Secure Third-Party Scripting Environment for Application Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software application developers face challenges in securely integrating third-party scripts into their applications due to security concerns and browser dependency, leading to inconsistent user experiences across different browsers.

Innovation Solution

A comprehensive system and method that provides a secure scripting environment, including server-side authentication, access control, and client-side API exposure, allowing third-party scripts to interact with applications while maintaining security and consistency across browsers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party scripts are allowed to enhance application functionality, then user experience and functionality are improved, but application security and consistency deteriorate

Engineering Contradiction:
Improvefunctionality extensionVSAvoidapplication security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a scripting environment as an intermediary layer between third-party scripts and the application. This environment provides authentication, access control, and sandboxing mechanisms that allow scripts to execute safely without compromising application security. The scripting environment acts as a mediator that enables functionality extension while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the application into core application logic and scriptable functionality layers. By separating these concerns and providing a controlled interface through the scripting environment, the system allows third-party scripts to extend functionality without direct access to core application code, thus maintaining security and consistency.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If browser-level scripts are used for functionality extension, then ease of implementation is improved, but cross-browser consistency and reliability deteriorate

Engineering Contradiction:
Improvescript implementationVSAvoidcross-browser consistency
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent transitions from browser-level scripting to application-level scripting by introducing a server-side scripting environment. This dimensional shift moves script execution from the client/browser dimension to the application server dimension, eliminating browser dependency while maintaining ease of script development through standardized APIs and interfaces.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentEP2962195B1Third party application scriptablity
Publication Date: 2019.04.10 GOOGLE LLC
  • EP2962195B1 patent drawingFigure 1
  • EP2962195B1 patent drawingFigure 2
  • EP2962195B1 patent drawingFigure 3

AI summary

A system and method for allowing third-party script developers to create secure scripts that can safely be incorporated into software applications is disclosed. The system may provide the flow and mechanisms for enabling a client/server secure scripting environment to be added to a hosted software application development environment so that third-party scripts can be added to software applications without application developers having to be concerned about protecting their applications from malicious scripts. This scripting environment may allow an application to be securely scriptable by untrusted third-party script developers.