METHOD FOR SECURING THE USE OF COMPUTER EQUIPMENT

The method detects and secures connected authentication and storage devices by triggering alerts and deactivation during unauthorized times, addressing the security risk of devices left connected when users are absent.

FR3161044B1Active Publication Date: 2026-04-17WYBOT
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
WYBOT
Filing Date
2024-04-08
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Authentication and storage devices often remain connected to computer equipment when users are not present, posing a security risk as malicious third parties can exploit these devices for unauthorized access or use.

Method used

A method and system to detect connected authentication or storage devices and trigger security actions if they are used during unauthorized time ranges, including alerts and deactivation, to prevent unauthorized access.

Benefits of technology

Secures computer equipment by preventing unauthorized use of connected devices during non-permitted times, reducing the risk of fraudulent access or data exposure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000017_0000
    Figure 00000017_0000
  • Figure 00000017_0001
    Figure 00000017_0001
  • Figure 00000018_0000
    Figure 00000018_0000
Patent Text Reader

Abstract

A method is proposed for securing the use of computer equipment (101), executed by at least one piece of equipment from among the computer equipment and a monitoring device (103) connected to the computer equipment, and comprising: detecting at a time whether at least one authentication or storage device (102) is connected to the computer equipment; for each authentication or storage device detected as connected at a time, detecting whether said time is in a time range not authorized for use of said authentication or storage device; and for each authentication or storage device detected as connected at a time being in a time range not authorized, triggering at least one first security action.Thus, the proposed solution secures the use of computer equipment to which one or more authentication or storage devices may be connected. Figure to be published with the abbreviation: Fig. 1.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: METHOD FOR SECURING THE USE OF COMPUTER EQUIPMENT technical field

[0001] The field of the invention is that of computer equipment (computer, tablet, smartphone, etc.) to which one or more authentication or storage devices can be connected.

[0002] More specifically, the present invention relates to a method of securing the use of computer equipment, carried out by at least one piece of equipment among the computer equipment and a monitoring piece of equipment connected to the computer equipment.

[0003] The present invention also relates to various elements that can enable, or participate in, the implementation of the process, namely a computer program product, a storage medium, computer equipment, and monitoring equipment. PRIOR TECHNOLOGY

[0004] Computer equipment (also called "computer device" or "computerized system") comprises two complementary components: the hardware component and the software component.

[0005] The hardware component, also called "computer hardware," represents all the physical components of the computer system. It includes electronic devices, integrated circuits, hard drives, memory, motherboards, processors, monitors, etc. It is responsible for executing the instructions of the software component and for processing data.

[0006] The software component encompasses all the programs, data, and instructions that control the operation of the computer system. It can be divided into two main categories: operating systems and applications. Operating systems, such as Windows, macOS, and Linux (registered trademarks), are software programs that manage the computer system's resources and allow users to interact with the hardware component. They are responsible for file management, memory allocation, device management, and so on. Applications, on the other hand, are software programs designed to perform specific tasks.

[0007] External electronic devices, called "computer peripherals" (or simply "peripherals"), are generally connected to the hardware component in order to increase the capabilities and functionality of the computer equipment. There are many types of peripherals, including the input devices (e.g. keyboard, mouse, microphone, etc.), output devices (e.g. printer, speaker, monitor, etc.), storage devices (e.g. external hard drive, removable storage flash drive (USB type or other), removable memory card (SD type or other), etc.) and network devices (e.g. router, modem and network adapter).

[0008] Peripherals can be connected (plugged in) to computer equipment by means of wired (cabled) or wireless connections. Wired connections use ports and connectors of various types (e.g., USB, HDMI, DVI, Ethernet, serial, etc.). Wireless connections use one or more wireless technologies (e.g., Bluetooth, Wi-Fi, infrared, etc.).

[0009] Another type of device is also known, namely authentication devices, which can be connected to computer equipment by means of wired connections (for example, a connector implementing serial bus technology (e.g., a USB-A or USB-C connector) or a Lightning connector) or by means of wireless connections (e.g., a connector implementing near-field communication technology (e.g., an NFC connector) or a connector implementing bidirectional short-range data exchange technology (e.g., a Bluetooth connector)). Authentication devices can take various forms, for example: a security key (also called a "hardware security key" or "physical security key"), a card reader (into which an authentication card can be inserted), etc.

[0010] Authentication devices are used to authenticate a user and have a security function for an organization. For example, and not exhaustively, an authentication device can be used to authenticate its owner in order to give them rights, to secure one or more processes (such as exchanges of confidential data, access to secure platforms, taking control of an industrial process (such as a PLC for a closed network) or to carry out financial payment operations (such as bank transfers for example).

[0011] In other words, authentication devices, particularly hardware security keys, are a physical form of authentication (a security means of authenticating their owner) that allows a user to access systems, applications, and accounts. In particular, hardware security keys are often used as a second form of authentication (2FA) or as a multi-factor authentication (MFA) method. They are "something you have" authentication factors because they are physical objects that the user has with them. They are easy to use because the user does not have than to insert their security key into their computer device (e.g., computer) to authenticate their identity.

[0012] However, a drawback of authentication or storage devices is that the user may sometimes forget about them and leave them connected to the computer equipment. This can happen, for example, when the user leaves their workstation in a hurry.

[0013] The fact that an authentication device remains connected to the computer equipment, even when the user is no longer physically present near the equipment, poses a security problem. Indeed, there is then a risk that a malicious third party could use the computer equipment in an unauthorized manner and thus fraudulently benefit from the rights conferred by the authentication provided by the authentication device that remained unintentionally connected (due to oversight). The malicious third party (such as a cybercriminal) could even operate remotely if they manage to control, from their own computer equipment, the computer equipment to which the authentication device remained mistakenly connected. The consequences can be dramatic for the organization that seeks to protect itself with the authentication provided by the authentication device.

[0014] The fact that a storage device remains connected to the computer equipment, even when the user is no longer physically present near the equipment, also poses a security problem. Indeed, there is then a risk that a malicious third party could use the computer equipment in an unauthorized manner and thus fraudulently access the contents of the storage device that remained unintentionally connected. Here again, the malicious third party could even operate remotely if they manage to control, from their own computer equipment, the computer equipment to which the storage device remained mistakenly connected.

[0015] There is therefore a need to secure the use of computer equipment to which one or more authentication or storage devices can be connected. Description of the invention

[0016] A method is proposed for securing the use of computer equipment, executed by at least one piece of equipment including the computer equipment and a monitoring device connected to the computer equipment, and comprising:

[0017] - detecting whether, at a current time, at least one authentication or storage is connected to the computer equipment;

[0018] - for each authentication or storage device detected as connected at the current time, detect if the current time falls within a time range not permitted for use of said authentication or storage device; and

[0019] - for each authentication or storage device detected as connected and for which the current time is in an unauthorized time range, trigger at least one initial security action.

[0020] Thus, the proposed solution secures the use of computer equipment to which one or more authentication or storage devices may be connected. Indeed, if an authentication or storage device is detected as connected at a time falling within an unauthorized time range, then at least one initial security action is triggered. This initial security action aims, for example by triggering an alert and / or disabling the authentication or storage device, to eliminate the risk that a malicious third party (a cybercriminal, for example) might fraudulently benefit from the rights conferred by the authentication provided by the authentication device that remained unintentionally connected, and / or the risk that the malicious third party might fraudulently access the contents of the storage device that remained unintentionally connected.

[0021] According to a particular embodiment, said at least one authentication or storage device belongs to the group comprising: a hardware security key, a card reader, a removable storage key, an external hard drive and a removable memory card.

[0022] According to a particular embodiment, said at least one authentication or storage device is connected to the computer equipment via a connector belonging to the group comprising:

[0023] - a connector implementing serial bus technology, in particular a USB-A connector or a USB-C connector;

[0024] - a connector implementing a near-field communication technology, including an NFC connector;

[0025] - a connector implementing a bidirectional data exchange technology short distance, including a Bluetooth connector; and

[0026] - a Lightning connector.

[0027] According to a particular embodiment, the first security action belongs to the group comprising: triggering a first alert and deactivating the authentication or storage device detected as connected.

[0028] According to a particular embodiment, the process further comprises the following steps:

[0029] - detect if the current instant, or an instant close to the current instant, is found within a time frame not authorized for use of the computer equipment; and

[0030] - if said current instant, or said nearby instant, is within a time range If unauthorized use of the computer equipment is not permitted, trigger at least one second security action.

[0031] According to a particular embodiment, the second security action belongs to the group comprising: triggering a second alert and deactivating the computer equipment.

[0032] According to a particular embodiment, the method further comprises an initial step of detecting whether the computer equipment is switched on, and in which the other steps are carried out only if the computer equipment is switched on.

[0033] According to a particular embodiment, the method further comprises a step of managing a dashboard and comprising at least one substep belonging to the group comprising:

[0034] - activate a function for displaying the status of authentication devices or connected storage;

[0035] - activate a function for programming unauthorized time ranges; and

[0036] - activate an alert scheduling function.

[0037] A computer program product is also proposed, comprising instructions leading to the execution, by a processor, of the process mentioned above according to any one of its embodiments, when said instructions are executed by the processor.

[0038] A storage medium is also proposed, storing such instructions.

[0039] Computer equipment is also offered, including circuitry electronics configured to implement:

[0040] - detect if, at a current time, at least one authentication or storage is connected to the computer equipment;

[0041] - for each authentication or storage device detected as connected at the current time, detect if said time falls within a time range not permitted for use of said authentication or storage device; and

[0042] - for each authentication or storage device detected as connected and for which the current time is in an unauthorized time range, trigger at least one initial security action.

[0043] A monitoring device connected to a computer system is also proposed, said monitoring device comprising electronic circuitry configured to implement:

[0044] - detect if, at a current time, at least one authentication or storage is connected to the computer equipment;

[0045] - for each authentication or storage device detected as connected at the current time, detect if said time falls within a time range not permitted for use of said authentication or storage device; and

[0046] - for each authentication or storage device detected as connected and for which the current time is in an unauthorized time range, trigger at least one initial security action. Brief description of the drawings

[0047] The features of the invention mentioned above, as well as others, will become clearer upon reading the following description of at least one exemplary embodiment, said description being made in relation to the accompanying drawings, among which:

[0048] [Fig-1] schematically illustrates a system in which the process of securing the use of computer equipment can be implemented, in one embodiment;

[0049] [Fig.2] schematically illustrates an example of a hardware architecture that can play the role of computer equipment or monitoring equipment appearing on [Fig.1];

[0050] [Fig.3] schematically illustrates an example of an algorithm for securing the use of computer equipment, in one embodiment; and

[0051] [Fig.4] schematically illustrates an example of an algorithm for managing an array of edge, in one embodiment.

[0052] DETAILED DESCRIPTION OF EMBODIMENT METHODS

[0053] Fig. 1 schematically illustrates a system in which the method of securing the use of computer equipment can be implemented, in one embodiment of the invention.

[0054] In this embodiment, the system comprises a computer device 101 (also referred to as "PC" in [Fig. 1], for "Personal Computer" in English). This is, for example, a computer, a tablet, or a smartphone (non-exhaustive list).

[0055] One or more authentication or storage devices can be connected to the computer equipment 101. In [Fig.1], for purely illustrative purposes, a single authentication or storage device 102 (also called “PSK” in [Fig.1], for “Physical Security Key” in English) has been shown.

[0056] In a conventional manner, and as already mentioned above, each authentication or storage device can be connected to the computer equipment 101 via a wired connection (USB-A connector, USB-C connector, Lightning connector, etc.) or wireless connection (NFC connector, Bluetooth connector, etc.). Examples include a security key, a card reader (into which an authentication card can be inserted), a removable storage device, an external hard drive, or a removable memory card. The present invention applies to any type of authentication or storage device.

[0057] In this embodiment, the system also includes a monitoring device 103 (also called “SS” in [Fig.1], for “Surveillance Server” in English) which communicates with the computer equipment 101 via one or more networks (for example the Internet network 104 in [Fig.1]).

[0058] Numerous communication configurations can be envisaged without departing from the scope of the present invention. For example, in one configuration, the computer equipment 101 and the monitoring equipment 103 communicate directly via a local area network (LAN or WLAN, for example) to which they are both connected. In another configuration, the two devices 101 and 103 are connected to different local area networks, which are themselves connected via one or more networks such as the Internet or other types.

[0059] The monitoring equipment 103 is, for example, a server. But the invention applies regardless of the form in which the monitoring equipment 103 is implemented (server, computer, tablet, etc.).

[0060] As detailed below, in relation to the algorithms of [Fig. 3] and 4, various embodiments of the invention are possible, depending on how the steps of these algorithms are distributed between the computer equipment 101 and the monitoring equipment 103. Thus, in one embodiment, the algorithms are performed entirely by the computer equipment 101. In another embodiment, the algorithms are performed entirely by the monitoring equipment 103. In yet another embodiment, the execution of the algorithms is shared between the computer equipment 101 and the monitoring equipment 103.

[0061] Figure 2 schematically illustrates an example of the hardware architecture of a device 200 that can play the role of the computer equipment 101 or the monitoring equipment 103 appearing in Figure 1. The hardware architecture of the device 200 then comprises, connected by a communication bus 210: a processor or CPU (Central Processing Unit) 201; a RAM (Random Access Memory) 202; a ROM (Read Only Memory) 203, for example a Flash memory; a data storage device, such as a HDD (Hard Disk Drive), or a storage media reader, such as an SD (Secure Digital) card reader 204; at least one communication interface.

[0062] The processor 201 is capable of executing instructions loaded into RAM 202 from ROM 203, external memory (not shown), a storage medium such as an SD card, or a communication network (not shown). When the equipment 200 is powered on, the processor 201 is capable of reading instructions from RAM 202 and executing them. These instructions form a computer program causing the processor 201 to implement the behaviors, steps, and algorithm described herein (for the computer equipment 101 and the monitoring equipment 103).

[0063] All or part of the behaviors, steps, and algorithm described herein can thus be implemented in software form by executing a set of instructions by a programmable machine, such as a DSP (Digital Signal Processor) or a microcontroller, or be implemented in hardware form by a dedicated machine or component (chip) or a dedicated set of components (chipset), such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit). Generally, the equipment 200 comprises electronic circuitry arranged and configured to implement the behaviors, steps, and algorithms described herein (for the computer equipment 101 and the monitoring equipment 103).

[0064] Figure 3 schematically illustrates an example of an algorithm for securing the use of computer equipment, in one embodiment of the invention.

[0065] After a starting step 301, this algorithm includes a step 302 in which the monitoring equipment 103 detects whether, at a time T1, the computer equipment 101 is switched on. To do this, the monitoring equipment uses a known technique enabling it to remotely manage the computer equipment 101. Such a known technique is described, for example, in the article entitled "System Power States" and available via the following link: - "https: / / learn.microsoft.com / fr-fr / windows / win32 / power / system-power- States.

[0066] If the computer equipment is detected as switched off (response "no" to the test in step 302), the algorithm returns to step 302 (for example after a predetermined duration).

[0067] If the computer equipment is detected as switched on (response "yes" to the test in step 302), the monitoring equipment 103 executes step 303 in which it detects whether time T1 is within a time range not authorized for use of the computer equipment 101. To this end, the monitoring equipment 103 stores (or accesses) data defining the time range(s) not authorized for use of the computer equipment 101, these ranges being predefined and / or programmed (by the user or a specific operator) via a dashboard (see below for the description of [Fig.4]). For example, the time periods not authorized for use of computer equipment 101 correspond to the following periods: 0am-9am and 7pm-midnight from Monday to Friday, and 0am-midnight on Saturday and Sunday.

[0068] If time T1 is within a time range not permitted for use of the computer equipment 101 (response "yes" to the test in step 303), the monitoring equipment 103 executes step 304 in which it triggers at least one security action (for example, triggering an alert and / or disabling the computer equipment 101) and then the algorithm proceeds to step 305. Otherwise (response "no" to the test in step 303), the algorithm proceeds directly to step 305.

[0069] In the event of an alert being triggered, the monitoring equipment 103 sends, for example, an alert message (e.g. by notification, SMS, email, etc.) to the user concerned and / or to any person (or entity) capable of handling this alert, so that the computer equipment is switched off (disabled).

[0070] In the event that the computer equipment 101 is deactivated by the monitoring equipment 103, the latter uses a known technique. Such a known technique is described, for example, in the articles entitled "System Power Action" and "Wake On LAN," available via the following links: - "https: / / learn.microsoft.com / en-us / windows-hardware / drivers / kernel / " "system-power-actions" and - "https: / / wiki.debian.org / WakeOnLan".

[0071] In step 305, the computer equipment 101 detects whether, at a current time (which may be the aforementioned time T1 or a time T2 close to time T1), at least one authentication or storage device 102 is connected to the computer equipment 101. In other words, it performs an inventory of the possible authentication or storage device(s) 102 that are connected to it.

[0072] Then, in step 306, the computer equipment 101 detects whether the inventory result is empty. If the inventory result is empty, the algorithm returns to step 302; otherwise, it proceeds to steps 307 through 310, which are designed to process the authentication or storage device(s) 102 listed by the inventory. To do this, the computer equipment 101 uses a known technique for managing authentication or storage devices. Such a known technique is described, for example, in the articles entitled "Get-PnpDevice" and "usb-devices(l) - Linux man page," available via the following links: - "https: / / learn.microsoft.com / fr-fr / powershell / module / pnpdevice / get- pnpdevice?view=windowsserver2022-ps” and - "https: / / linux.die.net / man / l / usb-devices".

[0073] In step 307, the computer equipment 101 selects an authentication or storage device 102 that is part of the inventory result, i.e. detected as connected at the current time.

[0074] Then in step 308, the computer equipment 101 detects whether, for the selected authentication or storage device 102, the current time is within a time range not permitted for use of the selected authentication or storage device.

[0075] If the current time is within a time range not permitted for use of the selected authentication or storage device (response "yes" to the test in step 308), the computer equipment 101 executes step 309 in which it triggers at least one security action (for example, triggering an alert and / or disabling the selected authentication or storage device) and then the algorithm proceeds to step 310. Otherwise (response "no" to the test in step 308), the algorithm proceeds directly to step 310.

[0076] In the event of an alert being triggered, the computer equipment 101 sends (or has sent by the monitoring equipment 103) for example an alert message (for example by notification, SMS, email, etc.) to the user concerned and / or to any person (or entity) capable of handling this alert, so that the selected authentication or storage device is deactivated.

[0077] In the case of a device disabling authentication or storage selected by the computer equipment 101, the latter uses a known technique. Such a known technique is described, for example, in the article entitled "Disable-PnpDevice" and available via the following link: - "https: / / learn.microsoft.com / en-us / powershell / module / pnpdevice / disable- pnpdevice?view=windowsserver2022-ps”.

[0078] In step 310, the computer equipment 101 detects whether the single or all of the authentication or storage devices 102 that are part of the inventory result have already been selected during a previous iteration of step 307. If the answer is positive in step 310, the algorithm returns to step 307 (to process another authentication or storage device), otherwise it returns to step 302.

[0079] In the embodiment described above, steps 302 to 304 are carried out by the monitoring equipment and steps 305 to 310 are carried out by the computer equipment 101.

[0080] In one variant, all steps 302 to 310 are carried out by the monitoring equipment 103.

[0081] In another variant, step 302 is omitted and all steps 303 to 310 are carried out either by the computer equipment 101 or by the monitoring equipment 103.

[0082] In another variant, steps 302 to 304 are omitted and all steps 305 to 310 are carried out either by the computer equipment 101 or by the monitoring equipment 103.

[0083] In another variant, steps 303 and 304 are carried out after steps 305 to 310.

[0084] In another variant, steps 303 and 304 are carried out in parallel with steps 305 to 310.

[0085] Fig. 4 schematically illustrates an example of an algorithm (forming a step referenced 400) for managing a dashboard, in one embodiment of the invention.

[0086] After a starting step 401, this algorithm includes a step 402 in which the monitoring equipment 103 detects whether a first function Fl, for displaying the state of authentication or storage devices connected to the computer equipment 101, is selected (via a human-machine interface) by a person using the monitoring equipment 103. If the first function Fl is selected (response "yes" to step 402), the monitoring equipment 103 activates the first function Fl and then proceeds to step 404. Otherwise (response "no" to step 402), the algorithm proceeds directly to step 404.

[0087] When the first Fl function is activated, the visualization of the status of authentication or storage devices connected to the computer equipment 101 includes, for example, displaying information (written and / or visual and / or audible) for each connected authentication or storage device, indicating whether the current time for that authentication device is within a time range not authorized for its use. For example, a list of connected authentication or storage devices is displayed, and a red or green flag is attached to each authentication or storage device depending on whether the current time for that device is within a time range not authorized for its use.

[0088] In step 404, the monitoring equipment 103 detects whether a second function F2, for programming unauthorized time ranges, is selected (via the aforementioned human-machine interface) by the person using the monitoring equipment 103. If the second function F2 is selected (response "yes" in step 404), the monitoring equipment 103 activates the second function F2 and then proceeds to step 406. Otherwise (answer "no" to step 404), the algorithm goes directly to step 406.

[0089] When the second function F2 is activated, the programming of unauthorized time slots includes, for example, programming unauthorized time slots for the use of the computer equipment 101 (see step 303 of [Fig. 3]) and / or programming unauthorized time slots for the use of each authentication or storage device 102 that can connect to the computer equipment 101 (see step 308 of [Fig. 3]). This programming is carried out via a human-machine interface that displays, for example, for the computer equipment 101 and for each authentication or storage device 102, a breakdown of the week into days and time slots, and allows the user to indicate for each time slot whether or not its use is authorized.

[0090] In step 406, the monitoring equipment 103 detects whether a third function F3, for programming alerts, is selected (via the aforementioned human-machine interface) by the person using the monitoring equipment 103. If the third function F3 is selected (response "yes" in step 406), the monitoring equipment 103 activates the third function F3 and then returns to step 402. Otherwise (response "no" in step 406), the algorithm returns directly to step 402.

[0091] When the third function F3 is activated, the programming of alerts includes, for example, the programming of alerts for unauthorized use of the computer equipment 101 (see step 304 of [Fig.3]) and / or the programming of alerts for unauthorized use of an authentication or storage device 102 that may connect to the computer equipment 101 (see step 309 of [Fig.3]).

[0092] In the embodiment described above, steps 401 to 407 are carried out by the monitoring equipment 103.

[0093] In one variant, one or more of the pairs of steps 402 / 403, 404 / 405 and 406 / 407 is (are) carried out by the computer equipment 101.

[0094] In another variant, the order of the step pairs 402 / 403, 404 / 405 and 406 / 407 is modified.

[0095] In another variant, one (or two) of the pairs of steps 402 / 403, 404 / 405 and 406 / 407 is (are) omitted.

Claims

Demands

1. A method for securing the use of computer equipment (101), performed by at least one piece of equipment including the computer equipment (101) and a monitoring device (103) connected to the computer equipment, and comprising: - detecting whether at least one authentication or storage device (102) has remained unintentionally connected to the computer equipment (101), comprising: * detecting (305) whether, at a current time, at least one authentication or storage device (102) is connected to the computer equipment (101);* for each authentication or storage device (102) detected as connected at the current time, detect (308) whether the current time is within a time range not permitted for use of said authentication or storage device, each authentication or storage device (102) detected as connected and for which the current time is within a time range not permitted being considered an authentication or storage device (102) that has remained unintentionally connected to the computer equipment (101); and - for each authentication or storage device (102) detected as having remained unintentionally connected, i.e. for which the current time is within a time range not permitted, trigger (309) at least one initial security action.

2. Method according to claim 1, wherein said at least one authentication or storage device (102) belongs to the group comprising: a hardware security key, a card reader, a removable storage key, an external hard drive and a removable memory card.

3. A method according to any one of claims 1 and 2, wherein said at least one authentication or storage device (102) is connected to the computer equipment (101) via a connector belonging to the group comprising: - a connector implementing serial bus technology, in particular a USB-A connector or a USB-C connector; - a connector implementing a near field communication technology, including an NFC connector; - a connector implementing a short-range bidirectional data exchange technology, including a Bluetooth connector; and - a Lightning connector.

4. A method according to any one of claims 1 to 3, wherein the first security action belongs to the group comprising: triggering a first alert and disabling the authentication or storage device detected as remaining unintentionally connected.

5. A method according to any one of claims 1 to 4, further comprising the following steps: - detect (303) whether said current time, or a time close to said current time, is within a time range not authorized for use of the computer equipment (101); and - if said current time, or a time close to said current time, is within a time range not authorized for use of the computer equipment, trigger (304) at least a second security action.

6. Method according to claim 5, wherein the second security action belongs to the group comprising: triggering a second alert and deactivating the computer equipment (101).

7. A method according to any one of claims 1 to 6, further comprising an initial step (302) of detecting whether the computer equipment (101) is switched on, and wherein the other steps (303 to 310) are performed only if the computer equipment (101) is switched on.

8. A method according to any one of claims 1 to 7, further comprising a step (400) of managing a dashboard and comprising at least one substep belonging to the group comprising: - activating (403) a function for visualizing the status of connected authentication or storage devices; - activating (405) a function for scheduling unauthorized time ranges; and - activating (407) a function for scheduling alerts.

9. Product computer program, comprising instructions causing a processor (201) to execute the method according to any one of claims 1 to 8, when said instructions are executed by the processor.

10. Storage medium (203), storing a computer program comprising instructions causing a processor (201) to execute the method according to any one of claims 1 to 8, when said instructions are read and executed by the processor.

11. Computer equipment (101), comprising electronic circuitry configured to implement: - detect if at least one authentication or storage device (102) has remained unintentionally connected to the computer equipment (101), comprising: * detect (305) if, at a current time, at least one authentication or storage device (102) is connected to the computer equipment (101);* for each authentication or storage device (102) detected as connected at the current time, detect (308) whether the current time is within a time range not permitted for use of said authentication or storage device, each authentication or storage device (102) detected as connected and for which the current time is within a time range not permitted being considered an authentication or storage device (102) that has remained unintentionally connected to the computer equipment (101); and - for each authentication or storage device (102) detected as having remained unintentionally connected, i.e. for which the current time is within a time range not permitted, trigger (309) at least one initial security action.

12. Monitoring equipment (103) connected to computer equipment (101), said monitoring equipment comprising electronic circuitry configured to implement: - detect whether at least one authentication or storage device (102) has remained unintentionally connected to the computer equipment (101), comprising: * detect (305) if, at a current time, at least one authentication or storage device (102) is connected to the computer equipment (101); * for each authentication or storage device (102) detected as connected at the current time, detect (308) whether the current time is within a time range not permitted for use of said authentication or storage device, each authentication or storage device (102) detected as connected and for which the current time is within a time range being considered an authentication or storage device (102) that remained unintentionally connected to the computer equipment (101); and - for each authentication or storage device (102) detected as remaining unintentionally connected, i.e. for which the current time is in an unauthorized time range, trigger (309) at least one first security action.