Enterprise browser system

The browser system addresses the challenges of costly and complex web browser management by integrating a policy engine for real-time enforcement and user authentication, enhancing security and control over data handling and user actions.

JP2025131812APending Publication Date: 2025-09-09ISLAND TECH INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025098212
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2021-05-10
Filing Date
2025-06-12
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

Existing web browser management solutions for organizations are costly, complex, lack visibility, and often hinder user productivity while failing to prevent unauthorized data transmission and malware.

Method used

A browser system with an integrated policy engine that enforces policies on web browser actions, user authentication, and data handling, allowing real-time policy evaluation and encryption, and includes an auditor for monitoring and reporting user actions.

Benefits of technology

Enhances security and control over web browser usage, preventing unauthorized data transmission and malware, while maintaining user efficiency by integrating policy enforcement directly within the browser.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025131812000001_ABST
    Figure 2025131812000001_ABST
Patent Text Reader

Abstract

To provide a web browser system that executes operation based on a policy.SOLUTION: A web browser includes a browser rendering engine configured to send and receive data via a computer network 110, and a policy engine configured to implement one or more policies configured to control any aspect of the web browser, data, a computer that hosts the web browser, and any devices that are accessible to the computer. The web browser is configured as an executable file that is created by compiling computer software instructions that implement the browser rendering engine and the policy engine. The web browser is configured to require a user of the web browser to be authenticated and one or more policies to be validated before the web browser is allowed to perform one or more predefined operations.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present invention relates to a browser system for businesses. [Background technology]

[0002] Web browsers are among the most widely used computer software applications. Organizations, including commercial enterprises and government agencies, increasingly rely on the use of web browsers to operate on their behalf. Organizations that wish to control web browsers, such as to audit their use and prevent the downloading of malware or the transmission of sensitive information outside the organization, are typically forced to implement various measures external to the web browser, such as on the computer hosting the web browser and on the network infrastructure with which the web browser communicates. Unfortunately, such measures are often costly and complex to configure and manage, lack visibility into all aspects of the web browser's inner workings, can hinder web browser users from efficiently accomplishing work tasks, and very often thwart attempts to circumvent them. Summary of the Invention

[0003] In one aspect of the invention, a web browser includes a browser rendering engine configured to send and receive data over a computer network, and a policy engine configured to implement one or more policies configured to control any aspect of the web browser, the data, a computer hosting the web browser, and devices accessible to the computer, the web browser being configured as an executable file created by compiling computer software instructions for implementing the browser rendering engine and the policy engine, and the web browser being configured to require authentication of a user of the web browser and verification of one or more policies before being allowed to perform one or more predefined actions.

[0004] In another aspect of the invention, each of the policies includes one or more policy conditions and one or more policy enforcement actions that are performed when the policy conditions are met.

[0005] In another aspect of the invention, the web browser is configured to receive the policy from a source external to the web browser, the policy being encrypted for decryption using a decryption key uniquely associated with an identity associated with a user of the web browser, the decryption key being provided to the web browser after the user has been authenticated.

[0006] In another aspect of the invention, the web browser is configured to receive browser settings associated with the authenticated user from the source, the browser settings being encrypted for decryption using the decryption key.

[0007] In another aspect of the invention, the web browser is configured to at least partially evaluate any policies that apply to the data in parallel with receiving the data.

[0008] In another aspect of the invention, the web browser is configured to at least partially evaluate any policies that apply to the data in parallel with receiving the data and providing any portion of the data to the browser rendering engine.

[0009] In another aspect of the invention, any of the policies includes a policy condition related to a category associated with a website accessed by the web browser.

[0010] In another aspect of the invention, any of the policies includes a policy condition related to a risk level associated with a website accessed by the web browser.

[0011] In another aspect of the invention, any of the policies includes a policy condition related to any characteristic of the computer hosting the web browser.

[0012] In another aspect of the invention, any of the policies includes a policy condition related to any characteristic of the identity of the user of the web browser.

[0013] In another aspect of the invention, any of the policies includes a policy condition related to any characteristic of the identity of a network accessible to the web browser.

[0014] In another aspect of the invention, any of the policies includes a policy condition related to the source of a uniform resource locator (URL) provided to the web browser.

[0015] In another aspect of the invention, any of the policies includes a policy enforcement action that requires one of data loss prevention (DLP), anti-virus, or anti-malware techniques to be performed on the data.

[0016] In another aspect of the invention, any of the policies includes a policy enforcement action that requires the data to be modified or manipulated before being rendered or provided to the user.

[0017] In another aspect of the invention, any of the policies includes a policy enforcement action that requires converting the data from a first format to a second format that removes at least a portion of the data, and then converting the converted data back to the first format before rendering the data or providing the data to the user.

[0018] In another aspect of the invention, any of the policies include policy enforcement actions that require control of client-side user interactions with the website.

[0019] In another aspect of the invention, any of the policies includes a policy enforcement action that requires hiding a browser tab that has been closed by the user and revealing the hidden browser tab the next time the user attempts to access a website or other content associated with the hidden browser tab.

[0020] In another aspect of the invention, any of the policies includes a policy enforcement action that calls for disabling a predefined application programming interface (API) of the web browser.

[0021] In another aspect of the invention, any of the policies include a policy enforcement action that requires either disabling, hiding, or masking predefined elements of the web page.

[0022] In another aspect of the invention, the web browser further includes an auditor configured to record any actions attempted or performed by the user when using the web browser.

[0023] In another aspect of the invention, the web browser further includes an auditor configured to record any actions attempted or performed by the web browser when the web browser is used by the user.

[0024] In another aspect of the invention, the web browser further includes an auditor configured to record any network activity detectable by the web browser.

[0025] In another aspect of the invention, the web browser is specially configured to operate with one or more target applications.

[0026] In another aspect of the invention, the policies are specifically adapted for use with the one or more target applications.

[0027] In another aspect of the invention, any of the above policies are defined and enforced using robotic process automation (RPA) technology.

[0028] The web browser is configured to implement multiple different profiles that are isolated from one another, each with its own unique data, such as policies, cookies, cache, local storage, etc., and the different profiles are associated with different concurrently displayed browser tabs, different concurrently running processes, and different concurrently running browser instances. [Brief explanation of the drawings]

[0029] Aspects of the present invention will be more fully understood and appreciated from the following detailed description read in conjunction with the accompanying drawings, in which:

[0030] [Figure 1] 1 is a simplified conceptual diagram of an enterprise browser system constructed and operative in accordance with one embodiment of the present invention; [Figure 2]2 is a simplified flowchart illustrating an exemplary method of operation of the system of FIG. 1 , operated in accordance with one embodiment of the present invention. [Figure 3A] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 3B] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 3C] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 3D] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 3E] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 3F] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 3G] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 3H] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 3I] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 3J] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 3K] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 3L] FIG. 2 is a simplified conceptual diagram of an exemplary policy configuration screen, constructed and operative in accordance with an embodiment of the present invention. [Figure 4A]6 is a set of exemplary code snippets illustrating various methods used in implementing policies, constructed and operative in accordance with an embodiment of the present invention; [Figure 4B] 6 is a set of exemplary code snippets illustrating various methods used in implementing policies, constructed and operative in accordance with an embodiment of the present invention; [Figure 4C] 6 is a set of exemplary code snippets illustrating various methods used in implementing policies, constructed and operative in accordance with an embodiment of the present invention; [Figure 5A] 1 is a simplified conceptual diagram of a cloud integration methodology constructed and operative in accordance with an embodiment of the present invention; [Figure 5B] 1 is a simplified flow diagram illustrating a browser login method constructed and operative in accordance with an embodiment of the present invention. [Figure 6] 1 is a simplified flow diagram illustrating a method for establishing a private browsing session, constructed and operative in accordance with an embodiment of the present invention. [Figure 7A] 1 is a simplified flow diagram illustrating a method for defining and distributing policies, constructed and operative in accordance with an embodiment of the present invention. [Figure 7B] 1 is a simplified example illustrating enforcement of policy definitions, constructed and operative in accordance with an embodiment of the present invention; [Figure 7C] 1 is a simplified example illustrating enforcement of policy definitions, constructed and operative in accordance with an embodiment of the present invention; [Figure 7D] 1 is a simplified example illustrating enforcement of policy definitions, constructed and operative in accordance with an embodiment of the present invention; [Figure 8A] FIG. 2 is a simplified conceptual diagram of an illustrative auditor configuration screen, constructed and operative in accordance with one embodiment of the present invention. [Figure 8B] 1 is a simplified conceptual diagram of an exemplary audit reporting system constructed and operative in accordance with an embodiment of the present invention; [Figure 9A]1 is a simplified flow diagram illustrating a method for enforcing the use of a web browser by using an identity provider, constructed and operative in accordance with an embodiment of the present invention. [Figure 9B] 1 is a simplified flow diagram illustrating a method for enforcing web browser usage by using a password vault, constructed and operative in accordance with one embodiment of the present invention. [Figure 9C] 1 is a simplified flowchart illustrating a method for enforcing web browser usage by using network tunneling, constructed and operative in accordance with an embodiment of the present invention. [Figure 10A] 6A-6C are exemplary code snippets illustrating various methods for extending web browser extension access, constructed and operative in accordance with an embodiment of the present invention. [Figure 10B] 6A-6C are exemplary code snippets illustrating various methods for extending web browser extension access, constructed and operative in accordance with an embodiment of the present invention. [Figure 11] 10 is an exemplary code snippet illustrating how to configure a proxy for use in embodiments of the present invention. [Figure 12A] 1 is a simplified flow diagram illustrating a method for using a web browser with a virtual private network (VPN), constructed and operative in accordance with an embodiment of the present invention. [Figure 12B] 1 is a simplified flow diagram illustrating a method for using a web browser with a cloud connector, constructed and operative in accordance with an embodiment of the present invention. [Figure 12C] 1 is a simplified flow diagram illustrating a method for using a web browser with a cloud connector, constructed and operative in accordance with an embodiment of the present invention. [Figure 13] 1 is a simplified diagram illustrating separation boundaries and multi-profile support, constructed and operative in accordance with an embodiment of the present invention; DETAILED DESCRIPTION OF THE INVENTION

[0031] Reference is now made to Figure 1, which is a simplified conceptual diagram of an enterprise browser system constructed and operative in accordance with one embodiment of the present invention. In Figure 1, web browser 100 comprises a browser rendering engine 101 configured to incorporate the functionality of a conventional web browser, such as a web browser based on the Google® Chromium® architecture, e.g., functionality for sending and receiving data over a computer network and rendering data such as web pages, except and / or in addition to functionality described elsewhere herein. Web browser 100 includes a policy engine 102 configured to implement policies 104 for controlling any aspect of web browser 100, such as, but not limited to, browser rendering engine 101, its user interface, JavaScript® interpreter, extensions, networking settings, and data persistence. For example, policy engine 102 may be configured to implement policies 104 by enabling or disabling extensions, controlling extension permissions, controlling local client cache and cookies, controlling user actions such as copying, pasting, printing, saving files, taking screenshots, and controlling communications between web browser 100 and any devices, such as peripheral devices, accessible to the computer hosting web browser 100. Policies 104 are configured to relate to various types of information, including, but not limited to, device posture associated with the computing device hosting or interacting with web browser 100, the identity of a computer user interacting with web browser 100, web pages and other data accessed or provided by web browser 100, networking information both on the local computer network of web browser 100 and on external computer network locations accessible to web browser 100, and the behavior of the computer user when using web browser 100.For example, policy 104 may be configured to depend on antivirus software or other types of software or operating system processes on the computing device hosting web browser 100, the presence, absence, or status of certain registry data and certificates, and whether web browser 100's network access is via mobile, WIFI, or wired connection, and from which network domain or address.

[0032] Web browser 100 is configured to provide policy engine 102 with any information necessary to evaluate policy 104. Some examples of such information necessary to evaluate policy 104 and actions that may be performed by policy engine 102 to implement policy 104 include the following: In one example, policy engine 102 disables a particular browser application programming interface (API), such as to protect the API from known exploits, if web browser 100 accesses a website with a reputation score below a predefined minimum score; such reputation score may be determined according to conventional techniques. In another example, policy engine 102 censors certain content on the retrieved web page, such as by applying a predefined regular expression to the document object model (DOM) of the web page, to find personally identifiable information (PII) and then hides or masks such information. In another example, if web browser 100 is configured to monitor use of a user interface sharing feature, policy engine 102 may report certain events to an analytics database or security operations center (SOC), such as when a user performs the action "share document" in Google® Docs®, even if Google® Docs® does not provide an application programming interface (API) for such actions. In another example, web browser 100 is configured to monitor code execution engine 106, which is integrated into web browser 100 to execute JavaScript® code or other software instructions, and policy engine 102 reports anomalous behavior identified by policy 104, such as poor performance characteristics and buffer overrun attempts. In another example, web browser 100 is configured to detect certain types of upload or download events, which policy engine 102 reports in accordance with policy 104.

[0033] Web browser 100 may be hosted by any computing device, such as computer 108, connected to computer network 110, which may be a corporate intranet that provides access to one or more other networks 112, such as the Internet. Copies of web browser 100 may be installed on multiple computing devices, company-owned or non-company-owned, for use by individuals associated with an organization, such as company employees or contractors, and configured to be operated as described herein by system administrators and / or other parties authorized by the organization to enforce policies established by the organization.

[0034] Web browser 100 is preferably configured to require each user of web browser 100 to be authenticated before web browser 100 is permitted to perform one or more predefined actions, e.g., each time web browser 100 runs and / or periodically thereafter, such as at predefined time intervals, and / or before web browser 100 performs one or more predefined actions such that web browser 100 requires re-authentication of the user. Web browser 100 is also preferably configured to verify one or more signed and / or encrypted policies 104 before web browser 100 is permitted to perform one or more predefined actions.

[0035] The management console 114 is provided to allow system administrators and / or other authorized parties to define policies 104 and provide the policies 104 to the web browser 100. The management console 114 may be hosted by any computing device, such as a computer 116, that communicates with the web browser 100 directly via the computer network 110 or indirectly via the network 112.

[0036] In one embodiment of the present invention, one or more instances of web browser 100 are configured to operate specifically with one or more target applications, such as WhatsApp®, Salesforce®, or other applications. Such configuration may be completed via management console 114 by providing specially configured web browser 100 with the target application's uniform resource locator (URL), icon, and executable file name, which provides specially configured web browser 100 and installation file 118 containing the above elements, in accordance with conventional techniques. Installation file 118 is then deployed and installed on the computing device in accordance with conventional techniques. In this embodiment, each specially configured web browser 100 includes all of the functionality of web browser 100 described herein, but may have user interface elements specifically adapted for use with that target application, and / or may restrict access to certain target application functionality, such as by blocking file sharing, where web browser 100 is specifically configured to operate with WhatsApp®, and / or may have policies specifically adapted for use with the target application.

[0037] In one embodiment of the present invention, web browser 100 includes an auditor 120 configured to record and / or report certain data and / or metadata related to users, websites, applications, networking, JavaScript and API usage, HTML and DOM information, policy-related information, and enforcement activity, as described in more detail herein below.

[0038] Web browser 100 is preferably configured as an executable file created in accordance with conventional techniques by compiling computer software instructions to implement any of the functionality of a conventional web browser as well as any of the functionality of web browser 100 described herein, including anything else described herein that comprises web browser 100 (e.g., but not limited to, policy engine 102, policies 104, and auditor 120).

[0039] Reference is now made to Figure 2, which is a simplified flowchart illustrating an exemplary method of operation of the system of Figure 1 operating in accordance with one embodiment of the present invention. In the method of Figure 2, an organization's system administrator uses an administrative console, such as administrative console 114 of Figure 1, to define one or more policies for controlling web browsers, such as web browser 100 of Figure 1, provided by the organization for the benefit of the organization, such as its employees or contractors (step 200). The policies are then encrypted for later decryption using a decryption key uniquely associated with the organization (step 202). The encrypted policies are stored in one or more data storage devices accessible to the organization's web browsers, such as by providing them to a cloud-based storage service (step 204). After the user of the web browser is authenticated and identified as acting on behalf of the organization (step 206), the user's web browser receives the organization's decryption key (step 208). The user's web browser receives the encrypted policies from the storage location (step 210), decrypts them using the organization's decryption key (step 212), and enforces the policies (step 214).

[0040] 3A-3L, which are simplified conceptual diagrams of exemplary policy configuration screens, such as may be provided by management console 114 for defining policy 104 of FIG. 1, constructed and operative in accordance with an embodiment of the present invention. Policy 104 includes policy conditions and associated policy enforcement actions that are executed when the associated policy conditions are met. In FIG. 3A, screen 300 illustrates various types of information based on the source location of web browser 100 that may be specified for policy conditions associated with policy 104, such as identity information associated with the user of web browser 100, information associated with the configuration or other characteristics of the computing device hosting web browser 100, information about computer networks accessible by web browser 100, the current geographic location of web browser 100, and the current date and time of web browser 100. FIG. 3B shows a subsidiary screen 302 of screen 300 in which required identity-related information can be specified for policy 104, such as by specifying user information, group information, role information, and custom information requirements, including identity-related information that can be determined using, for example, a Security Assertion Markup Language (SAML) query, in accordance with conventional techniques. FIG. 3C shows a subsidiary screen 304 of screen 300 in which required device information can be specified for policy 104, such as by specifying the type of operating system hosting web browser 100 and any other device-related information that can be determined using, for example, a Windows Management Instrumentation (WMI) query, in accordance with conventional techniques. FIG. 3D shows an example illustrating how a WMI query surface can be exposed to extensions. FIG. 3E shows a subsidiary screen 306 of screen 300 in which required network information can be specified for policy 104, such as by specifying valid and invalid IP address information, WiFi type, and any other network-related information that can be determined in accordance with conventional techniques.

[0041] In FIG. 3F , screen 308 illustrates various types of information associated with information submitted by web browser 100 and query destinations that may be specified for policy 104, such as information about applications with which web browser 100 communicates and URLs accessed by web browser 100, all of which may be determined according to conventional techniques, as well as website category information, website reputation information, network information, and location information. Examples of such information include one or more destination names, IP addresses, and URLs, such as specifying URL patterns using regular expressions and wildcards. URL context information may also be specified. For example, policy 104 may be configured to allow web browser 100 to access salesforce.com while blocking access to unknown URLs or IP addresses, or policy 104 may be configured to allow web browser 100 to access unknown destinations redirected by salesforce.com. Another URL context may be defined, for example, when a user clicks on a link in an email in an external email application, and the initial URL accessed in the browser tab is not the one the user entered using the keyboard, phishing protection may then be implemented. Examples of destination website categories may include "business," "bandwidth consumption," "risk," "unknown," "personal / private," "social network," "legal liability," etc. The management console 114 may be used to define destination IP addresses and address ranges, website URLs, regular expressions, Software as a Service (SaaS) application selections, and website categories, or may refer the web browser 100 to back-end services that provide threat intelligence and third-party website category providers, such as WebRoot®, Cyren®, or Google® Risk API, and website categories may be defined at the full URL level, the domain name level, or any level in between.The reputation of a website may be determined by querying a third-party website reputation provider or by applying predefined heuristics that analyze the website's behavior according to conventional techniques. Examples of destination network information include its IP address and subnetwork.

[0042] FIG. 3G shows a screen 310 for associating source and destination information representing policy conditions of a policy with an audit profile, which defines the policy enforcement actions to be performed when the specified policy conditions are met and the audit actions to be performed in conjunction with the defined policy. FIG. 3H shows a screen 312 for defining a data loss prevention (DLP) profile, which indicates the policy enforcement actions to be performed when a file upload is performed, such as scanning the file for credit card numbers and blocking the upload if a credit card number is found in the file. FIG. 3I shows a screen 314 for defining the policy enforcement actions to be performed when a file upload or download is performed based on the file type. FIG. 3J shows a screen 316 for defining a file download protection profile, which indicates the policy enforcement actions to be performed when a file download is performed, such as performing multiple types of anti-malware scans on downloaded files.

[0043] In one embodiment, policy conditions and enforcement actions are defined using conventional robotic process automation (RPA) techniques. In one embodiment, policy conditions and enforcement actions are obtained from a third-party vendor in the form of RPA modules and optionally modified using management console 114 (FIG. 1), where the RPA modules include policy conditions, policy enforcement actions, or both. FIG. 3K shows a screen 318 listing various types of RPA modules for selection. In one embodiment, policy conditions and / or enforcement actions are defined using a scripting language such as JavaScript, an example of which is shown in FIG. 3L.

[0044] In addition to the types of information described above that may be used to define policy conditions (e.g., device posture, identity, URL categories, networking information, computer user behavior), examples of such policy conditions include: a given result of a JavaScript function; - detecting a data download or upload event; The source of the URL provided to the web browser (e.g., typing the URL into the browser's address bar, selecting the URL from bookmarks, clicking a link in an external application, or being redirected from a visited web page).

[0045] Examples of policy enforcement actions include: -Masking certain content on a given website (e.g., masking PII when visiting salesforce.com); - disable screenshot functionality for the current website if it provides predefined types of sensitive data; -Blocking access to the "Share" button in Microsoft PowerPoint® on office365.com; - Adding a watermark with the current username to a specific web page (e.g. gmail.com) or a given document; Adding a red border when accessing websites that meet predefined security criteria (e.g., have predefined characteristics associated with suspicious websites); -Blocking the message forwarding feature on web.whataspp.com and -Mask credit card numbers and provide an "unmask" button that allows the masked information to be displayed; Redirecting outbound HTTP requests to an intermediate proxy service that controls what and how is sent back from the intended recipient of the HTTP request; and - Reducing the connection speed, for example by requesting lower quality content from the video stream; - modifying the security permissions of the current browser session or a specific browser tab, for example by launching a specific browser process with lower OS privileges when accessing unknown websites; -Automatically locking certain websites using a protective screen that requires additional authentication not required by the website, and / or locking certain browser tabs when entering or exiting them; -Automatically loading certain websites, such as corporate email websites, when your browser is running; A user may hide a closed browser tab rather than closing it, and then reveal the hidden tab the next time the user attempts to access a website or other associated content associated with the hidden tab.

[0046] Policies may be defined and applied to protect sensitive data and may be triggered, for example, by detecting an attempt to copy, cut, paste, save, or print data, or by detecting a specific web page element, or by accessing a specific website, or by detecting an attempt to submit data to a website via an HTML form. Sensitive data may be identified using a predefined list of data types and formats, such as credit card number formats or Social Security number formats, or by using predefined regular expressions. Sensitive data identified according to conventional techniques may be protected, for example, by masking, redacting, or obscuring the sensitive data. Sensitive data protection may be performed by a web browser, a web browser extension, or an RPA module, or may be performed on a remote computer.

[0047] Policies may be defined and applied when an attempt to upload or download a file or other data is detected. In one example, the download or upload attempt may be allowed without taking any action. In another example, the download or upload attempt may be blocked and a message indicating the download or upload attempt was blocked may be displayed. In another example, one or more known types of scans of the target file may be performed, such as a scan to detect malware and prevent disclosure of sensitive data, and one or more known types of post-scan actions may be performed if associated conditions are met, such as quarantining the file with the file stored in a local or remote location, deleting the file, etc. The scan may be performed by a web browser, browser extension, or RPA module, or may be performed on a remote computer. If the file is encrypted, a visual prompt may be provided to allow the user to enter a decryption key or password so that the file can be decrypted before scanning. In one embodiment, policies associated with an attempt to upload or download a file or other data are evaluated, partially or entirely, in parallel with the upload or download, if possible. For example, while a web page is being retrieved, the retrieved portions of the web page, e.g., HTML, JavaScript code, style sheets, may be provided to browser rendering engine 101 (FIG. 1), and policy engine 102 evaluates the policy conditions of the policies associated with the web page retrieval to determine whether the web page or any of its elements needs to be blocked or modified before browser rendering engine 101 displays the rendered web page.

[0048] Policies may be defined to control where and how downloaded files are stored. For example, downloaded files may be stored on the local file system or in a predefined remote location. Downloaded files may be encrypted using known encryption techniques before being stored, for example, based on the downloading user's identity, thus preventing other users of the same web browser from decrypting the file. Downloaded files may also be subjected to one or more conversions to other file formats, for example, from JPEG to PNG and back again to remove potentially malicious portions before rendering the file or providing it to the user.

[0049] 4A-4C, which are illustrative code snippets illustrating various methods used to implement policies that may be applied by the policy engine 102 to enforce the policy 104 of FIG. 1, constructed and operative in accordance with an embodiment of the present invention. FIG. 4A shows a code snippet illustrating policy matching operations using rules, matchers, and a built-in cache. The code accepts a policy object and a browser context object that provides current browser context information. The browser context object provides information related to the current browser context and preferably comprises fields and values ​​indicating, for example, the top-level URL of the currently accessed website (e.g., Dropbox.com), the current URL of the request (e.g., CDN.Internal.Dropbox.com), the user ID, the tab ID of the associated browser tab, the browser version, the source IP address of the request, device information, identity information, etc. FIG. 4B shows a code snippet illustrating website category matching. FIG. 4C shows a code snippet illustrating an upload profile associated with a policy that is applied to an uploaded file, for example, by scanning the uploaded file for malware or by performing data loss prevention (DLP) techniques.

[0050] Reference is now made to Figure 5A, which is a simplified conceptual diagram of a cloud integration methodology, constructed and operative in accordance with one embodiment of the present invention. In Figure 5A, a web browser 500, which may be hosted by a computing device such as a mobile phone, is configured as described hereinabove with reference to the web browser 100 of Figure 1, but the policy enforcement functions of the policy engine 102 that enforces the policies 104 are performed by both the web browser 500 and a computer server 502, such as a cloud-based server, that communicates with the web browser 500 over a computer network 504, such as the Internet. Network requests to the cloud, if required to execute the policies (e.g., to categorize a URL), may be implemented synchronously (e.g., as a blocking HTTP call), asynchronously (e.g., as a non-blocking HTTP call that allows the normal flow of the web browser 500 to continue executing, with a callback that applies the policy results after they are returned), or via the Web Sockets protocol.

[0051] Reference is now made to Figure 5B, which is a simplified flow diagram illustrating a browser login methodology constructed and operative in accordance with one embodiment of the present invention. In Figure 5B, a web browser 510, configured as described hereinabove with reference to, for example, web browser 100 of Figure 1, initiates silent single sign-on (SSO) or single sign-on (SSO) in step #1 by interacting with an identity provider (IdP) 512, which is configured to provide user authentication services to a user of the web browser 510. In step #1, user authentication information, such as a user login name known to IdP 512, is provided to IdP 512. In step #2, after authenticating the user authentication information, IdP 512 provides a JSON Web Token (JWT) to web browser 510, the JWT including information identifying an IdP tenant known to IdP 512 as being associated with the provided user authentication information; for example, the tenant may be a company or other organization associated with the user. In step #3, web browser 510 sends the JWT to cloud server 516 and requests a decryption key uniquely associated with the tenant from, for example, a key management service 514 hosted by cloud server 516, and cloud server 516 validates the JWT and identifies the user and tenant. In step #4, after validating the JWT and identifying the tenant and user, key management service 514 provides the tenant decryption key to web browser 510. In step #5, web browser 510 requests policies defined for the tenant, preferably encrypted, from policy storage service 518. In step #6, web browser 510 decrypts the encrypted policies using the decryption key for enforcement. In one embodiment, cloud server 516 stores browser settings associated with the authenticated user, such as, but not limited to, passwords, credit cards, user profile settings, and bookmarks, and provides these browser settings to web browser 510, preferably in encrypted form for decryption by web browser 510 using the tenant decryption key.

[0052] Reference is now made to Figure 6, which is a simplified flow diagram illustrating a method for establishing a private browsing session, constructed and operative in accordance with one embodiment of the present invention. Figure 6 illustrates a URL filtering policy being enforced in a non-blocking manner. In step #1, a web browser 600, configured as described above in this specification with reference to web browser 100 of Figure 1, attempts to access a website via a computer network 602, such as the Internet. In step #2, while web browser 600 receives a response from the website, web browser 600 instructs policy engine 604, configured as described above in this specification with reference to policy engine 102 of Figure 1, to determine whether a policy exists indicating that a private browsing session should be established for the accessed website, e.g., with the following private indicator for the following website if: -If the website category is categorized as "Personal Email" or "Healthcare Providers" - if the website is not a business-related website and such information is provided by a third-party website category provider or in a predefined list of all websites and applications used by an organization whose policies are enforced by web browser 600; -Websites whose IP addresses are not associated with any organization; -Websites accessed by devices not belonging to your organization, -Private indicators are essentially audit verdicts that can be applied to any combination of proposed rules.

[0053] Any policy may be accompanied by an indicator that a private browsing session will be established if the conditions of the policy are met. In step #3, after policy engine 604 determines that the accessed website is a private website, web browser 600 displays a visible indication that the accessed website is a private website, displays information retrieved from the private website, and applies the security controls indicated by policy engine 602 without storing any information related to accessing or interacting with the private website in data lake 606 or the like.

[0054] Reference is now made to FIG. 7A, which is a simplified flow diagram illustrating a method for defining and distributing policies, such as policy 104 of FIG. 1, constructed and operative in accordance with one embodiment of the present invention. In step #1, an authorized system administrator, for example, uses management console 700 to define various policies, including policy conditions to be evaluated and policy enforcement actions to be taken if the policy conditions are met, for example, in policy engine 102 of FIG. 1. Policies may be defined using the screens described above with reference to FIGS. 3A-3L. In one embodiment, management console 700 encrypts and signs the policy definitions in a specific manner, for example, specific to a given installation of web browser 704 or specific to a particular identity, such as an organization and an individual associated with the organization, and web browser 704 is configured as described above with reference to web browser 100 of FIG. 1. In step #2, management console 700 provides the policy definitions to a data store 702 accessible to web browser 704, for example, over a computer network. In step #3, web browser 704 periodically and asynchronously retrieves policy definitions applicable to it from data store 702. In step #4, the retrieved policy definitions are decrypted and made available to the policy engine of web browser 704 configured as described herein above with reference to policy engine 102 of Figure 1. In step #5, the retrieved policy definitions are checked and enforced.

[0055] An illustrative example of the enforcement of policy definitions is shown with further reference to Figures 7B-7D. In Figure 7B, a telephone number is displayed on a web page retrieved by web browser 704. Before web browser 704 displays the web page, it evaluates and enforces the policy definitions shown in Figure 7C, after which web browser 704 displays the web page with the masked telephone number, as shown in Figure 7D.

[0056] Reference is now made to Figure 8A, which is a simplified conceptual diagram of an exemplary auditor configuration screen that may be provided by management console 114 for configuring, for example, auditor 120 of Figure 1, constructed and operative in accordance with one embodiment of the present invention. In Figure 8A, screen 800 illustrates various types of information that may be specified for auditing web navigation events, file download events, file upload events, clipboard events such as copy / cut and paste, print events, etc., as well as for the execution of RPA automation tasks. More detailed examples of what data and / or metadata may be specified to record during an audit include: - network traffic, e.g. HTTP requests and responses, - User activities such as mouse input, keystroke input, scrolling, copying, screenshots, activating extensions, printing, saving files, etc.; navigation, including navigation that involves opening a new tab, such as navigation when a user clicks on a link within an application outside of a web browser, for example a link in an email; and redirects, - policy conditions met, - policy enforcement actions to be taken, JavaScript and API calls, e.g., using the Web Audio API in JavaScript; -HTML and DOM level data, e.g., PII data, hidden HTML elements, presence of password fields, - The RPA module that is executed and / or the specific actions that occur when the RPA module is executed, for example, an RPA module used by salesforce.com that masks all PII fields and allows users to unmask PII fields, where the user-initiated unmasking action is identified for audit purposes; - sharing, viewing and / or use of log files and / or the content of log files; and -Periodic screenshots or other recordings of browser activity.

[0057] Screen 800 may be used to specify that personal information is to be anonymized when auditing an event.

[0058] Additionally or alternatively, auditing may be implemented via policy definitions as described hereinabove, with specified audit actions being performed or prevented based on meeting specified policy conditions. For example, auditing of events related to private websites may be prevented by a policy definition.

[0059] Reference is now made to FIG. 8B, which is a simplified conceptual diagram of an exemplary audit reporting system constructed and operative in accordance with one embodiment of the present invention. FIG. 8B illustrates a web browser 810, configured as described hereinabove with reference to web browser 100 of FIG. 1, and the audit functionality described hereinabove with reference to FIG. 8A, in which audited information is transmitted by web browser 810 to computer server 812. Computer server 812 is configured with audit data manager 814, which routes audit information based on predefined policies to one or more destinations, such as tenant data store 816, customer data store 818, and / or customer SOC or security information and event management (SIEM) provider 820. Tenant data store 816 may contain data from multiple tenants, and tenant-specific keys or software partitions are used to access the tenant-specific data. Additionally or alternatively, customer-specific or tenant-specific data may be transmitted to data stores defined and controlled by the customer or tenant, such as customer data store 818 and / or customer SOC / SIEM 820.

[0060] Reference is now made to FIG. 9A, which is a simplified flow diagram illustrating a method for enforcing the use of a web browser by using an identity provider, constructed and operative in accordance with one embodiment of the present invention. In FIG. 9A, a given employee is requested by their employer to use web browser 900 when accessing a particular website 902, such as salesforce.com, on behalf of the employer, and web browser 900 is configured as described above in this specification with reference to web browser 100 of FIG. 1. Website 902 is configured to redirect the employee to identity provider (IdP) 904. In step #1, the employee attempts to access website 902 using web browser 906, which is not configured like web browser 900. Website 902 redirects web browser 906 to IdP 904, which is configured to redirect the employee to a verification web page 908 after authenticating the employee according to conventional techniques. In step 2, after authenticating the employee, the IdP 904 redirects the web browser 906 to a verification web page 908, which is configured to determine whether the employee is accessing the verification web page 908 using the web browser 900. In step 3, the verification web page 908 determines that the employee is not accessing the verification web page 908 using the web browser 900, for example, by determining that information received by the verification web page 908 from the web browser 906, such as one or more header information, a certificate, a Jason Web Token (JWT), or information for identifying the employee, does not match predefined information that configures the verification web page 908 and indicates that the employee is using the web browser 900. In step 4, the verification web page 908 launches the web browser 900 and attempts to redirect the web browser 900 to the website 902. Alternatively, the verification web page 908 may provide a link to download the web browser 900 or a message instructing the user to download the web browser 900.If the verification web page 908 determines in step #3 that the employee is using the web browser 900 to access the verification web page 908, the verification web page 908 redirects the web browser 900 to a website 902, e.g., salesforce.com, using the signed SAML assertion and requests access to the website 902.

[0061] Reference is now made to Figure 9B, which is a simplified flow diagram illustrating a method for enforcing web browser usage by using a password vault, constructed and operative in accordance with one embodiment of the present invention. In Figure 9B, a given employee is requested by their employer to use web browser 910 when accessing a particular website 912 on behalf of the employer, such as salesforce.com, where web browser 910 is configured as described hereinabove with reference to web browser 100 of Figure 1, and is additionally configured as follows: When accessing website 912 using web browser 910, the employee enters invalid login credentials into a login form provided by website 912. When an employee attempts to submit invalid login credentials to website 912, web browser 910 uses the invalid login credentials to access and decrypt valid login credentials that were previously encrypted and stored in password vault 914 configured on web browser 910; for example, both the invalid login credentials and the valid login credentials were previously provided to management console 114 of FIG. 1 , which then encrypts the valid login credentials and provides the encrypted valid login credentials to web browser 910. Web browser 910 then submits the valid login credentials to website 912 instead of the invalid login credentials. In this embodiment, if the employee attempts to access website 912 using a web browser 916 that is not configured like web browser 910 and enters invalid login credentials, the access attempt will fail.

[0062] Reference is now made to FIG. 9C, which is a simplified flowchart illustrating a method for enforcing web browser use by using network tunneling, constructed and operative in accordance with one embodiment of the present invention. In FIG. 9C, a given employee is required by their employer to use a web browser configured as described above with reference to web browser 100 of FIG. 1, and additionally configured as follows: In step 920, a website, e.g., salesforce.com, is configured to allow incoming communications from the employee only if the communications are received from a predefined IP address, such as 3.3.3.3. In step 922, the employee attempts to communicate with the website using the web browser from a computer with IP address 2.2.2.2. In step 924, the web browser tunnels the communication to IP address 3.3.3.3, which is, for example, a proxy server configured to authenticate the employee and / or the web browser according to conventional techniques. In step 926, the proxy server tunnels the communication to the website. In step 928, the website receives the communication and authenticates the employee according to conventional techniques. In step 930, the website further determines that the communication originated from IP address 3.3.3.3 and grants access to the employee.

[0063] 10A and 10B, which are illustrative code snippets illustrating various ways of extending web browser extension access, constructed and operative in accordance with an embodiment of the present invention. Figure 10A shows a code snippet illustrating how to expose PathExists functionality to JavaScript-based extensions. Figure 10B shows a code snippet illustrating how to expose clipboard operations to JavaScript-based extensions.

[0064] Reference is now made to Figure 11, which is an example code snippet illustrating how to configure a proxy for use in an embodiment of the present invention. Figure 11 illustrates how proxy settings can be dynamically configured using the Proxy Auto-Configuration (PAC) feature.

[0065] Reference is now made to Figure 12A, which is a simplified flow diagram illustrating a method for using a web browser with a virtual private network (VPN), constructed and operative in accordance with one embodiment of the present invention. Figure 12A illustrates a web browser 1200 hosted by a computer 1202, configured as described hereinabove with reference to web browser 100 of Figure 1, and including a policy engine 1204 configured as described hereinabove with reference to policy engine 102 of Figure 1. In step 1, web browser 1200 detects an attempt by a user to use web browser 1200 to access an application on computer network 1206. In step 2, policy engine 1204, in accordance with a predefined policy, determines that the application is an "internal" application, i.e., an application that does not have inbound Internet connectivity from outside the corporate network or cloud boundary, and invokes VPN 1208, which may be a VPN built into web browser 1200, a VPN installed on computer 1202, or any other VPN accessible to web browser 1200. In step #3, communication between web browser 1200 and computer network 1206 is established via VPN 1208 according to conventional VPN techniques. In step #4, web browser 1200 terminates the VPN connection, for example, by detecting closure of the web browser tab associated with the VPN session or by being configured to terminate the VPN connection upon termination of web browser 1200.

[0066] Reference is now made to FIG. 12B, which is a simplified flow diagram illustrating a method of using a web browser with a cloud connector, constructed and operative in accordance with one embodiment of the present invention. FIG. 12B is configured as described above with reference to FIG. 12A, except that a request to access an internal application is routed to the cloud connector 1210, which may be an implicit proxy, an explicit proxy, or IP-based routing, e.g., with a fixed IP address. The request may include additional authentication header information outside or inside the Secure Sockets Layer (SSL) stream. The cloud connector 1210 may be configured to decrypt the SSL stream, e.g., if the request is an SSL request. Additionally or alternatively, if the web browser 1200 controls the request headers, an additional header may be added outside the SSL stream, allowing the cloud connector 1210 to route traffic without opening the SSL stream. The cloud connector 1210 then routes the access request to the target application. If there is a firewall 1212 between the cloud connector 1210 and the target application, an incoming port is opened in the firewall 1212 to accept incoming communication from the target application.

[0067] Reference is now made to FIG. 12C, which is a simplified flow diagram illustrating a method of using a web browser with a cloud connector, constructed and operative in accordance with one embodiment of the present invention. FIG. 12C illustrates a cloud connector 1210 configured as described above with reference to FIG. 12B, except that instead of opening an inbound port in firewall 1212 to directly accept incoming communications from the target application, an application connector 1214, which may be configured as a TCP server, is shown to access the target application. The application connector 1214 opens an outbound connection to the cloud connector 1210, and server-to-server authentication may be used. The cloud connector 1210 is configured to determine which user requests require routing to the application connector 1214 or another application connector. The cloud connector 1210 preferably has multi-tenancy capabilities that support multiple tenants connecting simultaneously. For example, if tenants A and B connect to the same cloud connector 1210 from different networks, the cloud connector 1210 can determine which tenant it is based on JWT tokens, headers, and other identifiable information, and route each tenant's traffic to the appropriate destination application connector.

[0068] Reference is now made to FIG. 13, which is a simplified diagram illustrating isolation boundaries and multi-profile support, constructed and operative in accordance with one embodiment of the present invention. In FIG. 13, a web browser configured as described above with reference to web browser 100 of FIG. 1 is additionally configured to implement multiple profiles isolated from one another, each profile having its own data, including policies, cookies, cache, local storage, and other stateful data, that is inaccessible to other profiles. Data for each profile is preferably encrypted using any encryption technique and accessible from within its associated profile. Access to different profiles and associated data is preferably governed by any of the policy mechanisms described above. Different profiles may be associated with different concurrently displayed browser tabs, concurrently running processes, and / or concurrently running browser instances, and a visual indicator may be displayed to allow a user to know which profile is currently being accessed. Examples of various types of profiles include: 1. A public profile that may be associated with, for example, an anonymous user ID, and that does not allow access to critical applications; 2. A workspace profile associated with a user who is logged into a browser using a corporate ID, where policies governing the user's access to critical applications are enforced and the user's actions are audited; 3. A private profile that may be associated with a user, for example, when accessing private websites, to allow the user to perform private browsing with anti-tracking and privacy features turned on, where no auditing of the user's actions is performed; and 4. Workspace anonymous profiles associated with users who are logged in using a corporate ID and a browser configured to perform anonymous browsing, such as for research or law enforcement purposes; Examples include:

[0069] Any aspect of the invention described herein may be implemented in computer hardware and / or computer software embodied in a non-transitory computer-readable medium in accordance with conventional techniques, where the computer hardware includes one or more computer processors, computer memory, I / O devices, and network interfaces that interoperate in accordance with conventional techniques.

[0070] It should be understood that, as used herein, the term "processor" or "device" is intended to include any processing device, such as, for example, one that includes a CPU (Central Processing Unit) and / or other processing circuitry. It should also be understood that the term "processor" or "device" may refer to more than one processing device, and that various elements associated with a processing device may be shared by other processing devices.

[0071] As used herein, the term "memory" is intended to include memory associated with a processor or CPU, such as, for example, RAM, ROM, fixed memory devices (e.g., hard drives), removable memory devices (e.g., diskettes), flash memory, etc. Such memory may be considered a computer-readable storage medium.

[0072] Furthermore, as used herein, the phrase "input / output device" or "I / O device" is intended to include, for example, one or more input devices (e.g., keyboard, mouse, scanner, etc.) for inputting data into a processing unit, and / or one or more output devices (e.g., speaker, display, printer, etc.) for presenting results associated with a processing unit.

[0073] Embodiments of the invention may include systems, methods, and / or computer program products. The computer program product may include a computer-readable storage medium having computer-readable program instructions that cause a processor to perform aspects of the invention.

[0074] A computer-readable storage medium may be a tangible device capable of retaining and storing instructions for use by an instruction execution device. The computer-readable storage medium may be, for example, but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes portable computer diskettes, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanically encoded devices such as punch cards or ridge structures in grooves having instructions recorded thereon, and any suitable combination of the foregoing. Computer-readable storage medium, as used herein, should not be construed as being, per se, a transitory signal such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse passing through a fiber optic cable), or an electrical signal transmitted over an electrical wire.

[0075] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or can be downloaded to an external computer or external storage device over a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium in the respective computing / processing device.

[0076] Computer-readable program instructions for carrying out operations of the present invention may be source or object code written in any combination of one or more programming languages, including assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as the "C" programming language or similar programming languages. The computer-readable program instructions may execute entirely on the user's computer, partially on the user's computer as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be to an external computer (e.g., via the Internet using an Internet Service Provider). In some embodiments, to carry out aspects of the present invention, electronic circuitry including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may utilize state information of the computer-readable program instructions to execute the computer-readable program instructions to customize the electronic circuitry.

[0077] Aspects of the present invention are described herein with reference to flowchart and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart and / or block diagrams, and combinations of blocks in the flowchart and / or block diagrams, can be implemented by computer-readable program instructions.

[0078] These computer-readable program instructions may be provided to a processor of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, executed by the processor of the computer or other programmable data processing apparatus, create means for performing the functions / acts specified in the block or combination of blocks in the flowcharts and / or block diagrams. These computer-readable program instructions may be stored in a computer-readable storage medium that can instruct a computer, programmable data processing apparatus, and / or other device to function in a particular manner, such that the computer-readable storage medium having instructions stored thereon comprises an article of manufacture containing instructions that implement aspects of the functions / acts specified in the block or combination of blocks in the flowcharts and / or block diagrams.

[0079] The computer-readable program instructions may be loaded into a computer, other programmable data processing apparatus, or other device and cause the computer, other programmable apparatus, or other device to perform a series of operational steps to generate a computer-implemented process, such that the instructions operating on the computer, other programmable apparatus, or other device perform the functions / operations identified in the blocks or combinations of blocks in the flowcharts and / or block diagrams.

[0080] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowcharts or block diagrams may represent a module, segment, or portion of computer instructions, which comprises one or more executable computer instructions that perform the specified logical function(s). In some alternative implementations, the functions shown in the blocks may occur out of the order shown in the figures. For example, depending on the functionality involved, two blocks shown in succession may in fact be executed substantially simultaneously, or the blocks may even be executed in the reverse order. It should also be noted that each block in the block diagrams and flowcharts, and combinations of these blocks, may be implemented by dedicated hardware-based systems and / or dedicated software-based systems that perform the specified functions or operations.

[0081] The description of various embodiments of the present invention has been presented for purposes of illustration and is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the described embodiments.

Claims

1. A web browser, a browser rendering engine configured to transmit and receive data over a computer network; a policy engine configured to implement one or more policies configured to control any aspect of the web browser, the data, a computer hosting the web browser, and devices accessible to the computer; and Equipped with the web browser is configured as an executable file created by compiling computer software instructions for implementing the browser rendering engine and the policy engine; The web browser is configured to require a user of the web browser to be authenticated and one or more policies to be verified before the web browser is permitted to perform one or more predefined actions.

2. The web browser of claim 1 , wherein each of the policies includes one or more policy conditions and one or more policy enforcement actions that are performed when the policy conditions are met.

3. 10. The web browser of claim 1, wherein the web browser is configured to receive the policy from a source external to the web browser, the policy being encrypted for decryption using a decryption key uniquely associated with an identity associated with a user of the web browser, the decryption key being provided to the web browser after the user is authenticated.

4. 4. The web browser of claim 3, wherein the web browser is configured to receive browser settings associated with the authenticated user from the source, the browser settings being encrypted for decryption using the decryption key.

5. The web browser of claim 1 , wherein the web browser is configured to at least partially evaluate any policies that apply to the data in parallel with receiving the data.

6. 10. The web browser of claim 1, wherein the web browser is configured to at least partially evaluate any policies that apply to the data concurrently with receiving the data and concurrently with providing any portion of the data to the browser rendering engine.

7. The web browser of claim 1 , wherein any of the policies includes a policy condition related to a category associated with a website accessed by the web browser.

8. The web browser of claim 1 , wherein any of the policies includes a policy condition related to a risk level associated with a website accessed by the web browser.

9. The web browser of claim 1 , wherein any of the policies includes a policy condition related to any characteristic of the computer hosting the web browser.

10. The web browser of claim 1 , wherein any of the policies includes a policy condition related to any characteristic of the identity of a user of the web browser.

11. The web browser of claim 1 , wherein any of the policies includes a policy condition related to any characteristic of the identity of a network accessible to the web browser.

12. The web browser of claim 1 , wherein any of the policies includes a policy condition related to the source of a uniform resource locator (URL) provided to the web browser.

13. The web browser of claim 1 , wherein any of the policies includes a policy enforcement action that requires performing any of data loss prevention (DLP), antivirus, or anti-malware technology on the data.

14. The web browser of claim 1 , wherein any of the policies includes a policy enforcement action that requires the data to be modified or manipulated before being rendered or provided to the user.

15. 2. The web browser of claim 1, wherein any of the policies includes a policy enforcement action that requires converting the data from a first format to a second format that removes at least a portion of the data, and then converting the converted data back to the first format before rendering or providing the data to the user.

16. The web browser of claim 1 , wherein any of the policies includes a policy enforcement action required to control client-side user interaction with a website.

17. 2. The web browser of claim 1, wherein any of the policies includes a policy enforcement action that requires hiding a browser tab that has been closed by the user and revealing the hidden browser tab the next time the user attempts to access a website or other content associated with the hidden browser tab.

18. The web browser of claim 1 , wherein any of the policies includes a policy enforcement action that requires disabling a predefined application programming interface (API) of the web browser.

19. The web browser of claim 1 , wherein any of the policies includes a policy enforcement action that requires either disabling, hiding, or masking predefined elements of a web page.

20. The web browser of claim 1 , further comprising an auditor configured to record any actions attempted or performed by the user when using the web browser.

21. The web browser of claim 1 , further comprising an auditor configured to record any actions attempted or performed by the web browser when the web browser is used by the user.

22. The web browser of claim 1 further comprising an auditor configured to record any network activity detectable by the web browser.

23. The web browser of claim 1 , wherein the web browser is specifically configured to operate with one or more target applications.

24. 24. The web browser of claim 23, wherein the policy is specifically adapted for use with the one or more target applications.

25. The web browser of claim 1 , wherein any of the policies are defined and enforced using robotic process automation (RPA) techniques.

26. the web browser is configured to implement a plurality of different profiles that are isolated from one another; Each of the profiles has its own data, such as policies, cookies, cache, local storage, etc. The web browser of claim 1 , wherein the different profiles are associated with one of different concurrently displayed browser tabs, different concurrently running processes, and different concurrently running browser instances.