Feature-Level Access Control for Uncontrolled Web Applications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Businesses lack control over access to features and subfeatures of uncontrolled Web applications, such as social networking sites, which poses risks of data leakage and misuse, leading them to restrict access entirely, missing out on potential benefits.
Innovation Solution
A system and method that implement feature-level access control by programmatically inspecting Web pages from uncontrolled applications, allowing administrators to enable or disable specific features and subfeatures based on corporate policies, using a middleware solution that modifies pages on-the-fly to preserve access while blocking unwanted features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If businesses block access to entire uncontrolled Web applications, then security risks are reduced, but employees lose access to beneficial features and productivity opportunities
Solution Approach 1:
The patent segments the Web application into individual features and subfeatures, allowing granular control over what employees can access. Instead of blocking the entire application, the system divides it into controllable units (features) that can be selectively enabled or disabled based on security policies while maintaining access to safe, beneficial features.
Solution Approach 2:
The system applies different access control qualities to different parts of the Web application. Each feature can have its own access control settings, allowing businesses to permit certain features (e.g., information lookup) while blocking others (e.g., data submission), thereby maintaining security in critical areas while preserving productivity benefits in safe areas.
2Productivity
If businesses allow unrestricted access to uncontrolled Web applications, then employees gain access to beneficial features, but security risks of data leakage and misuse increase
Solution Approach 1:
The system performs preliminary analysis of the Web application to identify features, subfeatures, and their associated security risks before employees access them. By pre-configuring access control policies based on this analysis, the system establishes security measures in advance, allowing employees to use beneficial features safely without exposing the organization to preventable security risks.
Solution Approach 2:
The patent introduces an intermediary access control system between employees and the uncontrolled Web application. This intermediary layer analyzes employee requests, evaluates them against security policies, and selectively permits or blocks access to specific features, thereby mediating between productivity needs and security concerns without requiring direct employee interaction with risky elements.
3Reliability
If businesses implement feature-level access control, then granular security control is achieved, but system complexity increases
Solution Approach 1:
The patent implements a universal access control framework that can be applied to any uncontrolled Web application regardless of its specific features or functionality. This multi-functional system provides a consistent method for identifying, analyzing, and controlling access to features across different applications, reducing the need for application-specific customizations and managing complexity through standardization.
Solution Approach 2:
The system incorporates automated analysis capabilities that independently identify features, subfeatures, and their security characteristics without requiring manual configuration for each new Web application. This self-service approach reduces administrative complexity by automatically generating access control policies based on the analyzed structure and risk profile of the target application.
Data Source
AI summary
Embodiments disclosed herein provide feature-level access control functionality useful for enforcing access controls to features and subfeatures on uncontrolled, third party Web Applications such as those associated with social networking sites. Specifically, pages of uncontrolled Web applications are programmatically inspected as they are accessed by users of an enterprise computing environment. Specific features on the pages are located and access to these features is enabled or disabled on a per user basis. A modified page is generated if feature(s) on a Web page is/are to be disabled. To block certain feature(s), content may be rewritten on-the-fly. Because embodiments disclosed herein can programmatically inspect a Web page and understand what is on the page at a much finer granularity, it is possible for enterprises to gain benefits that may come from embracing social networking sites without risking the downsides of allowing enterprise users access to uncontrolled Web applications.


