Application Manager for Third-Party Interface Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Providers face security risks and management challenges when embedding third-party applications, as they have limited control over the output and managing these applications can be difficult and expensive.

Innovation Solution

Implementing a system that utilizes source interface data to provide a user interface for networked resources, where a provider can receive user requests, make service calls to associated applications, and render target interface data based on response data, policy, and additional provider data, while using an application manager to verify and process data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party applications are embedded to provide additional functionality, then service versatility is improved, but security risk increases

Engineering Contradiction:
Improveservice functionalityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an application manager as an intermediary component that sits between the embedded third-party applications and the provider's system. This manager verifies application source data, validates interface definitions, and controls the interaction between external applications and the provider's resources, thereby enabling functionality expansion while mitigating security risks through structured mediation and verification processes

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If embedded applications are used to extend capabilities, then service value is improved, but control over output is reduced

Engineering Contradiction:
Improveservice capabilityVSAvoidoutput control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary verification of application source data and interface definitions before the applications are allowed to execute. The application manager validates the interface definitions against the verified application source data in advance, ensuring that only approved and controlled interfaces can be used. This preliminary action establishes control boundaries before the applications produce output, maintaining reliability while enabling extended capabilities

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If multiple third-party applications are deployed, then functionality is improved, but management complexity increases

Engineering Contradiction:
Improveapplication functionalityVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates a universal application manager that handles multiple third-party applications through a single, standardized interface and verification process. This manager provides multi-functional capabilities including verification, validation, and control for diverse applications, thereby reducing management complexity by consolidating what would otherwise require multiple separate management mechanisms into one unified system

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10015240B2Method and system for interface data utilization
Publication Date: 2018.07.03 PAYPAL INC
  • US10015240B2 patent drawing
  • US10015240B2 patent drawing
  • US10015240B2 patent drawing

AI summary

Methods and systems for interface data utilization are described. In one embodiment, a provider server may offer resources and an application server may offer functionality not provided by the resources of the provider server. A user request may be received through the source user interface. A determination may be made whether the user request contains a request to access a functionality that is not offered by the provider but is offered by an application that is communicatively coupled to the provider via a network. In response, an electronic communication may be established between the provider and the application via a network. A policy of the provider may be accessed from a first database, and interface definition data may be accessed from a second database different from the first database. Target interface data may be rendered based on the policy of the provider and the interface definition data.