Monitoring for interception of image display pipeline and indicating to user
This disclosure provides systems, devices, apparatus, and methods, including computer programs encoded on storage media, for monitoring interception of an image display pipeline and indicating a determined interception to a user. A display processor may detect that at least one application is activated based on one or more CRC values that correspond to the at least one application. The display processor may generate a UI indication for the at least one application based on detecting that the at least one application is activated and transmit, based on generating the UI indication, at least one UI layer. The at least one UI layer may correspond to the UI indication for the at least one application.
1 . An apparatus for display processing at a device, comprising:
memory; and
at least one processor coupled to the memory and configured to:
configure, in a secure mode or a protected mode, one or more CRC registers for storing a first set of CRC values that correspond to at least one application;
store the first set of CRC values in the configured one or more CRC registers;
receive an indication that the at least one application is in an activated state as executed by a processor of an operating system (OS), wherein the indication is associated with a first set of cyclic redundancy check (CRC) values that correspond to the at least one application;
generate, after storage of the first set of CRC values in the configured one or more CRC registers, a user interface (UI) indication for the at least one application based on the received indication that the at least one application is in the activated state;
transmit, based on the generated UI indication, at least one UI layer corresponding to the generated UI indication for the at least one application; and
detect a security breach of the at least one application based on a mismatch between a second set of CRC values determined based on the transmitted at least one UI layer and the configured one or more CRC registers that store the first set of CRC values in the secure mode or the protected mode.
2 . The apparatus of claim 1 , wherein the at least one processor is further configured to:
transmit, based on the detected security breach, an indication of the detected security breach.
3 . The apparatus of claim 1 , wherein the second set of CRC values are associated with a region of interest (ROI) at the device.
4 . The apparatus of claim 1 , wherein the at least one processor is further configured to:
disable the at least one application based on the detected security breach; and
maintain the at least one application in a deactivated state.
5 . The apparatus of claim 1 , wherein the indication that the at least one application is in the activated state indicates that at least one camera application is in the activated state, wherein, to receive the indication that the at least one application is in the activated state as executed by the processor of the OS, the at least one processor is configured to:
receive a signal indicative of a camera sensor initiation.
6 . The apparatus of claim 1 , wherein to generate the UI indication, the at least one processor is configured to:
generate the UI indication via the secure mode or secure rendering.
7 . The apparatus of claim 1 , wherein, to detect the security breach of the at least one application based on the mismatch between the second set of CRC values determined based on the transmitted at least one UI layer and the first set of CRC values that correspond to the at least one application, the at least one processor is configured to:
determine the second set of CRC values based on a UI frame buffer associated with a display at the device.
8 . The apparatus of claim 7 , wherein, to transmit the at least one UI layer, the at least one processor is configured to:
transmit, to the UI frame buffer associated with the display at the device, the at least one UI layer.
9 . The apparatus of claim 1 , wherein the at least one processor is further configured to:
display the at least one UI layer after the generation of the UI indication, wherein the UI indication comprises an icon or a preview layer.
10 . The apparatus of claim 2 , wherein the at least one processor is further configured to:
disable the at least one application based on the transmitted indication of the detected security breach.
11 . The apparatus of claim 10 , wherein to disable the at least one application, the at least one processor is configured to:
automatically disable the at least one application to a deactivated state; or
disable the at least one application to the deactivated state via a user of the device.
12 . The apparatus of claim 1 , wherein the at least one processor is further configured to:
periodically determine the second set of CRC values based on the transmitted at least one UI layer.
13 . The apparatus of claim 1 , wherein the apparatus comprises a wireless communication device.
14 . A method of display processing at a device, comprising:
configuring, in a secure mode or a protected mode, one or more CRC registers for storing a first set of CRC values that correspond to at least one application;
storing the first set of CRC values in the configured one or more CRC registers;
receiving an indication that the at least one application is in an activated state as executed by a processor of an operating system (OS), wherein the indication is associated with a first set of cyclic redundancy check (CRC) values that correspond to the at least one application;
generating, after storage of the first set of CRC values in the configured one or more CRC registers, a user interface (UI) indication for the at least one application based on the received indication that the at least one application is in the activated state;
transmitting, based on the generated UI indication, at least one UI layer corresponding to the generated UI indication for the at least one application; and
detecting a security breach of the at least one application based on a mismatch between a second set of CRC values determined based on the transmitted at least one UI layer and the configured one or more CRC registers that store the first set of CRC values in the secure mode or the protected mode.
15 . The method of claim 14 , further comprising:
transmitting, based on the detected security breach, an indication of the detected security breach.
16 . The method of claim 14 , wherein the second set of CRC values are associated with a region of interest (ROI) at the device.
17 . The method of claim 14 , further comprising:
disabling the at least one application based on the detected security breach; and
maintaining the at least one application in a deactivated state.
18 . The method of claim 14 , wherein the indication that the at least one application is in the activated state indicates that at least one camera application is in the activated state, wherein receiving the indication that the at least one application is in the activated state as executed by the processor of the OS comprises:
receiving a signal indicative of a camera sensor initiation.
19 . The method of claim 14 , further comprising:
generating the UI indication via secure mode or secure rendering.
20 . The method of claim 14 , wherein detecting the security breach of the at least one application based on the mismatch between the second set of CRC values determined based on the transmitted at least one UI layer and the first set of CRC values that correspond to the at least one application comprises:
determining the second set of CRC values based on a UI frame buffer associated with a display at the device.
21 . The method of claim 20 , wherein transmitting the at least one UI layer comprises:
transmitting, to the UI frame buffer associated with the display at the device, the at least one UI layer.
22 . The method of claim 14 , further comprising:
displaying the at least one UI layer after the generation of the UI indication, wherein the UI indication comprises an icon or a preview layer.
23 . The method of claim 14 , further comprising:
disabling the at least one application based on the transmitted indication of the detected security breach.
24 . The method of claim 23 , further comprising:
automatically disabling the at least one application to a deactivated state; or
disabling the at least one application to the deactivated state via a user of the device.
25 . The method of claim 14 , further comprising:
periodically determining the second set of CRC values based on the transmitted at least one UI layer.
26 . A non-transitory computer-readable medium storing computer executable code, the code when executed by at least one processor, causes the at least one processor to:
configure, in a secure mode or a protected mode, one or more CRC registers for storing a first set of CRC values that correspond to at least one application;
store the first set of CRC values in the configured one or more CRC registers;
receive an indication that the at least one application is in an activated state as executed by a processor of an operating system (OS), wherein the indication is associated with a first set of cyclic redundancy check (CRC) values that correspond to the at least one application;
generate, after storage of the first set of CRC values in the configured one or more CRC registers, a user interface (UI) indication for the at least one application based on the received indication that the at least one application is in the activated state;
transmit, based on the generated UI indication, at least one UI layer corresponding to the generated UI indication for the at least one application; and
detect a security breach of the at least one application based on a mismatch between a second set of CRC values determined based on the transmitted at least one UI layer and the configured one or more CRC registers that store the first set of CRC values in the secure mode or the protected mode.