Secure Browser Synchronization Across Isolated BYOD Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increased vulnerability of Bring Your Own Device (BYOD) and workplace user equipment (WPUE) to cyberattacks due to their untethered nature and varied software configurations complicates the provision of cyber protection for enterprise data, especially in remote work scenarios, where multiple networks and cloud services are accessed.

Innovation Solution

A cybersecure system, CyberSafe, is implemented, comprising a secure web browser (SWB) within an isolated secure environment (CISE) on UEs, which monitors and controls data ingress and egress, enforces security policies, and integrates with a cloud-based hub for enhanced visibility and protection, using features like anti-injection software, risk estimation, and Single-Sign-On (SSO) to manage access and mitigate cyber threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If BYOD and WPUE are allowed for remote work access, then employee convenience and productivity are improved, but vulnerability to cyberattacks and security risks increase

Engineering Contradiction:
Improveremote work access convenienceVSAvoidcyberattack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments the UE into multiple isolation environments: a secure environment for enterprise resources and a less secure environment for personal use. This segmentation allows remote work access convenience while containing cyber threats within specific environments, preventing them from affecting the entire device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure browser acts as an intermediary between the user and enterprise resources, mediating all access requests through a controlled interface. This intermediary enforces security policies and monitors communications, enabling convenient remote access while maintaining security controls against cyberattacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple networks and cloud services are accessed for remote work, then work flexibility and productivity are improved, but complexity of providing cyber protection increases

Engineering Contradiction:
Improveremote work flexibilityVSAvoidcyber protection complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The secure browser provides universal security protection across multiple networks and cloud services through a single unified interface. It implements comprehensive security policies including encryption, authentication, and threat detection that work consistently across diverse remote work environments, simplifying cyber protection despite increased flexibility requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure isolation environment is implemented on UE, then cyber security protection is improved, but device resource consumption and operational complexity increase

Engineering Contradiction:
Improvecyber security protectionVSAvoiddevice resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system dynamically manages isolation environments based on usage context, activating secure environments only when enterprise resources are accessed and deactivating them when not needed. This dynamic approach maintains high security reliability while reducing device resource consumption during personal use periods.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20250225246A1Secure browser synchronization across browser instances
Publication Date: 2025.07.10 PALO ALTO NETWORKS INC
  • US20250225246A1 patent drawing
  • US20250225246A1 patent drawing
  • US20250225246A1 patent drawing

AI summary

A communications system for providing secure access to a digital resource of a group of digital resources accessible via the internet, the system comprising: a data processing hub accessible via an IP (internet protocol) address; and a plurality of user equipment (UEs) useable to communicate via the internet, each configured to have a cyber secure isolated environment (CISE) isolated from ambient software in the UE, and comprising a secure web browser (SWB); wherein the hub and CISE are configured so that digital resources in motion and at rest in CISE are visible to the hub.