Embedded Browser Session State Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprise computing environments face challenges in managing and monitoring Software-as-a-Service (SaaS) applications due to their isolation and lack of secure integration with devices, leading to limited contextual awareness and reduced productivity, as SaaS apps do not seamlessly transition between devices or understand user context.
Innovation Solution
The implementation of an embedded browser within a client application that maintains the state of SaaS sessions across different devices, allowing users to roam sessions securely and integrate with beacons and IoT devices, enabling logon/logoff based on proximity and context switching.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If SaaS applications are managed in isolation from one another, then each application can be securely accessed, but contextual awareness is lost and productivity is reduced
Solution Approach 1:
The patent combines multiple SaaS application sessions into a unified session state managed by the embedded browser. The browser maintains a consolidated session state that encompasses multiple applications, allowing the system to track user context across applications while preserving secure access controls. This merging enables contextual awareness without compromising the security of individual applications.
Solution Approach 2:
The embedded browser serves as a universal session manager that handles multiple SaaS applications through a single interface. Rather than requiring separate session management for each application, the browser provides multi-functional session state maintenance that works across different applications, enabling contextual awareness while maintaining secure access through a unified mechanism.
2Adaptability or versatility
If SaaS applications are integrated with devices, then contextual awareness improves, but security risks increase
Solution Approach 1:
The embedded browser acts as an intermediary between the device and SaaS applications, mediating session state management. Rather than allowing direct integration between devices and multiple applications (which would increase security risks), the browser serves as a secure intermediary that maintains session state and provides contextual awareness while preserving security boundaries. The browser controls and filters interactions, reducing security exposure.
Solution Approach 2:
The embedded browser performs self-service session management by automatically maintaining session state without requiring direct device-level integration with each application. The browser handles authentication, session persistence, and context management autonomously, reducing the security surface area while maintaining contextual awareness. This self-contained approach minimizes security risks associated with broad device integration.
3Productivity
If session state is maintained across devices, then user productivity improves, but system complexity increases
Solution Approach 1:
The embedded browser creates and maintains a copy of the session state locally on the device while synchronizing with the server. This copying mechanism enables seamless session roaming across devices by replicating essential session information, allowing users to continue work on different devices without increasing overall system complexity. The local copy provides immediate access to session context while the server maintains the authoritative state.
4Loss of information
If embedded browser is integrated with client application, then real-time visibility to traffic is achieved, but device resources are consumed
Solution Approach 1:
The embedded browser implements partial monitoring of traffic by focusing on session-relevant communications rather than all device traffic. This selective approach provides real-time visibility to authentication and session-related traffic while consuming fewer device resources. The browser prioritizes monitoring critical session data over comprehensive traffic analysis, achieving necessary visibility with reduced resource overhead.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system for maintaining a state of a session of a network application across different client device is disclosed. A first client application establishes sessions of a user to a network application. Each of the sessions is accessed via a first embedded browser of a first client application. The first client application stores a state of the sessions to a workspace service in association with the user, and a context of the user to a workspace hub. A second client application establishes the sessions to the network application based on the state of the sessions obtained via the workspace service that are each accessed via a second embedded browser of the second client application. The second client application updates the state of the sessions to a second state based on detection of a state change and a context of the user obtained from the workspace hub.