Web View Security Verification for Mobile Apps

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Web Views in mobile applications lack security features, making users vulnerable to phishing and malicious attacks, as they cannot reliably identify the safety of web content or the identity of application owners, leading to compromised user data and privacy risks.

Innovation Solution

Implementing a Web View system that checks trusted data sources using RESTful HTTPS API requests to classify web content and application owners, providing visual indicators or blocking access to unsafe content, and verifying application owner identities through a trusted third-party database.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Web View is used to display web content inside mobile applications, then users can access web content without opening a browser, but security features are lost and users cannot identify the safety of web content or application owners

Engineering Contradiction:
ImproveIntegrated web content accessVSAvoidSecurity verification capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a security verification system that acts as an intermediary between the Web View and the web content/application owner. This system includes a security server that receives verification requests from the mobile application, checks the safety of web content and application owner identities against a database of known malicious entities, and returns verification results. This intermediary layer restores security verification capabilities that were lost when using Web View, allowing the system to maintain both integrated access convenience and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If Web View allows displaying web content without browser features, then integrated user experience is improved, but security indicators and identity verification are removed making users vulnerable to phishing

Engineering Contradiction:
ImproveIntegrated user experienceVSAvoidPhishing and spoofing attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security verification by checking the safety of web content and application owner identities before allowing access through the Web View. The security server proactively verifies whether the web content or application owner is on a blocked list or has been identified as malicious, and only then permits the Web View to display the content. This preliminary action prevents phishing and spoofing attacks from succeeding, as malicious entities are identified and blocked before users can be exposed to them, thus protecting users while maintaining the integrated experience.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If hybrid applications built around Web View are used, then developers can update content without app updates, but trustworthiness decreases and the Trusted Computing Base is weakened

Engineering Contradiction:
ImproveContent update flexibilityVSAvoidTrust in application source
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a feedback mechanism where the security verification system continuously monitors and provides information about the trustworthiness of application owners and web content sources. The system maintains a database of verified application owners and their security credentials, and provides feedback to users through the mobile application interface indicating whether an application owner is trusted or not. This feedback loop restores trust transparency to hybrid applications, allowing users to make informed decisions about which content sources to trust, thus balancing content update flexibility with reliability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10264016B2Methods, systems and application programmable interface for verifying the security level of universal resource identifiers embedded within a mobile application
Publication Date: 2019.04.16 METACERT INC
  • US10264016B2 patent drawing
  • US10264016B2 patent drawing
  • US10264016B2 patent drawing

AI summary

The present disclosure discloses a method of allowing Web View to verify the security level of a web content and inform the user with regards to the security and blocks web contents that are determined harmful or inappropriate. In one embodiment of the present disclosure, the Web View checks a trusted data source to see if the visited web content has been labeled or flagged as safe or unsafe by initiating a connection to a trusted third-party database using a to determine whether or not the URL is associated with a domain that has been classified or labeled as safe or unsafe. The Web View then informs the user about the security level of the web content through a visual indicator or it can redirect the user to a warning page explaining why access to the site is prohibited, or it can block access without warning.