IP Library › Granted Patent US 9,177,353
Granted Patent B2
US 9,177,353 · App. 13/832,435 · Granted Nov 3, 2015

Secure rendering of display surfaces

Inventors: Siddhartha Chhabra (Hillsboro, OR); Uday R. Savagaonkar (Portland, OR); Prashant Dewan (Hillsboro, OR); Michael A. Goldsmith (Lake Oswego, OR); David M. Durham (Beaverton, OR)
Assignee: Intel Corporation
G06T1/60G06F3/147G06F21/84H04N21/42653H04N21/4318H04N21/4367H04N21/44004H04N21/4408G09G2358/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,177,353
App. No.
13/832,435
Granted
Nov 3, 2015
Kind
B2
Abstract

A protected graphics module can send its output to a display engine securely. Secure communications with the display can provide a level of confidentiality of content generated by protected graphics modules against software and hardware attacks.

Claims (37)

1. A method comprising:

sending an output from a protected graphics module to a display engine, wherein said module is part of a graphics processor, said module to assert correctness of execution to a remote party, and said module only executable on said graphics processing unit;

displaying the output on a display screen using the display engine; and

enabling the display engine to enter the protected graphics module.

2. The method of claim 1 including linking a display surface to a secure surface binding table.

3. The method of claim 2 including blocking reads from the display surface.

4. The method of claim 3 including encrypting writes to the display surface using a key associated with the current display context.

5. The method of claim 1 including using a protected graphics entry surface to display a surface.

6. The method of claim 1 including using the protected graphics entry surface to provide a way to access the surface.

7. The method of claim 6 including providing a way to access the surface residing in an enclave page cache.

8. The method of claim 7 including providing a way to access the surface in the enclave page cache using the protected graphics entry structure.

9. The method of claim 8 including decrementing an expiry counter in the protected graphics entry structure on a refresh cycle.

10. One or more non-transitory computer readable media storing instructions executed by a processor to perform a sequence comprising:

providing a secure output from a protected graphics module to a display engine, wherein said module is part of a graphics processor, said module to assert correctness of execution to a remote party, and said module only executable on said graphics processing unit;

displaying the output on a display screen using the display engine and;

enabling the display engine to enter the protected graphics module.

11. The media of claim 10 , said sequence including linking a display surface to a secure surface binding table.

12. The media of claim 11 , said sequence including blocking reads from the display surface.

13. The media of claim 12 , said sequence including encrypting writes to the display surface using a key associated with the current display context.

14. The media of claim 10 , said sequence including using a protected graphics entry surface to display a surface.

15. The media of claim 14 , said sequence including enabling a display engine to enter a protected graphics module.

16. The media of claim 15 , said sequence including using the protected graphics entry surface to provide a way to access the surface.

17. The media of claim 16 , said sequence including providing a way to access the surface residing in an enclave page cache.

18. The media of claim 17 , said sequence including providing a way to access the surface in the enclave page cache using the protected graphics entry structure.

19. The media of claim 18 , said sequence including decrementing an expiry counter in the protected graphics entry structure on a refresh cycle.

20. An apparatus comprising:

a storage: and

a processor, coupled to the storage, to provide a secure output of a protected graphics module for display on a display screen, using a display engine, wherein said module is part of a graphics processor, said module to assert correctness of execution to a remote party, and said module only executable on said graphics processing unit, to said display engine to enter the protected graphics module.

21. The apparatus of claim 20 , said processor to link a display surface to a secure surface binding table.

22. The apparatus of claim 21 , said processor to block reads from the display surface.

23. The apparatus of claim 22 , said processor to encrypt writes to the display surface using a key associated with the current display context.

24. The apparatus of claim 20 , said processor to use a protected graphics entry surface to display a surface.

25. The apparatus of claim 24 , said processor to enable a display engine to enter a protected graphics module.

26. The apparatus of claim 25 , said processor to use the protected graphics entry surface to provide a way to access the surface.

27. The apparatus of claim 20 including an operating system.

28. The apparatus of claim 20 including a battery.

29. The apparatus of claim 20 including firmware and a module to update said firmware.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 15, 2013
From: CHHABRA, SIDDHARTHA; DURHAM, DAVID M.; DEWAN, PRASHANT; GOLDSMITH, MICHAEL A.; SAVAGAONKAR, UDAY R.
To: INTEL CORPORATION
Reel/Frame 030009/0535 →
Continuity (1)
Related Publication 20140267332A1 · Sep 18, 2014