Web View Security Module for Mobile Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices lack effective security measures to identify and prevent malicious attacks when using web view functionality, making users susceptible to phishing and other fraudulent activities due to the absence of browser-like blacklisting capabilities.

Innovation Solution

A security system that monitors web view activities, identifies risk indications associated with resource pages, and implements security measures such as intercepting or blocking potentially malicious pages by cross-referencing information with a database of risk flags and threat feeds.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If web view functionality is implemented in mobile applications, then users can access web pages within applications, but users become susceptible to malicious attacks and phishing due to lack of security measures

Engineering Contradiction:
Improveweb view functionalityVSAvoidmalicious attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security module as an intermediary component between the web view functionality and the user's device. This security module intercepts and analyzes web page requests, checks them against threat feeds and risk flags, and determines whether to allow rendering. The security module acts as a mediator that enables web viewing capability while filtering out malicious content, thus resolving the contradiction between functionality and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If applications render web pages without security checks, then web content can be displayed freely, but fraudulent techniques can harm mobile device users

Engineering Contradiction:
Improveweb page renderingVSAvoiduser security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary security actions by checking web pages against threat feeds and risk flags before they are rendered in the web view. The security module proactively identifies potentially malicious content and prevents it from being displayed to the user. This preliminary verification ensures that only safe content reaches the user, maintaining both ease of operation and reliability.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If mobile devices lack browser blacklisting capabilities, then applications can access any web content, but users cannot identify malicious websites

Engineering Contradiction:
Improveweb content accessVSAvoidmalicious website identification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements a feedback mechanism where the security module continuously monitors web page requests, compares them against updated threat feeds and risk flags, and provides real-time security assessments. The system learns from new threats and updates its blocking decisions accordingly. This feedback loop enables the system to identify and block malicious websites while maintaining access to legitimate content.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11086990B2Security module for mobile devices
Publication Date: 2021.08.10 PAYPAL INC
  • US11086990B2 patent drawing
  • US11086990B2 patent drawing
  • US11086990B2 patent drawing

AI summary

A computer system detects an action corresponding to a resource page being rendered within a web view of an application. In response to the detecting the action corresponding to a resource page being rendered within the web view of the application, the computer system identifies information associated with the resource page and determines if one or more risk indications correspond to the identified information. In response to determining that one or more risk indications correspond to the identified information, the computer system implements one or more security measures.