Virtualized Browser Resource Synchronization for Zero-Day Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current web browsers lack robust security measures, particularly in dealing with zero-day exploit attacks from native executables like Adobe Flash or Microsoft Word, and their default privacy settings compromise user data, making them vulnerable to both malicious exploitation and management overhead in client virtualization solutions.

Innovation Solution

A virtualized web browser architecture that synchronizes resources across host and virtual machines to provide a secure browsing experience by isolating user actions within separate virtual machines, managing state data, and ensuring seamless user interaction without exposing sensitive information, while minimizing management overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If web browsers use default privacy settings to transfer browsing data to Internet businesses for monetization, then business revenue is improved, but user security and privacy are compromised

Engineering Contradiction:
Improvebusiness revenueVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the web browser into multiple virtual machine instances, each isolated from others. This allows different browsing sessions or data types to be separated into distinct security contexts, preventing a single breach from compromising all data while still enabling targeted data sharing for monetization purposes.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a virtualization layer as an intermediary between the browser and the underlying operating system. This intermediary enables controlled data transfer to Internet businesses through managed interfaces, maintaining security boundaries while facilitating monetization workflows.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If client virtualization is used to isolate browsing activities in separate virtual machines, then security is improved, but management overhead increases

Engineering Contradiction:
Improvesecurity vulnerabilityVSAvoidmanagement overhead
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges multiple virtual machine management functions into a unified virtualization layer that handles isolation, resource allocation, and security policies centrally. This consolidation reduces the complexity of managing individual virtual machines while maintaining security benefits.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The virtualization system implements self-service mechanisms where virtual machine instances automatically manage their own security contexts and resource requirements. The system autonomously handles isolation and security policies without requiring extensive manual configuration or intervention, reducing management overhead.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If web browsers sandbox downloaded code to improve security, then protection against malware is improved, but vulnerability to zero-day exploits through plugins and native executables remains

Engineering Contradiction:
Improvemalware protectionVSAvoidsecurity against zero-day exploits
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent extends sandboxing by segmenting the browser into multiple virtual machine instances, each with its own isolated environment. This goes beyond traditional code sandboxing by providing full system-level isolation, preventing zero-day exploits in plugins or native executables from affecting the host system or other browsing sessions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements nested virtualization where virtual machine instances run within a virtualization layer that itself runs on the host operating system. This nested structure creates multiple layers of isolation, with each layer protecting against threats that might penetrate previous layers, including zero-day exploits.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10095662B1Synchronizing resources of a virtualized browser
Publication Date: 2018.10.09 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US10095662B1 patent drawing
  • US10095662B1 patent drawing
  • US10095662B1 patent drawing

AI summary

Approaches for synchronizing resources of a virtualized web browser. When a virtualized web browser is instructed to display a web page, a host module executing within a host operating instructs retrieves, from each of one or more virtual machines, contents for a portion of the web page. The virtualized web browser assembles the contents and displays the web page. A web browser executing in the host operating system may, but need not, retrieve any of the content displayed thereby. Instead, the content retrieved by the web browser executing in the host operating system may be retrieved by and rendered within a virtual machine. The behavior of the virtualized web browser may be configured using policy data.