CA2481040C

Providing secure input and output to a trusted agent in a system with a high-assurance execution environment

Abstract

Techniques are disclosed to provide security for user output and input in which a first, host operating system is used along with a second, high assurance operating system (nexus), where the first system provides at least some of the infrastructure for the second system. A trusted UI engine has a trusted input manager and a trusted output manager. The trusted input manager controls access to trusted input, distributing decrypted input to the host operating system where appropriate, or to the appropriate process running in the nexus. The trusted output manager manages output to the display, and allows trusted agents in the nexus to output data for display without needing to be aware of output-device- dependent details.

CA2481040C, drawing sheet 1
Sheet 1 of 8

Term

Term ended

Expired 9 September 2024, 2 years ago.

  1. Priority
  2. Filed
  3. Granted
  4. Expired
  5. Today

17 claims: 11 independent, 6 dependent

  1. 1
    CA 02481040 2011-05-17 51050-64 CLAIMS:1. A method for providing a secure user interface to a secured execution environment on a system comprising said secured execution environment and a second execution environment, the second execution environment acting as a host for the secured execution environment, the method comprising the steps of: accepting encrypted user input from a user input device intended for either said secured execution environment or said second execution environment;decrypting said encrypted user input in the secured execution environment;determining a graphical user element that has focus from among at least one graphical user elements;determining whether a process that owns the graphical user element is in the secured execution environment or in the second execution environment;determining, based on whether the process that owns the graphical user element is in the secured execution environment or in the second execution environment, whether said decrypted user input is intended for said secured execution environment;if said decrypted user input is not intended for said secured execution environment, transferring said decrypted user input to said second execution environment;if said decrypted user input is intended for said secured execution environment, determining a specific destination entity within said secured execution environment for said decrypted user input, and transferring said decrypted user input to said specific destination entity;accepting output from a specific source entity within said secured execution environment and not within said second execution environment;and securely transferring said output to an output device. CA 02481040 2011-05-17 51050-64
  2. 4
    The method of any one of claims 1 to 3, wherein said transferring said decrypted user input to said specific destination entity comprises:interpreting said decrypted user input.
  3. 5
    The method of any one of claims 1 to 4, wherein said securely transferring said output to said output device comprises:encrypting said output data.
  4. 6
    The method of any one of claims 1 to 4, wherein said securely transferring said output to said output device comprises:transferring said output to a curtained memory.
  5. 7
    The method of any one of claims 1 to 4, wherein said output contains a data portion, and wherein said securely transferring said output to said output device comprises:encrypting said data portion of said output.
  6. 8
    A computer-readable storage medium containing computer executable instructions to provide a secure user interface to a secured execution environment on a system comprising said secured execution environment and a second execution environment, the second execution environment acting as a host for the secured execution environment, the computer-executable instructions to perform acts comprising:accepting encrypted user input from a user input device intended for either said secured execution environment or said second execution environment;decrypting said encrypted user input in the secured execution environment;CA 02481040 2011-05-17 51050-64 determining a graphical user element that has focus from among at least one graphical user elements;determining whether a process that owns the graphical user element is in the secured execution environment or in the second execution environment;determining, based on whether the process that owns the graphical user element is in the secured execution environment or in the second execution environment, whether said decrypted user input is intended for said secured execution environment;if said decrypted user input is not intended for said secured execution environment, transferring said decrypted user input to said second execution environment;if said decrypted user input is intended for said secured execution environment, determining a specific destination entity within said secured execution environment for said decrypted user input, and transferring said decrypted user input to said specific destination entity;accepting output from a specific source entity within said secured execution environment and not within said second execution environment;and securely transferring said output to an output device.
  7. 11
    12. The computer-readable storage medium of any one of claims 8 to 11, wherein said output contains a data portion, and wherein said securely transferring said output to said output device comprises:encrypting said data portion of said output.
  8. 12
    13. The computer-readable storage medium of any one of claims 8 to 11, wherein said securely transferring said output to said output device comprises:transferring said output to a curtained memory.
  9. 13
    14. A trusted user interface engine for providing a secure user interface to a secured execution environment on a system comprising said secured execution environment and a second execution environment, the second execution environment acting as a host for the secured execution environment, the trusted user interface engine comprising:an input trusted service provider in the secured execution environment accepting encrypted user input from a user input device and decrypting said encrypted user input, operably connected to said user device;a trusted input manager for determining a graphical user element that has focus from among at least one graphical user elements, determining whether a process that owns the graphical user element is in the secured execution environment or in the second execution environment, and, determining, based on whether the process that owns the graphical user element is in the secured execution environment or in the second execution environment, whether said decrypted user input is intended for said secured execution environment and, if said decrypted user input is not intended for said secured execution environment, transferring said decrypted user input to said second execution environment, and if said decrypted user input is intended for said secured execution environment, determining a specific destination entity within said secured execution environment for said decrypted user input, and transferring said decrypted user input to said specific destination entity;CA 02481040 2011-05-17 51050-64 and a trusted output manager for accepting output from a specific source entity within said secured execution environment and not within said second execution environment and securely transferring said output to an output device.
  10. 16
    17. The trusted user interface engine of any one of claims 14 to 16, wherein 10 said output contains a data portion, and wherein said trusted output manager encrypts said data portion of said output.
  11. 17
    18. The trusted user interface engine of any one of claims 14 to 16, wherein said trusted output manager transfers said output to a curtained memory.