Automatic Secure Login Method and System for Robotic Process Automation Applications

The method of using application robots to simulate user interactions and store credentials in a secondary zone securely addresses security risks in accessing automated processes across different zones, enhancing security and reducing unauthorized access.

CN115066864BActive Publication Date: 2025-07-15INTERNATIONAL BUSINESS MACHINE CORPORATION
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202180013517.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-03-09
Filing Date
2021-03-01
Publication Date
2025-07-15
Estimated Expiration
2041-03-01

AI Technical Summary

Technical Problem

In the process of secure login between the company network and the service network, the prior art is difficult to effectively prevent access credentials from being snooped and hacked, resulting in an increase in security risks of the service network.

Method used

By establishing a firewall connection between computer systems in different security areas, using an application robot to simulate imaginary users for login, and storing access credentials in the second security area to prevent direct storage in the first security area, and using the secure connection and login robot to automate the login process.

Benefits of technology

Reduces the risk of hackers entering the first secure area to snoop at access credentials through the third secure area, improves the security and automation of the login process, reduces human intervention, and enhances the protection of confidential data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115066864B_ABST
    Figure CN115066864B_ABST
Patent Text Reader

Abstract

The present disclosure includes executing an application process on a first computer system, where the first computer system is arranged within a first security zone. Access credentials for the application process may be stored in a storage device, where the storage device is arranged within a second security zone. The application process may interact with a further application process. The further application process may be executed on a third computer system, where the further application process is controlled by a graphical user interface of the further application process. An application robot may be executed on the first computer system. The application robot may execute the application process. Further, a login from a second computer system to the first computer system may be performed to obtain access to the application process using the access credentials.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0001] The present invention relates to the field of automated processes performed by a user at a workstation.

[0002] Typically, automated processes can be performed by a computer system arranged within a service network. To initiate an automated process, a user generally needs to log in from a corporate network to the service network, where the service network is arranged outside the corporate network. The corporate network can be a target for hackers. Thus, security issues related to the corporate network can also affect security issues related to the service network. The service network can be used for several different clients that serve several automated processes. Thus, if a single client is compromised, there is a risk that the service network may also be compromised and can snoop on data processed by several automated processes. Summary of the Invention

[0003] Various embodiments provide computer-implemented methods, computer program products, and computer systems. Advantageous implementations are also described. If the embodiments of the present invention are not mutually exclusive, they can be freely combined with each other.

[0004] In one aspect, the present invention relates to a computer-implemented method. The method includes: executing an application process on a first computer system, the first computer system being arranged within a first security zone; storing access credentials for the application process in a storage device, the storage device being arranged within a second security zone, and the first security zone and the second security zone being communicatively coupled via a firewall, wherein the first security zone is communicatively coupled to a third security zone, and the application process interacts with a further application process, the further application process being executed on a third computer system, the further application process being controlled by a graphical user interface of the further application process, the third computer system being arranged within the third security zone; executing an application robot on the first computer system, wherein the first computer system is communicatively coupled to the third computer system, the application robot executing the application process, wherein executing the application process includes the step of simulating a first imaginary user using the graphical user interface of the further application process; performing a login from a second computer system into the first computer system for obtaining access to the application process using the access credentials, the second computer system being arranged within the second security zone, wherein by obtaining access to the application process, the application process can be initialized.

[0005] In another aspect, the present invention relates to a computer program product including a computer-readable storage medium having computer-readable program code embodied therewith, the computer-readable program code being configured to implement the features of the method according to the foregoing embodiments.

[0006] In another aspect according to the present invention, a computer program product includes a computer-readable storage medium having program instructions embodied therein, the program instructions being executable by a computer to cause the computer to: execute an application process on a first computer system, the first computer system being disposed within a first security zone; store access credentials of the application process in a storage device, the storage device being disposed within a second security zone, and the first security zone and the second security zone being communicatively coupled via a firewall, wherein the first security zone is communicatively coupled with a third security zone, and the application process interacts with a further application process, the further application process being executed on a third computer system, the further application process being controlled by a graphical user interface of the further application process, the third computer system being disposed within the third security zone; execute an application robot on the first computer system by the computer, wherein the first computer system is communicatively coupled with the third computer system, the application robot executing the application process, wherein executing the application process includes the step of simulating a first imaginary user using the graphical user interface of the further application process; and execute a login from a second computer system to the first computer system by the computer for obtaining access to the application process using the access credentials, the second computer system being disposed within the second security zone, wherein by obtaining access to the application process, the application process can be initialized.

[0007] In another aspect, the present invention relates to a system, the system comprising a computer system, the computer system comprising: a computer processor, a computer-readable storage medium, and program instructions stored on the computer-readable storage medium and executable by the processor to cause the computer system to: execute an application process on a first computer system, the first computer system being disposed within a first security zone; store access credentials for the application process in a storage device, the storage device being disposed within a second security zone, and the first security zone and the second security zone being communicatively coupled via a firewall, wherein the first security zone is communicatively coupled to a third security zone, and the application process interacts with a further application process, the further application process being executed on a third computer system, the further application process being controlled by a graphical user interface of the further application process, the third computer system being disposed within the third security zone; execute an application robot on the first computer system, wherein the first computer system is communicatively coupled to the third computer system, the application robot executing the application process, wherein executing the application process includes the step of simulating a first imaginary user using the graphical user interface of the further application process; and execute a login from a second computer system into the first computer system for obtaining access to the application process using the access credentials, the second computer system being disposed within the second security zone, wherein, by obtaining access to the application process, the application process can be initialized. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] The embodiments of the present invention are explained in more detail below only by way of example with reference to the accompanying drawings, in which:

[0009] Figure 1 A block diagram of a computer system including a first computer system, a second computer system, and a third computer system is depicted;

[0010] Figure 2 shows Figure 1 a detailed block diagram of the first computer system, the second computer system, and the third computer system shown in; and

[0011] Figure 3 shows a flowchart of a method for performing a login from the Figure 2 second computer system shown in into the Figure 2 first computer system shown in. DETAILED DESCRIPTION

[0012] The description of the various embodiments of the present invention is given for illustrative purposes but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The terms used herein are chosen to best explain the principles of the embodiments, practical application, or technical improvement of the technology found in the marketplace, or to enable those of ordinary skill in the art to understand the embodiments disclosed herein.

[0013] This method can prevent access credentials from being stored in the first secure area for performing a login to the first computer system. This can reduce the risk of snooping on the access credentials by compromising the third secure area and entering the first secure area via the third secure area. Thus, this method can prevent a hacker who enters the third secure area from logging in to the first computer system, starting an application process, and obtaining access to the data being processed on the third computer system by accessing the graphical user interface (GUI) of a further application process.

[0014] As used herein, the term "computer system" refers to an entity capable of executing computer-readable program code. For example, a "computer system" can be a virtual computer system or a computer system with hardware components.

[0015] As used herein, the term "further application process" refers to a computer-controlled process that processes data within the third secure area. The data can be industrial data, such as values of product quantities, values of material quantities, etc. For example, a further application process can be any application process of a computer program product.

[0016] As used herein, the term "application process" refers to a computer-controlled process, where executing the application process causes the automatic control of the GUI of a further application process. The application process can be programmed using any type of computer program product used in the field of robotic process automation. The application process can be executed by an executable computer program product on the first computer system. The executable computer program product can be obtained by compiling computer code written by a computer program product used in the field of robotic process automation.

[0017] As used herein, the term "access credentials for an application process" refers to any information necessary to obtain access to the application process, such as a password or a certificate.

[0018] The first secure area can be formed by a first network consisting of the first computer system and several additional first computer systems. Within the first network, a computer system of the first network can be accessed from outside the first network via a first secure connection, such as an SSH (Secure Shell) tunnel, a VPN (Virtual Private Network) connection, or any type of encrypted connection.

[0019] The second security zone may be formed by a second network composed of a second computer system and a number of additional second computer systems. Within the second network, computer systems of the second network can be accessed from outside the second network via a second secure connection (such as a VPN connection or any type of encrypted connection).

[0020] The third security zone may be formed by a third network composed of a third computer system and a number of additional third computer systems. Within the third network, computer systems of the third network can be accessed from outside the third network via a third secure connection (such as a VPN connection or any type of encrypted connection).

[0021] As used herein, the term "firewall" refers to any hardware and / or software of the first and / or second computer systems or the setup of the hardware and / or software of the first and / or second computer systems, enabling the restriction of data traffic between the first security zone and the second security zone, preferably between the first computer system and the second computer system. For example, the firewall can be configured such that access credentials stored in a storage device cannot be accessed from the first security zone. The firewall can be arranged within the first security zone, within the second security zone, or between the first security zone and the second security zone.

[0022] According to one embodiment, the firewall is configured such that logging in to the first computer system can be performed only from the second computer system. This configuration of the firewall can further reduce the risk that the application process may be compromised by any computer system arranged within the first security zone or another security zone other than the second security zone.

[0023] According to one embodiment, the logging in is performed by a login robot that simulates a second imaginary user performing the steps of logging in from the second computer system to the first computer system. This embodiment enables automatic logging in by using the login robot. If the logging in is automatic, more complex access credentials can be used compared to embodiments where the logging in is performed manually, for example, when a first user manually performs the logging in using a desktop located within the second security zone. In addition, simulating the second imaginary user performing the steps of logging in to the first computer system can replace the first user. Moreover, the login robot can be automatically initialized via an exemplary running script.

[0024] As used herein, the term "robot" refers to an entity that includes an exemplary computer system and an exemplary computer program product executed on the exemplary computer system, where execution of the exemplary computer program product causes actions performed by an emulated imaginary user on the interface of an exemplary application process. The exemplary application process may be executed on the exemplary computer system or on another exemplary computer system. The interface may be an exemplary GUI of the exemplary application process or an exemplary command-oriented shell of the exemplary computer system or a further exemplary computer system, where input data input via the exemplary GUI or the exemplary command-oriented shell may be processed by the exemplary application process. With reference to an application robot, the exemplary application process may be a further application process. With reference to a login robot, the exemplary application process may be an application for performing a login, such as a computer program product that supports a remote desktop application.

[0025] According to one embodiment, the application process includes a GUI. Compared with the use via a command-oriented shell, the graphical user interface of the application process may provide easy use of the application process.

[0026] According to one embodiment, the application process includes a graphical user interface, and the login is performed by a login robot that emulates a second imaginary user performing the steps of logging in from a second computer system to a first computer system. The login robot obtains access to the GUI of the application process and uses the GUI of the application process to initialize the application process. In the case where the application process includes a GUI, this embodiment may enable automatic login by using the login robot.

[0027] According to one embodiment, the method further includes establishing a secure connection between the second computer system and the first computer system and using the secure connection to provide access information to the first computer system. The access information provides access to another application process, and in response to receiving the access information, the application robot emulates the steps of a first imaginary user using the GUI of the another application process to perform a login into the another application process by using the access information. According to this embodiment, within a first security zone, access information may only be received from a second security zone via the secure connection. This embodiment may use the second security zone as the source of the access information. This may prevent the access information from needing to be stored within the first security zone. This may reduce the risk that another application process may be compromised by any computer system within the first security zone. This may reduce the risk that confidential data being processed by another application may be snooped. The secure connection may include such things as an SSH tunnel, a VPN connection, or any type of encrypted connection.

[0028] According to one embodiment, the first computer system is implemented as a dedicated application server. The dedicated server can be configured to execute only an application process and another application process. This can give the possibility to optimize the software and hardware components of the first computer system with respect to the application process and the further application process.

[0029] According to one embodiment, the third computer system is implemented as a non-dedicated application server. According to this embodiment, the third computer system is configured to execute not only a further application process but also at least another application process. This can provide a flexible implementation of the method.

[0030] According to one embodiment, the second security zone and the third security zone are communicatively coupled only indirectly via the first security zone. If the third security zone is compromised, this can reduce the risk of the second security zone being compromised.

[0031] According to one embodiment, an interactive login into the first computer system from the first security zone is prohibited. As used herein, the term "executing from the first security zone" means an interactive login from a device arranged within the first security zone. By disabling the interactive login from the devices arranged within the first security zone, the risk that the first computer system may be compromised can be further reduced. The interactive login can include an interactive login via the command-oriented shell of the first computer system or the GUI of the first computer system or the GUI of an application process.

[0032] According to one embodiment, the execution of the login and the execution of the application robot are scheduled in a queue via a running script, the running script being executed within the first security zone, wherein executing the running script provides the execution of the login, followed by the execution of the application robot. This can enable the login to be started from outside the second security zone (e.g., from the first security zone). In addition, scheduling the execution of the login and sequentially executing the application robot via the running script can prevent the execution of the application process from starting before the login has occurred. This prevents the application robot from being initialized without performing the login. As used herein, the term "running script" means any software that enables the execution of the login and the execution of the application robot in a scheduled manner. The running script can be configured as a shell script, computer-readable program code, or a stored ordered list.

[0033] According to one embodiment, the method further includes executing a second application robot on a fourth computer system, the fourth computer system being arranged within a first security zone and communicatively coupled to a fifth computer system, the second application robot executing a second application process, wherein executing the second application process includes using the GUI of a second additional application process and using the GUI of the second additional application process to simulate another first imaginary user, the second additional application process operating on the fifth computer system and the second additional application process being controlled by the GUI of the second additional application process, the fifth computer system being disposed within a third security zone. This embodiment of the method further includes executing a login to the fourth computer system to obtain access to the second application process, wherein by obtaining access to the second application process, the second application process can be initialized, wherein the second login robot uses second access credentials to execute a login into the fourth computer system from the second security zone, the second login robot simulating the step of executing a login into the fourth computer system as another second imaginary user, wherein executing a login to the first computer system and executing a login to the fourth computer system are scheduled via a running script, and the second access credentials are stored within the second security zone.

[0034] This embodiment can provide a flexible implementation of the method. For example, not only the execution of the application robot but also the execution of the second application robot can be automatically initiated via a running script. Thus, the further application process and the second further application process can be automatically or concurrently executed in a queue via the running script. This can enhance the automation capabilities of several processes and can reduce the amount of human effort.

[0035] According to one embodiment, the method further includes starting a login robot via a jump server, the jump server being arranged within a first security zone and communicatively coupled via another secure connection between the first security zone and the third security zone, and being accessible from the third security zone via another secure connection for starting the login robot. The another secure connection can include an SSH tunnel or a VPN connection. Using the another secure connection can provide a secure way to log in to the jump server from the third security zone. Starting the login robot via the jump server can enable a user to start a further application from the third security zone via a further secure connection without accessing the first computer system. This is an advantageous embodiment because the risk of compromising the first computer system via the third security zone may still be low, while it may be possible for the user to start a further application process from the third security zone.

[0036] According to one embodiment, the method further includes controlling the running script via a jump server, the jump server being arranged within a first security zone and communicatively coupled by a further secure connection between the first security zone and a third security zone, and being accessible from the third security zone via the further secure connection for controlling the running script via the jump server. This enables the running script to be started from the third security zone without accessing the first computer system. This can be a further advantageous embodiment because the risk of compromising the first computer system via the third security zone may still be low while it is possible to start the running script from the third security zone.

[0037] According to one embodiment, the method further includes storing access information encrypted and protected within a second security zone. This can prevent the risk that the access information may be snooped.

[0038] According to one embodiment, the method further includes performing a login into a login robot using login robot access credentials, wherein the login robot is accessible only by using the login robot access credentials, and the login robot access credentials are stored within the second security zone. This embodiment can improve the security of the use of the login robot. Thus, this embodiment can enhance the security of the use of an application robot because, according to this embodiment, the application robot can be executed only by using access credentials and login robot access credentials.

[0039] Figure 1 is a block diagram of a computer system 10. The computer system 10 is adapted to implement the method steps involved in the present disclosure. The computer system includes at least a first computer system 100, a second computer system 120, and a third computer system 140.

[0040] Figure 2 More specifically, the first computer system 100, the second computer system 120, and the third computer system 140 are shown. The first computer system 100 may include a first processor 1, a first memory 103, a first I / O (input / output) circuit 104, and a first network interface 105 coupled together by a first bus 106.

[0041] The first processor 102 may represent one or more processors (e.g., microprocessors). The first memory 103 may include any one or a combination of volatile memory elements (e.g., random access memory (RAM), such as DRAM, SRAM, SDRAM, etc.) and non-volatile memory elements (e.g., ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM)). Note that the first memory 103 may have a distributed architecture, where different components are located far from each other, but can be accessed by the first processor 102.

[0042] The first memory 103 in combination with the first persistent storage device 107 may be used for local data and instruction storage. The first storage device 107 includes one or more persistent storage devices and media controlled by the first I / O circuit 104. The first storage device 107 may include magnetic, optical, magneto-optical, or solid-state devices for digital data storage, such as those having fixed or removable media. Example devices include hard disk drives, optical disk drives, and floppy disk drives. Example media include hard disks, CD-ROMs, DVD-ROMs, BD-ROMs, floppy disks, etc.

[0043] The first memory 103 may include one or more individual programs, each program including an ordered list of executable instructions for implementing a logical function (especially the functions involved in the example). The software in the first memory 103 may generally also include a first suitable operating system (OS) 108. The first OS 108 substantially controls the execution of other computer programs for implementing at least a part of the method as described herein.

[0044] The second computer system 120 may include a second processor 122, a second memory 123, a second I / O circuit 124, and a second network interface 125 coupled together by a second bus 126.

[0045] The second processor 122 may represent one or more processors (e.g., microprocessors). The second memory 123 may include any one or a combination of volatile memory elements (e.g., random access memory (RAM), such as DRAM, SRAM, SDRAM, etc.) and non-volatile memory elements (e.g., ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM)). Note that the second memory 123 may have a distributed architecture, where different components are located far from each other, but can be accessed by the second processor 122.

[0046] The second memory 123, in combination with the second persistent storage device 127, can be used for local data and instruction storage. The second storage device 127 includes one or more permanent storage devices and media controlled by the second I / O circuit 124. The second storage device 127 can include magnetic, optical, magneto-optical, or solid-state devices for digital data storage, for example, with fixed or removable media. Example devices include hard disk drives, optical disk drives, and floppy disk drives. Example media include hard disks, CD-ROMs, DVD-ROMs, BD-ROMs, floppy disks, etc.

[0047] The second memory 123 can include one or more separate programs, each program including an ordered list of executable instructions for implementing a logical function, particularly the functions involved in the example. The software in the second memory 123 typically can also include a second suitable operating system (OS) 128. The second OS 128 substantially controls the execution of other computer programs for implementing at least a portion of the methods described herein.

[0048] The third computer system 140 can include a third processor 142, a third memory 143, a third I / O circuit 144, and a third network interface 145 coupled together via a third bus 146.

[0049] The third processor 142 can represent one or more processors (e.g., microprocessors). The third memory 143 can include any one or a combination of volatile memory elements (e.g., random access memory (RAM), such as DRAM, SRAM, SDRAM, etc.) and non-volatile memory elements (e.g., ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM)). Note that the third memory 143 can have a distributed architecture where different components are located remotely from each other but are accessible by the third processor 142.

[0050] The combination of the third memory 143 and the third persistent storage device 147 can be used for local data and instruction storage. The third storage device 147 includes one or more persistent storage devices and media controlled by the third I / O circuit 144. The third storage device 147 can include magnetic, optical, magneto-optical, or solid-state devices for digital data storage, for example, with fixed or removable media. Example devices include hard disk drives, optical disk drives, and floppy disk drives. Example media include hard disks, CD-ROMs, DVD-ROMs, BD-ROMs, floppy disks, etc.

[0051] The third memory 143 may include one or more separate programs, each program including an ordered list of executable instructions for implementing logical functions (in particular, the functions involved in the example). The third software in the memory 143 generally may also include a third suitable operating system (OS) 148. The third OS 148 substantially controls the execution of other computer programs for implementing at least a part of the methods described herein.

[0052] The first computer system 100, the second computer system 120, and the third computer system 140 may be independent computer hardware platforms. Each computer system 100, 120, and 140 may be responsible for managing its own copy of data.

[0053] The first computer system 100 may communicate with the third computer system 140 via a first connection 151 and communicate with the second computer system 140 via a second connection 152 through the respective network interfaces 105, 125, 145. The first connection 151 may provide the above-mentioned third secure connection. The second connection 152 may include a local area network (LAN) or a general wide area network (WAN). The second connection 152 may provide the above-mentioned first secure connection and second secure connection. The first connection 151 may include a general wide area network (WAN) and / or a public network, such as the Internet. As Figure 2 shown, there may be no hardware connection between the second computer system 120 and the third computer system 140. However, the second computer system 120 may be communicatively coupled to the third computer system 140 indirectly only via the first secure area. Therefore, the second secure area 2 and the third secure area 3 are communicatively coupled indirectly only via the first secure area 1.

[0054] The first computer system 100 may be arranged within the first secure area 1. The second computer system 120 may be disposed within the second secure area 2. The third computer system 140 may be arranged within the third secure area 3. The first secure area 1, the second secure area 2, and the third secure area may each include additional devices, such as, Figure 1 storage devices or additional computer systems not shown in. The first secure area 1 may be communicatively coupled to the third secure area 3 via the first connection 151, for example.

[0055] The first computer system 100 and the additional devices in the first secure area 1 may form a first computer network 11. The second computer system 120 and the additional devices in the second secure area 2, and the third computer system 140 and the additional devices in the third secure area 3 may form a second computer network 12 and a third computer network 13, respectively. As Figure 1As shown, the second network 12 may include a storage device 4, which may be arranged within the second security zone 2. The first security zone 1 and the second security zone 2 may be communicatively coupled via a second connection 152, which preferably includes a firewall 5. Figure 1 It is shown that the firewall 5 is arranged between the first security zone 1 and the second security zone 2.

[0056] The third network 13 may be regarded as the company network as described above, and the first network 11 may be regarded as a service network, which may serve to execute the processing of the third network 13. The second network 12 may be considered a secure network that provides access to data for processes executed within the first network 11.

[0057] The computer system 10 may be configured to perform functions such as executing an application process on the first computer system 100, hereinafter referred to as the first function, storing access credentials for the application process in the storage device 4 (hereinafter referred to as the second function), executing a further application process (hereinafter referred to as the third function), executing an application robot on the first computer system 100, hereinafter referred to as the fourth function, simulating the steps of a first imaginary user using the GU1 of the further application process, hereinafter referred to as the fifth function, and performing a login from the second computer system 120 to the first computer system 100 to obtain access to the application process, hereinafter referred to as the sixth function.

[0058] In addition, the computer system 10 may be configured to perform functions such as executing a login automation process on the second computer system 120, hereinafter referred to as function 201, storing login robot access credentials for the login automation process in the storage device 4 (hereinafter referred to as function 202), executing a remote login application (hereinafter referred to as function 203), executing a login robot on the second computer system 120, hereinafter referred to as function 204, simulating the steps of a second imaginary user performing a login from the second computer system 120 to the first computer system 100, hereinafter referred to as function 205, and performing a login to the second computer system 120 to obtain access to the login automation process, hereinafter referred to as function 206.

[0059] The computer system 10 may execute the first, second, third, fourth, fifth, and sixth functions by respectively executing a first program 21, a second program 22, a third program 23, a fourth program

[0060] 24, a fifth program 25, and a sixth program 26.

[0061] Similarly, computer system 10 may execute functions 201, 202, 203, 204, 205, and 206 by executing program 221, program 222, program 223, program 224, program 225, and program 226, respectively.

[0062] As used herein, the term "program" refers to a set of instructions that includes commands that cause actions to be performed by at least one of processors 102, 122, 142 when the commands can be read by at least one of processors 102, 122, 142. The set of instructions may be in the form of a computer-readable program, routine, subroutine, or part of a library that can be executed by at least one of processors 102, 122, 142 and / or can be called by another program being executed by at least one of processors 102, 122, 142. Preferably, programs 21, 22, 23, 24, 25, 26, 221, 222, 223, 224, 225, 226 may be executable programs compiled according to the type of the hardware platforms of computer systems 100, 120, 140, respectively.

[0063] The first memory 103 may include a space for storing the first program 21; this space is hereinafter referred to as the first function memory 115. The first program 21, hereinafter referred to as a robotic processing automation program, may be generated by using at least one subroutine, library, and / or module of one of the aforementioned computer program products known in the field of robotic processing automation. The OS 108 may include executable program code for executing one of the robotic process automation programs of the first program 21.

[0064] In addition, the first function memory 115 may include a fourth program 24. The first processor 102 may execute the fourth program 24. Executing the fourth program 24 may include setting up a virtual workstation on the first memory 103, starting and executing an application robot on the virtual workstation, wherein executing the application robot may include performing an application process by the application robot. To perform the application process, the application robot may execute the first program 21. To achieve this, the virtual workstation may execute the first program 21 through the first processor 102. The application robot may be considered an application entity that includes the virtual workstation and the first program 21 executed on the virtual workstation. The virtual workstation may be a copy of the workstation of a user of the third network 13. According to one example, the fourth program 24 may be in the form of a shell script or any other set of instructions for setting up the virtual workstation, starting, and executing the application robot.

[0065] Executing the application process may include executing a fifth function that uses the GU1 of another application process to simulate the steps of a first imaginary user. This can be achieved by calling the fifth program 25 when the application robot executes the first program 21. The fifth program 25 may be stored in the first function memory 115.

[0066] The virtual workstation may include Figure 2 all the hardware elements of the first computer system 100 in the form of the virtual hardware elements shown, such as virtual processors, virtual memories including virtual function memories, virtual I / O circuits, virtual buses, virtual storage devices, and virtual network interfaces, where the virtual function memory contains the first program 21, the fourth program 24, the fifth program 25, and preferably the third program 23.

[0067] Establishing a virtual workstation may be just one possible embodiment. In another example, the first program 21, the fourth program 24, the fifth program 25, and preferably the third program 23 may be executed on the first processor 102 as described above and below, without setting up a virtual workstation on the first processor 102.

[0068] According to the first example, additional application processes may be executed on the first processor 102, preferably on the virtual workstation. In this first example, the first function memory 115 may also include the third program 23. The third program 23 may be an application program for processing industrial data (such as SAP as described above). By executing the third program 23 on the first processor 102, further applications may be executed, and data stored in the third security area may be processed on the first processor 102, preferably on the virtual workstation. The data may be industrial data as described above. The second network 12 may be regarded as a service network serving users of the third network 13. Therefore, the data will be referred to as client data hereinafter. To process the client data on the first computer system 100, the application robot may execute the first program 21, which includes the step of using the GU1 of a further application process to simulate the first imaginary user.

[0069] Executing the first program 21 and preferably the fifth program 25 may include performing a login from the first computer system 100 to the third computer system 140 via the first connection 151 for retrieving client data from the third security zone 3. The third computer system 140 may execute the third program 23 which is for performing further application processes and for enabling a first data flow of industrial data between the third security zone 3 and the first security zone 1. The third memory 143 may include a third functional memory 155 storing the third program 23 for performing another application process on the third processor 142. Running further application processes on the first processor 102 and on the third processor 142 may be advantageous for implementing the first data flow since the same data structure may be used by the third program 23 executed on the third processor 142 and on the first processor 102. The third computer system 140 may be configured to serve as Figure 1 a server for client computer systems of the third network 13 not shown herein.

[0070] According to a second example, a front-end application of a further application process may be executed on the first processor 102, preferably by executing the third program 23 or a subroutine of the third program 23 on the first processor 102. The third program 23 or its subroutine may include instructions for performing functions of a GUI for the further application process.

[0071] In the first example as well as the second example, the third program 23 and preferably its subroutine may be run on the first processor 102 for performing the GU1 of the further application process on the first processor 102.

[0072] As used herein, the term "performing the GU1 of the further application process on the first processor 102" may include running the third program 23 and / or its subroutine for setting up the GU1 of the further application process on the first processor 102. Setting up the GUI of the further application process may include activating at least one input function of the GUI for reading user input data. The input function is capable of reading in user input data independent of the source of the user input data.

[0073] The fifth program 25 can run on the first processor 102 in parallel with the third program 23 and / or its subroutines. The fifth program 25 can create output signals that simulate mouse output data and / or keyboard output data, and send the output signals to the input function. Sending the output signals to the input function can be an example of an application process that interacts with another application process. The input function can read in the output signals and process the output signals similarly to the aforementioned user input data. When a user of the third network 13 uses a further application process on one of the devices of the third network 13 or the second network 12, the mouse output data and / or keyboard output data can be recorded. By running the fifth program 25 and the third program 23 and / or its subprograms in parallel and sending the output signals to the input function, the steps of a first imaginary user (e.g., a user of the third network 13) using another application process with the GU1 can be simulated.

[0074] The steps of the first imaginary user can include entering entry data in a field of the GUI of the further application process, checking a box of the GUI of the further application process or any other use of the GUI of the further application process. The recording of the mouse output data and / or keyboard output data can be performed using one of the robotic process automation programs before running the fifth program 25. The entry data can include access information that provides access to a further application being executed on the third processor 142 by running the third program 23 on the third processor 142.

[0075] By executing the fifth program 25 and the third program 23 and / or its subroutines on the first processor 102, input data for a further application process that can be executed on the third processor 142 can be generated for processing on the third processor 142. The fifth program 25 can be initiated by executing the first program 21 on the first processor 102. The input data can be transmitted to the third computer system 140 by establishing a second data flow between the third security area 3 and the first security area 1. To establish the second data service, the application robot can log in to the third computer system 140 via the first connection 151 for delivering the input data to the third security area 3. The input data can be processed by the third program 23 on the third computer system 140 within the third security area 3. Generating the input data as described above and processing the input data on the third computer system 140 by the third program 23 can be an example where a further application process operates on the third computer system 140, and the further application process is controlled by the GUI of the further application process.

[0076] The application robot can log in to the third computer system 140 using access information, which can be included in the entry data. The access information can be stored on the storage device 4 or arranged on the second storage device 6 within the second security area 2. The access certificate and / or access information can be stored encrypted on the storage device 4 or the second storage device 5 within the second security area. Storing the access credential on the storage device 4 and the access information on the second storage device can increase security.

[0077] Input data, output signals, or input data can theoretically become visible by logging in to the first computer system 100 from another computer including a screen and initiating a shadow session. However, the firewall 5 can be configured such that logging in to the first computer system 100 can only be performed from the second computer system 120. This can include disabling interactive logins from the first security area 1 into the first computer system 100. This can prevent the possibility of logging in to the first computer system 100 from any device on the first network 11.

[0078] The second memory 123 can include space for storing the sixth program 26. The sixth program 26 can be a remote desktop application. The sixth program 26 can trigger the application of a first communication protocol for sending control data from the second network interface 125 to the first network interface 105 via the second connection 152. The first communication protocol can be the Remote Desktop Protocol. The control data can be sent from the first network interface 105 to the first processor 102 via the first bus 106 and can be processed by the first processor 102. By processing the control data, the first processor 102 can be controlled by the control data. The control data can be generated by the second processor 122 and sent to the second network interface 125 via the second bus 126. The control data can include access credentials and / or communication data for establishing communication between the first computer system 100 and the second computer system 120.

[0079] In a first example, control data can be generated by processing a keyboard input signal via the second I / O circuit 124. The keyboard input signal can be generated by a user of the second network 12 typing in the access credential. In a second example, control data can be automatically generated by executing a login robot. In this second example, the login robot simulates the steps of a second imaginary user, i.e., a user of the second network 12 performing a login from the second computer system 120 into the first computer system 100. The steps of the second imaginary user can include typing in the access credential using a keyboard. In this example, a keyboard is not required.

[0080] When the sixth program 26 is executed, the access credential can be verified by comparing it with first verification data. The first verification data can include a copy of the access credential, preferably an encrypted copy.

[0081] In a first example, the first authentication data may be stored, preferably encrypted, within the first secure area 1, for example on the first storage device 107. In this first example, the access credentials may be compared by the first processor 102 with the first authentication data.

[0082] In a second example, the first verification data may be stored in the second security area 2, for example, in the second storage device 127 or in Figure 1 The first authentication data is stored on a further storage device of the second network 12 (not shown) and can be compared with the access credentials by the second processor 122. This has the advantage that neither the access credentials nor the first authentication data need to be stored outside the second security area 12, thereby reducing the risk of performing a login into the first computer system 100 from outside the second security area 2.

[0083] The control data processed by the first processor 102 may trigger the generation of feedback data by the first processor 102. The feedback data may include confirmation data and / or first verification data. In the latter case, the first computer system 100 may send the first verification data to the second computer system 120, and the second processor 102 may compare the access credential with the first verification data. This is advantageous because the access credential may not need to be sent to the first security area 1 and may remain in the second security area 2. Preferably, the first verification data may be encrypted with a public key of the second security area 2. The second processor 102 may decrypt the first verification data by using a private key of the second security area 2. The private key of the second security area 2 may be stored in the storage device 4 and may be sent to the second computer system 120 upon request.

[0084] The confirmation data may include information that triggers initialization of communication between the first computer system 100 and the second computer system 120. The first processor 102 may generate feedback data using the sixth program 26. The feedback data may be sent from the first processor 102 to the first network interface 105 via the first bus 106, and may be sent from the first network interface 105 to the second network interface 125 using the first communication protocol. The feedback data may be sent from the second network interface 124 to the second processor 122 via the second bus 126.

[0085] The exchange of control data and feedback data between the second computer system 120 and the first computer system 100 using the access credentials described above can enable a login from the second computer system 120 to the first computer system 100. The login from the second computer system 120 to the first computer system 100 can be successfully achieved by a successful comparison of the access credentials with the first authentication data. Such a comparison can be performed by the first processor 102 or the second processor 122. In the latter case, the method can reduce the risk of performing an external login from the second security zone 2 to the first computer system 100. In response to a successfully achieved login from the second computer system 120 to the first computer system 100, an application process can be initiated by sending a start command from the second computer system 120 to the first computer system 100.

[0086] The firewall 5 can be configured such that if the data is sent from the second computer system 120, the first computer system 100 can only process data transmitted via the first communication protocol. In this instance, the firewall 5 can be associated with settings that restrict the first OS 128 of the first computer system 100 such that if the data is sent from the second computer system 120, it can only process data transmitted via the first communication protocol. Thus, the firewall 5 can be arranged within the first computer system 100. Figure 1 A firewall 5 arranged between the first security zone 1 and the second security zone 2 is shown. Since Figure 1 it is a block diagram, Figure 1 the position of the firewall 5 in it only represents a functional position rather than a physical position.

[0087] In the following example, how the login from the second computer system 120 to the first computer system 100 is performed by a login robot is described. In this example, the login robot can automatically generate control data.

[0088] The second memory 103 can include a space for storing the program 201; this space is hereinafter referred to as the second functional memory 135. The program 201 can be generated by using at least subroutines, libraries, and / or modules of one of the above-described robotic process automation programs. The OS 128 can include a second executable program code for executing one of the robotic process automation programs of the program 201.

[0089] In addition, the second functional memory 135 may include a program 204. The second processor 122 may execute the program 204. Executing the program 204 may include starting and executing a login robot on the second processor 122, wherein executing the login robot may include performing a login automation process by the login robot. To perform the login automation process, the login robot may execute a program 201. To achieve this, the second processor 122 may execute the program 201. The login robot may be considered an application entity including the second computer system 120 and the program 201 executed on the second computer system 120. According to one example, the program 204 may be in the form of a shell script or any other instruction set for starting and executing the login robot.

[0090] Performing the login automation process may include performing a function 205 that may simulate the steps of a second imaginary user using an interface (preferably, a GUI) of a remote login application. This may be achieved by calling the function 205 when the program 201 is executed by the login robot. The programs 205, 201, 204 may be stored in the second functional memory 135.

[0091] When the login robot can be executed by the second processor 122, a program 203 may be executed on the second processor 122. The program 203 may include instructions for performing the functions of the GUI of the remote login application on the second processor 122.

[0092] The term "performing the GUI of the remote login application on the second processor 122" as used herein may include running the program 203 and / or its subroutines for setting up the GUI of the remote login application on the second processor 122. Setting up the GUI of the remote login application may include activating at least one second input function of the GUI for reading second user input data. The second input function may be capable of reading in the second user input data independent of the source of the second user input data.

[0093] Program 205 can run on the second processor 122 in parallel with program 203 and / or its subroutines. Program 205 can create a second output signal that simulates second mouse output data and / or second keyboard output data, and send the second output signal to the second input function. The second input function can read in the second output signal and process the second output signal similar to the above-mentioned second user input data. When a second user of the second network 12 uses a remote login application on one of the devices of the second network 12, the second mouse output data and / or the second keyboard output data can be recorded. By running program 205 and program 203 in parallel and sending the second output signal to the second input function, the steps of a second fictional user (e.g., a user of the second network 12) using the GUI of the remote login application can be simulated. In addition, sending the second output signal to the second input function can be an example of how a login automation process can interact with a remote login application.

[0094] The steps of the second fictional user can include entering access credentials in a field of the GUI of the remote login application. Before running program 205, one of the robotic process automation programs can be used to perform the recording of the second mouse output data and / or the second keyboard output data.

[0095] The remote login application can include a network-level authentication process. This can further reduce the risk that can be executed to log in to the first computer system 100 from outside the second security area.

[0096] Figure 3 Is a flowchart of a method for performing a login from the second computer system 120 to the first computer system 100. The method can include the following operations or functions.

[0097] In block 301, an application process on the first computer system 100 can be executed, and the first computer system 100 is arranged within the first security area 1.

[0098] In block 302, the access credentials of the application process can be stored in the storage device 4.

[0099] In block 303, a further application process can be executed on the third computer system 140.

[0100] In block 304, the further application process can be controlled by the graphical user interface of the further application process as described above.

[0101] In block 305, the application process can interact with the further application process as described above.

[0102] In block 306, an application robot may be executed on the first computer system 100 as described above, where the first computer system 100 is communicatively coupled to the third computer system 140.

[0103] In block 307, the application robot may execute an application process, where executing the application process includes the step of simulating a first imaginary user using the graphical user interface of a further application process as described above.

[0104] In block 308, logging in to the first computer system 100 from the second computer system 120 may be performed to obtain access to the application process using access credentials. As described above, the logging in may be automatically performed by a login robot.

[0105] In block 309, the application process may be initialized. For example, the application process may be initialized by sending a start command from the second processor 122 to the first processor 102. The numbering of the steps or functional blocks does not prescribe the order of execution of the steps. Preferably, step 309 may be performed before performing steps 301, 302, 303, 304, 305, 306, 307, 308. Preferably, step 301 and step 303 may be performed in parallel to enable easy and time-saving interaction between the application process and a further application process. Sequential execution of step 301 and step 303 is possible but may be more time-consuming. Step 302 may be performed during the execution of all other steps 301, 303, 304, 305, 306, 307, 308, 309.

[0106] In one example, a secure connection may be established between the second computer system 120 and the first computer system 100. The access information may be provided to the first computer system 100 using the secure connection. The access information may provide access to a further application process. In response to receiving the access information, the application robot may simulate the steps of a first imaginary user using the graphical user interface of the further application process and perform a login into the further application process using the access information. Within a first security zone, the access information may be received from a second security zone only via the secure connection. The secure connection may be provided by a remote desktop application. For example, the secure connection may include the first communication protocol described above. In this case, the first communication protocol may be used to send the access information.

[0107] In another example, the login robot can be initiated via the jump server 7. The jump server 7 can be arranged within the first security zone 1 and communicatively coupled via a further secure connection 8 between the first security zone 1 and the third security zone 3, and can be accessed from the third security zone 3 via the further secure connection 8. The further secure connection can be a VPN connection. For example, a user of the third network 13 can log in to the jump server 7 from a workstation 9 of the third network 13. In response to the login on the jump server 7, the user of the third network 13 can access certain functions of one of the robotic process automation programs, and one of the functions can be a control function.

[0108] The control function can enable the user of the third network 13 to initiate the login robot via the jump server 7. To achieve this, a robot start command can be sent from the jump server 7 to the second computer system 120.

[0109] In another example, the run script can be controlled, preferably initiated, via the jump server 7. The run script can be programmable and / or controllable by the user of the third network 13 logged in to the jump server 7. For example, the run script can be programmed to cause the execution of the login from the second computer system 120 to the first computer system 100 and the execution of the application robot to be scheduled in a queue. The run script can also include an initialization command for starting a second application robot on a fourth computer system (not shown). Preferably, the execution of the login to the first computer system 100 and the execution of the login to the fourth computer system are scheduled via the run script. These two different logins can be executed in parallel. The second access credential for accessing the fourth computer can be stored on the storage device 4. By starting the run script, the user of the third network 13 can initiate a further application process and a second further application process without logging in to the first computer system 100 and without logging in to the fourth computer system. Figure 1 The present invention can be a system, method, and / or computer program product at any possible technical detail integration level. The computer program product can include a computer-readable storage medium (or media) having computer-readable program instructions thereon for causing a processor to execute aspects of the present invention. The computer-readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device.

[0110] The present invention can be a system, method, and / or computer program product at any possible level of integration of technical details. The computer program product may include a computer-readable storage medium (or media) having computer-readable program instructions thereon for causing a processor to execute aspects of the present invention. The computer-readable storage medium can be a tangible device that can retain and store instructions for use by an instruction execution device.

[0111] A computer-readable storage medium can be, for example but not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of computer-readable storage media includes the following: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device such as a punched card or a raised structure in a groove having instructions recorded thereon, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium should not be construed as a transitory signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through an optical fiber cable) or an electrical signal transmitted through a wire.

[0112] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing / processing device via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network), or to an external computer or an external storage device. The network can include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in a computer-readable storage medium within the corresponding computing / processing device.

[0113] The computer-readable program instructions for carrying out operations of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state-setting data, configuration data for integrated circuits, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages (such as Smalltalk, C++) and procedural programming languages (such as the "C" programming language or similar programming languages). The computer-readable program instructions may be executed entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the latter case, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider). In some embodiments, an electronic circuit, including, for example, a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA), can execute the computer-readable program instructions by using the state information of the computer-readable program instructions to personalize the electronic circuit, so as to perform various aspects of the present invention.

[0114] Aspects of the present invention are described herein with reference to the flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.

[0115] These computer-readable program instructions can be provided to a processor of a computer or other programmable data processing apparatus to produce a machine, such that the instructions executed via the processor of the computer or other programmable data processing apparatus create a means for implementing the functions / acts specified in one or more blocks of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, a programmable data processing apparatus, and / or other devices to work in a particular manner, so that the computer-readable storage medium storing the instructions includes a manufacture including instructions that implement aspects of the functions / acts specified in one or more blocks of the flowchart and / or block diagram.

[0116] The computer-readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device, such that a series of operational steps are performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, so that the instructions executed on the computer, other programmable apparatus, or other device implement the functions / acts specified in one or more blocks of the flowchart and / or block diagram.

[0117] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of the possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of instructions, which includes one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the blocks may occur out of the order noted in the figures. For example, two blocks shown in succession may in fact be completed as one step, executed simultaneously, substantially simultaneously, partially or wholly in a time-overlapped manner, or the blocks may sometimes be executed in the reverse order, depending on the functionality involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or acts or a combination of dedicated hardware and computer instructions.

Claims

1. A computer-implemented method for secure login, the method comprising: Executing an application process on a first computer system, the first computer system being arranged within a first security zone; Storing access credentials for the application process in a storage device, the storage device being arranged within a second security zone, and the first security zone and the second security zone being communicatively coupled via a firewall, wherein the first security zone is communicatively coupled with a third security zone, and the application process interacts with a further application process, the further application process being executed on a third computer system, the further application process being controlled by a graphical user interface of the further application process, the third computer system being arranged within the third security zone; Executing an application robot on the first computer system, wherein the first computer system is communicatively coupled with the third computer system, the application robot executing the application process, wherein executing the application process includes the step of simulating a first imaginary user using the graphical user interface of the further application process; and Performing a login from a second computer system into the first computer system for obtaining access to the application process using the access credentials, the second computer system being arranged within the second security zone, wherein, by obtaining access to the application process, the application process can be initialized, wherein the firewall is configured such that the login on the first computer system can only be performed from the second computer system.

2. The method according to claim 1, wherein Performing the login by a login robot, the login robot simulating the steps of a second imaginary user performing the login from the second computer system into the first computer system.

3. The method according to claim 1, wherein, The application process includes a graphical user interface.

4. The method according to claim 1, wherein The application process includes a graphical user interface, and the login is performed by a login robot, the login robot simulating the steps of a second imaginary user performing the login from the second computer system to the first computer system, the login robot obtaining access to the graphical user interface of the application process and initializing the application process using the graphical user interface of the application process.

5. The method according to claim 1, further comprising: Establishing a secure connection between the second computer system and the first computer system and providing access information to the first computer system using the secure connection, the access information providing access to the further application process and in response to receiving the access information, the application robot using the graphical user interface of the further application process to simulate the steps of the first imaginary user, performing a login into the further application process using the access information, wherein, within the first security zone, the access information can only be received from the second security zone via the secure connection.

6. The method according to claim 1, wherein The first computer system is implemented as a dedicated application server.

7. The method according to claim 1, wherein The third computer system is implemented as a non-dedicated application server.

8. The method according to claim 1, wherein The second security zone and the third security zone are communicatively coupled only indirectly via the first security zone.

9. The method according to claim 1, wherein Interactive logins into the first computer system from the first security zone are prohibited.

10. The method according to claim 2, wherein, The login and the execution of the application robot are scheduled for execution in a queue via a running script that is executed within the first security zone, wherein execution of the running script provides for execution of the login, followed by execution of the application robot.

11. The method according to claim 1, further comprising: Executing a second application robot on a fourth computer system, the fourth computer system being arranged within the first security zone and communicatively coupled to a fifth computer system, the second application robot executing a second application process, wherein execution of the second application process includes the steps of using a graphical user interface of a second further application process and simulating a further first imaginary user using the graphical user interface of the second further application process, the second further application process operating on the fifth computer system and being controlled by the graphical user interface of the second further application process, the fifth computer system being arranged within the third security zone, performing a login into the fourth computer system to obtain access to the second application process, wherein by obtaining access to the second application process, the second application process can be initialized, wherein the login into the fourth computer system is performed from the second security zone by a second login robot using a second access credential, the second login robot simulating the steps of the login into the fourth computer system by a further second imaginary user, wherein the login into the first computer system and the login into the fourth computer system are scheduled via a running script, and the second access credential is stored within the second security zone.

12. The method according to claim 2, further comprising: Initiating the login robot via a jump server, the jump server being arranged within the first security zone and communicatively coupled via a further secure connection between the first security zone and the third security zone, and being accessible from the third security zone via the further secure connection for initiating the login robot via the jump server.

13. The method according to claim 10, further comprising: Controlling the running script via a jump server, the jump server being arranged within the first security zone and communicatively coupled by a further secure connection between the first security zone and the third security zone, and the jump server being accessible from the third security zone via the further secure connection in order to control the running script via the jump server.

14. The method according to claim 5, further comprising: Storing the access information encrypted and protected within the second security zone.

15. The method according to claim 2, further comprising: Use the login robot access credentials to perform a login to the login robot, where the login robot is only accessible by using the login robot access credentials, and the login robot access credentials are stored in the second secure area.

16. A computer program product comprising program instructions executable by a computer to cause the computer to perform the steps in the method according to any one of claims 1-15.

17. A system for secure login, comprising: A computer system, the computer system comprising: a computer processor, a computer-readable storage medium, and program instructions stored on the computer-readable storage medium, the program instructions being executable by the processor to cause the computer system to perform the steps in the method according to any one of claims 1-15.

Citation Information

Patent Citations

  • Robotics process automation platform

    US20180197123A1