Trusted Application Display Buffer Capture for Brand Visibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In a Trusted Execution Environment (TEE), the display of a business's visual identity, such as its name and logo, is often missing when a user interacts with a trusted user interface during transactions, as the Trusted Application provided by a different party, like a payment processor, takes exclusive control of the device display, isolating it from the rich OS environment.
Innovation Solution
A method and apparatus that capture a display buffer from the rich OS environment and pass it to a Trusted Application executed in the TEE, allowing the captured display buffer to be displayed as a background image within the trusted UI, ensuring the business's visual identity remains visible even if the Trusted Application is provided by a different party.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the Trusted Application takes exclusive control of the device display to ensure security isolation, then security protection is improved, but the business's visual identity becomes invisible
Solution Approach 1:
The display is segmented into two independent layers: a trusted UI layer for security-critical information and a background layer for business visual identity. The background image layer displays the business's visual identity captured from the rich OS environment, while the trusted UI layer overlays security elements above it. This segmentation allows both security isolation and brand visibility to coexist without compromising either.
2Reliability
If the Trusted Application isolates itself from the rich OS environment to ensure integrity, then security isolation is improved, but access to display content for branding purposes is lost
Solution Approach 1:
An intermediary mechanism captures the display buffer from the rich OS environment and passes it to the Trusted Application as a background image. This intermediary approach allows the Trusted Application to access visual identity information without breaking security isolation, as the display buffer is captured and rendered as a static background rather than allowing direct interaction with the rich OS display system.
Data Source
AI summary
Aspects of the disclosure are related to a method, apparatus, and system for using display content from a rich operating system (OS) environment as a background image in a trusted user interface (UI), comprising: capturing a display buffer of the rich OS environment; passing the captured display buffer to a Trusted Application; and displaying, with the Trusted Application, the captured display buffer as the background image in the trusted UI, wherein the Trusted Application is executed in a Trusted Execution Environment (TEE).


