Intermediary System for Cross-Domain Session Data Exchange
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Web browsers limit access to session data stored as HTTP cookies, preventing cross-domain authentication and customized content delivery due to security policies and regulations, which hampers single sign-on authentication and content selection across different domains.
Innovation Solution
The system enables indirect transmission of session data between domains using first-party cookies and hashing functions, allowing secure exchange of information between third-party entities, thereby bypassing browser restrictions on cross-domain data exchange.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If web browsers enforce security policies to prevent cross-domain attacks, then security is improved, but cross-domain authentication and content delivery are blocked
Solution Approach 1:
The patent introduces a data processing system acting as an intermediary between the client device and content provider. This intermediary receives client device identifiers, determines corresponding identifiers for content requests, and enables cross-domain content delivery without direct access to session data between domains, thus maintaining security while enabling versatility
Solution Approach 2:
The system segments the authentication and content delivery process into separate components: the client device generates identifiers, the intermediary processes and maps identifiers between domains, and the content provider delivers content. This segmentation allows each component to operate within its security boundaries while achieving cross-domain functionality
2Reliability
If session data is purged from client device to maintain security and privacy, then security is improved, but customized content delivery based on session data is lost
Solution Approach 1:
Instead of storing actual session data on the client device, the system uses copying by generating and transmitting identifier representations that reference session data stored securely on the server. These identifiers enable retrieval of session-specific content without requiring the client to retain sensitive session information
Solution Approach 2:
The system performs preliminary action by pre-establishing the mapping between client device identifiers and content provider identifiers before content delivery. This allows the intermediary to quickly resolve identifiers and deliver customized content without requiring the client device to store or process actual session data
3Productivity
If direct access to session data is allowed for content customization, then content delivery quality is improved, but security restrictions are violated
Solution Approach 1:
The data processing system acts as an intermediary that receives content requests from content providers, determines the appropriate client device identifier based on the request, and facilitates content delivery without allowing direct access to session data. This enables customized content delivery while maintaining security policy compliance
Solution Approach 2:
The system changes the parameter representation from direct session data access to identifier-based referencing. By transforming the authentication mechanism from direct session data usage to identifier mapping and resolution, the system enables content customization without violating security restrictions
Data Source
AI summary
The systems and methods described herein can enable the selection of customized content in networked systems that prevent the transfer of session data between different domains. The systems and methods described herein enable the exchange of data between third-party entities that would be blocked in networked systems that prevent cross-domain data exchange. The systems and methods can provide multi-sourced content without sacrificing security of the client device and browser environment.


