Intermediate Browser Mediator for Enterprise Application Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems lack effective control over application access in enterprise environments, particularly when users access enterprise applications with personal devices that may have unmanaged vulnerabilities, leading to security concerns and data leakage risks.
Innovation Solution
A system utilizing an intermediate browser that generates control profiles based on user authorization levels, enabling secure access to enterprise applications by controlling interactions with webpages and sending rendered output to local browsers, while preventing unauthorized actions and monitoring user interactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If users access enterprise applications with personal devices, then device availability and user convenience are improved, but security control and data protection deteriorate
Solution Approach 1:
The patent introduces an intermediate browser as a mediator layer between the user's local browser and the enterprise application. This intermediate browser establishes a secure connection that allows users to access enterprise applications via personal devices while maintaining administrative control over data access, download, and interaction permissions. The intermediate browser acts as a security gateway that prevents direct access to enterprise resources.
2Reliability
If administrators implement strict access control measures, then data security is improved, but user accessibility and system usability deteriorate
Solution Approach 1:
The patent implements dynamic permission settings that adjust access control based on user roles, device types, and specific application contexts. The intermediate browser dynamically evaluates user credentials and applies appropriate permission levels, allowing legitimate users to access required resources while automatically blocking unauthorized actions. This dynamic approach maintains security without requiring manual approval for every user action.
Solution Approach 2:
The patent applies different security control levels to different regions or components within the enterprise application interface. The intermediate browser can selectively enable or disable specific functions (such as download, copy, or print) based on the sensitivity of the underlying data, allowing users to freely access non-sensitive areas while restricting access to sensitive regions.
3Adaptability or versatility
If enterprise applications provide full functionality to users, then application utility is improved, but vulnerability to attacks and data leakage deteriorates
Solution Approach 1:
The intermediate browser serves as a protective intermediary that filters and controls all interactions between the user's local browser and the enterprise application. It blocks malicious scripts, prevents unauthorized data exfiltration, and controls clipboard operations, thereby maintaining full application functionality while preventing attacks and data leakage vectors.
Solution Approach 2:
The intermediate browser implements preliminary security measures by pre-configuring permission policies and blocking potential attack vectors before they can execute. It preemptively prevents malicious actions such as automated scraping, unauthorized downloads, or injection attacks by establishing secure boundaries around the enterprise application content.
Data Source
AI summary
A system to control application access is disclosed. The system facilitates user interaction with a target application from a local browser in an additional secure approach. Here, an intermediate browser is communicatively coupled with the client browser to enable access of a user to the target application based on predefined levels of authorization. The system provides a way to define control profiles to control the application interaction based on administrator's needs. The user may access only a specific control profile of the target application.


