The way I would implement it is that the keyboard has a switch to enable this SSL type communication. Then the keyboard can perform a Diffie–Hellman key exchange with the current process. As a result any other interaction with the OS would become impossible until that process is terminated - basically disabling all OS related shortcuts etc. This would allow true end to end encryption - even on compromised systems (as long as the kernel code isn't modified to allow accessing the memory of other processes).