Browser Extension Re-Authorization for Policy-Based Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Browser extensions have access to sensitive data and can be exploited for malware and adware, posing security risks, and managing them on unmanaged devices is challenging.
Innovation Solution
A policy-based browser system that includes a client device, web server, and mid-link server to manage browser extensions, analyzing usage history, and enforcing policies for secure access, allowing or blocking extensions based on compliance with predefined policies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If browser extensions are allowed to access functionalities on web browsers, then user functionality and convenience are improved, but security risks increase due to potential malware and adware
Solution Approach 1:
The system performs preliminary analysis of browser extensions before allowing installation. The mid-link server checks extensions against predefined policies and usage history before granting access, preventing potentially harmful extensions from being installed in the first place
Solution Approach 2:
A mid-link server is introduced as an intermediary between the client device and the browser extension installation process. This mediator evaluates extensions against policies and usage history, acting as a security gatekeeper that allows or blocks extensions based on compliance assessment
2Reliability
If strict policies are enforced for browser extension installation, then security is improved, but ease of operation deteriorates due to additional review processes
Solution Approach 1:
The system automatically evaluates browser extensions against predefined policies and usage history without requiring manual intervention. The mid-link server autonomously makes determination to allow or block extensions based on policy compliance, eliminating the need for user involvement in the security review process
3Adaptability or versatility
If browser extensions are managed on unmanaged devices, then user flexibility is improved, but administrative control and security management deteriorate
Solution Approach 1:
The system replaces traditional mechanical/administrative control methods with automated policy-based evaluation. Instead of requiring manual administrative approval for each extension on unmanaged devices, the system uses automated policy checking and usage history analysis to make security determinations
Data Source
AI summary
A policy-based browser system for managing browser extensions used to access functionalities on a web browser in a cloud-based multi-tenant system. The policy-based browser system includes a client device, a web server, and a mid-link server. A set of policies is identified for the installation of a browser extension requested using the client device. The policies specify access to browser extensions at the client device for accessing functionalities associated with the browser extensions. The functionalities are associated with a user application on the client device. The browser extension is analyzed based on usage history for the installation of the browser extension. Non-compliance with one or more policies from the set of policies of the browser extension is flagged for a re-authorization. Based on the re-authorization, either the browser extension is allowed or blocked or partially allowed for the installation and access to the corresponding functionality of the browser extension.


