EP1526425A2

Providing secure input and output to a trusted agent in a system with a high-assurance execution environment

Abstract

Techniques are disclosed to provide security for user output and input in which a first, host operating system is used along with a second, high assurance operating system (nexus), where the first system provides at least some of the infrastructure for the second system. A trusted UI engine has a trusted input manager and a trusted output manager. The trusted input manager controls access to trusted input, distributing decrypted input to the host operating system where appropriate, or to the appropriate process running in the nexus. The trusted output manager manages output to the display, and allows trusted agents in the nexus to output data for display without needing to be aware of output-device-dependent details.

EP1526425A2, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Projected expiry passed 6 September 2024, 2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

40 claims: 6 independent, 34 dependent

  1. 1
    A method for providing a secure user interface to a secured execution environment on a system comprising said secured execution environment and an second execution environment, comprising:accepting user input from a user input device;determining whether said user input is intended for said secured execution environment;if said user input is not intended for said secured execution environment, transferring said user input to said second execution environment.
  2. 11
    A method for providing a secure user interface to a secured execution environment on a system comprising said secured execution environment and an second execution environment, comprising:accepting output from a specific source entity in said secured execution environment;andsecurely transferring said output to an output device.
  3. 14
    A computer-readable medium containing computer executable instructions to providing a secure user interface to a secured execution environment on a system comprising said secured execution environment and an second execution environment, the computer-executable instructions to perform acts comprising:accepting user input from a user input device;determining whether said user input is intended for said secured execution environment;if said user input is not intended for said secured execution environment, transferring said user input to said second execution environment.
  4. 24
    A computer-readable medium containing computer executable instructions to providing a secure user interface to a secured execution environment on a system comprising said secured execution environment and an second execution environment, the computer-executable instructions to perform acts comprising:accepting output from a specific source entity in said secured execution environment;andsecurely transferring said output to an output device.
  5. 27
    A trusted user interface engine for providing a secure user interface to a secured execution environment on a system comprising said secured execution environment and an second execution environment, comprising:an input trusted service provider accepting user input from a user input device, operably connected to said user device;a trusted input manager for determining whether said user input is intended for said secured execution environment and, if said user input is not intended for said secured execution environment, transferring said user input to said second execution environment.
  6. 37
    A trusted user interface engine for providing a secure user interface to a secured execution environment on a system comprising said secured execution environment and an second execution environment, comprising:a trusted output manager that accepts output from a specific source entity in said secured execution environment;and that securely transfers said output to an output device.