Zero-Trust Browser Isolation for Secure Internet Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing internet access systems face security vulnerabilities due to communication paths that allow malicious data to enter or exit networks, and user-level security configurations are difficult to manage with network-based solutions.

Innovation Solution

A zero-trust web browser is implemented, isolated from the operating system and other programs, using virtual containers and sandboxes to protect data, with features like virtual keyboards, content filtering, and centralized management to prevent data leakage and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a web browser is implemented with communication path to internet, then internet access functionality is provided, but security vulnerability increases allowing malicious data to enter or exit the network

Engineering Contradiction:
Improveinternet access functionalityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The browser is segmented into isolated containers (web views) that are separated from the host operating system. Each container runs in its own sandboxed environment with restricted access to system resources, allowing internet communication while preventing direct access to the host system. This segmentation resolves the contradiction by enabling network functionality within isolated segments that cannot be compromised to affect the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary layer (the container/sandbox mechanism) is introduced between the browser and the host operating system. This intermediary controls and mediates all interactions, allowing the browser to access the internet while blocking direct access to sensitive system resources. The intermediary resolves the security vulnerability by acting as a controlled gateway that permits necessary communication while preventing harmful access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If centralized network-based security management is implemented, then network-level security control is provided, but user-level configuration capability is lost and device complexity increases

Engineering Contradiction:
Improvenetwork security controlVSAvoiduser-level configuration capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Security management is given local quality by enabling each device to have its own configurable security policies at the user level, while still participating in centralized management. Different users or devices can have customized security configurations tailored to their specific needs, rather than a uniform network-wide policy. This resolves the contradiction by allowing both centralized oversight and local customization.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The security management system is made dynamic by allowing real-time configuration changes at the user level without requiring complex centralized intervention. Users can dynamically adjust their own security settings within policy boundaries, and these changes are automatically propagated and managed. This dynamic capability resolves the contradiction by providing both centralized control and user autonomy without increasing overall system complexity.

Inventive Principle:
Principle #15Dynamics

3Productivity

If traditional internet access systems are used, then data communication is enabled, but data leakage and unauthorized access risks increase

Engineering Contradiction:
Improvedata communication capabilityVSAvoiddata leakage risk
Core Design Contradiction:
ProductivityVSObject-generated harmful factors

Solution Approach 1:

The browser's data processing capabilities are extracted and isolated into separate containers that are taken out from the host system's direct access. Data communicated through the browser remains within these extracted containers, preventing it from being accessed or leaked to the host system or other applications. This extraction resolves the contradiction by enabling data communication while containing potential leakage risks within isolated boundaries.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Preliminary anti-action is implemented by pre-configuring the containerized browser environment with security restrictions and access controls before data communication occurs. The sandbox is established in advance with defined boundaries that prevent unauthorized access and data exfiltration. This preliminary protective measure resolves the contradiction by enabling communication while pre-establishing defenses against data leakage and unauthorized access.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS20240256651A1Internet access systems and methods involving integrated security features
Publication Date: 2024.08.01 SURF SECURITY INC
  • US20240256651A1 patent drawing
  • US20240256651A1 patent drawing
  • US20240256651A1 patent drawing

AI summary

An internet access system and method providing improved security. In one exemplary implementation, the internet access system may be provided as a web-browser which restricts certain functionality to prevent the access to and display of unallowed content. According to further aspects, the web-browser may prevent certain functionality in relation to displayed content such as copy functions.