Method for controlling access of a user of a blockchain to a computer server linked to said blockchain
The method addresses the challenge of controlling user access to computer servers linked to a blockchain by utilizing a digital safe service on the blockchain, ensuring secure and personalized access through encryption and decryption of identity data.
Patent Information
- Application Number
- FR2023014229
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-14
- Publication Date
- 2025-06-20
AI Technical Summary
Existing methods for controlling user access to computer servers linked to a blockchain lack simplicity and reliability, particularly in ensuring secure and personalized access according to user-defined methods.
A method utilizing a blockchain to control user access to a computer server by registering users through a digital safe service, where users encrypt identity data with a public key and the access gatekeeper decrypts it using a private key, allowing secure and personalized access.
The method provides a simple and reliable means of controlling user access, ensuring secure and personalized access to computer servers linked to a blockchain, thereby enhancing security and reducing risks associated with conventional access management.
Abstract
Description
Title of the invention: Method for controlling access of a user of a blockchain to a computer server linked to said blockchain
[0001] The invention relates to a method for controlling access of a user of a blockchain to a computer server linked to said blockchain, as well as an architecture comprising means for enabling the implementation of such a method.
[0002] It applies in particular to user access to online computer servers, in particular connected to a local network of the LAN type (for the English "Local Access Network"), or to a wide area network of the Internet type, to which said users access by entering a numerical address in a search bar displayed on a page of an online browser.
[0003] Such servers may in particular provide a computer portal for an organization, for example a company or an association, to which the members of said organization can connect to work and / or communicate with other members, in particular by internal instant messaging, or by participating in work meetings organized remotely via said portal.
[0004] Given the confidentiality required for this type of server, a user wishing to access it can create a personal account on the computer portal of such a server, and subsequently connect to it by entering a personal identifier and a password, in order to secure the confidential information and assets of said user managed by said online service.
[0005] In order to access a secure computer server, it is known to provide an electronic form in which the user must enter a connection identifier (for the English "login") and a secure authentication factor, for example a password. Additional identity information may be entered, such as for example the user's first and last names, their postal address, or even, in the context of a computer server used by members of an organization, the role and / or professional position occupied by said user within said organization.
[0006] Computer servers are also known whose access is regulated by means of authentication procedures between an identifying subject, i.e. the entity which accesses a counterpart (server, human trader, service, etc.), and an authenticating subject, i.e. the entity responsible for verifying that the identity provided by the identifying subject belongs to it, such procedures being based on at least one of the following types of authenticator: - an authenticator that is structurally attached to an identifier, for example a pair of mathematically linked cryptographic keys (the private key being the authenticator and the public key the identifier); and / or - an authenticator for which a secure link must be created with the identifier, for example a password which must be entered to be linked to a connection identifier for an online service (for the English “login”).
[0007] The invention aims to improve the prior art by proposing in particular a method which, by means of a blockchain, makes it possible to control a user's access to a computer server linked to said blockchain in a simple and reliable manner, in particular according to access methods specifically defined for said user.
[0008] To this end, according to a first aspect, the invention proposes a method for controlling the access of a user of a blockchain to a computer server linked to said blockchain, said method providing a prior procedure for registering the user, which provides: - the communication to said user, by a gatekeeper managing access to said computer server on the blockchain, of a notification comprising the digital address on said blockchain of a digital safe assigned to said gatekeeper for managing access to said computer server; - the reading by said user of a digital address of the access gatekeeper on the blockchain and of a public key linked to a terminal of said access gatekeeper on the blockchain by interaction with said notification; - the sending by the user to the digital access safe of a registration request to access the computer server, said request comprising identity data of said user encrypted by means of the public key linked to the terminal of said access gatekeeper; - the decryption by the access gatekeeper of the identity data of said user sent to the digital safe, by means of a private key of said access gatekeeper associated with the public key used to encrypt said identity data; - registration by the access gatekeeper in the digital access management safe of methods to allow the user access to the computer server, associated with a public key linked to a user terminal on the blockchain;
[0009] said method further providing, when the user subsequently wishes to access the computer server, a procedure for connecting said user to said computer server, which provides: - the sending by the user of a request for access to said computer server, said request containing respective digital addresses of said user and the digital access management safe, as well as connection data signed with a private key linked to the terminal of said user; - authentication of the user by means of his digital address and the signed data contained in said access request; - reading the terms of access to the computer server entered for said user in the digital access management safe; - the display, on a terminal intended for the user, of a computer page for accessing the computer server, said page being adapted to said access methods.
[0010] According to a second aspect, the invention proposes an architecture comprising a blockchain and a computer server linked to said blockchain, said architecture further comprising: - a platform for providing a digital safe service, said platform comprising means for enabling the creation of a digital access management safe to enable a doorman to manage user access to said computer server on said blockchain; - a management terminal comprising means for enabling the access manager to communicate to a user a notification comprising the digital address on said blockchain of a digital safe created by the platform and allocated to said access manager for managing access to said computer server; - an access terminal comprising means to enable a user to: • read a digital address of the access gatekeeper on the blockchain and a public key linked to the management terminal of said access gatekeeper on the blockchain, by interacting with said notification; • send to the digital access management safe a registration request to access the computer server, said request including identity data of said user encrypted using the public key linked to the management terminal;
[0011] said management terminal further comprising means for enabling the access gatekeeper to: - decrypt the identity data of said user sent to the digital access management safe, using a private key of said management terminal associated with the public key used to encrypt said identity data; - enter, in the digital access management safe, terms and conditions to allow the user access to the computer server, associated with a key public linked to the user's access terminal on the blockchain;
[0012] said access terminal further comprising means for, when the user wishes to subsequently access the computer server, allowing said user to send an access request to said computer server, said request containing respective digital addresses of said user and of the digital access management safe, as well as connection data signed with a private key linked to said access terminal, said architecture further comprising means for allowing: - authentication of the user by means of his digital address and the signed data contained in said access request; - reading the terms of access to the computer server entered for said user in the digital access management safe;
[0013] the computer server comprising means for displaying, on a terminal intended for the user, a computer page for accessing said computer server, said page being adapted to said access methods.
[0014] Other features and advantages of the invention will appear in the following description, given with reference to the appended figures, in which:
[0015] [Fig-1] represents the steps of creation on the blockchain, by an administrator gatekeeper, of a digital safe for managing access to a computer server linked to the blockchain and / or administration of the gatekeepers managing said access, within the framework of a method according to the invention;
[0016] [Fig.2a] represents steps of communication to the user, by a ges porter access manager to the computer server, a notification including the digital address of the digital access management safe assigned to said doorman, according to an alternative embodiment of the invention;
[0017] [Fig.2b] represents the steps of a preliminary user registration procedure on the blockchain to be able to access a computer server linked to said blockchain, according to a first embodiment of the invention;
[0018] [Fig.3] represents the steps of a subsequent procedure for connecting the user to the computer server, after having followed the registration procedure represented in [Fig.2b], according to the first embodiment of the invention;
[0019] [Fig.4] represents a preliminary step of making contact with a managing gatekeeper access to a computer server with an administrator gatekeeper on the blockchain, in order to be accredited by said administrator gatekeeper, according to a second embodiment of the invention;
[0020] [Fig.5] represents the hierarchical organization of the administration and access management safes to the computer server, according to the embodiment of [Fig.4];
[0021] [Fig.6] represents the steps of accreditation by an administrator gatekeeper of a gatekeeper managing access to the computer server, according to the embodiment of the figures 4 and 5;
[0022] [Fig.7] represents the steps of a preliminary user registration procedure on the blockchain to be able to access a computer server linked to said blockchain, according to the embodiment of figures 4 to 6;
[0023] [Fig.8] represents the steps of a subsequent user login procedure to the computer server, after following the registration procedure shown in [Fig.7], according to the second embodiment of the invention.
[0024] In relation to these figures, a method is described below for controlling the access of a user 1 of a blockchain to a computer server 2 linked to said blockchain, as well as an architecture comprising technical means adapted for the implementation of such a method.
[0025] The method provides in advance for the creation for the user 1 of a pair of private keys 3a and public keys 3b. This pair of keys 3a, 3b allows the user 1 to access a blockchain, but also to electronically sign computer data, in particular in the context of a transaction on said blockchain. In particular, the user 1 only discloses the public key 3b, and keeps the private key 3a strictly confidential.
[0026] To do this, the architecture comprises a blockchain and a terminal 4 for accessing said blockchain, this terminal 4 comprising means for creating such a pair of keys 3a, 3b for the user 1.
[0027] As shown in the figures, the access terminal 4 may be a mobile phone of the “smartphone” type. The access terminal 4 may also be of another type, provided that it is equipped with suitable means for implementing the method, in particular a digital tablet, a personal digital assistant (PDA), a laptop, a desktop computer or any other connected object.
[0028] In particular, the architecture may comprise an application with means adapted for implementing the method, which the user 1 can download to install it on his terminal 4, in particular by sending a request adapted to said architecture.
[0029] The method then provides for the creation of a digital safe 5 for the user 1 on the blockchain, then the recording in said safe of at least one public key 3b for access to said blockchain linked to a terminal 4 of said user.
[0030] To do this, the blockchain comprises a platform 6 for providing a digital safe service, which comprises means for enabling the creation of a digital safe 5 for the user 1 on said blockchain. These means may for example be in the form of a programming interface (API, for the English “Application Programming Interface”), said interface being adapted to allow the manual creation of safes 5 by a blockchain administrator and / or automatic creation of such a safe 5 at the request of the user 1.
[0031] Furthermore, the access terminal 4 or the application installed therein comprises means for recording in such a safe 5 at least one public key 3b for access to the block chain linked to it.
[0032] The digital safe 5 can in particular be created in the form of a computer protocol of the smart contract type, said smart contract being accessible by means of a public digital address 7.
[0033] During the creation of the digital safe 5, the method provides for the identification and authentication of the user 1 with a third-party identification platform (not shown), then the creation of a digital fingerprint for said user by means of identity data of said user provided by said identification platform, said digital fingerprint being recorded in said digital safe.
[0034] To do this, the architecture comprises such a third-party identification platform, with which the user 1 identifies and authenticates himself beforehand, the platform 6 for creating safes comprising means for creating the digital fingerprint of said user by means of identity data provided by said identification platform.
[0035] The third-party platform may comply with the elDAS (Electronic IDentification And Trust Services) regulation, and may be, for example, a platform for providing a public and / or administrative identification service such as social security, a service for the payment of official taxes such as income taxes, or any other identification service enabling a required elDAS trust level to be achieved, or equivalent. In particular, the third-party platform may be a corporate identification and authentication system having a structure and operation equivalent to the elDAS regulation.
[0036] After downloading the application onto his terminal 4, and if he does not already have one, the user 1 can launch a suitable procedure on said terminal, in particular by means of said application, to create a pair of keys 3a, 3b as described previously. These keys 3a, 3b are thus linked to the terminal 4 of the user 1, which only discloses the public key 3b to interact with the blockchain. As a result, the private key 3a never leaves the terminal 4, which guarantees the user 1 optimal security.
[0037] The terminal or application then sends a request containing the public key 3b to the safe creation platform 6, which in turn sends a notification to the third-party platform to request a user identification procedure, at the end from which the third-party platform communicates an indicator of validity of the identity of said user, as well as an authorization to access the identity data of said user, or the identity data itself. The safe platform then obtains the identity data of the user to calculate a digital fingerprint for user 1 from said identity data.
[0038] The safe platform 6 further comprises: - means for recording the digital fingerprint and the public key 3b in the digital safe 5 of the user 1, in particular by sending a notification adapted to said safe; and - means for communicating to said user the digital address 7 of said safe, in particular by means of a notification sent to his terminal 4.
[0039] The safe platform 6 can in particular be identified on the blockchain by an account whose identifier is a digital address of the EOA type (for the English “External Owner Account”), which it accesses by means of a pair of keys linked together by mathematical functions, among which a private key 8a, which must remain secret, and therefore never leave said platform, as well as a public key 8b, from which its digital address is derivable.
[0040] Advantageously, as shown in Figures 1 and 2a, the safe platform 6 can create and deploy digital safes 5 on the blockchain by means of a special safe 9 which is allocated to it on said blockchain, and in which the public key 8b for identifying said platform on said blockchain is recorded.
[0041] In particular, to request the creation of a safe 5, the user 1 can, in order to access the platform 6, perform a preliminary reading, by means of his terminal 4 or the application, of the digital address 10 of the safe 9 linked to said platform on the blockchain, in order to trigger the sending of the request containing the public key 3b of said terminal. The digital address 10 can in particular be pre-recorded in a database, or any other storage means, linked to the application, in order to be downloaded to said terminal at the same time as said application when the user 1 interacts with the platform 6 to install this application on said terminal.
[0042] After receiving the notification containing the digital address 7, the terminal 4 or the application initiates a procedure for activating the safe 5, and sends to the platform 6 a request for certification of said safe. In response, the platform 6 sends a notification to access the safe 5 by reading its digital address 7 then, if this reading is successful, records this digital address 7 in a single central safe 11 of reference of the blockchain, in which all the digital addresses of the safes created for other users are recorded on said blockchain, said addresses each being associated with the digital address 10 of the safe 9 identifying the platform 6 having created said safes.
[0043] At the end of these steps, the user 1 holds a safe 5 allowing him to access, as a registered user, the blockchain and / or computer servers linked to said blockchain, in particular a computer server 2 as shown in FIGS. 2b to 8, integrating functionalities accessible via said blockchain, and this by means of any terminal 4 whose public key 3b is recorded in said safe.
[0044] In particular, even in the event of loss of an old private key mathematically linked to a public key, and linked or not to an old terminal for accessing the blockchain, the user 1 keeps his assets on the blockchain thanks to the safe 5, subject to recording there a new public key 3b generated on his new terminal 4.
[0045] The architecture therefore comprises a computer server 2, which the user 1 can access by entering on a terminal 12 an electronic address for accessing said online service, for example in the form of a URL (Uniform Resource Locator) type address.
[0046] In particular, the user 1 may hold a personal account on the server 2, and the connection terminal 12 comprises means for allowing the user 1 to initiate a connection session to said server via said personal account.
[0047] In Figures 2b and 8, the terminal 12 for connection to the server 2 is shown as distinct from the terminal 4 for access of the user 1 to the blockchain, and is in the form of a laptop. This connection terminal 12 may in particular be a public computer, for example made available to visitors to a public place such as an internet cafe, or any other means of online access, and in particular comprises means for allowing the user 1 to connect to the server 2 via a browser.
[0048] Alternatively, the connection terminal 12 and the access terminal 4 are combined, the user 1 then using the same terminal 4 to access the blockchain and connect to his personal account on the server 2, via a browser or a programming interface installed on the terminal 4.
[0049] A terminal 12 for public use does not guarantee the user 1 optimal security when connecting to his personal account on an online service 2, and there is in particular a significant risk of theft of the connection identifiers (for the English "login") and authentication (password) of said user when he enters them on such a terminal 12.
[0050] In the case of a server 2 used for professional purposes, in particular by an or organization or a business, such a risk is also accompanied by a risk of theft of confidential information related to the activities of said organization / business, which can have a serious deleterious effect on said activities. Furthermore, conventional access management does not allow for satisfactory guarantees of personalized access to the different users of server 2, in particular according to their hierarchical position and / or their function within the organization / business.
[0051] To overcome these drawbacks, the method proposes to control the access of a user 1 to the computer server 2 with alternative means to conventional connection and authentication identifiers, in order to avoid their theft, to avoid the user 1 having to write them down so as not to forget them, and thus to guarantee the protection of the access data of said user, but also of the data available on the computer server 2.
[0052] To do this, the method provides a preliminary procedure for registering the user 1, this procedure firstly providing for the communication to said user, by a gatekeeper 14 managing access to the computer server 2, of a notification 15 comprising the digital address 16 on the block chain of a digital safe 17 allocated to said gatekeeper manager for managing access to said server.
[0053] The gatekeeper 14 may be an employee of the organization / company operating the computer server 2, and has, to connect to the blockchain, a terminal 13, in particular a portable terminal of the “smartphone” type, on which he can create private 18a and public 18b keys for access to said blockchain, as explained previously for the user 1. Similarly, the gatekeeper 14 may have a personal digital safe 19 on the blockchain, which he can create by interacting with the platform 6 as developed previously, and record there the public key 18b linked to his terminal 13.
[0054] In relation to [Fig. 1], the platform 6 also comprises means for enabling the creation of a digital safe 17 as described previously, in order to enable a gatekeeper 14 to manage access to the server 2 of users 1 on the blockchain.
[0055] In particular, the gatekeeper 14 can himself request the platform 6 to create such a safe 17. To do this, the gatekeeper 14 sends to the platform 6, via his terminal 13 (or an application installed thereon for this purpose), a request 20 containing the public key 18b of his terminal 13 and the digital address 21 of his personal safe 19 on the blockchain.
[0056] In response to this request 20, the platform 6 successively consults: - the personal safe 19, to verify the recording of the public key 18b communicated in said request; - the central safe 11, to check the referencing of said safe staff.
[0057] If these checks are successful, platform 6: - creates a digital management safe 17 on the blockchain, by recording therein the digital address 21 of the personal safe 19 of the doorman 14, as a parent address for said management safe; - communicates to terminal 13 a notification 22 containing the digital address 16 of said management safe.
[0058] The gatekeeper 14 then launches a procedure 23 for activating the management safe 17, by entering a specific activation code in said safe, using the digital address 21 of its personal safe 19, then by sending an activation request 24 to the platform 6. The platform 6 verifies the presence of a correct activation code in the safe 17 then, if so, certifies the safe 17 by entering its digital address 16 in the central safe 11, before sending a notification 25 to the terminal 4 to confirm said certification.
[0059] The safe 17 contains alphanumeric data which define its operation and its allocation to a given doorman 14, including a digital access address to a given computer server 2, for example of the URL type (for the English “Uniform Resource Locator”).
[0060] It is important that this digital address cannot be modified, in order to limit the association of the safe 17 to a single server 2. Thus, to the extent that the different connection operations to the server 2 are transparent to the user 1, the traceability of this connection is guaranteed to said user. Therefore, to manage the access of users 1 to another computer server, it is appropriate to create another safe.
[0061] The access management terminal 13 (or the application installed therein) comprises means for enabling the access gatekeeper 14, during the prior registration procedure, to communicate to the user 1 a notification 15 comprising the digital address 16 of the access management safe 17 assigned to said access gatekeeper.
[0062] Similarly, the terminal 4 comprises means for allowing, by interaction with the notification 15, the reading by the user 1 of the digital address 21 of the personal safe 19 of the access gatekeeper 14, as well as of a public key 18b linked to the terminal 13 of said access gatekeeper on the blockchain.
[0063] In the embodiments shown, the access management terminal 13 comprises means for sending a notification 15 comprising an interactive link 26 integrating the digital address 16 of the access management safe 17 assigned to the gatekeeper 14 on the blockchain, as well as possibly the public key 18b associated with the terminal 13 of said gatekeeper, the terminal 4 of the user 1 comprising means to interact with said link to read the digital address 21 and the public key 18b.
[0064] In [Fig.2b], terminal 4 of user 1 successively sends: - a request 27 to the access management safe 17, by interaction with the link 26, to read the digital address 21 of the personal safe 19 of the doorman 14;
[0065]
[0066] - a request 28 to the personal safe 19 of said doorman, by means of its digital address 21, to read the public key 18b linked to the management terminal 13 of said doorman. In [Fig.2a], the interactive link 26 integrates both the digital address 21 of the personal safe 19 of the doorman 14 and the public key 18b linked to the terminal 13 of said doorman. Thus, by a single interaction with the link 26, the terminal 4 of the user 1 sends: - a request 29 to the central server 11 to verify the validity of the access management safe 17; - a request 30 to the access management safe 17 to read the digital address of the personal safe 19 of the doorman 14; - a request 31 to the personal safe 19 to verify the concordance between the public key 18b recorded in said personal safe and the public key 18b integrated in the interactive link 26. At the end of these operations, if the results of the requests 29, 31 confirm the validity of the safe 17, its allocation to the gatekeeper 14 and the validity of the link 26, the terminal 4 can locally record the digital address 16 of the safe 17, for example in a database linked to the application installed on said terminal, in order to facilitate subsequent access to said safe 17.
[0067] In relation to [Fig.2b], to complete the registration procedure of user 1, the method provides: - sending by the user 1 to the safe 17, by means of his terminal 4 (or the application installed there), of a registration request 32 to access the server 2, said request comprising identity data of said user encrypted by means of the public key 18b linked to the terminal 13 of the access gatekeeper 14; - decryption by the access gatekeeper 14, in particular by launching a suitable procedure 33 on its terminal 13 (or the application installed there) of the identity data sent to the safe 17, and this by means of the private key 18a of the access management terminal 13 associated with the public key 18b used for the encryption of said identity data.
[0068] The identity data may in particular comprise the digital address 7 of the personal safe 5 of the user 1 on the blockchain, as well as a digital identity fingerprint of said user as recorded in said safe. personal. As shown in [Fig.2b], the access gatekeeper 14 can then verify the identity of the user 1 from the decrypted data, by sending suitable requests 34a, 34b to the central safe 11 and to the personal safe 5 of said user.
[0069] To finalize the procedure, the method then provides for the registration, in the access management safe 17 by the access gatekeeper 14, of modalities to allow access by the user 1 to the server 2, associated with the public key 3b linked to the terminal 4 of said user. To do this, the access gatekeeper 14 launches on its terminal 13 (or the application installed there) a procedure 63 adapted to carry out this registration.
[0070] The access conditions granted to a user 1 for the server 2 are presented in the form of a list of time-stamped alphanumeric data recorded in the safe 17, thus allowing the doorman 14 to have a history of the different conditions granted to said user.
[0071] Optionally, the method may also provide for recording a digital access address to the server 2, for example a URL type address, in the access management safe 17, by encrypting it with the public key 3b linked to the terminal of the user 1, as a method of accessing said user to said server. Thus, during a subsequent procedure for connecting the user 1 to the server 2, this digital address may also be used to verify that the user 1 does indeed have authorization to access said server.
[0072] To do this, the terminal 13 of the doorman 14 can in particular send a request 35 adapted to read the public key 3b in the personal safe 5 of the user 1, in parallel with the verification of the identity of said user, in order to be able to use said public key to encrypt and record the digital access address to the server 2 in the access management safe 17.
[0073] In relation to figures 3 and 8, the method further provides, when the user 1 registered in the safe 17 subsequently wishes to access the computer server 2, a procedure for connecting said user to said server.
[0074] This connection procedure firstly provides, using appropriate means of his terminal 4 (or the application installed there), the sending by the user 1 of a request 36 for access to the computer server 2, which contains the digital addresses 7, 16 of his personal safe 5 and of the safe 17, as well as connection data signed with the private key 3a linked to the terminal 4 of said user.
[0075] To do this, the terminal 4 (or the application installed therein) comprises means adapted to allow the user 1 to send such an access request 36 on the blockchain.
[0076] In the embodiments shown, the architecture includes a separate authentication server 37, which includes: - means for receiving the access request 36 sent by the terminal 4; - means for authenticating user 1 by means of the digital address 7 of his personal safe 5 and the signed connection data contained in said access request; - means for reading the access terms to the computer server 2 entered for said user in the access management safe 17; - means for triggering the display, on a terminal 12 intended for the user 1, of a computer page for accessing the server 2, said page being adapted to the specific access methods for said user.
[0077] This embodiment makes it possible to centralize within a single server 37 all the operations of authenticating the user 1, reading his access methods to the server 2, as well as displaying the access page 48 adapted to said methods on a terminal 12 intended for the user 1. Thus, the technical implementation of these operations is simplified, by connecting to this same centralized authentication server 37 several computer servers 2 linked to the blockchain, and in particular servers 2 developed subsequently.
[0078] Advantageously, to improve the security of the method, and in particular of the exchanges between the computer server 2 and the authentication server 37, the digital address of the authentication server 37 can be associated with the digital address 10 of the safe 9 linked to the platform 6, in particular by joint recording of these addresses in the central safe 1, in order to allow the terminal 4 (or the application installed there) to verify the authenticity of said authentication server.
[0079] In a variant not shown, all the functionalities of the authentication server 37 can be integrated into the computer server 2.
[0080] In the embodiments shown, the user 1 first initiates a connection session to the server 2 by means of a terminal 12, in particular by sending a request 38 containing the digital address (URL) for accessing said server 2. Furthermore, the computer server 2 comprises means for communicating to the user 1 via this terminal 12 a notification 39 which comprises means for accessing the authentication server 37.
[0081] Advantageously, the notification 39 is arranged to display on the connection terminal 12 an interactive link 40 linked to the connection session initiated by the user 1, said user interacting with said link, in particular using suitable means equipping his access terminal 4, to access the authentication server 37.
[0082] After interaction with the link 40, the access terminal 4 sends to the authentication server 37 the access request 36 comprising the addresses 7, 16 and the connection data signed with the private key 3a linked to said terminal.
[0083] The connection data may include in particular: - a digital token generated by the server 2 upon receipt of the request 38, then transmitted to the terminal 4 by the authentication server 37 via the interactive link 40; - a random number generated by terminal 4, the latter containing the private key 3a mathematically linked to the public key 3b.
[0084] Thus, the method is based on the use of two random connection data renewed each time user 1 connects to his personal account on the IT service 2, and on the signing of this random data by an asymmetric cryptography system.
[0085] Advantageously, the method may require the user 1 to enter confidential data on his terminal 4 before electronically signing the connection data and sending the notification 36, for example by entering a password or a PIN code (for "Personal Identification Number") and / or by entering biometric data such as a fingerprint or facial recognition data, in order to confirm his desire to connect to his personal account on the server 2.
[0086] Thus, thanks to a two-factor authentication system, it is possible to reinforce the security and confidentiality of the connection of user 1 to server 2, which is all the more important when said server contains sensitive data such as information linked to the identity and / or a bank account of said user, or even confidential information linked to the professional activity of said user and / or the organization / company using said server.
[0087] After receiving the access request 36, the authentication server 37 successively launches, to authenticate the user: - a request 41 addressed to the personal safe 5 of user 1, using its address 7 contained in the request 36, to read the public key 3b linked to the terminal 4 having sent said access request; - a procedure 43 for decrypting the connection data using the public key 3b read in said personal safe; - a request 42 addressed to the central safe 11, to verify the referencing of the user's personal safe 5.
[0088] Then, after authentication of user 1, the server 37 sends a request 44 to the access management safe 17, using the address 16 communicated in the request 36, to read the access conditions to the server 2 entered for the user 1.
[0089] In the case where several access modalities are recorded in the safe 17 for the same user 1, the authentication server 37 is arranged to read and apply as a priority the modality presenting the most recent timestamp information. Thus, in the case where the most recent access modality for the user 1 indicates a revocation of access to the server 2, the authentication server 37 comprises means for stopping the connection procedure and transmitting an error message to the user 1, in particular by interacting with the server 2 to trigger a suitable display on the connection terminal 12.
[0090] Advantageously, the authentication server 37 also comprises means for reading the digital access address to the server 2 previously recorded in the safe 17 during the registration of the user 1, then for launching a procedure 45 adapted to decrypt said digital address by means of the public key 3b read in the personal safe 5 of the user 1, in order to validate the authorization of the user 1 to access the server 2.
[0091] At the end of these procedures, the authentication server 37 sends to the computer server 2 a notification 46 to validate the authorization of the user 1 to access said computer server, as well as to communicate to said server the access conditions of said user. Then, the server 2 sends to the connection terminal 12 a notification 47 to display there, for the user 1, a page 48 adapted to the access conditions of said user.
[0092] As shown in Figures 3 and 8, the various operations which take place between the connection terminal 12, the computer server 2 and the authentication server 37 take place in a completely transparent manner for the user 1, for whom only the sending of the requests 38, 36 and the updating of the page 48 displayed on the terminal 12 after connection to the server 2 are actually visible.
[0093] According to a first embodiment, shown in Figures 2a, 2b and 3, user 1 accesses server 2 via a single gatekeeper 14.
[0094] According to a second embodiment, represented in Figures 4 to 8, the user 1 accesses the server 2 via an access gatekeeper 14, as described previously, and a second administrator gatekeeper 49 on the blockchain, said method providing beforehand the accreditation of the access gatekeeper 14 by said administrator gatekeeper.
[0095] This second embodiment is particularly suitable for business communities using a single computer server 2, for example of the “extranet” type. Thus, each business in the community can designate at least one gatekeeper 14 from among its employees to manage access to the server 2 of its own users 1, and administrator gatekeepers 49 can be designated by each of said businesses to accredit or revoke access gatekeepers 14, or possibly even users 1.
[0096] Just like the access gatekeeper 14, the administrator gatekeeper 49 may be a human employee working for the organization / company that uses the server 2. In particular, as shown in [Fig.5], the administrator gatekeeper 49 holds on the chain of blocks a specific digital safe 50 which is assigned to it in order to be able to manage doormen 14 designated to manage the access of users 1 to the server 2, and in particular the access management safes 17, 17', 17” assigned to each of said access doormen.
[0097] Furthermore, the architecture comprises a terminal 51, in particular of the type “smartphone”, which allows the administrator doorman 49 to accredit an access doorman 14.
[0098] In a similar manner to the respective terminals 4, 13 of the user 1 and the access gatekeeper 14, the terminal 51 is a portable terminal of the “smartphone” type, in which the administrator gatekeeper 49 can create private and public keys for accessing the blockchain by interacting with the platform 6, as explained previously in connection with the terminals 4, 13.
[0099] Similarly, the administrator gatekeeper 49 holds on the blockchain a personal safe 52 accessible via a digital address, which he can create by interaction with the platform 6, then record there the public key linked to his terminal 51, as explained previously in connection with the respective personal safes 5, 19 of the user 1 and the access gatekeeper 14.
[0100] To carry out the accreditation of an access gatekeeper 14, the administrator gatekeeper 49 begins by creating an access management safe 17 for said access gatekeeper 14, following a procedure as described previously, in relation to [Fig.l]. To do this, the administration terminal 51 comprises means adapted to create this safe 17, by interaction with the platform 6.
[0101] Then, the administrator gatekeeper 49 records, by means of its terminal 51 (or the application installed there), the digital address 53 of the administration safe 50 in the digital access management safe 17 that it has just created, then communicates the digital address 16 of said management safe to the access gatekeeper 14 to which it is assigned.
[0102] To finalize the accreditation of the access gatekeeper 14, the administrator gatekeeper 49 communicates to it a notification 54 comprising an interactive link 55 for access to the administration safe 50, said access gatekeeper interacting with the link 55, using suitable means of its terminal 13, to verify the validity of said administration safe.
[0103] Advantageously, the administrator gatekeeper 49 can communicate upstream to the access gatekeeper the public key linked to his terminal 51 and the digital address of his personal safe 52 on the blockchain, then send the interactive link 55 encrypted with the private key associated with said public key.
[0104] Then, to verify the identity of the administrator gatekeeper 49, the access gatekeeper 14 successively launches on its terminal 13: - a procedure 56 for decoding the signature of the link 55, using the public key associated with the private key used for said signature; - a request 57 to the personal safe 52 of the administrator gatekeeper 49, using the digital address communicated upstream by said administrator gatekeeper, to read the public signature key of said link; - a procedure 58 for verifying the validity of said public signature key.
[0105] After successfully identifying the administrator gatekeeper 49, the access gatekeeper 14 sends to the administration safe 50 an accreditation request 59, which the administrator gatekeeper 49 then reads, launching on its terminal 51 a procedure 60 for interacting with said administration safe.
[0106] Finally, the gatekeeper successively launches two procedures 61, 62 adapted on its terminal to record, in the administration safe 50, the digital address of the digital access management safe 17 assigned to the access gatekeeper 14, as well as information on the accreditation of said access gatekeeper.
[0107] In this second embodiment, and as shown in [Fig.7], the access terminal 4 comprises means for additionally carrying out the following operations, during the registration procedure of the user 1: - reading in the access management safe 17, by means of the address 16 communicated in the notification 15, the digital address 53 of the administration safe 50, in addition to the digital address 21 of the personal safe 19 of the access doorman 14, and this by sending the same request 27' to said access management safe; - reading the digital address of the personal safe 52 of the administrator doorman 49, as well as the public key linked to the administration terminal 51, by means of the digital address 53 of the administration safe 50, and this by sending a request 64 adapted to said administration safe; - sending to the digital administration safe 50 a second registration request 65, comprising identity data of the user 1 encrypted using the public key linked to the administration terminal.
[0108] Then, to finalize the registration of user 1, the administrator gatekeeper 49 carries out, by means of its terminal 51, the following operations: - decrypting the identity data sent by user 1 to the administration safe 50, using the private key associated with the public key used to encrypt said identity data; - the registration, by means of an adapted procedure 66, of the access gatekeeper 14 as the designated manager for the access of the user 1 to the computer server 2.
[0109] Advantageously, the method may also provide for recording by the administrator doorman 49, by means of his administration terminal 51, of the digital access address to the server 2 in the administration safe 50, by encrypting it with the public key 3b linked to the access terminal 4 of the user 1, as a method of access of said user to said server.
[0110] Similarly, and as shown in [Fig.8], the authentication server 37 comprises means for additionally carrying out the following operations, during a subsequent procedure for connecting the user 1 to the computer server 2: - sending a request 44' adapted to the access management safe 17 to read there, in addition to the access conditions of the user 1 to the server 2, the digital address 53 of the administration safe 50; - sending a request 67 to the digital administration safe 50 to verify the accreditation of the access gatekeeper 14 to manage the access of user 1 to the computer server 2; - reading, using an adapted procedure 45', the digital access address to server 2 previously recorded in the administration safe 50, by decrypting it using the public key 3b linked to the terminal 4 of user 1, in order to validate the authorization of user 1 to access server 2; - if the accreditation check is successful, sending notification 46 to the computer server 2 to trigger the display of access page 48 for user 1.
Claims
Claims
1. Method for controlling the access of a user (1) of a blockchain to a computer server (2) linked to said blockchain, said method providing a prior user registration procedure, which provides: - communication to said user, by a gatekeeper (14) managing access to said computer server on the blockchain, of a notification (15) comprising the digital address (16) on said blockchain of a digital safe (17) allocated to said gatekeeper for managing access to said computer server; - reading by said user of a digital address (21) of the access gatekeeper on the blockchain and of a public key (18b) linked to a terminal (13) of said access gatekeeper on the blockchain by interaction with said notification; - sending by the user (1) to the digital safe (17) for access management of a registration request (32) to access the computer server (2), said request comprising identity data of said user encrypted by means of the public key (18b) linked to the terminal (13) of said access gatekeeper; - decryption by the access gatekeeper (14) of the identity data of said user sent to the digital safe (17), by means of a private key (18a) of said access gatekeeper associated with the public key (18b) used for the encryption of said identity data; - the registration by the access gatekeeper (14) in the digital safe (17) for access management of methods to allow access by the user (1) to the computer server (2), associated with a public key (3b) linked to a terminal (4) of the user (1) on the blockchain; said method further providing, when the user (1) wishes to subsequently access the computer server (2), a procedure for connecting said user to said computer server, which provides: - sending by the user (1) a request (36) for access to said computer server, said request containing nu addresses respective keys (7, 16) of said user and of the digital safe (17) for access management, as well as connection data signed with a private key (3a) linked to the terminal (4) of said user; - authentication of the user (1) by means of his digital address (7) and the signed data contained in said access request; - reading the terms of access to the computer server (2) entered for said user in the digital safe (17) for access management; - the display, on a terminal (12) intended for the user (1), of a computer page (48) for access to the computer server (2), said page being adapted to said access methods.
2. Method according to claim 1, characterized in that it provides beforehand the accreditation of the access gatekeeper (14) by an administrator gatekeeper (49) on the blockchain, said accreditation being carried out by: - the creation, for the access gatekeeper (14), of a digital safe (17) for managing access to the computer server (2) on the blockchain; - recording, in the digital safe (17) for access management assigned to said access gatekeeper, the digital address (53) of an administration digital safe (50) assigned to said administrator gatekeeper on the blockchain; - recording, in said digital administration safe, a digital address (16) on the blockchain of said digital access management safe assigned to said access gatekeeper.
3. Method according to claim 2, characterized in that it provides, during the prior user registration procedure (1): - the reading by said user of the digital address (53) of the digital administration safe (50) recorded in the digital access management safe (17) allocated to the access gatekeeper (14), by means of the digital address (16) communicated in the notification; - reading by said user of a digital address of the administrator gatekeeper (49) on the blockchain and of a public key linked to a terminal (51) of said administrator gatekeeper on the blockchain, by means of the digital address (53) of the administration safe (50); - sending by the user (1) to the digital administration safe (50) a second registration request (65), said second request comprising identity data of said user encrypted by means of the public key linked to the terminal (51) of said administration doorman; - decryption by the administrator gatekeeper (49) of the identity data of said user sent to the digital administration safe (50), by means of a private key linked to the terminal (51) of said administrator gatekeeper and associated with the public key used for the encryption of said identity data; - registration by the administrator gatekeeper (49), in the digital administration safe (50), of the access gatekeeper (14) as the designated manager for the access of the user (1) to the computer server (2); said method further providing, during a subsequent procedure of connection of said user to said computer server: - reading, in the digital safe (17) for access management, the digital address (53) of the digital safe (50) for administration, in addition to the access methods to the computer server (2) entered for said user; - verification, in said digital administration safe, of the accreditation of said access gatekeeper to manage said user's access to the computer server (2); the display of the page (48) for access to the computer server (2) for the user (1) being carried out in the event of success of said verification.
4. Method according to any one of claims 1 to 3, characterized in which provides, during the preliminary registration procedure, the communication by the access gatekeeper (14) to the user (1) of a notification (15) comprising an interactive link (26) integrating the digital address (16) of the digital safe (17) for access management assigned to said access gatekeeper on the blockchain, the user (1) interacting with said link to read the digital address (21) of the access gatekeeper (14) and the public key (18b) linked to the terminal (13) of said access gatekeeper.
5. Method according to any one of claims 1 to 4, characterized in that it provides for the sending by the user (1) of the request (36) for access to the computer server (2) to an authentication server (37) present on the block chain, in order to carry out the authentication of the user (1), the reading of his access conditions to the computer server (1), the possible verification of the accreditation of the access gatekeeper (14) by an administrator gatekeeper (49) on the block chain and the triggering of the display of the access page (48) adapted to said computer server by means of said authentication server.
6. Method according to claim 5, characterized in that the connection procedure provides beforehand for the initiation by the user (1) of a connection session to the computer server (2) by means of a connection terminal (12), then the communication to the user (1) via said connection terminal of a notification (39) comprising means (40) for accessing the authentication server (37).
7. Method according to any one of claims 1 to 6, characterized in that the registration procedure provides for recording a digital access address to the computer server (2) in the digital safe (17) for access management or a possible digital safe (50) for administration, by encrypting it with the public key (3b) linked to the terminal (4) of the user (1), as a method of access for said user to said computer server.
8. Architecture comprising a blockchain and a computer server (2) linked to said blockchain, said architecture further comprising: - a platform (6) for providing a digital safe service, said platform comprising means for enabling the creation of a digital safe (17) for access management to enable a gatekeeper (14) to manage user access (1) to said computer server on said blockchain; - a management terminal (13) comprising means for enabling the access manager (14) to communicate to a user (1) a notification (15) comprising the digital address (16) on said blockchain of a digital safe (17) created by the platform and allocated to said access manager for managing access to said computer server; - an access terminal (4) comprising means for enabling a user (1) to: • reading a digital address (21) of the access gatekeeper (14) on the blockchain and a public key (18b) linked to the terminal (13) for managing said access gatekeeper on the blockchain, by interaction with said notification; • send to the digital safe (17) for access management a registration request (32) to access the computer server (2), said request comprising identity data of said user encrypted by means of the public key (18b) linked to the management terminal (13); said management terminal further comprising means for enabling the access gatekeeper (14) to: - decrypting the identity data of said user sent to the digital safe (17) for access management, by means of a private key (18a) of said management terminal associated with the public key (18b) used for the encryption of said identity data; - enter, in the digital safe (17) for access management, terms and conditions for allowing access by the user (1) to the computer server (1), associated with a public key (3b) linked to the access terminal (4) of the user (1) on the blockchain; said access terminal further comprising means for, when
9. the user (1) wishes to subsequently access the computer server (2), allow said user to send a request (36) for access to said computer server, said request containing respective digital addresses (7, 16) of said user and of the digital safe (17) for access management, as well as connection data signed with a private key (3a) linked to said access terminal, said architecture further comprising means for allowing: - authentication of the user (1) by means of his digital address (7) and the signed data contained in said access request; - reading the terms of access to the computer server (2) entered for said user in the digital safe (17) for access management; the computer server (2) comprising means for displaying, on a terminal (12) intended for the user (1), a computer page (48) for accessing said computer server, said page being adapted to said access methods. Architecture according to claim 8, characterized in that it comprises an administration terminal (51) which comprises means for allowing an administrator gatekeeper (49) on the blockchain to accredit in advance a gatekeeper (14) managing access to the computer server (2) on said blockchain, said administration terminal comprising for this purpose means for allowing said administrator gatekeeper to: - create, for the access gatekeeper (14), a digital safe (17) for managing access to the computer server (2) on the blockchain, by interaction with the platform (6); - recording, in the digital safe (17) for access management assigned to said access gatekeeper, the digital address (53) of an administration digital safe (50) assigned to said administrator gatekeeper on the blockchain; - recording, in said digital administration safe, a digital address (16) on the blockchain of said digital access management safe (17) assigned to said access gatekeeper.
10. Architecture according to claim 9, characterized in that the access terminal (4) further comprises means for allowing the user (1) to: - reading the digital address (53) of the administration digital safe (50) recorded in the access management digital safe (17) assigned to the access gatekeeper (14), by means of the digital address (16) communicated in the notification (15); - reading a digital address of the administrator gatekeeper (49) on the blockchain and a public key linked to the administration terminal (51) on the blockchain, by means of the digital address (53) of the administration safe (50); - sending to the digital administration safe (50) a second registration request (65), said second request comprising identity data of said user encrypted by means of the public key linked to the administration terminal (51); said administration terminal comprising means for enabling the administrator doorman (49) to: - decrypt the identity data of said user sent to the digital administration safe (50), by means of a private key linked to said administration terminal and associated with the public key used to encrypt said identity data; - register, in the digital administration safe (50), the access gatekeeper (14) as the designated manager for the user's access (1) to the computer server (2); said architecture further comprising means for enabling, during a subsequent procedure for connecting said user to said computer server: - reading, in the digital safe (17) for access management, the digital address (53) of the digital safe (50) for administration, in addition to the access methods to the computer server (2) entered for said user; - the verification, in said digital administration safe, of the accreditation of said access gatekeeper to manage the access of said user to the computer server (2); - the display of the page (48) of access to the computer server (2) for the user (1) in the event of success of said verification.
11. Architecture according to any one of claims 8 to 10, characterized in that the access management terminal (13) comprises means for allowing the access gatekeeper (14), during the prior registration procedure, to communicate to the user (1) a notification (15) comprising an interactive link (26) integrating the digital address (16) of the digital safe (17) for access management assigned to said access gatekeeper, the access terminal (4) comprising means for allowing the user (1) to interact with said link to read the digital address (21) of the access gatekeeper (14) and the public key (18b) linked to the terminal (13) of said access gatekeeper.
12. Architecture according to any one of claims 8 to 11, characterized in that it comprises an authentication server (37) which comprises: - means for receiving the access request (36) sent by the access terminal (4); - means for authenticating the user (1) by means of his digital address (7) and the signed data contained in said access request; - means for reading the access terms to the computer server (2) entered for said user in the digital safe (17) for access management; - possibly, means for verifying the accreditation of said access gatekeeper by an administrator gatekeeper (49) on the blockchain to manage the access of said user to the computer server (2);- means for triggering the display, on a terminal (12) intended for the user (1), of a computer page (48) for access to the computer server (2), said page being adapted to said access methods.;
13. Architecture according to claim 14, characterized in that it further comprises a connection terminal (12) which comprises means for allowing the user (1) to initiate a connection session to the computer server (2), said computer server comprising means for communicating to said connection terminal a notification (39) comprising means for accessing the authentication server (37).
14. Architecture according to any one of claims 8 to 13, characterized in that the terminal (13) of the access gatekeeper (14) or a terminal (51) of a possible administrator gatekeeper (49) comprises means for recording a digital access address to the computer server (2) in the digital safe (17) for access management or a possible digital safe (50) for administration, by encrypting it with the public key (3b) linked to the terminal (4) of the user (1), as a method of access of said user to said computer server.
Citation Information
Patent Citations
Transaction method between an organization and an institution on a blockchain
FR3125622A1
Blockchain identity safe and authentication system
US20200026834A1
Cryptoasset custodial system with proof-of-stake blockchain support
US20210056547A1
Process for managing the rights and assets of a user on a blockchain
US20220343025A1