Enterprise Browser Enforcement Through Token Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in controlling web browser usage efficiently and securely, as existing measures are costly, complex, lack visibility, and are often bypassed, hindering effective management and protection against malware and data leakage.

Innovation Solution

A method is implemented to configure web browsers to interact with identity providers and intermediary servers, using authentication tokens and predefined network addresses to authorize and authenticate user requests, and enforce access control through proxies and DNS servers, ensuring secure and managed communication routing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external control measures are implemented on computers and network infrastructure, then web browser control and security are improved, but device complexity and cost increase

Engineering Contradiction:
Improveweb browser control and securityVSAvoidconfiguration and management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary authentication server that mediates between users and web browsers. This server handles authentication tokens and authorization decisions, externalizing the control logic from individual computers and network infrastructure. The intermediary simplifies the overall system by centralizing security functions, reducing the complexity burden on distributed devices while maintaining reliable browser control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If external control measures are implemented on computers and network infrastructure, then web browser security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveweb browser securityVSAvoiduser work efficiency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication by issuing tokens to users before they access web browsers. This pre-authentication step establishes security credentials in advance, allowing the web browser to operate with pre-validated authorization. Users experience seamless browsing without repeated authentication prompts, as the preliminary token issuance has already secured their access rights, thus maintaining ease of operation while ensuring security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication tokens and intermediary servers are used, then access control and security are improved, but device complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidsystem configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts authentication and authorization logic from individual devices and network infrastructure, consolidating these functions into a dedicated authentication server. By taking out security-critical operations from distributed systems and centralizing them, the patent reduces device complexity across the network while maintaining strong access control. The server handles token validation and authorization decisions, simplifying the overall system architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If traditional external control measures are used, then security monitoring is improved, but visibility to internal web browser operation deteriorates

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidinternal web browser operation visibility
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The authentication server implements feedback mechanisms by receiving and validating authentication tokens from web browsers, and by providing authorization decisions back to users. This bidirectional communication creates visibility into internal browser operations, as the server can track token issuance, validation status, and authorization outcomes. The feedback loop enables comprehensive monitoring of browser activities while maintaining security control.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250279993A1Enforcement of enterprise browser use
Publication Date: 2025.09.04 ISLAND TECH INC
  • US20250279993A1 patent drawing
  • US20250279993A1 patent drawing
  • US20250279993A1 patent drawing

AI summary

Web browser control by configuring a web browser to send to a second computer server, in response to a request by a user of the web browser to access a resource at a first computer server, an authentication token and the request to access the resource, where the second computer server is configured to determine whether the authentication token is valid, and if the authentication token is valid, whether the request to access the resource is authorized, and send to the first computer server, if the request to access the resource is authorized, the request to access the resource, and where the request sent by the second computer server is sent via an intermediary configured to block attempts to access the first computer server that are received from a sender network address that is not a predefined valid network address of the second computer server.