HTML5 Resource Read-Only Protection Zone Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing popularity of HTML5 technology has highlighted the urgent need for effective security protection of HTML files to prevent tampering and reduce associated security risks.

Innovation Solution

A method and system that monitor operations on a preset HTML5 resource read-only protection zone through a system authority service, allowing only system authority processes to perform write operations, restricting access by the built-in browser kernel to non-HTML5 resource zones, and limiting read and non-read operations by non-system authority processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If HTML5 applications are allowed to access and write to local resources freely, then application functionality and ease of operation are improved, but security risks and file tampering increase

Engineering Contradiction:
Improveapplication functionalityVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the file system into distinct read-only protection zones for HTML5 resources and other data areas. The system authority service monitors and controls access to these segmented zones, allowing HTML5 applications to freely access their designated resources while preventing unauthorized tampering through the read-only protection mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system authority service acts as an intermediary between HTML5 applications and the file system. It monitors operations on HTML5 resources and enforces access control policies, allowing legitimate application functionality while blocking malicious operations that would compromise security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If read-only protection zones are implemented for HTML5 resources, then file security and anti-tampering are improved, but system complexity increases

Engineering Contradiction:
Improvefile securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The read-only protection mechanism is integrated into the file system structure itself, where the system authority service automatically monitors and enforces protection policies without requiring complex external security software. The firmware-built-in browser kernel inherently respects these protection zones, reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If system authority service monitors all operations on HTML5 resources, then security protection is improved, but processing overhead and system resource consumption increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The monitoring mechanism focuses specifically on HTML5 resource protection zones rather than monitoring all file system operations. The system authority service applies targeted monitoring only where HTML5 resources are stored, reducing unnecessary processing overhead while maintaining effective security protection for critical areas.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20230035678A1Method and system for protecting security of html5 file
Publication Date: 2023.02.02 PAX COMP TECH SHENZHEN
  • US20230035678A1 patent drawing
  • US20230035678A1 patent drawing
  • US20230035678A1 patent drawing

AI summary

The present application relates to the technical field of HTML5, and provides a method and a system for protecting security of a HTML5 file, and a terminal device. The embodiment of the present application monitors the operations on the HTML5 resource read-only protection zone by pre-establishing the HTML5 resource read-only protection zone, only allows the system authority process to perform read and write operations on the HTML5 resource read-only protection zone, and writes the data of the local HTML5 resource package into the HTML5 resource read-only protection zone to install HTML5 applications, restricting the HTML5 applications from accessing data in the non-HTML5 resource read-only protection zone, such that the non-system authority processes, including HTML5 applications, to only read the HTML5 resource read-only protection zone, and the system authority process is protected by firmware.