Method of authenticating a terminal by a gateway of an internal network protected by an access security entity providing secure access

US10356612B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10356612-B2
Application numberUS-201414898100-A
CountryUS
Kind codeB2
Filing dateJun 13, 2014
Priority dateJun 14, 2013
Publication dateJul 16, 2019
Grant dateJul 16, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

One embodiment is an authentication method comprising on receiving a request from the web browser of the terminal, the request including a user identifier, obtaining authentication data that is associated with the user identifier and that is stored in a database of the internal network, configuring a proxy server authorizing access via the access security entity to the internal network for a determined set of connection parameters, generating a first application from the connection parameters of the set, which application is protected using at least one determined portion of the authentication data and being configured to, on being executed by the web browser, set up a connection between the terminal and the proxy server using the parameters, this being done in response to the at least determined portion of the authentication data being supplied and transmitting the first application to the web browser of the terminal.

First claim

Opening claim text (preview).

The invention claimed is: 1. An authentication method enabling a gateway of an internal network that is protected by an access security entity for securing access to authenticate a terminal provided with a web browser, the method comprising: on receiving a request from the web browser of the terminal that includes a user identifier, obtaining authentication data that is associated with said user identifier from a database of the internal network; configuring a proxy server to authorize a determined set of connection parameters to access said internal network via the access security entity; generating a first application from parameters of said determined set of connection parameters, said first application including a determined portion of said authentication data, said first application being protected using said determined portion of said authentication data and being configured to, on being executed by the web browser of the terminal, set up a connection between said terminal and said proxy server by using said parameters, in response to the first application determining that data supplied to the first application by a user via the terminal corresponds to the at least one determined portion of the authentication data included in the first application; and transmitting said first application to the web browser of the terminal. 2. An authentication method according to claim 1 , wherein, during the generation of said first application, said determined portion of the authentication data used for protecting the application is determined in a random manner. 3. An authentication method according to claim 1 , wherein the first application as generated during the generation step includes said determined portion of the authentication data in protected form. 4. An authentication method according to claim 3 , wherein said protected form comprises a digital fingerprint of said determined portion of the authentication data as generated using a hashing function. 5. An authentication method according to claim 1 , wherein said first application is in the JavaScript® language. 6. An authentication method according to claim 1 , wherein the first application is generated in a manner that triggers deletion of said first application in the event of terminal authentication data that does not correspond to said determined portion of the authentication data used for protecting the first application being supplied in succession some predetermined number of times. 7. The method of claim 1 , wherein the terminal is authenticated by the gateway, the method further comprising: receiving, by the first application, a request from terminal to access a service made available by a service platform of an external network distinct from the internal network; upon a determination that said terminal is authorized to access said service, generating a second application configured to, on being executed by the web browser of the terminal, supply a direct connection between said terminal and said service platform for accessing said service; and transmitting said second application to the web browser of the terminal. 8. The method according to claim 7 , wherein said second application includes a security parameter previously exchanged between said service platform and an entity of the internal network for accessing said service, said second application being configured to supply the security parameter to said service platform on setting up the direct connection between the terminal and said service platform. 9. The method according to claim 7 , wherein the second application is in the JavaScript® language. 10. A computer comprising a processor and a non-transitory memory, the non-transitory memory having stored thereon instructions which, when executed by the processor of the computer, cause the processor to perform the authentication method of claim 1 . 11. A non-transitory computer readable data medium having stored thereon instructions, which when executed by a processor, cause the processor to perform the authentication method of claim 1 . 12. A connection set-up method for setting up a connection with an internal network protected by an access security entity for providing secure access, said method being for performing by a web browser of a terminal and comprising: after said web browser has sent a request including a user identifier to a gateway of the internal network, receiving from said gateway a first application that includes a determined portion of authentication data associated with said user identifier in a database of the internal network, the first application protected using said at least one determined portion of said authentication data; and executing said first application, the execution comprising: the first application obtaining authentication data from a user via the terminal; and if said authentication data obtained from the terminal corresponds to said determined portion of said authentication data protecting the first application and included in the first application, the first application setting up a connection between said terminal and a proxy server, said connection using parameters from a set of connection parameters authorized by said proxy server for accessing said internal network via said access security entity. 13. The method of claim 12 , wherein said connection has been set up between said terminal and said proxy server, said method further comprising: sending, by said first application, a request to the proxy server via said connection, the request being for access to said service made available by said service platform; if the terminal is authorized to access said service, receiving, by said web browser, a second application generated by the gateway; and executing said second application, wherein executing said second application supplies the terminal with a direct connection to said service platform to access said service. 14. A gateway of an internal network protected by an access security entity for providing secure access, said gateway configured to: on receiving a request from a web browser of a terminal that includes a user identifier, obtain authentication data that is associated with the user identifier from a database of the internal network; configure a proxy server to allow a determined set of connection parameters to access to said internal network via said access security entity; generate a first application from parameters of said determined set of connection parameters, said application including a determined portion of said authentication data, said first application being protected using said determined portion of said authentication data and being configured to, on being executed by the web browser of the terminal set up a connection between said terminal and said proxy server by using said parameters, in response to said first application determining that data supplied to the first application by a user via the terminal corresponds to the determined portion of the authentication data included in the first application; and transmit the first application to the web browser of the terminal. 15. A gateway according to claim 14 , further configured to: generate a second application upon a determination that said terminal is authorized to access a service made available by a service platform of an external network distinct from the internal network, said second application being configured to, on being executed by the web browser of the terminal, supply a direct connection between the terminal and said service platform in order to access said service; and transmit said second application to t

Assignees

Inventors

Classifications

  • Proxies · CPC title

  • involving the movement of software or configuration parameters  (network booting or remote initial program loading [RIPL] G06F9/4416) · CPC title

  • using one-time-passwords · CPC title

  • using one-time keys (cryptographic mechanisms or cryptographic arrangements for generation of one-time passwords H04L9/0863) · CPC title

  • Firewall traversal, e.g. tunnelling or, creating pinholes · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10356612B2 cover?
One embodiment is an authentication method comprising on receiving a request from the web browser of the terminal, the request including a user identifier, obtaining authentication data that is associated with the user identifier and that is stored in a database of the internal network, configuring a proxy server authorizing access via the access security entity to the internal network for a de…
Who is the assignee on this patent?
Orange
What technology area does this patent fall under?
Primary CPC classification H04L63/0281. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 16 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).