IP Library › Granted Patent US 12,542,812
Granted Patent B2
US 12,542,812 · App. 18/464,092 · Granted Feb 3, 2026

Browser extension access based on re-authorization

Inventor: James S. Robinson (Indianapolis, IN)
Assignee: Netskope, Inc.
H04L63/20H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,542,812
App. No.
18/464,092
Granted
Feb 3, 2026
Kind
B2
Abstract

A policy-based browser system for managing browser extensions used to access functionalities on a web browser in a cloud-based multi-tenant system. The policy-based browser system includes a client device, a web server, and a mid-link server. A set of policies is identified for the installation of a browser extension requested using the client device. The policies specify access to browser extensions at the client device for accessing functionalities associated with the browser extensions. The functionalities are associated with a user application on the client device. The browser extension is analyzed based on usage history for the installation of the browser extension. Non-compliance with one or more policies from the set of policies of the browser extension is flagged for a re-authorization. Based on the re-authorization, either the browser extension is allowed or blocked or partially allowed for the installation and access to the corresponding functionality of the browser extension.

Claims (43)

1 . A policy-based browser system for managing browser extensions used to access functionalities on web browsers in a cloud-based multi-tenant system, the policy-based browser system comprising:

a client device having a local application, the local application is used to access a functionality of a browser extension of a plurality of browser extensions, wherein the browser extension is requested for an installation on the client device;

a web server configured to provide the functionality of the browser extension on a web browser of the client device; and

a mid-link server configured to:

identify a set of policies from a plurality of policies for the installation of the browser extension, wherein:

the plurality of policies specify access to the plurality of browser extensions to be used at the client device for accessing a plurality of functionalities associated with the plurality of browser extensions, and

the plurality of functionalities is associated with a user application on the client device;

analyze the browser extension on usage history for the installation of the browser extension;

check compliance with the set of policies of the browser extension, wherein non-compliance with one or more policies from the set of policies of the browser extension is flagged for a re-authorization; and

based on the re-authorization, either the browser extension is allowed or blocked or partially allowed for the installation and access to the corresponding functionality of the browser extension.

2 . The policy-based browser system for managing browser extensions used to access functionalities on web browsers in a cloud-based multi-tenant system as recited in claim 1 , wherein the re-authorization is performed by an administrator associated with the client device.

3 . The policy-based browser system for managing browser extensions used to access functionalities on web browsers in a cloud-based multi-tenant system as recited in claim 1 , wherein an authorizer of an analyzer of the mid-link server is configured to assign risk scores to each of the plurality of browser extensions based on corresponding categories, compliance with the policies, and the risk score, wherein the re-authorization of the browser extension is based on the corresponding risk score.

4 . The policy-based browser system for managing browser extensions used to access functionalities on web browsers in a cloud-based multi-tenant system as recited in claim 1 , wherein the plurality of policies is based on network traffic, data loss, risks, and/or destination of browser extensions of the client device.

5 . The policy-based browser system for managing browser extensions used to access functionalities on web browsers in a cloud-based multi-tenant system as recited in claim 1 , wherein the browser extension is a plugin.

6 . The policy-based browser system for managing browser extensions used to access functionalities on web browsers in a cloud-based multi-tenant system as recited in claim 1 , wherein the plurality of policies is modified based on the re-authorization.

7 . The policy-based browser system for managing browser extensions used to access functionalities on web browsers in a cloud-based multi-tenant system as recited in claim 1 , wherein the plurality of policies is associated with the installation of the browser extension that is used to establish the functionality or feature using the web browser of the client device.

8 . A method for policy-controlled browser extensions for providing secure access to features and functionalities from a browser in cloud-based multi-tenant systems, the method comprising:

requesting by a local application running on a client device, access to a functionality on a browser extension of a plurality of browser extensions, wherein the browser extension is requested for an installation on the client device;

identifying by a mid-link server, a set of policies from a plurality of policies for the installation of the browser extension, wherein:

the plurality of policies specify access to the plurality of browser extensions to be used at the client device for accessing a plurality of functionalities associated with the plurality of browser extensions, and

the plurality of functionalities is associated with a user application on the client device;

analyzing the browser extension on usage history for the installation of the browser extension;

checking compliance with the set of policies of the browser extension, wherein non-compliance with one or more policies from the set of policies of the browser extension is flagged for a re-authorization; and

based on the re-authorization, either the browser extension is allowed or blocked or partially allowed for the installation and access to the corresponding functionality of the browser extension.

9 . The method for policy-controlled browser extensions for providing secure access to features and functionalities from a browser in cloud-based multi-tenant systems as recited in claim 8 , wherein the re-authorization is performed by an administrator associated with the client device.

10 . The method for policy-controlled browser extensions for providing secure access to features and functionalities from a browser in cloud-based multi-tenant systems as recited in claim 8 , further comprising assigning risk scores to each of the plurality of browser extensions based on corresponding categories, compliance with the policies, and the risk score, wherein the re-authorization of the browser extension is based on the corresponding risk score.

11 . The method for policy-controlled browser extensions for providing secure access to features and functionalities from a browser in cloud-based multi-tenant systems as recited in claim 8 , wherein the plurality of policies is based on network traffic, data loss, risks, and/or destination of browser extensions of the client device.

12 . The method for policy-controlled browser extensions for providing secure access to features and functionalities from a browser in cloud-based multi-tenant systems as recited in claim 8 , wherein the browser extension is a plugin.

13 . The method for policy-controlled browser extensions for providing secure access to features and functionalities from a browser in cloud-based multi-tenant systems as recited in claim 8 , wherein the plurality of policies is modified based on the re-authorization.

14 . The method for policy-controlled browser extensions for providing secure access to features and functionalities from a browser in cloud-based multi-tenant systems as recited in claim 8 , wherein the plurality of policies is associated with the installation of the browser extension that is used to establish the functionality or feature using a web browser of the client device.

15 . A browser controlled system for providing access to browser extensions based on policies in cloud-based multi-tenant systems, the browser controlled system comprising a plurality of servers, collectively having code for:

requesting by a local application running on a client device, access to a functionality on a browser extension of a plurality of browser extensions, wherein the browser extension is requested for an installation on the client device;

identifying by a mid-link server, a set of policies from a plurality of policies for the installation of the browser extension, wherein:

the plurality of policies specify access to the plurality of browser extensions to be used at the client device for accessing a plurality of functionalities associated with the plurality of browser extensions, and

the plurality of functionalities is associated with a user application on the client device;

analyzing the browser extension on usage history for the installation of the browser extension;

checking compliance with the set of policies of the browser extension, wherein non-compliance with one or more policies from the set of policies of the browser extension is flagged for a re-authorization; and

based on the re-authorization, either the browser extension is allowed or blocked or partially allowed for the installation and access to the corresponding functionality of the browser extension.

16 . The browser controlled system for providing access to browser extensions based on policies in cloud-based multi-tenant systems as recited in claim 15 , wherein the re-authorization is performed by an administrator associated with the client device.

17 . The browser controlled system for providing access to browser extensions based on policies in cloud-based multi-tenant systems as recited in claim 15 , further comprising assigning risk scores to each of the plurality of browser extensions based on corresponding categories, compliance with the policies, and the risk score, wherein the re-authorization of the browser extension is based on the corresponding risk score.

18 . The browser controlled system for providing access to browser extensions based on policies in cloud-based multi-tenant systems as recited in claim 15 , wherein the plurality of policies is based on network traffic, data loss, risks, and/or destination of browser extensions of the client device.

19 . The browser controlled system for providing access to browser extensions based on policies in cloud-based multi-tenant systems as recited in claim 15 , wherein the browser extension is a plugin.

20 . The browser controlled system for providing access to browser extensions based on policies in cloud-based multi-tenant systems as recited in claim 15 , wherein the plurality of policies is modified based on the re-authorization.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2023
From: ROBINSON, JAMES S.
To: NETSKOPE, INC.
Reel/Frame 064851/0063 →
Continuity (2)
Continuation 17985719 · Nov 11, 2022
Related Publication 20240163317A1 · May 16, 2024
References Cited (125)
US 5440723A · Arnold et al. · 1995 [cited by applicant]
US 6513122B1 · Magdych et al. · 2003 [cited by applicant]
US 6622248B1 · Hirai · 2003 [cited by applicant]
US 7080408B1 · Pak et al. · 2006 [cited by applicant]
US 7298864B2 · Jones · 2007 [cited by applicant]
US 7376719B1 · Shafer et al. · 2008 [cited by applicant]
US 7590684B2 · Herrmann · 2009 [cited by applicant]
US 7627896B2 · Herrmann · 2009 [cited by applicant]
US 7634800B2 · Ide et al. · 2009 [cited by applicant]
US 7735116B1 · Gauvin · 2010 [cited by applicant]
US 7966654B2 · Crawford · 2011 [cited by applicant]
US 8000329B2 · Fendick et al. · 2011 [cited by applicant]
US 8296178B2 · Hudis et al. · 2012 [cited by applicant]
US 8713630B2 · Raleigh · 2014 [cited by applicant]
US 8745205B2 · Anderson et al. · 2014 [cited by applicant]
US 8793151B2 · DelZoppo et al. · 2014 [cited by applicant]
US 8839417B1 · Jordan · 2014 [cited by applicant]
US 9197601B2 · Pasdar · 2015 [cited by applicant]
US 9225734B1 · Hastings · 2015 [cited by applicant]
US 9231968B2 · Fang et al. · 2016 [cited by applicant]
US 9280678B2 · Redberg · 2016 [cited by applicant]
US 9288199B1 · Winn et al. · 2016 [cited by applicant]
US 9811662B2 · Sharpe et al. · 2017 [cited by applicant]
US 10084825B1 · Xu · 2018 [cited by applicant]
US 10237282B2 · Nelson et al. · 2019 [cited by applicant]
US 10334442B2 · Vaughn et al. · 2019 [cited by applicant]
US 10382468B2 · Dods · 2019 [cited by applicant]
US 10484334B1 · Lee et al. · 2019 [cited by applicant]
US 10721239B2 · Koottayi et al. · 2020 [cited by applicant]
US 10826941B2 · Jain et al. · 2020 [cited by applicant]
US 11032301B2 · Mandrychenko et al. · 2021 [cited by applicant]
US 11036856B2 · Graun et al. · 2021 [cited by applicant]
US 11165585B2 · Wojcik · 2021 [cited by applicant]
US 11281775B2 · Burdett et al. · 2022 [cited by applicant]
US 11468172B2 · Rickerd · 2022 [cited by examiner]
US 11586769B2 · Adams et al. · 2023 [cited by applicant]
US 11740765B2 · Angappan · 2023 [cited by examiner]
US 11792234B1 · Robinson · 2023 [cited by examiner]
US 20020099666A1 · Dryer et al. · 2002 [cited by applicant]
US 20030055994A1 · Herrmann et al. · 2003 [cited by applicant]
US 20030063321A1 · Inoue et al. · 2003 [cited by applicant]
US 20030172292A1 · Judge · 2003 [cited by applicant]
US 20030204632A1 · Willebeek-LeMair et al. · 2003 [cited by applicant]
US 20040015719A1 · Lee et al. · 2004 [cited by applicant]
US 20050010593A1 · Fellenstein et al. · 2005 [cited by applicant]
US 20050271246A1 · Sharma et al. · 2005 [cited by applicant]
US 20060156401A1 · Newstadt et al. · 2006 [cited by applicant]
US 20070204018A1 · Chandra et al. · 2007 [cited by applicant]
US 20070237147A1 · Quinn et al. · 2007 [cited by applicant]
US 20080069480A1 · Aarabi et al. · 2008 [cited by applicant]
US 20080134332A1 · Keohane et al. · 2008 [cited by applicant]
US 20090144818A1 · Kumar et al. · 2009 [cited by applicant]
US 20090249470A1 · Litvin et al. · 2009 [cited by applicant]
US 20090300351A1 · Lei et al. · 2009 [cited by applicant]
US 20100017436A1 · Wolge · 2010 [cited by applicant]
US 20100077444A1 · Forristal · 2010 [cited by applicant]
US 20110119481A1 · Auradkar et al. · 2011 [cited by applicant]
US 20110145594A1 · Jho et al. · 2011 [cited by applicant]
US 20120278896A1 · Fang et al. · 2012 [cited by applicant]
US 20130159694A1 · Chiueh et al. · 2013 [cited by applicant]
US 20130298190A1 · Sikka et al. · 2013 [cited by applicant]
US 20130347085A1 · Hawthorn et al. · 2013 [cited by applicant]
US 20140013112A1 · Cidon et al. · 2014 [cited by applicant]
US 20140068030A1 · Chambers et al. · 2014 [cited by applicant]
US 20140068705A1 · Chambers et al. · 2014 [cited by applicant]
US 20140259093A1 · Narayanaswamy et al. · 2014 [cited by applicant]
US 20140282843A1 · Buruganahalli et al. · 2014 [cited by applicant]
US 20140359282A1 · Shikfa et al. · 2014 [cited by applicant]
US 20140366079A1 · Pasdar · 2014 [cited by applicant]
US 20150100357A1 · Seese et al. · 2015 [cited by applicant]
US 20160088021A1 · Venkata et al. · 2016 [cited by applicant]
US 20160315947A1 · Boss et al. · 2016 [cited by applicant]
US 20160323318A1 · Terrill et al. · 2016 [cited by applicant]
US 20160350145A1 · Botzer et al. · 2016 [cited by applicant]
US 20170064005A1 · Lee · 2017 [cited by applicant]
US 20170093917A1 · Chandra et al. · 2017 [cited by applicant]
US 20170250951A1 · Wang et al. · 2017 [cited by applicant]
US 20200050686A1 · Kamalapuram et al. · 2020 [cited by applicant]
US 20220385669A1 · Robinson · 2022 [cited by examiner]
US 20230132478A1 · Robinson et al. · 2023 [cited by applicant]
EP 1063833A2 · 2000 [cited by applicant]
EP 2973158A1 · 2016 [cited by applicant]
JP 2012033189A · 2012 [cited by applicant]
Martin, Victoria “Cooperative Security Fabric,” The Fortinet Cookbook, Jun. 8, 2016, 6 pgs., archived Jul. 28, 2016 at https://web.archive.org/web/20160728170025/http://cookbook.fortinet.com/cooperative-security-fabric-… [cited by applicant]
Huckaby, Jeff Ending Clear Text Protocols,' Rackaid.com, Dec. 9, 2008, 3 pgs. [cited by applicant]
Nevvton, Harry “fabric,” Newton's Telecom Dictionary, 30th Updated, Expanded, Anniversary Edition, 2016, 3 pgs. [cited by applicant]
Fortinet, “Fortinet Security Fabric Earns 100% Detection Scores Across Several Attack Vectors in NSS Labs' Latest Breach Detection Group Test [press release]”, Aug. 2, 2016, 4 pgs, available at https://www.fortinet.com/… [cited by applicant]
Fortinet, “Fortinet Security Fabric Named 2016 CRN Network Security Product of the Year [press release]”, Dec. 5, 2016, 4 pgs, available at https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2016/fortin… [cited by applicant]
McCullagh, Declan, “How safe is instant messaging? A security and privacy survey,” CNET, Jun. 9, 2008, 14 pgs. [cited by applicant]
Beck et al. “IBM and Cisco: Together for a World Class Data Center,” IBM Redbooks, Jul. 2013, 654 pgs. [cited by applicant]
Martin, Victoria “Installing internal FortiGates and enabling a security fabric,” The Fortinet Cookbook, Jun. 8, 2016, 11 pgs, archived Aug. 28, 2016 at https://web.archive.org/web/20160828235831/http://cookbook.fortine… [cited by applicant]
Zetter, Kim, “Revealed: The Internet's Biggest Security Hole,” Wired, Aug. 26, 2008, 13 pgs. [cited by applicant]
Adya et al., 'Farsite: Federated, available, and reliable storage for an incompletely trusted environment, SIGOPS Oper. Syst. Rev. 36, SI, Dec. 2002, pp. 1-14. [cited by applicant]
Agrawal et al., “Order preserving encryption for numeric data,” In Proceedings of the 2004 ACM SIGMOD international conference on Management of data, Jun. 2004, pp. 563-574. [cited by applicant]
Balakrishnan et al., “A layered naming architecture for the Internet,” ACM SIGCOMM Computer Communication Review, 34(4), 2004, pp. 343-352. [cited by applicant]
Downing et al. , Naming Dictionary of Computer and Internet Terms, (11th Ed.) Barron's, 2013, 6 pgs. [cited by applicant]
Downing et al., Dictionary of Computer and Internet Terms, (10th Ed.) Barron's, 2009, 4 pgs. [cited by applicant]
Zoho Mail, “Email Protocols: What they are & their different types,” 2006, 7 pgs. available at https://www.zoho.com/mail/glossary/email-protocols.html#:˜:text=mode of communication.-,What are the different email protoco… [cited by applicant]
NIIT, Special Edition Using Storage Area Networks, Que, 2002, 6 pgs. [cited by applicant]
Chapple, Mike, “Firewall redundancy: Deployment scenarios and benefits,” Tech Target, 2005, 5 pgs. available at https://www.techtarget.com/searchsecurity/tip/Firewall-redundancy-Deployment-scenarios-and-benefits?%20Offe… [cited by applicant]
Fortinet, FortiGate—3600 User Manual (vol. 1 , Version 2.50 MR2) Sep. 5, 2003, 329 pgs. [cited by applicant]
Fortinet, FortiGate SOHO and SMB Configuration Example, (Version 3.0 MR5), Aug. 24, 2007, 54 pgs. [cited by applicant]
Fortinet, FortiSandbox—Administration Guide, (Version 2.3.2), Nov. 9, 2016, 191 pgs. [cited by applicant]
Fortinet, FortiSandbox Administration Guide, (Version 4.2.4) Jun. 12, 2023, 245 pgs. available at https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/fba32b46-b7c0-11ed-8e6d-fa163e15d75b/FortiSandbox-4… [cited by applicant]
Fortinet,FortiOS—Administration Guide, (Versions 6.4.0), Jun. 3, 2021, 1638 pgs. [cited by applicant]
Heady et al., “The Architecture of a Network Level Intrusion Detection System,” University of New Mexico, Aug. 15, 1990, 21 pgs. [cited by applicant]
Kephart et al., “Fighting Computer Viruses,” Scientific American (vol. 277, No. 5) Nov. 1997, pp. 88-93. [cited by applicant]
Wang, L., Chapter 5: Cooperative Security in D2D Communications, “Physical Layer Security in Wireless Cooperative Networks,” 41 pgs. first online on Sep. 1, 2017 at https://link.springer.com/chapter/%2010.1007/978-3-319… [cited by applicant]
Lee et al., “A Data Mining Framework for Building Intrusion Detection Models,” Columbia University, n.d. 13 pgs. [cited by applicant]
Merriam-Webster Dictionary, 2004, 5 pgs. [cited by applicant]
Microsoft Computer Dictionary, (5th Ed.), Microsoft Press, 2002, 8 pgs. [cited by applicant]
Microsoft Computer Dictionary, (4th Ed.), Microsoft Press, 1999, 5 pgs. [cited by applicant]
Mika et al. “Metadata Statistics for a Large Web Corpus,” LDOW2012, Apr. 16, 2012, 6 pgs. [cited by applicant]
Oxford Dictionary of Computing (6th Ed.), 2008, 5 pgs. [cited by applicant]
Paxson, Vern, “Bro: a System for Detecting Network Intruders in Real-Time,” Proceedings of the 7th USENIX Security Symposium, Jan. 1998, 22 pgs. [cited by applicant]
Fortinet Inc., U.S. Appl. No. 62/503,252, “Building a Cooperative Security Fabric of Hierarchically Interconnected Network Security Devices.” n.d., 87 pgs. [cited by applicant]
Song et al., “Practical techniques for searches on encrypted data,” In Proceeding 2000 IEEE symposium on security and privacy. S&P 2000, May 2000, pp. 44-55. [cited by applicant]
Dean, Tamara, Guide to Telecommunications Technology, Course Technology, 2003, 5 pgs,. [cited by applicant]
U.S. Appl. No. 60/520,577, “Device, System, and Method for Defending a Computer Network,” Nov. 17, 2003, 21 pgs. [cited by applicant]
U.S. Appl. No. 60/552,457, “Fortinet Security Update Technology,” Mar. 2004, 6 pgs. [cited by applicant]
Tittel, Ed, Unified Threat Management For Dummies, John Wiley & Sons, Inc., 2012, 76 pgs. [cited by applicant]
Fortinet, FortiOS Handbook: UTM Guide (Version 2), Oct. 15, 2010, 188 pgs. [cited by applicant]
Full Definition of Security, Wayback Machine Archive of Merriam-Webster on Nov. 17, 2016, 1 pg. [cited by applicant]
Definition of Cooperative, Wayback Machine Archive of Merriam-Webster on Nov. 26, 2016, 1 pg. [cited by applicant]
Pfaffenberger, Bryan, Webster's New World Computer Dictionary, (10th Ed.), 2003, 5 pgs. [cited by applicant]