Secure Browser Embedded in Local Browser for Data Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data systems face challenges in accessing and exchanging sensitive data from resources that do not provide automated means, such as APIs, and impose restrictions on automation measures, making it difficult to securely retrieve and store sensitive information.

Innovation Solution

The implementation of a secure browser managed by a remote virtual machine, which is embedded in a local browser, allows for secure data access, transmission, and storage by preventing data exposure to malware, malicious actors, or local device users through the use of preconfigured directories and security policies that disable certain commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated means (APIs) are used for data access, then data retrieval efficiency is improved, but security control and compliance with data privacy regulations deteriorate

Engineering Contradiction:
Improvedata retrieval efficiencyVSAvoidsecurity control
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a secure browser as an intermediary component between the data system and external resources. This secure browser runs within a sandboxed environment and mediates all data access operations, allowing automated data retrieval while maintaining security controls. The intermediary enables compliance with data privacy regulations by preventing direct access to sensitive data and enforcing security policies during data exchange operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If automation measures are employed for data exchange, then data transmission speed is improved, but security restrictions and compliance requirements worsen

Engineering Contradiction:
Improvedata transmission speedVSAvoidsecurity restrictions
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security configuration by pre-configuring the secure browser with security policies, sandboxing parameters, and compliance rules before data transmission begins. This preliminary action establishes security boundaries and automation constraints in advance, enabling fast data transmission while pre-enforcing security restrictions and regulatory compliance requirements.

Inventive Principle:
Principle #10Preliminary action

3Quantity of substance

If sensitive data is accessed from restricted resources, then data completeness is improved, but security risk and exposure to malware worsen

Engineering Contradiction:
Improvedata completenessVSAvoidsecurity risk
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The patent segments the data access environment by creating a sandboxed secure browser instance that is isolated from the main system. This segmentation allows the system to access complete sensitive data from restricted resources while containing security risks within the sandboxed environment. The segmentation prevents malware and security threats from propagating to the host system while maintaining full data access capability within the isolated environment.

Inventive Principle:
Principle #1Segmentation

4Reliability

If secure browsers managed by remote virtual machines are implemented, then security isolation is improved, but device complexity worsens

Engineering Contradiction:
Improvesecurity isolationVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the secure browser functionality from the local device and relocates it to a remote virtual machine environment. This extraction improves security isolation by removing the secure browser from the potentially compromised local device. The complex virtualization and remote management infrastructure is taken out from the end-user device and consolidated in a controlled remote environment, reducing local device complexity while maintaining high security isolation.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250165586A1Data management using secure browsers
Publication Date: 2025.05.22 STRIPE LLC
  • US20250165586A1 patent drawing
  • US20250165586A1 patent drawing
  • US20250165586A1 patent drawing

AI summary

Various embodiments described herein support or provide for data management operations, such as receiving a request to access a webpage; determining that accessing the webpage requires secure access via a secure browser; identifying a virtual machine that is configured to allow access to the webpage; and causing display of the webpage in the secure browser embedded in a local browser of the sender device.