IP Library Granted Patent US 11,683,305
Granted Patent B1
US 11,683,305 · App. 17/861,107 · Granted Jun 20, 2023

Computer security system with remote browser isolation using forward proxying

Inventor: Paul Michael Martini (Boston, MA)
Assignee: iboss, Inc.
H04L63/083H04L63/0281H04L63/0815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,683,305
App. No.
17/861,107
Granted
Jun 20, 2023
Kind
B1
Abstract

A client device is configured to receive user-input and provide user-output to a client-user. A service provider is configured to serve a network-provided service for authorized users. An identity provider is configured to: maintain authorization information for the network-provided service and generate a permission-object that i) specifies that the client-user is an authorized user of the network-provided service and ii) may include an access-override field that specifies a network address of a remote browser isolation (RBI) host. The system also includes the RBI host configured to access the network-provided service; run the network-provided service in an isolation environment to generate a graphic user interface (GUI); provide a visual reproduction of the GUI to the client device; receive browser-input from the client device; and apply the browser-input to the running network-provided service.

Claims (85)

1. A system for managing access to a network-provided service, the system comprising:

a client device comprising a processor and memory, the client device configured to perform operations comprising:

receive user-input from, and provide user-output to, a client-user;

a service provider comprising a processor and memory, the service provider configured to:

serve a network-provided service for authorized client-users;

an identity provider comprising a processor and memory, the identity provider configured to:

maintain authorization information for the network-provided service; and

generate a permission-object that i) specifies that the client-user is an authorized user of the network-provided service; and ii) comprises an access-override field that

specifies a network address of a remote browser isolation (RBI) host;

the RBI host comprising a processor and memory, the RBI host configured to:

receive the permission-object; and

instantiate an RBI instance configured to:

access the network-provided service;

run the network-provided service in an isolation environment to generate a graphic user interface (GUI);

provide a visual reproduction of the GUI to the client device;

receive browser-input from the client device; and

apply the browser-input to the running network-provided service;

wherein a schema for the permission-object defines:

the access-override field as being free of user-specific characters; and

other fields as containing user-specific characters including at least one cryptographic signature.

2. The system of claim 1 , wherein:

the client device is configured to:

send, to the identity provider, an access-request to access the network-provided service that is served by the service provider;

the identity provider is configured to:

receive, from the client device, the access-request; and

send, to the client device, the permission-object;

the client device is configured to:

receive, from the identity provider, the permission-object; and

send, to the RBI host, the permission-object.

3. The system of claim 2 , wherein:

the client device is configured to:

send, to the identity provider, credentials for the client-user; and

the identity provider is configured to:

verify the identity and permissions of the client-user.

4. The system of claim 2 , wherein the identity provider is configured to, responsive to verifying the identity and permissions of the client-user, send, to the client device, the permission-object.

5. The system of claim 2 , wherein the identity provider is further configured to send, to the client device, a dashboard to be rendered with elements that, when selected by the client-user, cause the client device to send, to the identity provider, the access-request.

6. The system of claim 1 , wherein:

the client device is configured to:

send, to the service provider, an access-request to access the network-provided service that is served by the service provider;

the service provider is configured to:

receive, from the client device, the access-request;

send an authentication request;

the identity provider is configured to:

receive the authentication request;

determine that the client-user is an authorized user of the network-provided service;

send, to the client device, the permission-object;

the client device is configured to:

receive, from the identity provider, the permission-object; and

send, to the RBI host, the permission-object.

7. The system of claim 6 , wherein to determine that the client-user is an authorized user of the network-provided service, the identity provider is configured to:

send, to the client device, a credential request;

receive, from the client device, credentials for the client-user; and

verify authentication of the client-user.

8. The system of claim 6 , wherein to determine that the client-user is an authorized user of the network-provided service, the identity provider is configured to determine that the client-user is already authenticated.

9. The system of claim 1 , wherein the permission-object is a Security Assertion Markup Language (SAML) object.

10. The system of claim 1 , wherein the schema for the permission-object further defines:

the access-override field as containing a network address that is consistent for a plurality of the authorized.

11. The system of claim 1 , wherein the identity provider is one of a plurality of identity providers each configured to generate permission-objects the network-provided service.

12. The system of claim 1 , wherein the RBI host is one of a plurality of RBI hosts each configured to run the network-provided service.

13. The system of claim 1 , wherein:

the identity provider is configured to send, to the client device, the permission object; and

the client device is configured to send the permission-object to the RBI host.

14. The system of claim 1 , wherein the identity provider is configured to send, to the RBI host, the permission object.

15. An identity provider computing device comprising a processor and memory, the identity provider configured to perform operations comprising:

maintain authorization information for a network-provided service; and

generate a permission-object that i) specifies that a client-user is an authorized user of the network-provided service; and ii) comprises an access-override field that specifies a network address of a remote browser isolation (RBI) host

wherein a schema for the permission-object defines:

the access-override field as being free of user-specific characters; and

other fields as containing user-specific characters including at least one cryptographic signature.

16. The identity provider of claim 15 , wherein the identity provider is configured to:

receive, from a client device, an access-request to access the network-provided service that is served by a service provider; and

send, to the client device, the permission-object.

17. The identity provider of claim 16 , wherein the identity provider is configured to, responsive to verifying the identity and permissions of the client-user, send, to the client device, the permission-object.

18. The identity provider of claim 16 , wherein the identity provider is further configured to send, to the client device, a dashboard to be rendered with elements that, when selected by the client-user, cause the client device to send, to the identity provider, the access-request.

19. A remote browser isolation (RBI) host computing device comprising a processor and memory, the RBI host computing device configured to perform operations comprising:

receive a permission-object that i) specifies that a client-user is an authorized user of a network-provided service; and ii) comprises an access-override field that specifies a network address of the RBI host computing device; and

instantiate an RBI instance configured to:

access the network-provided service;

run the network-provided service in an isolation environment to generate a graphic user interface (GUI);

provide a visual reproduction of the GUI to a client device of the client-user;

receive browser-input from the client device; and

apply the browser-input to the running network-provided service;

wherein a schema for the permission-object defines:

the access-override field as being free of user-specific characters; and

other fields as containing user-specific characters including at least one cryptographic signature.

Assignments (4)
SUPPLEMENTAL INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 28, 2023
From: IBOSS, INC.
To: WILMINGTON SAVINGS FUND SOCIETY, FSB
Reel/Frame 066158/0266 →
RELEASE OF SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Dec 12, 2023
From: SILICON VALLEY BANK, A DIVISION OF FIRST-CITIZENS BANK TRUST COMPANY
To: IBOSS, INC.
Reel/Frame 066140/0480 →
SECURITY INTEREST Recorded Sep 19, 2022
From: IBOSS, INC.
To: SILICON VALLEY BANK
Reel/Frame 061463/0331 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 12, 2022
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 060485/0145 →
Cited By (2)
US 12,212,561 US 12,634,284