EP4237973A1 - Verfahren zur sicherung des betriebs eines industriesystems und zugehörige vorrichtungen - Google Patents

Verfahren zur sicherung des betriebs eines industriesystems und zugehörige vorrichtungen

Info

Publication number
EP4237973A1
EP4237973A1 EP21802260.6A EP21802260A EP4237973A1 EP 4237973 A1 EP4237973 A1 EP 4237973A1 EP 21802260 A EP21802260 A EP 21802260A EP 4237973 A1 EP4237973 A1 EP 4237973A1
Authority
EP
European Patent Office
Prior art keywords
equipment
digital certificate
access
industrial
piece
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP21802260.6A
Other languages
English (en)
French (fr)
Inventor
Stéphane ALAIMO
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
SAFT Societe des Accumulateurs Fixes et de Traction SA
Original Assignee
SAFT Societe des Accumulateurs Fixes et de Traction SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by SAFT Societe des Accumulateurs Fixes et de Traction SA filed Critical SAFT Societe des Accumulateurs Fixes et de Traction SA
Publication of EP4237973A1 publication Critical patent/EP4237973A1/de
Pending legal-status Critical Current

Links

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/30Authentication, i.e. establishing the identity or authorisation of security principals
    • G06F21/31User authentication
    • G06F21/33User authentication using certificates
    • G06F21/335User authentication using certificates for accessing specific resources, e.g. using Kerberos tickets
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/604Tools and structures for managing or administering access control systems
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/60Protecting data
    • G06F21/62Protecting access to data via a platform, e.g. using keys or access control rules
    • YGENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
    • Y04INFORMATION OR COMMUNICATION TECHNOLOGIES HAVING AN IMPACT ON OTHER TECHNOLOGY AREAS
    • Y04SSYSTEMS INTEGRATING TECHNOLOGIES RELATED TO POWER NETWORK OPERATION, COMMUNICATION OR INFORMATION TECHNOLOGIES FOR IMPROVING THE ELECTRICAL POWER GENERATION, TRANSMISSION, DISTRIBUTION, MANAGEMENT OR USAGE, i.e. SMART GRIDS
    • Y04S40/00Systems for electrical power generation, transmission, distribution or end-user application management characterised by the use of communication or information technologies, or communication or information technology specific aspects supporting them
    • Y04S40/20Information technology specific aspects, e.g. CAD, simulation, modelling, system security

Definitions

  • the present invention relates to a method for securing the operation of an industrial system.
  • the present invention also relates to an industrial system and an associated security system.
  • power supplies using batteries are capable of delivering increasingly high electrical power and over increasingly long durations, but this gain in power and energy density is accompanied in particular by an increased risk of fire or explosion due to thermal runaway. Such power supplies are therefore controlled by various electronic equipment to guarantee secure operation.
  • Guaranteeing such secure operation means that electronic equipment should only be adjusted, especially for maintenance, by people with extensive expertise. Indeed, improper adjustment of equipment can lead to unsafe operation that can lead to dramatic accidents.
  • document EP 1906586 A1 describes an authentication protocol for an industrial system.
  • the protocol is based on the use of a dedicated component of the industrial system that can communicate secure information along a network.
  • the control is then done by an exchange of private keys at the level of the industrial system.
  • the description describes a method for securing the operation of an industrial system comprising a set of equipment and a unit for controlling access to the equipment, the industrial system forming part of an industrial site, the industrial site forming part of a set of industrial sites, the set of industrial sites comprising a single centralized access rights control system, the securing process comprising a phase for obtaining a digital certificate authorizing an operator to access at least one piece of equipment of the industrial system to carry out a predefined intervention.
  • the obtaining phase comprises a step of requesting the generation of the digital certificate by the centralized access rights control system, the digital certificate being a unique and temporary digital certificate, and a step of receiving the digital certificate.
  • the securing method comprises a phase of attempting to access at least one piece of equipment of the industrial system to carry out an intervention on said at least one piece of equipment, the attempt phase comprising a step of requesting access to at least one piece of equipment of the system industrial by entering a plurality of data relating to the intervention to be carried out on the equipment access control unit, at least one data of the plurality of data relating to the digital certificate, a step of verification by the 'unit for controlling access to the equipment of the conformity of the access request with at least one condition of conformity, at least one condition of conformity being a condition of conformity relating to the digital certificate, and a step of authorization of access to the at least one piece of equipment of the industrial system to carry out the intervention when the or each condition of compliance is met or denial of access to at least one piece of equipment of the industrial system when a compliance condition is not met.
  • the securing method has one or more of the following characteristics, taken in isolation or in all technically possible combinations:
  • the industrial system is an energy production system or an energy storage system.
  • the industrial system is a power supply comprising a battery and a battery management system and at least one auxiliary equipment.
  • each auxiliary equipment is chosen from among a fire detection and extinguishing system, an air conditioning system and an electrical power measurement system.
  • the digital certificate generation request step further includes connecting to a web application, preparing a digital certificate generation request by entering information on the web application, to obtain a request prepared, and sending the prepared request to the centralized access rights control system for generation of the digital certificate on the basis of the information entered on the web application.
  • each compliance condition relating to the digital certificate is chosen from the following list of compliance conditions: a validity interval being defined for the digital certificate, the request for access to at least one piece of equipment of the industrial system is included in the interval time of validity of the digital certificate, the data relating to the intervention to be performed entered in the equipment access control unit is the same as the intervention indicated in the digital certificate, and the digital certificate is authentic.
  • the description also relates to an industrial system comprising a set of equipment and a unit for controlling access to the equipment, the industrial system being part of an industrial site, the industrial site being part of a set of industrial sites , the set of industrial sites comprising a single centralized access rights control system, the equipment access control unit being able to receive a plurality of data on the equipment access control unit equipment, at least one datum of the plurality of data being relating to a digital certificate authorizing access to at least one piece of equipment of the industrial system, the digital certificate having been generated by the centralized access rights control system, the digital certificate being a unique and temporary digital certificate, the set of data forming a request for access to at least one piece of equipment of the industrial system.
  • the control unit is capable of verifying the compliance of the access request with at least one compliance condition, at least one compliance condition being a compliance condition relating to the digital certificate, and capable of authorizing access to the at least one piece of equipment of the industrial system when the or each compliance condition is fulfilled or denying access to the at least one piece of equipment of the industrial system when a compliance condition is not fulfilled.
  • the description also relates to a system for securing the operation of an industrial system comprising a set of equipment and a unit for controlling access to the equipment, the industrial system forming part of an industrial site, the industrial site forming part of a set of industrial sites, the set of industrial sites comprising a single centralized access rights control system, the security system comprising a terminal making it possible to obtain a digital certificate authorizing access to at least one piece of equipment in the system industrial, the terminal being suitable for requesting the generation of the digital certificate by the centralized access rights control system, the digital certificate being a unique and temporary digital certificate, suitable for receiving the digital certificate.
  • the equipment access control unit is suitable for receiving a plurality of data on the equipment access control unit, at least one data item of the plurality of data items relating to the digital certificate, the set data forming a request for access to at least one piece of equipment of the industrial system, suitable for verifying the conformity of the access request with at least one condition of conformity, at least one condition of conformity being a condition of conformity relating to the certificate digital, and capable of authorizing access to the at least one item of equipment of the industrial system when the or each compliance condition is fulfilled or denying access to the at least one item of equipment of the industrial system when a compliance condition n is not fulfilled.
  • the description also relates to a computer program product comprising program instructions stored on a readable information medium implementing the steps of a method as previously described when the computer program is implemented on a data processing unit.
  • the description also relates to a readable information medium on which are stored program instructions implementing steps of a method as previously described when the computer program is implemented on a data processing unit.
  • FIG. 1 is a schematic view of a set of industrial sites
  • FIG. 2 is a flowchart of an example of implementation of a method for securing the operation of an industrial system forming part of a site of the set of sites.
  • a set of industrial sites 10 is schematically illustrated in FIG.
  • Set 10 includes several industrial sites 12.
  • An industrial site 12 is a site grouping together a set of industrial systems in operation.
  • the industrial site 12 is a manufacturing plant or a production plant, in particular an energy production plant.
  • Each industrial site 12 includes a local centralized access rights control system 14, called local control system 14, and at least one industrial system 16.
  • the local control system 14 makes it possible in particular to check that the persons who access the site are authorized persons.
  • the industrial system 16 comprising a set of equipment 18 and an equipment access control unit 20.
  • the first industrial site 12 (the one on the left in Figure 1) comprises a single industrial system 16 which is a power supply 22.
  • the power supply 22 is capable of supplying electrical energy to other elements, and for example, other industrial systems.
  • the power supply 22 comprises a plurality of equipment 24 and an equipment access control unit 26.
  • the equipment 24 of the power supply 22 is a battery 28, auxiliary equipment 30 and the battery management system 32.
  • a battery 28 is a generic term designating a set of electric accumulators, called cells, connected together so as to create an electric generator of the desired voltage, power and capacity.
  • a battery 28 converts the electrical energy accumulated during the charging phase into chemical energy.
  • the chemical energy is constituted by electro-chemically active compounds arranged in the element. Electrical energy is returned by converting chemical energy into electrical energy during the discharge phase.
  • the electrodes, arranged in a container, are electrically connected to current output terminals which provide electrical continuity between the electrodes and an electrical consumer with which the element is associated.
  • the battery 28 is formed of one or more branches electrically connected in parallel. Each branch comprises one or more modules connected electrically in series, and each module comprising one or more electrochemical elements connected electrically in series or in parallel.
  • a battery 28 is a set of several electrochemical elements which are connected in series and arranged together in the same enclosure to form a first module.
  • each module comprises a plurality of electrochemical elements connected in series and arranged in a respective enclosure.
  • the modules are connected in series to form a battery 28.
  • the modules constitute a branch of the circuit.
  • Such a circuit branch is often called ESSU in reference to the English denomination of “Energy Storage System Unit” which literally means unitary energy storage system.
  • the elements are connected in parallel.
  • the battery 28 can comprise any number of modules, in a configuration not necessarily limited to a series connection.
  • the battery may comprise parallel branches, each parallel branch comprising at least one module consisting of at least one element.
  • Each auxiliary equipment 30 has a specific function, each specific function is most often related to the safety, security, performance or operation of the battery.
  • the power supply 22 includes three auxiliary devices 30 which are now described.
  • the first auxiliary equipment 36 is a fire detection and extinguishing system.
  • Such a system is configured to prevent the spread of fire if one or more electrochemical modules catch fire.
  • a second piece of equipment 38 is an air conditioning system.
  • a third piece of equipment 40 is an electrical power measurement system.
  • the electrical power measured by the third device is, for example, the electrical power delivered and/or received by the battery.
  • auxiliary equipment 30 can be envisaged, such as a system for monitoring physical access to the battery (for example the room in which the battery is stored).
  • the battery management system 32 is able to control the battery 28 and at least one auxiliary equipment 30.
  • the equipment access control unit 26 referred to as the control unit 26 in the following, is suitable for controlling access to the equipment 24 by an operator.
  • control unit 26 comprises an interface 42 and a computer 44.
  • Interface 42 allows an operator wishing to access equipment 24 to enter data to request it.
  • the operator here is qualified personnel who can implement any type of operation on at least one piece of equipment 24, and in particular maintenance operations.
  • a set of operations to be carried out is sometimes referred to as a mission.
  • intervention will be used in the remainder of this description.
  • the interface 42 is, for example, a touch interface or a screen and keyboard assembly.
  • the computer 44 is used to check the data entered and to authorize or not the access according to these data.
  • the set of industrial sites 10 is also provided with a centralized access rights control system 46, called centralized control system 46 in the following.
  • the centralized control system 46 is capable of generating digital certificates authorizing an operator to access at least one piece of equipment 24 of the power supply 22 to carry out a predefined intervention.
  • a digital certificate is, by definition, a set of information relating to the operation to be carried out accompanied by a signature from the centralized control system 46.
  • the presence of the signature is a guarantee that all the information contained in the digital certificate is true.
  • the centralized control system 46 is a certification authority.
  • a certification authority (also designated by the acronym CA for the English name of “Certificate Authority”) is a trusted third party allowing information to be authenticated.
  • the signature is generated with a safe cryptographic hash algorithm with the associated cryptographic parameters (number of rounds for example) necessary to obtain a sufficient level of security, such as SHA-2 for example.
  • the digital certificate uses to encrypt the signature, a secure asymmetric cryptographic system, with the associated cryptographic parameters (key size for example) necessary to obtain a sufficient level of security according to the required intervention and the duration. lifetime of the cryptographic material used, such as the RSA (Rivest-Shamir-Adleman) algorithm with 4096-bit keys.
  • RSA Rivest-Shamir-Adleman
  • the digital certificate includes a public key, the identity of the operator, the intervention, the start date of validity of the digital certificate, the end date of validity of the digital certificate and a unique serial number. .
  • the digital certificate is a unique and temporary certificate.
  • intervention can also be expressed in the form of a role.
  • an electrical power meter 40 specialist does not have to access an air conditioning system 38.
  • the digital certificate is in the form of a file in X.509 format.
  • the centralized control system 46 gets its information from a web application.
  • a web application is an application that can be manipulated directly online using a web browser or an intranet and which therefore does not require installation on client machines.
  • the operator is provided with a terminal 48 which is specific to him.
  • the terminal 48 is, according to the example of Figure 1, a smartphone more often called smartphone.
  • the terminal 48 can be seen as a computer system that can interact with one or more computer programs.
  • a computer system is an electronic computer suitable for manipulating and/or transforming data represented as electronic or physical quantities in registers of the computer and/or memories into other similar data corresponding to physical data in memories, registers or other types of display, transmission or storage devices.
  • the computer system comprises a processor comprising a data processing unit, memories and an information carrier reader.
  • the calculator also includes a man-machine interface, for example a keyboard and a display unit.
  • the computer program product comprises a readable carrier of information.
  • a readable information medium is a medium readable by the computer system, usually by the reader.
  • the readable information carrier is a medium suitable for storing electronic instructions and capable of being coupled to a bus of a computer system.
  • the readable information medium is a diskette or floppy disk (from the English name "floppy disk"), an optical disk, a CD-ROM, a magneto-optical disk, a ROM memory, a RAM memory, an EPROM memory, an EEPROM memory, a magnetic card or an optical card.
  • a computer program comprising program instructions.
  • the computer program is loadable on the data processing unit and is adapted to cause the implementation of a desired method.
  • control unit 26 can be seen as a computer system.
  • the assembly of the terminal 48 and the control unit 26 forms a security system 50 for the operation of the power supply 22.
  • FIG. 2 is a flowchart of an example of implementation of a method of securing the power supply 22.
  • the securing process is a process aimed at securing the operation of the power supply 22 by preventing the carrying out of an intervention that is not authorized or carried out by unqualified personnel.
  • the securing process comprises two phases: a phase for obtaining a digital certificate P1 and a phase for attempting access P2 to at least one piece of equipment 24 of the power supply 22.
  • the phase for obtaining P1 is a phase for obtaining a digital certificate authorizing access to at least one piece of equipment 24 of the power supply 22.
  • the obtaining phase P1 comprises two steps which are a generation request step E100 and a reception step E102.
  • the generation request step E100 the generation of the digital certificate is requested by the centralized control system 46, the digital certificate being a unique and temporary digital certificate.
  • the generation request step E100 comprises three operations: connection, preparation and sending.
  • the operator connects to the application.
  • the operator enters an identifier and a password on his terminal.
  • operator identification can be double-checked by using a single-use token in addition to the username/password pair.
  • the operator enters information on the web application to prepare a request for the generation of the digital certificate.
  • the operator enters a start date of validity of the digital certificate.
  • the start date often corresponds to the scheduled date of his feeding intervention 22.
  • the operator specifies the nature of his intervention.
  • the prepared query is sent to the centralized control system 46.
  • the sending is, for example, carried out by the web application following a selection on the terminal 48 of a send button by the user.
  • the centralized control system 46 then generates a digital certificate based on the prepared request.
  • the digital certificate includes an end of validity date.
  • the end date of validity is calculated from the start date by adding a predetermined time interval.
  • the time interval is chosen at 7 days.
  • the time interval depends on the equipment 24 on which the intervention is planned.
  • the digital certificate also has a predefined intervention.
  • the generated digital certificate is received.
  • the operator downloads to his terminal 48 the file comprising the digital certificate generated by the centralized control system 46.
  • the operator therefore has a digital certificate certified by the centralized control system 46.
  • This phase of obtaining P1 was carried out by connecting to the web application.
  • Such a phase of obtaining P1 is therefore a phase implemented online by a link between the terminal 48 and the centralized control system 46 via the web application. This link is materialized by dotted lines 52 in FIG.
  • the access attempt phase P2 does not imply the presence of an Internet connection, it is therefore for the example described considered as an offline phase.
  • the P2 access attempt phase is a phase during which an attempt is made to access at least one piece of equipment 24 of the power supply 22 using the digital certificate obtained at Tissue from the P1 obtaining phase.
  • the access attempt phase P2 comprises an access request step E104, a verification step E106 and an access authorization step E108.
  • the operator requests access to the equipment 24 via the control unit 26.
  • the access request includes the entry of a plurality of data, at least one of the plurality of data relating to the digital certificate.
  • the operator enters an intervention on the control unit 26 and sends the file to the control unit 26.
  • the operator sends his certificate to the control unit 26 using his terminal 48 (see dotted lines 54 in FIG. 1).
  • the verification step E106 is a verification step by the control unit 26 of the compliance of the access request with at least one compliance condition, at least one compliance condition being a compliance condition relating to the digital certificate .
  • control unit 26 verifies whether a certain number of conformity conditions relating to the plurality of data are verified or not.
  • control unit 26 verifies five conformity conditions which are set out below.
  • control unit 26 verifies a condition of conformity relating to the integrity of the digital certificate.
  • control unit 26 checks other additional compliance conditions (here four).
  • An additional conformity condition relates to the identity between the intervention entered on the control unit 26 and the intervention defined by the digital certificate.
  • the first condition of conformity concerns the identity of the role entered and the role contained in the digital certificate.
  • Another additional compliance condition relates to the signing of the digital certificate.
  • control unit 26 verifies whether the signature is a signature of the centralized control system 46.
  • Yet another compliance condition relates to the start date of validity.
  • the fourth compliance condition is met when the validity start date is later than the current date.
  • the last additional compliance condition is similar to the previous compliance condition but relates to the expiry date.
  • the compliance condition is met when the validity end date is prior to the current date.
  • control unit 26 has verified that the various conformity conditions are fulfilled.
  • the authorization step E108 is then implemented.
  • the control unit 26 then authorizes access for the operator to at least one piece of equipment 24 of the power supply 22.
  • control unit 26 refuses access to at least one piece of equipment 24 of the power supply 22.
  • the method described therefore allows authentication of the operator making it possible to identify and authenticate by name the operators required to intervene in an industrial site 12 rather than using anonymous generic accounts. Furthermore, the method is hybrid since it comprises two phases P1 and P2, one of which is on-line and the other is off-line. The method therefore makes it possible to extend the authentication of the operator without being master of the initial certification authority (here the centralized control system 46) and without having access to this authority in the off-line environment.
  • a certificate is generated which can be designed as a cryptographic object that allows the operator to be authenticated in another environment, this time offline. , with a completely separate certification chain.
  • the centralized character of the generation of the certificate makes it possible to guarantee better security because all the means of identification of an intervention are listed in a single place.
  • the updating of identifiers and rights is done in a centralized manner on the centralized control system 46 (and no longer on the industrial site 12).
  • the uniqueness of the digital certificate allows good traceability of the interventions carried out with the logging of information such as the name of the operator, the date of creation of the certificate, the date of attempt to use the certificate, the number series of the certificate, the type of intervention.
  • Access to the equipment 24 is therefore perfectly controlled, which prevents the power supply 22 and more generally the industrial system 16 from being incorrectly configured.
  • the securing method can be used effectively in all the scenarios that may arise in practice when an operation is to be performed on the industrial system 16.
  • the identity of the operator could be verified.
  • the manufacturer of the industrial system 16 or its original company could be verified.
  • the authorization could be of several degrees.
  • the digital certificate can be used for the traceability of one or more files generated within the framework of the mission.
  • the operator may have to generate a parameter file comprising the new adjustment parameters imposed on the equipment.
  • the file could also be an in situ test file of a new part installed on the equipment.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • General Physics & Mathematics (AREA)
  • Computer Hardware Design (AREA)
  • Software Systems (AREA)
  • Physics & Mathematics (AREA)
  • General Engineering & Computer Science (AREA)
  • Health & Medical Sciences (AREA)
  • Bioethics (AREA)
  • General Health & Medical Sciences (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Automation & Control Theory (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)
  • Stored Programmes (AREA)
EP21802260.6A 2020-10-28 2021-10-28 Verfahren zur sicherung des betriebs eines industriesystems und zugehörige vorrichtungen Pending EP4237973A1 (de)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR2011022A FR3115646B1 (fr) 2020-10-28 2020-10-28 Procédé de sécurisation du fonctionnement d’un système industriel et dispositifs associés
PCT/EP2021/079935 WO2022090371A1 (fr) 2020-10-28 2021-10-28 Procédé de sécurisation du fonctionnement d'un système industriel et dispositifs associés

Publications (1)

Publication Number Publication Date
EP4237973A1 true EP4237973A1 (de) 2023-09-06

Family

ID=74205996

Family Applications (1)

Application Number Title Priority Date Filing Date
EP21802260.6A Pending EP4237973A1 (de) 2020-10-28 2021-10-28 Verfahren zur sicherung des betriebs eines industriesystems und zugehörige vorrichtungen

Country Status (4)

Country Link
US (1) US20230403162A1 (de)
EP (1) EP4237973A1 (de)
FR (1) FR3115646B1 (de)
WO (1) WO2022090371A1 (de)

Families Citing this family (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
EP4528565A1 (de) * 2023-09-20 2025-03-26 Siemens Aktiengesellschaft Verfahren und anordnung zur benutzerbezogenen freischaltung einer funktion einer anwendung einer industriellen automatisierungskomponente

Family Cites Families (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US7761910B2 (en) * 1994-12-30 2010-07-20 Power Measurement Ltd. System and method for assigning an identity to an intelligent electronic device
US20050229004A1 (en) * 2004-03-31 2005-10-13 Callaghan David M Digital rights management system and method
US20080077976A1 (en) 2006-09-27 2008-03-27 Rockwell Automation Technologies, Inc. Cryptographic authentication protocol
US8707032B2 (en) * 2012-04-30 2014-04-22 General Electric Company System and method for securing controllers
US20150048684A1 (en) * 2013-08-06 2015-02-19 Bedrock Automation Platforms Inc. Secure power supply for an industrial control system
US20150324589A1 (en) * 2014-05-09 2015-11-12 General Electric Company System and method for controlled device access
WO2017106132A1 (en) * 2015-12-16 2017-06-22 Trilliant Networks, Inc. Method and system for hand held terminal security

Also Published As

Publication number Publication date
WO2022090371A1 (fr) 2022-05-05
FR3115646B1 (fr) 2023-09-29
US20230403162A1 (en) 2023-12-14
FR3115646A1 (fr) 2022-04-29

Similar Documents

Publication Publication Date Title
EP3547270B1 (de) Überprüfungsverfahren einer biometrischen authentifizierung
Khan et al. A blockchain based secure decentralized transaction system for energy trading in microgrids
US12088573B2 (en) System and method for securely changing network configuration settings to multiplexers in an industrial control system
EP3506557A1 (de) Schlüsselaustauschmethode durch intelligenten vertrag, der über eine blockchain entwickelt wird
CN112306978B (zh) 一种可信数据授权方法、亮证授权方法及业务接入方法
CN101589361A (zh) 控制数字身份表示的分发和使用
EP1393527A1 (de) Verfahren zur authentifizierung zwischen einem tragbaren funkgerät und einem netzdienstleister
FR3041798A1 (fr) Procede et dispositif d'authentification ameliores
EP3489854B1 (de) Gesichertes anmeldeverfahren eines entfernbaren elektrischen geräts bei seinem einbau in ein elektrisches system
EP4237973A1 (de) Verfahren zur sicherung des betriebs eines industriesystems und zugehörige vorrichtungen
CN103686711B (zh) 网络连接方法和电子设备
CN113506108A (zh) 一种账户管理方法、装置、终端及存储介质
CN115664823B (zh) 一种身份认证方法、装置、设备及存储介质
CA2647239C (fr) Procede et serveur pour l'acces a un coffre-fort electronique via plusieurs entites
FR3070776A1 (fr) Enrolement perfectionne d'un equipement dans un reseau securise
US12531750B2 (en) Method and system for validating transferring data between communication devices
WO2022184726A1 (fr) Procédé pour permettre à des utilisateurs de déployer des contrats intelligents dans une chaîne de blocs au moyen d'une plateforme de déploiement
WO2025190338A1 (zh) 电动汽车充电站运营架构
WO2025220101A1 (ja) 判定方法、情報処理装置、プログラム、及び、応答方法
CN118101206A (zh) 数据处理方法、装置、设备和计算机可读存储介质
CN119583083A (zh) 配电边缘物联网终端多因子信任评估系统、方法及应用
FR3145074A1 (fr) Procédés de signature de données, de fourniture de données signées, terminal et serveur associés
EP0965106A1 (de) Selbstkontrollverfahren eines elektronischen schlüssels in einem zugangskontrollsystem und elektronischer schlüssel dafür
CN113645623A (zh) 一种远程费控系统、安全认证方法及费控装置
Besson et al. I. ICT-2011-285135 FINSENY D1. 11 version 1.0 Security Elements for the FINSENY Functional Architecture

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: UNKNOWN

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20230424

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR

DAV Request for validation of the european patent (deleted)
DAX Request for extension of the european patent (deleted)
P01 Opt-out of the competence of the unified patent court (upc) registered

Effective date: 20240202