Trusted Zone Data Word Visual Indicator for Secure Application Recognition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing devices lack a secure method to visually or audibly indicate the operating state of secure applications running in a trustworthy area, making it difficult for users to distinguish between secure and insecure applications.

Innovation Solution

A data processing device and method that outputs a user-defined data word, which can be visual, audio-visual, or a combination of graphics and numbers, to indicate the execution of secure applications in the trustworthy area, allowing users to recognize the operating state and preventing manipulation by insecure applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure applications are executed in a trustworthy area without visual indication, then security is maintained, but users cannot recognize the operating state or distinguish secure from insecure applications

Engineering Contradiction:
ImprovesecurityVSAvoiduser recognition of operating state
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent uses visual indicators (color changes, graphical representations) to display the operating state of the device. When a secure application is executed in the trustworthy area, a specific visual indicator is shown to the user, allowing immediate recognition of the secure operating state without compromising security.

Inventive Principle:
Principle #32Color changes

Solution Approach 2:

The patent introduces an intermediary visual indication layer between the secure application execution and user perception. This intermediary provides information about the operating state through displayed indicators while maintaining the security boundary, allowing users to recognize secure mode without exposing sensitive data or system internals.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Difficulty of detecting and measuring

If visual indicators are displayed to show secure application execution, then user recognition is improved, but the device complexity increases

Engineering Contradiction:
Improveuser recognition of operating stateVSAvoidsystem structure
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The visual indication mechanism serves multiple functions: it indicates secure operating state, provides user feedback, and maintains security context. By making the indication system multi-functional, the patent reduces the need for separate dedicated components for each function, thereby limiting the increase in device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If a data word is displayed to identify secure applications, then ease of operation is improved, but security risks increase if the data word is compromised

Engineering Contradiction:
Improveuser identification of secure applicationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary verification and establishes the secure context before displaying the data word indicator. The visual indication is only shown after confirming that a secure application is actually executing in the trustworthy area, preventing misleading indicators that could compromise security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the visual indicator is dynamically updated based on the actual execution state. The indicator is shown only when a secure application is confirmed to be running and is hidden or changed when insecure applications execute, providing accurate real-time feedback without creating security vulnerabilities.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2210241B1Data processing device and method for operating a data processing device
Publication Date: 2011.12.28 GIESECKEDEVRIENT IP
  • EP2210241B1 patent drawingFigure 1~2

AI summary

The invention describes a data processing device (1), which has a trusted zone area (2) and a non-trusted zone (3). For a secure application (5, 7), which is executed in the trusted zone (2), a data word (6, 8), which is established by a user of the device and stored in the device (1), can be output.