Secure User Interface Isolation in Trusted Execution Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing reliance on digital payment transactions exposes users to vulnerabilities in computing devices, as sensitive data can be compromised through hacking or malware, especially when entered into non-secure execution environments, risking fraud and data exposure.
Innovation Solution
Implementing a secure user interface in a trusted execution environment that takes ownership of display and data input devices, isolating them from the normal execution environment to protect sensitive data, and generating a combined display that includes secure and non-secure elements, ensuring secure data entry while maintaining user experience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure user interface is implemented in a trusted execution environment with ownership of display and data input devices, then data security is improved, but device complexity increases
Solution Approach 1:
The system divides the execution environment into distinct secure and non-secure portions, with the trusted execution environment (TEE) handling sensitive operations separately from the normal execution environment. This segmentation isolates sensitive data processing from potential security threats while maintaining overall system functionality.
Solution Approach 2:
The patent introduces a secure user interface as an intermediary layer between the user and the application. This secure UI acts as a mediator that handles sensitive data input and display operations through the TEE, preventing direct access to sensitive data by applications running in the non-secure environment while still enabling user interaction.
2Object-affected harmful factors
If sensitive data is processed in a secure execution environment, then vulnerability to hacking and malware is reduced, but user interface integration becomes more complex
Solution Approach 1:
The patent merges the secure user interface and the non-secure application interface into a unified user experience. The secure UI elements (such as sensitive input fields and security-critical controls) are integrated with the application's regular UI, creating a seamless interface that appears as a single cohesive application to the user while maintaining security boundaries.
3Reliability
If ownership of data input devices is assigned to the secure execution environment, then sensitive data protection is enhanced, but system operation complexity increases
Solution Approach 1:
The system dynamically assigns ownership of data input devices to the appropriate execution environment based on the context of the operation. When sensitive data input is required, the secure UI temporarily gains ownership of the input device; when processing non-sensitive operations, ownership reverts to the application. This dynamic ownership management enables flexible security control without requiring permanent device partitioning.
Data Source
AI summary
Various embodiments include methods and devices for implementing a secure user interface. The method may include generating a secure user interface display in a secure execution environment, generating a non-secure display in a normal execution environment, combining the secure user interface and the non-secure display into a combined display, and presenting the combined display via a display device.


