Isolated Secure Web Browser Access for BYOD Enterprise Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased vulnerability of modern communications networks to cyberattacks due to the proliferation of personal user equipment (BYOD) and cloud-based services complicates the protection of enterprise data and resources, necessitating enhanced cyber security measures.

Innovation Solution

A cyber secure communications system (CyberSafe) with a cloud-based data and processing security hub and a secure web browser (SWB) in an isolated environment, which monitors and controls data ingress and egress, enforces security policies, and provides real-time anomaly detection and risk assessment to protect enterprise resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personal user equipment (BYOD) and cloud-based services are proliferated to enable remote work and access to enterprise resources, then accessibility and convenience are improved, but vulnerability to cyberattacks and data leakage risks increase

Engineering Contradiction:
Improveaccessibility to enterprise resourcesVSAvoidcyberattack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments the enterprise data environment from personal devices by deploying isolated browser instances that create separate execution contexts. Each browser instance operates in an isolated environment with restricted access to system resources, preventing personal devices from directly accessing enterprise resources while still enabling remote work accessibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary security layer between personal devices and enterprise resources. The isolated browser environment acts as a mediator that controls and monitors all communications, enforcing security policies and preventing direct access that could lead to cyberattacks or data leakage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security monitoring and control measures are implemented to protect enterprise data, then security protection is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvedata protection capabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring and control functions are segmented into modular components including policy enforcement modules, anomaly detection modules, and communication interception modules. Each module operates independently within the isolated browser environment, managing security complexity through functional decomposition while maintaining comprehensive data protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The isolated browser environment implements self-service security mechanisms where the system automatically enforces security policies, monitors communications, and detects anomalies without requiring extensive external management. The security hub autonomously manages threat response and policy application, reducing operational complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If isolated secure environments are deployed on each user device to control data access, then data security is improved, but device resource consumption and performance overhead increase

Engineering Contradiction:
Improveenterprise data securityVSAvoiddevice resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by creating focused isolation only for browser processes that access enterprise resources, rather than isolating entire operating systems. The security measures are concentrated specifically where enterprise data access occurs, providing strong security protection while minimizing impact on overall device performance and resource consumption.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts isolation parameters and security monitoring intensity based on the context of resource access. When enterprise resources are accessed, enhanced security parameters are applied; during personal device operations, the system operates with reduced overhead, optimizing the balance between security and performance.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12413624B2Cyber secure communications system
Publication Date: 2025.09.09 PALO ALTO NETWORKS INC
  • US12413624B2 patent drawing
  • US12413624B2 patent drawing
  • US12413624B2 patent drawing

AI summary

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.