Method and system for framed access of at least one external operator to a set of operations of a computing infrastructure
Abstract
Method and system for supervised access by at least one external operator to a set of operations of a computing infrastructure The invention relates to a method and a system for supervised access by at least one external operator to a set of operations provided by a remote computing infrastructure to a client, via a communications network. The access system is operated by a trusted operator, different from said external operator. This method comprises receiving (40) a request from said trusted operator to set up a computer session shared with the external operator, instantiating (44) a server and a terminal service for remote connection to said server, generating (46) an access gateway to said terminal service and providing (48-56) access to said terminal service, via said access gateway, to the operator of confidence and to the external operator. Following receipt (58) of a request to stop said shared computer session, the trusted operator and the external operator are disconnected (60) and the terminal service on the server is stopped (64). Figure for the abstract: Figure 3

Term
15.3 yearsto projected expiry
Projected expiry 29 December 2041, counted from filing; an application has no term until it is granted.
- Priority and filed
- Published
- Today
- Projected expiry
10 claims: 3 independent, 7 dependent
- 1Revendications [Revendication 1] Procédé d’accès encadré d’au moins un opérateur externe à un ensemble d’opérations fournies par une infrastructure de calcul distante à un client, via un réseau de communications, le procédé étant caractérisé en ce qu’il est mis en œuvre par au moins un processeur de calcul d’un système d’accès encadré opéré par un opérateur de confiance, différent dudit opérateur externe, l’opérateur de confiance ayant un niveau de droits d’accès supérieur au niveau de droits d’accès dudit opérateur externe, et comprend des étapes de :- réception (40) d’une requête dudit opérateur de confiance (10) de mise en place d’une session informatique partagée avec l’opérateur externe (8), - instanciation (44) d’un serveur exécutant un système d’exploitation, implémentant un service de terminal de connexion à distance audit serveur, ledit serveur étant configuré pour accéder audit ensemble d’opérations fournies par ladite infrastructure de calcul distante audit client, - génération (46) d’une passerelle d’accès audit service de terminal, - fourniture (48-56) d’accès audit service de terminal, via ladite passerelle d’accès, à l’opérateur de confiance et à l’opérateur externe ;- suite à une réception (58) d’une requête d’arrêt de ladite session informatique partagée en provenance dudit opérateur de confiance, déconnexion (60) dudit opérateur de confiance et dudit opérateur externe du service de terminal, et - arrêt (64) de l’exécution du service de terminal sur ledit serveur.
- 2[Revendication 2] Procédé selon la revendication 1, dans lequel l’étape de fourniture d’accès audit service de terminal comporte la transmission (48) d’une adresse de connexion à l’opérateur de confiance.
- 3[Revendication 3] Procédé selon l’une des revendications 1 ou 2, comportant, suite à la réception (40) d’une requête dudit opérateur de confiance de mise en place d’une session informatique partagée, une étape (42) d’authentification dudit opérateur de confiance et d’autorisation d‘accès suite à ladite authentification.
- 4[Revendication 4] Procédé selon la revendication 1 à 3, dans lequel l’étape de fourniture (48-56) d’accès audit service de terminal comporte une authentification (54) de l’opérateur externe, la fourniture d’accès audit opérateur externe étant conditionnée à la réussite de l’authentification.
- 5[Revendication 5] Procédé selon l’une quelconque des revendications 1 à 3, comportant en outre, suite à la réception (58) de la requête d’arrêt de ladite session informatique partagée, un archivage (62) de l’ensemble des actions effectuées par l’opérateur externe et l’opérateur de confiance durant ladite session.
- 6[Revendication 6] Procédé selon l’une quelconque des revendications 1 à 5, dans lequel à l’étape d’instanciation, le système d’exploitation exécuté par ledit serveur est un système d’exploitation non modifiable.
- 7[Revendication 7] Programme d’ordinateur comportant des instructions logicielles qui, lorsqu’elles sont exécutées par un dispositif électronique programmable, mettent en œuvre un procédé conforme aux revendications 1 à 6.
- 8[Revendication 8] Système d’accès encadré d’au moins un opérateur externe à un ensemble d’opérations fournies par une infrastructure de calcul distante à un client, via un réseau de communications, le système d’accès encadré étant opéré par un opérateur de confiance, différent dudit opérateur externe, l’opérateur de confiance ayant un niveau de droits d’accès supérieur au niveau de droits d’accès dudit opérateur externe, et le système comprenant au moins un processeur configuré mettre en œuvre des modules de:- réception d’une requête dudit opérateur de confiance (10) de mise en place d’une session informatique partagée avec l’opérateur externe (8), - instanciation d’un serveur (24) exécutant un système d’exploitation, implémentant un service de terminal de connexion à distance audit serveur, ledit serveur étant configuré pour accéder audit ensemble d’opérations fournies par ladite infrastructure de calcul distante audit client, - génération d’une passerelle d’accès (20) audit service de terminal, - fourniture d’accès audit service de terminal, via ladite passerelle d’accès (20), à l’opérateur de confiance et à l’opérateur externe ;- suite à une réception d’une requête d’arrêt de ladite session informatique partagée en provenance dudit opérateur de confiance, déconnexion dudit opérateur de confiance (10) et dudit opérateur externe (8) du service de terminal, et - arrêt de l’exécution du service de terminal sur ledit serveur.
- 9[Revendication 9] Système selon la revendication 8, comportant en outre un module d’authentification (16), configuré pour authentifier ledit opérateur de confiance et/ou ledit au moins un opérateur externe.
- 10[Revendication 10] Système selon la revendication 8 ou 9, comportant en outre des modules de connexion sécurisés par réseau virtuel privé, pour la connexion de l’opérateur de confiance et pour la connexion dudit au moins un opérateur externe.
Independent claims10
92 paragraphs, as filed
Description
Title of the invention: Method and system for supervised access by at least one external operator to a set of operations of a computing infrastructure
The present invention relates to a method and a supervised access system of at least one external operator to a set of operations provided by a remote computing infrastructure to a client, via a communications network. It also relates to associated computer program.
[0002] The invention lies in the field of computer system security, and more particularly the securing of operations and services provided by computer system infrastructures.
[0003] The infrastructure provision of remote computing and data storage devices is widely developed, generally known as “cloud computing”. Conventionally, such an infrastructure is provided by a service provider, the computing devices being managed by the service provider. A customer, for example a company, obtains a quantity of data storage and/or a computing capacity, accessible via a communication network (eg Internet).
[0004] In this context, there are increased problems of data security and of the risk of access without authorisation, potentially malicious, to the data or to the operations of the client.
[0005] The invention lies in this technological context of securing operations and services provided by cloud computing, to create a trust infrastructure (or "trusted cloud"). The notion of trust is linked to the guarantee of a level of security offered by a computer system.
[0006] In particular in the field of distributed calculations ("cloud computing"), one of the problems that may arise is the need to access operations or services operated for a client to provide support, resolution of problems encountered (computer support, debugging, etc.).
[0007] Conventionally, an operator with access rights of a higher level than a user's access rights, generally called the "administrator" level, connects to a computer system dedicated to a customer to such support operations.
[0008] In a trusted environment, with a high level of security, for example SecNumCloud level according to the classification of ANSSI ("National Agency for the Security of Information Systems") which defines the security of infor2 systems matics in France, such an access system is not sufficient.
To provide secure access to various operators to perform support actions in a computer system dedicated to a customer, it is known to set up a computer "bastion" aimed at protecting the computer system dedicated to the customer from external threats. , access to such a bastion being subject to a strong authentication barrier. However, if a malicious third party manages to recover the information necessary to pass such an authentication barrier, this third party has complete and unsupervised access to the system.
The object of the invention is to overcome the disadvantages of the aforementioned state of the art.
[0011] To this end, the invention proposes, according to one aspect, a supervised method of access by at least one external operator to a set of operations provided by a remote computing infrastructure to a client, via a network of communications. This method is implemented by at least one calculation processor of a supervised access system operated by a trusted operator, different from said external operator, the trusted operator having a level of access rights higher than the level of access rights of said external operator, and includes steps of:
[0012] - receipt of a request from said trusted operator to set up a computer session shared with the external operator,
- instantiation of a server executing an operating system, implementing a remote connection terminal service to said server, said server being configured to access said set of operations provided by said remote computing infrastructure to said client,
- generation of an access gateway to said terminal service,
- provision of access to said terminal service, via said access gateway, to the trusted operator and to the external operator;
- following receipt of a request to stop said shared computer session from said trusted operator, disconnection of said trusted operator and said external operator from the terminal service, and - termination of the execution of the terminal service on said server.
[0013] Advantageously, the framed access method provides a shared computer session to which access is granted on the one hand to the trusted operator and on the other hand to at least one external operator, which allows the trusted operator to control the actions of the external operator.
[0014] Advantageously, the provision of a connection terminal service to the remote server is ephemeral in the sense that it is provided only during a session. Thus, advantageously, security is increased.
The supervised access method according to the invention may also have one or more of the characteristics below, taken independently or in all technically possible combinations:
[0016] The step of providing access to said terminal service includes the transmission of a connection address to the trusted operator.
[0017] The method comprises, following receipt of a request from said trusted operator to set up a shared computer session, a step of authenticating said trusted operator and authorizing access following said authentication .
The provision of access to said terminal service includes authentication of the external operator, the provision of access to said external operator being conditional on the success of the authentication.
The method further comprises, following receipt of the request to stop said shared computer session, an archiving of all the actions performed by the external operator and the trusted operator during said session.
At the instantiation step, the operating system executed by said server is a non-modifiable operating system.
According to another aspect, the invention relates to a supervised access system for at least one external operator to a set of operations provided by a remote computing infrastructure to a client, via a communications network, the system supervised access being operated by a trusted operator, different from said external operator, the trusted operator having a level of access rights higher than the level of access rights of said external operator. The system includes at least one processor configured to implement modules of:
[0022] - receipt of a request from said trusted operator to set up a computer session shared with the external operator,
- instantiation of a server executing an operating system, implementing a remote connection terminal service to said server, said server being configured to access said set of operations provided by said remote computing infrastructure to said client,
- generation of an access gateway to said terminal service,
- provision of access to said terminal service, via said access gateway, to the trusted operator and to the external operator;
- following receipt of a request to stop said shared computer session from said trusted operator, disconnection of said trusted operator and of said external operator from the terminal service, and
- stopping the execution of the terminal service on said server.
According to one embodiment, the system further comprises an authentication module, configured to authenticate said trusted operator and/or said at least one external operator.
[0024]According to one embodiment, the system further comprises connection modules secured by virtual private network, for the connection of the trusted operator and for the connection of said at least one external operator.
The supervised access system is configured to implement the supervised access method briefly described above, in all its implementation variants.
According to another aspect, the invention relates to an information recording medium, on which are stored software instructions for the execution of a framed access method as briefly described above, when these instructions are executed by a programmable electronic device.
According to another aspect, the invention relates to a computer program comprising software instructions which, when they are executed by a programmable electronic device, implement a framed access method as briefly described above. .
Other characteristics and advantages of the invention will emerge from the description given below, by way of indication and in no way limiting, with reference to the appended figures, among which:
[0029] [Fig.l] [Fig.l] is a schematic representation of a framed access system according to one embodiment;
[0030] [Fig.2] [Fig.2] is a block diagram representative of a programmable electronic device suitable for executing a framed access method according to one embodiment;
[0031] [Fig.3] [Fig.3] is a flowchart of the main steps of an access method framed according to one embodiment.
[0032] The [Fig.l] schematically illustrates a global system 1 for access / sharing and modification of operations provided by a remote computing infrastructure, comprising a system 2 of framed access according to an embodiment of the invention .
The system 1 is represented in a partition into two logical zones, respectively a so-called production zone 4 and an administration zone 5.
In a variant, the production area 4 and the administration area 5 are also physically separated, in order to reinforce security.
[0035] The supervised access system 2 includes the administration area 5 and part of the production area 4.
This framed access system 2 aims to provide framed and secure access to a set of operations provided by a remote computing infrastructure to a client C, via a communications network, for example the Internet.
[0037] The term “set of operations provided” means one or more operation(s) or service(s) provided by the computing infrastructure to the client.
[0038] For example, the set of operations is executed by a virtual machine (or VM) of client 6, which runs in production area 4.
[0039] The supervised access system 2 allows access by at least one external operator 8 as well as a trusted operator 10 to perform an intervention (eg corrections, debugging, etc.) on the VM 6.
[0040] The term operator designates both a natural person (for example an employee of a company) or software with which a service account is associated which makes it possible to authenticate it in a unique way.
The trusted operator 10 is different from the external operator 8, the trusted operator having a level of access rights (or level of privilege) higher than the level of access rights of the external operator 8.
In a practical application scenario, the trusted operator 10 is a "trusted third party" operator and the external operator 8 is for example the supplier of the remote computing infrastructure on which the virtual machine is operated. client.
Each of the operators 8, 10 is able to connect to the administration zone 5, preferably via a virtual private network (or VPN) 12, 14, allowing secure, private and encrypted connections to be made from end to end. end.
The system 1 comprises, in the administration area 5, an authentication module 16, a shared computer session management module 18 and a module 20 implementing an access gateway to a remote terminal service. 22 connection to a server 24 in the production area 4.
The shared computer session management module 18 is adapted to cooperate with the modules 16 and 20 to implement a supervised access method as described in more detail below.
The remote terminal service 22 provides, in other words, a remote "office", in the computer sense, allowing access to all the functionalities of the server 24.
The server 24 is an ephemeral server, generated on request. This server 24 executes a non-modifiable or immutable operating system, such as for example MicroOS on Linux.
The server 24 also comprises modules 26, 28 comprising software tools, for example software code debugging tools allowing each of the operators 8, 10 to perform actions of support on the virtual machine (VM) 6.
The server 24 is configured to send commands to the virtual machine 6, for example using a secure communication protocol such as an SSH protocol (for "secure shell"), and commands to implement one or several services30.
[0050] Examples of commands placed in this context are commands that display the state of the virtual machine/container or modify the state of the virtual machine/container to modify its behavior (for example, correct the faulty behavior)
[0051] The modules 16, 18, 20 and 22 cooperate, as described in more detail below, to implement a method of providing supervised access from at least one external operator to a set of operations provided. by a remote computing infrastructure to a client.
The modules 16, 18, 20, 22 are for example made in the form of software instructions forming one or more computer programs, executable by a programmable electronic device such as a computer, as shown schematically in [Fig. 2].
The programmable electronic device 30 comprises at least one calculation processor 32, an electronic memory unit 34 of the RAM type, a non-transitory memory unit 35, an interface 36 for communication with remote devices, by a protocol of communication chosen, for example a wired protocol and/or a radio communication protocol, and an interface 38 of inputs/outputs, allowing input/reception of commands and display of results. The elements of the device 30 are adapted to communicate via a communication bus.
The calculation processor 32 is configured to implement the authentication module 16, the shared computer session management module 18 and the module 20 implementing an access gateway to a remote terminal service, the remote terminal service 22 being implemented by another programmable electronic device.
In one embodiment, the modules 16, 18, 20, and the module 22, implemented in the form of software instructions, form a computer program which, when executed by a programmable electronic device, implements a method of providing framed access according to the invention. These software instructions are also capable of being recorded on a non-transitory, computer-readable information recording medium. This computer-readable medium is, for example, a medium capable of storing electronic instructions and of being coupled to a bus of a computer system. By way of example, this medium is an optical disc, a magneto-optical disc, a ROM memory, a RAM memory, any type of non-volatile memory (for example EPROM, EEPROM, FLASH, NVRAM), a magnetic card or an optical card.
In a variant not shown, the modules 16, 18, 20 and 22 are each made in the form of programmable logic components, such as FPGAs (Field Programmable Gate Array), microprocessors, GPGPU components (of English General-purpose processing on graphies processing), or dedicated integrated circuits, such as ASICs (Application Specific Integrated Circuit
).
[0057] [Fig.3] is a flowchart of the main steps of a supervised access process by at least one external operator to a set of operations provided by a remote computing infrastructure to a client, according to a mode of achievement.
This process comprises the reception 40 by the module 18 of shared computer session management, of a request to set up a shared computer session with the external operator, coming from the trusted operator.
The method then comprises, preferably, a step 42 of authentication of authorization, consisting in verifying the identity of the applicant (trusted operator) before authorizing his access. This step is for example carried out by the authentication module 16. The implementation of an authentication makes it possible to increase the reliability of the system. Any known authentication mechanism, for example by password, can be implemented.
The method then comprises a step 44 of instantiating (ie creating and putting into working order) a server executing an operating system which is preferably an unmodifiable operating system and a service of connection terminal to this server, the server being configured to access a set of operations provided by said remote computing infrastructure to said client (for example, via VM 6)
For example, the terminal service is performed by implementing the RDP protocol (for Remote Desktop Server).
[0062] In addition, during the installation 44 of such a server, modules 26, 28 comprising software tools, for example software code debugging tools are also installed. on this server.
These software tools are for example provided for maintenance to be performed on the set of operations provided by a remote computing infrastructure to the customer.
Following a successful instantiation, the method further comprises a step 46 of generating an access gateway to the remote terminal service. For example, if the terminal service by the RDP protocol, the access gateway generated in step 46 is an RDP client.
Then, the method includes obtaining 48, via this access gateway, a network address of the remote terminal service, this network address being provided to the trusted operator 10.
For example, the network address is a web address or URL (for “Uniform Resource Locator”).
Subsequently, the trusted operator has the possibility of accessing the remote terminal service using this network address, via the access gateway set up.
The network address of the remote terminal service is also provided (step 50) to the external operator 8, for example by the trusted operator 10.
The external operator sends (step 52) a request for access to the remote terminal service, using the network address of the remote terminal service received. For example, the external operator connects to the access gateway.
The method then preferably comprises a step 54 of authentication and authorization of the external operator, similar to step 42 described above. Any known authentication mechanism, for example by password, can be implemented. Advantageously, in order to guarantee security, only an external operator explicitly declared, for example by a trusted operator, is thus authorized to connect to the system.
If the authentication of the external operator is validated, the access of this external operator to the remote terminal service is authorized (step 56).
[0072] Thus, shared access to the server via the remote terminal service is granted.
This access is supervised, any action by the external operator being able to be controlled by the trusted operator.
[0074] An implementation of actions of corrections/maintenance/debugging etc on the VM 6 of the client follows. For example, these actions include VM 6 status display actions (for, for example, debugging or monitoring), status modification (for, for example, correction or maintenance) .
The method for providing framed access then comprises a step 58 of receiving a request to stop said shared computer session from said trusted operator.
This request is followed by a disconnection 60 of the trusted operator and of the external operator of the terminal service.
An archiving 62, in an electronic memory unit, of all the actions carried out by the external operator and the trusted operator, is then carried out. Thus, all the actions performed during the shared computer session are memorized, for possible later inspection. Thus, the overall security of the system is further increased.
Finally, the method includes a stop 64 of the execution of the terminal service on the server by the module 20.
Thus, the remote terminal allowing access to the remote server is ephemeral, which further increases security by avoiding any possibility of subsequent reconnection by a malicious third party who may have retrieved information (network address, identifiers, words password) allowing him to assume the identity of one of the authorized operators.
The invention has been described above for supervised access to an external operator, but it is understood that it is possible to apply it, in a similar way, for supervised access to a plurality of separate external operators.
3 sheets
Sheet 1 Sheet 2 Sheet 3
Every citation, both ways
| Document | Relation | Office | Category | Cited during | Relevant claims |
|---|---|---|---|---|---|
| US2016234196A1 | Cites | United States of America | X | Search report | 1-10 |
| US9830430B2 | Cites | United States of America | A | Search report | 1-10 |
2 members in 2 offices
Members2
| Document | Office | Kind | |
|---|---|---|---|
| FR3131490A1This record | France | A1 | |
| EP4206917A1 | European Patent Office (EPO) | A1 |
5 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Fee paymentPLFP | PLFP | |
| Publication of the preliminary search reportPLSC | PLSC | |
| Fee paymentPLFP | PLFP |
Numbers
- Publication
- 3131490
- Application
- 2114605
Titles2
- French
- Procédé et système d'accès encadré d'au moins un opérateur externe à un ensemble d'opérations d'une infrastructure de calcul
- English
- Method and system for supervised access by at least one external operator to a set of operations of a computing infrastructure
Classification
- CPC, 3
- G06F9/45558
- H04L12/4641
- H04L63/0272
- IPC, 3
- H04L9 40
- G06F21 40
- G06F21 62