IP Library Granted Patent US 12,657,059
Granted Patent B1
US 12,657,059 · App. 18/162,139 · Granted Jun 16, 2026

Siloed browser isolation with multiple affinity

Inventors: Christopher J. C. Ford (Reading, GB); Lionel Litty (San Francisco, CA)
Assignee: Menlo Security, Inc.
G06F9/5033G06F9/44505
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,657,059
App. No.
18/162,139
Granted
Jun 16, 2026
Kind
B1
Abstract

Siloed browser isolation with multiple affinity is disclosed. A request from a client browser executing on a client device to connect with a first resource is received. The browser isolation system provides a first surrogate browser to facilitate communications between the client browser and a remote application. The browser isolation system receives a request from the client browser executing on the client device to connect with a second resource. A determination is made that access to the second resource should not be provided by the first surrogate browser. In response, a second surrogate browser is caused to be provided to the client browser.

Claims (42)

1 . A system, comprising:

a processor; and

a non-transitory computer-readable storage medium storing instructions that cause the processor to:

receive, at a browser isolation system, a request from a client browser executing on a client device to connect with a first resource during a client browsing session;

determine, by the browser isolation system based at least in part on a policy applicable to the first resource, that a first type of surrogate browser providing a first set of functionality is applicable under the policy to facilitate access to the first resource;

pair, by the browser isolation system, the client browser with a first surrogate browser of the first type to facilitate communications between the client browser and the first resource;

receive, at the browser isolation system during the client browsing session, a request from the client browser executing on the client device to connect with a second resource during the client browsing session;

responsive to receiving the request to connect with the second resource, determine, by the browser isolation system based at least in part on a policy applicable to the second resource, that the first type of surrogate browser is not applicable under the policy to facilitate access to the second resource,

instruct, by the first surrogate browser, the client device to send a siloed navigation request to navigate to the second resource; and

responsive to the browser isolation system receiving the siloed navigation request, obtain the policy applicable to the second resource and determine that a second type of surrogate browser providing a second set of functionality is applicable to facilitate access to the second resource, wherein the second set of functionality is different from the first set of functionality; and

pair, by the browser isolation system, the client browser with a second surrogate browser of the second type to facilitate communication between the client browser and the second resource.

2 . The system of claim 1 , wherein the first surrogate browser and the second surrogate browser have associated respective first and second cookie jars that persist across multiple browsing sessions of the client browser.

3 . A method, comprising:

receiving, at a browser isolation system, a request from a client browser executing on a client device to connect with a first resource during a client browsing session;

determining, by the browser isolation system based at least in part on a policy applicable to the first resource, that a first type of surrogate browser providing a first set of functionality is applicable under the policy to facilitate access to the first resource;

pairing, by the browser isolation system, the client browser with a first surrogate browser of the first type to facilitate communications between the client browser and the first resource;

receiving, at the browser isolation system during the client browsing session, a request from the client browser executing on the client device to connect with a second resource during the client browsing session;

responsive to receiving the request to connect with the second resource, determining, by the browser isolation system based at least in part on a policy applicable to the second resource, that the first type of surrogate browser is not applicable under the policy to facilitate access to the second resource,

instructing, by the first surrogate browser, the client device to send a siloed navigation request to navigate to the second resource; and

responsive to the browser isolation system receiving the siloed navigation request, obtaining the policy applicable to the second resource and determining that a second type of surrogate browser providing a second set of functionality is applicable to facilitate access to the second resource, wherein the second set of functionality is different from the first set of functionality; and

pairing, by the browser isolation system, the client browser with a second surrogate browser of the second type to facilitate communication between the client browser and the second resource.

4 . The method of claim 3 , wherein the first type of surrogate browser is only authorized to access resources that are accessible via a public network and wherein the second type of surrogate browser is authorized to access resources that are accessible via a private network.

5 . The method of claim 3 , wherein the second type of surrogate browser is associated with a graphics processing unit and wherein the first type of surrogate browser is not.

6 . The method of claim 3 , wherein the first surrogate browser is included in a pool comprising a plurality of similarly configured surrogate browsers sharing the first type.

7 . The method of claim 3 , wherein the first surrogate browser and the second surrogate browser have different configurations.

8 . The method of claim 3 , wherein determining that the first surrogate browser is not applicable under the policy to facilitate access to the second resource includes causing the first surrogate browser to cancel attempting navigation to the second resource.

9 . The method of claim 3 , wherein pairing the client browser with the first surrogate browser includes providing the client browser with a first thin client for pairing with the first surrogate browser, and wherein pairing the client browser with the second surrogate browser includes providing the client browser with a second thin client for pairing with the second surrogate browser.

10 . The method of claim 3 , wherein the siloed navigation request includes a parameter that causes the browser isolation system to obtain the policy applicable to the second resource prior to initiating the navigation.

11 . The method of claim 10 , wherein determining that the first type of surrogate browser is not applicable to the second resource comprises comparing a category of second resource against the policy.

12 . The method of claim 3 , further comprising storing respective first and second encrypted cookie jars associated with the respective first and second surrogate browsers.

13 . The method of claim 12 , wherein cookies stored in the respective first and second cookie jars are encrypted at least in part using respective first and second surrogate browser identifiers.

14 . The method of claim 3 , wherein the first surrogate browser and the second surrogate browser have associated respective first and second cookie jars that persist across multiple browsing sessions of the client browser.

15 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

receiving, at a browser isolation system, a request from a client browser executing on a client device to connect with a first resource during a client browsing session;

determining, by the browser isolation system based at least in part on a policy applicable to the first resource, that a first type of surrogate browser providing a first set of functionality is applicable under the policy to facilitate access to the first resource;

pairing, by the browser isolation system, the client browser with a first surrogate browser of the first type to facilitate communications between the client browser and the first resource;

receiving, at the browser isolation system during the client browsing session, a request from the client browser executing on the client device to connect with a second resource during the client browsing session;

responsive to receiving the request to connect with the second resource, determining, by the browser isolation system based at least in part on a policy applicable to the second resource, that the first type of surrogate browser is not applicable under the policy to facilitate access to the second resource,

instructing, by the first surrogate browser, the client device to send a siloed navigation request to navigate to the second resource; and

responsive to the browser isolation system receiving the siloed navigation request, obtaining the policy applicable to the second resource and determining that a second type of surrogate browser providing a second set of functionality is applicable to facilitate access to the second resource, wherein the second set of functionality is different from the first set of functionality; and

pairing, by the browser isolation system, the client browser with a second surrogate browser of the second type to facilitate communication between the client browser and the second resource.

16 . The computer program product of claim 15 , wherein the first surrogate browser and the second surrogate browser have associated respective first and second cookie jars that persist across multiple browsing sessions of the client browser.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 5, 2023
From: FORD, CHRISTOPHER J.C.; LITTY, LIONEL
To: MENLO SECURITY, INC.
Reel/Frame 063858/0734 →
References Cited (8)
US 9391832B1 · Song · 2016 [cited by examiner]
US 11005819B1 · Song · 2021 [cited by examiner]
US 11290429B1 · Ashley · 2022 [cited by examiner]
US 20150058923A1 · Rajagopal · 2015 [cited by examiner]
US 20190075130A1 · Petry · 2019 [cited by applicant]
US 20200314121A1 · Mittermaier · 2020 [cited by examiner]
US 20220188438A1 · Lewin · 2022 [cited by examiner]
US 20240111821A1 · Dogaru · 2024 [cited by examiner]