Method and device for providing data protected by authentication.

The method and device facilitate malware diagnosis in customer networks by enabling server access to local network data via terminal-managed rights, addressing access and skill limitations, and improving cyberattack detection.

FR3166721A1Pending Publication Date: 2026-03-27ORANGE SA
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-09-23
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Telecommunications operators face challenges in diagnosing customer networks infected with malware due to lack of access rights and customer computer skills, hindering effective detection and prevention of cyberattacks.

Method used

A method and device enable a server to obtain diagnostic data from an authentication-protected resource within a customer's local network by using a terminal within the network to manage execution rights on behalf of the server, allowing consent-based data retrieval without direct authentication.

Benefits of technology

Enables telecommunications operators to diagnose local networks for malware presence efficiently by obtaining necessary diagnostic data through user-consented terminal access, enhancing security and operational efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

The invention relates to a method for providing, by a first terminal located within a first computer network, at least one diagnostic data point, said method being implemented by said first terminal and characterized in that the method comprises the following steps: - receiving from a second terminal located within a second computer network a request to execute a command capable of obtaining said at least one data point; - obtaining execution rights for said command; - executing said command and transmitting said at least one data point obtained to said second terminal. Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method and device for providing data protected by authentication.

[0001] 1. Scope of the invention

[0002] The invention belongs to the field of telecommunications, and relates more particularly to a method enabling a service logic executed by a server of a first telecommunications network, to obtain information from an authentication-protected resource located within a second telecommunications network.

[0003] 2. Prior Art

[0004] For security reasons, a telecommunications operator must continuously monitor / analyze its telecommunications networks (network load, traffic, data type, etc.) in order to anticipate and prevent attacks launched by hackers. When an anomaly is detected originating from one of its customers' local networks, the operator informs them and asks them to stop their activities. However, the customer is usually unaware of this. Indeed, it is quite common for one or more terminals located within their local network, that is, behind the home interconnection gateway, to be infected by malware (software capable of carrying out cyberattacks) remotely controlled by a third party, i.e., by a hacker.

[0005] During the investigation, in order to identify the equipment causing the malfunction(s) / problem(s), the telecommunications operator may ask the customer to perform a diagnostic of their local network. However, not all customers have sufficient computer skills to carry out such a diagnostic. Furthermore, the operator may not have the necessary access (rights / authentication credentials) to the local network to perform the diagnostic remotely on behalf of the customer.

[0006] More specifically, a diagnostic service logic executed by an operator's server has no means of accessing a resource (for example, a connected object or the home interconnection gateway) located within the customer's local network in order to obtain the useful and necessary data (list of connected terminals, etc.) for the proper execution of the diagnostic process.

[0007] 3. Description of the invention

[0008] The invention improves upon the prior art and, to this end, proposes a method for providing, via a terminal located within a first computer network, at least a given data point, said process being implemented by said terminal and characterized in that the process comprises the following steps: - reception from an electronic device located within a second computer network of a request to execute a command capable of obtaining said at least one piece of data; - obtaining a right of execution for said order; - execution of said order and transmission of said at least one data obtained to said electronic device.

[0009] Advantageously, according to the invention, a service logic (i.e., a service), for example executed by a server on a second telecommunications network, can obtain information from an authentication-protected resource located within a first telecommunications network. Specifically, the execution rights for the command that enables data retrieval are managed by the terminal located within the first computer network on behalf of the server. Thus, the server is not required to authenticate with the gateway of the first network and / or the terminals that comprise it.

[0010] An electronic (or computer) device is defined as any device capable of communicating with a terminal and executing service logic, for example, in connection with a service offered by a chatbot. Examples of electronic devices include a personal computer, a smartphone, a tablet, a television, a car's onboard computer, a connected object, a router, an interconnection gateway, a server, etc.

[0011] According to a particular embodiment of the invention, a method as described above is characterized in that said at least one data point corresponds to at least one diagnostic data point.

[0012] Advantageously, according to the invention, a telecommunications operator wishing to diagnose a local network of one of its customers receives (for example, at the level of a dedicated server) via a terminal located in the local network (for example, a mobile terminal connected via Wi-Fi® to the customer's home interconnection gateway) the data useful and necessary for the diagnosis. This diagnostic data is, for example, retrieved from the gateway itself or from a connected object located in the local network.

[0013] Specifically, according to the invention, a service logic capable of establishing a diagnosis (i.e., a diagnostic service) of a local network, which is executed, for example, on a server located outside the inspected local network, obtains authentication-protected diagnostic data from the inspected local network without itself being authenticated at the local network level, and more particularly at the terminal(s) capable of providing the diagnostic data. Indeed, the execution rights The commands that enable the acquisition of diagnostic data are managed by the terminal located within the local network on behalf of the diagnostic service.

[0014] According to a particular embodiment of the invention, a method as described above is characterized in that the execution of said command is carried out according to the result of an agreement request returned to a user via a human-machine interface of said terminal.

[0015] Advantageously, this embodiment allows for obtaining diagnostic data based on the outcome of a consent request submitted to a user / client. Thus, the user / client gives or withholds their consent regarding the execution of the diagnostic process on their local network.

[0016] According to a particular embodiment of the invention, a method as described above is characterized in that the execution rights for said command are obtained following authentication of a user via a human-machine interface of a computer application executed by said terminal and in that said command is executed by said application.

[0017] Advantageously, this embodiment allows a telecommunications operator wishing to diagnose a local network of one of its customers to receive (for example, on a dedicated server) the data necessary for the diagnosis via a proxy application run by a terminal located on the local network. This is the case, for example, when the proxy application is a companion application capable of guiding the customer through the diagnostic process and is run by a mobile terminal connected via Wi-Fi® to the customer's local network's home gateway. In practice, the companion / proxy application most often already has access rights to the home gateway and other terminals on the local network. Indeed, the customer must first authenticate (for example, via a session cookie, a username / password combination, multi-factor authentication, etc.).This authentication is used to configure and use the services offered by the companion application (setting up the gateway's Wi-Fi, controlling the TV decoder, etc.) and / or the services offered by devices on the local network (connected camera, NAS for Network Attached Storage, etc.). This authentication can then be reused by the companion application to access data that allows it to diagnose the client's local network and determine if malware is present. This diagnostic data is retrieved, for example, from the gateway itself or from a connected device located on the local network.

[0018] Alternatively, client authentication is required by the proxy application each time diagnostic data is requested.

[0019] According to a particular embodiment of the invention, a method as described above is characterized in that said at least one data obtained is returned with a request for agreement to a user via a human-machine interface of said terminal and in that the transmission step is conditioned on the result of said request for agreement.

[0020] Advantageously, this embodiment allows diagnostic data to be sent based on the result of a request for approval submitted to a user / customer. This request for approval can present the diagnostic data in detail to the user to inform their decision. Thus, the user retains control over the diagnostic data transmitted to the operator.

[0021] The various modes or embodiments mentioned above can be added independently or in combination with each other to the supply process defined above.

[0022] The invention also relates to a device for supplying at least one piece of data, said supply device being located within a first computer network and characterized in that it comprises: - a receiving module from an electronic device located within a second computer network of a request to execute a command capable of obtaining said at least one piece of data; - a module for obtaining execution rights for said command; - a command execution module and a command issuance module said at least one piece of data obtained for said electronic device.

[0023] The term module can refer to a software component, a hardware component, or a set of hardware and software components. A software component itself corresponds to one or more computer programs or subprograms, or more generally to any element of a program capable of implementing a function or set of functions as described for the modules concerned. Similarly, a hardware component corresponds to any element of a hardware assembly capable of implementing a function or set of functions for the module concerned (integrated circuit, smart card, memory card, etc.).

[0024] According to a particular embodiment of the invention, a supply device as described above is included in a mobile terminal (for example, a smart terminal or a smartphone) or a home gateway or a connected object.

[0025] The invention also relates to a computer program comprising instructions for implementing the above method according to any one of the particular embodiments described above, where said program is executed by a processor. The method can be implemented in various ways, including in hardwired or software form. This program can use any programming language and be in the form of source code, object code, or code intermediate between source and object code, such as in a partially compiled form, or in any other desirable form.

[0026] The invention also relates to a computer-readable recording or information medium containing instructions for a computer program as described above. The aforementioned recording media can be any entity or device capable of storing the program. For example, the medium may include a storage means, such as a ROM, for example a CD-ROM or a microelectronic circuit ROM, or a magnetic recording means, for example a hard drive. Furthermore, the recording media may be a transmissible medium such as an electrical or optical signal, which can be transmitted via an electrical or optical cable, by radio, or by other means. The programs according to the invention can, in particular, be downloaded from a network such as the Internet.

[0027] Alternatively, the recording media may correspond to an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in the execution of the process in question.

[0028] This supply device and computer program have characteristics and advantages similar to those described above in relation to the supply method.

[0029] 4. List of figures

[0030] Other features and advantages of the invention will become more apparent upon reading the following description of particular embodiments, given by way of simple illustrative and non-limiting examples, and the accompanying drawings, among which:

[0031] [Fig-1] Fig. 1 illustrates an example of an implementation environment according to a a particular embodiment of the invention,

[0032] [Fig.2] Fig.2 illustrates the hardware architecture of a device configured for to implement the supply process according to a particular embodiment of the invention,

[0033] [Fig.3] Fig.3 illustrates steps in the supply process according to a first mode particular implementation of the invention.

[0034] 5. Description of an embodiment of the invention

[0035] Fig. 1 illustrates an example of an implementation environment for the invention according to a particular embodiment of the invention.

[0036] Figure 1 represents a smart mobile terminal 102 (smartphone) belonging to user U1 within a local area network 100. The local area network 100 is interconnected with a telecommunications network 105 (for example, a WAN for Wide Area Network) via a gateway 101. Such a gateway is, for example, a residential modem-router gateway. The mobile terminal 102 can thus access services offered by the server 106. The server 106 is, for example, a diagnostic server operated by the telecommunications provider of user U1.

[0037] Typically, the terminal 102 comprises an audio acquisition and playback device associated with a loudspeaker and a microphone, a screen (touchscreen or not), a processor, and memory in which software is loaded, including instructions to be executed by the processor. The terminal 102 further comprises at least one communication interface, such as a Wi-Fi or Bluetooth network interface or an interface with a cellular data network, for example a 3G, 4G, or 5G network, enabling it to send and receive messages over a communication network.

[0038] Terminal 102 further includes a supply device according to the invention and is therefore capable of performing said supply process.

[0039] The local network 100 also includes a plurality of terminals, for example a camera 103 and / or a computer 104.

[0040] Figure 2 illustrates the hardware architecture of a DISP device configured to implement the supply method according to a particular embodiment of the invention. In the embodiment described herein, this device has the hardware architecture of a mobile terminal. It includes, in particular, a PROC processor, a RAM MV, a ROM MEM, and a non-volatile flash memory MF. Such components are known per se and are not described in further detail here. The ROM constitutes a storage medium according to the invention, readable by the PROC processor, on which a computer program PG according to the invention is stored. This program comprises instructions for implementing the steps of the supply method as described above when the program is executed by the PROC processor.At initialization, the code instructions of the computer program PG are, for example, loaded into memory before being executed by the processor PROC. The processor PROC of the processing unit UT implements, in particular, the steps of the supply process according to any one of the specific embodiments described in relation to Figures 1 and 3, according to the instructions of the computer program PG.

[0041] The DISP device also includes a RECV receiving module capable of receiving, from a second terminal located within a second computer network, for example server 106, a request to execute a command, alternatively the command itself, capable of obtaining at least one diagnostic data from network 100 and more particularly from the terminals connected to it (camera 103, computer 104, etc.).

[0042] The DISP device further includes an OBT acquisition module capable of obtaining execution rights for the command received via the RECV module. The rights are obtained, for example, from a memory location (e.g., MV or MEM of the DISP device). Alternatively, the rights can be obtained from another terminal associated with or connected to the DISP device.

[0043] The DISP device also includes an EXEC execution module for the command received via the RECV module according to the rights obtained via the OBT module.

[0044] In addition, the DISP device includes an SND module capable of transmitting the result of the execution of the command, i.e. the diagnostic data(s), to the second terminal (for example, server 106).

[0045] Figure 3 illustrates steps in the supply process according to a particular embodiment of the invention. Figure 3 uses the same environment as that described in support of Figure 1.

[0046] During a first step E10, the server 106 initiates a communication to the terminal 102. The server 106 executes a diagnostic service operated by the telecommunications operator of the user Ul, that is to say the operator which provides access to the Internet through the home gateway 101. Note that the communication between the server 106 and the terminal 102 is made for example via a Wi-Fi or cellular connection (3G, 4G, 5G, 6G, etc.).

[0047] During this communication, server 106 sends a request to execute a command to terminal 102.

[0048] Alternatively or cumulatively, server 106 issues the command to be executed by terminal 102.

[0049] Communication is, for example, established between server 106 and terminal 102 via the RCS (Rich Communication Suite) rich messaging protocol.

[0050] Communication can also be established between the server 106 and a companion application running on the terminal 102. The companion application is, for example, an Android® or iOS® application developed by the operator and offering services to the user U1 related to their home network and / or their Internet access. The companion application allows, for example, the configuration / setting up of the local / home network 100 via the gateway 101 and / or dedicated terminals located within the network 101. The companion application also allows the user U1 to be guided through a diagnostic process.

[0051] Obviously, the control of network 101 by user U1 via the companion application requires prior authentication of user UL. Authentication is performed, for example, through a human-machine interface rendered (graphically and / or audibly) by terminal 102 as a human-machine interface for the companion application. Note that this authentication can be performed via a username / password, a biometric fingerprint, a session cookie, a certificate, or any other means capable of identifying the user Ul.

[0052] In the following description we assume that it is a companion application executed by terminal 102 which implements the supply method according to the invention.

[0053] During step E20, terminal 102, and more specifically the companion application, receives a request to execute an authentication-protected command. The command might be, for example, a command to retrieve diagnostic data from gateway 101, such as a list of terminals connected to it along with associated information (e.g., bandwidth used, transaction / connection history, IP (Internet Protocol) address, etc.) for each terminal in the list. This type of command requires prior authentication (authentication-protected command) because the results / information obtained from its execution may be sensitive and must not be disclosed to malicious actors.

[0054] During step E20 / E21 the companion application obtains, for example from an internal memory of terminal 102 or from an integrated security device (for example a secure element such as a smart card) or associated with terminal 102, the rights to execute the command protected by authentication.

[0055] Note that execution rights may correspond to authentication elements (e.g., an identifier / password) used by the user Ul to authenticate with the companion application.

[0056] Advantageously, obtaining command execution rights is done completely transparently for the user UL. Indeed, it is the authentication performed by user U1 with the companion application that enables this acquisition of rights. Thus, the command execution rights that allow obtaining diagnostic data are managed by terminal 102 on behalf of server 106.

[0057] Alternatively, the rights to execute the command are obtained from a human-machine interface of terminal 102 and / or the companion application, which is provided orally and / or graphically to the UL user

[0058] Once the execution rights and / or authentication elements to be used to execute the command have been obtained, the companion application executes it (E21). The command is, for example, a computer function of an API (API for Application Programming Interface) capable of querying gateway 101 or another terminal located in the local network 100. The command can also be a command capable of obtaining data from an internal memory of terminal 102.

[0059] According to a particular embodiment, the execution of the command by the companion application is conditioned on the result of a request for consent given vocally and / or graphically to the user U1 via a human-machine interface of the terminal 102 and / or the companion application.

[0060] The gateway receives the request from the companion application during step E31, then processes it and in response issues the requested diagnostic data (command results) during step E32.

[0061] Terminal 102, and more specifically the companion application, receives diagnostic data from gateway 101 during step E22.

[0062] According to a particular embodiment, once the diagnostic data has been obtained by the companion application, the latter provides it vocally and / or graphically to the user U1 via a human-machine interface of the terminal 102 and / or the companion application.

[0063] During step E23, the companion application retransmits the diagnostic data to server 106. The diagnostic data is received by server 106 during step E13. Once the diagnostic data is received, the server, and more specifically the diagnostic service, processes it and then determines / identifies the local network equipment(s) responsible for the network anomalies detected from network 100. Thus, after processing the data received during step E13, the diagnostic service can, for example, conclude that camera 103 (or computer 104) is infected with malware.

[0064] Note that the command's semantics can refer to a resource without fully specifying it. For example, the gateway present on local network 100 may not be identified as such. Indeed, the command can refer to any gateway located on the network in question (that is, regardless of its identifier). There is therefore a degree of genericity in the request. This can be written, for example, using regular expressions or a formalism that allows this genericity to be expressed (JSON, XML, ontology, etc.). Also, at the companion application level, there is an interpretation module capable of identifying a local resource, the corresponding API, and the authentication information to use to access it, based on the generic request (example: access to a lookup table, an LDAP directory, etc.).

Claims

Demands

1. Method of supplying, by a terminal (102) located within a first computer network (100), at least one piece of data, said method being implemented by said terminal and characterized in that the method comprises the following steps: - receiving (E20) from an electronic device (106) located within a second computer network (105) a request to execute a command capable of obtaining said at least one piece of data; - obtaining (E20, E21) a right to execute said command; - executing (E21) said command and sending (E23) said at least one piece of data obtained to said electronic device.

2. Method according to claim 1 characterized in that said at least one data point corresponds to at least one diagnostic data point.

3. Method according to claim 1 characterized in that the execution of said command is carried out according to the result of an agreement request returned to a user via a human-machine interface of said terminal.

4. The method according to claim 1 characterized in that the execution rights for said command are obtained following authentication of a user via a human-machine interface of a computer application executed by said terminal and in that said command is executed by said application.

5. Method according to claim 1 characterized in that said at least one data obtained is returned with a request for agreement to a user via a human-machine interface of said terminal and in that the transmission step is conditioned on the result of said request for agreement.

6. Device for supplying at least one piece of data, said supply device being located within a first computer network and characterized in that it comprises: - a receiving module (RECV) from an electronic device located within a second computer network of a request to execute a command capable of obtaining said at least one piece of data;

7.

8.

9. - a module for obtaining (OBT) an execution right for said command; - an execution module (EXEC) of said command and a transmission module (SND) of said at least one data obtained for said electronic device. Mobile terminal or home gateway or connected object comprising a supply device according to claim 6. Computer program comprising instructions for implementing the method according to any one of claims 1 to 5, when the program is executed by a processor. Computer-readable information carrier, and comprising instructions for a computer program according to claim 8.

Citation Information

Patent Citations

  • Maintenance / diagnosis data storage server

    US20040268151A1

  • Systems and methods for access point device recovery using mobile devices

    US20220408254A1