and manipulated applications on a terminal device, particularly in determining whether they are communicating with a secure runtime environment, as unauthorized applications can pretend to be from the secure environment, leading to potential data breaches.

Innovation Solution

The method involves transferring display data from the normal runtime environment to the secure runtime environment for verification against security criteria, ensuring that only unmanipulated data is displayed, and modifying data if criteria are not met to distinguish it from secure environment data, using graphical elements or cryptographic checks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If display data is provided via normal runtime environment, then ease of operation is improved, but reliability deteriorates due to potential manipulation

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a security element as an intermediary between the normal runtime environment and the display device. This security element verifies display data before it is shown to the user, acting as a mediator that ensures reliability while allowing the normal runtime environment to continue providing ease of operation. The security element checks whether display data originates from trusted sources and has not been manipulated, thus resolving the contradiction between operational convenience and data reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate display elements are provided for secure and normal runtime environments, then reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the display functionality for both secure and normal runtime environments into a single display device. Instead of providing separate display elements, the invention combines them while using a security element to verify and distinguish display data sources. This merging approach maintains reliability through verification while reducing device complexity by eliminating the need for separate physical display elements.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If display data from normal runtime environment is transferred to secure runtime environment for verification, then reliability is improved, but productivity decreases due to additional processing

Engineering Contradiction:
ImprovereliabilityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial verification by having the security element check specific security-relevant aspects of display data rather than performing exhaustive analysis on all display data. The verification focuses on critical security criteria such as source authentication and manipulation detection, while allowing other display operations to proceed efficiently. This partial action approach maintains reliability for security-critical functions while preserving overall productivity by avoiding excessive processing of all display content.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2700033B1Method for displaying information on a display device of a terminal
Publication Date: 2018.09.05 TRUSTONIC
  • EP2700033B1 patent drawingFigure 1

AI summary

The invention relates to a method for displaying information on a display device (D1, D2) of a terminal, particularly a mobile terminal, wherein the terminal contains a microprocessor unit in which a normal runtime environment (NZ) and a protected runtime environment (TZ) are implemented, wherein display data (DD1, DD2, DD2', TDD2) can be provided for reproduction on the display device (D1, D2) by means of the normal runtime environment (NZ) and the protected runtime environment (TZ). In this case, at least some display data (DD2) provided by means of the normal runtime environment (NZ) are transferred to the protected runtime environment (TZ), which checks whether the transferred display data (DD2) satisfy one or more security criteria, wherein if they do not satisfy at least one security criterion then the display data (DD2) are rejected or are altered such that they can be distinguished from display data (TDD2) provided by means of the protected runtime environment (TZ) when they are next reproduced on the display device (D1, D2).