WO2021015686A1 - Système de sécurité pour réseau informatique - Google Patents

Système de sécurité pour réseau informatique Download PDF

Info

Publication number
WO2021015686A1
WO2021015686A1 PCT/TR2019/050711 TR2019050711W WO2021015686A1 WO 2021015686 A1 WO2021015686 A1 WO 2021015686A1 TR 2019050711 W TR2019050711 W TR 2019050711W WO 2021015686 A1 WO2021015686 A1 WO 2021015686A1
Authority
WO
WIPO (PCT)
Prior art keywords
mobile device
electronic message
computer network
service
network
Prior art date
Application number
PCT/TR2019/050711
Other languages
English (en)
Inventor
Ahmet TOPRAKCI
Emrah USLU
Fatih Dogan
Kadir Can TOPRAKCI
Kivanc BAKDI
Original Assignee
Peakup Teknoloji Anonim Sirketi
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Peakup Teknoloji Anonim Sirketi filed Critical Peakup Teknoloji Anonim Sirketi
Priority to EP19849049.2A priority Critical patent/EP3847564A1/fr
Publication of WO2021015686A1 publication Critical patent/WO2021015686A1/fr

Links

Classifications

    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/083Network architectures or network communication protocols for network security for authentication of entities using passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/72Subscriber identity
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/21Indexing scheme relating to G06F21/00 and subgroups addressing additional information or applications relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/2131Lost password, e.g. recovery of lost or forgotten passwords
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W4/00Services specially adapted for wireless communication networks; Facilities therefor
    • H04W4/12Messaging; Mailboxes; Announcements
    • H04W4/14Short messaging services, e.g. short message services [SMS] or unstructured supplementary service data [USSD]

Definitions

  • the present invention relates to a security system for a computer network with a directory service, particularly authentication systems processing user credentials.
  • Computer networks operate directory services to store password information and authenticate users to access any password protected services over the computer network.
  • a system administrator manually reset the password on the directory service and inform user manually.
  • the computer network provide a web based password reset system, user is obliged to fill out a web form and submit to the web server to submit a password reset request to the computer network.
  • a one time verification code is generated by the password reset system and user asked to use a graphical user interface to provide verification code in correct manner. This procedure is time consuming and for the most of the time very complex for an ordinary computer user.
  • EP3407536 discloses a server device in communication with a control panel device in a region can include a database of authorized users and phone numbers of mobile devices associated with the authorized users.
  • the control panel device can generate a onetime password or security token, and when the control panel device generates the onetime password or security token, the control panel device can use GSM capability to transmit the onetime password or security token to the server device, and the server device can identify from the database one of the authorized users associated with the region in which the control panel device is located, identify from the database the phone number of a mobile device associated with the one of the authorized users, and transmit the onetime password or security token to the mobile device associated with the one of the authorized users for use in programming and updating software or firmware of the control panel device.
  • the object of the invention is to facilitate providing a new permanent password upon request to a user allowing access to a password protected computer network.
  • invention relates to a security system for a computer network comprising an operation server accessible to a directory service of the computer network and a mobile device connected with the operation server by means of an electronic message service adapted to transmit electronic messages between the operation server and the mobile device.
  • an access control server in communication with a processor of the computer network is configured such that receive and parse a first electronic message from the mobile device into an identification data of the mobile device and a predetermined command, validate predetermined command with a stored pattern thereon; establish a data connection with the directory service via a network connection module and pair the device identification information with a registered user on a user database of the directory service, generate a permanent new password data for authorization of the registered user to the computer network by a security protocol and overwrite on a stored password data on the directory service with the new password data and send a second electronic message including new password data directly to the mobile device via electronic message service.
  • Security system provide easy access to the computer network by a user of the mobile device when the mobile device is known to the directory service of the computer network.
  • Directory service can be provided on the multiple operation servers for various services, e.g. active directory, SAP directory etc. distributed over the computer network communicating with the access control server using TCP/IP protocol.
  • a single first message to the access control server will suffice to retrieve the new password data without any need for a further security steps to be followed by the user of the mobile device.
  • additional security measures can be taken.
  • the permanent password means a password that is not changing during each cycle of the described operation.
  • the password in the second electronic message can be a temporary password for the operation server and user can be forced to change the password after using the permanent password provided in the second electronic message.
  • the operation server can be a single server or can be a group of servers providing single or integrated directory service of various services.
  • the processor under the computer network belong to the operation server.
  • the processor can be a CPU provided at the access control server.
  • the electronic message service is an SMS service over a GSM network provided by a GSM operator. SMS prioritization is provided by the GSM operator so that resources of security system is not allocated by such a task. This allow installation of a scalable security system in an affordable cost.
  • the identification data is GSM subscription number assigned by the GSM network. Simply registration of the GSM subscription number to the directory service of the computer network will allow easy authentication by the access control server to provide a sensitive information, i.e. new password data to user of the mobile device.
  • the access control server is equipped with a SIM shield in a persistent connection with the GSM network.
  • the access control server on various computer networks provide with persistent connection with the GSM network over the electronic messaging service and will allow any user to access new password data to access the computer network at any time.
  • the access control server further comprises a memory module in which a pattern for predetermined command is stored such that access control server is enabled to terminate the remaining process when predetermined command does not match with the stored pattern.
  • Memory module can be RAM or any SSD or hard drive storing the pattern for a predetermined command to compare with the first message.
  • Integrated memory module provide box type server device running as access control server to be installed in a computer network.
  • Predetermined command can be any alphanumerical character or a gesture data captured by the mobile device. In some instances, predetermined command can be blank.
  • the network connection module is configured to access local area network to establish a data connection with the directory service on the computer network. Therefore, instant access to the operation server by the access control server is possible.
  • data connection can be encrypted over an SSL protocol.
  • an operating method for a mobile device comprising the steps of sending a first electronic message having an identification data of the mobile device and a predetermined command for password renewal request from the mobile device to an access control server under a computer network by means of a first electronic message; interpretation of the first electronic message by an operation server at the computer network via LAN connection to the access control server to parse into an identification data and a predetermined command; validate the predetermined command with a stored pattern thereon; connect to a directory service; pair a registered user on a user database of the directory service using the identification data; generate a new password data for the registered user and overwrite on a stored password data.
  • the electronic messaging service connecting the mobile device and the access control server is SMS over a GSM network.
  • Figure 1 shows a schematic view of a security system for a computer network according to an exemplary application of the present invention.
  • FIG. 1 a security system for a computer network (1 ) is schematically shown.
  • An operation server (10) namely a group of servers providing various services in the same network area, e.g. operating system, ERP, CRM, etc. is actively connected or separately providing a directory service (12) to the computer network (1 ) under a known protocol, e.g. Active Directory, LDAP, from an assigned port and handle requests from the computer network (1 ).
  • a directory service store user information such as, username, password, mobile phone number, e-mail address, role of the user, etc. in an encrypted manner.
  • Mobile device (20) which is equipped with a SIM Card (22) having an assigned mobile phone number as identification data (261 ) to change a stored password data (A) on the directory service (12).
  • Mobile device (20) is a cell phone with graphical user interface or SIM interface to send an electronic message through electronic messaging service (32) of a GSM network (30).
  • An access control server (40) in the computer network (1 ) is arranged such that post data to the directory service (12) of the operation server (10) using a middleware (50) running on the operation server (10).
  • Access control server (40) has a processor (42), a memory module (43) and a network connection module (44) which are connected to each other in an electronic signal transmitting manner.
  • a SIM shield (48) is adapted into the access control server (40) providing access to the GSM network (30) by means of a SIM card inserted inside the SIM shield (48).
  • a GSM operator has assigned a unique subscription number to the SIM card inside the SIM shield (48) and configured such that allowing access to the electronic messaging service (32), namely SMS service.
  • the middleware (50) run on the operation control server (10) interprets the electronic messages received by the SIM shield (46).
  • the middleware (50) is a piece of software run by a processor and has full access rights on the directory service (12) and in connection with the access control server (40) by means of the network connection module (44) and can send electronic messages to the access control server (40).
  • the access control server (40) forward the electronic messages by means of the SIM shield (48) to the GSM network.
  • GSM operator of the GSM network (30) has means to prioritize the messages to the SIM shield (48) and provide a number of electronic messages, namely SMS to the access control server (40) by means of the SIM shield (48).
  • Access control server (40) persistently connected to the GSM network (30) by SIM shield (48).
  • GSM network (30) provide a list of electronic messages
  • access control server (40) initiate a read and validation procedure by running software commands for each one of the electronic messages independently. If the first electronic message (26) is unreadable, access control server (40) break the interpretation operation and terminate the first electronic message (26). Otherwise, forward the first electronic message (26) to the middleware (50) over the network connection module (44).
  • Middleware (50) running on the operation server (10) initiate a parse procedure and split the first electronic message into several pieces including an identification data (261 ) and a predetermined command (262).
  • Identification data (261 ) is the assigned subscriber number of the SIM card (22) in the mobile device (20).
  • Middleware (50) establish a connection with the directory service (12) to check phone number information of the users registered to the directory service (12). If the identification data pairs with a user with the identification data (261 ) generate a new password data (B) according to the internal password policy of the computer network and send a command to the directory service (12) to overwrite a stored password data (A) accordingly. If the password change at the directory service (12) is successful, middleware (50) prepare a plain text password information from the new password data (B) and forward the access control server (40) to create an electronic message as the second electronic message (46) and send back to the mobile device (20) over the GSM network (30) using SIM shield (48). The user receive the new password data (B) from the mobile device (20). User can be able to access operation server (10) using the new password data (B) over the secure internet connection (14) using the computer (60).
  • Operation server 32 Electronic messaging service

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • General Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Theoretical Computer Science (AREA)
  • Computing Systems (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)
  • Telephone Function (AREA)

Abstract

L'invention concerne un système de sécurité pour un réseau informatique (1) comprenant un serveur d'exploitation (10) accessible à un service de répertoire (12) du réseau informatique (1) et un dispositif mobile (20) connecté au serveur d'exploitation (10) au moyen d'un service de messagerie électronique (32) conçu pour transmettre des messages électroniques entre le serveur d'exploitation (10) et le dispositif mobile (20). Le système de sécurité comprend en outre un serveur de contrôle d'accès (40) avec un processeur (42) qui est configuré pour recevoir et analyser un premier message électronique (26) à partir du dispositif mobile (20), établir une connexion de données avec le service de répertoire (12) par l'intermédiaire d'un module de connexion réseau (44) et une paire d'informations d'identification de dispositif (26) avec un utilisateur enregistré sur une base de données d'utilisateurs du service de répertoire (12), générer de nouvelles données de mot de passe (A) pour l'autorisation de l'utilisateur enregistré au réseau informatique (1) par un protocole de sécurité et écraser des données de mot de passe mémorisées (B) sur le service de répertoire (12) avec les nouvelles données de mot de passe (A) et envoyer un second message électronique (46) comprenant de nouvelles données de mot de passe (B) directement au dispositif mobile (20) par l'intermédiaire d'un service de message électronique.
PCT/TR2019/050711 2019-07-23 2019-08-28 Système de sécurité pour réseau informatique WO2021015686A1 (fr)

Priority Applications (1)

Application Number Priority Date Filing Date Title
EP19849049.2A EP3847564A1 (fr) 2019-07-23 2019-08-28 Système de sécurité pour réseau informatique

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
TR201911013 2019-07-23
TR2019/11013 2019-07-23

Publications (1)

Publication Number Publication Date
WO2021015686A1 true WO2021015686A1 (fr) 2021-01-28

Family

ID=69528930

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/TR2019/050711 WO2021015686A1 (fr) 2019-07-23 2019-08-28 Système de sécurité pour réseau informatique

Country Status (2)

Country Link
EP (1) EP3847564A1 (fr)
WO (1) WO2021015686A1 (fr)

Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2001091486A1 (fr) * 2000-05-22 2001-11-29 Bolt Media Ltd. Procede permettant de renseigner un abonne sur l'emplacement d'un autre abonne
US20070190995A1 (en) * 2006-02-13 2007-08-16 Nokia Corporation Remote control of a mobile device
US20100004980A1 (en) * 2006-01-20 2010-01-07 Berkley Bowen Systems and methods for managing product and consumer information
US8503988B2 (en) * 2007-08-31 2013-08-06 At&T Mobility Ii Llc Systems and methods for providing a password reset feature
EP3407536A1 (fr) 2017-05-26 2018-11-28 Honeywell International Inc. Systèmes et procédés permettant de fournir un mot de passe sécurisé et mécanisme d'authentification de programmation et de mise à jour de logiciel ou de micrologiciel

Patent Citations (5)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2001091486A1 (fr) * 2000-05-22 2001-11-29 Bolt Media Ltd. Procede permettant de renseigner un abonne sur l'emplacement d'un autre abonne
US20100004980A1 (en) * 2006-01-20 2010-01-07 Berkley Bowen Systems and methods for managing product and consumer information
US20070190995A1 (en) * 2006-02-13 2007-08-16 Nokia Corporation Remote control of a mobile device
US8503988B2 (en) * 2007-08-31 2013-08-06 At&T Mobility Ii Llc Systems and methods for providing a password reset feature
EP3407536A1 (fr) 2017-05-26 2018-11-28 Honeywell International Inc. Systèmes et procédés permettant de fournir un mot de passe sécurisé et mécanisme d'authentification de programmation et de mise à jour de logiciel ou de micrologiciel

Also Published As

Publication number Publication date
EP3847564A1 (fr) 2021-07-14

Similar Documents

Publication Publication Date Title
US8589675B2 (en) WLAN authentication method by a subscriber identifier sent by a WLAN terminal
CN110855621B (zh) 用于控制对车载无线网络的访问的方法
US12011094B2 (en) Multi-factor authentication with increased security
JP5926441B2 (ja) マルチパーティシステムにおける安全な認証
EP2368339B1 (fr) Authentification de transaction sécurisée
CN100438421C (zh) 用于对网络位置的子位置进行用户验证的方法和系统
KR101451359B1 (ko) 사용자 계정 회복
EP2924944B1 (fr) Authentification de réseau
US9787678B2 (en) Multifactor authentication for mail server access
CN101986598B (zh) 认证方法、服务器及系统
CN113341798A (zh) 远程访问应用的方法、系统、装置、设备及存储介质
US11768930B2 (en) Application authenticity verification in digital distribution systems
CN114157438A (zh) 网络设备管理方法、装置及计算机可读存储介质
KR101473719B1 (ko) 지능형 로그인 인증 시스템 및 그 방법
WO2021015686A1 (fr) Système de sécurité pour réseau informatique
US12063215B2 (en) Method for configuring access to an internet service
JP6322590B2 (ja) 端末検知システムおよび方法
CN114531303B (zh) 一种服务器端口隐藏方法及系统
EP2529329B1 (fr) Procédure sécurisée pour accéder à un réseau et réseau ainsi protégé
CN106100889A (zh) 一种snmp协议安全的增强方法及装置
KR101484972B1 (ko) 스마트폰 도용방지 서비스 방법 및 시스템
CN114513348A (zh) 一种终端认证的方法、云平台和云ap
CN116796305A (zh) 一种数据中心访问方法、装置、设备及介质
KR20130124448A (ko) 정당성 확인 로그인 인증 시스템 및 그 방법

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 19849049

Country of ref document: EP

Kind code of ref document: A1

ENP Entry into the national phase

Ref document number: 2019849049

Country of ref document: EP

Effective date: 20210406

NENP Non-entry into the national phase

Ref country code: DE