EP1526426A2

Providing secure input to a system with a high-security execution environment

Abstract

Techniques are disclosed to provide security for user input in which a first, host operating system is used along with a second, high assurance operating system, where the first system provides at least some of the infrastructure for the second system. Two modes are presented. In a first mode, user data is passed to the host operating system. In a second mode, user data is retained in the second operating system for the use of the second operating system or processes running on the second operating system. Transitions between the nodes can be accomplished according to hypothecated user actions such as keystroke combinations, or when the user performs an action which indicates a programmatic activation of a process running in the second operating system. Where shadow graphical elements are run by the first operating system to indicate the location of graphical elements from processes running on the second operating system, this programmatic activation may be indicated by programmatic activation of a shadow graphical element.

EP1526426A2, drawing sheet 1
Sheet 1 of 6

Term

Term ended

Projected expiry passed 9 September 2024, 2 years ago.

  1. Priority
  2. Filed
  3. Published
  4. Projected expiry
  5. Today

45 claims: 5 independent, 40 dependent

  1. 1
    A method for maintaining the security of a secured execution environment on a system comprising said secured execution environment and a second execution environment, comprising:accepting user input from a trusted input device;determining whether said secured execution environment is in a standard input mode;and if said secured execution environment is in a standard input mode, transferring at least a first portion of said user input to said second execution environment.
  2. 15
    A computer-readable medium containing computer executable instructions to maintain the security of a secured execution environment on a system comprising said secured execution environment and a second execution environment, the computer-executable instructions to perform acts comprising:accepting user input from a trusted input device;determining whether said secured execution environment is in a standard input mode;and if said secured execution environment is in a standard input mode, transferring at least a first portion of said user input to said second execution environment.
  3. 29
    A trusted user interface engine for use in a computer system comprising a secured execution environment and a second execution environment, said trusted user interface engine comprising:an input stack for accepting user input;and a trusted input manager for determining whether said secured execution environment is in a standard input mode;and for directing at least a first portion of said user input to said second execution environment if said secured execution environment is in a standard input mode.
  4. 42
    A method for maintaining the security of a secured execution environment on a system comprising said secured execution environment and a second execution environment, comprising:maintaining a current state for said secured execution environment selected from among a group of possible states comprising: a standard input mode state and a nexus input mode state;directing a flow of user input according to said current state.
  5. 44
    A computer-readable medium containing computer executable instructions to maintain the security of a secured execution environment on a system comprising said secured execution environment and a second execution environment, the computer-executable instructions to perform acts comprising:maintaining a current state for said secured execution environment selected from among a group of possible states comprising: a standard input mode state and a nexus input mode state;directing a flow of user input according to said current state.