Browser Lockbox for Securing Web Application Sessions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in securing data within web-based applications accessed on a client system, particularly when they need to lend their device to others or forget to log out, leading to potential security issues due to the inconvenience of logging out of multiple applications and the risk of unauthorized access.
Innovation Solution
A system that allows users to lock designated applications within a web browser by storing authorization credentials in a lockbox, rendering them inaccessible until the correct password or credential is entered, while keeping the applications logged in, thus preventing unauthorized access and simplifying the process of securing data across multiple client systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If users log out of multiple web-based applications to secure data, then security is improved, but time consumption and operational inconvenience increase
Solution Approach 1:
The system performs preliminary action by automatically locking designated applications when the user switches to a different client system or closes the browser. The lockbox mechanism pre-establishes a security state that activates without requiring manual logout, thus preventing unauthorized access while eliminating the time-consuming manual logout process.
Solution Approach 2:
The system implements self-service through automatic locking mechanisms that engage when users switch systems or close browsers. The lockbox automatically secures applications based on detected user actions, eliminating the need for users to manually logout of multiple applications while maintaining security.
2Ease of operation
If users remain logged in to web-based applications for convenience, then ease of operation is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The system applies dynamics by implementing a dynamic locking state that transitions between locked and unlocked conditions based on user actions. Applications remain accessible during active use but automatically lock when users switch systems or close browsers, creating a flexible security mechanism that adapts to user behavior patterns.
Solution Approach 2:
The lockbox serves as an intermediary mechanism between the user and the applications. It mediates access by requiring authentication credentials before allowing access to designated applications, thus maintaining ease of operation for authorized users while preventing unauthorized access.
3Reliability
If users manually lock each application individually, then security is improved, but device complexity and operational steps increase
Solution Approach 1:
The system merges the locking function into a single integrated mechanism that applies to multiple applications simultaneously. The lockbox consolidates individual application locking into one unified security layer, eliminating the need to manually lock each application separately and reducing operational complexity.
Solution Approach 2:
The lockbox implements universality by providing a single security mechanism that secures multiple designated applications across different web-based services. One locking action protects all enrolled applications, making the security process simple and scalable without requiring application-specific locking procedures.
Data Source
AI summary
Techniques are shown for executing a web browser on a client computing device and requesting access to applications available from a hosting server over a network in communication with the client device. The web browser stores authorization credentials for accessing designated applications available from the hosting server in a lockbox. A message received at the web browser provides instructions to lock all designated applications by rendering at least partially blanked-out or partially obscured visual displays for the designated applications, with no viewing of, access to, or operation on selected data within the designated applications permitted, while the locked designated applications remain logged-in. This Abstract is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims.


