Dynamic Hidden Form Field Validation Against Automated Bots
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional form validation techniques are inadequate in determining whether form data submitted by a client device is completed by a human user, as malicious automatic completion programs can recognize and exploit the static name of hidden form fields, leading to issues like spamming and malicious forum flooding.
Innovation Solution
A system and method where a server generates random parameters for a hidden form field, which are used to create a hidden form field on the client device, and only assigns a valid value to this field upon human interaction, making it difficult for automatic programs to complete the form correctly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hidden form field with a static name is used for validation, then form validation can be implemented, but malicious programs can recognize and exploit the static name to perform automated completion
Solution Approach 1:
The patent applies dynamics by making the hidden form field name variable rather than static. The server generates a unique random name for each form instance and dynamically updates it upon user interaction. This dynamic naming prevents malicious programs from recognizing and exploiting a fixed pattern, while still allowing valid human users to complete the form successfully.
Solution Approach 2:
The patent changes the parameter of the hidden form field from a static name to a dynamically generated random name. The server generates a random string as the field name and updates it when user interaction is detected. This parameter change ensures that each form instance has a unique identifier that cannot be predicted or exploited by automated programs.
2Stability of the object's composition
If the hidden form field name is generated in advance and remains the same across requests, then form structure is consistent, but security against automated programs is compromised
Solution Approach 1:
The patent introduces dynamics into the form structure by making the hidden field name changeable. While the overall form structure remains stable, the specific name of the hidden validation field becomes dynamic - generated randomly for each request and updated upon user interaction. This resolves the contradiction by allowing structural consistency at the form level while introducing variability at the field level for security.
Solution Approach 2:
The server performs preliminary action by generating a random name for the hidden form field before the user interacts with the form. This pre-generated random name is then updated when user interaction is detected, creating a two-stage process that both secures the form against automated programs and maintains usability for human users.
3Object-affected harmful factors
If validation requires detecting human interaction events, then automated completion is prevented, but the complexity of form handling increases
Solution Approach 1:
The patent applies self-service by having the client device automatically detect user interaction events and autonomously update the hidden form field name without requiring server intervention. The browser's event handling mechanisms automatically track user actions and trigger the name update, simplifying the overall system while maintaining security.
Solution Approach 2:
The system implements feedback by having the client device monitor user interaction events and automatically update the hidden form field name in response to detected human behavior. This feedback loop creates a dynamic validation mechanism that adapts to user actions while preventing automated completion, without significantly increasing system complexity.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Form validation is disclosed, including: generating a first parameter and a second parameter in response to a request for a form from a client device; sending a first triggering message including the first parameter and the second parameter to the client device; receiving data associated with submission of the form; and determining whether the data associated with the submission of the form includes the hidden form field that matches the first parameter and a submitted value corresponding to the hidden form field that corresponds to the second parameter, in the event that the hidden form field matches the first parameter and the submitted value corresponding to the hidden form field corresponds to the second parameter, determine that the data associated with the submission of the form is successfully validated.