IP Library › Granted Patent US 10,769,312
Granted Patent B2
US 10,769,312 · App. 15/752,450 · Granted Sep 8, 2020

Method and apparatus for trusted display on untrusted computing platforms to secure applications

Inventors: Virgil D. Gligor (Pittsburgh, PA); Zongwei Zhou (Mountain View, CA); Miao Yu (Pittsburgh, PA)
Assignee: CARNEGIE MELLON UNIVERSITY
G06F21/84G06F9/45508G06F9/45558G06F21/53G06F21/57G06F21/62G06F21/70G06F21/71G06F2221/2141G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,769,312
App. No.
15/752,450
Granted
Sep 8, 2020
Kind
B2
Abstract

This invention provides a method for providing trusted display to security sensitive applications on untrusted computing platforms. This invention has a minimal trusted code base and maintains full compatibility with the computing platforms, including their software and hardware. The core of our invention is a GPU separation kernel that (1) defines different types of GPU objects, (2) mediates access to security-sensitive GPU objects, and (3) emulates accesses to security-sensitive GPU objects whenever required by computing platform compatibility.

Claims (24)

1. A system for providing a trusted display for secure applications on an untrusted computing platform, comprising:

one or more graphics processing units (GPU) driving one or more display monitors, each GPU defining a plurality of GPU objects; and

a GPU separation kernel (GSK) performing the functions of

determining which of said plurality of GPU objects are security-sensitive;

mediating access to the security-sensitive objects issued by the secure applications and non-secure operating systems and applications;

emulating accesses to a subset of the security-sensitive objects for the non-secure operating systems and applications.

2. The system of claim 1 where the one or more GPUs are concurrently accessed by both secure applications and the non-secure operating systems and applications.

3. The system of claim 1 further comprising a trusted computing base on which said GSK can execute.

4. The system of claim 1 wherein said GSK further comprises:

an access mediation component;

an access emulation component; and

a screen overlay component.

5. The system of claim 4 wherein said access mediation component mediates accesses to the security-sensitive GPU objects by enforcing a set of access invariants.

6. The system of claim 5 wherein said access emulation component maintains object-code compatibility with said computing platform by emulating expected returns from accesses to GPU objects.

7. The system of claim 6 wherein said returns are emulated when untrusted components access the security-sensitive GPU objects shared by the unsecure operating systems and applications and the GSK and the secure applications or when untrusted components access said security-sensitive GPU objects in violation of said access invariants.

8. The system of claim 4 wherein the screen overlay component displays output of secured applications over that of unsecured OS and applications.

9. The system of claim 3 wherein said trusted computing base is implemented as a micro-hypervisor.

10. The system of claim 9 further comprising:

a trusted display extension of said micro-hypervisor; and

a trusted display kernel component.

11. The system of claim 10 wherein said trusted display extension notifies said trusted display kernel component about requests from untrusted components to access the security-sensitive GPU objects.

12. The system of claim 11 wherein said trusted display kernel component provides trusted display services to said secure applications.

13. The system of claim 12 wherein said trusted display kernel component mediates access to the security-sensitive GPU objects by enforcing a set of access invariants.

14. The system of claim 13 wherein said trusted display kernel component emulates expected returns from accesses to GPU objects when the non-secure operating systems and applications access the security-sensitive GPU objects or access the security-sensitive GPU objects in violation of said access invariants.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 18, 2018
From: GLIGOR, VIRGIL D.; ZHOU, ZONGWEI; YU, MIAO
To: CARNEGIE MELLON UNIVERSITY
Reel/Frame 045847/0212 →
Continuity (2)
Provisional Application 62284695 · Oct 6, 2015
Related Publication 20190012489A1 · Jan 10, 2019