Web Browser Session Timeout Enforcement via Content Concealment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web sessions are susceptible to hijacking and data exposure due to non-expiring sessions on user devices, leading to potential data leaks and unauthorized access, especially when users become inactive and leave their devices unattended.

Innovation Solution

A web browser plugin or built-in functionality that detects user inactivity and temporarily conceals web session content by blanking or shading the web page, using a timer to reset and expire when no activity is detected, ensuring sensitive data is protected without affecting other applications on the desktop.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If web sessions are kept open for extended periods to maintain user information and status, then user convenience and application functionality are improved, but security risks and data exposure vulnerability increase

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by detecting user inactivity and concealing session content before unauthorized access can occur. The automated timeout mechanism proactively hides sensitive information when the user walks away or becomes distracted, preventing potential data exposure while maintaining session functionality during active use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements periodic monitoring of user activity through timers that continuously check for inactivity. The session timeout enforcement occurs periodically at predetermined intervals, automatically concealing content when inactivity thresholds are met and restoring access when user activity is detected, creating a rhythmic security protection cycle.

Inventive Principle:
Principle #19Periodic action

2Object-affected harmful factors

If session timeout is enforced to improve security, then data protection is improved, but user productivity and access continuity deteriorate

Engineering Contradiction:
Improvedata protectionVSAvoiduser productivity
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The session timeout system dynamically adjusts between two states: active and concealed. The content visibility is not static but changes based on real-time user activity detection. When the user returns after inactivity, the system automatically restores access, creating a dynamic balance between security enforcement and user productivity maintenance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system provides self-service by automatically detecting user inactivity and enforcing timeout without requiring manual user intervention. The automated monitoring and concealment processes occur independently, eliminating the need for users to manually log out or manage timeout settings, thus maintaining productivity while ensuring data protection.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If sensitive data is displayed on screen for user interaction, then application functionality is improved, but vulnerability to visual reading by others increases

Engineering Contradiction:
Improveapplication functionalityVSAvoidvisual reading vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies local quality by selectively concealing only the sensitive content areas of the web session while maintaining overall application functionality. The timeout enforcement specifically targets the display content within the web browser window, applying concealment locally to sensitive data regions rather than affecting the entire system or user interface.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses color changes as the concealment mechanism, blanking or shading the web page content when timeout is enforced. This visual transformation changes the appearance of sensitive data from readable text to obscured or blank areas, preventing visual reading by others while maintaining the underlying application functionality for authenticated users.

Inventive Principle:
Principle #32Color changes

Data Source

PatentUS11347900B2Automated web session timeout enforcement
Publication Date: 2022.05.31 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11347900B2 patent drawing
  • US11347900B2 patent drawing
  • US11347900B2 patent drawing

AI summary

An example operation may include one or more of detecting a web session within an open window of a web browser on a user device, monitoring for user activity on the user device with respect to the web browser, determining there has been a lack of user activity with respect to the web browser for a predetermined amount of time based on the monitoring of the user activity, and temporarily concealing content within the open window of the web browser in response to the lack of user activity.