Secure Web Browser Isolation for BYOD Data Leakage Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased vulnerability of communications networks and digital resources due to the proliferation of personal devices (BYOD) and cloud-based services complicates cyber protection, making them susceptible to cyberattacks and data leakage.

Innovation Solution

A cyber secure communications system (CyberSafe) with a secure web browser (SWB) in an isolated environment (CISE) monitors and controls data ingress and egress, enforces security policies, and provides enhanced visibility and protection against cyber threats by integrating with a data and processing security hub.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personal devices (BYOD) and cloud-based services are proliferated to enable remote work and accessibility, then ease of operation and adaptability are improved, but vulnerability to cyberattacks and data leakage increases

Engineering Contradiction:
Improveremote work accessibilityVSAvoidcyberattack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments the device environment into a secure container for business operations and the rest of the device for personal use. The containerized browser creates an isolated execution environment that separates business data and applications from personal data, preventing cross-contamination while allowing both personal and business activities to coexist on the same device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure container acts as an intermediary layer between the untrusted personal device environment and the business data/resources. It provides a controlled interface that allows business applications to access device resources only through defined security policies, blocking direct access to personal data and applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a secure container environment is implemented to isolate business activities, then cyber protection is improved, but device complexity increases

Engineering Contradiction:
Improvecyber protectionVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The containerization framework provides multiple security functions through a single unified mechanism. It simultaneously achieves process isolation, data protection, policy enforcement, and application sandboxing, eliminating the need for separate complex security systems while maintaining comprehensive protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the operational parameters of the browser by imposing strict resource constraints and security policies on the containerized environment. This includes limiting file system access, network permissions, and hardware resource usage, thereby achieving security through parameter control rather than architectural complexity.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If monitoring and control of data ingress and egress is enforced, then data leakage protection is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedata leakage protectionVSAvoiduser interaction freedom
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service security by automatically monitoring and controlling data flows between the container and external environments. Security policies are enforced automatically without requiring user awareness or intervention, allowing users to operate freely within the container while background processes handle security monitoring and control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250284813A1Managing permitted browser related risky activity in a secure environment
Publication Date: 2025.09.11 PALO ALTO NETWORKS INC
  • US20250284813A1 patent drawing
  • US20250284813A1 patent drawing
  • US20250284813A1 patent drawing

AI summary

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.