METHOD FOR SECURING THE USE OF COMPUTER EQUIPMENT
Patent Information
- Application Number
- FR2024003613
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-08
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2044-04-08
AI Technical Summary
The risk of unauthorized access and fraudulent use of computer equipment due to authentication or storage devices being left connected when users are not present poses a significant security threat, as malicious third parties can exploit these devices for unauthorized access or data fraud.
A method and system to detect connected authentication or storage devices and trigger security actions if they are used during unauthorized time ranges, including alerts and deactivation, using monitoring equipment and computer equipment to manage device usage.
Prevents unauthorized use of connected devices by triggering alerts and deactivations, thereby securing the computer equipment and reducing the risk of fraudulent access or data breaches.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: METHOD FOR SECURING USE OF COMPUTER EQUIPMENT Technical field
[0001] The field of the invention is that of computer equipment (computer, tablet, smartphone, etc.) to which one or more authentication or storage devices can be connected.
[0002] More specifically, the present invention relates to a method for securing the use of computer equipment, executed by at least one piece of equipment among the computer equipment and monitoring equipment connected to the computer equipment.
[0003] The present invention also relates to various elements which can enable, or participate in, the implementation of the method, namely a computer program product, a storage medium, computer equipment and monitoring equipment. STATE OF THE PRIOR ART
[0004] Computer equipment (also called “computer device” or “computer system”) comprises two complementary components: the hardware component and the software component.
[0005] The hardware component, also called "computer hardware", represents all the physical components of the computer system. It includes electronic devices, integrated circuits, hard drives, memories, motherboards, processors, monitors, etc. It is responsible for executing the instructions of the software component and processing data.
[0006] The software component encompasses all the programs, data, and instructions that control the operation of the computer system. It can be divided into two main categories: operating systems and applications. Operating systems, such as Windows, macOS, and Linux (registered trademarks), are software programs that manage the computer system's resources and allow users to interact with the hardware component. They are responsible for file management, memory allocation, peripheral management, and more. Applications, on the other hand, are software programs designed to perform specific tasks.
[0007] External electronic devices, called "computer peripherals" (or simply "peripherals"), are generally connected to the hardware component in order to increase the capabilities and functionality of the computer equipment. There are many types of peripherals, including peripherals input devices (e.g. keyboard, mouse, microphone, etc.), output devices (e.g. printer, speaker, display, etc.), storage devices (e.g. external hard drive, removable storage key (USB or other type), removable memory card (SD or other type), etc.) and network devices (e.g. router, modem and network adapter).
[0008] Peripherals can be connected (plugged in) to the computer equipment using wired (cabled) or wireless connections. Wired connections use ports and connectors that can be of different types (e.g., USB, HDMI, DVI, Ethernet, serial, etc.). Wireless connections use one or more wireless technologies (e.g., Bluetooth, Wi-Fi, infrared, etc.).
[0009] Another type of peripheral is also known, namely authentication peripherals, which can be connected to the computer equipment by means of wired connections (for example a connector implementing a serial bus technology (USB-A connector or USB-C connector for example) or a Lightning connector) or by means of wireless connections (for example a connector implementing a near field communication technology (NFC connector for example) or a connector implementing a short-range bidirectional data exchange technology (for example a Bluetooth connector)). Authentication peripherals can take different forms, for example: security key (also called "hardware security key" or "physical security key"), card reader (in which an authentication card can be inserted), etc.
[0010] Authentication devices are used to authenticate a user and have a security function for an organization. For example, and in a non-exhaustive manner, an authentication device can be used to authenticate its holder in order to give them rights, to secure one or more processes (such as exchanges of confidential data, access to secure platforms, taking control of an industrial process (such as an automaton for a closed network) or to carry out financial payment operations (such as bank transfers for example).
[0011] In other words, authentication devices, including hardware security keys, are a physical form of authentication (a security means for authenticating their owner) that allows a user to access systems, applications, and accounts. In particular, hardware security keys are often used as a second form of authentication (2FA) or as a multi-factor authentication (MFA) method. They are “something you have” authentication factors, as they are physical objects that the user has with them. They are easy to use because the user only needs to insert their security key into their computing device (e.g., computer). to authenticate his identity.
[0012] However, a disadvantage of authentication or storage devices is that the user may sometimes forget them and leave them connected to the computer equipment. This can happen, for example, when the user leaves his workstation in a hurry.
[0013] The fact that an authentication device remains connected to the IT equipment, while the user is no longer physically present near the IT equipment, poses a security problem. Indeed, there is then a risk that a malicious third party may use the IT equipment in an unauthorized manner, and therefore fraudulently benefit from the rights offered by the authentication provided by the authentication device that remained connected involuntarily (forgetting). The malicious third party (such as a cybercriminal) can even operate remotely if he succeeds in controlling, from his own IT equipment, the IT equipment to which the authentication device remained connected by mistake. The consequences can be dramatic for the organization that seeks to protect itself with the authentication provided by the authentication device.
[0014] The fact that a storage device remains connected to the computer equipment, while the user is no longer physically present near the computer equipment, also poses a security problem. Indeed, there is then a risk that a malicious third party could use the computer equipment in an unauthorized manner, and therefore fraudulently access the content of the storage device that remained connected involuntarily. Here again, the malicious third party can even operate remotely if he succeeds in controlling, from his own computer equipment, the computer equipment to which the storage device remained connected by mistake.
[0015] There is therefore a need to secure the use of computer equipment to which one or more authentication or storage devices can be connected. Statement of the invention
[0016] A method for securing the use of computer equipment is proposed, executed by at least one piece of equipment among the computer equipment and a monitoring piece of equipment connected to the computer equipment, and comprising: - detecting whether, at a current time, at least one authentication or storage device is connected to the computer equipment; - for each authentication or storage device detected as connected at the current time, detect whether the current time is within a range unauthorized time for use of said authentication or storage device; and - for each authentication or storage device detected as connected and for which the current time is in an unauthorized time range, trigger at least one first security action.
[0017] Thus, the proposed solution makes it possible to secure the use of computer equipment to which one or more authentication or storage devices can be connected. Indeed, if an authentication or storage device is detected as connected at a time falling within an unauthorized time range, then at least a first security action is triggered. This first security action aims, for example by triggering an alert and / or deactivating the authentication or storage device, to stop the risk of a malicious third party (cybercriminal for example) fraudulently benefiting from the rights offered by the authentication provided by the authentication device that has remained connected involuntarily and / or the risk of the malicious third party fraudulently accessing the content of the storage device that has remained connected involuntarily.
[0018] According to a particular embodiment, said at least one authentication or storage device belongs to the group comprising: a hardware security key, a card reader, a removable storage key, an external hard drive and a removable memory card.
[0019] According to a particular embodiment, said at least one authentication or storage device is connected to the computer equipment via a connector belonging to the group comprising: - a connector implementing serial bus technology, in particular a USB-A connector or a USB-C connector; - a connector implementing near-field communication technology, in particular an NFC connector; - a connector implementing short-distance bidirectional data exchange technology, in particular a Bluetooth connector; and - a Lightning connector.
[0020] According to a particular embodiment, the first security action belongs to the group comprising: triggering a first alert and deactivation of the authentication or storage device detected as connected.
[0021] According to a particular embodiment, the method further comprises the following steps: - detect whether said current instant, or an instant close to said current instant, is in a time range not authorized for use of the equipment in- computer science; and - if the said current instant, or the said close instant, is in a time range not authorized for use of the IT equipment, trigger at least a second security action.
[0022] According to a particular embodiment, the second security action belongs to the group comprising: triggering a second alert and deactivation of the IT equipment.
[0023] According to a particular embodiment, the method further comprises an initial step consisting of detecting whether the computer equipment is switched on, and in which the other steps are carried out only if the computer equipment is switched on.
[0024] According to a particular embodiment, the method further comprises a step consisting of managing a dashboard and comprising at least one sub-step belonging to the group comprising: - enable a function for viewing the status of connected authentication or storage devices;
[0025] - activate a function for programming unauthorized time slots; and - activate an alert scheduling function.
[0026] A computer program product is also provided, comprising instructions causing the execution, by a processor, of the method mentioned above according to any one of its embodiments, when said instructions are executed by the processor.
[0027] A storage medium is also provided, storing such instructions.
[0028] Also proposed is computer equipment, comprising electronic circuitry electronics configured to implement: - detect whether, at a current time, at least one authentication or storage device is connected to the computer equipment; - for each authentication or storage device detected as connected at the current time, detecting whether said time is within a time range not authorized for use of said authentication or storage device; and - for each authentication or storage device detected as connected and for which the current time is in an unauthorized time range, trigger at least one first security action.
[0029] Also provided is monitoring equipment connected to computer equipment, said monitoring equipment comprising electronic circuitry configured to implement: - detect whether, at a current time, at least one authentication or storage device is connected to the computer equipment; - for each authentication or storage device detected as connected at the current time, detect whether said time is in a time range not authorized for use of said authentication or storage device; and - for each authentication or storage device detected as connected and for which the current time is in an unauthorized time range, trigger at least a first security action. Brief description of the drawings
[0030] The characteristics of the invention mentioned above, as well as others, will appear more clearly on reading the following description of at least one exemplary embodiment, said description being made in relation to the attached drawings, among which:
[0031] [Fig-1] schematically illustrates a system in which the method for securing the use of computer equipment, in one embodiment;
[0032] [Fig.2] schematically illustrates an example of hardware architecture that can play the role of the computer equipment or monitoring equipment shown in [Fig.l];
[0033] [Fig.3] schematically illustrates an example of an algorithm for securing the use of computer equipment, in one embodiment; and
[0034] [Fig.4] schematically illustrates an example of an algorithm for managing a table of edge, in one embodiment.
[0035] DETAILED DESCRIPTION OF EMBODIMENTS
[0036] [Fig.l] schematically illustrates a system in which the method for securing the use of computer equipment can be implemented, in one embodiment of the invention.
[0037] In this embodiment, the system comprises a computer device 101 (also called a “PC” in [Fig.l], for “Personal Computer” in English). This is for example a computer, a tablet or a smartphone (non-exhaustive list).
[0038] One or more authentication or storage devices may be connected to the computer equipment 101. In [Fig.l], purely for illustrative purposes, a single authentication or storage device 102 (also called “PSK” in [Fig.l], for “Physical Security Key” in English) is shown.
[0039] Conventionally, and as already mentioned above, each authentication or storage device can be connected to the computer equipment 101 by means of a wired connection (USB-A connector, USB-C connector, Lightning connector, etc.) or wireless connection (NFC connector, Bluetooth connector, etc.). This is for example a security key, a card reader (in which a authentication card), a removable storage key, an external hard drive or a removable memory card. The present invention applies to any type of authentication or storage device.
[0040] In this embodiment, the system also comprises a surveillance device 103 (also called “SS” in [Fig.l], for “Surveillance Server” in English) which communicates with the computer device 101 via one or more networks (for example the Internet network 104 in [Fig.l]).
[0041] Many communication configurations can be envisaged without departing from the scope of the present invention. For example, in one configuration, the computer equipment 101 and the monitoring equipment 103 communicate directly via a local network (LAN or WLAN for example) to which they are both connected. In another configuration, the two equipments 101 and 103 are connected to different local networks themselves connected via one or more networks of the Internet or other type.
[0042] The monitoring equipment 103 is for example a server. But the invention applies regardless of the form in which the monitoring equipment 103 is implemented (server, computer, tablet, etc.).
[0043] As detailed below, in relation to the algorithms of [Fig. 3] and 4, various embodiments of the invention are possible, depending on the way in which the steps of these algorithms are distributed between the computer equipment 101 and the monitoring equipment 103. Thus, in one embodiment, the algorithms are carried out entirely by the computer equipment 101. In another embodiment, the algorithms are carried out entirely by the monitoring equipment 103. In another embodiment, the carrying out of the algorithms is shared between the computer equipment 101 and the monitoring equipment 103.
[0044] [Fig. 2] schematically illustrates an example of hardware architecture of a piece of equipment 200 that can play the role of the computer equipment 101 or the monitoring equipment 103 appearing in [Fig. 1]. The hardware architecture of the piece of equipment 200 then comprises, connected by a communication bus 210: a processor or CPU (Central Processing Unit) 201; a RAM (Random Access Memory) 202; a ROM (Read Only Memory) 203, for example a Flash memory; a data storage device, such as a hard disk HDD (Hard Disk Drive), or a storage media reader, such as an SD (Secure Digital) card reader 204; at least one communication interface.
[0045] The processor 201 is capable of executing instructions loaded into the RAM 202 from the ROM 203, from an external memory (not shown), from a storage medium, such as an SD card, or from a communication network (not shown). When the equipment 200 is powered on, the processor 201 is capable of reading instructions from the RAM 202 and executing them. These instructions form a computer program causing the processor 201 to implement the behaviors, steps and algorithm described herein (for the computer equipment 101 and the monitoring equipment 103).
[0046] All or part of the behaviors, steps and algorithm described herein may thus be implemented in software form by executing a set of instructions by a programmable machine, such as a DSP (Digital Signal Processor) or a microcontroller, or be implemented in hardware form by a machine or a dedicated component (chip) or a set of components (chipset), such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application-Specified Integrated Circuit). Generally speaking, the equipment 200 comprises electronic circuitry arranged and configured to implement the behaviors, steps and algorithms described herein (for the computer equipment 101 and the monitoring equipment 103).
[0047] [Fig. 3] schematically illustrates an example of an algorithm for securing the use of computer equipment, in one embodiment of the invention.
[0048] After a start step 301, this algorithm comprises a step 302 in which the monitoring equipment 103 detects whether, at a time T1, the computer equipment 101 is switched on. For this, the monitoring equipment uses a known technique allowing it to remotely manage the computer equipment 101. Such a known technique is for example described in the article entitled “System power states” and available via the following link: - "https: / / leam.microsoft.com / fr-fr / windows / win32 / power / system-power-states ".
[0049] If the computer equipment is detected as switched off (response “no” to the test of step 302), the algorithm returns to step 302 (for example after a predetermined duration).
[0050] If the computer equipment is detected as switched on (response “yes” to the test of step 302), the monitoring equipment 103 executes step 303 in which it detects whether the instant T1 is in a time range not authorized for use of the computer equipment 101. For this purpose, the monitoring equipment 103 stores (or has access to) data defining the time range(s) not authorized for use of the computer equipment 101, these ranges being predefined and / or programmed (by the user or a specific operator) via a dashboard (see below the description of [Fig. 4]). For example, the time ranges not authorized for use of the computer equipment 101 correspond to the following periods: 0h-9h and 19h-24h from Monday to Friday, and 0h-24h Saturday and Sunday.
[0051] If the instant T1 is in a time range not authorized for use of the computer equipment 101 (response “yes” to the test of step 303), the monitoring equipment 103 executes step 304 in which it triggers at least one security action (for example, triggering an alert and / or deactivating the computer equipment 101) then the algorithm goes to step 305. Otherwise (response “no” to the test of step 303), the algorithm goes directly to step 305.
[0052] In the case of triggering an alert, the monitoring equipment 103 sends for example an alert message (for example by notification, SMS, e-mail, etc.) to the user concerned and / or to any person (or entity) capable of handling this alert, so that the computer equipment is switched off (deactivated).
[0053] In the case of deactivation of the computer equipment 101 by the monitoring equipment 103, the latter uses a known technique. Such a known technique is for example described in the articles entitled “System Power Action” and “Wake On LAN” and available via the following links: - "https: / / leam.microsoft.com / en-us / windows-hardware / drivers / kemel / system- power-actions » and - "https: / / wiki.debian.org / WakeOnLan".
[0054] In step 305, the computer equipment 101 detects whether, at a current time (which may be the aforementioned time T1 or a time T2 close to the time T1), at least one authentication or storage peripheral 102 is connected to the computer equipment 101. In other words, it carries out an inventory of the possible authentication or storage peripheral(s) 102 which are connected to it.
[0055] Then, in step 306, the computer equipment 101 detects whether the inventory result is empty. If the inventory result is empty, the algorithm returns to step 302, otherwise it goes to steps 307 to 310 which aim to process the authentication or storage device(s) 102 listed by the inventory. For this, the computer equipment 101 uses a known technique allowing it to manage the authentication or storage devices. Such a known technique is for example described in the articles entitled “Get-PnpDevice” and “usb-devices(l) - Linux man page” and available via the following links: - "https: / / leam.microsoft.com / fr-fr / powershell / module / pnpdevice / get-pnpdevic e?view=windowsserver2022-ps” and - "https: / / linux.die.net / man / l / usb-devices".
[0056] In step 307, the computer equipment 101 selects an authentication or storage device 102 forming part of the inventory result, i.e. detected as connected at the current time.
[0057] Then in step 308, the computer equipment 101 detects whether, for the selected authentication or storage device 102, the current time is in a time range not authorized for use of the selected authentication or storage device.
[0058] If the current instant is in a time range that is not authorized for use of the selected authentication or storage device (response “yes” to the test of step 308), the computer equipment 101 executes step 309 in which it triggers at least one security action (for example, triggering an alert and / or deactivating the selected authentication or storage device) then the algorithm goes to step 310. Otherwise (response “no” to the test of step 308), the algorithm goes directly to step 310.
[0059] In the case of triggering an alert, the computer equipment 101 sends (or has sent by the monitoring equipment 103) for example an alert message (for example by notification, SMS, e-mail, etc.) to the user concerned and / or to any person (or entity) capable of handling this alert, so that the selected authentication or storage device is deactivated.
[0060] In the case of deactivation of an authentication or storage device selected by the computer equipment 101, the latter uses a known technique. Such a known technique is for example described in the article entitled “Disable-PnpDevice” and available via the following link: - "https: / / leam.microsoft.com / en-us / powershell / module / pnpdevice / disable-pnp device?view=windowsserver2022-ps”.
[0061] In step 310, the computer equipment 101 detects whether the single or all of the authentication or storage devices 102 forming part of the inventory result have already been selected during a previous iteration of step 307. In the event of a positive response to step 310, the algorithm returns to step 307 (for processing another authentication or storage device), otherwise it returns to step 302.
[0062] In the embodiment described above, steps 302 to 304 are performed by the monitoring equipment and steps 305 to 310 are performed by the computer equipment 101.
[0063] In a variant, all steps 302 to 310 are carried out by the monitoring equipment 103.
[0064] In another variant, step 302 is omitted and all steps 303 to 310 are performed either by the computer equipment 101 or by the monitoring equipment 103.
[0065] In another variant, steps 302 to 304 are omitted and all steps 305 to 310 are performed either by the computer equipment 101 or by the surveillance 103.
[0066] In another variant, steps 303 and 304 are carried out after steps 305 to 310.
[0067] In another variant, steps 303 and 304 are carried out in parallel with steps 305 to 310.
[0068] [Fig.4] schematically illustrates an example of an algorithm (forming a step referenced 400) for managing a dashboard, in one embodiment of the invention.
[0069] After a start step 401, this algorithm comprises a step 402 in which the monitoring equipment 103 detects whether a first function F1, for displaying a state of the authentication or storage devices connected to the computer equipment 101, is selected (via a human-machine interface) by a person using the monitoring equipment 103. If the first function F1 is selected (response “yes” to step 402), the monitoring equipment 103 activates the first function F1 and then goes to step 404. Otherwise (response “no” to step 402), the algorithm goes directly to step 404.
[0070] When the first function F1 is activated, the display of a state of the authentication or storage devices connected to the computer equipment 101 comprises for example the display, for each connected authentication or storage device, of information (written and / or visual and / or audible) indicating whether for this authentication device the present moment is or is not in a time range not authorized for use of this authentication or storage device. For example, a list of the connected authentication or storage devices is displayed, and a red or green flag is attached to each authentication or storage device depending on whether for it the present moment is or is not in a time range not authorized for use.
[0071] In step 404, the monitoring equipment 103 detects whether a second function F2, for programming unauthorized time slots, is selected (via the aforementioned human-machine interface) by the person using the monitoring equipment 103. If the second function F2 is selected (response “yes” to step 404), the monitoring equipment 103 activates the second function F2 and then goes to step 406. Otherwise (response “no” to step 404), the algorithm goes directly to step 406.
[0072] When the second function F2 is activated, the programming of the unauthorized time slots comprises for example the programming of the unauthorized time slots for the use of the computer equipment 101 (see step 303 of [Fig.3]) and / or the programming of the unauthorized time slots for the use of each authentication or storage device 102 capable of connecting to the computer equipment 101 (see step 308 of [Fig. 3]). This programming is carried out via a human-machine interface which displays, for example, for the computer equipment 101 and for each authentication or storage device 102, a breakdown of the week into days and time slots, and makes it possible to indicate for each time slot whether use is authorized or not.
[0073] In step 406, the monitoring equipment 103 detects whether a third function F3, for programming alerts, is selected (via the aforementioned human-machine interface) by the person using the monitoring equipment 103. If the third function F3 is selected (response “yes” to step 406), the monitoring equipment 103 activates the third function F3 and then returns to step 402. Otherwise (response “no” to step 406), the algorithm returns directly to step 402.
[0074] When the third function F3 is activated, the programming of the alerts comprises for example the programming of the alerts for the unauthorized use of the computer equipment 101 (see step 304 of [Fig. 3]) and / or the programming of the alerts for the unauthorized use of an authentication or storage device 102 likely to connect to the computer equipment 101 (see step 309 of [Fig. 3]).
[0075] In the embodiment described above, steps 401 to 407 are performed by the monitoring equipment 103.
[0076] In a variant, one or more of the pairs of steps 402 / 403, 404 / 405 and 406 / 407 is (are) carried out by the computer equipment 101.
[0077] In another variant, the order of the pairs of steps 402 / 403, 404 / 405 and 406 / 407 is modified.
[0078] In another variant, one (or two) of the pairs of steps 402 / 403, 404 / 405 and 406 / 407 is (are) omitted.
Claims
Claims
1. Method for securing the use of a computer equipment (101), executed by at least one of the computer equipment (101) and a monitoring equipment (103) connected to the computer equipment, and comprising: - detecting (305) whether, at a current time, at least one authentication or storage device (102) is connected to the computer equipment (101); - for each authentication or storage device (102) detected as connected at the current time, detecting (308) whether the current time is in a time range not authorized for use of said authentication or storage device; and - for each authentication or storage device (102) detected as connected and for which the current time is in an unauthorized time range, triggering (309) at least one first securing action.
2. The method of claim 1, wherein said at least one authentication or storage device (102) belongs to the group comprising: a hardware security key, a card reader, removable storage key, external hard drive and removable memory card.
3. Method according to any one of claims 1 and 2, wherein said at least one authentication or storage device (102) is connected to the computer equipment (101) via a connector belonging to the group comprising: - a connector implementing a serial bus technology, in particular a USB-A connector or a USB-C connector; - a connector implementing a near-field communication technology, in particular an NFC connector; - a connector implementing a short-distance bidirectional data exchange technology, in particular a Bluetooth connector; and - a Lightning connector.
4. Method according to any one of claims 1 to 3, in which the first securing action belongs to the group comprising: a triggering of a first alert and a deactivation of the authentication or storage device detected as connected.
5. A method according to any one of claims 1 to 4, further comprising the following steps: - detecting (303) whether said current instant, or an instant close to said current instant, is in a time range not authorized for use of the computer equipment (101); and - if said current instant, or said close instant, is in a time range not authorized for use of the computer equipment, triggering (304) at least one second security action.
6. Method according to claim 5, in which the second securing action belongs to the group comprising: triggering a second alert and deactivating the computer equipment (101).
7. A method according to any one of claims 1 to 6, further comprising an initial step (302) of detecting whether the computer equipment (101) is turned on, and wherein the further steps (303 to 310) are performed only if the computer equipment (101) is turned on.
8. Method according to any one of claims 1 to 7, further comprising a step (400) of managing a dashboard and comprising at least one sub-step belonging to the group comprising: - activating (403) a function for viewing a state of the connected authentication or storage devices; - activating (405) a function for programming unauthorized time ranges; and - activating (407) a function for programming alerts.
9. Computer program product, comprising instructions causing the execution, by a processor (201), of the method according to any one of claims 1 to 8, when said instructions are executed by the processor.
10. Storage medium (203), storing a computer program comprising instructions causing a processor (201) to execute the method according to any one of claims 1 to 8, when said instructions are read and executed by the processor.
11. Computer equipment (101), comprising electronic circuitry configured to implement: - detecting (305) whether, at a current time, at least one authentication or storage device (102) is connected to the computer equipment (101); - for each authentication or storage device (102) detected as connected at the current time, detecting (308) whether the current time is in a time range not authorized for use of said authentication or storage device; and - for each authentication or storage device (102) detected as connected and for which the current time is in an unauthorized time range, triggering (309) at least one first security action.
12. Monitoring equipment (103) connected to computer equipment (101), said monitoring equipment comprising electronic circuitry configured to implement: - detecting (305) whether, at a current time, at least one authentication or storage device (102) is connected to the computer equipment (101); - for each authentication or storage device (102) detected as connected at the current time, detecting (308) whether the current time is in a time range not authorized for use of said authentication or storage device; and - for each authentication or storage device (102) detected as connected and for which the current time is in an unauthorized time range, triggering (309) at least one first security action.
Citation Information
Patent Citations
Authorization of unique computer device specimens
US20160203311A1