Browser Extension Credential Evaluation for Enterprise Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprise organizations face risks due to users reusing business credentials for personal purposes, leading to unauthorized access, as existing solutions fail to effectively differentiate between business and personal website access.

Innovation Solution

A browser extension embedded in web browsers performs credential evaluation by generating event records that analyze URLs, credentials, and additional details to determine if they match business or personal designations, triggering mitigating actions when mismatches are detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users reuse business credentials for personal purposes to simplify credential management, then ease of operation improves, but security and policy compliance deteriorate

Engineering Contradiction:
Improvecredential managementVSAvoidsecurity and policy compliance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements real-time feedback by monitoring credential usage through browser extensions, analyzing event records to detect mismatches between credential type and website purpose, and providing immediate notifications to users when business credentials are used for personal purposes, thereby maintaining security awareness while allowing operational flexibility

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces an intermediary credential evaluation system that sits between the user and the website authentication process. This intermediary analyzes credential requests, determines website purpose through URL analysis and machine learning, compares credential designations with website designations, and enforces policy compliance without requiring users to manually manage different credentials for different purposes

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If organizations implement strict credential separation policies to improve security, then reliability improves, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidcredential usage
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically monitoring and enforcing credential policies without requiring user intervention. The browser extension autonomously captures authentication events, analyzes credential usage patterns, determines website purposes, and enforces policy compliance, freeing users from the burden of manually tracking which credentials to use where while maintaining strict security policies

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-establishing credential designations (business vs. personal) and website purpose classifications before authentication occurs. The system pre-configures policy rules and uses machine learning to pre-categorize websites, enabling automatic real-time evaluation and enforcement of credential policies without requiring users to make judgment decisions at the moment of authentication

Inventive Principle:
Principle #10Preliminary action

3Reliability

If organizations manually monitor credential usage to prevent unauthorized access, then security improves, but productivity deteriorates

Engineering Contradiction:
Improveunauthorized access preventionVSAvoiduser and administrator efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces manual mechanical monitoring with an automated electronic system. Browser extensions automatically capture authentication events, machine learning models automatically analyze website purposes, and algorithms automatically compare credential designations with website designations. This substitution eliminates the need for manual review while maintaining comprehensive security monitoring, thereby preserving productivity

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If real-time credential evaluation is implemented to detect mismatches, then security improves, but device complexity increases

Engineering Contradiction:
Improvecredential misuse detectionVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the credential evaluation system into distinct modular components: browser extensions for event capture, event record generation modules, website purpose determination modules using machine learning, credential analysis modules, and policy enforcement modules. This segmentation allows each component to perform its specific function independently, making the overall complex system manageable, maintainable, and scalable

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11750595B2Multi-computer processing system for dynamically evaluating and controlling authenticated credentials
Publication Date: 2023.09.05 BANK OF AMERICA CORP
  • US11750595B2 patent drawing
  • US11750595B2 patent drawing
  • US11750595B2 patent drawing

AI summary

Systems for credential evaluation and control are provided. In some examples, a request to access data via a website may be received. The request may include a username. A browser extension embedded in the web browser used to request the data via the website may be triggered and one or more credential evaluation functions may be executed. An event record associated with the request to access data may be generated. The event record may be analyzed to determine a designation associated with the website and a designation associated with user credentials provided with the request to access the data. The designation of the website and the designation of the credentials may be compared to determine whether the designations match. If so, access to the requested data may be provided. If not, one or more mitigating actions may be identified and executed.