Virtualized Browser Resource Synchronization for Zero-Day Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current web browsers lack robust security measures, particularly in dealing with zero-day exploit attacks from native executables like Adobe Flash or Microsoft Word, and their default privacy settings compromise user data, making them vulnerable to both malicious exploitation and management overhead in client virtualization solutions.
Innovation Solution
A virtualized web browser architecture that synchronizes resources across host and virtual machines to provide a secure browsing experience by isolating user actions within separate virtual machines, managing state data, and ensuring seamless user interaction without exposing sensitive information, while minimizing management overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If web browsers use default privacy settings to transfer browsing data to Internet businesses for monetization, then business revenue is improved, but user security and privacy are compromised
Solution Approach 1:
The patent segments the web browser into multiple virtual machine instances, each isolated from others. This allows different browsing sessions or data types to be separated into distinct security contexts, preventing a single breach from compromising all data while still enabling targeted data sharing for monetization purposes.
Solution Approach 2:
The patent introduces a virtualization layer as an intermediary between the browser and the underlying operating system. This intermediary enables controlled data transfer to Internet businesses through managed interfaces, maintaining security boundaries while facilitating monetization workflows.
2Object-affected harmful factors
If client virtualization is used to isolate browsing activities in separate virtual machines, then security is improved, but management overhead increases
Solution Approach 1:
The patent merges multiple virtual machine management functions into a unified virtualization layer that handles isolation, resource allocation, and security policies centrally. This consolidation reduces the complexity of managing individual virtual machines while maintaining security benefits.
Solution Approach 2:
The virtualization system implements self-service mechanisms where virtual machine instances automatically manage their own security contexts and resource requirements. The system autonomously handles isolation and security policies without requiring extensive manual configuration or intervention, reducing management overhead.
3Object-affected harmful factors
If web browsers sandbox downloaded code to improve security, then protection against malware is improved, but vulnerability to zero-day exploits through plugins and native executables remains
Solution Approach 1:
The patent extends sandboxing by segmenting the browser into multiple virtual machine instances, each with its own isolated environment. This goes beyond traditional code sandboxing by providing full system-level isolation, preventing zero-day exploits in plugins or native executables from affecting the host system or other browsing sessions.
Solution Approach 2:
The patent implements nested virtualization where virtual machine instances run within a virtualization layer that itself runs on the host operating system. This nested structure creates multiple layers of isolation, with each layer protecting against threats that might penetrate previous layers, including zero-day exploits.
Data Source
AI summary
Approaches for synchronizing resources of a virtualized web browser. When a virtualized web browser is instructed to display a web page, a host module executing within a host operating instructs retrieves, from each of one or more virtual machines, contents for a portion of the web page. The virtualized web browser assembles the contents and displays the web page. A web browser executing in the host operating system may, but need not, retrieve any of the content displayed thereby. Instead, the content retrieved by the web browser executing in the host operating system may be retrieved by and rendered within a virtual machine. The behavior of the virtualized web browser may be configured using policy data.


