Browser Plug-in for Transparent Certificate Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web mashups and composite applications face user experience and security challenges due to frequent certificate verification prompts from web browsers, which can lead to user annoyance and security risks, especially for mobile users who need quick access to information.

Innovation Solution

Implementing a browser plug-in or online verification service that performs local or cloud-based digital certificate verification, allowing for transparent and automated certificate validation, reducing the need for user intervention and improving security management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If web browsers perform certificate validation for composite applications, then security is improved, but user experience deteriorates due to frequent verification prompts

Engineering Contradiction:
Improvecertificate validation securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a certificate verification service as an intermediary between the browser and the user. This service automatically verifies certificates from multiple sources in composite applications and presents a single aggregated result, eliminating the need for users to manually evaluate multiple verification prompts while maintaining security

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables self-service by automatically performing certificate verification without requiring user intervention. The browser or verification service autonomously evaluates certificates from multiple sources and makes security decisions, freeing users from the burden of manual verification while maintaining security standards

Inventive Principle:
Principle #25Self-service

2Reliability

If users manually evaluate certificate verification prompts, then security control is improved, but time consumption increases

Engineering Contradiction:
Improvesecurity controlVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The verification service performs preliminary certificate verification actions automatically before content is displayed to the user. By pre-evaluating all certificates from multiple sources and aggregating results, the system eliminates the time users would otherwise spend manually examining each verification prompt while maintaining security control

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple certificate sources are verified, then security coverage is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple certificate verification processes into a single unified verification service. Instead of separately managing verification from multiple sources, the service aggregates all verification results and presents a single consolidated outcome, reducing system complexity while maintaining comprehensive security coverage

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9081940B2Method and service for user transparent certificate verifications for web mashups and other composite applications
Publication Date: 2015.07.14 INTEL CORP
  • US9081940B2 patent drawing
  • US9081940B2 patent drawing
  • US9081940B2 patent drawing

AI summary

Embodiments for providing user transparent certificate verifications for web mashups and other composite applications are generally described herein. In some embodiments, a content buffer is provided for holding content until receiving verification results that allow the content to be presented in a browser user interface. A browser core receives an aggregation of content from a plurality of sources and performing local verification of digital certificates associated with the content received from the plurality of sources. A browser content interface intercepts content associated with verified digital certificates from the browser core to provide content associated with verified digital certificates to the content buffer for holding. An online certification module is arranged to receive untrusted certificates from the browser content interface and to perform verification of the received untrusted certificates using online certification services and/or local certificate store on the client device.