Method and system of providing security services using a secure device
US-9092635-B2 · Jul 28, 2015 · US
US9699190B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9699190-B2 |
| Application number | US-201414543003-A |
| Country | US |
| Kind code | B2 |
| Filing date | Nov 17, 2014 |
| Priority date | Nov 19, 2013 |
| Publication date | Jul 4, 2017 |
| Grant date | Jul 4, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
The present invention relates to the field of the connection to a secure remote service from a terminal and notably of the establishment of a connection between the secure remote service and a security device connected to the terminal. A security device including a security element is connected to the terminal via a physical or virtual local network. When trying to access a secure remote service, a software module is automatically downloaded onto the terminal, without requiring particular rights, from the secure remote service for the discovery and the interaction with the security device. In this way, it is not necessary to install drivers or other specific software in order to enable the use of the secure element when trying to access a secure remote service.
Opening claim text (preview).
The invention claimed is: 1. A method for establishing a connection between a security network service hosted by a security device connected to a consultation terminal and a remote service during the consultation of said remote service by said consultation terminal, comprising: transmitting, from the remote service, a discovery software module to the consultation terminal, in response to a request sent by said consultation terminal; executing the discovery software module received from the remote service on said consultation terminal, said executed discovery software module performing steps of: discovering one or more security network services available on a local network and hosted by the security device connected to the consultation terminal, validating the one or more security network services by carrying out an attempt to connect to each one of the one or more security network services, and for each one of the security network services for which said attempt carried out is successful, indicating the one of the security network services corresponding to the successful attempt as a validated network service, sending, to the remote service, a list containing only validated discovered security network services discovered and validated by the discovery software module, receiving information designating a validated discovered security network service, selected by said remote service from said sent list of validated discovered security network services, as a selected security network service, establishing a first connection between said consultation terminal and the selected security network service, and establishing a second connection between said consultation terminal and the remote service; and causing the discovery software module to operate as a relay between the first connection and the second connection so that said relay functions as a tunnel between the remote service and the selected security network service. 2. The method according to claim 1 , wherein, in attempting to connect to each one of the one or more discovered security network services, the received discovery software module, executed on said consultation terminal, receives a set of parameters and adds the received parameters to the list of discovered security network services. 3. The method according to claim 1 , further comprising: storing, on the terminal, parameters for establishing the first and second connections. 4. The method according to claim 1 , wherein the first and second connections established by the received discovery software module executed on said consultation terminal are encrypted. 5. The method according to claim 1 , further comprising: encrypting the first and second connections from end to end by the remote service and the selected security network service. 6. The method according to claim 1 , wherein, in transmitting the discovery software module, the discovery software module is inserted into a WEB page in the form of an interpreted program. 7. The method according to claim 6 , wherein the discovery software module is inserted into a hidden framework. 8. The method according to claim 1 , wherein, in transmitting the discovery software module, the discovery software module is in the form of a plugin for a WEB browser. 9. The method according to claim 1 , wherein the one of the one or more security network services is hosted on a mobile telephone. 10. A non-transitory data storage medium having stored thereon information, readable by a computer, comprising coded instructions of a computer program that, upon execution by a processor device having a memory and a communications interface connected thereto, causes the processor device to execute steps comprising: transmitting, from a remote service, a discovery software module to a consultation terminal, in response to a request sent by said consultation terminal; executing, at said consultation terminal, the discovery software module received from the remote service, causing said discovery software module including coded instructions of the computer program to: discover one or more security network services available on a local network and hosted by a security device connected to the consultation terminal, validate the one or more security network services by carry out an attempt to connect to each one of the one or more security network services, and for each one of the security network services for which said attempt carried out is successful, indicating the one of the security network services corresponding to the successful attempt as a validated network service, send, to the remote service, a list containing only validated discovered security network services discovered and validated by the discovery software module, receive information designating a validated discovered security network service, selected by said remote service from said sent list of validated discovered security network services, as a selected security network service, establish a first connection between said consultation terminal and the selected security network service, and establish a second connection between said consultation terminal and the remote service; and cause the discovery software module to operate as a relay between the first connection and the second connection so that said relay functions as a tunnel between the remote service and the selected security network service.
by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity · CPC title
Proxies · CPC title
based on web technology, e.g. hypertext transfer protocol [HTTP] · CPC title
involving the movement of software or configuration parameters (network booting or remote initial program loading [RIPL] G06F9/4416) · CPC title
Access security · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.