Intermediate Web Browser Credential Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional password management systems are inadequate in preventing unauthorized access and password theft, particularly due to the limitations of local password managers that cannot protect against keyloggers and require users to manually input credentials across multiple applications.

Innovation Solution

A system and method utilizing an intermediate web browser subsystem that establishes connections with local web browsers to authenticate users using pre-stored credentials, enforce password policies, and route web pages to applications without requiring users to manually input credentials, thereby isolating passwords from potential malware and automating password management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If local password managers are used to manage credentials, then users can access multiple applications conveniently, but the system becomes vulnerable to keyloggers and malware that can steal credentials

Engineering Contradiction:
Improvepassword management convenienceVSAvoidcredential security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediate web browser that acts as a mediator between the user's local browser and web applications. The intermediate browser hosts the password manager subsystem, creating a security layer that prevents direct access to credentials by local malware and keyloggers. This intermediary architecture allows convenient password management while protecting credentials from theft.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users manually input passwords for each application, then password secrecy is maintained, but user convenience and productivity decrease

Engineering Contradiction:
Improvepassword secrecyVSAvoidauthentication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The password manager subsystem automatically detects login forms on web pages and fills in credentials without user intervention. The system self-services the authentication process by monitoring the intermediate browser for authentication requirements and automatically providing credentials, eliminating manual password input while maintaining security through the intermediary browser architecture.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If password managers are installed as browser extensions, then password management is integrated, but the system cannot prevent users from knowing passwords and remains vulnerable to local malware

Engineering Contradiction:
Improvepassword manager integrationVSAvoidmalware vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Instead of installing the password manager in the traditional location (as a browser extension on the user's machine), the patent moves it to a different dimension - hosting it within the intermediate web browser environment. This dimensional shift places the password manager in a protected sandboxed environment that is isolated from local malware, while still providing integrated password management functionality.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11729168B2System and method for managing security credentials of a user in a computing environment
Publication Date: 2023.08.15 APPAEGIS INC
  • US11729168B2 patent drawing
  • US11729168B2 patent drawing
  • US11729168B2 patent drawing

AI summary

A system and method for managing security credentials of a user are disclosed. The method includes establishing a connection with a local web browser hosted on a user device. The method also includes receiving a request for accessing a web application on the local web browser hosted on the user device. The method also includes determining whether current web page associated with the web application on the local web browser requires authentication of the user. Further, the method includes determining a password policy. Furthermore, the method includes authenticating the user on the web page using pre-stored user credentials based on the determined password policy. Additionally, the method includes routing the web page of the local web browser to the web application via an intermediate web browser. Also, the method includes providing access of the web application to the local web browser based on privileges associated with the user.