Method of communicating with a remote computer from a local computer

The method and system using a mobile operating system with encryption keys for secure remote communication address the resource and security issues of existing solutions, ensuring minimal local computer resource usage and enhanced security.

FR3154272B1Active Publication Date: 2026-04-24EPSEED
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
EPSEED
Filing Date
2023-10-16
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing remote work solutions, such as TeamViewer®, heavily utilize a local computer's resources and pose security vulnerabilities, making them non-optimal and insecure for personal computers.

Method used

A method and system utilizing a mobile operating system with a public encryption key, executed on a local computer, to securely communicate with a remote computer, minimizing resource usage and enhancing security by encrypting data transmission through a mobile communication module.

Benefits of technology

The solution ensures secure and transparent remote communication, limiting local computer resource involvement and reducing security risks, while maintaining optimal performance and data integrity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000020_0000
    Figure 00000020_0000
  • Figure 00000020_0001
    Figure 00000020_0001
  • Figure 00000021_0000
    Figure 00000021_0000
Patent Text Reader

Abstract

Title: Method for Communicating with a Remote Computer from a Local Computer The invention relates to a method for communicating with a remote computer (3000) from a local computer (1000) comprising a local processor (1600) using a device (2000). It includes storage in a memory (2500) of the device of a mobile operating system comprising a public encryption key and a connection of the device to the local computer. The device includes a mobile communication module (2100) configured to receive and decrypt data encrypted using the public encryption key and to send encrypted data after it has been encrypted using the public encryption key.The process includes running the mobile operating system on the local computer, sending synchronized mobile files from the local computer to the remote computer, and receiving synchronized remote files from the remote computer. Figure for the abstract: Fig. 1.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method for communicating with a remote computer from a local computer technical field

[0001] The present invention relates to the field of communications, and more particularly to the field of remote connection. Remote work is a particularly advantageous application for it. STATE OF THE ART

[0002] Remote work is an increasingly widespread way of working. One of the main challenges of this practice is its technological implementation.

[0003] Several remote working solutions exist. One of the most widespread is TeamViewer®, software initially developed for remote assistance and allowing connection to a remote computer. More specifically, TeamViewer® allows a user working on a local computer to temporarily take control of a remote machine. The user has access to the remote machine's programs, software, and files.

[0004] This solution has the drawback of not being transparent to the local computer: its resources (processor, RAM, storage space, etc.) are used throughout the entire remote connection. Two problems arise from this: first, remote work is not neutral for the local computer, whose components are heavily used throughout the work session. This is not optimal, especially when an employee uses a personal computer as their local computer. Furthermore, the fact that the remote connection uses the local computer's components constitutes a major security vulnerability. Company data could be intercepted by malicious programs present on the local computer.

[0005] There is therefore a need for a simple and secure solution for remote work. SUMMARY

[0006] To achieve this objective, a first object of the invention relates to a method of communication with a remote computer from a local computer using a device, the local computer comprising a local processor, the method comprising the following steps: i. storage in the device memory of a so-called mobile operating system including a public encryption key, ii. a connection of the enclosure to the local computer,

[0007] The enclosure includes: i. a mobile communication module configured to receive encrypted data and decrypt it using the public encryption key, and to send encrypted data after encrypting it using the public encryption key, ii. a mobile synchronization program,

[0008] Furthermore, the method also comprises: i. a step of executing the local computer under the mobile operating system by accessing the local processor's memory in the case, then ii. during execution, a transmission of synchronized mobile files from the local computer to the remote computer via the mobile communication module and a communication network, including data encryption with the public encryption key, iii. during execution, reception and decryption of synchronized remote files from the remote computer via the communication network and the mobile communication module.

[0009] The method thus enables secure data exchange between the local computer and the remote computer. Furthermore, because the mobile operating system runs on the local computer, the resources of the device are used for remote communication with the remote computer. Only the peripherals of the local computer (screen, keyboard, mouse, etc.) are used during remote communication. Resources such as the processor and RAM of the local computer are primarily used during an initialization phase and when the local computer starts up, but the resources of the device then take over during periods of remote communication with the remote computer. This greatly limits the involvement of the local computer's resources and makes the process completely transparent to the local computer.The process therefore offers a higher level of safety than prior art solutions.

[0010] A second object of the invention relates to a system comprising a case and a computer program product, the case being able to be connected to a local computer, the case comprising: i. a memory containing a so-called mobile operating system including a public encryption key, ii. a mobile communication module configured to receive encrypted data and decrypt it using the public encryption key, and to send encrypted data after encrypting it using the public encryption key, iii. a mobile synchronization program.

[0011] The computer program product comprising instructions configured for: i. provide the local computer's processor with access to the case's memory and cause the local computer to run under the mobile operating system, then ii. trigger, during execution, the transmission of synchronized mobile files from the local computer to the remote computer via the mobile communication module and a communication network, including data encryption with the public encryption key, iii. trigger, during execution, the reception and decryption of synchronized remote files from the remote computer via the communication network and the mobile communication module. BRIEF DESCRIPTION OF THE FIGURES

[0012] The aims, objects, features and advantages of the invention will become clearer from the detailed description of an embodiment thereof, which is illustrated by the following accompanying drawings in which:

[0013] [Fig.1] Fig.1 represents an overview of the different entities that can be involved in the process according to the invention, and notably shows the exchanges between the box and the remote computer.

[0014] [Fig.2] Fig.2 represents the architecture of the case.

[0015] [Fig.3] Fig.3 illustrates a sequence of steps enabling the association of the device with a user and the remote computer.

[0016] [Fig.4A] Fig.4A illustrates a protocol for securing exchanges between programs on the remote computer and the main program.

[0017] [Fig.4B] Fig.4B illustrates a secure protocol for exchanges between the programs of the remote computer and the main program.

[0018] [Fig.5] The [Fig.5] illustrates a sequence of steps to run the local computer under the mobile operating system.

[0019] [Fig.6] Fig.6 illustrates a sequence of steps enabling secure data exchange between the mobile communication module and the remote communication module.

[0020] The drawings are given by way of example and are not limiting of the invention. They constitute schematic representations of principle intended to facilitate understanding of the invention and are not necessarily to scale with practical applications. In particular, the appearance of the computers and cases, as well as the various programs they contain, is not representative of reality. DETAILED DESCRIPTION

[0021] Before beginning a detailed review of embodiments of the invention, are The following are optional features that may be used in combination or alternatively:

[0022] According to one example, the housing contains a communication network connection module.

[0023] According to an advantageous embodiment, the method further comprises, prior to the step of running the local computer under the mobile operating system: i. a step of executing on the local computer a script configured to modify the execution order of operating systems accessible from the local computer and place the mobile operating system in the first position, then ii. a step to shut down the local computer.

[0024] According to an advantageous embodiment, the method further comprises, prior to the step of executing the local computer under the mobile operating system, a step of executing on the remote computer a program for associating the device with the remote computer, this step comprising: i. a record of a device identifier in the memory of the remote computer, ii. a sending of the public encryption key from the remote computer to the device.

[0025] According to one example, the connection of the box to the local computer is made by a wired connection between a port of the box and a port of the local computer.

[0026] According to a preferred example, the remote computer includes a remote communication module configured to receive encrypted data and decrypt it using the private encryption key and to send encrypted data using the private encryption key.

[0027] According to a preferred example, the remote computer includes a memory containing: i. information about users, ii. Information about file sharing permissions stored on the remote computer.

[0028] According to a preferred example, the remote computer includes a sharing program configured to receive sharing requests and, in response to these sharing requests, to modify the sharing permission information for files stored in the remote computer.

[0029] According to a preferred example, the remote computer is shared between several boxes, the remote computer supporting a plurality of directories, each directory being assigned to at least one box, the sharing permission information determining the content of which directory(ies) can be accessed by which box(es).

[0030] According to a preferred example, the remote computer includes a remote synchronization program configured to receive synchronized mobile files from the box via the communication network and the remote communication module, and to send synchronized remote files to the box via the remote communication module and the communication network.

[0031] According to a preferred example, the sending of remote files synchronized by the remote synchronization program takes place following the reception by the remote communication module of a synchronization request from the mobile synchronization program.

[0032] According to a preferred example, the nomadic synchronization program sends synchronization requests periodically.

[0033] The term "memory" in the present invention is understood as "computer-readable memory storage." This term refers to any storage medium capable of storing files and programs and includes all types of memory such as random access memory (RAM) or read-only memory (ROM). It is understood that, in the present invention, a computer's memory may in fact comprise several types of memory.

[0034] The term "database" in the present invention refers to any data repository suitable for storing and retrieving a large volume of data.

[0035] The encryption keys referred to above are advantageously asymmetric encryption keys, that is to say, comprising a private encryption key and a public encryption key. They are preferably RSA type keys.

[0036] The various embodiments of the method according to the present invention can be implemented in digital electronic circuits, or in computer hardware, firmware, software, or combinations thereof. They can be implemented in the form of a computer program product, that is to say, a computer program materialized by an information medium, for example, a machine-readable storage device or a propagated signal, intended to be executed by a data processing device, for example, a programmable processor, a computer, or several computers, or to control its operation.A computer program, such as the computer program(s) described above, can be written in any programming language, including compiled or interpreted languages, and can be deployed in any form, including as a standalone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. A computer program can be deployed to be... executed on one or more computers located on the same site or distributed across several sites and interconnected by a communication network.

[0037] Processors suitable for executing a computer program include, by way of example, general-purpose and special-purpose microprocessors, as well as one or more processors in any type of digital computer. Generally, a processor receives instructions and data from read-only memory (ROM) or random-access memory (RAM), or both. The components of a computer may include at least one processor for executing instructions and one or more memory devices for storing instructions and data. Typically, a computer may also include, or be operationally coupled to receive data or transfer data to, or both, one or more mass storage devices for storing data, for example, magnetic, magneto-optical, or optical disks.

[0038] The various embodiments of the invention can be implemented in a computer system that includes a back-end component, for example, a data server, or an intermediate component, for example, an application server, or a front-end component, for example, a client computer with a graphical user interface or a web browser through which a user can interact with an embodiment, or any combination of these back-end, intermediate, or front-end components. The components can be interconnected by any form or medium of digital data communication, for example, a communication network. Examples of communication networks include a local area network (LAN) and a wide area network (WAN), for example, the Internet.

[0039] The method according to the invention will now be described with reference to Figures 1 to 6.

[0040] The method according to the invention involves a local computer 1000 and a case 2000 used to communicate with a remote computer 3000 from the local computer 1000.

[0041] The remote computer 3000 is typically a computer located on the premises of a company. It is commonly part of the company's intranet, or private computer network, along with other company computers. The company's intranet is typically a secure network within which data exchange is possible between the various computers connected to it.

[0042] The local computer 1000 is typically used by the user to work remotely from the company. It may be a computer provided by the company, or a computer owned by the user. The local computer 1000 can also be used by the user for personal purposes when it is not connected to the 2000 box.

[0043] Subsequently, reference will be made to a communication network 4000 enabling in particular exchanges between the box 2000 and the remote computer 3000. This communication network 4000 can in particular be a Wi-Fi network or an Ethernet network.

[0044] For the sake of simplicity, the method will subsequently be described in its implementation for a single local computer 1000, associated with a single enclosure 2000. Naturally, as illustrated in [Fig. 1], the method can be implemented for a plurality of local computers 1000a, 1000b, 1000c, each connected to an enclosure 2000a, 2000b, 2000c. This is particularly relevant when several employees of the same company work remotely and all need to be connected to the company's intranet. It is understood that the characteristics described below for a local computer and an enclosure apply mutatis mutandis to each of these different local computers 1000a, 1000b, 1000c and enclosures 2000a, 2000b, 2000c, respectively.

[0045] Local computer architecture 1000

[0046] The local computer 1000 includes in particular a local processor 1600 and advantageously a local memory 1500.

[0047] Advantageously, the local computer 1000 is connected to peripherals such as a display, keyboard, mouse, speakers, microphone, and printer. These various resources can be used when running the mobile operating system on the local computer 1000. Therefore, the enclosure 2000 does not need to include these same resources, making the enclosure 2000 easily portable and user-friendly. This also eliminates the need for a second set of peripherals.

[0048] Case architecture 2000

[0049] Fig. 2 is a schematic representation of the architecture of the 2000 case. As illustrated, the 2000 case includes an internal 2010 operating system and an external 2020 operating system.

[0050] The internal 2010 operating system includes, in particular: i. A 2500 memory unit that can contain, depending on the steps of the process: a. Various files such as synchronized mobile files and synchronized remote files, which will be discussed further. b. A public encryption key. ii. A 2100 mobile communication module, configured to allow the sending and receiving of data. More specifically, the 2100 mobile communication module allows data to be encrypted using the public encryption key before being sent. It is also configured to decrypt, after receipt, data encrypted with the private key of Encryption using the public encryption key. The 2100 mobile communication module is specifically configured to send requests to the 3100 remote communication module and receive requests from the 3100 remote communication module, these requests generally originating from and destined for other programs on the 2000 unit and the 3000 remote computer. iii. A mobile synchronization program 2200, configured to receive synchronized remote files from the remote computer 3000 via the communication network 4000 and the mobile communication module 2100, and to send synchronized mobile files to the remote computer 3000 via the mobile communication module 2100 and the communication network 4000. This program allows the user of the 2000 device to work on files with the most recent modifications. For example, if other users of the company intranet have recently worked on files of interest accessible via the company intranet, it is important that the user of the 2000 device has a recent version of these files.By regularly receiving synchronized remote files, the 2000 device allows the user to work under optimal conditions. Similarly, it can be very important that the work done by the 2000 device user be accessible to other users of the company intranet. Sending synchronized mobile files from the 2000 device to the 3000 remote computer connected to the intranet ensures that the 2000 device user's latest progress is available to their colleagues. Furthermore, this synchronization is important so that the 2000 device user can work on a recent version—preferably the most recent version—of their files when switching between remote work on the local computer 1000 and work on-site at the company's remote computer 3000, and vice versa. iv. The core of the 2300 box, configured in particular to perform certain actions on the other programs of the 2000 box. For example, it can be configured to determine the state of other programs of the 2000 box and possibly carry out actions based on this state. v. A 2400 control program including a user interface supported by a website. This interface allows the user of the 2000 unit to administer it. It allows the 2000 unit to connect to an internet network such as a Wi-Fi network, or to view the status of the 2000 unit (connected or not to the remote computer, connected or not to the Wi-Fi...).

[0051] The external operating system 2020 is dedicated to user data, which may include, in particular, the software used by the user and the related data. This 2020 system may therefore include: i. A file access system ii. User programs / software iii. A program for accessing the 2400 control program

[0052] The external 2020 operating system can be delivered empty and software and data can then be added according to the user's needs.

[0053] The internal 2010 and external 2020 operating systems are contained in a fast storage system, for example of the SSD type (Solid-state drive), for example of 256 GB.

[0054] The 2000 package also includes a 2600 portable processor, random access memory (RAM), and storage space. The 2600 portable processor may, for example, have 4 cores and a clock speed of 1.9 GHz. The RAM may, for example, be 2 GB and the storage space 16 GB.

[0055] The 2000 case also includes a rechargeable battery on which it can operate without being connected by wired connection to the local computer 1000 or to the electrical network.

[0056] The housing advantageously includes a 2002 connection module for the 4000 communication network.

[0057] It is also possible to integrate a communication key for a wireless network such as a standard 4G and / or 5G (e.g., a 4G / 5G GSM module) into the 2000 unit so that the 2000 unit can connect to the internet without using a public network. This is particularly advantageous when the user is traveling. They then do not need to connect to networks of unknown security (e.g., public Wi-Fi networks in an airport or train station).

[0058] The remote computer 3000 with which the box 2000 allows the local computer 1000 to communicate may include, in particular: i. A main program 3300 including a database. This database includes, in particular: a. Information about the users of the 2000a, 2000b, 2000c device(s) enabling communication with the remote computer 3000, b. Information about file sharing permissions stored on the remote computer 3000, c. Information on access permissions for the administration and management of the solution, d. Any information relating to the proper functioning of the process according to the invention. ii. A remote communication module 3100, configured to send and receive data. Specifically, the remote communication module 3100 encrypts data using the private encryption key before sending it. It is also configured to decrypt, after receipt, data encrypted at the mobile communication module 2100 with the public encryption key using the private encryption key. The remote communication module 3100 is configured to send requests to the mobile communication module 2100 and receive requests from the mobile communication module 2100, these requests typically originating from and destined for other programs on the remote computer 3000 and the 2000 unit. iii. A remote synchronization program 3200, configured to receive synchronized mobile files from the 2000 box via the 4000 communication network and the 3100 remote communication module, and to send synchronized remote files to the 2000 box via the 3100 remote communication module and the 4000 communication network. iv. A 3400 sharing program configured to manage file sharing permissions for files stored on the remote computer 3000. Specifically, the 3400 sharing program is configured to receive sharing requests and, based on the content of these requests, modify the sharing permissions information for files stored on the remote computer 3000. These sharing requests can cause a user (i.e., a 2000a, 2000b, or 2000c device) to gain access to certain files, or conversely, to lose access. The sharing requests typically originate from the main 3300 program on the remote computer 3000. v. A control program 3500, including a manager interface supported by a website accessible from the company's intranet. This interface allows the manager to administer the solution by sending requests, such as sharing requests. It also allows the manager to access information about the 2000a, 2000b, and 2000c units communicating with the remote computer 3000. The control program 3500 communicates, among other things, with the main program 3300. vi. A 3700 memory that can notably contain a first private encryption key.

[0059] It is understood that the local computer 1000, the box 2000 and the remote computer 3000 may include other programs, modules and interfaces.

[0060] Initialization phase

[0061] During an initialization phase, a mobile operating system is stored in a memory 2500 of the box 2000. This mobile operating system includes among other things a public encryption key used for the secure exchange of data between the box 2000 and the remote computer 3000.

[0062] During this same initialization phase, the 2000 box is connected to the local computer 1000. The connection between the 2000 box and the local computer 1000 is preferably made by wired connection, between a port 2001 of the 2000 box and a port 1001 of the local computer 1000. However, it is also possible for this connection to be made wirelessly, for example by Bluetooth®.

[0063] It is advantageously provided that, during the installation phase, the 2000 box is assigned to the remote computer 3000. This assignment or association is typically done using a program executed on the remote computer 3000, called the association program for the 2000 box to the remote computer 3000. The association program notably allows the remote computer 3000 to send the public encryption key to the 2000 box and store it in the operating system of the 2000 box.

[0064] Assigning the 2000 box to the remote computer 3000 can be done according to the protocol described below with reference to [Fig.3].

[0065] Block 301 illustrates the initial situation at the beginning of this protocol: the 2000 device is not yet associated with the remote computer 3000. As illustrated by block 302, a user or manager checks whether the association program is installed on the remote computer 3000. If not, they download and install it (block 303). If it is installed, the manager runs the program (block 304) on the remote computer 3000.

[0066] The execution of the association program causes the steps illustrated by blocks 305 to 317.

[0067] An association request is sent by the association program to the remote computer 3000 (block 305). At this stage, a user identifier for the device 2000 is stored in the memory 3700 of the remote computer 3000.

[0068] The association program then sends a request to the core of the 2300 unit to retrieve a serial number for the 2000 unit (block 306). Upon receiving this request, the core of the 2300 unit executes a command to obtain this serial number (block 307). The serial number is then sent to the association program (blocks 308 and 309). This same program then assigns the 2000 unit and its user via the user ID and the serial number. serial number of the newly obtained case 2000 (block 310). Typically, the serial number of case 2000 is saved in memory 3700 of remote computer 3000 by associating it with the user ID (block 311).

[0069] The main program 3300 then creates an asymmetric encryption key dedicated to communication between the remote computer 3000 and the device 2000 for which the protocol is implemented (block 312). This asymmetric encryption key comprises a private encryption key, stored in the memory 3700 of the remote computer 3000, and a public encryption key. The latter is sent to the association program (blocks 313 and 314).

[0070] As illustrated in blocks 315 and 316, the public key is then sent to the core of the 2300 device where it is stored. The 2000 device is then operational and the execution of the association program can cease (block 317). As a security measure, the sending of the public key from the remote computer 3000 to the 2000 device is conditional upon the execution of the association program. This ensures that the public key will not be disclosed to any entity other than the 2000 device, particularly a malicious entity seeking to hack the system. The exchange of information between the 2000 device and the remote computer 3000 can thus be carried out securely.

[0071] It is understood that the manager implementing the protocol for assigning the device 2000 to the remote computer 3000 is not necessarily the user using the local computer 1000 to work remotely via the device. The assignment of the device 2000 may, for example, be carried out upstream by a dedicated department within the company to which the manager belongs. The manager typically has special rights to administer the solution, for example, to be able to send requests to the various programs and modules of the remote computer 3000.

[0072] It is also advantageous to implement a security protocol during the initialization phase. Such a protocol ensures that communication from each of the different programs on the remote computer 3000 to the main program 3300 is secure. An example of such a protocol is shown in [Fig. 4A].

[0073] Once the programs on remote computer 3000 are installed (block 401), groups are created (block 402). These groups are used to manage the rights of each program before assigning them an asymmetric key. Creating these groups allows for program identification and control of their permissions. The purpose of these groups is to prevent a program from initiating a request that should originate from another program.

[0074] An identifier and a pair of encryption keys (private and public) are then created for each of the programs (block 403). The identifier and the pair of encryption keys are, for each program, stored in a secure file called Identification file. The files for each program are stored in the relevant program (block 405). The programs are thus able to exchange data securely with the main program 3300 (block 406).

[0075] An example of a secure communication protocol between a program on the remote computer 3000 and the main program 3300 is illustrated in [Fig.4B].

[0076] When a request is to be sent from a program on the remote computer 3000 to the main program 3300 (block 451), this program reads the associated saved identification file (block 452) to find out the identifier and the encryption key, adds the identifier to the head of the request (block 453), uses the encryption key to encrypt the request (block 454) and then sends the encrypted request to the main program 3300 (blocks 455 and 456).

[0077] Housing usage phase 2000

[0078] Once the 2000 box is associated with a remote computer 3000, it can be used by connecting it to a local computer 1000.

[0079] In order for the mobile operating system to be executed on the local computer 1000, it must take precedence over the usual operating system(s) of the local computer 1000. For this purpose, it is advantageously provided that the process includes a step of executing a script configured in particular to modify the order of execution of the operating systems accessible from the local computer 1000.

[0080] Process of launching the 2000 case on the local computer 1000

[0081] Fig. 5 illustrates a series of steps enabling local computer 1000 to run under the local computer 1000 operating system through this script.

[0082] Block 501 illustrates the initial situation: Local computer 1000 is not configured to boot under the nomadic operating system, and by default runs under another operating system.

[0083] The script allowing modification of the operating systems available from local computer 1000 and their order of execution can then be downloaded and executed by the user (blocks 502 and 503).

[0084] If the mobile operating system is not yet listed as a possible operating system for local computer 1000, the script can add it (block 504).

[0085] The script then modifies the execution order of the operating systems available from local computer 1000 and places the mobile operating system in the first position so that it is executed by default when local computer 1000 starts up (block 505). Local computer 1000 is then configured for use with the 2000 enclosure.

[0086] Next, a shutdown and then startup step is planned for the local computer 1000. The latter is then launched under the mobile operating system.

[0087] The 2000 device can then be used to communicate with the remote computer 3000 from the local computer 1000. An example of a communication protocol between the local computer 1000 and the remote computer 3000 will now be described. This protocol is preferably used to exchange synchronized files between the 2000 device and the remote computer 3000. It is understood, however, that this protocol can be used to exchange any type of data.

[0088] Secure data exchange process between the 2100 mobile communication module and the 3100 remote communication module

[0089] Figure 6 illustrates an example of a communication protocol between the 2000 unit and the remote computer 3000 via their respective communication modules 2100 and 3100. More precisely, it shows an example of sending a request from the 2000 unit to the remote computer 3000 and sending a response to this request from the remote computer 3000 to the 2000 unit.

[0090] As illustrated in block 601, the protocol can begin with the reception by the 2100 mobile communication module of a request to send data. This could, for example, be a "TCP" ("Transmission Control Protocol") request in JSON ("JavaScript Object Notation") format. The reception by the 2100 mobile communication module of this request to send data triggers the steps illustrated in blocks 602 to 610.

[0091] As illustrated in block 602, the request is encrypted by the mobile communication module 2100 using the public encryption key. Once encrypted, it is sent to the remote communication module 3100 via the communication network 400 (block 603). The remote communication module 3100 then decrypts the request using the private encryption key (block 604).

[0092] Typically, the request transferred from the mobile communication module 2100 to the remote communication module 3100 contains information about the program(s) on the remote computer 3000 to which the data should be transferred. Based on this information, the remote communication module 3100 sends the request to the appropriate program(s) (block 605).

[0093] As illustrated in block 606, the program(s) to which the request was sent process it. Once this processing is complete, a response is sent from the program(s) to the remote communication module 3100.

[0094] After receiving the response, the remote communication module 3100 encrypts the response using the public encryption key (block 607). The response is then sent to the mobile communication module via the communication network 4000 (block 608). Upon receiving the encrypted response, the mobile communication module 2100 decrypts it using the public encryption key (block 609). Finally, the mobile communication module 2100 transmits the decrypted response to the appropriate program (block 610), typically the one from which the request was initially issued.

[0095] The invention is not limited to the embodiments previously described and extends to all embodiments covered by the invention.

Claims

Demands

1. A method for communicating with a remote computer (3000) from a local computer (1000) using a device (2000), the local computer (1000) comprising a local processor (1600), the method comprising the following steps: • storing in a memory (2500) of the device (2000) a so-called mobile operating system comprising a public encryption key, • connecting the device (2000) to the local computer (1000), the device (2000) comprising: • a mobile communication module (2100) configured to receive encrypted data and decrypt it using the public encryption key and to send encrypted data after encrypting it using the public encryption key, • a mobile synchronization program (2200),The method further comprises: • a step of executing the local computer (1000) under the mobile operating system by accessing the local processor (1600) to the memory (2500) of the device (2000), then • during execution, sending synchronized mobile files from the local computer (1000) to the remote computer (3000) via the mobile communication module (2100) and a communication network (4000), including encryption of the data with the public encryption key, • during execution, receiving and decrypting synchronized remote files from the remote computer (3000) via the communication network (4000) and the mobile communication module (2100).

2. A method according to the preceding claim in which the housing (2000) contains a connection module (2002) for the communication network (4000).

3. A method according to any one of the preceding claims further comprising, prior to the step of running the local computer (1000) under the mobile operating system: • a step of running on the local computer (1000) a script configured to change the order of execution of the operating systems accessible from the local computer (1000) and place the mobile operating system in first position, and then • a step of shutting down the local computer (1000).

4. A method according to any one of the preceding claims further comprising, prior to the step of running the local computer (1000) under the mobile operating system, a step of running on the remote computer (3000) a program for associating the device (2000) with the remote computer (3000), this step comprising: • a recording of an identifier of the device (2000) in a memory (3700) of the remote computer (3000), • a sending of the public encryption key from the remote computer (3000) to the device (2000).

5. A method according to any one of the preceding claims wherein the connection of the enclosure (2000) to the local computer (1000) is made by a wired connection between a port (2001) of the enclosure (2000) and a port (1001) of the local computer (1000).

6. A method according to any one of the preceding claims wherein the remote computer (3000) includes a remote communication module (3100) configured to receive encrypted data and decrypt it using the private encryption key and to send encrypted data using the private encryption key.

7. A method according to any one of the preceding claims, wherein the remote computer (3000) comprises a memory (3700) containing: • user information, • file sharing permission information stored in the remote computer (3000).

8. A method according to any one of the preceding claims wherein the remote computer (3000) includes a sharing program (3400) configured to receive sharing requests and, in response to these sharing requests, to modify the sharing permission information for files stored in the remote computer (3000).

9. A method according to any one of the preceding claims wherein the remote computer (3000) is shared between several boxes (2000a, 2000b, 2000c), the remote computer (3000) supporting a plurality of directories, each directory being assigned to at least one box (2000a, 2000b, 2000c), the sharing permission information determining the content of which directory(ies) can be accessed by which box(es) (2000a, 2000b, 2000c).

10. A method according to any one of the preceding claims wherein the remote computer (3000) includes a remote synchronization program (3200) configured to receive synchronized mobile files from the box (2000) via the communication network (4000) and the remote communication module (3100), and to send synchronized remote files to the box (2000) via the remote communication module (3100) and the communication network (4000).

11. A method according to the preceding claim in which the sending of remote files synchronized by the remote synchronization program (3200) takes place following the reception by the remote communication module (3100) of a synchronization request from the mobile synchronization program (2200).

12. A method according to the preceding claim in which the nomadic synchronization program (2200) sends synchronization requests periodically.

13. A system comprising a housing (2000) and a computer program product, the housing (2000) being connectable to a local computer (1000), the housing (2000) comprising: • a memory (2500) containing a so-called mobile operating system including a public encryption key, • a mobile communication module (2100) configured to to receive encrypted data and decrypt it using the public encryption key, and to send encrypted data after encrypting it using the public encryption key, • a mobile synchronization program (2200), The computer program product includes instructions configured for: • provide the local processor (1600) of the local computer (100) with access to the memory (2500) of the enclosure (2000) and cause the local computer (1000) to run under the mobile operating system, then • trigger, during execution, the transmission of synchronized mobile files from the local computer (1000) to the remote computer (3000) via the mobile communication module (2100) and a communication network (4000), including data encryption with the public encryption key, • trigger, during execution, the reception and decryption of synchronized remote files from the remote computer (3000) via the communication network (4000) and the mobile communication module (2100).