Hidden Messaging Frame for Cross-Domain Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing browsers and applications impose restrictions on cross-domain requests and cross-site scripting, making it difficult for content providers to communicate information between frames from different domains, especially in secure and non-secure environments, and compliance with standards like PCI DSS can be challenging.
Innovation Solution
A hidden messaging frame that can switch between domains, allowing communication between elements from different domains without violating cross-domain restrictions or compliance standards, by using a messaging frame with zero width and height that can be sourced from multiple domains and switch between them to facilitate message passing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cross-domain communication is enabled between frames, then user experience consistency is improved, but security vulnerabilities and compliance violations occur
Solution Approach 1:
The patent introduces an intermediary messaging frame that acts as a mediator between domains. This hidden frame with zero dimensions serves as a safe communication channel, allowing information exchange between different domains without enabling direct cross-domain scripting that would create security vulnerabilities.
Solution Approach 2:
The communication mechanism is segmented into distinct components: the hidden messaging frame that switches domains, the message passing interface, and the content provider frames. This segmentation allows controlled communication while maintaining security boundaries between domains.
2Productivity
If direct JavaScript interaction between domains is implemented, then content update responsiveness is improved, but PCI DSS compliance is violated
Solution Approach 1:
The hidden messaging frame serves as a compliant intermediary that enables content providers to receive notifications about user actions across domains without implementing direct JavaScript interaction. This maintains PCI DSS compliance while achieving the desired content update responsiveness.
Solution Approach 2:
Instead of direct interaction, the system uses a copied communication pattern where messages are passed through the hidden frame interface, allowing content providers to react to user actions without establishing direct cross-domain JavaScript connections that would violate compliance standards.
3Adaptability or versatility
If cross-site scripting restrictions are removed, then frame communication flexibility is improved, but system security is compromised
Solution Approach 1:
The hidden messaging frame acts as a secure intermediary that enables flexible frame communication without requiring removal of cross-site scripting restrictions. All communication must pass through this controlled interface, preventing direct XSS attacks while maintaining communication flexibility.
Solution Approach 2:
The messaging frame has specialized local properties (zero width and height, hidden from user view) that distinguish it from regular frames. This local quality allows it to perform communication functions without exposing the same security vulnerabilities as visible, interactive frames.
Data Source
AI summary
A messaging frame can be used to allow different domains to communicate in an electronic environment that are otherwise prevented from directly communicating. A messaging frame or other communication element can be configured to receive messages or communications from any frame, object, or element in the same domain as the messaging frame. The messaging frame then can switch to a target domain in order to provide the message or communication to a frame, object, or element in the target domain. The messaging frame can include an interface definition that allows only approved messages to be passed between domains, such that the risk of malicious attack is minimized.


