Server-Mediated Client Application Launch via Agent String Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The detection and launch of client applications on client machines are hindered by disparate security settings across browsers and operating systems, leading to complex and security-compromising nonstandard approaches, such as browser plug-ins and ActiveX controls, which result in unpleasant user experiences and potential security vulnerabilities.
Innovation Solution
A system and method that analyze requests to launch or install applications by extracting an agent string, distributing a formatted document, and causing the application to commence execution, utilizing a server that communicates with clients to determine platform compatibility and user consent, thereby simplifying the detection, launch, and installation process while maintaining security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If nonstandard approaches such as browser plug-ins and ActiveX controls are used to detect and launch client applications, then application launch capability is achieved, but user experience deteriorates due to multiple security dialogs and security compromises
Solution Approach 1:
The patent introduces a server as an intermediary between the web page and the client application. The server receives launch requests from web pages, analyzes them, and distributes formatted documents to clients without requiring direct client-side plug-ins or ActiveX controls. This intermediary approach eliminates the need for multiple security dialogs while maintaining security through server-based authentication and document distribution.
Solution Approach 2:
The patent replaces the mechanical system of browser plug-ins and ActiveX controls with a document-based system. Instead of relying on complex binary components that trigger security dialogs, the system uses formatted documents distributed by a server, which clients process more seamlessly. This substitution eliminates the mechanical complexity and security friction of traditional plug-in approaches.
2Ease of manufacture
If conventional means such as ActiveX controls are used to install applications, then installation capability is achieved, but security is compromised by creating exploit vectors for malicious sites
Solution Approach 1:
The server acts as a secure intermediary that validates and distributes application installation documents. Rather than allowing direct installation from untrusted sources (which creates exploit vectors), the server mediates the process by authenticating requests and distributing only authorized installation documents, thereby eliminating the security vulnerability while maintaining installation capability.
Solution Approach 2:
The system implements feedback mechanisms where the server analyzes launch requests, determines platform compatibility, and selectively distributes formatted documents. This feedback loop ensures that only appropriate clients receive appropriate installation documents, preventing malicious sites from exploiting vulnerable clients while maintaining smooth installation processes.
3Reliability
If browser and operating system security settings are tightened to improve security, then security is improved, but application detection and launch capability deteriorates
Solution Approach 1:
The server serves as a mediator that operates at a higher security level than traditional browser-based approaches. By performing authentication and document distribution server-side, the system can work with tightened client security settings without compromising launch capability. The server handles the security-critical operations, allowing clients to maintain stricter security postures while still enabling application launches.
Data Source
AI summary
The claimed subject matter provides a system and/or method that detects, installs and launches applications on client machines. The disclosed system can include a component that receives a request to launch or install a client application. The component detects whether an application is present in a client machine by scrutinizing the received request and extracting an agent string associated with the client application. Based at least in part on the agent string, a server in receipt of the request can distribute a formatted document affiliated with the client application and thereafter initiate the application to execute on the client machine through MIME-type association.


