Browser-Based Secure Desktop Isolating Sensitive Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing platforms face challenges in securely accessing sensitive data due to the risk of malware compromising devices, even when enterprises restrict device usage and implement authentication procedures, as these methods may still allow unauthorized access to secure connections and authentication information.

Innovation Solution

An on-demand, browser-based secure desktop environment is provided that establishes a secure connection between a computing platform and a trusted entity, preventing untrusted applications from accessing sensitive data by using a secure desktop application that is downloadable on-demand, which enforces policies based on user and device profiles and stores data remotely for virtual, always-on functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If enterprises restrict computing devices to access sensitive data, then security is improved, but user choice and device flexibility are worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a browser-based secure desktop environment as an intermediary layer between the user's computing device and the sensitive data. This secure desktop acts as a mediator that enforces security policies while allowing users to access enterprise resources from various devices, thus resolving the contradiction between security and device flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the computing environment into a trusted secure desktop environment and an untrusted external environment. The secure desktop is segmented as a separate browser-based instance that isolates sensitive data access, allowing users to maintain flexibility in device choice while security is enforced within the segmented secure boundary.

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication procedures are implemented, then access control is improved, but the risk of malware compromising authentication information remains

Engineering Contradiction:
Improveaccess controlVSAvoidmalware risk to authentication
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts authentication information and sensitive data from the traditional operating system environment and relocates them into the isolated browser-based secure desktop environment. This extraction ensures that even if malware compromises the host device, the authentication information stored in the secure desktop remains protected.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure desktop serves as an intermediary that handles authentication procedures. By implementing authentication within this isolated environment rather than relying on the host operating system, the system maintains access control while protecting against malware that may compromise the host device.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If secure connections are established, then data protection is improved, but unauthorized access to secure connections may still occur

Engineering Contradiction:
Improvedata protectionVSAvoidunauthorized access to secure connections
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts secure connection establishment from the general network stack and implements it within the isolated secure desktop environment. By taking out the secure connection logic and isolating it within the browser-based desktop, the system prevents unauthorized access even when the host device is compromised.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The secure desktop acts as an intermediary that manages secure connections between the user's device and enterprise resources. This intermediary enforces data protection policies and controls access to secure connections, preventing unauthorized access while maintaining robust data protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If device restrictions are imposed, then security is improved, but ease of operation and user convenience are worsened

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a universal secure desktop environment that can be accessed from multiple different computing devices (laptops, tablets, smartphones) while maintaining consistent security policies and user experience. This universality improves ease of operation by allowing users to access enterprise resources from any device without encountering different security restrictions, while still maintaining strong security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9047476B2Browser-based secure desktop applications for open computing platforms
Publication Date: 2015.06.02 AT&T INTELLECTUAL PROPERTY I L P
  • US9047476B2 patent drawing
  • US9047476B2 patent drawing
  • US9047476B2 patent drawing

AI summary

Example browser-based secure desktop applications for open computing platforms are disclosed. An example method disclosed herein to provide secure desktop functionality to a computing platform comprises providing, in response to a first request, a secure desktop application to the computing platform, the secure desktop application for execution by a browser on the computing platform, and establishing a secure communication connection between a service node and the secure desktop application, the secure communication connection to provide the secure desktop application with access to a trusted entity, the secure communication connection being accessible to a trusted application downloaded to the computing platform for execution by the browser in association with the secure desktop application, the secure communication connection being inaccessible to an untrusted application not executed in association with the secure desktop application.