Browser Access Control via Configuration Script

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network access control solutions are limited in effectively scanning client devices through firewalls or network address translation (NAT), and they often require client-resident agents, which can be cumbersome and incomplete in protecting against vulnerabilities exploited by malicious content through client browsers.

Innovation Solution

A browser-based access control method that receives requests from client browsers, determines if browser authorization data is present, and if not, provides a configuration script to generate browser configuration data, which is then compared to security policies to ensure compliance before allowing access, implemented externally, such as at a proxy server, without needing a client-resident agent.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network access control solutions are implemented using agents or remote scanning, then device health can be assessed, but these solutions cannot scan devices through firewalls or NAT and require client-resident agents that are cumbersome

Engineering Contradiction:
Improveaccess control effectivenessVSAvoidagent installation and configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a configuration page as an intermediary mechanism that mediates between the NAC system and the client device. Instead of requiring direct agent installation or complex remote scanning through firewalls/NAT, the configuration page is delivered through the web browser and acts as a mediator to collect device information and enforce security policies. This intermediary approach allows the NAC system to assess device health without needing client-resident agents or penetrating firewall/NAT barriers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The client device performs self-assessment by executing JavaScript code within the configuration page that automatically collects device information such as browser version, plugins, and system properties. The device itself generates and transmits its configuration data without requiring external agents or manual configuration, enabling the NAC system to evaluate compliance autonomously. This self-service mechanism eliminates the need for cumbersome agent installation while maintaining reliable access control.

Inventive Principle:
Principle #25Self-service

2Reliability

If client browsers are protected by security patches and anti-virus software, then vulnerabilities can be addressed, but these measures are of little effect if not implemented

Engineering Contradiction:
Improvebrowser securityVSAvoiduser implementation responsibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The NAC system implements a feedback mechanism by assessing browser configuration and security status through the configuration page, then providing actionable information to users about required updates or configurations. The system collects data on browser version, security patches, and anti-virus status, compares it against security policies, and communicates compliance status back to the user. This feedback loop enables users to understand their security posture and take appropriate actions without requiring them to proactively implement measures.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary security assessment and configuration validation before granting network access. By evaluating browser security posture in advance through the configuration page and preventing access until compliance is achieved, the system ensures security measures are in place before they are needed. This preliminary action approach proactively addresses vulnerabilities rather than reacting to them after compromise occurs.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If existing NAC solutions are implemented in the same network environment, then device scanning can be performed, but they are of limited utility when scanning through firewalls or NAT

Engineering Contradiction:
Improvedevice scanning capabilityVSAvoidnetwork environment compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The configuration page-based approach provides universal functionality that works across diverse network environments including those with firewalls and NAT. By leveraging the ubiquitous web browser and standard HTTP/HTTPS protocols, the system can collect device information and enforce policies regardless of network architecture. This multi-functional mechanism handles both direct network access and firewall/NAT scenarios without requiring separate solutions, making the NAC system adaptable to various deployment contexts.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The web browser and configuration page serve as intermediaries that enable communication between the NAC system and client devices through firewall/NAT barriers. Instead of requiring direct network access or agent installation on the client side, the intermediary web-based configuration page can be delivered through standard web protocols that traverse firewalls and NAT devices. This intermediary mechanism allows the NAC system to assess device health and enforce policies even in restricted network environments where traditional scanning methods fail.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8286220B2Browser access control
Publication Date: 2012.10.09 ZSCALER INC
  • US8286220B2 patent drawing
  • US8286220B2 patent drawing
  • US8286220B2 patent drawing

AI summary

Systems, methods and apparatus for a distributed security that monitors communications to manage client browser network access based upon the browser configuration of the client browser by use of a configuration script executed in the browser environment. Such management can reduce the exposure of potentially vulnerable client browsers to domains associated with malicious activity.