Embedded Browser for Encrypted Session Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in managing access to network resources and monitoring for potential misuse due to differences between client devices and network resource access methods, particularly in mobile and BYOD environments, where administrators lack visibility and control over encrypted sessions in generic browsers.

Innovation Solution

The implementation of an embedded browser within a client application that establishes secure connections with network applications, providing real-time visibility into traffic and enabling policy-based management, data loss prevention, and analytics, while ensuring that traffic is routed through the client application for enhanced security and control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If administrators use generic browsers for network resource access, then ease of operation is improved, but visibility and control over encrypted sessions deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidvisibility and control
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent introduces an intermediary component (browser extension or proxy) that sits between the generic browser and the network resources. This intermediary decrypts or inspects encrypted traffic, allowing administrators to maintain visibility and control while users continue to benefit from the ease of use of generic browsers. The intermediary acts as a mediator that preserves user convenience while enabling administrative oversight.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprises implement strict access management and monitoring, then security is improved, but device complexity and ease of operation worsen

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the browser extension automatically performs authentication, encryption, and policy enforcement without requiring manual configuration by users or administrators. The system self-manages security credentials, automatically applies access policies, and monitors compliance, thereby maintaining high security while minimizing the complexity burden on users and administrators.

Inventive Principle:
Principle #25Self-service

3Reliability

If enterprises implement strict access management and monitoring, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies preliminary action by pre-configuring security policies, authentication credentials, and monitoring rules before users access network resources. The browser extension is pre-installed and pre-configured with enterprise security requirements, so that when users access resources, the security measures are already in place and operate transparently. This eliminates the need for users to manually configure security settings, maintaining ease of operation while ensuring security compliance.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3850817B1Systems and methods for integrated service discovery for network applications
Publication Date: 2023.01.25 CITRIX SYSTEMS INC
  • EP3850817B1 patent drawingFigure 1
  • EP3850817B1 patent drawingFigure 2
  • EP3850817B1 patent drawingFigure 3

AI summary

Embodiments described include systems and methods for integrating use of a cloud discovery service into a client application for a network application is provided. A client application can establish, for a user, one or more sessions with one or more network applications via an embedded browser within the client application. A request to access a uniform resource locator (URL) from a network application accessed via the embedded browser can be intercepted. The client application can communicate with a cloud discovery service to determine a location for which to send the URL for the user. The cloud service can select the location from a plurality of locations based at least on a context of the user. The client application can receive, from the cloud discovery service, the location for the URL and, responsive to the request, transmit the URL to the location selected by the cloud discovery service.