Method to control software services by grade based on web isolation

KR1020260122682APending Publication Date: 2026-08-12SOFTCAMP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
KR1020250014696
Authority / Receiving Office
KR · KR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-02-05
Publication Date
2026-08-12

Smart Images

  • Figure PAT00002_ABST
    Figure PAT00002_ABST
Patent Text Reader

Abstract

The present invention relates to a method for controlling software services by grade through web isolation, which separates storage areas according to security grades of an internal network and manages software service access according to the grade of the internal network accessed by a user. The method comprises: a security grade setting step in which one or more clients, a management server, and a data file storage server are configured to communicate with each other by connecting to an internal network isolated from an external network; a security grade setting step in which a storage configured in the data file storage server is classified according to a security grade and a security grade is set for each software service; an external network access attempt step in which the internal network system attempts to access a service server of the external network for software services; a virtual browsing activation step in which virtual browsing is activated in response to web browsing of the internal network system to create a relay environment; a control step in which a control environment is established so that the execution of software services and data management are performed restrictively in a storage corresponding to the security grade; and a rendering image output step in which a first execution window of software output during virtual browsing in the relay environment is rendered to generate a rendering image, and the rendering image is output through web browsing of the internal network system.
Need to check novelty before this filing date? Find Prior Art

Description

Technology Field

[0001] The present invention relates to a method for controlling software services by grade through web isolation, which separates storage areas according to the security grade of an internal network and manages access to software services according to the grade of the internal network accessed by the user. Background Technology

[0003] In work environments such as government offices, companies, and research institutes where data exposure is restricted, a closed network system isolated from the outside (hereinafter referred to as the 'internal network') was established to share data among members.

[0005] Recently, business system technologies have been proposed that provide dedicated software to enable users to perform specific tasks, such as Customer Relationship Management (CRM). To this end, not only have software service technologies that provide dedicated software to clients within the internal network been applied, but cloud-based Software as a Service (SaaS) has also been integrated with the internal network.

[0007] To illustrate with an example regarding the aforementioned software services, in companies where an internal network is established within the work environment, dedicated business system software—such as Customer Relationship Management (CRM) systems, collaboration tools, productivity applications, and project management systems—is generally distributed and utilized for work. This dedicated business system software is accessed via the Internet and enhances the convenience of data usage by providing data storage and sharing functions.

[0009] However, when software provided from an external network executed data files, there was a high possibility of external leakage, which could pose a security risk. Additionally, even for business systems where access is restricted based on user security levels, providing dedicated software for those systems without distinction could lead to users accessing the restricted systems, thereby weakening business security. The problem to be solved

[0011] Accordingly, the present invention aims to resolve the above-mentioned problem by providing a method for class-based control of software services through web isolation that controls the movement and storage of data, so as to differentiate data file sharing and software services according to security levels. means of solving the problem

[0013] In order to achieve the above objectives, the present invention,

[0014] In an internal network system configured such that one or more clients, a management server, and a data file storage server communicate with each other by connecting to an internal network isolated from an external network, a security level setting step comprising classifying a storage configured in the data file storage server according to a security level and setting a security level for each software service;

[0015] An external network access attempt step in which the internal network system attempts to access a service server on an external network for software services;

[0016] A virtual browsing activation step for creating a relay environment by activating virtual browsing in response to web browsing of the internal network system;

[0017] A control step for establishing a control environment so that the execution of software services and data management are carried out restrictively in a repository corresponding to a security level; and

[0018] A rendering image output step of generating a rendering image by rendering a first execution window of software output during virtual browsing in the above relay environment, and outputting the rendering image through web browsing of an internal network system;

[0019] It is a method of class-based control of software services through web isolation that includes. Effects of the invention

[0021] The present invention described above can minimize the risk of external threats infiltrating the internal system through web isolation between the external network and the internal network, and reduce the possibility of malware infection and information leakage.

[0022] In addition, by classifying data file repositories according to security levels and differentiating software services, it is possible to prevent data files from leaking out of repositories of designated security levels, and the safe management of important information is guaranteed.

[0023] Furthermore, since the creation of a relay environment using a virtual browser and rendering tasks are distributed and executed by the client—the user of the data file or software—server resource usage can be minimized, and there is no need to unnecessarily increase device specifications for data file management and software services. Brief explanation of the drawing

[0025] FIG. 1 is a block diagram illustrating an embodiment of a control system according to the present invention, and FIG. 2 is a flowchart illustrating an example of a control method based on the above-mentioned control system, and FIG. 3 is a list window image showing an example of software provided by a service server in an embodiment of a control system according to the present invention, and FIG. 4 is a block diagram illustrating another embodiment of a control system according to the present invention, and FIG. 5 is a block diagram illustrating another embodiment of a control system according to the present invention. Specific details for implementing the invention

[0026] The terms used in the embodiments have been selected to be as widely used as possible, taking into account their functions in the present invention; however, these terms may vary depending on the intent of those skilled in the art, case law, the emergence of new technologies, etc. Additionally, in specific cases, terms have been arbitrarily selected by the applicant, and in such cases, their meanings will be described in detail in the corresponding description of the invention. Therefore, the terms used in the present invention should be defined not merely by their names, but based on their meanings and the overall content of the invention.

[0028] In this specification, the term "~device" refers to a part that performs a specific function. A "~device" may be a defined part of a body, or it may be an object formed by combining multiple components. The functions provided within the components and "~devices" may be combined into a smaller number of components and "~devices," or further separated into additional components and "~devices." A "~device" should be understood as a unit whose form is embodied for the performance of a specific function.

[0030] Below, embodiments of the present invention are described in detail with reference to the attached drawings so that those skilled in the art can easily implement the invention. However, the present invention may be embodied in various different forms and is not limited to the embodiments described herein.

[0032] Hereinafter, the present invention will be described in detail with reference to the attached drawings.

[0034] FIG. 1 is a block diagram illustrating an example of a control system according to the present invention.

[0036] Referring to FIG. 1, the control system according to the present invention comprises a data management server (110) that connects to an external network such as the Internet and performs general cloud functions, a service server (120) that provides software services dedicated to business systems such as a customer relationship management (CRM) system, collaboration tools, productivity applications, and project management systems, or general software services such as word processors and Excel, and an internal network system (130) isolated from the external network. Here, the internal network system (130) is based on an internal network that creates a communication environment isolated from the external network, and is configured to enable communication between one or more clients (131) equipped with general computer functions used by a user, a management server (132) that controls communication between the clients (131) and the external network, and a data file storage server (133) that protects, stores, and manages data files.

[0038] To explain each configuration in more detail, a service server (120) connected to an external network provides a public software service to a designated client (131). In this embodiment, the service server (120) creates a relay environment by activating virtual browsing via a virtual browser (FB) to provide the software service. In this embodiment, the virtual browser (FB) is configured in the service server (120), and virtual browsing is executed in the service server (120) (first embodiment).

[0040] However, the control method and control system according to the present invention may be configured such that the virtual browser (FB) is connected to an external network and is configured on a separate security server (not shown) to create the relay environment (2nd embodiment), may be configured on a management server (132) of an internal network system (130) to create the relay environment (3rd embodiment), or may be configured on a client (131) of an internal network system (130) to create the relay environment (4th embodiment). In this description, the case where virtual browsing is activated on a service server (120) is described as an example.

[0042] The data management server (110) stores and manages data files executed by the software of the service server (120) and newly created or updated data files. The data management server (110) performs general cloud computing functions to create a data storage environment on an external network, and a separate data security device (111) may be installed to enhance security.

[0044] However, data files executed by software in the internal network system (130) and newly created or updated data files can be stored and managed in a data file storage server (133) configured in the internal network system (130) for more stable security.

[0046] As described above, an internal network system (130) that has established an internal network isolated from an external network comprises a user client (131), a management server (132) that manages the communication environment and security of the internal network system (130) and manages software code and other data files received from the external network, and a data file storage server (133) that stores, searches for, and manages the data files.

[0048] To explain this in more detail, the client (131) is a standard computer and connects to the data file storage server (133) through an internal network and connects to the external network through a security channel designated by the management server (132). The client (131) may have a dedicated application (not shown) installed for receiving software services, and the user connects to the service server (120) according to the communication control of the management server (132) by executing the dedicated application.

[0050] The management server (132) activates a security channel for communication security when the client (131) attempts to connect to an external network and assigns it to the client (131). Additionally, when a software service is executed for the client (131), the generated data file is stored in the data file storage server (133). For reference, when the software is executed directly on the service server (120), the software receives and executes a data file from the data management server (110) and stores the generated data file in the data management server (110). However, when the software is executed on the internal network system (130), the software receives and executes a data file from the data file storage server (133) and stores the generated data file in the data file storage server (133).

[0052] A security level is set for each user or client (131) and software, and a management server (132) or service server (120) checks the security level of each user or client (131) and software to enable access to software that the client (131) can use. In addition, the management server (132) assigns a corresponding security level to each data file.

[0054] The data file storage server (133) stores data files received from an external network by the management server (132), and when a client (131) attempts to search for software execution, it searches for data files under the control of the management server (132). The data files thus searched are transmitted to the service server (120) under the control of the management server (132).

[0056] Additionally, the data file storage server (133) can configure storage according to security level and checks the security level of the received data file and stores it in the corresponding storage.

[0058] The control system according to the present invention described above has been configured in the case of the first and second embodiments, but in the description with reference to FIGS. 4 and FIGS. 5, the configuration of the third and fourth embodiments is described respectively.

[0060] FIG. 2 is a flowchart illustrating an example of a control method based on the above-mentioned control system, and FIG. 3 is a list window image showing an example of software provided by a service server in an example of a control system according to the present invention.

[0062] A control method according to the present invention will be explained with reference to FIGS. 1 to 3.

[0064] S11: Security Level Setting Step

[0065] In an internal network system (130) configured such that one or more clients (131), a management server (132), and a data file storage server (133) communicate with each other by connecting to an internal network isolated from an external network, the storage configured in the data file storage server (133) is classified according to security level, and security levels are set for each software service.

[0067] The security level of the data files executed and generated by the software may be set according to the software service, or the security level may be set for each data file regardless of the software service. Additionally, the data files are stored in a designated storage according to the set security level in the data management server (110) or the data file storage server (133).

[0069] When the above data file is stored in the data file storage server (133), the data file is stored and managed in an isolated state within the internal network system (130) without leakage to the external network. When a security level is set for each data file, the data file is not shared with storage other than the security level within the internal network system (130).

[0071] Security level settings can be classified based on the security level of data files and software, but they can also be classified according to purpose, such as business networks, development networks, and computer networks.

[0073] S12: External network access attempt stage

[0074] For software services, the internal network system (130) attempts to access the service server (120) of the external network.

[0076] In this embodiment, for a client (131) of an internal network system (130) to access a service server (120), the user executes a dedicated application for software services on the client (131). The dedicated application executes web browsing on the client (131) to connect with the internal network. In addition, the dedicated application outputs an execution window (W1) in which one or more software identification marks (APs) are posted, as shown in FIG. 3, so that the user can directly select the software to use. The user can click on one or more of the identification marks (APs) posted in the execution window (W), and the dedicated application finally confirms the software to be used entered through the selection of identification marks (APs) as the service target.

[0078] In this embodiment, the internal network system (130) allows the user to directly select the software service to be provided from the service server (120), but in addition, the specified software service may be automatically selected when the client (131) boots up or a dedicated application is executed.

[0080] Meanwhile, in this embodiment, along with the execution of the dedicated application described above, when the client (131) connects to the management server (132) while web browsing, the management server (132) designates a secure channel for connection with an external network. The client (131) accesses the service server (120) through the secure channel.

[0082] Regarding communication between the client (131) and the external network through the above security channel, security technology concerning data communication, authentication, encryption, etc. is already known technology, so a detailed explanation thereof is omitted.

[0084] S13: Virtual Browsing Activation Step

[0085] In response to web browsing of the internal network system (130), virtual browsing is activated to create a relay environment.

[0087] In this embodiment, the creation of a relay environment by activating the virtual browsing is performed by a virtual browser on an external network. To explain this in more detail, in the first embodiment, the service server (120) configures a virtual browser (VB) itself. The virtual browser (VB) displays the website of the service server (120) on behalf of the client (131)'s web browser, and executes a subsequent web page or data by selecting a menu for each web page of the website.

[0089] The establishment of a relay environment by a virtual browser (VB) takes place in a web isolation area for data security. Generally, a sandbox is a representative web isolation technology. The sandbox ensures that the executable code of the software input from the service server (120) and the data file input from the data file storage server (133) of the internal network system (130) are executed in the web isolation area, thereby preventing infection of the software service by malicious code, etc., and ensuring that rendering images and data files generated during the software service process are transmitted to the internal network system (130) without infection by malicious code.

[0091] Since sandbox technology is already a known technology, a detailed explanation thereof will be omitted.

[0093] In the first embodiment, the relay environment by the virtual browser (VB) is established on the service server (120), but in the second embodiment, the virtual browser (VB) is installed on a security server (not shown) separate from the service server (120) to establish the relay environment, and the rendering image and data file generated in the relay environment of the security server are transmitted to the internal network system (130).

[0095] S14: Software Service Decision Phase

[0096] The service server (120) checks the security level of the software to be used requested by the client (131) and checks the security level of the client (131)'s user or the client (131).

[0098] If the security level check confirms that the user or client (131) is qualified to use the software, the software service procedure is continued, and if it is confirmed that the user is not qualified, the software service procedure is rejected.

[0100] To verify the security level, one or more selected from the service server (120) and the management server (132) hold information data such as a user or client (131) containing information regarding the security level, and when a service request for software is received from the client (131), the security level is verified in the information data based on the user's ID or the client's (131) IP.

[0102] S15: Data Control Step

[0103] The internal network system (130) establishes a control environment so that the execution of software services and data management are carried out restrictively in a repository corresponding to a security level.

[0105] To this end, at least one of the selected data file storage servers (133) of the data management server (110) and the internal network system (130) forms a storage corresponding to the security level of the user when the software service is executed, and the search, storage, and updating of data files for the software service are performed only within the scope of the storage.

[0107] In this embodiment, one or more selected storages among the data management server (110) and the data file storage server (133) may already be partitioned by security level, and since the user's client (131) is already configured to access only storages of a security level lower than or equal to a predetermined security level, the software running in the relay environment of the current service server (120) of the first embodiment or the security server of the second embodiment cannot search for data files stored in storages of a security level exceeding the security level.

[0109] S16: Rendered image output step

[0110] When the execution of a software service for a user or client (131) is authorized through a security level check, a rendering image is generated by rendering the first execution window of the software output during virtual browsing in the relay environment, and the rendering image is output through web browsing of the internal network system (130).

[0112] In the first embodiment, when the service server (120) transmits the rendered image to the internal network system (130) in the relay environment, or in the second embodiment, when the security server transmits the rendered image to the internal network system (130) in the relay environment, the management server (132) receives the rendered image and transmits it to the client (131).

[0114] Since the web browser of the client (131) outputs the rendering image received from the management server (132), the user uses the service by recognizing that the software is running on the client (131).

[0116] As explained above, Remote Browser Isolation (RBI) technology, a security technology that runs a virtual browser in a web isolation area and uses rendering technology to transmit and share only rendered images, is already a known technology; therefore, a detailed explanation regarding it will be omitted.

[0118] The first and second embodiments described above established a relay environment in an external network to implement RBI technology, whereas the third and fourth embodiments establish a relay environment in an internal network system (130) to implement RBI technology. The third and fourth embodiments are described below.

[0120] FIG. 4 is a block diagram illustrating another embodiment of a control system according to the present invention.

[0122] Referring to FIGS. 2 to 4, the control system (200) of the third embodiment of the present embodiment includes a service server (220) and an internal network system (230). The service server (220) provides software services to a client (231), and the internal network system (230) comprises a client (231), a management server (232), and a data file storage server (233).

[0124] The client (231) and data file storage server (233) configured in the control system (200) of the third embodiment have the same basic functions as the client (131) and data file storage server (133) configured in the control system (100) of the first and second embodiments. However, unlike the first or second embodiment, the management server (232) configured in the control system (200) of the third embodiment is configured with a virtual browser (VB) for virtual browsing, and through this, the relay environment construction and rendering functions are executed in the management server (232).

[0126] Accordingly, when a dedicated application of a client (231) requests a software service from a service server (220), the service server (220) transmits the code of the requested software to an internal network system (200), and the management server (232) of the internal network system (200), upon receiving the software code, has a virtual browser (VB) execute and render the software in a relay environment and transmit the rendered image to the corresponding client (231).

[0128] To explain the control method of the third embodiment, in the external network access attempt step (S12), an attempt to access the service server (220) of the external network for the software service is made through web browsing of a client (231) configured in the internal network system (230).

[0130] In the virtual browsing activation step (S13), the creation of a relay environment by the activation of the virtual browsing is performed by a virtual browser (VB) in a management server (232) configured in the internal network system (200). Accordingly, the management server (232) receives code for software execution from the service server (220) and receives a data file for software services from the data file storage server (133).

[0132] In the rendering image output step (S16), the rendering image is output through web browsing of a client (231) configured in the internal network system (200).

[0134] FIG. 5 is a block diagram illustrating another embodiment of a control system according to the present invention.

[0136] Referring to FIGS. 2, 3, and 5, the control system (300) of the fourth embodiment, which is the present embodiment, includes a service server (320) and an internal network system (330). The service server (320) provides software services to a client (331), and the internal network system (330) comprises a client (331), a management server (332), and a data file storage server (333).

[0138] The data file storage server (333) configured in the control system (300) of the fourth embodiment has the same basic functions as the data file storage server (133, 233) configured in the control systems (100, 200) of the first to third embodiments. However, unlike the first to third embodiments, the client (331) configured in the control system (300) of the fourth embodiment is configured with a virtual browser (VB) for virtual browsing, and through this, the relay environment construction and rendering functions are executed on the client (331) itself.

[0140] Additionally, the management server (332) transmits the software code received from the service server (320) to the client (331).

[0142] To explain the client (331) of the fourth embodiment in more detail, an attempt to access a service server (320) of an external network for software services is made through web browsing of the client (331) configured in the internal network system (330), and the client (331) is divided into a general area (Z1) that is open in the internal network and an isolated area (Z2) that is isolated from the internal network and where data communication with the service server (320) takes place.

[0144] That is, when the dedicated application of the client (331) is executed, the client (331) is divided into a general area (Z1) where a rendered image is output and an isolated area (Z2) where the relay environment formation and rendering functions are executed.

[0146] In an environment where a client (331) is divided into a general area (Z1) and an isolated area (Z2), the external network access attempt step (S12) includes the step of executing a dedicated application for software services in the general area (Z1) on the client (331), the step of web browsing of the client (331) being executed in the general area (Z1), the step of outputting a second execution window in which one or more software identification marks (AP) are posted when the dedicated application is executed, and the step of determining the software service to be used through the selection of the identification mark (AP).

[0148] Meanwhile, in the virtual browsing activation step (S13), the creation of a relay environment by the activation of the virtual browsing is performed by the virtual browser (VB) in the isolation area (Z2) of the client (331). Accordingly, the rendering image output step (S16) includes the step of generating a rendering image by rendering the third execution window of the software output during virtual browsing in the relay environment of the isolation area (Z2), and the step of outputting the rendering image through web browsing in the general area (Z1).

[0150] Ultimately, when a dedicated application of a client (331) requests a software service from a service server (320), the service server (320) transmits the code of the requested software to an internal network system (300), and when the management server (332) of the internal network system (300) that received the software code transmits it to the isolation area (Z2) of the client (331), the virtual browser (VB) of the isolation area (Z2) executes and renders the software in a relay environment and transmits the rendered image to the general area (Z1) of the corresponding client (331).

[0152] In the isolation area (Z2), data files are retrieved from the data file storage server (333) for software services, and data files generated during software services are stored in the data file storage server (333).

[0154] In the fourth embodiment, tasks such as creating a relay environment by a virtual browser (VB), rendering processing, and outputting rendered images are distributed and performed for each client (331). Therefore, the burden of concentrating tasks for software services requested by the client (331) on the service server (320) or the management server (332) of the internal network system (300) can be reduced, and server resource usage can be minimized. In addition, since there is no need to increase the device specifications of the service server (320) or the management server (332) for software services, the cost burden for building the service server (320) or the management server (332) can be reduced.

[0156] In addition, the client (331) of this embodiment is equipped with a web editor (ED) for viewing and editing data files stored in the data file storage server (333). Since local storage of the client (331) is blocked when the web editor (ED) of the client (331) is used, security can be expected in which unauthorized leakage of data files stored in the data file storage server (333) is restricted.

[0158] Although the detailed description of the present invention described above has been explained with reference to preferred embodiments of the invention, those skilled in the art or those with ordinary knowledge in the art will understand that various modifications and changes can be made to the present invention without departing from the spirit and technical scope of the invention as described in the claims set forth below.

Claims

Claim 1 A method for controlling software services by grade through web isolation, characterized by comprising: a security grade setting step in which a storage configured in the data file storage server is classified according to a security grade and a security grade is set for each software service, wherein in an internal network system configured such that one or more clients, a management server, and a data file storage server communicate with each other by connecting to an internal network isolated from an external network; an external network access attempt step in which the internal network system attempts to access a service server in the external network for software services; a virtual browsing activation step in which virtual browsing is activated in response to web browsing of the internal network system to create a relay environment; a control step in which a control environment is established so that the execution of software services and data management are performed restrictively in a storage corresponding to a security grade; and a rendering image output step in which a first execution window of software output during virtual browsing in the relay environment is rendered to generate a rendering image, and the rendering image is output through web browsing of the internal network system. Claim 2 A method for classifying control of software services through web isolation, characterized in that, in claim 1, the step of attempting external network access includes the step of executing a dedicated application for software services in the internal network system, the step of executing web browsing in the internal network system, the step of outputting a second execution window in which an identification mark of one or more software is posted when the dedicated application is executed, and the step of determining the software service to be used through the selection of the identification mark. Claim 3 A method for class-based control of software services through web isolation, characterized in that, in the relay environment of claim 1, a sandbox is formed in which rendering processing for the first execution window of the software is executed. Claim 4 A method for class-based control of software services through web isolation, characterized in that, in the virtual browsing activation step, the creation of a relay environment by the activation of the virtual browsing is performed by a virtual browser of an external network. Claim 5 A method for class-based control of software services through web isolation, characterized in that, in the external network access attempt step, an attempt to access a service server of an external network for the software service is made through web browsing of a client configured in the internal network system; and in the virtual browsing activation step, the creation of a relay environment by the activation of the virtual browsing is made by a virtual browser in the client's isolation area. Claim 6 In claim 5, the attempt to access a service server of an external network for the software service is made through web browsing of a client configured in an internal network system, and the client is divided into a general area open to the internal network and an isolated area isolated from the internal network and where data communication with the service server takes place; the external network access attempt step includes the step of executing a dedicated application for the software service in the general area by the client, the step of executing the client's web browsing in the general area, the step of outputting a second execution window in which one or more software identification marks are posted when the dedicated application is executed, and the step of determining the software service to be used through the selection of the identification marks; and the rendering image output step includes the step of generating a rendering image by rendering a third execution window of the software output during virtual browsing in the relay environment of the isolated area, and the step of outputting the rendering image through web browsing in the general area; characterized by a method for controlling software services by grade through web isolation. Claim 7 A method for class-based control of software services through web isolation, characterized in that, in claim 1, an attempt to access a service server of an external network for the software service is made through web browsing of a client configured in the internal network system; and in the virtual browsing activation step, the creation of a relay environment by the activation of the virtual browsing is made by a virtual browser on a management server configured in the internal network system.