Split Browser Architecture for Centralized Security Policy Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for managing browser security in enterprise environments are inadequate, leading to challenges in preventing malware spread and managing browser options across multiple user machines, which increases the risk of malicious software infections and phishing attacks.

Innovation Solution

A split browser architecture is implemented, where certain browser processes are executed locally on user devices and others remotely on an intermediary system, allowing IT personnel to centrally manage security settings and policies through a common access point, reducing the need for individual machine management and enhancing protection against malware and malicious exploitations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If browser security is managed individually on each user machine, then local control and customization are improved, but IT administration time and complexity increase significantly

Engineering Contradiction:
ImproveLocal browser controlVSAvoidIT administration time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent divides browser management into two segments: local browser instances running on user machines and a centralized remote browser server. The local browsers maintain operational independence for user interactions while the remote server handles security policy enforcement, configuration management, and updates. This segmentation allows individual machines to operate autonomously without requiring manual IT intervention for each browser instance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a remote browser server as an intermediary between IT administrators and local browser instances. This intermediary centralizes management functions including security policy distribution, browser configuration, and update deployment. IT administrators can manage all enterprise browsers through a single access point to the remote server, eliminating the need to individually configure each local browser while maintaining local operational capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security features are enabled in browsers, then protection against malware and phishing is improved, but user browsing experience and simplicity deteriorate

Engineering Contradiction:
ImproveSecurity protectionVSAvoidBrowsing simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary security actions by having the remote browser server pre-configure security policies, enable protective features, and distribute security updates before users access potentially harmful content. The server proactively manages security settings including malware protection, phishing filters, and safe browsing configurations, ensuring security is already in place before users encounter threats during browsing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service security management where the remote browser server automatically monitors, detects, and responds to security threats without requiring user intervention. The server autonomously updates security policies, blocks malicious content, and manages browser configurations, allowing users to browse with enhanced security while maintaining interface simplicity. Security operations are handled automatically by the system rather than requiring user configuration.

Inventive Principle:
Principle #25Self-service

3Productivity

If centralized browser management is implemented, then IT administration efficiency is improved, but device complexity and infrastructure requirements increase

Engineering Contradiction:
ImproveIT administration efficiencyVSAvoidSystem architecture complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent merges multiple browser management functions into a single remote browser server infrastructure. Configuration management, security policy enforcement, update deployment, and threat monitoring are combined in one centralized system that communicates with all local browsers. This consolidation improves IT administration efficiency by providing unified control through a single access point while managing the complexity through integrated architecture rather than distributed systems.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9635041B1Distributed split browser content inspection and analysis
Publication Date: 2017.04.25 AMAZON TECH INC
  • US9635041B1 patent drawing
  • US9635041B1 patent drawing
  • US9635041B1 patent drawing

AI summary

Distributed split browser content inspection and analysis are described. A server, comprising a browser engine, stores a definition of sets of browser policies. A definition of one or more sets of users is stored. The server stores an association with a respective set of browser policies for the one or more sets of users. A request is received from a client browser associated with a user, wherein the client browser is configured to communicate with the server browser engine. The server determines which set of users the user is associated with. The server identifies a first set of browser policies that is associated with the determined set of users and applies the identified first set of browser policies to the request. A determination is made, for one or more browser processes, which browser processes are to be executed by the server browser engine and which browser processes are to be executed by the client browser.