US2017068818A1PendingUtilityA1

Computer system and method of securely booting a computer system

Assignee: FUJITSU TECH SOLUTIONS IP GMBHPriority: Jan 10, 2013Filed: Nov 17, 2016Published: Mar 9, 2017
Est. expiryJan 10, 2033(~6.5 yrs left)· nominal 20-yr term from priority
Inventors:Mario Wegener
G06F 21/6218H04L 63/0457G06F 21/575G06F 21/31G06F 21/572
47
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A computer system includes a data network connection, a reading device, an input component and a security device that receives access data from the data network connection, the reading device and the input component, wherein the security device establishes a data network link via the data network connection as the computer system is starting up and the security device further receives access data either via the data network link or via the reading device and the input component, and the security device compares the received access data with a data record stored in a firmware on a memory element including security-related data to authenticate a user and boots the computer system if the comparison was successful.

Claims

exact text as granted — not AI-modified
1 . A computer system comprising a data network connection, a chip card reader, an input component and a security device that receives access data from the data network connection, the chip card reader and the input component, wherein the security device establishes a data network link via the data network connection as the computer system is starting up and said security device further receives access data either via the data network link or via the chip card reader and the input component, and said security device compares the received access data with a data record stored in a firmware on a memory element comprising security-related data, and the security device boots the computer system if the comparison was successful, wherein the access data either comprises a security code stored on a chip card, received via the chip card reader, and a personal identification number (PIN), received via the input component, or the access data received via the data network link simulates to the security device a combination of the security code on the chip card and the personal identification number (PIN). 
     
     
         2 . The computer system according to  claim 1 , wherein the security device repeats the receiving and comparing of the access data for a predefined number of times if the comparison is unsuccessful. 
     
     
         3 . The computer system according to  claim 2 , wherein the security device, once the predefined number of repeated comparisons of the access data has been reached and the comparison was unsuccessful, blocks the access data received via the chip card reader or the data network link, and said security device receives, either via the input component or the data network link, a personal unlock key (PUK), compares the personal unlock key (PUK) with a data record stored in the firmware on the memory element, and following a successful comparison of the personal unlock key (PUK) unblocks the blocked access data. 
     
     
         4 . (canceled) 
     
     
         5 . The computer system according to  claim 1 , wherein the security device, following a successful comparison of the access data received via the data network link, allows booting the computer system repeatedly on successive occasions without receiving access data afresh, wherein the number of booting processes is limited quantitatively or with respect to a predefined time period. 
     
     
         6 . The computer system according to  claim 1 , wherein the data received via the data network link is encrypted and the security device decrypts the received data. 
     
     
         7 . A method of booting a computer system comprising a data network connection, a chip card reader, an input component and a security device that receives access data from the data network connection, the chip card reader and the input component, the method comprising:
 establishing, by the security device, a data network link via the data network connection as the computer system starts up,   receiving access data, by the security device, either via the data network link or via the chip card reader and the input component, wherein the access data comprises either a security code on a chip card, received via the chip card reader and a personal identification number (PIN), received via the input component or the access data received via the data network link simulates to the security device a combination of the security code on the chip card and the personal identification number (PIN),   comparing, by the security device, the received access data with a data record stored in a firmware on a memory element, and   booting the computer system if the comparison was successful.   
     
     
         8 . The method according to  claim 7 , wherein the steps of receiving and comparing the access data are repeated for a predefined number of times in the event of an unsuccessful comparison. 
     
     
         9 . The method according to  claim 7 , wherein booting the computer system following a successful comparison of access data received via the data network link can be repeated on successive occasions without having to repeat the steps of receiving and comparing access data, and the number of repetitions is limited quantitatively or with respect to a predefined time period. 
     
     
         10 . (canceled) 
     
     
         11 . The method according to  claim 7 , further comprising encrypting data prior to transmitting data via the data network link, and decrypting the encrypted data that has been received via the data network link. 
     
     
         12 . A computer system comprising a data network connection, a chip card reader, an input component and a security device that receives access data from the data network connection, the chip card reader and the input component, wherein the security device establishes a data network link via the data network connection with a local area network as the computer system is starting up and said security device further receives access data either remotely via the data network link from a third agent or locally via the chip card reader and the input component, and said security device compares the received access data with a data record stored in a firmware on a memory element comprising security-related data, wherein the access data either comprises a security code stored on a chip card, received via the chip card reader, and a personal identification number (PIN), received via the input component, or the access data received via the data network link simulates to the security device a combination of the security code on the chip card and the personal identification number (PIN), and said security device boots the computer system if the comparison was successful. 
     
     
         13 . The computer system according to  claim 12 , wherein the access data in form of a security code on a chip card, received via the chip card reader, and a personal identification number (PIN), received via the input component is used to authenticate a user of the computer system when the user is in possession of the chip card and the personal identification number (PIN),
 and the access data received via the data network link, simulating to the security device a combination of the security code on the chip card and the personal identification number (PIN) is used to boot the computer system when the user of the computer system has forgotten the chip card and/or the personal identification number (PIN) or to unlock and boot the computer system remotely from the third agent when the user of the computer system is not present.   
     
     
         14 . The computer system according to  claim 1 , wherein the data network connection connects the security device to a local area network. 
     
     
         15 . The method according to  claim 7 , wherein the data network connection connects the security device to a local area network. 
     
     
         16 . The method according to  claim 8 , wherein the access data is blocked if the predefined number of repeatedly receiving and comparing the access data has been reached and the comparison was unsuccessful. 
     
     
         17 . The method according to  claim 16 , further comprising:
 receiving a personal unlock key (PUK) by the security device, either via the data network link or via the input component, if the access data has been blocked;   comparing, by the security device, the personal unlock key (PUK) with a data record stored in the firmware on the memory element; and   unblocking the blocked access data if the comparison of the personal unlock key (PUK) was successful.   
     
     
         18 . The method according to  claim 7 , wherein the access data received via the data network link is used to boot the computer system when a user of the computer system has forgotten the user's chip card and/or personal identification number (PIN) or, when the user of the computer system is not present and an administrator requires booting the computer system remotely via the data network link from a third agent.

Join the waitlist — get patent alerts

Track US2017068818A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.