Computer process

A computer method using identification messages, unique tokens, and an interconnection server enhances security by authenticating and authorizing connections between applications and peripherals, preventing unauthorized access and ensuring secure data backup and recovery.

FR3152901B1Active Publication Date: 2025-10-24BKUBE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2023009586
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-09-12
Publication Date
2025-10-24
Estimated Expiration
2043-09-12

AI Technical Summary

Technical Problem

Existing methods for securing communications between computer peripherals or software and peripherals are limited in their ability to prevent malware from accessing the network and connecting with devices, lacking sufficient security against malicious intrusive actions.

Method used

A computer method involving identification messages, unique tokens, and an interconnection server to authenticate and authorize connections between an application and a peripheral, ensuring only authorized devices can communicate, with the server managing connection procedures to enhance security.

Benefits of technology

The method provides enhanced security by preventing unauthorized access and communication, reinforcing protection against computer attacks, and ensuring secure data backup and recovery.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000027_0000
    Figure 00000027_0000
  • Figure 00000027_0001
    Figure 00000027_0001
Patent Text Reader

Abstract

Title: Computer method The invention relates to a computer method for communication between an application (2) of a computer station (4) and a first peripheral (1) comprising the following steps: Step 1: sending, by the application of the computer station (4), a first identification message to an interconnection server (3); Step 2: sending, by the first peripheral, a second identification message to the interconnection server; Step 3: reception by the application of a unique token (9) from the interconnection server; Step 4: broadcasting the unique token on a local network (7) to which both the computer station and the first peripheral are connected, Step 5: upon receipt of the unique token by the first peripheral, sending, by the first peripheral to the interconnection server, a message associating the first peripheral with the unique token; Step 6: reception by the application of a procedure for connecting to the first peripheral;Step 7: Connecting the application to the first device using the connection procedure. Figure for summary: Fig. 1.;
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Computer process Technical field

[0001] The present invention relates to the field of computer security and more particularly to the field of secure connection, via a server, between one computer hardware and another, and in particular between software (or an application) of a computer hardware and a computer peripheral. It finds a particularly advantageous application in the field of secure backup of computer data. STATE OF THE ART

[0002] There are several technical solutions for securing communications between computer peripherals or between software (or an application) and a computer peripheral. We can notably cite the principle of broadcasting (or "token" in English) tokens (which are contained in data packets) on a predetermined network where the elements that need to communicate are connected. More precisely, after the broadcasting of tokens by a peripheral on a network, the other peripherals also present on the network receive a token and determine whether the token received was intended for them, this in order to be able to associate with the peripheral that sent the tokens and therefore to be able to communicate with it. Thus, by this method, only the peripherals receiving a token intended for them can connect with the peripheral that issued the tokens.Furthermore, this type of technical solution can also be based on the use of an intermediary, which could be a server, whose role is to increase the level of security by granting communication between the two devices or refusing it according to predetermined criteria.

[0003] However, this type of technical solution has drawbacks. In particular, it is limited in terms of the security it provides against malware that wants to access the network to connect with devices connected to the network.

[0004] An object of the present invention is therefore to propose a method having more extensive capabilities and in particular allowing greater security against malicious intrusive actions.

[0005] Other objects, features and advantages of the present invention will become apparent from the following description and accompanying drawings. It is understood that other advantages may be incorporated. SUMMARY

[0006] To achieve this objective, according to one embodiment, a computer method is provided for communication between an application of a computer station and a first peripheral comprising the following steps: • Step 1: sending, by the computer workstation application, of a first identification message to an interconnection server; • Step 2: sending, by the first device, of a second identification message to the interconnection server; • Step 3: reception by the application of a unique token from the interconnection server; • Step 4: broadcasting the unique token on a local network to which both the computer workstation and the first device are connected, • Step 5: upon receipt of the unique token by the first device, sending, by the first device to the interconnection server, of a message associating the first device with the unique token; • Step 6: reception by the application of a connection procedure to the first device; • Step 7: The application enters into communication with the first device using the connection procedure.

[0007] Thus, the fact that after the application and the first device identify themselves to the interconnection server (by sending the first identification message and the second identification message) and the application broadcasts a unique token on the network, the first device sends to the interconnection server a message associating the first device with the unique token so that only then does the interconnection server send to the application a procedure for connecting the application to the first device so that the fact that the application can connect with the first device implies that the application cannot directly enter into communication with the first device, this because the first device is invisible to the application until the moment when the interconnection server grants communication between the application and the first device.Indeed, at no time before the application receives the connection procedure between the application and the first device, can the application identify which devices are present on the local network at a particular address.

[0008] Furthermore, due to the steps of the method, the interconnection server will only grant the connection between the first device and the application (defined in the computer method) and will not grant the connection between the first device and an application not identified by the computer server as being the one can connect with the first device. Therefore, no malicious application will be able to communicate with the first device.

[0009] Also, in this method, given that the protocols and in particular the connection procedure between the application and the peripherals can be modified over time, the security of the process against computer attacks can be reinforced. Indeed, given that the application and the peripherals only enter into communication thanks to the interconnection server which provides the connection procedure to the application, the interconnection server is able to modify the connection procedure before each connection.

[0010] Another aspect relates to a computer method comprising, after step 7, the following steps: • Step 8: transfer by the application to the first device of the first files to be saved; • Step 9: Backup the first files to be backed up using the first device.

[0011] Thus, the first peripheral involved in the computer method according to the invention may have the function of saving computer data. Thus, the computer method according to the invention has the function of securing the communication between the application and the first peripheral, in particular by prohibiting any application from entering into communication with the first peripheral. In this way, the computer data saved on the first peripheral cannot be intercepted by a malicious application, in particular with the aim of making them public or using them for identity theft purposes.

[0012] Another aspect relates to a computer method comprising, after step 9, the following steps: • Step 10: sending to the application by the first device a first list of files to be transferred; • Step 11: Transfer from the first device to the application at least one of the files on the first list of files to be transferred; • Step 12: Duplication by the first device on the interconnection server of at least one file appearing on the first list of files to be transferred and which has been transferred.

[0013] The computer method according to the invention can also allow the application to recover files that have been previously saved on the first device. In this case, the duplication of the files transferred to the interconnection server is a security measure that makes it possible to avoid possible losses of computer data, particularly in the event that the computer data present on the computer workstation has been the target of computer hacking.

[0014] Another aspect relates to a computer method in which the first device is configured so as not to broadcast a message of its presence on the local network.

[0015] Thus, in this way, a malicious application that has not been identified by the interconnection server as being able to communicate with the first device will be unable to communicate with the first device. Indeed, given that the first device will not broadcast any message of its presence, it will be impossible for the malicious application to intercept the first device.

[0016] Another aspect relates to a computer device comprising: - a computer station comprising an application and - a first peripheral, in which: - the computer station and the first device are connected to a local network, and in which: - the application is configured to send a first identification message to an interconnection server, then - the first device is configured to send a second identification message to the interconnection server, then - after sending the first identification message, the application is configured to receive a unique token sent from the interconnection server, - after receiving the unique token, the application is configured to broadcast the unique token on the local network, - upon receipt of the unique token, the first device is configured to send to the interconnection server a message associating the first device with the unique token, - after sending the association message from the first device to the unique token, the application is configured to receive a connection procedure from the first device, - after receiving the connection procedure from the first device, the application is configured to enter into communication with the first device by means of the connection procedure.

[0017] Thus, given that the different elements of the computing device are configured in such a way that the interconnection server is the only computing element that can grant communication between the application and the first device, the computing device provides optimal security against malware. Furthermore, since the first device cannot broadcast a message on the local network allowing it to be identified, malware will be unable to identify the first device in order to communicate with it. BRIEF DESCRIPTION OF THE FIGURES

[0018] The aims, objects, as well as the characteristics and advantages of the invention will emerge more clearly from the detailed description of an embodiment thereof which is illustrated by the following accompanying drawings in which:

[0019] [Fig.l] [Fig.l] represents a diagram of the different stages of the computer method according to an embodiment of the invention resulting in communication between the application and the first peripheral.

[0020] [Fig.2] [Fig.2] represents a diagram of steps in the computer process according to an embodiment of the invention where a selection of the device can be carried out.

[0021] The drawings are given as examples and are not limiting of the invention. They constitute schematic representations of principle intended to facilitate the understanding of the invention and are not necessarily on the scale of practical applications. DETAILED DESCRIPTION

[0022] Before beginning a detailed review of embodiments of the invention, optional features which may possibly be used in combination or alternatively are set out below:

[0023] According to one example, the computer method comprises, before step 1, the following steps: • Step 0: Query by the first device 1 of a DNS server to retrieve an address 6 from the interconnection server 3; • Step 0a: sending by the first device 1 to address 6 of a file containing parameters describing the first device 1 so that it can be identified by the interconnection server 3.

[0024] According to one example, the unique token 9 has a limited lifespan.

[0025] Thus, the fact that the unique token 9 has a limited lifespan in time allows for connection protocols that evolve over time and are therefore difficult to hack. More specifically, the unique token contains a timestamp system that allows the unique token to be revoked when it expires.

[0026] Furthermore, in the same way, the procedure for connecting the application 2 to the first peripheral 1 (or to the at least one second peripheral 1') can also be modified over time in order to strengthen the security of the method against computer hacking.

[0027] According to one example, the computer method, for at least one second peripheral 1' being connected to the local network 7, comprises: - the next step, after step 2: • Step 2a: sending, by at least one second device 1', at least one third identification message to the interconnection server 3, each second device 1' sending a third separate identification message; - the next step, after step 5: • Step 5a: upon receipt of the unique token 9 by the at least one second device 1', sending, by the at least one second device 1' to the interconnection server 3, of at least one association message from the at least one second device 1' to the unique token 9, each second device 1' sending to the interconnection server 3 a separate association message; - the next step, after step 6: • Step 6a: reception by the application 2 of at least one connection procedure to the at least one second peripheral 1', each connection procedure allowing the connection of the application 2 to a separate second peripheral 1'; - the next step, after step 7: • Step 7a: entry into communication of the application 2 with the at least one second peripheral 1' by means of the at least one connection procedure.

[0028] Thus, the computer method provides the possibility that the application 2 connects at the same time with several peripherals (a first peripheral 1 and at least one second peripheral 1'), this in a secure manner in the same way as the application 2 connects to the first peripheral 1.

[0029] According to one example, the computer method comprises, after step 7a, the following steps: • Step 8a: transfer by application 2 to at least one second device 1' of the second files to be saved; • Step 9a: backup by at least one second device 1' of the second files to be backed up.

[0030] Thus, thanks to these steps of the computer process, backups of files can be carried out in parallel on several devices, this allowing greater security against potential losses of computer data.

[0031] According to one example, the computer method comprises, after step 9a, the following steps: • Step 10a: sending to application 2 by at least one second device 1' a second list of files to be transferred; • Step 1: transfer from at least one second device 1' to the application 2 of at least one of the files appearing on the second list of files to be transferred; • Step 12a: duplication by the at least one second device 1' on the interconnection server 3 of the at least one file appearing on the second list of files to be transferred and which has been transferred.

[0032] In the same way as for the first peripheral 1, the at least one second peripheral 1' makes it possible to transfer (to the application 2) the computer data that has been saved on the peripheral in question. The fact that all of the files transferred from the peripheral to the application (i.e. to the computer station) are duplicated on the interconnection server 3 makes it possible to ensure additional security so that the computer data can be recovered in the event of hacking targeting the computer station.

[0033] According to one example, the computer method comprises, after step 7a, the following steps: • Step 7b: request by the application 2 to the interconnection server 3 for a list 8 comprising the identifiers of the first device 1 and of the at least one second device 1' present on the local network 7; • Step 7c: reception by application 2 of list 8; • Step 7d: Selection by application 2 in list 8 of a device chosen from the first device 1 and the at least one second device 1'.

[0034] Thus, the method provides the possibility that the application 2 can select with which peripherals (among the first peripheral 1 and the at least one second peripheral 1') it wishes to enter into communication.

[0035] According to one example, the computer method comprises, after step 7d, the following steps: • Step 8b: transfer by the application 2 to the device chosen from among the first device 1 and at least one second device 1' of third files to be saved; • Step 9b: backup by the device chosen from the first device 1 and at least one second device 1' of the third files to be backed up.

[0036] Thus, in the case where application 2 wishes to enter into communication with a single peripheral, the transfer of files is carried out from application 2 to the selected peripheral(s).

[0037] According to one example, the computer method comprises, after step 9b, the following steps: • Step 10b: sending to application 2 by the device chosen from the first device 1 and at least one second device 1' of a third list of files to be transferred; • Step 11b: transfer from the device chosen from the first device 1 and at least one second device 1' to the application 2 of at least one of the files appearing on the third list of files to be transferred; • Step 12b: duplication by the device chosen from the first device 1 and the at least one second device 1' on the interconnection server 3 of the at least one file appearing on the third list of files to be transferred and which has been transferred.

[0038] Thus, when the application 2 has selected with which peripherals it wishes to enter into communication, in the same way as when the application 2 enters into communication with several peripherals, a duplication of the files is carried out on the interconnection server 3 in order to prevent a loss of files due in particular to computer hacking.

[0039] According to one example, the computer method comprises, between step 0a and step 1, the following steps: • Step 0b: interrogation by at least one second device 1' of the DNS server to retrieve the address 6 of the interconnection server 3; • Step 0c: sending by the at least one second device 1' to the address 6 of a file containing parameters describing the at least one second device 1' so that it can be identified by the interconnection server 3, each second device 1' sending a separate file to the address 6.

[0040] According to one example, the at least one second device 1' is configured so as not to broadcast a message of its presence on the local network 7.

[0041] Thus, given that the at least one second device 1' cannot broadcast messages of its presence on the local network 7, in the same way as for the first device 1, the at least one second device 1' cannot be detected by the application before the interconnection server 3 has granted communication between the at least one second device 1' and the application 2.

[0042] In the context of the present invention, the term "local area network" (Local Area Network) is understood to mean a computer network where the terminals (in particular the computers) which are connected to it send frames to each other at the link layer (or the second layer of the seven layers of the OSI model) without using access to a global computer network (i.e. in particular the Internet). Also, a local area network is defined by the broadcast domain associated with it, i.e. by all the stations which receive the same broadcast frame. A local area network can for example be a business network or a home network.

[0043] A computer (or computer workstation) is a programmable information processing system operating by the sequential reading of a set of instructions, organized into programs. A computer therefore executes, one after the other, instructions allowing the manipulation of a set of data acquired either by reading memories or from internal or external peripherals.

[0044] The term "memory" is understood in the present invention as "computer-readable memory medium". This term designates here any storage means allowing files and programs to be stored and includes all types of memories such as random access memory (RAM) or read-only memory (ROM). It is understood that, in the present invention, the memory of a computer can in reality comprise several types of memories.

[0045] In the context of the present invention, at least a portion of the computer memory is capable of storing the application (subject of the present invention) which itself comprises instructions executable by the programmable information processing system.

[0046] The term "processor" refers to the element of the computer which organizes the exchange of data between different components of the computer, i.e. the hard disk, the memory and the graphics card.

[0047] The term "software" refers to a set of machine-readable instruction sequences (called programs) and a data set. A computer program may be written in any programming language, including compiled or interpreted languages, and may be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. A computer program may be deployed for execution on one computer or on multiple computers located at a single site or distributed across multiple sites and interconnected by a communications network.

[0048] It is specified that in the context of the present invention, the term "application" is a computer program making it possible to carry out a set of tasks for a predefined objective. Thus, an application corresponds to the use of software for a specific purpose.

[0049] Processors suitable for executing a computer program include, by way of example, general and special purpose microprocessors, as well as one or more processors of any type of digital computer. Generally, a processor receives instructions and data from read-only memory or random access memory, or both. The elements of a computer may include at least one processor for executing the instructions and one or more memory devices for storing the instructions and data. Generally, a computer may also include, or be operably coupled to receive data from or transfer data to, or both, one or more mass storage devices for storing data, e.g., magnetic, magneto-optical, or optical disks.

[0050] A "computer peripheral" is a device connected to an information processing system, i.e. in our case, a computer workstation, which adds functionality to the information processing system. There are several types of peripherals: input peripherals (keyboard, mouse, scanner, webcam, etc.) which are used to obtain information, output peripherals (screen, printer, speakers, etc.) which are used to obtain information and storage peripherals (hard disk, USB key, etc.) which act in both directions, i.e. they allow computer data to be stored and also read.

[0051] In the context of the present invention, a "computer server or interconnection server" is a computer device whose function is to provide services to one or more software programs. These services may consist of providing an electronic mail system, database storage (or data directory suitable for storing and retrieving a large volume of data), management of authentication and access control.

[0052] In the context of the present invention, an address allows one entity to address another among a set of entities. Thus, it is necessary that each address associated with each entity be unique. More precisely, an IP address is an identification number that is assigned to a device connected to a computer network that uses the Internet Protocol.

[0053] The term "encryption key" means a parameter used as input to a cryptographic operation. In the context of the present invention, the encryption keys may be symmetric or asymmetric. In the case where it is symmetric, the same key is used to encrypt and decrypt. In the case where it is asymmetric, two different keys are used, a public key is used for encryption while a secret key (which is as its name suggests kept secret) is used for decryption.

[0054] In the context of the present invention, the term "token" (or "authentication token") is understood to be a computer device allowing an element to authenticate itself against another element. More precisely, the token is a device used to allow access to a protected resource in which the element that can authenticate can only be the one having the token (because the token has been specifically given to it).

[0055] According to one embodiment, the computer method of communication between an application 2 and a first peripheral 1 comprises the following steps: • Step 1: communication, by the application 2 of a computer station 4, of a first identification message to an interconnection server 3; • Step 2: communication, by the first device 1, of a second identification message to the interconnection server 3; • Step 3: application 2 obtains a unique token 9 sent from the interconnection server 3; • Step 4: simultaneous transmission on the local network 7 (to all the IT elements present on the local network 7) of the unique token 9, the computer station 4 and the first peripheral 1 being connected to the local network 7; • Step 5: upon obtaining the unique token 9 by the first device 1, transmission, by the first device 1 to the interconnection server 3, of an association message from the first device 1 to the unique token 9; • Step 6: obtaining by application 2 of a connection procedure to the first device 1, the connection procedure having been sent by the interconnection server 3; • Step 7: Contact application 2 with the first device 1 using the connection procedure.

[0056] The interconnection server 3 can be at the local network 7 level or at the cloud computing level.

[0057] In this method, it is considered that the computer station, the first peripheral and the at least one second peripheral are connected to the Internet (which may also be called a “global computer network”). It is also considered that the computer station is connected to the local network. The first peripheral and the at least one second peripheral will therefore retrieve an IP address via the DHCP server in order to be able to connect to the Internet (which may also be called a “global computer network”).

[0058] In this method, the step during which the first device sends an identification message to the interconnection server after it has received the unique token corresponds to the transmission by the first device of the unique token to the interconnection server with its identifiers (its IP address on the local network, its transfer name, its identifier on the network, disk occupancy, supported protocol). During this step, the first device (or the at least one second device 1') also sends the address and the encryption key allowing the application to communicate with the first device 1 (or the at least one second device). The interconnection server does not directly hold the encryption key. The encryption key is in fact held on a server external to the interconnection server.

[0059] In this method, the connection procedure for the application 2 to communicate with the first device 1 is created by the interconnection server 3. The connection procedure can be unique and can be modified at any time. The connection procedure is not configured to have to be recreated after a certain predefined time interval. It can only be regenerated if the interconnection server and the two devices are online and accessible. Thus, for example, in the case of an attack, where access to the Internet would be impossible, the fact that the connection procedure can be modified only on request makes it possible to work in degraded mode without needing to regenerate the connection procedure.The communication of this connection procedure takes into account the communication of the address and the encryption key allowing the application to communicate with the first device 1 (or at least one second device). More precisely, the connection procedure will contain the IP address of the device in question, the name of the device in question, the protocol to be used (SSH for example), the connection port and the SSH encryption key.

[0060] After the application 2 is downloaded, in the case of first connection, the user can enter his contact details (e-mail address, password and telephone number) and create an account on the web server. The e-mail address is then verified by sending an e-mail with a link used to confirm the e-mail address. In the same way, an SMS (Short Message Service) is sent to the telephone number provided. In the case of use of the application 2 with an existing account, authentication with a username and a password is set up. Double authentication with sending an SMS or an e-mail can be carried out. The application 2 can also be installed on the computer station 4 from a locally available data medium and in particular a USB key (Universal Serial Bus in English).

[0061] At the start of the communication between the first device 1 (or the at least one second device) and the application 2 (i.e. once the connection procedure and the connection have been established), the application 2 communicates to the first device 1 (or to the at least one second device) a backup manifest allowing it to be able to communicate with the application 2 the list of backups already carried out.

[0062] Preferably, the computer method comprises, after step 7 or after step 7a, the following steps: • Step 8: transmission by application 2 to the first device 1 of the first files to be saved; • Step 9: Backup by the first device 1 of the first files to be backed up.

[0063] Advantageously, the computer method comprises, after step 9, the following steps: • Step 10: communication to application 2 by the first device 1 of a first list of files to be transferred; • Step 11: transmission from the first device 1 to the application 2 of at least one of the files present on the first list of files to be transferred; • Step 12: reproduction of a copy (for conservation) by the first device 1 on the interconnection server 3 of at least one file present on the first list of files to be transmitted which has been transmitted.

[0064] Thus, in the method, since a copy of each file is kept, it is not possible to completely delete files.

[0065] When a file that had already been saved by the device is replaced by a partially different file, only the part of the file that is different is replaced. Thus, a hash of the file is made to replace only the part of the file that is different (between the initial file and the one replacing the initial file).

[0066] In the case where files downloaded to the first device (or one of the second devices 1') have been encrypted, that is to say in particular in the case of piracy, the first device (or one of the second devices 1') can give statistics of the saved data so that the user can identify that piracy has occurred. Indeed, in the case of data encryption, the original file is deleted and is replaced by a file whose extension has changed and which is encrypted.

[0067] Also, the first device (or one of the second devices 1') can sort the files to keep only the latest versions of the files that have not been encrypted.

[0068] According to an advantageous example, the computer method comprises, before step 1, the following steps: • Step 0: Query by the first device 1 of a DNS server to obtain an address 6 of the interconnection server 3; • Step 0a: communication by the first device 1 to address 6 of a file containing parameters giving the characteristics of the first device 1 so that it can be determined by the interconnection server 3.

[0069] More precisely, the file containing the parameters describing the first device 1 so that it can be identified by the interconnection server 3 can be contained in a connection interface (or “socket” in English).

[0070] The file containing the parameters describing the first device 1 so that it can be identified by the interconnection server 3 can be a JSON type file sent in SSL. More precisely, the file contains the following parameters: the name of the equipment in question, the type of equipment, the UUID (Universally Unique IDentifier) ​​of the equipment, the local V4 IP address and the local V6 IP address. The file will be sent in SSL so that it is encrypted on the network.

[0071] Preferably, the unique token 9 has a limited lifetime, that is to say that the unique token 9 can only be used during a finite time interval. Thus, if the time interval allowing the use of the unique token 9 is exceeded, the interconnection server 3 will refuse the connection between the first peripheral 1 and the application 2. The lifetime of the unique token 9 can be 10 min.

[0072] Advantageously, the first device 1 is configured so as not to send a message on the local network 7 which could thus indicate its existence on the local network 7.

[0073] Preferably, the computer method, for at least one second peripheral 1' being connected to the local network 7, comprises: - the next step, after step 2: • Step 2a: communication, by at least one second device 1', of at least one third identification message to the interconnection server 3, each second device 1' communicating a third distinct identification message; - the next step, after step 5: • Step 5a: upon obtaining the unique token 9 by the at least one second device 1', communication, by the at least one second device 1' to the interconnection server 3, of at least one association message from the at least one second device 1' to the unique token 9, each second device 1' communicating to the interconnection server 3 a separate association message; - the next step, after step 6: • Step 6a: obtaining by the application 2 of at least one connection procedure to the at least one second peripheral 1', each connection procedure allowing the application 2 to make contact with a separate second peripheral 1'; - the next step, after step 7: • Step 7a: contacting the application 2 with the at least one second device 1' using the at least one connection procedure.

[0074] In this method, the at least one second device is connected to the Internet (which may also be referred to as a "global computer network").

[0075] According to a preferred example, the computer method comprises, after step 7a or after step 9, the following steps: • Step 8a: transmission by the application 2 to at least one second device 1 of second files to be saved; • Step 9a: backup by at least one second device 1' of the second files to be backed up.

[0076] The second files to be backed up may be the same as the first files to be backed up.

[0077] According to an advantageous embodiment, the computer method comprises, after step 9a or after step 12, the following steps: • Step 10a: communication to the application 2 by the at least one second peripheral 1' of a second list of files to be transmitted; • Step 1: transmission from at least one second device 1' to the application 2 of at least one of the files present on the second list of files to be transmitted; • Step 12a: reproduction of a copy (for its conservation) by the at least one second device 1' on the interconnection server 3 of the at least one file present on the second list of files to be transmitted which has been transmitted.

[0078] Preferably, the computer method comprises, after step 7a, the following steps: • Step 7b: request by the application 2 to the interconnection server 3 for a list 8 comprising the identifiers of the first device 1 and of the at least one second device 1' present on the local network 7; • Step 7c: obtaining by application 2 of list 8; • Step 7d: choice by application 2 from list 8 of a device selected from the first device 1 and at least one second device 1'.

[0079] Only devices that have sent a message associating the device in question with the unique token received are present on list 8.

[0080] Advantageously, the computer method comprises, after step 7d, the following steps: • Step 8b: transmission by the application 2 to the device selected from among the first device 1 and the at least one second device 1' of third files to be saved; • Step 9b: backup by the device selected from the first device 1 and at least one second device 1' of the third files to be backed up.

[0081] Advantageously, the computer method comprises, after step 9b, the following steps: • Step 10b: communication to the application 2 by the peripheral chosen from the first peripheral 1 and the at least one second peripheral 1' of a third list of files to be transmitted; • Step 11b: transmission from the device chosen from the first device 1 and at least one second device 1' to the application 2 of at least one of the files present on the third list of files to be transmitted; • Step 12b: reproduction of a copy (for its conservation) by the device chosen from among the first device 1 and the at least one second device 1' on the interconnection server 3 of the at least one file present on the third list of files to be transmitted which has been transmitted.

[0082] Preferably, the computer method comprises, between step 0a and step 1, the following steps: • Step 0b: query by at least one second device 1' of the DNS server to obtain the address 6 of the interconnection server 3; • Step 0c: communication by the at least one second device 1' to the address 6 of a file containing parameters giving the characteristics of the second device 1' so that it can be determined by the interconnection server 3, each second device 1' sending a separate file to the address 6.

[0083] The file containing the parameters describing the at least one second device 1' so that it can be identified by the interconnection server 3 may be a JSON type file in SSL.

[0084] According to a preferred example, the at least one second device 1' is configured so as not to send a message on the local network 7 which can thus indicate its existence on the local network 7.

[0085] According to a preferred embodiment, the computing device comprises a computer station 4, a first peripheral 1 and an application 2.

[0086] Preferably, in the computing device: - the computer station 4 and the first peripheral 1 are configured to connect to the Internet (which may also be called a “global computer network”) or to another network allowing data communications between remote hardware, - application 2 is configured to be downloaded to computer workstation 4, - the computer station 4 and the first device 1 are configured to be connected to a local network 7, - the first device 1 is configured so as not to send any message on the local network 7 which could thus indicate its existence, - after connection of the computer station 4 to the Internet, the application 2 is configured to communicate a first identification message to an interconnection server 3, - after connection of the first device 1 to the Internet, the first device 1 is configured to communicate a second identification message to the interconnection server 3, - after communication of the first identification message, the application 2 is configured to receive a unique token 9 communicated from the interconnection server 3, - after obtaining the unique token 9, the application 2 is configured to simultaneously transmit (to all the IT elements present on the local network 7) the unique token 9 on the local network 7, - upon obtaining the unique token 9, the first device 1 is configured to communicate to the interconnection server 3, a message associating the first device 1 with the unique token 9, - after communication of the association message from the first device 1 to the unique token 9, the application 2 is configured to receive a connection procedure to the first device 1, - after obtaining the connection procedure to the first device 1, the application 2 is configured to contact the first device 1 using the connection procedure.

[0087] In the computing device, the computer station 4 is defined so as to be connected to the local network 7.

[0088] Advantageously, in the computer device: - the application is configured to transfer the first files to be backed up to the first device, - the first device is configured to save the first files to be saved, - the first device is configured to send to the application a first list of files to be transferred, the application is configured to receive the first list of files to be transferred, - the first device is configured to transfer to the application at least one of the files appearing on the first list of files to be transferred, - the first device is configured to duplicate on the interconnection server the at least one file appearing on the first list of files to be transferred which has been transferred.

[0089] Thus, by these characteristics, the first peripheral has the function of saving computer data in order in particular to be able to retransmit them subsequently. Thus, the fact that the computer device makes it possible to ensure optimal security for the communication between the application and the first peripheral has the consequence that no malicious software will be able to intercept the computer data saved on the first peripheral.

[0090] According to a preferred example, in the computer device comprising at least one second peripheral 1': - the at least one second device 1' is configured to be connected to the local network 7 and to the Internet (which may also be called a “global computer network”), - the at least one second device 1' is configured so as not to broadcast a message of its presence on the local network 7, - after connection of the at least one second device 1' to the internet (which may also be called a "global computer network"), the at least one second device 1' is configured to send at least one third identification message to the interconnection server 3, each second device 1' sending a third separate identification message, - upon receipt of the unique token 9 by the at least one second device 1', the at least one second device 1' is configured to send to the interconnection server 3 a message associating the at least one second device 1' with the unique token 9, each second device 1' sending to the interconnection server 3 a separate association message, - after sending the association message from the at least one second device 1' to the unique token 9, the application 2 is configured to receive at least one connection procedure to the at least one second device 1', each connection procedure allowing the connection of the application 2 to a separate second device 1', - after receiving the connection procedure to the at least one second device 1', the application 2 is configured to enter into communication with the at least one second device 1' by means of the at least one connection procedure.

[0091] Thus, in the same way as for the first peripheral 1, given that only the interconnection server 3 can grant communication between the at least one second peripheral 1' and the application 2 and given that the at least one second peripheral 1' does not broadcast messages of its presence on the local network, the computer device makes it possible to obtain high security against computer hacks aimed at connecting to the peripheral in question.

[0092] According to an advantageous example: - the application 2 is configured to transfer to the at least one second device 1' second files to be saved, - at least one second device 1' is configured to save the second files to be saved, - the at least one second device 1' is configured to send to the application 2 a second list of files to be transferred, - the at least one second device 1' is configured to transfer to the application 2 at least one of the files appearing on the second list of files to be transferred, the application 2 is configured to receive the second list of files to be transferred, - the at least one second device 1' is configured to duplicate on the interconnection server 3 the at least one file appearing on the second list of files to be transferred which has been transferred.

[0093] Thus, thanks to these characteristics, in the computer device, the at least one second peripheral 1' is configured so that it allows the backup of the computer data and the subsequent restitution of the saved computer data. The duplication of the computer data on the computer server 3 after they have been transferred from at least one second device 1' to the application (and therefore to the computer workstation) provides additional security against computer hacking.

[0094] One aspect relates to a computing system comprising a computing device and the interconnection server.

[0095] The invention is not limited to the embodiments previously described and extends to all embodiments covered by the invention.

[0096] List of references 1. first ring road 1 '. second ring road 2. application 3. interconnection server 4. computer station 6. address 7. local network 8. list 9. unique token

Claims

Claims

1. Computer method of communication between an application (2) of a computer station (4) and a first peripheral (1) comprising the following steps: • Step 1: sending, by the application (2) of the computer station (4), a first identification message to an interconnection server (3); • Step 2: sending, by the first peripheral (1), a second identification message to the interconnection server (3); • Step 3: reception by the application (2) of a unique token (9) from the interconnection server (3); • Step 4: broadcasting the unique token (9) on a local network (7) to which both the computer station (4) and the first peripheral (1) are connected; • Step 5: upon receipt of the unique token (9) by the first device (1), sending, by the first device (1) to the interconnection server (3), of a message associating the first device (1) with the unique token (9);• Step 6: reception by the application (2) of a connection procedure to the first peripheral (1); • Step 7: entry into communication of the application (2) with the first peripheral (1) by means of the connection procedure, the method being such that step 7 is only carried out when all steps 1 to 6 are carried out.;

2. Computer method according to the preceding claim comprising after step 7 the following steps: • Step 8: transfer by the application (2) to the first device (1) of first files to be saved; • Step 9: backup by the first device (1) of the first files to be saved.

3. Computer method according to the preceding claim comprising, after step 9, the following steps: • Step 10: sending to the application (2) by the first device (1) of a first list of files to be transferred; • Step 11: transfer from the first device (1) to the application (2) of at least one of the files appearing on the first list of files to be transferred; • Step 12: duplication by the first device (1) on the interconnection server (3) of the at least one file appearing on the first list of files to be transferred and which has been transferred.

4. Computer method according to any one of the preceding claims comprising, before step 1, the following steps: • Step 0: interrogation by the first device (1) of a DNS server to retrieve an address (6) of the interconnection server (3); • Step 0a: sending by the first device (1) to the address (6) of a file containing parameters describing the first device (1) so that it is identifiable by the interconnection server (3).

5. A computer method according to any preceding claim wherein the unique token (9) has a limited lifetime.

6. Computer method according to any one of the preceding claims in which the first peripheral (1) is configured so as not to broadcast a message of its presence on the local network (7).

7. Computer method according to any one of the preceding claims, in which for at least one second peripheral (1') being connected to the local network (7), the computer method comprises: - the following step, after step 2: • Step 2a: sending, by at least one second peripheral (1'), at least one third identification message to the interconnection server (3), each second peripheral (1') sending a third distinct identification message; the next step, after step 5: • Step 5a: upon receipt of the unique token (9) by the at least one second device (1'), sending, by the at least one second device (1') to the interconnection server (3), at least one association message from the at least one second device (1') to the unique token (9), each second device (1') sending to the interconnection server (3) a separate association message; - the next step, after step 6: • Step 6a: reception by the application (2) of at least one connection procedure to the at least one second peripheral (1'), each connection procedure allowing the connection of the application (2) to a second distinct peripheral (1'); - the next step, after step 7: • Step 7a: entry into communication of the application (2) with the at least one second peripheral (1') by means of the at least one connection procedure.

8. Computer method according to the preceding claim comprising after step 7a the following steps: • Step 8a: transfer by the application (2) to at least one second device (1') of second files to be saved; • Step 9a: backup by at least one second device (1') of the second files to be backed up.

9. Computer method according to the preceding claim comprising, after step 9a the following steps: • Step 10a: sending to the application (2) by the at least one second device (1') a second list of files to be transferred; • Step 1: transfer from at least one second device (1') to the application (2) of at least one of the files appearing on the second list of files to be transferred; • Step 12a: duplication by at least one second device (1') on the interconnection server (3) of the ... least one file on the second list of files to transfer that has been transferred.

10. Computer method according to claim 7, comprising, after step 7a, the following steps: • Step 7b: request by the application (2) to the interconnection server (3) for a list (8) comprising the identifiers of the first peripheral (1) and of the at least one second peripheral (1') present on the local network (7); • Step 7c: reception by the application (2) of the list (8); • Step 7d: selection by the application (2) from the list (8) of a peripheral chosen from among the first peripheral (1) and the at least one second peripheral (1').

11. Computer method according to the preceding claim comprising after step 7d the following steps: • Step 8b: transfer by the application (2) to the device chosen from among the first device (1) and the at least one second device (1') of third files to be saved; • Step 9b: backup by the device chosen from among the first device (1) and the at least one second device (1') of the third files to be saved.

12. Computer method according to the preceding claim comprising after step 9b the following steps: • Step 10b: sending to the application (2) by the peripheral chosen from among the first peripheral (1) and the at least one second peripheral (1') of a third list of files to be transferred; • Step 11b: transfer from the peripheral chosen from among the first peripheral (1) and the at least one second peripheral (1') to the application (2) of at least one of the files appearing on the third list of files to be transferred; • Step 12b: duplication by the peripheral chosen from among the first peripheral (1) and the at least one second peripheral (1') on the interconnection server (3) of the at least one second peripheral (1') on ... least one file on the third list of files to transfer that has been transferred.

13. Computer method according to any one of claims 7 to 12 comprising, between step Oa and step 1, the following steps: • Step Ob: interrogation by the at least one second device (1') of the DNS server to retrieve the address (6) of the interconnection server (3); • Step Oc: sending by the at least one second device (1') to the address (6) of a file containing parameters describing the at least one second device (1') so that it is identifiable by the interconnection server (3), each second device (1') sending to the address (6) a separate file.

14. Computer method according to any one of claims 7 to 13 in which the at least one second peripheral (1') is configured so as not to broadcast a message of its presence on the local network (7).

15. A computer device comprising: - a computer station (4) comprising an application (2) and - a first peripheral (1), in which: - the computer station (4) and the first peripheral (1) are connected to a local network (7), and in which: - the application (2) is configured to send a first identification message to an interconnection server (3), then - the first peripheral (1) is configured to send a second identification message to the interconnection server (3), then - after sending the first identification message, the application (2) is configured to receive a unique token (9) sent from the interconnection server (3), after receiving the unique token (9), the application (2) is configured to broadcast the unique token (9) on the local network (7), upon receipt of the unique token (9), the first device (1) is configured to send to the interconnection server (3), an association message from the first device (1) to the unique token (9), after sending the association message from the first device (1) to the unique token (9), the application (2) is configured to receive a connection procedure from the first device (1), only after receipt of the connection procedure from the first device (1), the application (2) is configured to enter into communication with the first device (1) by means of the connection procedure.