Web View Security Verification for Mobile Apps
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Web Views in mobile applications lack security features, making users vulnerable to phishing and malicious attacks, as they cannot reliably identify the safety of web content or the identity of application owners, leading to compromised user data and privacy risks.
Innovation Solution
Implementing a Web View system that checks trusted data sources using RESTful HTTPS API requests to classify web content and application owners, providing visual indicators or blocking access to unsafe content, and verifying application owner identities through a trusted third-party database.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Web View is used to display web content inside mobile applications, then users can access web content without opening a browser, but security features are lost and users cannot identify the safety of web content or application owners
Solution Approach 1:
The patent introduces a security verification system that acts as an intermediary between the Web View and the web content/application owner. This system includes a security server that receives verification requests from the mobile application, checks the safety of web content and application owner identities against a database of known malicious entities, and returns verification results. This intermediary layer restores security verification capabilities that were lost when using Web View, allowing the system to maintain both integrated access convenience and security reliability.
2Ease of operation
If Web View allows displaying web content without browser features, then integrated user experience is improved, but security indicators and identity verification are removed making users vulnerable to phishing
Solution Approach 1:
The patent implements preliminary security verification by checking the safety of web content and application owner identities before allowing access through the Web View. The security server proactively verifies whether the web content or application owner is on a blocked list or has been identified as malicious, and only then permits the Web View to display the content. This preliminary action prevents phishing and spoofing attacks from succeeding, as malicious entities are identified and blocked before users can be exposed to them, thus protecting users while maintaining the integrated experience.
3Adaptability or versatility
If hybrid applications built around Web View are used, then developers can update content without app updates, but trustworthiness decreases and the Trusted Computing Base is weakened
Solution Approach 1:
The patent implements a feedback mechanism where the security verification system continuously monitors and provides information about the trustworthiness of application owners and web content sources. The system maintains a database of verified application owners and their security credentials, and provides feedback to users through the mobile application interface indicating whether an application owner is trusted or not. This feedback loop restores trust transparency to hybrid applications, allowing users to make informed decisions about which content sources to trust, thus balancing content update flexibility with reliability.
Data Source
AI summary
The present disclosure discloses a method of allowing Web View to verify the security level of a web content and inform the user with regards to the security and blocks web contents that are determined harmful or inappropriate. In one embodiment of the present disclosure, the Web View checks a trusted data source to see if the visited web content has been labeled or flagged as safe or unsafe by initiating a connection to a trusted third-party database using a to determine whether or not the URL is associated with a domain that has been classified or labeled as safe or unsafe. The Web View then informs the user about the security level of the web content through a visual indicator or it can redirect the user to a warning page explaining why access to the site is prohibited, or it can block access without warning.


