Auxiliary Code Injection for Security Rule Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users often struggle to adhere to computer-usage rules, such as avoiding phishing websites or sharing sensitive information, due to lack of awareness or oversight.

Innovation Solution

A system that augments third-party code with auxiliary code to enforce computer-usage rules, including prompting users for input, using machine-learned algorithms, and modifying webpages or emails to prevent rule violations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If auxiliary code is injected into third-party code to enforce computer-usage rules, then security compliance is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity complianceVSAvoidcode complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary security system that acts as a mediator between users and third-party code. The auxiliary code injected into third-party applications serves as an intermediary layer that monitors and controls user actions, enforcing security rules without requiring changes to the core third-party code. This intermediary mechanism resolves the contradiction by providing security enforcement while maintaining the independence and complexity of the original third-party systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If real-time monitoring and user prompting are implemented to enforce rules, then information security is improved, but loss of time increases

Engineering Contradiction:
Improveinformation securityVSAvoiduser interaction time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-configuring security rules and policies before user interactions occur. The auxiliary code is injected in advance, and security constraints are established beforehand. When users attempt actions, the system checks against pre-defined rules rather than creating and evaluating policies in real-time, significantly reducing the time loss while maintaining strong security enforcement.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If machine-learned algorithms are used to process user input, then enforcement accuracy is improved, but use of energy increases

Engineering Contradiction:
Improveenforcement accuracyVSAvoidcomputational energy
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The system applies partial machine learning processing only when necessary - specifically when user input requires complex evaluation beyond simple rule matching. For straightforward security violations, basic rule-based enforcement is used. For ambiguous cases requiring nuanced judgment, the machine-learned algorithm is selectively engaged, optimizing energy consumption while maintaining high enforcement accuracy for critical decisions.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12277209B2Interactive security orchestration
Publication Date: 2025.04.15 SAILPOINT TECHNOLOGIES INC
  • US12277209B2 patent drawing
  • US12277209B2 patent drawing
  • US12277209B2 patent drawing

AI summary

A method includes providing auxiliary code implementing a process for facilitating enforcement of one or more computer-usage rules, and augmenting third-party code with the auxiliary code such that execution of the third-party code carries out the process. Other embodiments are also described.