Emergent Web Spaces Using True Random Data for Secure Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional website provisioning technologies face challenges such as domain name scarcity, typosquatting, DNS vulnerabilities, subdomain takeovers, multi-tenancy issues, and various security threats, leading to increased complexity and vulnerability to attacks.

Innovation Solution

The implementation of emergent web spaces using true random data to generate unique names and data aspects for website resources, which are resolved within a secure, decentralized environment, reducing reliance on domain names and enhancing security through isolation and resilience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If domain names are used for website provisioning, then websites can be easily accessed and identified, but domain name scarcity and typosquatting increase security vulnerabilities and operational complexity

Engineering Contradiction:
ImproveWebsite accessibilityVSAvoidSecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the domain name system from the website provisioning infrastructure and replaces it with content-addressable URLs and IPFS hashes. This removes the vulnerability surface associated with domain names while preserving the ability to easily access and identify websites through their actual content location and cryptographic identifiers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces IPFS (InterPlanetary File System) as an intermediary layer between websites and users. Instead of relying on domain names that can be spoofed or exhausted, IPFS provides a decentralized content-addressable storage system that resolves to actual website content, eliminating typosquatting and domain exhaustion issues while maintaining accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If DNS systems are used for traffic routing, then accurate records can be maintained, but DNS is vulnerable to tunneling attacks and was never designed with security in mind

Engineering Contradiction:
ImproveTraffic routing accuracyVSAvoidDNS tunneling attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical DNS lookup process with direct content-addressable URL resolution through IPFS. Instead of relying on DNS records that can be manipulated or exhausted, the system directly resolves to the actual content location using cryptographic hashes and peer-to-peer networking, eliminating DNS tunneling vulnerabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent changes the fundamental parameters of web addressing from domain name-based (human-readable but vulnerable) to content-hash-based (cryptographically secure but initially less readable). This parameter change fundamentally alters how traffic routing is performed, making it resistant to DNS-based attacks while maintaining accuracy through cryptographic verification.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If subdomains are used for website resources, then flexible resource organization is achieved, but subdomain takeover vulnerabilities allow attackers to gain control

Engineering Contradiction:
ImproveResource organization flexibilityVSAvoidSubdomain takeover
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the subdomain mechanism from the website resource organization system and replaces it with content-addressable paths in IPFS. This removes the vulnerability surface associated with subdomain takeovers while preserving the ability to organize resources flexibly through hierarchical content paths and metadata.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses composite identifiers combining content hashes, IPFS paths, and metadata to create a secure resource organization system. This composite approach provides both the flexibility needed for resource organization and the cryptographic security needed to prevent takeover, as the entire path must be cryptographically verified.

Inventive Principle:
Principle #40Composite materials

4Adaptability or versatility

If multiple domain name extensions are registered, then more website options are available, but fees multiply and management becomes burdensome

Engineering Contradiction:
ImproveWebsite provisioning optionsVSAvoidRegistration management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent makes IPFS the universal addressing system for all websites, replacing the need for multiple domain name extensions. This single universal system provides content-addressable URLs that work for all websites regardless of their content or purpose, eliminating the complexity of managing multiple domain registrations while preserving extensive provisioning options.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses content hashes and IPFS identifiers as copies of the actual website content location. These cryptographic copies serve as the addressing mechanism, eliminating the need for expensive and complex domain name registrations. The content hash itself becomes the identifier, providing both the address and verification mechanism in a single element.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12495071B2Emergent web spaces and system
Publication Date: 2025.12.09 CALLPLEX
  • US12495071B2 patent drawing
  • US12495071B2 patent drawing
  • US12495071B2 patent drawing

AI summary

A system implements an emergent web space to bind a host computer to one or more client computers. A host computer generates data aspects of characteristically random data to create emergent web spaces in which website resources can be rendered by one or more client computers intersecting the same emergent web spaces. A binding is established between the host computer and one or more client computers when a block of true random data generated by the host computer is provided to the one or more client computers. A unique block of true random data together with the remote storage of data aspects constitutes a zone. A software application executing on the one or more client computers is configured to retrieve data aspects from within the same zone, and further configured to resolve and then render website resources.