IP Library › Granted Patent US 11,924,211
Granted Patent B2
US 11,924,211 · App. 17/337,333 · Granted Mar 5, 2024

Computerized device and method for authenticating a user

Inventor: Christophe Guionneau (Grenoble, FR)
Assignee: BULL SAS
H04L63/102H04L63/04H04L63/0823H04L63/083
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,924,211
App. No.
17/337,333
Granted
Mar 5, 2024
Kind
B2
Abstract

The invention relates to a device and a method for authenticating a user utilizing an internet access client ( 10 ) for accessing remote resources of a computer infrastructure, said access comprising a first authentication ( 130 ) of the internet access client ( 10 ) and a second authentication ( 140 ) of the user of the internet access client ( 10 ). The method includes sending ( 132 ), to a token security module ( 21 ), by the internet access client ( 10 ), a client certificate ( 220 ), said client certificate ( 220 ) being associated with items of identification information of the internet access client ( 10 ); and receiving ( 133 ), by the internet access client ( 10 ), an authentication token ( 210 ) generated by the token security module when the client certificate ( 220 ) sent has been verified by the token security module.

Claims (37)

1. A method for authenticating a user utilizing an internet access client for accessing remote resources of a computer infrastructure, said method comprising:

enrolling the internet access client, said enrolling comprising receiving, by the internet access client, of a client certificate associated with items of identification information of the internet access client and generated by a certificate server,

wherein the internet access client is executed on a computerized device;

a first authentication of the internet access client, said first authentication of the internet access client comprising

sending, by the internet access client, to said computer infrastructure, said client certificate associated with items of identification information of the internet access client;

receiving, by the internet access client, an authentication token generated by a token security module when the client certificate sent has been verified;

a second authentication of the user of the internet access client, said second authentication of the user of the internet access client comprising

sending, by the internet access client, to the computer infrastructure, data representing a security level of the second authentication of the user comprising the authentication token, user identification data and user authentication data, wherein said user identification data and said user authentication data are not included in the client certificate; and

receiving, by the internet access client, a permission for access to said remote resources of the computer infrastructure when the authentication token, the user identification data and the user authentication data have been verified;

wherein if the first authentication of the internet access client is unsuccessful, the user will be offered one or more methods of a third authentication of the user, having a higher security level than the security level of the second authentication.

2. The method for authenticating a user according to claim 1 , wherein if the first authentication of the internet access client is unsuccessful, the method initiates said enrolling the internet access client.

3. The method for authenticating a user according to claim 1 , further comprising, before the first authentication of the internet access client, establishing a secure channel between the internet access client and the computer infrastructure.

4. The method for authenticating a user according to claim 1 , wherein if the first authentication of the internet access client is unsuccessful, the user will be refused said access to the remote resources of the computer infrastructure.

5. The method for authenticating a user according to claim 1 , wherein the authentication token corresponds to a random code that can only be verified by the computer infrastructure.

6. The method for authenticating a user according to claim 1 , further comprising, after receiving the permission of access, establishing, by the internet access client, a remote access session to the remote resources of the computer infrastructure.

7. The method for authenticating a user according to claim 1 , wherein the computer infrastructure comprises at least one remote communications server that does not belong to a same local network as the internet access client.

8. The method for authenticating a user according to claim 1 , further comprising verifying a match between the user identification data and the identification information of the internet access client utilized by the user, and when these data do not match, the permission for said access to the remote resources of the computer infrastructure is not granted.

9. A computer program product comprising a non-transitory storage medium that comprises program code instructions which, when executed on a computerized device, implement a method for authenticating a user utilizing an internet access client for accessing remote resources of a computer infrastructure when said computer program product is executed on said computerized device, wherein said method comprises:

enrolling the internet access client, said enrolling comprising receiving, by the internet access client, of a client certificate associated with items of identification information of the internet access client and generated by a certificate server,

wherein the internet access client is executed on said computerized device;

a first authentication of the internet access client, said first authentication of the internet access client comprising

sending, by the internet access client, to said computer infrastructure, said client certificate associated with items of identification information of the internet access client;

receiving, by the internet access client, an authentication token generated by a token security module when the client certificate sent has been verified;

a second authentication of the user of the internet access client, said second authentication of the user of the internet access client comprising

sending, by the internet access client, to the computer infrastructure, data representing a security level of the second authentication of the user comprising the authentication token, user identification data and user authentication data, wherein said user identification data and said user authentication data are not included in the client certificate; and

receiving, by the internet access client, a permission for access to said remote resources of the computer infrastructure when the authentication token, the user identification data and the user authentication data have been verified;

wherein if the first authentication of the internet access client is unsuccessful, the user will be offered one or more methods of a third authentication of the user, having a higher security level than the security level of the second authentication.

10. A computerized device configured for authenticating a user for access to remote resources of a computer infrastructure, said computerized device comprising:

a hardware processor; and

an internet access client executed on said hardware processor configured to implement enrolling the internet access client, said enrolling comprising receiving, by the internet access client, of a client certificate associated with items of identification information of the internet access client and generated by a certificate server;

a first authentication of the internet access client, said first authentication of the internet access client comprising

sending, to said computer infrastructure, said client certificate associated with items of identification information of the internet access client;

receiving, an authentication token generated by a token security module when the client certificate sent has been verified;

a second authentication of the user of the internet access client, said second authentication of the user of the internet access client comprising

sending, to the computer infrastructure, data representing a security level of the second authentication of the user comprising the authentication token, user identification data and user authentication data, wherein said user identification data and said user authentication data are not included in the client certificate;

receiving, a permission for access to remote resources of the computer infrastructure when the authentication token, the user identification data and the user authentication data have been verified;

wherein if the first authentication of the internet access client is unsuccessful, the user will be offered one or more methods of a third authentication of the user, having a higher security level than the security level of the second authentication.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 16, 2022
From: EVIDIAN
To: BULL SAS
Reel/Frame 060838/0884 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2021
From: GUIONNEAU, CHRISTOPHE
To: EVIDIAN
Reel/Frame 056420/0288 →
Priority Claims (1)
FR 2005977 · Jun 8, 2020 · national
Continuity (1)
Related Publication 20210385225A1 · Dec 9, 2021