Intermediate Browser Mediator for Enterprise Application Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack effective control over application access in enterprise environments, particularly when users access enterprise applications with personal devices that may have unmanaged vulnerabilities, leading to security concerns and data leakage risks.

Innovation Solution

A system utilizing an intermediate browser that generates control profiles based on user authorization levels, enabling secure access to enterprise applications by controlling interactions with webpages and sending rendered output to local browsers, while preventing unauthorized actions and monitoring user interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If users access enterprise applications with personal devices, then device availability and user convenience are improved, but security control and data protection deteriorate

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an intermediate browser as a mediator layer between the user's local browser and the enterprise application. This intermediate browser establishes a secure connection that allows users to access enterprise applications via personal devices while maintaining administrative control over data access, download, and interaction permissions. The intermediate browser acts as a security gateway that prevents direct access to enterprise resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If administrators implement strict access control measures, then data security is improved, but user accessibility and system usability deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiduser accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic permission settings that adjust access control based on user roles, device types, and specific application contexts. The intermediate browser dynamically evaluates user credentials and applies appropriate permission levels, allowing legitimate users to access required resources while automatically blocking unauthorized actions. This dynamic approach maintains security without requiring manual approval for every user action.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different security control levels to different regions or components within the enterprise application interface. The intermediate browser can selectively enable or disable specific functions (such as download, copy, or print) based on the sensitivity of the underlying data, allowing users to freely access non-sensitive areas while restricting access to sensitive regions.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If enterprise applications provide full functionality to users, then application utility is improved, but vulnerability to attacks and data leakage deteriorates

Engineering Contradiction:
Improveapplication utilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The intermediate browser serves as a protective intermediary that filters and controls all interactions between the user's local browser and the enterprise application. It blocks malicious scripts, prevents unauthorized data exfiltration, and controls clipboard operations, thereby maintaining full application functionality while preventing attacks and data leakage vectors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The intermediate browser implements preliminary security measures by pre-configuring permission policies and blocking potential attack vectors before they can execute. It preemptively prevents malicious actions such as automated scraping, unauthorized downloads, or injection attacks by establishing secure boundaries around the enterprise application content.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11743263B2System and method to control application access
Publication Date: 2023.08.29 APPAEGIS INC
  • US11743263B2 patent drawing
  • US11743263B2 patent drawing
  • US11743263B2 patent drawing

AI summary

A system to control application access is disclosed. The system facilitates user interaction with a target application from a local browser in an additional secure approach. Here, an intermediate browser is communicatively coupled with the client browser to enable access of a user to the target application based on predefined levels of authorization. The system provides a way to define control profiles to control the application interaction based on administrator's needs. The user may access only a specific control profile of the target application.