Trusted display and input using screen overlays

Anthony Brandon, Michael P. Trimarchi · 2017

Consumer Operating Systems, such as Android are often used in mobile devices to handle secure information, such as for example logging in to an online banking service. These operating systems are difficult to fully secure, especially because they can run applications outside of the control of the vendor. Certifying such devices is expensive and time consuming. Various software techniques, such as for instance SELinux access policies are used to limit access to secure features for untrusted applications. A different approach is to use a physically separate processor, running a simpler, and therefore easier to verify and certify, OS. This OS can overlay information on the screen, which can never be altered by the untrusted OS. The overlay is created using an FPGA which sits between the processor and display, thereby ensuring that the information is never seen, and cannot be altered, by the untrusted processor.

Read the paper · More papers on PaperTik