Secure Browser Automatic Mode Switching for Assessment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure browsers require specific launch and cannot seamlessly transition between secure and insecure modes, limiting flexibility in mixed usage scenarios where assessments are integrated with other computer activities.

Innovation Solution

A method to automatically launch a secure browser when secure content is encountered, using MIME types and server-side verification to ensure secure content is displayed with restricted functionality, reverting to standard browser mode after secure content is completed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure browser is used to deliver assessments, then security is improved, but flexibility and ease of operation deteriorate because users cannot perform other tasks

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The browser dynamically transitions between secure and insecure modes based on the content being accessed. When secure content is detected via MIME type, the browser automatically switches to secure mode with restricted functionality. When non-secure content is accessed, it reverts to standard browser mode, allowing users to perform other tasks while maintaining security when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The browser changes its operational parameters (functionality restrictions, menu visibility, navigation capabilities) based on the security requirements of the content being accessed. This allows the same browser to provide both secure and flexible operation modes without requiring separate applications.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a secure browser is specifically launched for assessments, then security is improved, but device complexity and ease of operation worsen due to multiple browser configurations

Engineering Contradiction:
ImprovesecurityVSAvoidbrowser configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A single browser application provides both secure and standard browsing functionality. The browser automatically detects when secure content is being accessed and switches to secure mode, eliminating the need for users to manually launch different browser versions or configurations for assessments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The browser automatically detects secure content through MIME type verification and self-configures to secure mode without user intervention. The system handles the transition between modes automatically, reducing user burden and complexity.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If secure content is delivered through standard browser, then ease of operation is improved, but security deteriorates because users can access and modify content

Engineering Contradiction:
Improveuser accessibilityVSAvoidcontent protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The browser changes its operational parameters based on content type. When secure content is detected, it restricts functionality (preventing printing, copying, navigation, and other modifications). When non-secure content is accessed, it provides full browser functionality for ease of use.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9055048B2Secure browser
Publication Date: 2015.06.09 QUESTIONMARK COMPUTING
  • US9055048B2 patent drawing
  • US9055048B2 patent drawing
  • US9055048B2 patent drawing

AI summary

A method for interacting with a user, comprising communicating with at least one cooperative server through a normal browser; automatically receiving encrypted data having an associated received type code indicative of a requirement for a secure browser having restricted functionality with respect to a functionality of the normal browser; selectively and automatically invoking the secure browser for handling of the received encrypted data based on the received type code associated with the received encrypted data; receiving the encrypted data with the invoked secure browser for handling thereof, wherein the received encrypted data is not available for use by the user in the normal browser and the invoked secure browser imposes restrictions on availability outside of the secure browser of decrypted data derived from the encrypted data; and communicating an input from the user, through the secure browser, to the at least one cooperative server.