US2014101782A1PendingUtilityA1

Digital video guard

Assignee: COMMW OF AUSTRALIAPriority: Dec 24, 2008Filed: Sep 30, 2013Published: Apr 10, 2014
Est. expiryDec 24, 2028(~2.4 yrs left)· nominal 20-yr term from priority
G06F 21/84G06F 21/85H04N 21/4181H04N 21/4367G06F 21/60
46
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

This invention relates to the veracity of information displayed to a user of a computer, and information provided to a computer by human input devices such as mice and keyboards. A digital video guard (DVG) device is a peripheral that is retrofitted to commodity computer devices. The DVG resides in-line with a digital display and enables secure end-to-end interactions between a user and a displayed (usually remote) application. In-band signalling within the digital video stream is used to carry encrypted information from a local or remote source, over untrusted network infrastructure through the digital video guard device to a user. The DVG decrypts and verifies the integrity of the digital video. The integrity of the displayed information is indicated by a trusted LED on the DVG hardware. Portions of the video signal may be designated as trusted, if the received data has been encrypted, signed, or labelled as trustworthy.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A trusted digital display guard for controlling the display of trustworthy and untrustworthy digital display data on a digital display device, comprising:
 a. a digital display data input unit configured to receive untrustworthy digital display data and in-band trustworthy digital data;   b. a trusted digital display output unit configured to output digital display data to the digital display device;   c. a trusted status indicator configured to indicate a trusted indicator state; and   d. a trusted digital processor operatively connected to the digital display data input unit, trusted digital display output unit and trusted status indicator, the trusted digital processor configured to identify untrustworthy digital display data and in-band trustworthy digital data, the trusted digital processor configured to direct to the trusted digital display output unit,
 i. untrustworthy digital display data; or 
 ii. processed trustworthy digital data as trustworthy digital display data and none or some modified untrustworthy digital display data, and 
   the trusted digital processor configured to control the status of the trusted status indicator to the trusted indicator state.   
     
     
         2 . The trusted digital display guard of  claim 1  wherein the trusted digital processor is configured to decrypt trustworthy encrypted digital data. 
     
     
         3 . The trusted digital display guard of  claim 1  wherein the trusted digital processor is configured to verify digital signatures which encapsulate trustworthy digital data. 
     
     
         4 . The trusted digital display guard of  claim 1  further comprising
 e. at least one peripheral interconnect input port, operatively connected to the trusted digital processor, configured to receive an input signal; and 
 f. at least one peripheral interconnect output port, operatively connected to the trusted digital processor, configured to output an output signal. 
 
     
     
         5 . The trusted digital display guard of  claim 4  wherein the trusted digital processor is configured to encrypt the input signal thereby forming the output signal. 
     
     
         6 . The trusted digital display guard of  claim 1  further comprising at least one peripheral interconnect port operatively connected to the trusted digital processor and configured to receive an input signal and output an output signal. 
     
     
         7 . The trusted digital display guard of  claim 1  wherein the trusted digital display output unit outputs digital display data which conforms to a Digital Visual Interface specification. 
     
     
         8 . The trusted digital display guard of  claim 1  wherein at least one of the trusted digital processor, the digital display data input unit, and the trusted digital display output unit, comprises a programmed Application Specific Integrated Circuit, Field Programmable Gate Array, micro-controller or a digital logic device. 
     
     
         9 . The trusted digital display guard of  claim 4  wherein the at least one peripheral interconnect input port is configured to receive the input signal from a human to computer interface device, and the at least one peripheral interconnect output port is configured to output the output signal to a remote computer device via an untrusted connection. 
     
     
         10 . The trusted digital display guard of  claim 9  wherein the trusted digital processor encrypts the input signal from the human to computer interface device. 
     
     
         11 . The trusted digital display guard of  claim 9  wherein the trusted digital processor processes the input signal from the human to computer interface device to form the output signal comprising an in-band data signal. 
     
     
         12 . The trusted digital display guard of  claim 1  wherein the trusted digital processor is configured to process in-band signalling, in-band multiplexing, and tagging of data of received digital display data. 
     
     
         13 . The trusted digital display guard of  claim 1  wherein the trusted digital processor further comprises a digital data store configured to store digital data, and the trusted digital processor is configured to process stored digital data to generate digital display data content which is directed as trustworthy digital display data to the trusted digital display output unit. 
     
     
         14 . The trusted digital display guard according to  claim 1  wherein the trusted status indicator is a light emitting diode which is in the emitting state in response to the trusted indicator state. 
     
     
         15 . The trusted digital display guard of  claim 2  further comprising
 g. a removable media reader, operatively connected to the trusted digital processor, configured to read a removal media, wherein the removable media is configured to store a key for encryption or decryption. 
 
     
     
         16 . The trusted digital display guard of  claim 15  wherein the removable media reader further comprises a trusted processor configured to encrypt or decrypt digital data using the key. 
     
     
         17 . The trusted digital display guard of  claim 15  wherein the removable media is a smartcard. 
     
     
         18 . A trusted digital guard for transferring trustworthy digital data from a trusted server over an untrusted digital data network, comprising
 a. a digital display data input unit configured to receive untrustworthy digital display data and in-band trustworthy digital data from the untrusted digital data network;   b. at least one peripheral interconnect output configured to output trustworthy digital data; and   c. a trusted digital processor operatively connected to the digital display data input unit and the at least one peripheral interconnect output configured to process in-band trustworthy digital data and direct trustworthy digital data to the at least one peripheral interconnect output.   
     
     
         19 . The trusted digital guard of  claim 18  wherein the trusted digital processor is configured to decrypt encrypted trustworthy digital data. 
     
     
         20 . The trusted digital guard of  claim 18  wherein the trusted digital processor is configured to verify a digital signature which encapsulates trustworthy digital data. 
     
     
         21 . The trusted digital guard of  claim 18  further comprising
 d. a removable media reader, operatively connected to the trusted processor, configured to read a removable media, wherein a key for decryption or verification of digital signatures is stored in the removable media. 
 
     
     
         22 . The trusted digital guard of  claim 21  wherein the removable media reader further comprises a trusted processor configured to encrypt and decrypt digital data using the key. 
     
     
         23 . The trusted digital guard of  claim 21  wherein the removable media is a smartcard. 
     
     
         24 . A digital data security method for delivery of trustworthy digital display data from a remote server to a digital display device associated with a computer device over an untrusted digital data network, the method comprising:
 a. forming a security association between an encryption device attached to the remote server and a digital display guard attached to the computer device, utilising bi-directional communication enabled by:
 i, in-band communications within trustworthy digital display data using the encryption device, the trustworthy digital display data for display using the digital display guard, and; 
 ii, trustworthy digital data within peripheral interconnect data provided by the digital display guard provided to the encryption device. 
   b. receiving by the encryption device digital display data from the remote server,   c. encrypting the digital display data in accordance with the security association to create trustworthy digital data,   d. directing the trustworthy digital data over the untrusted digital network to the computer device associated with the digital display device.   e. outputting by the computer device associated with the digital display device, as digital display data, the trustworthy digital data to the digital display device in-band along with none or some untrustworthy digital display data,   f. processing in the digital display guard for the display of trustworthy and untrustworthy data on the digital display device comprising;
 i. receiving at a digital display data input unit untrustworthy digital display data and in-band trustworthy digital data; 
 ii. processing with a trusted digital processor operatively connected to the digital display data input unit, a trusted digital display output unit and a trusted status indicator having a trusted indicator state, to process digital data to identify untrustworthy digital display data and to identify in-band trustworthy digital data; 
 iii. decrypting and processing the in-band trustworthy digital data, and for directing to the trusted digital display output unit,
 a. untrustworthy digital display data; or 
 b. processed trustworthy digital data as trustworthy digital display data and none or some modified untrustworthy digital display data, and controlling the status of the trusted status indicator to the trusted indicator state; and 
 
   g. forwarding human to computer interface device data, from the digital display guard having a peripheral interconnect input port, to the remote server through the encryption device, comprising:
 i. receiving human to computer interface device data at the peripheral interconnect input port operatively connected to the digital display guard, 
 ii. encrypting the human to computer interface device data in accordance with the defined security association to form trustworthy digital data, 
 iii. directing the trustworthy digital data from the digital display guard peripheral interconnect output port to the computer device associated with the digital display device, 
 iv. transferring the trustworthy digital data from the computer device associated with the digital display device to the encryption device attached to the remote server, 
 v. receiving at the encryption device trustworthy digital data, 
 vi. decrypting at the encryption device the trustworthy digital data into human to computer interface device data, and 
 vii. directing the human to computer interface device data to the remote server. 
   
     
     
         25 . A digital data security system for delivery of trustworthy digital display data from a remote server to a digital display device associated with a computer device over an untrusted digital data network, comprising:
 a. an encryption device operatively connected to the remote server for forming a security association between the encryption device and a digital display guard operatively connected to the computer device, utilising bi-directional communication enabled by:
 i, in-band communications within trustworthy digital display data using the encryption device, the trustworthy digital display data for display using the digital display guard, and; 
 ii, trustworthy digital data within peripheral interconnect data provided by the digital display guard provided to the encryption device, whereby the encryption device receives digital display data from the remote server and encrypts the digital display data in accordance with the defined security association to create trustworthy digital data, and directs the trustworthy digital data over the untrusted digital network to the computer device associated with the digital display device; 
   b. the digital display guard operatively connected to the computer device for controlling the display of trustworthy and untrustworthy data on the digital display device associated with the computer device, comprising:
 i. a digital display data input unit for receiving untrustworthy digital display data and in-band trustworthy digital data; 
 ii. a trusted digital display output unit for outputting digital display data to the digital display device; 
 iii. a trusted status indicator having a trusted indicator state; 
 iv. a peripheral interconnect input port for receiving digital data; and 
 v. a trusted digital processor operatively connected to the digital display data input unit, trusted digital display output unit and trusted status indicator, and which processes digital data to identify untrustworthy digital display data and to identify in-band trustworthy digital data and for directing to the trusted digital display output unit,
 1) untrustworthy digital display data; or 
 2) processed trustworthy digital data as trustworthy digital display data and none or some modified untrustworthy digital display data and controlling the status of the trusted status indicator to the trusted indicator state; and 
 
   c. a human to computer interface device for creating computer interface data based on user interaction using the human to computer interface device and forwarding human to computer interface device data from the peripheral interconnect input port to the remote server through the encryption device, wherein the human to computer interface device data is encrypted by the digital display guard in accordance with the defined security association to form trustworthy digital data and directed through the peripheral interconnect output port to the computer device associated with the digital display device for transfer of the trustworthy digital data from the computer device associated with the digital display device to the encryption device attached to the remote server for decryption by the encryption device of the trustworthy digital data into human to computer interface device data, and then directing the human to computer interface device data to the remote server.

Join the waitlist — get patent alerts

Track US2014101782A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.