Secure Web Browser Isolation for BYOD Corporate Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased vulnerability of communications networks to cyberattacks due to the use of personal devices (BYOD) and the complexity of protecting enterprise data in cloud environments complicates the provision of cyber protection and confidentiality.

Innovation Solution

A cyber secure communications system (CyberSafe) with a data and processing security hub and a secure web browser (SWB) in an isolated environment, monitoring and controlling data ingress and egress, enforcing security policies, and providing enhanced visibility and protection against cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personal devices (BYOD) are allowed to access enterprise resources, then accessibility and ease of operation are improved, but vulnerability to cyberattacks and security risks increase

Engineering Contradiction:
Improveaccessibility to enterprise resourcesVSAvoidvulnerability to cyberattacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments the enterprise resource access by creating a dedicated secure web browser environment that is isolated from the personal device's ambient software. This segmentation allows personal devices to access enterprise resources while maintaining a clear boundary that prevents malware and harmful factors from the personal device from affecting enterprise resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure web browser acts as an intermediary between the personal device and enterprise resources. It mediates all communications and data transfers, enforcing security policies and preventing direct access that could expose enterprise resources to cyberattacks. The browser environment serves as a controlled buffer zone.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure isolation environments are implemented, then protection against cyberattacks is improved, but device complexity increases

Engineering Contradiction:
Improveprotection against cyberattacksVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure web browser is designed to be a universal solution that can be deployed on any personal device regardless of the device's operating system or hardware configuration. This multi-functionality approach allows the same browser environment to provide consistent security isolation across diverse devices, avoiding the need for device-specific complex security architectures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the parameter of security enforcement from the device level to the application level. Instead of modifying device-level security parameters, the secure browser implements security policies as configurable parameters within the browser environment, simplifying the overall system architecture while maintaining strong protection.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If monitoring and control of data ingress and egress are implemented, then data leakage prevention is improved, but loss of information and operational flexibility increase

Engineering Contradiction:
Improvedata leakage preventionVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The security policy enforcement is designed to be dynamic rather than static. The secure web browser can adaptively control data ingress and egress based on real-time security assessments, user actions, and policy configurations. This dynamic approach prevents data leakage while maintaining operational flexibility by allowing legitimate business operations to proceed without unnecessary restrictions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the secure browser continuously monitors data flows and user interactions, then adjusts its control measures accordingly. This feedback loop ensures that data leakage prevention is effective while minimizing impact on operational flexibility, as the system learns from and adapts to legitimate business patterns.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250284812A1Browser managed access of corporate resources
Publication Date: 2025.09.11 PALO ALTO NETWORKS INC
  • US20250284812A1 patent drawing
  • US20250284812A1 patent drawing
  • US20250284812A1 patent drawing

AI summary

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.