Authentication Agent for Secure Sensitive Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face challenges in accessing sensitive work-related content on portable devices due to security limitations in browser applications, which can restrict access or require inconvenient software usage.

Innovation Solution

Implementing a separate authentication agent on the client device that manages sensitive data securely, allowing it to be stored in a secure location inaccessible to unsecure applications, while enabling access to restricted content through a conventional browser by rendering content remotely and transmitting only image data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive content is accessed through conventional browsers on portable devices, then user convenience is improved, but security is compromised due to browser limitations

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the access process into two distinct components: a conventional browser for user interaction and an authentication agent for security management. The browser handles user convenience while the agent enforces security policies, allowing both requirements to be satisfied simultaneously through functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication agent acts as an intermediary between the user/browser and the sensitive content. It mediates all access requests by verifying credentials and enforcing security policies, allowing the browser to remain simple and convenient while the agent ensures security requirements are met.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If specific security software is required to access sensitive content, then security is improved, but user convenience deteriorates due to restrictive usage requirements

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication agent provides universal security functionality that works across multiple browser applications and devices. Instead of requiring specific security software, the agent implements a standardized authentication mechanism that can be accessed through any conventional browser, making the security solution both secure and convenient.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If authentication credentials are stored in the browser, then access is simplified, but security is compromised as credentials become accessible to unsecure applications

Engineering Contradiction:
Improveaccess simplicityVSAvoidcredential exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The authentication credentials are extracted from the browser environment and stored separately in a secure location managed by the authentication agent. This separation removes the harmful factor of credential exposure while maintaining the benefit of simplified access through the agent's secure management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The authentication agent serves as an intermediary that manages credential storage and retrieval securely. Credentials are stored in a protected location inaccessible to the browser, and the agent mediates access by providing credentials only when authentication is verified, preventing exposure while enabling access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11233776B1Providing content including sensitive data
Publication Date: 2022.01.25 AMAZON TECH INC
  • US11233776B1 patent drawing
  • US11233776B1 patent drawing
  • US11233776B1 patent drawing

AI summary

An agent can be installed that is separate from an unsecure application, such as a third party browser, executing on a client device. Content to be displayed by, or accessible to, the application can be rendered or determined remotely, such that only unrestricted data is received by the application. Restricted data to be stored on the device, as may include one or more authentication credentials, can be transmitted over a secure connection to the agent, which can store the sensitive information to a secure location on the client device that is inaccessible to the application. Such management allows the sensitive information to be stored on the client device and provided with requests for restricted data, for example, while preventing the restricted data from being exposed to the application on the client device.