Web Cookie Firewall for Selective Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in maintaining control over the use of web cookies on computing devices while preserving users' privacy, as existing technologies lack effective mechanisms to selectively manage and filter web cookies based on security policies.

Innovation Solution

A web cookie firewall application and service that monitor and control web cookies by implementing web cookie security policies, allowing or prohibiting storage or use based on domain, type, name, and content, using machine learning models to identify cookie types and attributes, and enabling centralized policy configuration and deployment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If web cookies are blocked to improve security, then data security is improved, but user privacy and web activity freedom are restricted

Engineering Contradiction:
Improvedata securityVSAvoiduser privacy and web activity freedom
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments web cookies into different categories (first type cookies like session/auth cookies that are blocked, and second type cookies like personalization cookies that are allowed). This segmentation enables selective blocking based on cookie type, domain, and attributes, thereby improving security by blocking harmful cookies while preserving user privacy and experience by allowing benign cookies.

Inventive Principle:
Principle #1Segmentation

2Reliability

If web cookie filtering is implemented to improve security control, then organizational control is improved, but device compatibility and implementation complexity increase

Engineering Contradiction:
Improveorganizational controlVSAvoidimplementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal web cookie firewall application that can be deployed across diverse computing devices (desktops, laptops, mobile devices) and web browsers. The application provides multi-functional capabilities including cookie blocking, allowing, modification, and policy enforcement, thereby achieving organizational control without requiring device-specific solutions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces a web cookie firewall application as an intermediary component between the web browser and web servers. This intermediary intercepts and evaluates web cookies before they are stored or transmitted, applying organizational policies without requiring changes to the browser or server infrastructure, thus simplifying implementation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If machine learning models are used to identify cookie types, then cookie classification accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvecookie classification accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent employs machine learning models to pre-train and classify cookie types offline, creating classification rules and patterns in advance. During runtime, the web cookie firewall application applies these pre-established classification rules to quickly identify and categorize cookies, thereby achieving high classification accuracy without significant processing delays during web browsing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12132704B1Web cookie firewall
Publication Date: 2024.10.29 AMAZON TECH INC
  • US12132704B1 patent drawing
  • US12132704B1 patent drawing
  • US12132704B1 patent drawing

AI summary

Techniques are described for providing a web cookie firewall application capable of monitoring and controlling the use of web cookies at computing devices. The web cookie firewall application uses web cookie security policies to selectively allow or prohibit the storage or use of individual web cookies or types of web cookies. For example, web cookie security permissions can be defined by such policies to permit or deny the storage or use of web cookies associated with certain website domains, to permit or deny the storage or use of defined types of cookies, or to control access to web cookies based on other attributes. The web cookie firewall application can be implemented as a standalone application, as a web browser plugin or extension, or as any other type of software application that it is capable of monitoring and controlling the use web cookies on a computing device.