Browser Extension Re-Authorization for Policy-Based Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Browser extensions have access to sensitive data and can be exploited for malware and adware, posing security risks, and managing them on unmanaged devices is challenging.

Innovation Solution

A policy-based browser system that includes a client device, web server, and mid-link server to manage browser extensions, analyzing usage history, and enforcing policies for secure access, allowing or blocking extensions based on compliance with predefined policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If browser extensions are allowed to access functionalities on web browsers, then user functionality and convenience are improved, but security risks increase due to potential malware and adware

Engineering Contradiction:
Improvebrowser extension functionalityVSAvoidsecurity risks from malware and adware
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary analysis of browser extensions before allowing installation. The mid-link server checks extensions against predefined policies and usage history before granting access, preventing potentially harmful extensions from being installed in the first place

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A mid-link server is introduced as an intermediary between the client device and the browser extension installation process. This mediator evaluates extensions against policies and usage history, acting as a security gatekeeper that allows or blocks extensions based on compliance assessment

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict policies are enforced for browser extension installation, then security is improved, but ease of operation deteriorates due to additional review processes

Engineering Contradiction:
Improvesecurity through policy complianceVSAvoidextension installation process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically evaluates browser extensions against predefined policies and usage history without requiring manual intervention. The mid-link server autonomously makes determination to allow or block extensions based on policy compliance, eliminating the need for user involvement in the security review process

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If browser extensions are managed on unmanaged devices, then user flexibility is improved, but administrative control and security management deteriorate

Engineering Contradiction:
Improveuser flexibility on unmanaged devicesVSAvoidadministrative control complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system replaces traditional mechanical/administrative control methods with automated policy-based evaluation. Instead of requiring manual administrative approval for each extension on unmanaged devices, the system uses automated policy checking and usage history analysis to make security determinations

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12542812B2Browser extension access based on re-authorization
Publication Date: 2026.02.03 NETSKOPE INC
  • US12542812B2 patent drawing
  • US12542812B2 patent drawing
  • US12542812B2 patent drawing

AI summary

A policy-based browser system for managing browser extensions used to access functionalities on a web browser in a cloud-based multi-tenant system. The policy-based browser system includes a client device, a web server, and a mid-link server. A set of policies is identified for the installation of a browser extension requested using the client device. The policies specify access to browser extensions at the client device for accessing functionalities associated with the browser extensions. The functionalities are associated with a user application on the client device. The browser extension is analyzed based on usage history for the installation of the browser extension. Non-compliance with one or more policies from the set of policies of the browser extension is flagged for a re-authorization. Based on the re-authorization, either the browser extension is allowed or blocked or partially allowed for the installation and access to the corresponding functionality of the browser extension.