Secure Browser Launch from Privileged Process
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face vulnerabilities when users log in with compromised web browsers, leading to exposure to viruses, trojans, and malware due to the launch of browsers from privileged processes, which can result in security breaches and system infections.
Innovation Solution
A secure method is implemented where a limited user account launches a web browser from a privileged process with restricted rights, preventing writes to the file system or registry, and using an https protocol to authenticate and change forgotten passwords without exposing the enterprise to vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a web browser is launched from a privileged process to enable users to change passwords, then user authentication capability is improved, but enterprise security vulnerability increases due to exposure to viruses, trojans, and malware
Solution Approach 1:
The system segments the user account into two distinct modes: a limited functionality account for browser operations and a full functionality account for system access. This segmentation allows the browser to run with restricted privileges, preventing malware from compromising the entire system while still enabling password change operations.
Solution Approach 2:
The patent introduces an intermediary executable file that acts as a mediator between the privileged process and the web browser. This intermediary imposes restrictions on browser capabilities (preventing registry writes, ActiveX installation, etc.) and controls the browser's interaction with the file system, thereby reducing security vulnerabilities while maintaining authentication functionality.
2Object-affected harmful factors
If a limited user account is used to launch the browser to prevent malware infections, then enterprise security is improved, but browser functionality is restricted
Solution Approach 1:
The system dynamically adjusts the user account's functionality based on the operational context. When the browser is launched for password recovery, the limited account is used with specific restrictions. Upon successful authentication, the system dynamically transitions to a full functionality account, restoring complete browser capabilities. This dynamic adjustment maintains security during vulnerable operations while preserving functionality when needed.
Solution Approach 2:
The patent changes the privilege parameters of the user account during the authentication process. The account starts with limited permissions (read-only access, no registry writes, no ActiveX installation), and upon successful password verification, the permissions are changed to full functionality. This parameter change allows the system to balance security and functionality based on the authentication state.
3Object-affected harmful factors
If an executable file imposes restrictions on browser capabilities to prevent malware installation, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The executable file implements preliminary actions by pre-configuring the browser environment with necessary permissions and restrictions before the user interacts with it. The system pre-loads required components, pre-establishes safe browsing parameters, and pre-configures the restricted environment, thereby reducing the impact of restrictions on user operation during the actual password change process.
Data Source
AI summary
Methods and apparatus include securely launching a web browser from a privileged process of a workstation to minimize enterprise vulnerabilities. The workstation includes a restricted-capability web browser pointed toward a web server. An executable file is wrapped about the browser and imposes restrictions, such as preventing the writing to a registry or installing ActiveX controls. It also has functionality to prevent users from linking to web locations in other than an https protocol or following links beyond an original host. Upon indication of a forgotten password/credential, the restricted-capability web is launched browser toward a web server. Upon authentication of identity, the user changes their password/credential for later logging-on to the workstation, but in a capacity without the limited functionality or the imposed browser restrictions.


