Embedded Browser Authentication Binding User and Data Channels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods, whether through mobile applications or web browsers, face challenges in providing secure and user-friendly access to multiple services, often overwhelming users with different authentication procedures and vulnerable to security attacks like MITM, especially when relying on user knowledge and vigilance for TLS channel security.
Innovation Solution
A computer-implemented system comprising an authenticator and a data channel module, integrated with an embedded browser, uses cryptographic algorithms to securely authenticate users and bind user authentication to a secure data channel, eliminating the need for application-level authentication and enhancing security to match single-purpose mobile applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If web browser-based authentication is used, then accessibility across multiple platforms is improved, but security is worsened due to vulnerabilities and MITM attacks
Solution Approach 1:
The patent introduces an embedded browser as an intermediary component that acts as a secure sandbox between the user agent and external web services. This embedded browser isolates authentication operations within a controlled environment, preventing direct exposure to external threats while maintaining cross-platform accessibility through standardized web protocols.
Solution Approach 2:
The patent implements nesting by embedding a browser environment within the secure context of the user agent. The embedded browser operates as a nested layer that provides web-based authentication capabilities while being contained within and protected by the parent application's security model, allowing secure authentication without requiring separate mobile applications.
2Reliability
If multiple separate authentication systems are used for different services, then service-specific security is improved, but user burden is worsened due to remembering multiple passwords and procedures
Solution Approach 1:
The patent implements a universal embedded browser authentication mechanism that can handle multiple service-specific authentication protocols through a single interface. The embedded browser supports various authentication methods (username/password, biometric, hardware token) and can adapt to different service requirements while providing a unified user experience through standardized web-based interactions.
Solution Approach 2:
The patent segments authentication functionality into modular components within the embedded browser, allowing different authentication methods to be independently implemented and selected based on service requirements. This segmentation enables the system to maintain service-specific security protocols while presenting a unified authentication interface to users through standardized web forms and flows.
3Reliability
If application-level authentication is implemented, then security control is improved, but system complexity is worsened requiring authentication implementation in each web application
Solution Approach 1:
The embedded browser serves as an intermediary that centralizes authentication control logic, eliminating the need for each web application to implement its own authentication mechanism. The embedded browser handles authentication protocols, security controls, and user interactions within a unified framework, reducing overall system complexity while maintaining strong security controls through standardized implementations.
Data Source
AI summary
A software system that has an embedded browser, an authenticator and a data channel module where the authenticator is adapted to authenticate a user, to authenticate a data channel and to bind the user authentication with the authenticated channel is disclosed. The authenticator is further adapted to communicate with the user via a graphical user interface of the embedded browser using graphical and control primitives of the authenticator and/or using a stand-alone graphical user interface of the authenticator, and the data channel module is adapted to communicate with service provider servers via a secure protocol, to communicate with the embedded browser and to communicate with the authenticator. A method of authentication using this system increases security and user comfort when accessing services and data requiring authentication is also disclosed.


