Embedded Browser API Interception for SaaS Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in managing access to network resources and securing data as employees use personal devices to access web and SaaS applications, leading to potential misuse and security breaches due to differences in device capabilities and lack of visibility into encrypted traffic.

Innovation Solution

A client application with an embedded browser intercepts API calls, enhances or modifies them to include security features and access controls, and enforces policies, allowing direct printing, smartcard authentication, and granular access controls, while optimizing network application performance and usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If employees use personal devices to access network resources, then mobility and flexibility are improved, but security and control are worsened

Engineering Contradiction:
ImprovemobilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an embedded browser as an intermediary layer between the personal device and network resources. This embedded browser intercepts API calls from web applications and redirects them through a secure gateway, enabling security policies to be enforced without restricting employee mobility. The intermediary captures and controls all traffic, preventing direct access to corporate resources while maintaining user convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the browser functionality into two parts: an embedded browser within the corporate-managed application that handles secure corporate resources, and the device's native browser for personal use. This segmentation allows the corporate environment to enforce security policies on specific applications while leaving personal device functionality intact, resolving the contradiction between mobility and security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encrypted traffic is used for security, then data protection is improved, but visibility and monitoring are worsened

Engineering Contradiction:
Improvedata protectionVSAvoidvisibility
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements preliminary action by establishing secure tunnels and encrypted connections through the embedded browser before any data transmission occurs. Security policies, authentication mechanisms, and monitoring capabilities are pre-configured in the embedded browser, allowing the system to maintain both encryption and visibility simultaneously. The gateway can inspect and control traffic at the application layer before encryption takes effect.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The embedded browser acts as an intermediary that maintains encrypted connections while providing visibility to the corporate gateway. The gateway can intercept and inspect API calls at the application layer through the embedded browser without breaking encryption, enabling monitoring and policy enforcement while preserving data protection through encrypted transport.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If standard browser API calls are used, then compatibility is improved, but security and functionality are worsened

Engineering Contradiction:
ImprovecompatibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent changes the parameters of API calls by intercepting standard browser requests and modifying them before forwarding to corporate resources. The embedded browser transforms standard API calls into secure, policy-compliant requests, adding authentication tokens, enforcing access controls, and modifying request parameters to meet security requirements while maintaining compatibility with corporate applications.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The embedded browser serves as an intermediary that receives standard API calls from web applications and translates them into secure requests. It adds security layers, authentication mechanisms, and policy enforcement to standard API calls, maintaining compatibility with applications while improving security through the translation and mediation process.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If multiple devices are supported, then flexibility is improved, but device complexity and management are worsened

Engineering Contradiction:
Improvedevice supportVSAvoidmanagement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements universality by creating a device-agnostic embedded browser that functions identically across smartphones, tablets, and computers. The embedded browser provides a standardized interface and security model that works uniformly on all device types, eliminating the need for device-specific configurations or management policies. This universal approach simplifies management while supporting diverse devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3652922B1Systems and methods for intercepting and enhancing SAAS application calls via embedded browser
Publication Date: 2024.07.31 CITRIX SYSTEMS INC
  • EP3652922B1 patent drawingFigure 1
  • EP3652922B1 patent drawingFigure 2
  • EP3652922B1 patent drawingFigure 3

AI summary

Embodiments described include systems and methods for calling an application programming interface of a client application for a network application via an embedded browser of the client application. The method includes establishing, by a client application on a client device, one or more sessions to one or more network applications accessed via an embedded browser of the client application. The client application providing a plurality of application program interfaces (APIs). The client application can intercept a first API called by a network application of the one or more network applications and identify a policy for using the plurality of APIs of the client application. The client application can determine, based at least on the policy, a second API of the plurality of APIs to use for the intercepted first API, and execute, for the intercepted first API call, the second API of the plurality of APIs of the client application.