Secure User Interface Isolation in Trusted Execution Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing reliance on digital payment transactions exposes users to vulnerabilities in computing devices, as sensitive data can be compromised through hacking or malware, especially when entered into non-secure execution environments, risking fraud and data exposure.

Innovation Solution

Implementing a secure user interface in a trusted execution environment that takes ownership of display and data input devices, isolating them from the normal execution environment to protect sensitive data, and generating a combined display that includes secure and non-secure elements, ensuring secure data entry while maintaining user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure user interface is implemented in a trusted execution environment with ownership of display and data input devices, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidexecution environment structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the execution environment into distinct secure and non-secure portions, with the trusted execution environment (TEE) handling sensitive operations separately from the normal execution environment. This segmentation isolates sensitive data processing from potential security threats while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure user interface as an intermediary layer between the user and the application. This secure UI acts as a mediator that handles sensitive data input and display operations through the TEE, preventing direct access to sensitive data by applications running in the non-secure environment while still enabling user interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If sensitive data is processed in a secure execution environment, then vulnerability to hacking and malware is reduced, but user interface integration becomes more complex

Engineering Contradiction:
Improvevulnerability to hacking and malwareVSAvoidinterface integration
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges the secure user interface and the non-secure application interface into a unified user experience. The secure UI elements (such as sensitive input fields and security-critical controls) are integrated with the application's regular UI, creating a seamless interface that appears as a single cohesive application to the user while maintaining security boundaries.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If ownership of data input devices is assigned to the secure execution environment, then sensitive data protection is enhanced, but system operation complexity increases

Engineering Contradiction:
Improvesensitive data protectionVSAvoiddevice ownership management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system dynamically assigns ownership of data input devices to the appropriate execution environment based on the context of the operation. When sensitive data input is required, the secure UI temporarily gains ownership of the input device; when processing non-sensitive operations, ownership reverts to the application. This dynamic ownership management enables flexible security control without requiring permanent device partitioning.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12112321B2Systems and methods for implementing a secure user interface
Publication Date: 2024.10.08 QUALCOMM INC
  • US12112321B2 patent drawing
  • US12112321B2 patent drawing
  • US12112321B2 patent drawing

AI summary

Various embodiments include methods and devices for implementing a secure user interface. The method may include generating a secure user interface display in a secure execution environment, generating a non-secure display in a normal execution environment, combining the secure user interface and the non-secure display into a combined display, and presenting the combined display via a display device.