Authenticator Embedded Browser Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current web browser security and authentication systems are user-unfriendly and vulnerable to security risks, as users lack the expertise to manage certificates and passwords effectively, leading to potential attacks and increased complexity in managing multiple accounts.

Innovation Solution

A system comprising a client part with an authenticator, embedded browser, and data channel module, which communicates with a server part to authenticate users, manage certificates, and securely transmit data, using cryptographic protocols to ensure secure communication and simplify user interactions across multiple service providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users manually manage certificates and passwords themselves, then users have control over their security settings, but security risks increase due to lack of user expertise and ability to distinguish genuine certificates from faked ones

Engineering Contradiction:
ImproveUser control over security settingsVSAvoidSecurity against fake certificates
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a server system that acts as an intermediary between users and certificates. The server receives certificates, verifies their authenticity, and returns verification results to users. This mediator handles the complex security verification process that users cannot perform themselves, eliminating the risk of users being deceived by fake certificates while maintaining user control over which certificates to verify.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables users to independently verify certificate authenticity through a simple interface without requiring expert knowledge. Users can upload certificates to the server and receive automatic verification results, allowing them to self-service their security needs without needing to understand complex cryptographic validation processes.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If users manage multiple passwords for dozens to hundreds of websites, then users can access multiple service providers, but the complexity of password management becomes almost impossible and security risks increase

Engineering Contradiction:
ImproveAccess to multiple service providersVSAvoidPassword management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal password management system where a single master password protects all other passwords stored in the encrypted database. The system can manage multiple service provider credentials through one unified interface, allowing users to access dozens of websites while dealing with only one password that needs memorization. The system handles password generation, storage, and retrieval across multiple service providers through a single application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system creates encrypted copies of passwords and stores them in a secure database. Instead of users needing to remember multiple passwords, the system stores encrypted copies and retrieves them when needed. The authenticator application maintains copies of credential information that can be automatically filled into web forms, eliminating the need for users to manually manage multiple passwords.

Inventive Principle:
Principle #26Copying

3Ease of operation

If browsers provide specialized functionalities and extensions, then user experience is improved, but security vulnerabilities increase as extensions may no longer be supported after browser updates

Engineering Contradiction:
ImproveUser experience with web applicationsVSAvoidSecurity support after browser updates
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the password management and certificate verification functionalities from the browser environment into a standalone authenticator application. This extracted system operates independently of browser updates and extensions, maintaining consistent security functionality across different browser versions. The authenticator application handles authentication tasks that would otherwise require browser extensions, removing the dependency on browser-specific add-ons.

Inventive Principle:
Principle #2Taking out (Extraction)

4Ease of manufacture

If green certificates are used to mark genuine certificates, then users receive clear security signals, but attackers can forge fake certificates that also appear green, creating security risks

Engineering Contradiction:
ImproveImplementation of certificate markingVSAvoidSecurity risk from forged certificates
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a server as an intermediary that performs the actual certificate verification. Instead of relying on browser-generated green markers that can be forged, the system sends certificates to the server for verification and displays results based on the server's authentication. This intermediary process ensures that only genuinely verified certificates are accepted, eliminating the vulnerability to forged green certificates.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250005120A1System and method for controlling access to target application
Publication Date: 2025.01.02 ADUCID
  • US20250005120A1 patent drawing

AI summary

A system and method are described for controlling access of a user to service providers and/or to target applications, in particular web or mobile applications. The system contains a client part and a server part. The client part contains an authenticator, an embedded browser and a data channel module. The authenticator is configured to authenticate the user. The authenticator is also configured to communicate with the user via a graphical user interface of the embedded browser using graphical and control primitives of the authenticator and/or using a stand-alone graphical user interface of the authenticator. The data channel module is configured to communicate with service provider servers via http/https protocol to communicate with the embedded browser and to communicate with the authenticator. The client part further contains a program memory, a variables memory and a control module configured to control the execution of programs stored in the program memory.