Embedded Browser Plugin Security via Risk-Based Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face challenges in managing access to network resources and monitoring for potential misuse due to differences between client devices and network resource access methods.
Innovation Solution
The system dynamically manages and redirects browser components, such as plugins and extensions, within embedded browsers based on risk profiles and centrally managed policies, ensuring only authorized components access web-application content.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If browser components are allowed to access web-application content, then functionality and user experience are improved, but security risks increase due to unauthorized components
Solution Approach 1:
The patent introduces a browser component manager as an intermediary between browser components and web-application content. This manager enforces policies that control which components can access content, allowing legitimate functionality while blocking unauthorized access. The manager acts as a security gatekeeper that mediates all interactions between components and content.
Solution Approach 2:
The system dynamically changes the access parameters of browser components based on risk profiles and policy evaluations. Components are granted or revoked access rights depending on their security clearance level, the sensitivity of the content, and current risk conditions. This allows the same component to have different access permissions at different times.
2Reliability
If browser components are dynamically controlled based on risk profiles, then security is improved, but system complexity increases
Solution Approach 1:
The browser component manager is designed as a universal system that handles multiple functions: policy enforcement, risk assessment, component registration, and access control. By consolidating these diverse functions into a single multi-functional manager, the system reduces overall complexity compared to having separate mechanisms for each function.
Solution Approach 2:
The system performs preliminary risk assessments and policy evaluations before granting component access to web-application content. By pre-evaluating components and establishing access rules in advance, the system avoids complex real-time decision-making during content access, thereby reducing operational complexity.
3Reliability
If session is transferred to hosted browser, then security control is improved, but connection time and latency increase
Solution Approach 1:
The patent implements a nested browser architecture where an embedded browser runs within the hosted browser environment. This allows the embedded browser to maintain local control for routine operations while the hosted browser provides the security control layer. The nesting enables seamless session transfer without requiring complete reconnection, reducing latency.
Solution Approach 2:
The system maintains continuous session state and component configurations during transfer between embedded and hosted browsers. By preserving the session context and avoiding complete re-initialization, the system minimizes connection time while maintaining security control through the hosted browser's policy enforcement capabilities.
Data Source
AI summary
Embodiments described include systems and methods for securely managing browser plugins via embedded browser. The solution enables a client application or embedded browser to dynamically load the browser components into the embedded browser based on a risk or security profile and one or more policies. The policies can be centrally managed to enable only allowed browser components to be loaded within the embedded browser for a given risk profile. Based on the risk profile, a session established by the embedded browser can be transferred from the client application to a hosted browser at a secure server. When the session is transferred to the hosted browser, the present system can also redirect the browser component configurations to the hosted browser such that the same browser components are enabled, disabled, or modified at the hosted browser.


