Computer security system with remote browser isolation using forward proxying
A client device is configured to receive user-input and provide user-output to a client-user. A service provider is configured to serve a network-provided service for authorized users. An identity provider is configured to: maintain authorization information for the network-provided service and generate a permission-object that i) specifies that the client-user is an authorized user of the network-provided service and ii) may include an access-override field that specifies a network address of a remote browser isolation (RBI) host. The system also includes the RBI host configured to access the network-provided service; run the network-provided service in an isolation environment to generate a graphic user interface (GUI); provide a visual reproduction of the GUI to the client device; receive browser-input from the client device; and apply the browser-input to the running network-provided service.
1 . A computer system comprising:
an identity provider comprising a processor and memory, the identity provider configured to:
verify authentication of a client device for a client-user as an authorized user of a network-provided service;
generate a permission-object that specifies that the client-user is an authorized-users of the network-provided service, the permission-object comprising, at the time of creation, an access-override field that specifies a network address of a remote browser isolation (RBI) host;
transmit, over a computer network, a redirect message to the client-user, the redirect message comprising i) the permission-object and ii) redirect instructions that, when executed by the client device, causes the client device to request that the network-provided service is loaded into a remote security environment using the permission-object.
2 . The computer system of claim 1 , wherein the identity provider is configured to maintain authorization information for the network-provided service.
3 . The computer system of claim 2 , wherein to verify authenticity of the client device, the identity provider is further configured to:
send, to the client device, a credential request;
receive, from the client device, credentials for the client-user; and
verify authentication of the client-user.
4 . The computer system of claim 1 , wherein the permission-object is a Security Assertion Markup Language (SAML) object.
5 . The computer system of claim 1 , wherein a schema for the permission-object further defines:
the access-override field as containing the network address as consistent for a plurality of the authorized user.
6 . An identity provider comprising a processor and memory, the identity provider configured to:
verify authentication of a client device for a client-user as an authorized user of a network-provided service;
generate a permission-object that specifies that the client-user is an authorized-users of the network-provided service, the permission-object comprising, at the time of creation, an access-override field that specifies a network address of a remote browser isolation (RBI) host;
transmit, over a computer network, a redirect message to the client-user, the redirect message comprising i) the permission-object and ii) redirect instructions that, when executed by the client device, cause the client device to request that the network-provided service is loaded into a remote security environment using the permission-object.
7 . The identity provider of claim 6 , wherein the identity provider is configured to maintain authorization information for the network-provided service.
8 . The identity provider of claim 7 , wherein the identity provider is further configured to:
send, to the client device, a credential request;
receive, from the client device, credentials for the client-user; and
verify authentication of the client-user.
9 . The identity provider of claim 6 , wherein the permission-object is a Security Assertion Markup Language (SAML) object.
10 . A computer system comprising:
an identity provider comprising a processor and memory, the identity provider configured to:
verify authentication of a client device for a client-user as an authorized user of a network-provided service;
generate a permission-object that specifies that the client-user is an authorized-users of the network-provided service, the permission-object comprising, at the time of creation, an access-override field that specifies a network address of a remote browser isolation (RBI) host;
communicate, over a computer network, a redirect message to the client-user, the redirect message comprising i) the permission-object and ii) redirect instructions that, when executed by the client device, causes the client device to request that the network-provided service is loaded into a remote security environment using the permission-object;
wherein a schema for the permission-object defines:
the access-override field as being free of user-specific characters; and
other fields as containing user-specific characters including at least one cryptographic signature.
11 . The computer system of claim 10 , wherein the computer system is further configured to:
send, to a client device, a credential request;
receive, from the client device, credentials for the client-user; and
verify authentication of the client-user.
12 . The computer system of claim 10 , wherein the permission-object is a Security Assertion Markup Language (SAML) object.
13 . The computer system of claim 10 , wherein the computer system is further configured to:
send, to a client device, a credential request;
receive, from the client device, credentials for the client-user; and
verify authentication of the client-user.
14 . The computer system of claim 10 , wherein the computer system is configured to:
send, to a client device, the permission-object; and
the client device is configured to send the permission-object to an RBI host.