EP4639939A1 - Procédé de gestion de la connexion à un réseau d'un objet communicant mis en oeuvre par un dispositif d'interface - Google Patents

Procédé de gestion de la connexion à un réseau d'un objet communicant mis en oeuvre par un dispositif d'interface

Info

Publication number
EP4639939A1
EP4639939A1 EP23821653.5A EP23821653A EP4639939A1 EP 4639939 A1 EP4639939 A1 EP 4639939A1 EP 23821653 A EP23821653 A EP 23821653A EP 4639939 A1 EP4639939 A1 EP 4639939A1
Authority
EP
European Patent Office
Prior art keywords
interface device
network
communicating object
identifier
communicating
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
EP23821653.5A
Other languages
German (de)
English (en)
Inventor
Mathieu Rivoalen
Hervé Marchand
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Orange SA
Original Assignee
Orange SA
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Orange SA filed Critical Orange SA
Publication of EP4639939A1 publication Critical patent/EP4639939A1/fr
Pending legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/12Detection or prevention of fraud
    • H04W12/126Anti-theft arrangements, e.g. protection against subscriber identity module [SIM] cloning
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/08Access security
    • H04W12/088Access security using filters or firewalls
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/18Network architectures or network communication protocols for network security using different networks or channels, e.g. using out of band channels
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/63Location-dependent; Proximity-dependent
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/60Context-dependent security
    • H04W12/69Identity-dependent
    • H04W12/71Hardware identity

Definitions

  • the technical field is that of the management of communicating objects.
  • the invention relates to a method for managing the connection to a network of a communicating object.
  • This communicating object can be searched, that is to say it could have been declared lost or stolen by its owner who is looking for information about it.
  • the invention also relates to an interface device, such as a domestic gateway, implementing the management method according to the invention.
  • the communicating objects in question are equipment of all kinds which have a communication capacity according to a defined protocol.
  • This may for example be a computer, portable or not, which can connect to a local network via a wireless or wired connection, then using a gateway present on the local network, can connect to the Internet network.
  • a computer can have the form of a tablet, reduced to a screen, using a touch keyboard.
  • It can also be a phone that will connect to a mobile telephone network or not. This connection to a telephone network can then allow the mobile phone to also connect to the Internet network. We will then talk about ordiphone, translation from English smartphone.
  • Communicating objects can also be objects dedicated to a specific function, which also have means allowing them to connect to a local network then to the Internet network to better fulfill their function. For example, this will involve a surveillance camera that can send its images via the Internet, a speaker capable of retrieving music from the Internet, a car with on-board communications means that allow it to retrieve navigation information, 'a refrigerator that can pass over Internet of food orders when it no longer contains any, of a goods container equipped with a chip which will regularly report information about its environment (temperature, possible movement) and the goods it contains.
  • modern objects increasingly include means of communication which allow them to be connected to the Internet network and can therefore be qualified as communicating objects.
  • Access of communicating objects to the Internet network is done via an interface device which provides the communicating object with the service of access to the communication network.
  • the interface device can be a domestic gateway which constructs a local network to which the communicating object belongs; from the local network, the communicating object can access a global network such as the Internet thanks to the IP protocol (acronym for Internet Protocol) request processing and transfer services offered by the home gateway.
  • the home gateway therefore presents an interface between the communicating objects present in the local network and the entire global network.
  • the interface device can also be a simple device for accessing a communications network, such as for example a base station giving a mobile telephone access to the mobile telephone network. The base station is then seen as building a local network limited to the mobile telephone connected to the station and offering an interface between this local network and a global telephone network or the Internet network if the mobile telephone is a smartphone and has the capabilities of communication on this network.
  • Communicating objects are likely to be lost or stolen, especially when they are portable objects, such as computers, tablets, smartphones, or objects such as connected speakers, surveillance cameras . In this case, the owner of the object in question will search for it.
  • Mobile telecommunications operators have implemented the possibility of reporting mobile phone theft. This declaration is made by entering the IMEI number of the phone, which is a unique identifier for each mobile phone.
  • the telephone numbers thus provided can then be used by telephone operators to prevent access to the telephone service of telephones whose IMEI number is present on a centralized database in the mobile operator's core network.
  • this system does not prevent the stolen mobile phone from being reused using its connection capabilities to local networks, for example via a wireless local network using the WiFi protocol.
  • the detection of a possible stolen phone does not result in any action on the part of the mobile network operator other than the impossibility of accessing the telephone network and does not trigger actions linked to the location of the phone. phone reported stolen.
  • the Apple company also offered a location service (FindMyTM) and blocking (Lost ModeTM) or erasing data from a lost or presumed stolen terminal.
  • This service uses a service platform (iCloudTM) which, from an identifier declared by the user, will send a command to the terminal whose standard operating mode is to report regularly to the platform.
  • iCloudTM service platform
  • This service therefore assumes that the terminal regularly connects to a dedicated service platform, and is based on actions implemented by the terminal. If such actions are not provided for by the stolen object, because its data has been updated for example, or because it is a simple object not intended for this, Apple protection services against theft are not going to work. Likewise if an action by the thief prevents the stolen object from connecting to the iCloud service platform.
  • the invention relates to a method of managing the connection to a network of a communicating object provided with an identifier characterized in that the method comprises the following steps implemented by a communication device. interface between the communicating object and the network:
  • protection actions for communicating objects sought by their legitimate owner, at the time of their request for connection to a network.
  • These protection actions are implemented by the interface device which connects the communicating object to the network.
  • These protection actions being implemented by the interface device apply to any communicating object, for any communication protocol that this interface device implements. A stolen mobile phone could therefore also be blocked if it tries to connect to the Internet via WiFi via a domestic gateway.
  • the location of the communicating object at the time of its connection request can be taken into account by the protection action.
  • the protection actions are not implemented by the communicating object concerned and therefore do not require special capabilities on its part.
  • a protection measure is implemented, namely the signaling to other objects connected to the interface device of the connection request of a desired communicating object.
  • This will allow, for example, an administrator of a local network to receive a signal from the home gateway which creates this local network that a desired communicating object is seeking to connect to the local network which it administers.
  • This signaling can be done without blocking the connection of the desired communicating object, therefore discreetly for this communicating object.
  • the method also comprises the following steps:
  • the interface device maintains a database of searched objects by receiving identifiers of the searched communicating objects. This reception can come from a centralized platform or from a decentralized system.
  • An advantage of locating the database within the interface device is to make it possible to implement an immediate reaction from the interface device following a connection request from a connected object whose identifier is present in the base. Other embodiments are possible.
  • the action includes a refusal of the connection of the communicating object to the interface device.
  • a first protection action consists of blocking, by the interface device, the connection of the communicating object.
  • the communicating object if it has been stolen, loses its capacity as a communicating object, which drastically limits the interest in the theft.
  • the action comprises an acceptance of the connection of the communicating object to the interface device and to the network .
  • the actions implemented by the interface device do not include blocking the connection of the communicating object to the network. In this way, protection actions can be implemented without this being reported to the communicating object supposedly stolen since its connection takes place normally.
  • the action comprises signaling by the interface device to a service platform located in the network of a connection request of a communicating object whose identifier appears in the database of communicating objects sought.
  • the interface device signals to a service platform the connection request made by a desired communicating object.
  • This signaling can take place whether or not the communicating object is ultimately connected to the requested network.
  • This signaling will make it possible to carry out other protective measures such as reporting to the authorities, taking into account the location of the communicating object sought, since it is the interface device which carries out the initial signaling.
  • the signaling is done while the connection of the communicating object is made by the interface device, the signaling is done discreetly with respect to the communicating object.
  • the database is located in the network and is queried by the interface device following 'a request for connection of a communicating object.
  • the interface device does not need to maintain a database comprising the identifiers of searched objects.
  • This mode will therefore be easier to deploy, and the interface devices according to the invention will not include the memory necessary for saving the database, which will save resources.
  • This mode has these advantages but has the disadvantage of adding a request from the interface device to a remote database during each connection request from a communicating object, which will extend the connection time to the interface device. interface for all communicating objects, including those that are not wanted.
  • the compared identifiers of communicating objects are MAC addresses.
  • MAC addresses are unique identifiers attached in hardware to all network cards used to create the network link of a communicating object. By using this identifier, the invention ensures that all categories of communicating objects can be searched for and have the invention applied. Indeed, this identifier is universal and will be found in all communicating objects. In addition, this identifier is easy to obtain by an interface device, because a network command sent by the interface device to the communicating object makes it possible to obtain it.
  • the compared identifiers of communicating objects are IMEI numbers.
  • the IMEI number is an identifier attached to mobile phones. Thanks to this embodiment, the invention can be applied when the desired communicating object is a mobile telephone which seeks to connect to a mobile telephone network.
  • the invention relates to an interface device between a communicating object provided with an identifier and a network implementing a method for managing the connection to the network of the communicating object characterized in that said interface device comprises the following modules: • A recovery module capable of recovering the identifier of the communicating object following a request for connection of the communicating object to the interface device
  • a comparison module capable of comparing the retrieved identifier with at least one identifier stored in a database of searched objects
  • a module capable of implementing an action based on the comparison, said action comprising a signaling by the interface device to the communicating objects connected to the interface device of a request for connection of a communicating object whose identifier appears in the search object database
  • a connection module capable of connecting the communicating object to the interface device and to the network
  • the invention relates to an interface device between a communicating object provided with an identifier and a network implementing a method for managing the connection to the network of the communicating object further comprising the following modules:
  • a reception module capable of receiving another communicating object identifier
  • a recording module capable of recording, in a database of desired communicating objects, said other received communicating object identifier
  • the invention relates to a domestic gateway between a local network and the Internet type network which comprises an interface device according to the invention.
  • the invention can be applied to any type of communicating object which seeks to connect to the Internet through an interface device such as a domestic gateway.
  • This aspect is particularly suitable when the identifier used is the MAC address of the communicating object sought.
  • the invention relates to a base station of a mobile telephone network which comprises an interface device according to the invention. Thanks to this aspect, the invention applies to the search for a stolen mobile phone and is particularly suitable when the identifier used is an IMEI number.
  • the invention relates to a computer program capable of being implemented by an interface device, the program comprising code instructions which, when executed by a processor, carries out the steps of the method according to the invention for managing the connection to a network of a communicating object.
  • the invention relates to a data medium on which is recorded a computer program comprising a sequence of instructions for implementing the management method according to the invention when it is loaded in and executed by a processor.
  • Data carriers can be any entity or device capable of storing programs.
  • the media may comprise a storage means, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or even a magnetic recording means such as a hard disk.
  • the media may be transmissible media such as an electrical or optical signal, which may be carried via an electrical or optical cable, by radio or by other means.
  • the programs according to the invention can in particular be downloaded over an Internet type network.
  • the information carrier may be an integrated circuit in which the program is incorporated, the circuit being adapted to execute or to be used in executing the method in question.
  • FIG 1 represents an interface device according to the invention, ensuring the connection of a communicating object present in a local network to a global network.
  • Figure 1 represents an example of an interface device 100 ensuring the connection of communicating objects present in a local network LAN (from the English Local Area Network to an extended communication network WAN (from the English Wide Area Network.
  • the local network LAN includes communicating objects 01, 02, 03 which are attached to this LAN network via the interface device 100.
  • the interface device 100 can be for example a domestic gateway which, on the one hand creates a local LAN network in which communicating objects 01, 02, 03 can communicate with each other and on the other hand connects the communicating objects 01 , 02, 03 present in the LAN network with an extended WAN communication network such as for example the Internet network.
  • the local network LAN can be created by the device 100 by deploying a wireless communication protocol such as WiFi or by ensuring wired communications between the communicating objects 01, 02, 03 and itself.
  • the interface device 100 then plays the role of router for the local LAN network.
  • the device 100 also ensures the connection of the communicating objects 01, 02, 03 to the extended WAN communication network, generally the Internet network in the case of a domestic gateway.
  • the WAN network can also be a corporate network and the interface device 100 a gateway responsible for managing a local LAN network on one of the company's sites.
  • the interface device 100 can also be a base station of a mobile telephone network.
  • the interface device does not maintain a local LAN network for several communicating objects but it can be considered that it creates a local LAN network for a communicating object which connects to the device 100.
  • This LAN network will be used exclusively for communication between a communicating object which is a mobile telephone, and the device 100 which is a base station, the device 100 also ensuring access of the mobile telephone to the WAN telephone network.
  • the interface device 100 has the hardware architecture of a conventional computer. It notably comprises a processor, a RAM type random access memory and a read only memory such as a Flash type memory, ROM, (not shown in the figure).
  • the device 100 may have input-output devices such as buttons, keyboards, screens (not shown in the figure) but this is not a general obligation, because the interface device 100 is generally dedicated to the realization of the interfacing service between the two networks LAN and WAN and does not always require interacting with users.
  • input-output devices such as buttons, keyboards, screens (not shown in the figure) but this is not a general obligation, because the interface device 100 is generally dedicated to the realization of the interfacing service between the two networks LAN and WAN and does not always require interacting with users.
  • the interface device 100 comprises a CON connection module capable of connecting a communicating object provided with an identifier to the interface device 100 and to the WAN network.
  • the CON connection module fulfills all of the functions expected of the interface device 100 independently of its implementation of the invention.
  • the interface device 100 comprises a reception module 101 capable of receiving REC another communicating object identifier II, but other embodiments are possible, not including this module.
  • the interface device 100 comprises a recording module 102 capable of recording REG in a database BDD of communicating objects searched for said other identifier II of received communicating object REC, but other embodiments are possible, not including this module.
  • the interface device 100 comprises a recovery module 103 capable of recovering COL the identifier I of a communicating object O following a connection request from the communicating object O to the interface device 100.
  • the interface device 100 comprises a comparison module 104 capable of comparing COM the retrieved identifier I COL with at least one identifier II stored in a BDD database of searched objects.
  • the interface device 100 comprises a module 105 capable of implementing an ACT action as a function of the COM comparison, said ACT action comprising signaling by the interface device to communicating objects 01, 02, 03 connected to the interface device 100 of a connection request from a communicating object O whose identifier I appears in the database of searched objects.
  • the method according to the invention begins with a step of receiving REC of a communicating object identifier II.
  • This REC step is implemented by module 101 of interface device 100.
  • the identifier II in question is that of a communicating object sought by its legitimate owner.
  • the item in question may be lost or may have been stolen.
  • a service platform has been set up to allow a user of the service to declare an identifier II of the desired communicating object.
  • This service platform will allow the interface device 100 to receive REC the identifier II of the desired communicating object.
  • This REC reception step can be done at the initiative of the service platform which will submit the identifier II to the interface device 100 or at the initiative of the interface device 100 which can regularly request the service platform what are the identifiers II of the communicating object sought.
  • This distinction has no importance in the context of the invention, and the device 100 according to the invention can implement the REC reception step in these two ways.
  • the method according to the invention will see its effectiveness increase with the number of interface devices 100 implementing the invention.
  • a telecommunications operator will thus be able to implement the invention in all of the domestic gateways that it provides to its customers to access the Internet as well as in the base stations of the mobile telephone network that it operates.
  • the identifier II depends on the nature of the communicating object sought.
  • a communicating object has a network card to carry out the communication operations specific to its nature of communicating object and therefore has a MAC address attached to the network card.
  • This MAC address can therefore be an identifier II of the communicating object sought for all communicating objects.
  • the communicating object sought is a telephone mobile
  • its IMEI number can be an identifier.
  • Other identifiers may be received REC.
  • the interface device 100 then proceeds to a REG recording step of the identifier II in a BDD database of searched objects.
  • the REG recording operation allows the interface device 100 to have an up-to-date BDD database of searched object identifiers.
  • the BDD database can be a relational database implemented using the SQL query language (Structured Query Language) or, on the contrary, an object database not using the principles of relational databases ( so-called “NoSQL” databases) or be limited to a file recorded in the RAM or dead memory of the interface device 100 in which the relevant information is recorded.
  • the BDD database is recorded in the interface device 100, in a memory area of the interface device 100 and is accessible directly by queries executed by the interface device 100.
  • the BDD database is not stored in the interface device but is hosted by a device that can be accessed via the WAN communication network. This device can be a classic server or a server deployed in a cloud computing architecture.
  • the interface device 100 does not have to register REG the first identifier II. It is a centralized service platform that is responsible for updating the database of searched objects.
  • the interface device 100 receives requests as part of its usual operation as an interface device. connection from objects communicators.
  • the interface device 100 When the interface device 100 receives a connection request from the communicating object O, it will proceed to a COL recovery step of an identifier I of the communicating object O. To recover an identifier I which is a MAC address , the interface device 100 simply needs to send a specific network command to the communicating object O, such as a “ping” command. In response to this command, the communicating object O provides its MAC address which is therefore recovered COL by the interface device 100.
  • a specific network command such as a “ping” command.
  • the next step of the method then consists of the interface device COM comparing the retrieved identifier I COL with an identifier II stored in a BDD database of searched objects.
  • the identifier II was received REC then recorded REG in the database BDD of objects searched by the interface device 100.
  • the comparison step COM in general, will not be carried out. apply to a single identifier II but to all the identifiers registered REG in the BDD database as the interface device 100 operates, taking into account the updates of the BDD database.
  • the COM comparison operation consists of a remote query of the BDD database. This request is made via the WAN communication network.
  • the interface device 100 will or will not carry out an ACT action specific to the method according to the invention.
  • the device 100 will proceed to the connection request of the communicating object O as expected from the standard operation of the interface device 100. This connection request will then be processed by the CON module dedicated to this function of the interface device 100. In this case, the interface device 100 will not perform an ACT action specific to the process according to the invention.
  • the comparison operation COM reveals that the identifier I of the communicating object O corresponds to the identifier of an object sought because it is present in the database BDD, the device 100 will carry out an ACT action specific to the process according to the invention.
  • the ACT action in question can take several forms depending on the embodiments of the method according to the invention.
  • the ACT action includes a signaling by the device 100 to the other communicating objects 01, 02, 03 present in the local network LAN of the connection request of a potentially stolen object O.
  • the device 100 is a domestic gateway ensuring the possibility of access to the WAN network for a public place such as a hotel, a restaurant, a place of passage such as a station or an airport, the signaling can make it possible to try to find the potentially stolen object O. This signaling must not be made to the object O in question and can be combined with a refusal or acceptance of the connection of the object O to the WAN network.
  • the ACT action includes the refusal by the device 100 of the connection of the communicating object O.
  • the communicating object O will then not be able to connect to the device 100 nor a fortiori to the LAN and WAN networks to which the device 100 provides access. In this way, the communicating object O can no longer be used as a communicating object. If it has been stolen, as indicated by the presence of the identifier I in the BDD database of wanted objects, the object O will therefore no longer be usable in its communication function.
  • the ACT blocking action including a connection refusal is therefore a deterrent action regarding the theft of communicating objects.
  • the ACT action includes acceptance by the device 100 of the connection of the communicating object O. This acceptance can then allow the communicating object O to access the WAN network.
  • the advantage of this mode may be not to signal to the holder of the communicating object O, who is potentially its thief, that the object O has indeed been identified as belonging to the BDD database of wanted objects.
  • the owner of object O is not alerted by a blockage.
  • the ACT action includes signals of the connection request of the object O to the interface device 100. If the ACT action includes an acceptance of the connection of the object O, these Signals are made without alerting the holder of the object O which is potentially stolen.
  • a possible signaling within the framework of the ACT action carried out by the device 100 is to signal to a service platform the request for connection of the object O to the device 100.
  • This service platform can be linked to the one which provided the first identifier II of a desired communicating object.
  • the device 100 signals that a searched object is seeking to connect to the device 100 and more generally to the WAN network.
  • the device 100 can also provide its location and this information will allow the manager of the service platform to take subsequent measures to find the potentially stolen object O, as well as its current holder, potentially thief.
  • identifiers I and II are MAC addresses. MAC addresses are present on all communicating objects because they are assigned to each network card, therefore to any communicating object.
  • the portable computers could therefore be identified by an interface device 100 according to the invention.
  • a connected vehicle could also be identified by an interface device 100 according to the invention when passing near the local LAN network created by the interface device 100.
  • Domestic objects such as connected cameras, connected speakers, connected televisions could also be identified by interface devices 100 according to the invention.
  • the connected object O is a mobile phone or a tablet which seeks to connect to the device 100 using the WiFi protocol, a device 100 according to the invention which fulfills the role of domestic gateway will also be able to locate the communicating object O.
  • the identifiers I and II are IMEI numbers. These modes make it possible to apply the invention to the search for mobile terminals or smartphones seeking to connect to a mobile telephone network.
  • the interface device 100 then plays the role of base station of the mobile telephone network.
  • the invention it is therefore possible to implement protection actions making it possible to block the communication functions of stolen or lost communicating objects as well as to signal their location. Signaling can be done without alerting the holder of the stolen or lost communicating object O if the ACT action does not include blocking the connection request.
  • the invention does not assume any action carried out by the stolen or lost object and can therefore be applied to all categories of communicating objects, regardless of their functionalities and manufacturers.
  • Another advantage is that the method is implemented by the interface device 100 to which the communicating object O connects, and the method can therefore have fairly precise location information of the communicating object O. The location of the communicating object O can be approximated by the location of the interface device 100 to which the object O seeks to connect.
  • module can correspond as well to a software component as to a hardware component or a set of hardware and software components, a software component itself corresponding to one or more programs or computer subprograms or more generally to any element of a program capable of implementing a function or a set of functions as described for the modules concerned.
  • a hardware component corresponds to any element of a hardware assembly capable of implementing a function or a set of functions for the module concerned (integrated circuit, smart card, memory card, etc. .).

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Telephonic Communication Services (AREA)
  • Data Exchanges In Wide-Area Networks (AREA)

Abstract

L'invention se rapporte à un procédé de gestion de la connexion à un réseau (WAN) 5 d'un objet communicant (O) muni d'un identifiant (I) caractérisé en ce que le procédé comprend les étapes suivantes mises en œuvre par un dispositif d'interface (100) entre l'objet communicant (O) et le réseau (WAN) : • A la suite d'une demande de connexion de l'objet communicant (O) au dispositif d'interface (100), récupérer (COL) l'identifiant (I) de l'objet communicant (O) • Comparer (COM) l'identifiant (I) récupéré (COL) avec au moins un identifiant (I1) mémorisé dans une base de données (BDD) d'objets recherchés • En fonction du résultat de la comparaison (COM), réaliser une action (ACT) ayant trait à la connexion de l'objet communicant (O) au réseau (WAN), ladite action (ACT) comprenant la signalisation aux objets connectés au dispositif d'interface (100) d'une demande de connexion d'un objet communicant dont l'identifiant (I) apparaît dans la base de données (BDD) d'objets recherchés.

Description

Description
Titre : Procédé de gestion de la connexion à un réseau d'un objet communicant mis en œuvre par un dispositif d'interface
Domaine technique
Le domaine technique est celui de la gestion d'objets communicants.
Plus précisément, l'invention se rapporte à un procédé de gestion de la connexion à un réseau d'un objet communicant. Cet objet communicant peut être recherché, c'est-à-dire qu'il a pu être déclaré comme perdu ou volé par son propriétaire qui recherche des informations à son sujet.
L'invention se rapporte également à un dispositif d'interface, tel qu'une passerelle domestique, mettant en œuvre le procédé de gestion conforme à l'invention.
Les objets communicants dont il est question sont des équipements de toute nature qui disposent d'une capacité de communication selon un protocole défini. Il peut s'agir par exemple d'un ordinateur, portable ou non, qui peut se connecter à un réseau local par une connexion sans fil ou filaire, puis grâce à une passerelle présente sur le réseau local, pourra se connecter au réseau Internet. Un tel ordinateur peut avoir une forme de tablette, réduite à un écran, utilisant un clavier tactile. Il peut également s'agir d'un téléphone qui va se connecter à un réseau téléphonique mobile ou non. Cette connexion à un réseau téléphonique peut ensuite permettre au téléphone mobile de se connecter également au réseau Internet. On parlera alors d'ordiphone, traduction de l'anglais smartphone.
Les objets communicants peuvent être aussi des objets dédiés à une fonction précise, qui disposent de surcroît de moyens leur permettant de se connecter à un réseau local puis au réseau Internet pour mieux remplir leur fonction. Il s'agira par exemple d'une caméra de surveillance qui pourra envoyer ses images via Internet, une enceinte capable de récupérer de la musique sur Internet, une voiture disposant de moyens de communications embarqués qui lui permettent de récupérer des informations de navigation, d'un réfrigérateur pouvant passer sur Internet des commandes de denrées alimentaires quand il n'en contient plus, d'un conteneur de marchandises disposant d'une puce qui va remonter régulièrement des informations au sujet de son environnement (température, déplacement éventuel) et des marchandises qu'il contient. En général, les objets modernes comprennent de plus en plus des moyens de communication qui leur permettent d'être connectés au réseau Internet et peuvent donc être qualifiés d'objets communicants.
L'accès des objets communicants au réseau Internet se fait par l'intermédiaire d'un dispositif d'interface qui fournit à l'objet communicant le service d'accès au réseau de communication. Le dispositif d'interface peut être une passerelle domestique qui construit un réseau local auquel appartient l'objet communicant ; depuis le réseau local, l'objet communicant peut accéder à un réseau global tel qu'internet grâce aux services de traitement et de transfert des requêtes du protocole IP (acronyme de l'anglais Internet Protocol) qu'offre la passerelle domestique. La passerelle domestique présente donc une interface entre les objets communicants présents dans le réseau local et l'ensemble du réseau global. Le dispositif d'interface peut être aussi un simple dispositif d'accès à un réseau de communication, tel que par exemple une station de base donnant à un téléphone mobile l'accès au réseau de téléphonie mobile. La station de base est vue alors comme construisant un réseau local limité au téléphone mobile connecté à la station et offrant une interface entre ce réseau local et un réseau global de téléphonie ou le réseau Internet si le téléphone mobile est un ordiphone et dispose des capacités de communication sur ce réseau.
Etat de la technique
Les objets communicants sont susceptibles d'être perdus ou volés, d'autant plus quand il s'agit d'objets portables, tels des ordinateurs, des tablettes, des ordiphones, ou d'objets tels que des enceintes connectées, des caméras de surveillance. Dans ce cas, le propriétaire de l'objet en question va le rechercher.
Il n'existe pas de procédé général permettant d'utiliser les capacités de communication des objets communicants afin de parer à ce risque. Lorsqu'un objet communicant est volé ou égaré, il pourra donc être réutilisé par quelqu'un d'autre que son propriétaire légitime, y compris dans sa fonction de communication.
Les opérateurs de télécommunications mobiles ont mis en place une possibilité de déclaration d'un vol de téléphone mobile. Cette déclaration se fait en renseignant le numéro IMEI du téléphone, qui est un identifiant unique de chaque téléphone mobile. Les numéros de téléphone ainsi renseignés peuvent alors être utilisés par les opérateurs de téléphonie pour empêcher l'accès au service de téléphonie des téléphones dont le numéro IMEI est présent sur une base de données centralisée dans le cœur de réseau de l'opérateur mobile. Cependant, ce système n'empêche pas de réutiliser le téléphone mobile volé en utilisant ses capacités de connexion à des réseaux locaux, par exemple via un réseau local sans fil utilisant le protocole WiFi. De plus, la détection d'un éventuel téléphone volé n'entraîne aucune action de la part de l'opérateur de réseau mobile autre que l'impossibilité d'accéder au réseau de téléphonie et ne déclenche pas des actions en lien avec la localisation du téléphone signalé volé.
La société Apple a également proposé un service de localisation (FindMy™) et de blocage (Lost Mode™) ou d'effacement des données d'un terminal perdu ou supposé volé. Ce service utilise une plate-forme de service (iCloud™) qui, à partir d'un identifiant déclaré par l'utilisateur, va envoyer une commande au terminal dont le mode de fonctionnement standard est de se signaler régulièrement à la plate-forme de service iCloud. Ce service suppose donc que le terminal se connecte régulièrement à une plate-forme de service dédiée, et repose sur des actions implémentées par le terminal. Si de telles actions ne sont pas prévues par l'objet dérobé, parce que ses données ont été remises à jour par exemple, ou bien parce qu'il s'agit d'un objet simple non prévu pour cela, les services Apple de protection contre le vol ne vont pas fonctionner. De même si une action du voleur empêche l'objet dérobé de se connecter à la plate-forme de service iCloud.
Il existe donc un besoin pour une protection générale en cas de perte ou de vol s'appliquant à l'ensemble des objets communicants, indépendamment des services de communication qu'ils utilisent et indépendamment des capacités de ses objets communicants. L'invention vient améliorer la situation.
Exposé de l'invention
Selon un premier aspect fonctionnel, l'invention a trait à un procédé de gestion de la connexion à un réseau d'un objet communicant muni d'un identifiant caractérisé en ce que le procédé comprend les étapes suivantes mises en œuvre par un dispositif d'interface entre l'objet communicant et le réseau :
• A la suite d'une demande de connexion de l'objet communicant au dispositif d'interface, récupérer l'identifiant de l'objet communicant
• Comparer l'identifiant récupéré avec au moins un identifiant mémorisé dans une base de données d'objets recherchés
• En fonction du résultat de la comparaison, réaliser une action ayant trait à la connexion de l'objet communicant au réseau, ladite action comprenant une signalisation par le dispositif d'interface aux objets communicants connectés au dispositif d'interface d'une demande de connexion d'un objet communicant dont l'identifiant apparaît dans la base de données d'objets recherchés
Grâce à l'invention, il est possible de mettre en œuvre des actions de protection pour des objets communicants recherchés par leur propriétaire légitime, et ce au moment de leur demande de connexion à un réseau. Ces actions de protection sont mises en œuvre par le dispositif d'interface qui réalise la connexion de l'objet communicant au réseau. Ces actions de protection étant mises en œuvre par le dispositif d'interface s'appliquent à tout objet communicant, pour tout protocole de communication que met en œuvre ce dispositif d'interface. Un téléphone mobile volé pourra donc être bloqué aussi s'il cherche à se connecter en WiFi à Internet via une passerelle domestique. Par ailleurs, de cette manière, la localisation de l'objet communicant au moment de sa demande de connexion peut être prise en compte par l'action de protection. De plus, les actions de protection ne sont pas mises en œuvre par l'objet communicant concerné et ne nécessitent donc pas de capacités spéciales de la part de celui-ci. Grâce à l'invention, une mesure de protection est mise en œuvre, à savoir la signalisation aux autres objets connectés au dispositif d'interface de la demande de connexion d'un objet communicant recherché. Cela permettra par exemple à un administrateur d'un réseau local de recevoir une signalisation depuis la passerelle domestique qui crée ce réseau local qu'un objet communicant recherché cherche à se connecter sur le réseau local qu'il administre. Cette signalisation pourra se faire sans bloquer la connexion de l'objet communicant recherché, donc de manière discrète pour cet objet communicant.
Selon un premier mode de mise en œuvre particulier de l'invention, le procédé comprend de surcroît les étapes suivantes :
• Recevoir un autre identifiant d'objet communicant
• Enregistrer dans la base de données d'objets recherchés ledit autre identifiant d'objet communicant reçu
Dans ce mode de réalisation, le dispositif d'interface maintient une base de données d'objets recherchés en recevant des identifiants des objets communicants recherchés. Cette réception peut provenir d'une plate-forme centralisée ou bien d'un système décentralisé. Un avantage de la localisation de la base de données au sein du dispositif d'interface est de permettre de mettre en œuvre une réaction immédiate du dispositif d'interface à la suite d'une demande de connexion d'un objet connecté dont un identifiant est présent dans la base. D'autres modes de réalisation sont possibles.
Selon un deuxième mode de mise en œuvre particulier de l'invention, qui pourra être mis en œuvre alternativement ou cumulativement avec le précédent mode, l'action comprend un refus de la connexion de l'objet communicant au dispositif d'interface.
Grâce à ce mode de réalisation, une première action de protection consiste en le blocage, par le dispositif d'interface, de la connexion de l'objet communicant. De cette manière, l'objet communicant, s'il a été volé, perd sa capacité d'objet communicant ce qui limite drastiquement l'intérêt du vol. Selon un troisième mode de mise en œuvre particulier de l'invention, qui pourra être mis en œuvre alternativement ou cumulativement avec les précédents modes, l'action comprend une acceptation de la connexion de l'objet communicant au dispositif d'interface et au réseau.
Grâce à ce mode de réalisation, les actions mises en œuvre par le dispositif d'interface ne comprennent pas le blocage de la connexion de l'objet communicant au réseau. De cette manière, des actions de protection peuvent être mises en œuvre sans que cela ne soit signalé à l'objet communicant supposé volé puisque sa connexion se déroule normalement.
Selon un quatrième mode de mise en œuvre particulier de l'invention, qui pourra être mis en œuvre alternativement ou cumulativement avec les modes précédents, l'action comprend une signalisation par le dispositif d'interface à une plate-forme de service située dans le réseau d'une demande de connexion d'un objet communicant dont l'identifiant apparaît dans la base d'objets communicants recherchés.
Grâce à ce mode de réalisation, le dispositif d'interface signale à une plate-forme de service la demande de connexion réalisée par un objet communicant recherché. Cette signalisation peut avoir lieu que l'objet communicant soit connecté ou pas finalement au réseau demandé. Cette signalisation permettra de réaliser d'autres mesures de protection comme un signalement aux autorités, en prenant en compte la localisation de l'objet communicant recherché, puisque c'est le dispositif d'interface qui réalise la signalisation initiale. Quand la signalisation se fait alors que la connexion de l'objet communicant est réalisée par le dispositif d'interface, la signalisation se fait de façon discrète par rapport à l'objet communicant.
Selon un cinquième mode de mise en œuvre particulier de l'invention, qui pourra être mis en œuvre alternativement ou cumulativement avec les modes précédents, la base de données est située dans le réseau et est interrogée par le dispositif d'interface à la suite d'une demande de connexion d'un objet communicant.
Grâce à ce mode de réalisation, le dispositif d'interface n'a pas besoin de maintenir une base de données comprenant les identifiants d'objets recherchés. Ce mode sera donc plus facile à déployer, et les dispositifs d'interface selon l'invention ne comprendront pas la mémoire nécessaire à la sauvegarde de la base de données, ce qui permettra d'économiser des ressources. Ce mode présente ces avantages mais présente l'inconvénient d'ajouter une requête du dispositif d'interface à une base de données distante lors de chaque demande de connexion d'un objet communicant, ce qui va allonger le temps de connexion au dispositif d'interface pour tous les objets communicants, y compris ceux qui ne sont pas recherchés.
Selon un sixième mode de mise en œuvre particulier de l'invention, qui pourra être mis en œuvre alternativement ou cumulativement avec les modes précédents, les identifiants comparés d'objets communicants sont des adresses MAC.
Les adresses MAC sont des identifiants uniques attachés de façon matérielle à l'ensemble des cartes réseau servant à réaliser la liaison réseau d'un objet communicant. En utilisant cet identifiant, l'invention permet de s'assurer que toutes les catégories d'objets communicants pourront être recherchés et se faire appliquer l'invention. En effet, cet identifiant est universel et va se retrouver dans tous les objets communicants. De plus, cet identifiant est facile à obtenir par un dispositif d'interface, car une commande réseau adressé par le dispositif d'interface à l'objet communicant permet de l'obtenir.
Selon un septième mode de mise en œuvre particulier de l'invention, qui pourra être mis en œuvre alternativement ou cumulativement avec les modes précédents, les identifiants comparés d'objets communicants sont des numéros IMEI.
Le numéro IMEI est un identifiant attaché aux téléphones mobiles. Grâce à ce mode de réalisation, l'invention peut s'appliquer quand l'objet communicant recherché est un téléphone mobile qui cherche à se connecter à réseau de téléphonie mobile.
Selon un premier aspect matériel, l'invention a trait à un dispositif d'interface entre un objet communicant muni d'un identifiant et un réseau mettant en œuvre un procédé de gestion de la connexion au réseau de l'objet communicant caractérisé en ce que ledit dispositif d'interface comprend les modules suivants : • Un module de récupération apte à récupérer l'identifiant de l'objet communicant à la suite d'une demande de connexion de l'objet communicant au dispositif d'interface
• Un module de comparaison apte à comparer l'identifiant récupéré avec au moins un identifiant mémorisé dans une base de données d'objets recherchés
• Un module apte à mettre en œuvre une action en fonction de la comparaison, ladite action comprenant une signalisation par le dispositif d'interface aux objets communicants connectés au dispositif d'interface d'une demande de connexion d'un objet communicant dont l'identifiant apparaît dans la base de données d'objets recherchés
• Un module de connexion apte à connecter l'objet communicant au dispositif d'interface et au réseau
Selon un autre aspect matériel, l'invention a trait à un dispositif d'interface entre un objet communicant muni d'un identifiant et un réseau mettant en œuvre un procédé de gestion de la connexion au réseau de l'objet communicant comprenant de surcroît les modules suivants :
• Un module de réception apte à recevoir un autre identifiant d'objet communicant
• Un module d'enregistrement apte à enregistrer, dans une base de données d'objets communicants recherchés, ledit autre identifiant d'objet communicant reçu
Selon un autre aspect matériel, l'invention a trait à une passerelle domestique entre un réseau local et le réseau de type Internet qui comprend un dispositif d'interface selon l'invention.
Grâce à cet aspect, l'invention peut s'appliquer à tout type d'objet communicant qui cherche à se connecter à Internet à travers un dispositif d'interface tel qu'une passerelle domestique. Cet aspect est particulièrement adapté quand l'identifiant utilisé est l'adresse MAC de l'objet communicant recherché.
Selon un autre aspect matériel, l'invention a trait à une station de base d'un réseau de téléphonie mobile qui comprend un dispositif d'interface selon l'invention. Grâce à cet aspect, l'invention s'applique à la recherche de téléphone mobile volé et est particulièrement adapté quand l'identifiant utilisé est un numéro IMEI.
Selon un autre aspect matériel, l'invention a trait à un programme d'ordinateur apte à être mis en œuvre par un dispositif d'interface, le programme comprenant des instructions de code qui, lorsqu'il est exécuté par un processeur, réalise les étapes du procédé conforme à l'invention de gestion de la connexion à un réseau d'un objet communicant.
Selon un autre aspect matériel, l'invention a trait à un support de données sur lequel est enregistré un programme d'ordinateur comprenant une séquence d'instructions pour la mise en œuvre du procédé de gestion conforme à l'invention lorsqu'il est chargé dans et exécuté par un processeur.
Les supports de données peuvent être n'importe quelle entité ou dispositif capable de stocker les programmes. Par exemple, les supports peuvent comporter un moyen de stockage, tel qu'une ROM, par exemple un CD ROM ou une ROM de circuit microélectronique, ou encore un moyen d'enregistrement magnétique tel qu'un un disque dur. D'autre part, les supports peuvent être des supports transmissibles tels qu'un signal électrique ou optique, qui peuvent être acheminés via un câble électrique ou optique, par radio ou par d'autres moyens. Les programmes selon l'invention peuvent être en particulier téléchargés sur un réseau de type Internet. Alternativement, le support d'informations peut être un circuit intégré dans lequel le programme est incorporé, le circuit étant adapté pour exécuter ou pour être utilisé dans l'exécution du procédé en question.
Brève description des figures
L'invention sera mieux comprise à la lecture de la description qui suit, donnée à titre d'exemple, et faite en référence aux dessins annexés, à savoir :
[Fig 1] représente un dispositif d'interface selon l'invention, assurant la connexion d'un objet communicant présent dans un réseau local à un réseau global. Description détaillée
La figure 1 représente un exemple de dispositif d'interface 100 assurant la connexion d'objets communicants présents dans un réseau local LAN (de l'anglais Local Area Network à un réseau de communication étendu WAN (de l'anglais Wide Area Network . Le réseau local LAN comprend des objets communicants 01, 02, 03 qui sont attachés à ce réseau LAN par l'entremise du dispositif d'interface 100.
Le dispositif d'interface 100 peut être par exemple une passerelle domestique qui, d'une part crée un réseau local LAN dans lequel des objets communicants 01, 02, 03 peuvent communiquer entre eux et d'autre part réalise la connexion des objets communicants 01, 02, 03 présents dans le réseau LAN avec un réseau de communication étendu WAN tel que par exemple le réseau Internet. Le réseau local LAN peut être créé par le dispositif 100 en déployant un protocole de communication sans fil tel que WiFi ou bien en assurant des communications filaires entre les objets communicants 01, 02, 03 et lui-même. Le dispositif d'interface 100 joue alors un rôle de routeur pour le réseau local LAN. Le dispositif 100 assure aussi la connexion des objets communicants 01, 02, 03 au réseau de communication étendu WAN, en général le réseau Internet dans le cas d'une passerelle domestique. Cependant, le réseau WAN peut aussi être un réseau d'entreprise et le dispositif d'interface 100 une passerelle en charge de gérer un réseau local LAN sur un des sites de l'entreprise.
Le dispositif d'interface 100 peut être aussi une station de base d'un réseau de téléphonie mobile. Dans ce cas, le dispositif d'interface ne maintient pas un réseau local LAN pour plusieurs objets communicants mais on peut considérer qu'il crée un réseau local LAN pour un objet communicant qui se connecte au dispositif 100. Ce réseau LAN servira exclusivement à la communication entre un objet communicant qui est un téléphone mobile, et le dispositif 100 qui est une station de base, le dispositif 100 assurant également l'accès du téléphone mobile au réseau de téléphonie WAN. Le dispositif d'interface 100 présente l'architecture matérielle d'un ordinateur conventionnel. Il comporte notamment un processeur, une mémoire vive de type RAM et une mémoire morte telle qu'une mémoire de type Flash, ROM, (non représentés sur la figure). Le dispositif 100 peut présenter des dispositifs d'entrée- sortie tels que des boutons, claviers, écrans (non représentés sur la figure) mais ce n'est pas une obligation générale, car le dispositif d'interface 100 est en général dédié à la réalisation du service d'interfaçage entre les deux réseaux LAN et WAN et ne nécessite pas toujours d'interagir avec des utilisateurs.
Dans tous les cas, le dispositif d'interface 100 comprend un module CON de connexion apte à connecter un objet communicant muni d'un identifiant au dispositif d'interface 100 et au réseau WAN. Le module CON de connexion remplit l'ensemble des fonctions attendues du dispositif d'interface 100 indépendamment de sa mise en œuvre de l'invention.
Dans notre exemple, le dispositif d'interface 100 comprend un module 101 de réception apte à recevoir REC un autre identifiant II d'objet communicant, mais d'autres modes de réalisation sont possibles, ne comprenant pas ce module.
Dans notre exemple, le dispositif d'interface 100 comprend un module 102 d'enregistrement apte à enregistrer REG dans une base de données BDD d'objets communicants recherchés ledit autre identifiant II d'objet communicant reçu REC, mais d'autres modes de réalisation sont possibles, ne comprenant pas ce module.
Le dispositif d'interface 100 comprend un module 103 de récupération apte à récupérer COL l'identifiant I d'un objet communicant O à la suite d'une demande de connexion de l'objet communicant O au dispositif d'interface 100.
Le dispositif d'interface 100 comprend un module 104 de comparaison apte à comparer COM l'identifiant I récupéré COL avec au moins un identifiant II mémorisé dans une base de données BDD d'objets recherchés.
Le dispositif d'interface 100 comprend un module 105 apte à mettre en œuvre une action ACT en fonction de la comparaison COM, ladite action ACT comprenant une signalisation par le dispositif d'interface aux objets communicants 01, 02, 03 connectés au dispositif d'interface 100 d'une demande de connexion d'un objet communicant O dont l'identifiant I apparaît dans la base de données d'objets recherchés.
Dans notre exemple, le procédé selon l'invention commence par une étape de réception REC d'un identifiant II d'objet communicant. Cette étape REC est mise en œuvre par le module 101 du dispositif d'interface 100.
L'identifiant II en question est celui d'un objet communicant recherché par son propriétaire légitime. L'objet en question peut être égaré ou bien avoir été volé. Une plate-forme de service, dont les détails ne sont pas précisés davantage, a été mise en place pour permettre à un utilisateur du service la déclaration d'un identifiant II d'objet communicant recherché. Cette plate-forme de service permettra au dispositif d'interface 100 de recevoir REC l'identifiant II d'objet communicant recherché. Cette étape de réception REC peut se faire à l'initiative de la plate-forme de service qui va soumettre au dispositif d'interface 100 l'identifiant II ou bien à l'initiative du dispositif d'interface 100 qui peut demander régulièrement à la plate-forme de service quels sont les identifiants II d'objet communicant recherché. Cette distinction n'a pas d'importance dans le contexte de l'invention, et le dispositif 100 selon l'invention peut mettre en œuvre l'étape de réception REC selon ces deux manières.
Le procédé selon l'invention verra son efficacité augmenter avec le nombre de dispositifs d'interface 100 mettant en œuvre l'invention. Un opérateur de télécommunications pourra ainsi mettre en œuvre l'invention dans l'ensemble des passerelles domestiques qu'il fournit à ses clients pour accéder à Internet ainsi que dans les stations de base du réseau de téléphonie mobile qu'il opère.
L'identifiant II dépend de la nature de l'objet communicant recherché. Un objet communicant dispose d'une carte réseau pour effectuer les opérations de communication propre à sa nature d'objet communicant et dispose donc d'une adresse MAC attachée à la carte réseau. Cette adresse MAC peut donc être un identifiant II de l'objet communicant recherché pour la-totalité des objets communicants. Dans le cas où l'objet communicant recherché est un téléphone mobile, son numéro IMEI peut être un identifiant. D'autres identifiants peuvent être reçus REC.
Dans notre exemple, le dispositif d'interface 100 procède ensuite à une étape d'enregistrement REG de l'identifiant II dans une base de données BDD d'objets recherchés. L'opération d'enregistrement REG permet au dispositif d'interface 100 de disposer d'une base de données BDD à jour d'identifiants d'objets recherchés. La base de données BDD peut être une base de données relationnelles implémentée en utilisant le langage de requête SQL (de l'anglais Structured Query Language} ou bien au contraire une base de données objet n'utilisant pas les principes des bases de données relationnelles (bases de données dites « NoSQL ») ou bien se limiter à un fichier enregistré dans la mémoire vive ou morte du dispositif d'interface 100 dans lequel les informations pertinentes sont enregistrées.
D'autres opérations, non précisées, permettent de retirer des identifiants de la base de données BDD quand les objets communicants correspondant aux identifiants ne sont plus recherchés pour une raison quelconque. Ces étapes de mise à jour de la base de données BDD n'ont pas de particularités propres à l'invention et ne sont pas davantage détaillées ici.
Dans des modes de réalisation, la base de données BDD est enregistrée dans le dispositif d'interface 100, dans une zone mémoire du dispositif d'interface 100 et est accessible directement par des requêtes exécutées par le dispositif d'interface 100. Dans d'autres modes de réalisation, la base de données BDD n'est pas enregistrée dans le dispositif d'interface mais est hébergée par un dispositif qui peut être accédé par l'intermédiaire du réseau de communication WAN. Ce dispositif peut être un serveur classique ou bien un serveur déployé dans une architecture informatique en nuage (de l'anglais doud computing . Dans ces modes de réalisation, le dispositif d'interface 100 n'a pas à enregistrer REG le premier identifiant II. C'est à une plate-forme de service centralisée qu'incombe la responsabilité de la mise à jour de la BDD d'objets recherchés. Le dispositif d'interface 100 reçoit dans le cadre de son fonctionnement habituel comme dispositif d'interface des demandes de connexion de la part d'objets communicants. Lorsque le dispositif d'interface 100 reçoit une demande de connexion de l'objet communicant O, il va procéder à une étape de récupération COL d'un identifiant I de l'objet communicant O. Pour récupérer un identifiant I qui soit une adresse MAC, il suffit au dispositif d'interface 100 d'adresser une commande réseau spécifique à l'objet communicant O, comme une commande « ping ». En réponse à cette commande, l'objet communicant O fournit son adresse MAC qui est donc récupérée COL par le dispositif d'interface 100.
L'étape suivante du procédé consiste alors pour le dispositif d'interface à comparer COM l'identifiant I récupéré COL avec un identifiant II mémorisé dans une base de données BDD d'objets recherchés. Dans des exemples de réalisation, l'identifiant II a été reçu REC puis enregistré REG dans la base de données BDD d'objets recherchés par le dispositif d'interface 100. L'étape de comparaison COM, en général, ne va pas s'appliquer à un seul identifiant II mais bien à tous les identifiants enregistrés REG dans la base de données BDD au fur et à mesure du fonctionnement du dispositif d'interface 100, en prenant en compte les mises à jour de la base de données BDD.
Dans les modes de réalisation où la base de données BDD n'est pas hébergée par le dispositif d'interface 100, l'opération de comparaison COM consiste en une requête à distance de la base de données BDD. Cette requête se fait par l'intermédiaire du réseau de communication WAN.
Selon le résultat de l'opération de comparaison COM, le dispositif d'interface 100 procédera ou non à une action ACT spécifique du procédé selon l'invention.
Si l'opération de comparaison COM révèle que l'identifiant I de l'objet communicant O ne correspond à aucun des identifiants enregistrés REG dans la base de données BDD, le dispositif 100 va procéder à la demande de connexion de l'objet communicant O comme attendu du fonctionnement standard du dispositif d'interface 100. Cette demande de connexion sera alors traitée par le module CON dédié à cette fonction du dispositif d'interface 100. Dans ce cas, le dispositif d'interface 100 ne réalisera pas une action ACT spécifique du procédé selon l'invention. Au contraire, si l'opération de comparaison COM révèle que l'identifiant I de l'objet communicant O correspond à l'identifiant d'un objet recherché car présent dans la base de données BDD, le dispositif 100 va procéder à une action ACT spécifique au procédé selon l'invention. L'action ACT en question peut prendre plusieurs formes selon les modes de réalisation du procédé selon l'invention. L'action ACT comprend une signalisation par le dispositif 100 aux autres objets communicants 01, 02, 03 présents dans le réseau local LAN de la demande de connexion d'un objet O potentiellement volé. Si le dispositif 100 est une passerelle domestique assurant la possibilité d'accès au réseau WAN pour un lieu public tel qu'un hôtel, un restaurant, un lieu de passage tel qu'une gare ou un aéroport, la signalisation peut permettre d'essayer de retrouver l'objet O potentiellement volé. Cette signalisation ne doit pas être faite à l'objet O en question et peut se combiner à un refus ou à une acceptation de la connexion de l'objet O au réseau WAN.
Dans un mode de réalisation, l'action ACT comprend le refus par le dispositif 100 de la connexion de l'objet communicant O. L'objet communicant O ne pourra alors pas se connecter au dispositif 100 ni a fortiori aux réseaux LAN et WAN auxquels le dispositif 100 donne accès. De cette manière, l'objet communicant O n'est plus utilisable en tant qu'objet communicant. S'il a été volé, comme indiqué par la présence de l'identifiant I dans la base de données BDD d'objets recherchés, l'objet O ne sera donc plus utilisable dans sa fonction de communication. L'action ACT de blocage comprenant un refus de connexion est donc une action dissuasive quant au vol d'objets communicants.
Dans un autre mode de réalisation, l'action ACT comprend une acceptation par le dispositif 100 de la connexion de l'objet communicant O. Cette acceptation pourra ensuite permettre à l'objet communicant O d'accéder au réseau WAN. L'avantage de ce mode peut être de ne pas signaler au détenteur de l'objet communicant O, qui est potentiellement son voleur, que l'objet O a bien été identifié comme appartenant à la base de données BDD d'objets recherchés. En permettant à l'objet O de procéder à sa connexion, le détenteur de l'objet O n'est pas alerté par un blocage. Dans d'autres modes de réalisation, l'action ACT comprend des signalisations de la demande de connexion de l'objet O au dispositif d'interface 100. Si l'action ACT comprend une acceptation de la connexion de l'objet O, ces signalisations se font sans alerter le détenteur de l'objet O qui est potentiellement volé.
Une signalisation possible dans le cadre de l'action ACT effectuée par le dispositif 100 est de signaler à une plate-forme de service la demande de connexion de l'objet O au dispositif 100. Cette plate-forme de service peut être en lien avec celle qui a fourni le premier identifiant II d'un objet communicant recherché. En indiquant que l'objet communicant O possède un identifiant appartenant à la base de données BDD d'objets recherchés, le dispositif 100 signale qu'un objet recherché cherche à se connecter au dispositif 100 et plus généralement au réseau WAN. Le dispositif 100 peut également fournir sa localisation et cette information permettra au gestionnaire de la plate-forme de service de prendre des mesures ultérieures pour retrouver l'objet O potentiellement volé, ainsi que son détenteur actuel, potentiellement voleur.
Dans certains modes de réalisation, les identifiants I et II sont des adresses MAC. Les adresses MAC sont présentes sur tous les objets communicants car elles sont attribuées à chaque carte réseau, donc à tout objet communicant. Les ordinateurs portables pourraient donc être repérés par un dispositif d'interface 100 selon l'invention. Un véhicule connecté pourrait également être repéré par un dispositif d'interface 100 selon l'invention lors de son passage à proximité du réseau local LAN créé par le dispositif d'interface 100. Des objets domestiques tels que des caméras connectées, des enceintes connectées, des télévisions connectées pourraient également être repérées par des dispositifs d'interface 100 selon l'invention. Si l'objet connecté O est un téléphone portable ou une tablette qui cherche à se connecter au dispositif 100 grâce au protocole WiFi, un dispositif 100 selon l'invention qui remplit le rôle de passerelle domestique pourra également repérer l'objet communicant O. Ces exemples montrent la portée générale de l'invention, ce qui est un avantage clair.
Dans d'autres modes de réalisation, les identifiants I et II sont des numéros IMEI. Ces modes permettent d'appliquer l'invention à la recherche de terminaux mobiles ou d'ordiphones qui cherchent à se connecter à un réseau de téléphonie mobile. Le dispositif d'interface 100 joue alors le rôle de station de base du réseau de téléphonie mobile.
Grâce à l'invention, il est donc possible de mettre en œuvre des actions de protection permettant de bloquer les fonctions de communication d'objets communicants dérobés ou égarés ainsi que de signaler leur localisation. La signalisation peut se faire sans alerter le détenteur de l'objet communicant O dérobé ou égaré si l'action ACT ne comprend pas le blocage de la demande de connexion. L'invention ne suppose aucune action effectuée par l'objet dérobé ou égaré et peut donc s'appliquer à toutes les catégories d'objets communicants, indépendamment de leurs fonctionnalités et fabricants. Un autre avantage est que le procédé est mis en œuvre par le dispositif d'interface 100 auquel l'objet communicant O se connecte, et le procédé peut donc disposer d'une information de localisation assez précise de l'objet communicant O. La localisation de l'objet communicant O peut être approchée par la localisation du dispositif d'interface 100 auquel l'objet O cherche à se connecter.
Signalons enfin ici que, dans le présent texte, le terme « module » peut correspondre aussi bien à un composant logiciel qu'à un composant matériel ou un ensemble de composants matériels et logiciels, un composant logiciel correspondant lui-même à un ou plusieurs programmes ou sous-programmes d'ordinateur ou de manière plus générale à tout élément d'un programme apte à mettre en œuvre une fonction ou un ensemble de fonctions telles que décrites pour les modules concernés. De la même manière, un composant matériel correspond à tout élément d'un ensemble matériel (ou hardware) apte à mettre en œuvre une fonction ou un ensemble de fonctions pour le module concerné (circuit intégré, carte à puce, carte à mémoire, etc.).

Claims

Revendications
1. Procédé de gestion de la connexion à un réseau (WAN) d'un objet communicant (O) muni d'un identifiant (I) caractérisé en ce que le procédé comprend les étapes suivantes mises en œuvre par un dispositif d'interface (100) entre l'objet communicant (O) et le réseau (WAN) :
• A la suite d'une demande de connexion de l'objet communicant (O) au dispositif d'interface (100), récupérer (COL) l'identifiant (I) de l'objet communicant (O)
• Comparer (COM) l'identifiant (I) récupéré (COL) avec au moins un identifiant (II) mémorisé dans une base de données (BDD) d'objets recherchés
• En fonction du résultat de la comparaison (COM), réaliser une action (ACT) ayant trait à la connexion de l'objet communicant (O) au réseau (WAN), ladite action (ACT) comprenant une signalisation par le dispositif d'interface (100) aux objets communicants (01, 02, 03) connectés au dispositif d'interface (100) d'une demande de connexion d'un objet communicant (O) dont l'identifiant (I) apparaît dans la base de données (BDD) d'objets recherchés
2. Procédé de gestion selon la revendication 1 caractérisé en ce que le procédé comprend de surcroît les étapes suivantes :
• Recevoir (REC) un autre identifiant (II) d'objet communicant
• Enregistrer (REG) dans la base de données (BDD) d'objets recherchés ledit autre identifiant (II) d'objet communicant reçu (REC)
3. Procédé de gestion selon l'une des revendications 1 ou 2 caractérisé en ce que l'action (ACT) comprend un refus de la connexion de l'objet communicant (O) au dispositif d'interface (100)
4. Procédé de gestion selon l'une des revendications 1 à 3 caractérisé en ce que l'action (ACT) comprend une acceptation de la connexion de l'objet communicant (O) au dispositif d'interface (100) et au réseau (WAN)
5. Procédé de gestion selon l'une des revendications 1 à 4 caractérisé en ce que l'action (ACT) comprend une signalisation par le dispositif d'interface (100) à une plate-forme de service située dans le réseau (WAN) d'une demande de connexion d'un objet communicant (O) dont l'identifiant (I) apparaît dans la base (BDD) d'objets communicants recherchés
6. Procédé de gestion selon l'une des revendications 1 à 5 caractérisé en ce que la base de données (BDD) est située dans le réseau (WAN) et est interrogée par le dispositif d'interface (100) à la suite d'une demande de connexion de l'objet communicant (O)
7. Dispositif d'interface (100) entre un objet communicant (O) muni d'un identifiant (I) et un réseau (WAN) mettant en œuvre un procédé de gestion de la connexion au réseau (WAN) de l'objet communicant (O) caractérisé en ce que le dispositif (100) comprend les modules suivants :
• Un module (103) de récupération apte à récupérer (COL) l'identifiant (I) de l'objet communicant (O) à la suite d'une demande de connexion de l'objet communicant (O) au dispositif d'interface (100)
• Un module (104) de comparaison apte à comparer (COM) l'identifiant (I) récupéré (COL) avec au moins un identifiant (II) mémorisé dans une base de données (BDD) d'objets recherchés
• Un module (105) apte à mettre en œuvre une action (ACT) en fonction de la comparaison (COM), ladite action (ACT) comprenant une signalisation par le dispositif d'interface (100) aux objets communicants (01, 02, 03) connectés au dispositif d'interface (100) d'une demande de connexion d'un objet communicant (O) dont l'identifiant (I) apparaît dans la base de données (BDD) d'objets recherchés
• Un module (106) de connexion apte à connecter l'objet communicant (O) au dispositif d'interface (100) et au réseau (WAN)
8. Dispositif d'interface (100) selon la revendication 7 caractérisé en ce qu'il comprend de surcroît :
• Un module (101) de réception apte à recevoir (REC) un autre identifiant (II) d'objet communicant
• Un module (102) d'enregistrement apte à enregistrer (REG), dans une base de données (BDD) d'objets communicants recherchés, ledit autre identifiant (II) d'objet communicant reçu (REC)
9. Passerelle domestique entre un réseau local (LAN) et le réseau (WAN) de type Internet qui comprend un dispositif d'interface (100) selon la revendication 7
10. Station de base d'un réseau (WAN) de téléphonie mobile qui comprend un dispositif d'interface (100) selon la revendication 7
11. Programme d'ordinateur apte à être mis en œuvre par un dispositif d'interface (100), le programme comprenant des instructions de code qui, lorsqu'il est exécuté par un processeur, réalise les étapes du procédé de gestion de la connexion à un réseau (WAN) d'un objet communicant (O) selon la revendication 1
12. Support de données sur lequel est enregistré un programme d'ordinateur selon la revendication 11 comprenant une séquence d'instructions pour la mise en œuvre du procédé de gestion conforme à la revendication 1 lorsqu'il est chargé dans et exécuté par un processeur
EP23821653.5A 2022-12-19 2023-12-12 Procédé de gestion de la connexion à un réseau d'un objet communicant mis en oeuvre par un dispositif d'interface Pending EP4639939A1 (fr)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
FR2213806A FR3143926A1 (fr) 2022-12-19 2022-12-19 Procédé de gestion de la connexion à un réseau d’un objet communicant mis en œuvre par un dispositif d’interface
PCT/EP2023/085271 WO2024132669A1 (fr) 2022-12-19 2023-12-12 Procédé de gestion de la connexion à un réseau d'un objet communicant mis en œuvre par un dispositif d'interface

Publications (1)

Publication Number Publication Date
EP4639939A1 true EP4639939A1 (fr) 2025-10-29

Family

ID=85570324

Family Applications (1)

Application Number Title Priority Date Filing Date
EP23821653.5A Pending EP4639939A1 (fr) 2022-12-19 2023-12-12 Procédé de gestion de la connexion à un réseau d'un objet communicant mis en oeuvre par un dispositif d'interface

Country Status (3)

Country Link
EP (1) EP4639939A1 (fr)
FR (1) FR3143926A1 (fr)
WO (1) WO2024132669A1 (fr)

Family Cites Families (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
WO2014117811A1 (fr) * 2013-01-29 2014-08-07 Telefonaktiebolaget L M Ericsson (Publ) Commande d'accès d'un équipement utilisateur à des services
US9860825B2 (en) * 2014-12-22 2018-01-02 Verizon Patent And Licensing Inc. Mobile hardware identity in an environment with multiple radio access networks
FR3044792A1 (fr) * 2015-12-07 2017-06-09 Orange Procede de securisation d'un terminal mobile et terminal correspondant
US11250172B2 (en) * 2018-04-28 2022-02-15 Hewlett Packard Enterprise Development Lp Handling wireless client devices associated with a role indicating a stolen device

Also Published As

Publication number Publication date
WO2024132669A1 (fr) 2024-06-27
FR3143926A1 (fr) 2024-06-21

Similar Documents

Publication Publication Date Title
US11540101B2 (en) Methods and systems for determining eSIM profile presence for reactivation
US20210089644A1 (en) Method, means, system, processor, and memory for intercepting malicious websites
US11726961B2 (en) Dynamically updating distributed content objects
US10750370B2 (en) Disabling a mobile device that has stolen hardware components
CN107147748B (zh) 文件上传方法和装置
KR20160044470A (ko) 배경 이미지를 설정하기 위한 방법, 서버 및 시스템
CA2913102A1 (fr) Mecanisme de securite remanent pour dispositif mobile
WO2015017581A1 (fr) Homologation sélective centralisée d'applications pour dispositifs mobiles
US20160088151A1 (en) Communication method, apparatus, and system
US20140040292A1 (en) System and method for massive call data storage and retrieval
CN102480501A (zh) 应用资源下载方法及相关设备
WO2009133029A1 (fr) Procede de diagnostic d'un terminal de telephonie mobile incluant des applications sans contact
CN109982293B (zh) 流量产品推送方法、系统、电子设备及存储介质
US9992664B2 (en) Determining network connection structure of target area
CN114640741A (zh) 一种未读消息的管理方法和设备
CN105320885A (zh) 恶意网站检测方法及装置
FR2894419A1 (fr) Procede et systeme pour gerer des donnees de dispositif de reseau et systeme de gestion de reseau
EP4639939A1 (fr) Procédé de gestion de la connexion à un réseau d'un objet communicant mis en oeuvre par un dispositif d'interface
CN105049452B (zh) 资源下载方式的切换方法、装置及智能终端
CN109756525B (zh) 信息订阅方法及装置
US11109189B2 (en) System and method for retrieving lost electronic device
CN105100251A (zh) 一种信息共享方法及装置
FR2791846A1 (fr) Terminal telephonique, support de donnees amovible pourvu(s) de moyens permettant la suppression de fonctionnalites communes et procede de gestion des menus de fonctionnalites correspondant
EP4360338A1 (fr) Procédé de détection de la présence d'une personne utilisatrice d'un dispositif communicant dans un environnement considéré
CN114912937B (zh) 一种生成广告跟踪标识的方法及相关设备

Legal Events

Date Code Title Description
STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: UNKNOWN

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE

PUAI Public reference made under article 153(3) epc to a published international application that has entered the european phase

Free format text: ORIGINAL CODE: 0009012

STAA Information on the status of an ep patent application or granted ep patent

Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE

17P Request for examination filed

Effective date: 20250716

AK Designated contracting states

Kind code of ref document: A1

Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC ME MK MT NL NO PL PT RO RS SE SI SK SM TR

DAV Request for validation of the european patent (deleted)
DAX Request for extension of the european patent (deleted)