Middleware Tagging for Uncontrolled Web Application Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Businesses lack control over and monitoring of communications and data exchanged through uncontrolled Web applications, such as social networking sites, which poses risks of data leakage and misuse, leading them to restrict access and miss out on potential benefits.

Innovation Solution

A system and method for tagging and structuring content from uncontrolled Web applications, allowing for the creation of a controlled version with additional functionalities, enabling businesses to monitor and manage user interactions while maintaining transparency to end users, by using a middleware or proxy that inspects and modifies unstructured data into structured application element types.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If businesses restrict access to uncontrolled Web applications, then data security and control are improved, but loss of information and productivity are worsened

Engineering Contradiction:
Improvedata securityVSAvoidloss of beneficial communications
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent introduces a gateway server as an intermediary between users and uncontrolled Web applications. This gateway inspects, filters, and controls communications without completely blocking access. It allows businesses to maintain data security by monitoring and filtering content while still permitting beneficial communications to pass through, thus resolving the contradiction between security and information loss.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The gateway server extracts and removes harmful or unauthorized content from communications while allowing legitimate content to pass through. By selectively extracting problematic elements rather than blocking all external communications, the system maintains security without losing beneficial information exchange.

Inventive Principle:
Principle #2Taking out (Extraction)

2Object-affected harmful factors

If businesses block access to social networking sites, then data leakage risks are reduced, but productivity and employee engagement are worsened

Engineering Contradiction:
Improvedata leakage riskVSAvoidemployee productivity
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The gateway server implements feedback mechanisms by monitoring communications in real-time and dynamically adjusting filtering based on content analysis. This allows the system to permit productive communications while blocking harmful ones, maintaining both security and productivity through continuous adaptation rather than static blocking.

Inventive Principle:
Principle #23Feedback

3Reliability

If businesses implement strict access controls, then data security is improved, but ease of operation and user experience are worsened

Engineering Contradiction:
Improvedata securityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service capabilities where users can configure their own communication preferences and policies through the gateway interface. This allows users to manage their own security settings and communication rules without requiring complex administrative intervention, maintaining security while improving ease of operation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9954965B2Method, system and computer program product for tagging content on uncontrolled web application
Publication Date: 2018.04.24 PROOFPOINT INC
  • US9954965B2 patent drawing
  • US9954965B2 patent drawing
  • US9954965B2 patent drawing

AI summary

Communications by a device in a private network to a site operating outside of the network can be programmatically inspected. Unstructured data, including messages and application content, originating from outside of the network may be dynamically converted to structured data that can be tagged. Interactions and activities can be monitored and processed differently according to internal policies and/or business rules. For example, at least a portion of the structured data can be modified prior to forwarding to the device, access by the device to at least a portion of the structured data can be blocked or limited, access by the device to one or more features associated with the structured data can be blocked or limited, etc.