Method and device for the connection to a remote service

US9699190B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9699190-B2
Application numberUS-201414543003-A
CountryUS
Kind codeB2
Filing dateNov 17, 2014
Priority dateNov 19, 2013
Publication dateJul 4, 2017
Grant dateJul 4, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The present invention relates to the field of the connection to a secure remote service from a terminal and notably of the establishment of a connection between the secure remote service and a security device connected to the terminal. A security device including a security element is connected to the terminal via a physical or virtual local network. When trying to access a secure remote service, a software module is automatically downloaded onto the terminal, without requiring particular rights, from the secure remote service for the discovery and the interaction with the security device. In this way, it is not necessary to install drivers or other specific software in order to enable the use of the secure element when trying to access a secure remote service.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for establishing a connection between a security network service hosted by a security device connected to a consultation terminal and a remote service during the consultation of said remote service by said consultation terminal, comprising: transmitting, from the remote service, a discovery software module to the consultation terminal, in response to a request sent by said consultation terminal; executing the discovery software module received from the remote service on said consultation terminal, said executed discovery software module performing steps of: discovering one or more security network services available on a local network and hosted by the security device connected to the consultation terminal, validating the one or more security network services by carrying out an attempt to connect to each one of the one or more security network services, and for each one of the security network services for which said attempt carried out is successful, indicating the one of the security network services corresponding to the successful attempt as a validated network service, sending, to the remote service, a list containing only validated discovered security network services discovered and validated by the discovery software module, receiving information designating a validated discovered security network service, selected by said remote service from said sent list of validated discovered security network services, as a selected security network service, establishing a first connection between said consultation terminal and the selected security network service, and establishing a second connection between said consultation terminal and the remote service; and causing the discovery software module to operate as a relay between the first connection and the second connection so that said relay functions as a tunnel between the remote service and the selected security network service. 2. The method according to claim 1 , wherein, in attempting to connect to each one of the one or more discovered security network services, the received discovery software module, executed on said consultation terminal, receives a set of parameters and adds the received parameters to the list of discovered security network services. 3. The method according to claim 1 , further comprising: storing, on the terminal, parameters for establishing the first and second connections. 4. The method according to claim 1 , wherein the first and second connections established by the received discovery software module executed on said consultation terminal are encrypted. 5. The method according to claim 1 , further comprising: encrypting the first and second connections from end to end by the remote service and the selected security network service. 6. The method according to claim 1 , wherein, in transmitting the discovery software module, the discovery software module is inserted into a WEB page in the form of an interpreted program. 7. The method according to claim 6 , wherein the discovery software module is inserted into a hidden framework. 8. The method according to claim 1 , wherein, in transmitting the discovery software module, the discovery software module is in the form of a plugin for a WEB browser. 9. The method according to claim 1 , wherein the one of the one or more security network services is hosted on a mobile telephone. 10. A non-transitory data storage medium having stored thereon information, readable by a computer, comprising coded instructions of a computer program that, upon execution by a processor device having a memory and a communications interface connected thereto, causes the processor device to execute steps comprising: transmitting, from a remote service, a discovery software module to a consultation terminal, in response to a request sent by said consultation terminal; executing, at said consultation terminal, the discovery software module received from the remote service, causing said discovery software module including coded instructions of the computer program to: discover one or more security network services available on a local network and hosted by a security device connected to the consultation terminal, validate the one or more security network services by carry out an attempt to connect to each one of the one or more security network services, and for each one of the security network services for which said attempt carried out is successful, indicating the one of the security network services corresponding to the successful attempt as a validated network service, send, to the remote service, a list containing only validated discovered security network services discovered and validated by the discovery software module, receive information designating a validated discovered security network service, selected by said remote service from said sent list of validated discovered security network services, as a selected security network service, establish a first connection between said consultation terminal and the selected security network service, and establish a second connection between said consultation terminal and the remote service; and cause the discovery software module to operate as a relay between the first connection and the second connection so that said relay functions as a tunnel between the remote service and the selected security network service.

Assignees

Inventors

Classifications

  • by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity · CPC title

  • Proxies · CPC title

  • based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title

  • involving the movement of software or configuration parameters  (network booting or remote initial program loading [RIPL] G06F9/4416) · CPC title

  • Access security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9699190B2 cover?
The present invention relates to the field of the connection to a secure remote service from a terminal and notably of the establishment of a connection between the secure remote service and a security device connected to the terminal. A security device including a security element is connected to the terminal via a physical or virtual local network. When trying to access a secure remote servic…
Who is the assignee on this patent?
Vallee Florian, Bousquet Nicolas, Oberthur Technologies
What technology area does this patent fall under?
Primary CPC classification H04L63/0853. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Jul 04 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 1 related publication on this page (citations in our corpus or others sharing the same primary CPC).