Encrypted Browser Cache for Secure User Input Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to securely cache and recover user input data in web form fields across network applications, leading to data loss during page reloads or timeouts, and lack visibility and control over network application traffic.

Innovation Solution

An embedded browser on a client device establishes and maintains an encrypted cache to securely store and recover user input data, allowing policy-based control and authentication for improved data retention and visibility into network application traffic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If user input data is cached in web form fields for recovery during page reloads or timeouts, then data loss is prevented and user experience is improved, but security risks increase due to potential exposure of sensitive data

Engineering Contradiction:
Improvedata retentionVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates an encrypted copy of user input data and stores it in a secure cache. This copy can be recovered during page reloads or timeouts without exposing the original data, thus preventing data loss while maintaining security. The encrypted cache serves as a safe replica that can be accessed only when needed and only by authenticated users.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent changes the security parameters of cached data by applying encryption. User input data is transformed from plain text to encrypted format before being stored in the cache. This parameter change ensures that even if the cache is accessed unauthorizedly, the data remains protected. The encryption state is maintained throughout the caching and recovery process.

Inventive Principle:
Principle #35Parameter changes

2Object-affected harmful factors

If an encrypted cache is implemented to securely store user input data, then security is improved, but system complexity increases due to additional encryption and cache management overhead

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces an embedded browser as an intermediary component that manages the encrypted cache. This intermediary handles the complexity of encryption and decryption operations, cache storage and retrieval, and coordination with the network application. By centralizing these functions in the embedded browser, the overall system complexity is contained and managed more effectively.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The embedded browser performs multiple functions: it acts as a web browser, manages the encrypted cache, handles authentication, and coordinates with the network application. By making the embedded browser multi-functional, the patent avoids adding separate dedicated components for each function, thus reducing overall system complexity while still providing comprehensive security and caching capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If the embedded browser overrides network application settings to allow access to securely cached data, then user productivity is improved, but control over data access is reduced

Engineering Contradiction:
Improveuser productivityVSAvoidaccess control
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent performs preliminary authentication of the user before allowing access to the encrypted cache. The embedded browser verifies the user's credentials and authorization level before permitting cache access. This preliminary action ensures that only authenticated users can access cached data, maintaining security while enabling productivity improvements through data recovery during interruptions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms to monitor and control access to the encrypted cache. The embedded browser communicates with the network application to report cache access requests and receive authorization decisions. This feedback loop ensures that while users can access cached data for productivity purposes, the access is continuously monitored and controlled according to security policies.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12199953B2Systems and methods for encrypted browser cache
Publication Date: 2025.01.14 CITRIX SYSTEMS INC
  • US12199953B2 patent drawing
  • US12199953B2 patent drawing
  • US12199953B2 patent drawing

AI summary

Embodiments described include systems and methods of an encrypted cache. An embedded browser of a client application executing on a client device may provide access to a network application accessed via the client application. The embedded browser may detect an event at the client device that causes the network application to send or request application data. The embedded browser may access a copy of the application data from encrypted cache of the embedded browser. The encrypted cache may be maintained for the user and store application data for network application(s) accessed by the user. The embedded browser may use the cached application data for establishing or updating a user interface of the network application for display at the client device.