Centralized Trust Authority for Web Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for protecting web applications against application-layer attacks are inadequate, particularly due to the lack of effective vetting and verification of third-party web components, leading to vulnerabilities and security risks from compromised or malicious code.

Innovation Solution

A centralized web resource trust authority operates as a cloud service, ingesting, maintaining, and delivering security attributes and integrity information for web objects, using object fingerprinting and vulnerability tracking to identify and classify risks, providing zero-day vulnerability protection and proactive alerts for developers and users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized trust authority analyzes all web resources to generate security profiles, then security protection capability is improved, but system complexity and processing time increase

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments web resources into distinct analyzable units with unique identities, analyzing each resource separately to determine its security attributes. This segmentation allows the complex task of securing entire web applications to be broken down into manageable per-resource security profile generation, improving reliability without overwhelming system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trust authority performs preliminary analysis and generates security profiles for web resources before they are deployed or used in web applications. By conducting security assessments in advance and maintaining updated security attributes, the system ensures protection capability is established proactively rather than reactively, addressing security concerns before they manifest as vulnerabilities

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If security profiles are generated for all third-party web resources, then vulnerability detection is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Security profiles and vulnerability assessments are generated in advance for third-party web resources before they are integrated into web applications. The trust authority maintains updated security attributes and risk factors beforehand, allowing for rapid vulnerability detection without requiring time-consuming analysis at the point of use

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates security profiles as simplified representations or copies of the actual web resources, capturing essential security attributes and risk factors without requiring the full resource to be re-analyzed each time. These profile copies enable fast vulnerability detection by comparing against known security criteria without processing the complete original resources repeatedly

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11336676B2Centralized trust authority for web application components
Publication Date: 2022.05.17 TALA SECURITY INC
  • US11336676B2 patent drawing
  • US11336676B2 patent drawing
  • US11336676B2 patent drawing

AI summary

Techniques to facilitate operation of a centralized trust authority for web application components are disclosed herein. In at least one implementation, a plurality of web resources used to construct web applications is received. Over a secure application programming interface (API), component registration information associated with each of the plurality of web resources is received, provided by producers of the web resources. The plurality of web resources is analyzed to determine unique identities and security attributes for each of the web resources. A plurality of security risk factors is identified for each of the plurality of web resources based on the component registration information and the security attributes determined for each of the web resources. A security profile is generated for each of the plurality of web resources based on the security risk factors identified for each of the web resources.