Web Data Container Context-Based Security Policy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Emerging markup languages like HTML5 expose end-user platform components to web applications, leading to security concerns as web content may access local data stores without proper authorization, posing risks of unintended or malicious access.

Innovation Solution

A data container system with a web application interface that detects access attempts by web content and enforces context-based security policies using a user profile, multi-user data source, and cloud service to prevent unauthorized access, allowing granular control over access based on content types, sources, and browsing sequences.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If web applications use emerging markup languages like HTML5 to access platform components, then functionality and multimedia capabilities are improved, but security risks increase due to unauthorized access to local data stores

Engineering Contradiction:
Improveweb application functionalityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a data container as an intermediary layer between web applications and local data stores. This container enforces security policies by mediating all access attempts, allowing functional web applications to operate while preventing unauthorized data access through policy-based control mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If web content is allowed to access local data stores without restrictions, then ease of operation is improved, but reliability deteriorates due to unintended or malicious access

Engineering Contradiction:
Improvedata access convenienceVSAvoidaccess authorization
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary action by establishing security policies before any data access occurs. The data container pre-configures access rules based on content type, source, and browsing sequence, automatically enforcing these policies before access attempts can compromise reliability while maintaining ease of operation for authorized access

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a data container system with context-based security policies is implemented, then security reliability is improved, but device complexity increases due to multiple enforcement modules and policy repositories

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the data container as a multi-functional component that simultaneously provides security enforcement, policy management, and access control. This single structure handles multiple security functions that would otherwise require separate systems, reducing overall device complexity while maintaining high reliability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2901361B1Secure data container for web applications
Publication Date: 2017.10.25 INTEL CORP
  • EP2901361B1 patent drawing
  • EP2901361B1 patent drawing
  • EP2901361B1 patent drawing

AI summary

Systems and methods may provide for identifying web content and detecting an attempt by the web content to access a local data store. Additionally, a determination may be made as to whether to permit the attempt based on a context-based security policy. In one example, the context-based security policy is obtained from one or more of a user profile, a multi-user data source and a cloud service.