Managed Mobile Web Access Through Secure Split Tunneling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems require users to use two different browsers for accessing internal and external websites, which is inconvenient, especially in a Bring Your Own Device (BYOD) scenario, and pose security risks due to potential malware and data leakage.

Innovation Solution

A system and method integrating a single web browser on managed mobile devices using a Mobile Device Management (MDM) system, employing a Proxy Auto-Config (PAC) file and internal/external Web Application Firewalls (WAFs) to securely redirect and inspect traffic, ensuring safe access to internal and external websites.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If two different browsers are used to access internal and external websites, then security is improved by isolating traffic, but user convenience deteriorates due to the need to switch browsers

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments network traffic at the proxy level rather than requiring separate browsers. The proxy server divides web requests into internal (intranet) and external (internet) streams, applying different security policies to each stream while presenting a unified browser interface to the user. This resolves the contradiction by maintaining security isolation without forcing users to switch between browsers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a proxy server as an intermediary between the user's browser and both internal and external websites. This intermediary automatically routes traffic based on URL analysis, applying appropriate security measures for each destination type. The proxy acts as a transparent mediator that maintains security boundaries while allowing seamless user access through a single browser.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Data Leakage Prevention (DLP) is enabled on the mail client, then data protection is improved, but user convenience deteriorates as users must manually type URLs

Engineering Contradiction:
Improvedata protectionVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service functionality where the proxy server automatically analyzes URLs in email messages and determines whether they are internal or external links. The system autonomously routes these links through appropriate security channels without requiring user intervention or manual URL entry. This resolves the contradiction by maintaining DLP protection while eliminating the need for users to manually type URLs.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary analysis of web requests at the proxy level before traffic reaches the user's browser. By pre-classifying URLs as internal or external and pre-configuring appropriate security policies, the system prepares the access path in advance. This preliminary action eliminates the need for users to manually configure settings or type URLs, maintaining both security and convenience.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If a single browser is used to access both internal and external websites, then user convenience is improved, but security control deteriorates due to inability to differentiate traffic streams

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments network traffic at the proxy server level by analyzing request URLs and routing them to different destination streams (internal intranet or external internet). This segmentation maintains security control by applying appropriate policies to each stream while allowing users to access both types of websites through a single unified browser interface.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The proxy server acts as an intelligent intermediary that sits between the user's single browser and both internal and external networks. It automatically differentiates traffic streams by analyzing request characteristics and applying appropriate security controls for each destination type, thereby maintaining security control while enabling convenient single-browser access.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If Web Application Firewall (WAF) inspection is applied to all traffic, then security is improved, but processing time deteriorates due to decryption requirements

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by differentiating security inspection requirements for different traffic streams. Internal traffic encrypted via VPN is exempt from WAF inspection since it already has strong encryption and authentication. External traffic is subjected to WAF inspection with SSL decryption. This localized approach to security inspection reduces overall processing time while maintaining appropriate security for each traffic type.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial inspection by applying WAF security measures only to external internet traffic that requires SSL decryption, while exempting internal VPN-encrypted traffic from this additional inspection step. This partial application of security measures reduces processing time for the majority of internal traffic while maintaining security for external traffic through targeted inspection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12438847B2System and method for integrating systems to access websites by managed mobile devices
Publication Date: 2025.10.07 SAUDI ARABIAN OIL CO
  • US12438847B2 patent drawing
  • US12438847B2 patent drawing
  • US12438847B2 patent drawing

AI summary

Network systems integration and method inspect network traffic to enable secure access to internal and Internet websites from managed mobile devices. The integrated networks system implements a secure split tunneling to allow users of mobile devices managed by an organization Mobile Device Management system to securely browse only safe websites on the Internet or on an intranet resource of the organization. The system includes an internal firewall, a reception firewall, internal and external web application firewalls, a reverse proxy, an Internet proxy, and an enterprise mobility management system having a VPN-Tunnel system to implement the secure split tunneling method.