Method for recovery of an authentication code required by a control terminal and corresponding system
11 claims: 2 independent, 9 dependent
- 1-13REVENDICATIONS 1. Procédé de récupération à distance par un terminal (10) d’au moins un code d’authentification requis par une borne de contrôle (30a, 30b, 30c), le procédé comprenant :- l’identification (A) par un terminal (10) de tout ou partie des bornes de contrôle (30a, 30b, 30c) situées dans une zone géographique prédéfinie ;- l’envoi d’une requête (B) par le terminal (10) à un serveur distant (20) selon un premier protocole de communication, ladite requête étant une demande d’au moins un code d’authentification correspondant à au moins une des bornes de contrôle sélectionnée parmi les bornes de contrôles identifiées (30a, 30b, 30c) ;- à réception de ladite requête par le serveur (20), interrogation (C) par le serveur d’une table (220) mémorisée dans une base de données (22), ladite table (220) comprenant une liste de bornes de contrôle associées à des codes d’authentification respectifs ;- si la borne de contrôle sélectionnée et le code d’authentification correspondant sont mémorisés dans la table (220) : i) extraction (D) par le serveur (20) du code d’authentification associé à la borne de contrôle sélectionnée ;ii) envoi par le serveur (20) du code d’authentification extrait au terminal (10) selon le premier protocole de communication ;et iii) envoi par le terminal (F) dudit code d’authentification correspondant à ladite borne de contrôle sélectionnée, via un deuxième protocole de communication.
- 2Procédé selon la revendication 1, dans lequel la borne de contrôle (30a, 30b, 30c) est un point d’accès à un réseau partagé (3), le code d’authentification étant requis par le point d’accès pour autoriser l’accès du terminal (10) audit réseau partagé (3).
- 3Procédé selon l’une des revendications 1 ou 2, dans lequel le deuxième protocole de communication est compatible avec une des normes de radiocommunication sans fil ou filaire existantes.
- 4Procédé selon l’une des revendications 1 à 3, dans lequel le premier protocole de communication est compatible avec une technologie radio de bande ultra-étroite.
- 5Procédé selon l’une des revendications 1 à 4, dans lequel l’étape d’identification par le terminal (10) des bornes de contrôle (30a, 30b, 30c) comprend une phase de découverte de tout ou partie des bornes de contrôle (30a, 30b, 30c) situées dans la zone géographique environnante du terminal (10), et une étape de récupération de l’identifiant d’au moins une des bornes de contrôle (30a, 30b, 30c) découvertes.
- 6Procédé selon l’une des revendications 1 à 5, dans lequel l’étape d’identification par le terminal (10) des bornes de contrôle (30a, 30b, 30c) peut en outre comprendre des étapes de :- géolocalisation du terminal (10) via un module de géolocalisation embarqué dans le terminal (10) ;- recherche dans une liste de bornes de contrôle mémorisées dans une base de données couplée au terminal, d’au moins une borne de contrôle se trouvant dans une zone géographique environnante du terminal.
- 7Procédé selon l’une des revendications 1 à 6, comprenant en outre une étape de vérification de conditions supplémentaires associées à la borne de contrôle sélectionnée pour l’envoi au terminal (10) du code d’authentification correspondant.
- 8Procédé selon l’une des revendications 1 à 7, dans lequel chaque borne de contrôle (30a, 30b, 30c) est identifiée par son adresse MAC ou son SSID.
- 9Système de récupération à distance d’au moins un code d’authentification, comprenant :- un serveur (20) distant couplé à une table (220) mémorisée dans une base de données (22) et comprenant une liste de bornes de contrôle associées à des codes d’authentification respectifs ;- au moins une borne de contrôle (30a, 30b, 30c) ;- un terminal (10) couplé à un premier module de communication (11) apte à échanger avec le serveur (20) distant selon un premier protocole de communication, et couplé à un deuxième module de communication (12) apte à échanger avec une borne de contrôle selon un deuxième protocole de communication ;ledit terminal (10) étant apte à : - identifier tout ou partie des bornes d’accès (30a, 30b, 30c) dans une zone géographique prédéfinie ;- envoyer une requête au serveur (20) distant via le premier module de communication (11) pour demander au moins un code d’authentification requis par au moins une borne de contrôle sélectionnée parmi les bornes de contrôles (30a, 30b, 30c) identifiées ;- envoyer le code d’authentification requis à la borne de contrôle sélectionnée via le deuxième module de communication (12) ;ledit serveur étant apte à : - à réception de la requête du terminal, interroger la table et extraire le code d’authentification associée à la borne de contrôle sélectionnée ;- envoyer le code d’authentification extrait au terminal selon le premier protocole de communication.
- 10Système selon la revendication 9, dans lequel l’un au moins des premier et deuxième modules est intégré dans le terminal.
- 11Système selon la revendication 9 ou 10, dans lequel le premier module de communication (11) met en œuvre tout ou partie des étapes du procédé de récupération selon l’une des revendications 1 à 8.
Independent claims11
86 paragraphs, as filed
-1 PROCEDURE FOR RECOVERING AN AUTHENTICATION CODE REQUIRED BY A CONTROL TERMINAL AND CORRESPONDING SYSTEM
Technical area
The present invention relates to the field of communication systems and relates more specifically to a method and to a system for recovering an authentication code required by a control terminal, such as an access point to a network. sharing.
State of the prior art
In general, the connection of a terminal or any other device to a computer network, such as for example the Internet network or a shared local network, via an access point or gateway, first goes through an authentication procedure or identification of the terminal with this access point. Such an access point, generally in the form of a box (or "set-top box" in English terminology) or of a card integrated in a router or a modem for example, therefore serves as an interface to authorize or not the terminal to access the computer network.
Such an access point can in particular be affiliated with a wired or wireless community network meeting the specifications of standards such as for example IEEE 802.11 (better known under the name of Wi-Fi® for “Wireless Fidelity” according to the English terminology). , or IEEE 802.15 (better known under the name Bluetooth®), or IEEE 802.16 (better known under the name WiMAX® for “Worldwide Interoperability for Microwave Access”), or RFID (acronym for "Radio Frequency IDentification) or CPL (acronym for" power line carrier ").
For example, in the case of a Wi-Fi access point (also called a Wi-Fi hotspot or Wi-Fi hotspot), the terminal authentication procedure results in particular by sending a authentication by the terminal at the Wi-Fi access point. This authentication code can be in the form of a secure key (for example of the WEP type for “Wired Equivalent Privacy” or of the WPA type “Wi-Fi Protected Access ») Or in the form of an identifier followed by a password.
In practice, to connect to the shared network via a Wi-Fi access point, the terminal, such as a mobile phone equipped with a module capable of communicating with
-2 the Wi-Fi access point, first initiates a discovery phase of all the Wi-Fi access points located near the terminal. In fact, in the context of Wi-Fi radiocommunication technology, each access point periodically transmits a frame containing a beacon (or "beacon" in English) making it possible to identify it among the other access points of the system. network. Once this discovery phase has been completed, the terminal or the user chooses the access point to which he wishes to connect from the list of discovered access points. Then begins an exchange between the terminal and the chosen access point in which the access point asks the terminal for the corresponding authentication code, for example a WP A type secure key, code that the user will have previously acquired. from the owner of the access point.
For example, some service providers offer free access to all of their Wi-Fi access points subject to prior registration, generally via the Internet. The authentication code, generally in the form of an identifier and a password, is then valid for all access points belonging to the same provider. However, some users sometimes forget to make such a registration. As a result, when traveling, the user therefore finds himself without an authentication code to connect to one of the supplier's access points, and therefore unable to access the Internet network via his terminal.
In addition, the user of the mobile telephone may find himself in a geographical area without a Wi-Fi access point for which he has an authentication code. The user may also have forgotten to memorize these authentication codes or may be in possession of authentication codes which are no longer valid, in the case of codes with limited validity for example. The user is then unable to connect to the Internet network via these Wi-Fi access points.
Disclosure of the invention
The present invention therefore proposes to remedy these situations, by proposing an alternative solution for recovering such an authentication code. The object of the invention is in particular to extend the possibilities of retrieving an authentication code corresponding to an access point to the Internet network.
-3To this end, the present invention relates to a method for remotely retrieving by a terminal at least one authentication code required by a control terminal, such as an access point to a shared network.
According to the invention, this method comprises:
- identification by the terminal of all or part of the control terminals located in a predefined geographical area;
sending a request by the terminal to a remote server according to a first communication protocol, this request being a request for at least one authentication code corresponding to at least one control terminal selected from among the control terminals identified;
on receipt of the request by the server, interrogation by the server of a table stored in a database, this table comprising a list of control terminals associated with respective authentication codes;
- if the selected control terminal and the corresponding authentication code are stored in the table:
i) extraction by the server of the authentication code associated with the selected control terminal;
ii) sending by the server of the extracted authentication code to the terminal according to the first communication protocol; and iii) sending by the terminal of said authentication code corresponding to said selected control terminal, via a second communication protocol.
The recovery process is therefore likened to an exchange mechanism, the purpose of which is authentication in the context of access to a shared network. The particularity of this recovery method being that the communication protocol used between the terminal and the control terminal is different from the communication protocol used between the terminal and the remote server. The first and second communication protocols, for example, meet very distinct communication standards. In other words, the terminal uses two different communication channels, one to exchange with the control terminal, the other to exchange with the remote server.
It is therefore understood that this recovery method can be initiated at any time by the terminal, and in particular at the time of the authentication process with the control terminal. The terminal can retrieve at any time an authentication code required by a control terminal already known or newly discovered.
Of course, the authentication code according to the present invention is not only limited to a secure key or to an identifier, and can in particular include all the information that the terminal must provide to the control terminal.
By terminal is meant any device coupled to hardware and / or software means for communicating with the control terminal and the remote server according to the respective communication protocols. Such a terminal can be fixed or mobile, and can for example be in the form of a mobile station, a computer, a mobile phone, a smartphone, a tablet, a card, etc.
The hardware and / or software means can be integrated directly into the terminal or can be external modules connected to the terminal, for example via a connection conforming to the USB standard (acronym for “Universal Serial Bus”). For example, these hardware and / or software means may be in the form of a hardware key (commonly referred to as a “dongle”) formed of integrated circuits coupled to a radio antenna compatible with one of the wireless radiocommunication technologies. These hardware and / or software means can also be a network card compatible with one of the existing communication technologies.
The terminal, the remote server and the control terminal can be located in different geographical areas, for example in different buildings, on different floors, or even separated by a few meters or even more.
The control terminal can be a point of access to a computer network such as the Internet, a company network, or any other local network, but can also be a terminal for checking and authorizing access to a building.
According to a particular embodiment, the control terminal is an access point to a shared network, the authentication code being required by the access point to authorize access by the terminal to said shared network.
Preferably, the network to which the remote server is integrated is different from the network to which the access point is affiliated, for example in terms of infrastructure and / or in terms of communication technology implemented. In a particular case, the network to which the access point belongs may comply with a medium-range high-speed communication technology, a hundred meters for example, while the network to which the remote server belongs may comply with a communication technology allowing only long-range low-speed communications, of the Ultra Narrow Band type, with a range of several tens of kilometers for example. Likewise, the server may be affiliated with a private local area network and the control terminal may be affiliated with a shared community network.
Advantageously, the second communication protocol is compatible with one of the existing radiocommunication standards, which can be wireless or wired, such as for example Ethernet, the group standards IEEE 802.11 (Wi-Fi), IEEE 802.15 (Bluetooth, ZigBee), IEEE 802.16 (WiMAX), RFID, Powerline, NFC (near field communication technology), etc.
In a preferred embodiment, the first communication protocol is compatible with ultra-narrowband radio technology.
Such ultra-narrow band radio technology is better known by the acronym UNB for "Ultra-Narrow Band". This UNB technology uses in particular the frequency bands free of rights (that is to say that does not require a request for prior authorization from the authorities) to transmit on a very narrow spectrum data intended for or coming from devices connected. It allows in particular low-speed wireless radio communications (typically of the order of lOb / s to lkb / s) over long distances (in particular up to 40km in free field), and is particularly well suited for the realization of Machine-to-Machine (M2M) or “Internet of Things” type low-speed communication network. An example of a communication system implementing such UNB technology is described in particular in the international patent application published under the number WO 2013/068559.
In practice, the step of identification by the terminal of the control terminals can include a phase of discovery of all or part of the control terminals located in
-6the surrounding geographic area of the terminal, and a step of retrieving the identifier of at least one of the control terminals discovered.
Of course, the extent of the geographical area depends on the means implemented to initiate this discovery phase. For example, the range of communication modules conforming to one of the standards of the IEEE 802.11 group can be around one hundred meters.
All of the surrounding control terminals can be obtained by a geolocation process, by mapping, or even by listening to beacons sent by each of the control terminals in accordance with one of the wireless radiocommunications standards.
Thus, the step of identification by the terminal of the control terminals can also comprise steps of:
- geolocation of the terminal via a geolocation module embedded in the terminal;
- Search in a list of control terminals stored in a database coupled to the terminal, for at least one control terminal located in a surrounding geographic area of the terminal.
According to one variant, the method described above may further comprise a step of verifying additional conditions associated with the control terminal selected by the remote server for sending the corresponding authentication code to the terminal.
In practice, each control terminal is characterized by an identifier which is specific to it. As a result, the table stored in the database coupled to the remote server preferably comprises a list of these identifiers as well as the associated authentication codes. Of course, this list may not be fixed, and it is possible to provide for an update of this list as a function of the control terminals newly discovered by the terminal.
For example, the identifier of a control terminal can be the MAC address (or “MAC address” in English), MAC being the acronym for “Media Access
-7Control ”). This MAC address assigned by 1ΊΕΕΕ is the unique physical identifier of the control terminal, generally a network card or a similar network interface. This MAC address is sometimes called an Ethernet address, UAA (for “Universally Administered Address”), BIA (for “Bumed-In Address”), etc. This MAC address has the advantage of being unique.
As a variant, the identifier of a control terminal can also be an identifier of the S SID type, the acronym standing for “Service Set Identifier”. This S SID corresponds to the name of the wireless network according to the IEEE 802.11 standard to which the control terminal is affiliated.
In another variant, the identifier of the device can also be defined by its geographical position, which can be obtained via geolocation means on board the terminal, for example.
The identifier can also be an IP address (acronym for “Internet Protocol”). This IP address is an identification number assigned to each device connected to a network. This IP address has the advantage of being unique when it is public.
In the case where the IP address is internal to a network, and is therefore not unique, just like an SSID, this identifier can be supplemented by an additional identifier, and in particular the geographical position mentioned above.
In practice, each control terminal can be identified in the table using one of the information listed above, namely its MAC address, its SSID, its IP address, its geographical position, or via a combination of all or part of this information.
In practice, in the absence of a MAC address of the control terminal to which the terminal wants to connect, the server can implement a method of discriminating the various control terminals located in a predefined geographical area. This method of discrimination can for example use the IP address and information relating to the geographical position of the control terminal selected by the terminal.
The invention also relates to a system for the remote recovery of at least one authentication code, comprising:
a remote server coupled to a table stored in a database and comprising a list of control terminals associated with respective authentication codes;
- at least one control terminal;
a terminal coupled to a first communication module able to exchange with the remote server according to a first communication protocol, and coupled to a second communication module able to exchange with a control terminal according to a second communication protocol.
In addition, the terminal is able to:
- identify all or part of the access points in a predefined geographical area;
sending a request to the remote server via the first communication module to request at least one authentication code required by at least one control terminal selected from among the identified control terminals;
- send the required authentication code to the selected control terminal via the second communication module.
In addition, the server is able to:
- on receipt of the request from the terminal, interrogate the table and extract the authentication code associated with the selected control terminal;
- send the extracted authentication code to the terminal according to the first communication protocol.
Advantageously, at least one of the first and second modules is integrated into the terminal.
Preferably, the first module implements all or part of the steps of the recovery method defined above.
Brief description of the drawings
Other characteristics and advantages of the invention will emerge clearly from the description which is given below, by way of indication and in no way limiting, with reference to the appended drawings, in which:
FIG. 1 is a partial schematic representation of the communication system implementing the recovery method according to one embodiment of the invention; and
FIG. 2 represents, by way of illustration, a flowchart of a few steps of the method according to one embodiment of the invention.
Detailed description of particular embodiments
FIG. 1 schematically represents an example of a communication system suitable for the implementation of a particular embodiment of the invention.
This system comprises in particular control terminals 30a, 30b, 30c affiliated with a shared network 3. These control terminals 30a, 30b, 30c are distinct from each other and constitute entry doors to the shared network 3. In particular, each of the control terminals 30a, 30b, 30c serves as an interface to authorize or not access to the shared network 3. In general, each of the control terminals comprises hardware and / or software communication means 32a, 32b, 32c for communicating with a terminal according to a predefined communication protocol. In addition, in general, access to the shared network 3 is conditioned by an authentication code, for example a secure key, an identifier and a password, etc.
The system further comprises a remote server 20 coupled to a database 22 in which a table 220 is stored. This table 220 contains in particular a list of predefined control terminals, as well as the authentication codes associated with each of these listed control terminals. For example, the control terminals can be listed in table 220 in the form of an identifier which is specific to them. Control terminals can also be listed in table 220 as a combination of useful information to discriminate one control terminal from another control terminal. In general, the remote server 20 also integrates communication hardware and / or software means 21 for communicating with a terminal according to another communication protocol.
Furthermore, the system further comprises a terminal 10, for example a mobile telephone, coupled to communication modules 11, 12 adapted to ensure
-10 data exchanges between the remote server 20 on the one hand and the control terminals 30a, 30b, 30c on the other hand, according to the respective communication protocols.
In the following, the invention will be described in the particular case where the control terminals 30a, 30b, 30c are affiliated with a wireless community network conforming to the specifications of the Wi-Fi standard, and where the remote server 20 is compatible with a radio technology known as UNB (for "Ultra Narrow Band").
The terminal therefore comprises a first radio communication module 11 compatible with the UNB technology to communicate with the remote server according to the protocol defined by this UNB technology, and a second radio communication module 12 compatible with the Wi-Fi standard to communicate with the devices. Wi-Fi terminals according to the Wi-Fi communication protocol.
In the particular context of such a network, each Wi-Fi control terminal 30a, 30b, 30c (which will be referred to hereinafter as Wi-Fi terminal) periodically emits a signal (or beacon) to indicate its presence, and to broadcast information such as its radio characteristics and its own identifier which differentiates it from other access points in the network. Such an identifier is commonly called a MAC address.
The terminal 10 to connect to the Wi-Fi network, initiates via its second communication module 12, a phase of discovery of the Wi-Fi terminals 30a, 30b, 30c which are within its reach, by listening to these beacons.
Of course, this discovery phase is not mandatory insofar as the terminal can for example be coupled to a database containing a list of Wi-Fi hotspots listed according to their location. In this scenario, the terminal can quite simply use a geolocation tool to determine its geographical position and query this database to establish all the WiFi terminals located nearby.
Once the Wi-Fi hotspots have been identified (step A of FIG. 2), the terminal 10 or the user selects the Wi-Fi hotspot to which he wishes to connect from among the WiFi hotspots identified 30a, 30b, 30c. The terminal 10 then executes the steps illustrated in FIG. 2 to retrieve the associated authentication codes from the remote server 20.
-11 to one or more Wi-Fi terminals identified 30a, 30b, 30c. In particular, the terminal 10 sends (step B) a request to the remote server 20 via the first communication module 11. On receipt of this request, the remote server 20 interrogates (step C) the table 220 to determine whether the terminal (s) Wi-Fi selected by terminal 10 are stored in table 220 and if so, extract (step D) and send (step E) to terminal 10 the corresponding authentication codes. Once these codes have been received, the terminal 10 can send (step F) the authentication code corresponding to one of the Wi-Fi hotspots selected via the second communication protocol.
Of course, the sending of authentication codes by the server to the terminal may be subject to special conditions such as, for example, the acceptance of advertising, payment, etc.
In another particular embodiment, the control terminals may or may not be used to authorize access to a building, or even to open a building door by means of an access code. In this particular case, the terminal, for example a badge or even a smartphone, obviously integrates different means of communication with the remote server and the control terminals according to the respective communication protocols. For example, the terminal can integrate an RFID antenna to communicate with the control terminals and an antenna according to UNB technology to communicate with the remote server. Conventionally, the RFID control terminal can periodically emit a signal containing its unique identifier number, for example defined according to the EPC standard (acronym for “Electronic Product Code”). As in the previous case, the terminal retrieves this identification number and interrogates the remote server to retrieve the corresponding access code. On receipt of the request, the remote server consults its database and after checking the registered authorizations can decide whether or not to return the corresponding access code to the terminal.
It is therefore understood that the solution of the invention can be implemented independently of the size of the network. This solution can in particular be applied in an industrial situation but also at a private home. Thus, it is possible to implement the method of the invention to ensure the exchange of information between a domestic appliance and a maintenance service. For example, the household appliance, such as a washing machine, a cooking appliance, etc. can be equipped with the various communication modules described above allowing it to retrieve from the server
-12distant from the invention, an authentication code for automatically connecting to an available Wi-Fi terminal. This connection can in particular be useful for exchanging information, such as breakdown, fault, necessary updating of the device, etc., with a remote maintenance service or a terminal of the owner of the device.
Of course, it will be understood that all or part of the steps presented above can be executed automatically by the terminal.
It therefore emerges from the foregoing that the alternative solution proposed above offers the user of a terminal the possibility of connecting to the Internet network via the use of two different communication channels, one for remote retrieval. and at any time the necessary authentication codes, the other to connect to the desired network. For example, the first communication channel may conform to UNB technology optimized for long distance low-speed communications and the second communication channel may conform to one of the high-speed wireless radio communication standards such as than Wi-Fi. Thus, the terminal can retrieve the authentication code at any time to connect to a Wi-Fi hotspot. In addition, the recovery of such an authentication code can be carried out remotely, namely far from the remote server, since the UNB technology allows communications over distances of several tens or even hundreds of kilometers.
2 sheets
Sheet 1 Sheet 2
8 members in 7 offices; this record represents the family
Members8
| Document | Office | Kind | |
|---|---|---|---|
| FR3022665A1 | France | A1 | |
| WO2015197563A1 | World Intellectual Property Organization (WIPO) | A1 | |
| FR3022665B1This record | France | B1 | |
| AU2015279373A1 | Australia | A1 | |
| EP3158708A1 | European Patent Office (EPO) | A1 | |
| US2017118644A1 | United States of America | A1 | |
| CN106664295A | China | A | |
| JP2017530571A | Japan | A |
13 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Lien (pledge) constitutedGC | GC | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Transmission of propertyTP | TP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Publication of the preliminary search reportPLSC | PLSC | |
| Fee paymentPLFP | PLFP |
Numbers
- Publication
- 3022665
- Application
- 1455817
Titles2
- French
- PROCEDE DE RECUPERATION D'UN CODE D'AUTHENTIFICATION REQUIS PAR UNE BORNE DE CONTROLE ET SYSTEME CORRESPONDANT
- English
- METHOD FOR RECOVERING AN AUTHENTICATION CODE REQUIRED BY A CONTROL TERMINAL AND CORRESPONDING SYSTEM
Classification
- CPC, 6
- H04L63/08
- H04L63/18
- H04W12/06
- H04L63/083
- H04L63/0876
- H04L63/107
- IPC, 1
- G06F21 44
