Web Browser Frame Isolation for Secure Content Display
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing web browser systems face challenges in securely displaying and communicating trusted and untrusted internet content, as malicious sellers can embed harmful code in item descriptions, risking alteration of trusted content and interference with the intended page behavior.
Innovation Solution
The solution involves separating trusted and untrusted content by storing them on separate network domains and instructing the web browser to display them in different views, utilizing cross-frame security features to prevent interaction, while allowing controlled exchange of predetermined information between these domains through additional browser views.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If sellers are permitted to embed executable code in item descriptions, then the functionality and expressiveness of content is improved, but security risks increase as malicious code can alter trusted content and interfere with page behavior
Solution Approach 1:
The patent divides the web page content into separate frames: trusted content from the service provider and untrusted content from the seller. This segmentation isolates malicious code in the seller's frame, preventing it from affecting the trusted service content while still allowing the seller's code to execute and provide functionality.
Solution Approach 2:
The patent introduces a framing service as an intermediary between the seller's untrusted content and the service provider's trusted content. The framing service creates the frame structure and controls how the two contents coexist, acting as a buffer that prevents direct interaction and potential harm while enabling both contents to be displayed.
2Object-affected harmful factors
If filter programs are used to remove potentially malicious code, then security is improved, but legitimate scripts are also removed reducing content functionality
Solution Approach 1:
Instead of filtering code, the patent segments the page into separate frames for trusted and untrusted content. This allows all scripts to execute without filtering, while the frame boundary prevents malicious scripts from accessing or modifying trusted content, thus preserving functionality while ensuring security.
Solution Approach 2:
The frame structure acts as an intermediary boundary that allows untrusted content to execute freely within its own frame while preventing it from interfering with trusted content in other frames. This mediator approach eliminates the need for filtering while maintaining security through isolation.
3Reliability
If trusted and untrusted content are displayed in separate browser windows, then security is improved by preventing interaction, but device complexity and user interface complexity increase
Solution Approach 1:
The patent merges multiple separate browser windows into a single unified browser window by using HTML frames. This combining approach maintains the security benefits of separation (trusted and untrusted content are isolated in different frames) while eliminating the complexity of managing multiple separate windows, providing a simpler user interface.
Data Source
AI summary
A method and apparatus for securely displaying and communicating trusted and untrusted internet content via a web browser is described. In a preferred embodiment, the invention is an electronic marketplace system in which auction-related content is displayed in one window of a customer's web browser while item-related content is displayed in a second window of the customer's web browser, such that the auction-related content and the item-related content are substantially prevented from substantially interacting. The invention further provides a method and apparatus for communicating predetermined information between multiple documents opened in multiple web browser windows, where the documents are served from multiple domains.


