IP Library › Granted Patent US 12,647,409
Granted Patent B2
US 12,647,409 · App. 18/614,894 · Granted Jun 2, 2026

Computer security system with remote browser isolation using forward proxying

Inventor: Paul Michael Martini (Boston, MA)
Assignee: iboss, Inc.
H04L63/083H04L63/0281H04L63/0815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,409
App. No.
18/614,894
Granted
Jun 2, 2026
Kind
B2
Abstract

A client device is configured to receive user-input and provide user-output to a client-user. A service provider is configured to serve a network-provided service for authorized users. An identity provider is configured to: maintain authorization information for the network-provided service and generate a permission-object that i) specifies that the client-user is an authorized user of the network-provided service and ii) may include an access-override field that specifies a network address of a remote browser isolation (RBI) host. The system also includes the RBI host configured to access the network-provided service; run the network-provided service in an isolation environment to generate a graphic user interface (GUI); provide a visual reproduction of the GUI to the client device; receive browser-input from the client device; and apply the browser-input to the running network-provided service.

Claims (43)

1 . A computer system comprising:

an identity provider comprising a processor and memory, the identity provider configured to:

verify authentication of a client device for a client-user as an authorized user of a network-provided service;

generate a permission-object that specifies that the client-user is an authorized-users of the network-provided service, the permission-object comprising, at the time of creation, an access-override field that specifies a network address of a remote browser isolation (RBI) host;

transmit, over a computer network, a redirect message to the client-user, the redirect message comprising i) the permission-object and ii) redirect instructions that, when executed by the client device, causes the client device to request that the network-provided service is loaded into a remote security environment using the permission-object.

2 . The computer system of claim 1 , wherein the identity provider is configured to maintain authorization information for the network-provided service.

3 . The computer system of claim 2 , wherein to verify authenticity of the client device, the identity provider is further configured to:

send, to the client device, a credential request;

receive, from the client device, credentials for the client-user; and

verify authentication of the client-user.

4 . The computer system of claim 1 , wherein the permission-object is a Security Assertion Markup Language (SAML) object.

5 . The computer system of claim 1 , wherein a schema for the permission-object further defines:

the access-override field as containing the network address as consistent for a plurality of the authorized user.

6 . An identity provider comprising a processor and memory, the identity provider configured to:

verify authentication of a client device for a client-user as an authorized user of a network-provided service;

generate a permission-object that specifies that the client-user is an authorized-users of the network-provided service, the permission-object comprising, at the time of creation, an access-override field that specifies a network address of a remote browser isolation (RBI) host;

transmit, over a computer network, a redirect message to the client-user, the redirect message comprising i) the permission-object and ii) redirect instructions that, when executed by the client device, cause the client device to request that the network-provided service is loaded into a remote security environment using the permission-object.

7 . The identity provider of claim 6 , wherein the identity provider is configured to maintain authorization information for the network-provided service.

8 . The identity provider of claim 7 , wherein the identity provider is further configured to:

send, to the client device, a credential request;

receive, from the client device, credentials for the client-user; and

verify authentication of the client-user.

9 . The identity provider of claim 6 , wherein the permission-object is a Security Assertion Markup Language (SAML) object.

10 . A computer system comprising:

an identity provider comprising a processor and memory, the identity provider configured to:

verify authentication of a client device for a client-user as an authorized user of a network-provided service;

generate a permission-object that specifies that the client-user is an authorized-users of the network-provided service, the permission-object comprising, at the time of creation, an access-override field that specifies a network address of a remote browser isolation (RBI) host;

communicate, over a computer network, a redirect message to the client-user, the redirect message comprising i) the permission-object and ii) redirect instructions that, when executed by the client device, causes the client device to request that the network-provided service is loaded into a remote security environment using the permission-object;

wherein a schema for the permission-object defines:

the access-override field as being free of user-specific characters; and

other fields as containing user-specific characters including at least one cryptographic signature.

11 . The computer system of claim 10 , wherein the computer system is further configured to:

send, to a client device, a credential request;

receive, from the client device, credentials for the client-user; and

verify authentication of the client-user.

12 . The computer system of claim 10 , wherein the permission-object is a Security Assertion Markup Language (SAML) object.

13 . The computer system of claim 10 , wherein the computer system is further configured to:

send, to a client device, a credential request;

receive, from the client device, credentials for the client-user; and

verify authentication of the client-user.

14 . The computer system of claim 10 , wherein the computer system is configured to:

send, to a client device, the permission-object; and

the client device is configured to send the permission-object to an RBI host.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 14, 2025
From: MARTINI, PAUL MICHAEL
To: IBOSS, INC.
Reel/Frame 070225/0506 →
Continuity (3)
Continuation 18139192 · Apr 25, 2023
Continuation 17861107 · Jul 8, 2022
Related Publication 20240422151A1 · Dec 19, 2024
References Cited (16)
US 12309134B2 · Mehra · 2025 [cited by examiner]
US 20080301460A1 · Miller · 2008 [cited by examiner]
US 20140245389A1 · Oberheide · 2014 [cited by examiner]
US 20150200924A1 · Parla · 2015 [cited by examiner]
US 20160044124A1 · Sarukkai et al. · 2016 [cited by applicant]
US 20200236102A1 · Azulay et al. · 2020 [cited by applicant]
US 20210194871A1 · Batchu et al. · 2021 [cited by applicant]
US 20210336944A1 · Brinckman · 2021 [cited by examiner]
US 20220046018A1 · Mullender et al. · 2022 [cited by applicant]
US 20220141278A1 · Malik et al. · 2022 [cited by applicant]
US 20220188438A1 · Lewin et al. · 2022 [cited by applicant]
US 20220245263A1 · Pasternak · 2022 [cited by examiner]
M. Jung, G. Kienesberger, W. Granzer, M. Unger and W. Kastner, “Privacy enabled web service access control using SAML and XACML for home automation gateways,” 2011 International Conference for Internet Technology and Se… [cited by examiner]
International Preliminary Report on Patentability in International Appln. No. PCT/US2023/027050, mailed on Jan. 23, 2025, 14 pages. [cited by applicant]
International Search Report and Written Opinion in International Appln. No. PCT/US2023/027050, mailed on Aug. 11, 2023, 15 pages. [cited by applicant]
Extended European Search Report in European Application No. 23836103.4, mailed on Jul. 30, 2025, 9 pages. [cited by applicant]