Remote Browser Isolation for Unmanaged Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud-based services face security risks when accessed via unmanaged devices, as the security posture of these devices is not assured, potentially leading to compromised information due to malware or undesirable data downloads.
Innovation Solution
Implementing remote browser isolation, where user authentication occurs via a managed device, and a cached credential establishes a connection to a cloud-based service through a trusted node, using a remote browser instance that streams information without storing data on the unmanaged device, and applies policies to limit data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If access to cloud-based services is allowed via unmanaged devices, then user convenience and accessibility are improved, but security risks increase due to malware and unverified device posture
Solution Approach 1:
A remote browser isolation service acts as an intermediary between the unmanaged device and the cloud-based service. The service receives authentication requests from unmanaged devices, verifies credentials against a managed device's cached authentication, and provides access through an isolated remote browser instance. This mediator enables accessibility while preventing direct exposure of the unmanaged device to sensitive services.
Solution Approach 2:
The system segments the authentication process into two distinct parts: (1) initial authentication performed on a managed device with verified security posture, and (2) service access granted to unmanaged devices using cached credentials from the managed device. This segmentation allows unmanaged devices to access services without compromising security, as the critical authentication step occurs in a controlled environment.
2Productivity
If sensitive information is made accessible via unmanaged devices, then user productivity is improved, but data security is compromised due to potential malware and unauthorized downloads
Solution Approach 1:
The system creates an inert security environment through remote browser isolation. The unmanaged device connects to an isolated remote browser instance that runs in a controlled, sandboxed environment. This isolation prevents malware on the unmanaged device from interacting with or compromising sensitive information, while still allowing full access to cloud-based services. The isolated environment acts as a protective barrier similar to an inert atmosphere.
Solution Approach 2:
Instead of providing direct access to sensitive information on the unmanaged device, the system creates a copied access experience through a remote browser instance. The remote browser renders and streams a visual copy of the cloud-based service interface to the unmanaged device, allowing users to interact with information without transferring actual data to the unmanaged device. This copying approach maintains productivity while eliminating data security risks.
3Reliability
If authentication is performed on managed devices only, then security posture is maintained, but accessibility from unmanaged devices is limited
Solution Approach 1:
The system performs preliminary authentication on the managed device before granting access to unmanaged devices. The managed device authenticates the user and caches the authentication credentials. Subsequently, unmanaged devices can use these cached credentials to access services without performing new authentication. This preliminary action on the managed device enables broad accessibility while maintaining security, as the critical verification occurs once in a controlled environment.
Solution Approach 2:
The remote browser isolation service acts as an intermediary that bridges managed and unmanaged devices. It receives authentication requests from unmanaged devices, verifies them against cached credentials from the managed device, and grants access accordingly. This intermediary enables unmanaged devices to access services with the same security guarantees as managed devices, without requiring the unmanaged devices themselves to have verified security posture.
Data Source
AI summary
Techniques to provide secure access to a service via an unmanaged device are disclosed. In various embodiments, a request from an unmanaged device to access a service is received via a communication interface. A user associated with the request is authenticated at least in part by prompting the user to use a managed device associated with the user to interact with data displayed at the unmanaged device. Access to the service is provided via the unmanaged device at least in part via a virtual browser instance running on a secure node and configured to access the service on behalf of the user and stream data associated with the service to the unmanaged device.


