Isolated Secure Web Browser Access for BYOD Enterprise Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increased vulnerability of modern communications networks to cyberattacks due to the proliferation of personal user equipment (BYOD) and cloud-based services complicates the protection of enterprise data and resources, necessitating enhanced cyber security measures.
Innovation Solution
A cyber secure communications system (CyberSafe) with a cloud-based data and processing security hub and a secure web browser (SWB) in an isolated environment, which monitors and controls data ingress and egress, enforces security policies, and provides real-time anomaly detection and risk assessment to protect enterprise resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If personal user equipment (BYOD) and cloud-based services are proliferated to enable remote work and access to enterprise resources, then accessibility and convenience are improved, but vulnerability to cyberattacks and data leakage risks increase
Solution Approach 1:
The system segments the enterprise data environment from personal devices by deploying isolated browser instances that create separate execution contexts. Each browser instance operates in an isolated environment with restricted access to system resources, preventing personal devices from directly accessing enterprise resources while still enabling remote work accessibility.
Solution Approach 2:
The patent introduces an intermediary security layer between personal devices and enterprise resources. The isolated browser environment acts as a mediator that controls and monitors all communications, enforcing security policies and preventing direct access that could lead to cyberattacks or data leakage.
2Reliability
If comprehensive security monitoring and control measures are implemented to protect enterprise data, then security protection is improved, but system complexity and processing overhead increase
Solution Approach 1:
The monitoring and control functions are segmented into modular components including policy enforcement modules, anomaly detection modules, and communication interception modules. Each module operates independently within the isolated browser environment, managing security complexity through functional decomposition while maintaining comprehensive data protection.
Solution Approach 2:
The isolated browser environment implements self-service security mechanisms where the system automatically enforces security policies, monitors communications, and detects anomalies without requiring extensive external management. The security hub autonomously manages threat response and policy application, reducing operational complexity.
3Reliability
If isolated secure environments are deployed on each user device to control data access, then data security is improved, but device resource consumption and performance overhead increase
Solution Approach 1:
The patent applies local quality by creating focused isolation only for browser processes that access enterprise resources, rather than isolating entire operating systems. The security measures are concentrated specifically where enterprise data access occurs, providing strong security protection while minimizing impact on overall device performance and resource consumption.
Solution Approach 2:
The system dynamically adjusts isolation parameters and security monitoring intensity based on the context of resource access. When enterprise resources are accessed, enhanced security parameters are applied; during personal device operations, the system operates with reduced overhead, optimizing the balance between security and performance.
Data Source
AI summary
A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.


