Secure Browser Mediator for Enterprise Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Corporations face security risks when allowing remote access to their enterprise networks through personal devices, as they lack control over these devices and users are hesitant to allow employer access, leading to a need for secure and policy-based access solutions.

Innovation Solution

A system and method that involve a client device receiving policies for resource access, using a secure application to manage encrypted repositories, and selecting appropriate applications to open resources based on these policies, while establishing secure communication channels and authenticating users to ensure controlled access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If an enterprise network is opened to external access through VPN or other means to allow employees remote access to internal resources, then ease of operation is improved, but security risks increase due to lack of control over personal devices

Engineering Contradiction:
Improveremote access to internal resourcesVSAvoidsecurity risks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A secure browser application acts as an intermediary between the enterprise network and personal devices. This secure browser creates a controlled communication channel that allows remote access to internal resources while maintaining security boundaries. The secure browser mediates all interactions, preventing direct access to the enterprise network and thereby reducing security risks associated with uncontrolled personal device connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies different security policies to different applications and resources. The secure browser enforces specific security policies locally within its environment, allowing controlled access to enterprise resources while maintaining strict security boundaries. This localized security approach enables remote access functionality while containing security risks within defined boundaries rather than applying uniform restrictions across all system access.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If personal devices are used for remote access to enterprise networks, then ease of operation is improved, but device complexity increases due to the need for policy enforcement and control mechanisms

Engineering Contradiction:
Improveaccess from personal devicesVSAvoidpolicy enforcement mechanisms
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent segments the device ecosystem into distinct zones with different security requirements. Personal devices are separated from the enterprise network core, with a secure browser creating an isolated environment for enterprise resource access. This segmentation allows personal devices to maintain their simplicity while the secure browser handles the complexity of policy enforcement and security control mechanisms in a dedicated, isolated space.

Inventive Principle:
Principle #1Segmentation

3Reliability

If employers exert control over personal devices to allow remote access, then security is improved, but ease of operation deteriorates due to user resistance and privacy concerns

Engineering Contradiction:
Improvesecurity controlVSAvoiduser acceptance
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The secure browser serves as an intermediary that implements employer control requirements without directly modifying or controlling the personal device itself. All security policies and control mechanisms are enforced within the secure browser's isolated environment, allowing employers to maintain security control while leaving the personal device and its data untouched. This mediates the conflict between security control needs and user privacy concerns.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If a secure browser application is implemented to enforce policies, then security is improved, but device complexity increases due to the additional application and encryption mechanisms

Engineering Contradiction:
Improvesecure access controlVSAvoidapplication architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure browser creates a segmented, isolated environment for enterprise resource access. By confining security-sensitive operations within this dedicated secure zone, the patent avoids the need to implement complex security mechanisms across the entire device architecture. The segmentation allows security functions to be concentrated in a manageable, isolated space rather than distributed throughout the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure browser creates a virtual copy or representation of the enterprise network environment within the personal device. This virtualized secure environment replicates necessary enterprise functions and security controls without requiring direct integration with the personal device's core systems. The copying approach allows security mechanisms to operate in an isolated virtual space, reducing the complexity impact on the host device architecture.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9813421B2Systems and methods for secure resource access and network communication
Publication Date: 2017.11.07 BOX INC
  • US9813421B2 patent drawing
  • US9813421B2 patent drawing
  • US9813421B2 patent drawing

AI summary

Systems and methods for secure resource access and network communication are provided. A plurality of policies are received on a client device, each policy comprising a respective resource and a respective permission for a respective action that can be performed by a user of the client device in regards to the resource. A first application, which is configured to store data in an encrypted repository on the client device, receives a request to open a resource. The first application determines that one of the policies prohibits access by the resource to the encrypted repository and, based thereon, selects a different second application to open the resource that does not have access to the encrypted repository. The second application then opens the resource.