WO2025003201A1 - Procédés de protection d'un équipement et de transmission de données, dispositifs et ensemble électroniques, produits programmes d'ordinateur et supports d'information correspondants - Google Patents
Procédés de protection d'un équipement et de transmission de données, dispositifs et ensemble électroniques, produits programmes d'ordinateur et supports d'information correspondants Download PDFInfo
- Publication number
- WO2025003201A1 WO2025003201A1 PCT/EP2024/067921 EP2024067921W WO2025003201A1 WO 2025003201 A1 WO2025003201 A1 WO 2025003201A1 EP 2024067921 W EP2024067921 W EP 2024067921W WO 2025003201 A1 WO2025003201 A1 WO 2025003201A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- packet
- equipment
- data
- transmission
- network
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0227—Filtering policies
- H04L63/0236—Filtering by address, protocol, port number or service, e.g. IP-address or URL
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/02—Network architectures or network communication protocols for network security for separating internal from external traffic, e.g. firewalls
- H04L63/0209—Architectural arrangements, e.g. perimeter networks or demilitarized zones
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
Definitions
- This application relates to the field of securing at least a portion of a communications network.
- It relates in particular to a method of protecting at least one item of equipment, implemented by a first electronic device of a first portion of a communication network, and a method of transmitting data, implemented by a second electronic device of a second portion of a communication network, as well as the corresponding electronic devices and assemblies, computer program products and information media.
- the present invention relates to the protection of at least one piece of equipment accessible via a communication network.
- this may be equipment handling sensitive data, or carrying out sensitive processing, and may therefore be the target of attack by malicious third parties, either to improperly access sensitive data, or to disrupt, or even prevent, certain processing via the propagation of a computer virus to the equipment.
- This equipment is, for example, part of a private company network or a home network, interconnected to a public network such as the Internet.
- Examples of sensitive data include personal data (medical data, banking data, etc.), industrial data (such as plans of manufactured objects, data relating to the production of certain industrial machines such as measurement results, number of parts produced, etc.), order histories received by industrial equipment, alerts, etc.
- Private network security solutions have been developed to protect equipment or a plurality of equipment belonging to the same private network from such attacks. Examples include solutions based on firewalls and/or intrusion detection systems. Also included is the use of virtual private networks (VPNs) that isolate, by encryption, within a wide area network, exchanges between equipment in the wide area network belonging to the virtual private network. Such solutions make it possible to limit communications with equipment outside the private network to communications sent from the private network to these equipment. “external”, and thus prevent access from outside the network to equipment to be protected.
- VPNs virtual private networks
- the purpose of this application is to propose improvements to at least some of the drawbacks of the state of the art.
- the present application aims to improve the situation by means of a method for protecting at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via a first device of said first portion and a second device of said second portion, said method comprising:
- said filtering rule takes into account at least one element contained in said packet among the following elements:
- said filtering is performed prior to said transcoding. In some embodiments, said filtering is performed after said transcoding.
- said first and second devices communicate with each other via at least two communication paths, a first unidirectional communication path allowing the first device to receive data from said second device, and a second, unidirectional communication path allowing the first device to send to said second device a response to said packet transmitted to said recipient equipment.
- said transcoding comprises deserialization of said data.
- the present application also relates to a method for transmitting at least one piece of data intended for at least one piece of equipment in a communication network partitioned into a plurality of portions comprising at least a first portion, and at least a second portion interconnected with said first portion via a first device of said first portion and a second device of said second portion; said method comprising:
- said filtering rule takes into account at least one element contained in said packet among the following elements:
- the transmission method comprises obtaining a description relating to said equipment of said first portion of said communication network comprising said at least one addressing identifier of said at least one equipment on said first portion of said communication network.
- said filtering is performed on the serialized data. In some embodiments, said filtering is performed prior to said serialization. In some embodiments, said first and second devices communicate with each other via at least two one-way communication paths, a first one-way communication path allowing the second device to transmit data to said first device, and a second one-way communication path allowing the second device to receive from the first device a response to said data transmitted to said first device.
- the present application also relates to an electronic device adapted to implement at least one of the methods of the present application in any of its embodiments.
- the present application thus relates to a first electronic device of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising at least one piece of equipment to be protected and said first device, and at least a second portion interconnected with said first portion via the first device and a second device of said second portion, said first device comprising at least one processor configured to:
- the present application also relates to a second electronic device of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising at least one piece of equipment, and at least a second portion comprising said second device, and interconnected with said first portion via a first device of said first portion and the second device; said second device comprising at least one processor configured to:
- the present application also relates to an electronic assembly for protecting at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via at least a first device of said electronic assembly, said first device belonging to said first portion, and at least a second device of said electronic assembly, said second device belonging to said second portion, said at least one first electronic device comprising at least one processor configured to:
- said at least one second electronic device comprising at least one processor configured to:
- the present application also relates to a system comprising at least one piece of equipment to be protected and at least one electronic assembly for protecting said at least one piece of equipment.
- at least one piece of equipment in a communication network partitioned into a plurality of portions comprising at least a first portion comprising said equipment, and at least a second portion interconnected with said first portion via at least a first device of said electronic assembly, said first device belonging to said first portion and at least a second device of said electronic assembly, said second device belonging to said second portion,: said at least one first electronic device comprising at least one processor configured to:
- said at least one second electronic device comprising at least one processor configured to:
- the present application also relates to a computer program comprising instructions for implementing the various embodiments of at least one of the above methods, when said program is executed by a processor, and an information medium readable by an electronic device and on which the computer program is recorded.
- the present application thus relates to a computer program comprising instructions for implementing, when the program is executed by a processor of a first electronic device, a method for protecting at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment and said first device, and at least a second portion interconnected with said first portion via the first device and a second device of said second portion, said method comprising:
- the present application relates to a computer program comprising instructions for implementing, when the program is executed by a processor of a second electronic device, a method for transmitting at least one piece of data from at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, and at least a second portion, comprising said second device and interconnected with said first portion via a first device of said first portion and the second device; said method comprising:
- the present application also relates to an information medium readable by a processor of a first electronic device and on which is recorded a computer program comprising instructions for implementing, when the program is executed by the processor, a method for protecting at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said piece of equipment and said first device, and at least a second portion interconnected with said first portion via the first device of said first portion and a second device of said second portion, said method comprising:
- the present application further relates to an information medium readable by a processor of a second electronic device and on which is recorded a computer program comprising instructions for implementing, when the program is executed by the processor, a method for transmitting at least one piece of data from at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, and at least a second portion comprising said second device and interconnected with said first portion via a first device of said first portion and the second device of said second portion, said method comprising:
- the above-mentioned programs may use any programming language, and may be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable form.
- the information (or recording) media referred to in this application may be any entity or device capable of storing the program.
- an information medium may comprise a storage medium, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording medium.
- Such storage means can be, for example, a hard disk, flash memory, etc.
- an information carrier may be a transmissible information carrier such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means.
- a program according to the invention may in particular be downloaded from a network such as the Internet.
- an information carrier may be an integrated circuit in which a program is incorporated, the circuit being adapted to execute or to be used in the execution of any of the embodiments of at least one of the methods which are the subject of the present patent application.
- an element we mean in the present application for example a reception of this element from a communication network, an acquisition of this element (via for example user interface elements, sensors, etc.), a creation of this element by various processing means such as by copying, encoding, decoding, transformation etc. and/or an access of this element from a local or remote storage medium accessible to at least one device (such as the first and/or the second device of the set) implementing, at least partially, this obtaining.
- FIG 1 shows a simplified view of an exemplary system in which at least some embodiments of the methods of the present application can be implemented
- FIG 2 shows a simplified view of a device suitable for implementing at least certain embodiments of at least one of the methods of the present application
- FIG 3 shows an overview of the method of protecting the present application, in some of its embodiments.
- FIG 4 shows an overview of the data transmission method of the present application, in some of its embodiments.
- FIG 5 is a simplified view of an exemplary system 500 in which at least some embodiments of the method of the present application may be implemented.
- This application aims to provide a simple and effective solution for both protecting one or more devices of a communication network against computer attacks, in particular external to this communication network, while allowing electronic devices, located for example in an unprotected portion of the communication network or outside the communication network, to access (in reading and writing) and in a secure manner, at least some data of these devices to be protected.
- the application proposes to equip the communication network with at least two devices, these devices partitioning the communication network into at least two portions.
- partition we mean here a sharing of the communication network into a plurality of portions each comprising at least one electronic device, separated two by two (except certain interconnection elements between the at least two devices as specified below) and the assembly of which reconstitutes the communication network.
- At least one first of these portions is a portion (called “protected") inaccessible directly from an electronic device located outside this first portion, this first portion comprising at least one piece of equipment to be protected.
- At least one second portion called “exposed” i.e. external to this first protected portion
- devices outside the first portion such as devices located in a "first" protected portion other than the first "protected” portion where the equipment is located, and/or devices of the second portion, and/or devices outside the communication network).
- the equipment(s) to be protected may, for example, be industrial machines.
- requests for access to a device from a device external to the first portion are filtered by the first and/or the second device, in application of filtering rules, so as to retain only access requests deemed safe. For example, only requests concerning non-critical devices of the first portion can be retained. According to another example, only requests for reading memory zones of a device of the first portion can be retained. According to yet another example, only write requests relating to “non-critical” memory zones of a device of the first portion issued by certain devices (such as a device of a network administrator) can be retained.
- Different federation rules may be applied by the first and/or second devices.
- the federation rule(s) applied by the first device may take into account the second device from which the requests were received.
- the first device may receive requests from a “second device” implementing no federation.
- Applying the same rule to the second device and then to the first device may allow, at the second device, to delete certain packets earlier in the processing chain (in accordance with the federation rules), thus avoiding unnecessary processing.
- Applying the same rule to the second device and then to the first device may allow, at the second device, to delete certain packets earlier in the processing chain (in accordance with the federation rules), thus avoiding unnecessary processing.
- At the first device it may protect against possible corruption of the second device (located in an “exposed” portion of the network) and in particular of its federation rules.
- the first device and the second device communicate only via one-way communication means.
- third-party device requests received by the second device may be forwarded by the second device (from the exposed portion) to the first device via a first one-way communication path. Allowing only one-way communications can help to better control the exchanges between a third-party device and equipment (via the electronic assembly) and therefore to better prevent attacks from third-party devices.
- messages corresponding for example to “UDP” messages from the equipment or to possible responses to requests
- messages can be transmitted via a second unidirectional communication path from the protected portion to the exposed portion.
- responses include, when it is a read request, data values from the equipment receiving the request and/or in the case of a write request, a confirmation of receipt of the request or a confirmation of writing.
- the messages (such as “UDP” messages or responses) are transmitted from the first device to the second device (via the second communication path). Alternatively, they can be transmitted transparently to the first and second devices (via a second communication path not passing through the first and second devices).
- message filtering may optionally be implemented by the first device and/or the second device (so as to ensure, for example, that no sensitive data can be communicated to an external device of the first portion).
- This filtering may be based on rules that are identical or similar to those used during the first communication path (for example, they may relate to the same registers) or on different rules.
- This application may in particular help both to protect a portion of the network, while allowing the control of at least certain equipment of this first portion from outside the network.
- the logical assembly comprising the at least one first and second device and the means of communication (one-way for example) between these at least two devices is also called in the present patent application "electronic assembly", “electronic protection assembly” or “Smart Diode” (or Smart Diode according to the English terminology).
- it may be a virtual assembly, virtually encapsulating the first and second devices and first one-way communication means in a first direction of communication (from the second device to the first device), and optionally second one-way communication means in a second direction of communication, opposite to the first direction) or a physical assembly (such as a hardware element), having for example a housing in which the at least one first and second device and their mutual communication means are installed.
- This assembly may comprise depending on the embodiments, and the network topology (for example the number of portions to be protected) a variable number of “first” devices and “second” devices.
- Such an electronic assembly offers the advantage of being easy to install in a communication network, for example as an “intermediary” between a (particular) piece of equipment to be protected and the rest of the communication network, or in order to limit access to this equipment to be protected to only accesses made by the first device or simply to limit access to the equipment to be protected to devices located in a (protected) portion of the communication network, to which this equipment belongs.
- Such an assembly can also help to offer a “turnkey” product to a communication network administrator.
- Such an electronic assembly can thus help, at least in certain embodiments, to secure equipment to be protected, without requiring modification and/or replacement of this equipment.
- the term “electronic equipment”, or “equipment”, is used in this application to refer to equipment that can be protected by the electronic assembly.
- the term “electronic device”, or “device”, will be used to refer to the first or second electronic device of the electronic assembly 160 introduced above.
- the term “electronic device” or “device” relates to any electronic device (it may sometimes be equipment to be protected or a device of the electronic assembly).
- Ua figure 1 represents a system 100 in which certain embodiments of the invention can be implemented.
- a system 100 comprises one or more electronic devices, at least some of which can communicate with each other via one or more communication networks 110, 120, 130 which are possibly partitioned and/or interconnected.
- the system thus comprises a private network partitioned into two portions 110, 120.
- One of the portions 120 is further interconnected with another network 130 (such as a wide area and/or public network, thus enabling communications between electronic devices 150, 164, 170 of this portion 120 and electronic devices 180 not belonging to the private network.
- a private network may for example be a private corporate or domestic network, for example a local private network (or UAN for Local Area Network, according to English terminology).
- the other network 130 may for example be another local network, or a “wide” network with significant geographic coverage, such as a metropolitan area network (or MAN, for Metropolitan Area Network, according to English terminology) or a network whose geographic area covers at least one region of a country, or a country (or WAN, for Wide Area Network, according to English terminology). It may for example be a WAN network of the Internet type, or cellular, GSM - Global System for Mobile Communications, UMTS - Universal Mobile Telecommunications System, Wifi - Wireless, etc.). As illustrated in FIG.
- the system 100 may also comprise a non-interconnected portion 110 of the private network, called protected, comprising one or more electronic devices 140.
- electronic devices 140 may be devices such as a terminal (such as a laptop, a smartphone, a tablet or a connected object), a connected object (such as a robot, an automatically and/or remotely guided mobile device, an energy meter, a machine tool in the case of an industrial private network, and/or household appliance in the case of a home network), a server, for example an application server, and/or a storage device.
- a terminal such as a laptop, a smartphone, a tablet or a connected object
- a connected object such as a robot, an automatically and/or remotely guided mobile device, an energy meter, a machine tool in the case of an industrial private network, and/or household appliance in the case of a home network
- server for example an application server, and/or a storage device.
- the equipment of the non-interconnected portion 100 may use different communication protocols depending on the embodiments, such as OPCUA (for OPen Connectivity - Unified Architecture), MQTT (for Message Queuing Telemetry Transport in English), ModBus TCP, Siemens S7, MTConnect, LabView. These protocols may differ depending on the equipment of the non-interconnected portion.
- OPCUA for OPen Connectivity - Unified Architecture
- MQTT for Message Queuing Telemetry Transport in English
- ModBus TCP Siemens S7
- MTConnect LabView
- a device not belonging to a first protected portion (such as a device not belonging to the communication network, or belonging to the second “exposed” portion of the communication network) transmits a data packet (a request to read or write from/in a memory area for example) intended for equipment in the first portion.
- the second device intercepts this data packet, optionally decides whether or not to keep this data packet based on a filtering rule (hereinafter called the “second” filtering rule with reference to the “second” device) and, if applicable (if the packet complies with this second filtering rule), transcodes this packet into serialized data and transmits them to the first device, located in the protected portion, where this data is filtered again by the first device before being transcoded in the form of at least one new data packet (having, depending on the embodiments, a structure identical to or different from that of the packet transmitted by the third-party device).
- This or these new packets is/are then transmitted to a device receiving the first portion.
- the response from the third-party device can then be transmitted via the first and second devices to the third-party device that sent the data packet (for example using a data serialization/deserialization mechanism with and/or without filtering).
- the system comprises at least one electronic assembly 160 as introduced above aimed at protecting at least certain electronic equipment 140 of the private network 110.
- the first device 162 of the electronic assembly 160 is located in a portion 110 called "to be protected" of the private network comprising the equipment 140 to be protected.
- the first device 162 communicates with the second device 164 (located in the interconnected portion 120) via means 1622, 1624, 1642, 1644 unidirectional communication means, comprising for example first unidirectional communication means 1622, 1642 in a first direction of communication, and second unidirectional communication means 1624, 1644 in a second direction of communication, opposite to the first direction.
- unidirectional communication means may vary according to the embodiments (and in particular according to the hardware capabilities of the first and/or second device).
- the unidirectional communication means may comprise at least one optocoupler, and/or bidirectional communication means having been limited to a single direction of transmission, such as an Ethernet cable, a serial link and/or an optical fiber and/or at least one digital isolator (Digital isolator according to the English terminology) with galvanic, capacitive, inductive and/or optical isolation.
- a single direction of transmission such as an Ethernet cable, a serial link and/or an optical fiber and/or at least one digital isolator (Digital isolator according to the English terminology) with galvanic, capacitive, inductive and/or optical isolation.
- the first and second means of communication may be different.
- the second device may transmit data to the first device via an Ethernet link limited to one direction of communication and the first device may transmit data to the second device via an optocoupler.
- the first and second means of communication may be similar.
- each of the first and second means of unidirectional communication may include an optocoupler 166.
- optocoupler(s) makes it possible to physically separate the two devices (no electrical flow is exchanged, just light), and therefore to reinforce the security of the exchanges.
- the electrical isolation of the devices from each other can help, for example, to prevent attacks by injection of current or electrical signal on the second portion of said network.
- the system may also include network management and/or interconnection elements 164, 170.
- the electronic assembly 160 may include at least one interconnection gateway with another network.
- this gateway may for example be connected to the second device of the electronic assembly (and therefore allow an interconnection between the “exposed” portion of the private network and the other network).
- the second device may itself play the role of an interconnection gateway between the “exposed” portion of the private network and the other network.
- the private network can for example use wired connections such as at least one serial connection and/or one Ethernet connection, or wireless communication means.
- the network can implement a communication protocol such as ModBus Serial, or CAN (acronym for “Controller Area Network”) in the case of a serial connection, or such as ModBus TCP, OPC-UA, MQTT in the case of an Ethernet connection.
- a communication protocol such as ModBus Serial, or CAN (acronym for “Controller Area Network”) in the case of a serial connection, or such as ModBus TCP, OPC-UA, MQTT in the case of an Ethernet connection.
- Figure 2 illustrates a simplified structure of an electronic device 200 of the system 100, for example the first device 162, the first device 162, and/or the equipment to be protected 140 of Figure 1.
- it may be a server, and/or a terminal, or even a microcomputer with a simple human-machine interface such as a RaspberryPi ⁇ , an OrangePi ⁇ or even a NanoPl NEO.
- the device 200 comprises in particular at least one memory M 210.
- the device 200 may in particular comprise a buffer memory, a volatile memory, for example of the RAM type (for “Random Access Memory” according to the English terminology), and/or a non-volatile memory (for example of the ROM type (for “Read Only Memory” according to the English terminology).
- the device 200 may also comprise a processing unit UT 220, equipped for example with at least one processor P 222, and controlled by a computer program PG 212 stored in memory M 210. On initialization, the code instructions of the computer program PG are for example loaded into a RAM memory before being executed by the processor P.
- said at least one processor P 222 of the processing unit UT 220 may in particular implement, individually or collectively, any of the embodiments of at least one of the methods of the present application (described in particular in relation to Figures 3 and 4), according to the instructions of the computer program PG.
- the device may also comprise, or be coupled to, at least one I/O input/output module 230.
- the at least one I/O input/output module 230 of the device may comprise, in certain embodiments, at least one module for interfacing with a user of the device (also more simply called in this application “user interface”).
- user interface of the device we mean for example an interface integrated into the device 200, or a part of a third-party device with which it is coupled by wired or wireless communication means. For example, it may be a secondary screen of the device.
- a user interface may in particular be a user interface, called an “output” user interface, adapted to a rendering (or to the control of a rendering) of an output element of a computer application used by the device 200, for example an application running at least partially on the device 200 or an “online” application running at least partially remotely, for example on a server.
- Examples of an output user interface of the device include one or more screens, in particular at least one graphic screen (touch screen for example), one or more speakers, a connected object.
- a user interface may be a user interface, called an “input” interface, adapted to an acquisition of a command from a user of the device 200. This may in particular be an action to be carried out in connection with a returned item, and/or a command to be transmitted to a computer application used by the device 200, for example an application running on the at least partially on the device 200 or an “online” application running at least partially remotely, for example on a server.
- input user interface include a sensor, an audio and/or video acquisition means (microphone, camera (webcam) for example), a keyboard, a mouse.
- the device may also comprise, or be coupled to, at least one I/O input/output module 230, such as a communication module, allowing the device 200 to communicate with at least one other device of the system 100, via wired or wireless communication interfaces.
- I/O input/output module 230 such as a communication module, allowing the device 200 to communicate with at least one other device of the system 100, via wired or wireless communication interfaces.
- it may be at least one Ethernet type interface, and/or Wifi, Bluetooth type.
- the communication means 1622, 1622, 1642, 1644 comprise for example first unidirectional communication means 1622, 1642 in a first direction of communication, and second unidirectional communication means 1624, 1644 in a second direction of communication, opposite to the first direction, such as at least one Ethernet type interface, or at least one serial interface with an optocoupler of the electronic assembly 160.
- the optocoupler can be connected directly to the serial interface.
- the transmission port of the first device (protected portion) can be connected to a pin of the optocoupler and the reception port of the second device (exposed portion) can be connected to another pin of the optocoupler.
- Each side of the optocoupler can be supplied with voltage by the first and second device respectively (e.g. with a voltage of 3.3V).
- the communication means of the device can be only family communication means, so as to physically limit the possibilities of access (directly or via this device) to equipment to be protected located in the same portion to be protected of the network (and therefore the possibilities of third-party attacks).
- at least one of the first and second devices 162, 164 can be a microcomputer of the “NanoPi NEO” ⁇ type, equipped only with an Ethernet port (and no Wifi).
- Said at least one microprocessor of the first device 162 can in particular be adapted for:
- Said at least one microprocessor of the second device 164 can in particular be adapted for:
- Some of the above input-output modules are optional and may therefore be absent from the equipment to be protected, from the first device and/or from the second device in certain embodiments.
- the electronic assembly introduced above may comprise, in certain embodiments, a physical housing in which the first and second devices and the bidirectional communication means between the first device and the second device are housed.
- the housing may for example limit or prevent physical access to the first and second devices and to their mutual communication means. It may in particular be a housing closed by a non-repositionable guarantee strip, or a sealed housing, so as to make any opening of the housing visible, due to the deterioration of a seal or of the guarantee strip, or to make its opening difficult.
- the housing may for example allow physical access to at least certain communication interfaces of the first and/or of the second device (other than the mutual communication means between these two devices for example) and/or comprise communication interfaces connected to at least certain of the communication interface(s) of the first and of the second device.
- the housing may provide access only to certain wired communication interfaces of the first device. For example, this may involve “forcing” the use of certain communication interfaces between the equipment and the first device, for example offering advantages in terms of security (for example due to the protocol involved in such interfaces) or to favor the use of “wired” interfaces.
- the housing may allow free access to several communication interfaces of the first and second devices, so as to provide a set adapted to different network environments.
- some of these interfaces can be deactivated in software (for example not provide any service), so that third-party equipment cannot access in reading and/or writing mode (via an SHH connection in the case of an Ethernet link for example) the description of the first device and equipment data stored by the first device.
- module or the term “component” or “element” of the device here means a hardware element, in particular wired, or a software element, or a combination of at least one hardware element and at least one software element.
- the method according to the invention can therefore be implemented in various ways, in particular in wired form and/or in software form.
- Figure 3 illustrates certain embodiments of the method 300 for protecting the present application (implemented for example by a first device of an electronic assembly according to the invention) and Figure 4 illustrates certain embodiments of the method 400 for providing data of the present application (implemented for example by a second device of an electronic assembly according to the invention).
- the method 400 (before the method 300) is now described to respect a chronological order of processing of a request (such as read/write access to equipment) received from a third-party device, and thus facilitate the reading of the present patent application.
- the method 400 can for example be implemented by a second device located in a portion of a communication network completely distinct from a protected portion of this network, such as the second device 164 of the electronic assembly 160 of the system 100.
- the method can be implemented automatically at startup of the second device (via a script executed at startup (“boot”) of the device) or later, for example following the launch, manual or automatic (via a background task for example) of an executable implementing at least one embodiment of the method 400.
- the method can notably comprise, as illustrated in FIG. 4, a so-called initialization phase 410 (during startup of the second device for example or subsequently, upon receipt of a user command for example).
- This initialization phase 410 comprises an establishment 412 (initialization and/or establishment) of communications (for example unidirectional) from the second device to the first device, and optionally unidirectional communications from the first device to the second device.
- This initialization phase 410 also includes obtaining 414 a description, which may take the form of one or more files in YAML, XML or JSON format for example.
- This description may in particular include information relating to the requests that the second device will receive (format of the packets to be received for example), and/or information relating to filtering rules that the second device must apply, and/or information relating to equipment for which a packet that will be received by the second device may be intended (such as an identifier of this equipment, a designation of at least one protocol that it can use, etc.), information relating to the data to be transmitted to the first device (protocol to be used, format, etc.).
- the description may also include information necessary for establishing one-way communication between the second device and the first device and vice versa (such as an address of the first device on the communication network, a data format and/or a protocol to be used to communicate with the first device, etc.).
- the information necessary for establishing a one-way communication between the second device and the first device can be obtained by the second device (via parameter data locally accessible to the second device or remotely for example) prior to setting up 412 the two-way communication means and obtaining 414 the description.
- obtaining the description can comprise a deserialization of the data (corresponding to the description) received (if the content of the description has been serialized before its transmission to the second device).
- the format for receiving the description may differ depending on the implementations. For example, it may be an XML or JSON format.
- the pseudo-code below illustrates as an example the transmission of the description in a serialized manner in the case of the JSON protocol: ⁇ ‘m’ : ’description ⁇ JSON description ⁇ where in this example
- description is a text label announcing the transmission of a description ⁇ JSON description ⁇ in JSON format.
- the description may be received from the first device.
- the description may be obtained by accessing a storage area accessible to the second device, such as a storage area local to the second device or accessible from the second portion of the network or a removable storage area (such as a USB drive) coupled to the second device.
- the description obtained 414 may in particular include information describing at least one protocol (such as Ethernet) to be used to receive these packets, a packet size, a packet format (or structure), a reception rate, etc.
- at least one protocol such as Ethernet
- protocols include hierarchical protocols, using standardized data structures, such as Open Platform Communications Unified Architecture (OPC-UA) and ModBus, or non-hierarchical protocols such as MQTT and Direct Datagram Protocol (UDP).
- OPC-UA Open Platform Communications Unified Architecture
- ModBus ModBus
- non-hierarchical protocols such as MQTT and Direct Datagram Protocol (UDP).
- this may include, for example: a designation of at least one accepted or prohibited protocol; a designation of at least one network domain whose requests, when issued from this domain, will be accepted or prohibited; an identifier of at least one device, issuer of a request, accepted or prohibited; a designation of at least one portion of the network accepted or prohibited as a portion of belonging of a recipient of a request; an identifier of at least one device accepted or prohibited as a recipient of a request; a type of access request (read, write, etc.) accepted or prohibited; a range of addresses accepted or prohibited as parameters of a request; an accepted or prohibited parameter in connection with a particular protocol (such as a "topic" for MQTT for example) a combination of at least two of said information.
- a designation of at least one accepted or prohibited protocol such as a "topic" for MQTT for example
- This information may be optional in certain embodiments.
- Concerning the information relating to a device for which a packet may be intended it may in particular comprise an addressing identifier of this device (for example according to the protocols an IP address, a MAC address of at least one access point, etc.), a designation of at least one protocol that it accepts, a communication port open on this device.
- the description may also comprise information relating to data to be received from the first device in response to a sending by the second device of a request from a third-party device.
- This may for example be a protocol to be used to receive this data, and/or a size, type and/or format of this data, or a protocol to be used to transmit this data, and/or an output format of this data to be used for their transmission to a third-party device.
- the description concerns several devices.
- the term "devices” announces a list of devices to be protected (designated by their respective IP addresses), each accessible by a different protocol in this example. For each, we find the authorized ports, the authorized transmitters (sources) (designated by their respective IP addresses), the type of possible access and the registers, the "namespaces" (for OPC-UA), topic (for MQTT), http requests (for MTConnect) authorized by type of access.
- config ve sion 1.0 config date: 2023-05-15 diode: hostname: SmartDiode devices:
- the transmission method 400 may include an (optional) update of the obtained description 414, either automatically by the second device or via a user interface of the second device, to delete certain information from the description or add new information (for example to create, delete and/or modify at least one filtering rule).
- the method may comprise a processing 420 of a data packet originating from a third-party device located outside the protected portion.
- This may for example be a request for read or write access to a memory area of a device of the first portion.
- the packet may for example be obtained 422 (i.e. received here) by the second device via the second portion of the communication network.
- the second device can intercept data packets circulating on the second portion of the network and having a destination address corresponding to an addressing identifier contained in the description.
- the method can comprise an examination 430 of the packets received, taking into account at least one filtering rule (called a “second” filtering rule by reference to the “second” device).
- the at least one second filtering rule can for example be obtained 432 from the information present in the description (and detailed above).
- the method can thus comprise a filtering 434 of the packets received to retain only those consistent with the at least one “second” filtering rule obtained.
- packets with MQTT protocol can be kept or deleted according to their “topic”.
- packets with OPC-UA protocol can be kept or deleted according to the designated nodes and a type of request (read or write access) to which the packet corresponds.
- packets with ModBus protocol can be kept or deleted according to the designated registers and a type of request (read or write access) to which the packet corresponds.
- the recipient equipment can also be taken into account to keep or delete packets.
- a packet intended for the “ModBus” machine will be kept only if they have port 9400 as their destination port and concern “registers” 0 to 105 of “coils” 0 to 1 in the case of a read access request.
- only write access requests to registers 0-12 will be kept.
- a write request on register 13 for example, will be eliminated.
- the method may comprise a transcoding 440 of the stored packets.
- the method may comprise an extraction 442 of the data contained in the obtained packet 422 taking into account the structure of the packet and in particular the protocol used in the encoding of the packet.
- the extracted data may for example comprise, in addition to the address of the recipient of the packet, at least one destination port on the destination equipment, a type of request to be sent to the equipment, data relating to the command (address range, data values, etc.).
- the method may include a serialization of the extracted data.
- This serialization may for example take into account the description obtained 414 (in particular a designation, in the description; of a protocol to be used for the serialization, such as XML or JSON).
- the serialized data may include in the header an announcement of a type of data (protocol used or announcement of data corresponding to a description, etc.), a label identifying this type of data, as well as possible text labels or digital code announcing the meaning of the elements which follow them.
- announcements may be optional device described later included in certain embodiments, in particular when the description of the second device (and that of the first device) only provides a single protocol.
- the method may include a transmission 450 to the first device of the transcoded data (via one of the unidirectional communication paths set up for example)
- filtering can be performed on the extracted/serialized data (not on the received packets).
- Filtering on packets allows to rely on the structure of the packets (and therefore on the semantics of the fields of these packets) to perform the filtering. In addition, it avoids performing unnecessary serialization processing of data that will not be preserved.
- the method may comprise a processing 460 of a message from the equipment (such as a UDP message or a response to the request sent to the first device (and transmitted by the latter to the equipment)).
- the method may comprise a transmission 464 of the response to the third-party device for which it is intended.
- this may involve a simple retransmission of a received packet.
- the processing may optionally comprise a filtering of the received packets (similar to what has already been described above, but optionally with different filtering rules (for example to prohibit the communication of the content of certain registers), or to filter the recipients of the messages).
- the manner in which the second device obtains a packet intended for a device in the first portion may vary.
- the second device may intercept data packets traveling on the second portion of the network when their destination address matches that of the device.
- the second device may use, as its own addressing identifier on the second portion, an addressing identifier of at least one device on the first portion.
- the addressing identifier of the device on the first portion may for example be obtained by reading the description or received from the first device and the method may include defining or modifying its own addressing identifier to be equal to the addressing identifier of the device on the first portion. It may also involve adding the addressing identifier of the device on the first portion to its addressing identifier(s) on the second portion.
- Such embodiments may allow the second device to “impersonate” the equipment, with respect to devices in the second portion or external to the communication network. Such embodiments may thus help an administrator of the communication network to have a “plug and play” solution.
- the insertion of the electronic assembly into the network, for the protection of a piece of equipment may be transparent to other devices already present in the network and may not require modifying a routing (or addressing) plan for the entire network or modifying the software of one of the third-party devices wishing to obtain data from the equipment.
- the second device when the second device is part of an electronic assembly protecting several devices, the second device can be assigned several addresses (IP for example) on the second portion (via “subnets” for example) each identical to one of the addressing identifiers of a device to be protected on the first portion.
- IP IP
- the electronic assembly may be installed in an existing network comprising equipment that is (newly) to be protected.
- the electronic assembly When the electronic assembly is installed so as to be able to communicate (for example via a wired link) with the equipment to be protected, thus constituting a first portion of the network (comprising at least the equipment and the first device), a network operator may not have to perform any action (apart from this installation).
- the requests intended for the equipment being received by the second device and any responses from the equipment being transmitted by the second device, the devices and software external to the protected portion of the network can continue to make requests to the equipment, without modifying the access routine that they used before the installation of the electronic assembly to protect the equipment.
- the insertion of the electronic assembly into the network can therefore be transparent to these devices and software.
- the method 300 can be implemented, according to the embodiments, during the start-up of the first device, or later, and can comprise, as illustrated in FIG. 3, a so-called initialization phase 310 (during startup of the first device for example or subsequently, upon receipt of a user command for example).
- This initialization phase may include obtaining 312 a description that may take the form of one or more files for example and that may in particular include information relating to the establishment of a two-way communication between the first device and the second device (such as an address of the second device on the communication network, a protocol to be used, etc.) and/or information relating to the data that the first device will receive from the second device (protocol to be used, format, etc.), and/or information relating to rules for filtering this data that the first device must apply, and/or information relating to at least one piece of equipment for which this data may be intended (such as an identifier of this piece of equipment, a designation of at least one protocol that it can use, etc.), and/or information relating to the structuring of this data into data packet(s) before their transmission to a piece of equipment, and information relating to a communication to be established with a piece of equipment for the transmission of at least one such packet (such as a password, or a necessary public or private key). to a connection to the
- the information relating to the establishment of a two-way communication between the first device and the second device, the information relating to the data that the first device will receive from the second device (protocol to be used, format, etc.), and/or the information relating to the structuring of this data into packet(s) may be similar to that described in connection with the transmission method 400 (the format of the packets received by the second device may be different from the format of the packets transmitted by the first device).
- the information relating to filtering rules may be similar to that described in connection with the transmission method 400.
- the filtering rules may differ from the filtering rules applied by the second device.
- the filtering rules to be applied by the first device may take into account the second device from which the data is received (when the first device can receive data from several “second” devices) so as, for example, to eliminate certain data corresponding to write requests originating from a second portion interconnected with a public network such as the Internet.
- the information necessary for identifying equipment to be protected may include at least one of the following identification information: a textual label; an address (or addressing identifier) of the equipment on the first portion (for example, depending on the protocols, an IP address, a MAC address of at least one access point of the equipment, etc.); a manufacturer reference of the equipment; a serial number of the equipment; a combination of at least two of the above identification information.
- the information necessary for establishing communication between the first device and the equipment may include in particular at least one of the following so-called communication information: information designating a protocol that can be used to communicate with the equipment; a port of the equipment that can be used to communicate with the equipment according to said protocol; at least one connection security element (such as an access identifier, a password, a public or private key, etc.); additional parameters specific to certain protocol(s) (such as a “topic” in the case of the MQTT protocol). a combination of at least two of the above communication information.
- protocols for communicating with equipment include hierarchical protocols, using standardized data structures, such as Open Platform Communications Unified Architecture (OPC-UA) ModBus protocols, or non-hierarchical protocols such as MQTT or Direct UDP.
- OPC-UA Open Platform Communications Unified Architecture
- ModBus protocols or non-hierarchical protocols such as MQTT or Direct UDP.
- MQTT Direct UDP.
- the description may be obtained by accessing a storage area accessible to the first device (such as a storage area local to the first device or located in the first portion of the network or a removable storage area (such as a USB key) coupled to the first device or accessible via a serial connection on a micro-USB port of the first device. This may in particular be a micro-USB port inaccessible to a third party when the housing of the electronic assembly comprising the first device is closed.
- the method 300 may include transmitting 316 at least a portion of the obtained description 312 to the second device.
- the description may be created, or completed, dynamically (and at least partially automatically) by the first device itself.
- the method may comprise a polling (or exploration) (or ARP (for Address Resolution Protocol) scan according to the English terminology) of the first portion, to discover the devices present in the first portion, then at least one attempt to connect to these devices using one or more candidate protocol(s) (according to the embodiments), making it possible, when a connection attempt is successful, to detect at least one protocol used by the equipment.
- the connection attempts may optionally use additional elements (such as at least one port value (to discover at least one open port on the device concerned) and/or additional parameters consistent with this (or these) candidate protocol(s).
- the method may comprise, for each discovered device of the first portion, an attempt to connect with a set of candidate protocols defined by configuration (manual or automatic) of the device.
- the method may include a recording of the address of the discovered device in association with the protocols that enabled the connection, and any additional elements in said description.
- Such an embodiment may allow not only to create a description, but also to automatically update an existing description. This may involve adding information relating to a newly discovered device or modifying information in the description relating to a device, for example to add information relating to a new protocol accepted by this device (following a software update of the device for example), or to delete the designation of a port that has become inaccessible (defective for example).
- the method may further comprise an (optional) update of the description obtained by the first device.
- an automatic update may comprise, for example, an addition of default filtering information, applicable for access requests to a newly discovered device (and recorded in the description), such as a retention of only read access requests, or an addition of filtering information prohibiting the use, regardless of the device concerned, of a protocol that is not very secure, for example) or prohibiting the use of a defective port.
- An update may also be performed manually by an operator, via a user interface of the first device, in particular to create and/or delete and/or modify filtering information. This may involve, for example, manually completing a descriptive file automatically created by the first device.
- the obtained description 312 may be identical to the description described in connection with the method 400 implemented in the first device.
- both descriptions may be obtained by copying from the same removable storage medium, or the second device can receive from the first device the entire description that the first device itself has previously obtained 312 (or vice versa).
- the description of the second device can then contain certain information not useful to the second device (such as a password, or a public or private key necessary for a connection to the equipment from which the data comes).
- Such an embodiment can offer advantages in terms of simplicity of processing (for one of the first and second devices) and/or simplicity of configuration, therefore time saving, on the second device side, since it is not necessary to provide a “description” specific to the second device.
- the descriptions can be different.
- certain information contained in the description obtained by the first device and relating to the equipment to be protected and/or to communications with this equipment can be omitted in the description obtained by the second device.
- information contained in the descriptions relating to the formats of the packets to be received or created will be different.
- the initialization phase 310 may comprise an establishment 314 of the bidirectional communication means with the second device and, optionally, a transmission 316 of at least a portion of the description obtained 310 to the second device.
- the transmission 316 may in particular comprise the transmission of at least one item of identification information of the equipment such as an address of the equipment on the first portion (for example according to the protocols an IP address, a MAC address, etc.), (also called an addressing identifier on the first portion in the present application).
- the transmitted descriptive portion may include descriptive information that may help the second device “impersonate” the equipment, vis-à-vis devices in the second portion or external to the communications network.
- the method may comprise obtaining 320 data, corresponding to a request from a third-party device, received (obtained) from the second device, via the bidirectional communication means.
- the method may further comprise transcoding, for example deserialization (or structuring) 330 of this data to obtain a structured data packet.
- the structuring of the data may take into account information present in the description designating a protocol used by the equipment.
- the method may comprise an examination 340 of the extracted data taking into account at least one filtering rule (called the “first” filtering rule with reference to the “first” device).
- the at least one “first” filtering rule may for example be obtained 342 from the information present in the description of the first device (and detailed above).
- the method may thus comprise a filtering 344 of the received data, or alternatively a filtering of the packets formed from the received data, to retain only those (or those) consistent with the at least one “first” filtering rule obtained.
- filtering can be performed on the extracted data, so as to structure only the data to be kept into packets.
- performing filtering on packet-structured data allows the packet structure to be used to apply filtering rules.
- the method comprises a transmission 350 of the packet obtained on the first portion of the network, to a device receiving this packet.
- the first device can optionally process a response from the equipment, more precisely the first device can receive a message 362 from the equipment and transmit 364 this message (after serialization and/or filtering before or after this possible serialization) to the second device.
- the first device and the second device can be adapted to communicate according to several protocols with, respectively, at least one equipment to be protected and at least one third-party device.
- the first device and the second device may communicate with a device to be protected and a third-party device with a single protocol.
- the network may include multiple protection electronic assemblies, each protecting one or more devices having a single protocol. Such embodiments may allow simpler descriptions.
- the electronic assembly may be dedicated to a particular protocol and programmed for this protocol only.
- several second devices may communicate with the first device to respectively transmit requests from third-party devices using different protocols.
- the same second device can communicate with several “first devices”, this second device being able for example to have several different addresses, each chosen to correspond to that of a piece of equipment protected by one of the first devices and directing the requests received to the appropriate “first” device.
- the present application provides an electronic assembly constituting, at least in some of its embodiments, a simple and effective solution for requesting data securely from an industrial machine connected to a public network such as the Internet.
- the configuration of at least one of the first and second devices of the electronic assembly can be easy (in particular when it is automatic) and one or the other of the devices of the electronic assembly can be usable with several different protocols, which can therefore make it possible to offer a solution adaptable to different industrial environments.
- the solution presented in the present application can find applications in many fields, and in particular in areas that are privileged targets of computer attacks.
- the solution that is the subject of the present application can help protect industrial machines (to prevent their corruption for example), by preventing access to certain sensitive data of these machines such as data relating to the industrial processes implemented, while making other data (such as production data) available to monitoring and control applications.
- the electronic protection assembly 160 is implemented to allow secure remote interrogation of an industrial machine (the equipment 140) by a third-party SCADA (Supervisory Control and Data Acquisition) type remote management device from an unsecured portion of the communication network.
- SCADA Supervisory Control and Data Acquisition
- Another example of implementation concerns the field of distribution.
- the solution that is the subject of this application can in fact be used to help protect electronic point-of-sale equipment, by limiting the possibilities of access to data stored on this equipment, such as sales data and/or sensitive information on customers.
- Yet another example of implementation concerns the field of finance (banking, financial services) and in particular the sensitive financial and personal information handled, which the solution which is the subject of this application can help to protect from attacks (while offering possibilities of access to other data, less sensitive for example).
- the solution which is the subject of this application may also find applications in the field of health, to protect patients' sensitive medical data while allowing health professionals to access at least some of this data.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- Computer Security & Cryptography (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
Description
Claims
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP24735643.9A EP4736371A1 (fr) | 2023-06-28 | 2024-06-26 | Procédés de protection d'un équipement et de transmission de données, dispositifs et ensemble électroniques, produits programmes d'ordinateur et supports d'information correspondants |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FRFR2306799 | 2023-06-28 | ||
| FR2306799A FR3150675A1 (fr) | 2023-06-28 | 2023-06-28 | Procédés de protection d’un équipement et de transmission de données, dispositifs et ensemble électroniques, produits programmes d’ordinateur et supports d’information correspondants |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025003201A1 true WO2025003201A1 (fr) | 2025-01-02 |
Family
ID=88689390
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/EP2024/067921 Ceased WO2025003201A1 (fr) | 2023-06-28 | 2024-06-26 | Procédés de protection d'un équipement et de transmission de données, dispositifs et ensemble électroniques, produits programmes d'ordinateur et supports d'information correspondants |
Country Status (3)
| Country | Link |
|---|---|
| EP (1) | EP4736371A1 (fr) |
| FR (1) | FR3150675A1 (fr) |
| WO (1) | WO2025003201A1 (fr) |
Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20200036732A1 (en) * | 2018-07-27 | 2020-01-30 | The Boeing Company | Machine learning data filtering in a cross-domain environment |
| US20200106742A1 (en) * | 2018-07-09 | 2020-04-02 | Centripetal Networks, Inc. | Methods and Systems for Efficient Network Protection |
| EP3729773B1 (fr) * | 2017-12-22 | 2021-11-03 | Fend Incorporated | Dispositif de transfert de données unidirectionnel avec détection de système embarqué |
-
2023
- 2023-06-28 FR FR2306799A patent/FR3150675A1/fr not_active Withdrawn
-
2024
- 2024-06-26 EP EP24735643.9A patent/EP4736371A1/fr active Pending
- 2024-06-26 WO PCT/EP2024/067921 patent/WO2025003201A1/fr not_active Ceased
Patent Citations (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP3729773B1 (fr) * | 2017-12-22 | 2021-11-03 | Fend Incorporated | Dispositif de transfert de données unidirectionnel avec détection de système embarqué |
| US20200106742A1 (en) * | 2018-07-09 | 2020-04-02 | Centripetal Networks, Inc. | Methods and Systems for Efficient Network Protection |
| US20200036732A1 (en) * | 2018-07-27 | 2020-01-30 | The Boeing Company | Machine learning data filtering in a cross-domain environment |
Also Published As
| Publication number | Publication date |
|---|---|
| FR3150675A1 (fr) | 2025-01-03 |
| EP4736371A1 (fr) | 2026-05-06 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US20150156183A1 (en) | System and method for filtering network communications | |
| EP2692089B1 (fr) | Mécanisme de redirection entrante sur un proxy inverse | |
| EP3891959B1 (fr) | Communiquer entre des réseaux radio/fixe par le biais d'une blockchain | |
| FR2923969A1 (fr) | Procede de gestion de trames dans un reseau global de communication, produit programme d'ordinateur, moyen de stockage et tete de tunnel correspondants | |
| EP3917108A1 (fr) | Procede de configuration d'un equipement pare-feu dans un reseau de communication, procede de mise a jour d'une configuration d'un equipement pare-feu, dispositif, equipement d'acces, equipement pare-feu et programmes d'ordinateur correspondants | |
| EP3734901A1 (fr) | Procede de transmission securisee de donnees | |
| EP3622688B1 (fr) | Singularisation de trames à émettre par un objet connecté et blocage de trames réémises sur un réseau de communication sans-fil basse consommation | |
| WO2025003201A1 (fr) | Procédés de protection d'un équipement et de transmission de données, dispositifs et ensemble électroniques, produits programmes d'ordinateur et supports d'information correspondants | |
| FR3105486A1 (fr) | Procédé de détection d’un comportement malveillant dans un réseau de communication, dispositif, équipement d’accès audit réseau, procédé de détection d’une attaque distribuée dans ledit réseau, dispositif, équipement nœud et programmes d’ordinateur correspondants | |
| EP4736370A1 (fr) | Procédés de protection d'un équipement et de fourniture de données, dispositifs et ensemble électroniques, produits programmes d'ordinateur et supports d'information correspondants | |
| EP3087719B1 (fr) | Procédé de ralentissement d'une communication dans un réseau | |
| EP3688926B1 (fr) | Gestion de groupes d'objets connectés utilisant des protocoles de communication sans fil | |
| EP4068818A1 (fr) | Procédé de gestion de sécurité dans un système de communication de données, et système pour la mise en oeuvre du procédé | |
| EP3424184B1 (fr) | Procédé d'initialisation et de sécurisation de communication bidirectionnelle d'un appareil avec un réseau domotique | |
| FR2813151A1 (fr) | Communication securisee dans un equipement d'automatisme | |
| WO2019243706A1 (fr) | Procédé de découverte de fonctions intermédiaires et de sélection d'un chemin entre deux équipements de communication | |
| EP3709185A1 (fr) | Procédé d'optimisation d'échanges de données dans une infrastructure d'objets connectés | |
| EP2614630B1 (fr) | Traitement de données pour la notification d'un équipement | |
| FR3052004B1 (fr) | Procede d'echange de donnees entre un objet connecte et un serveur central. | |
| WO2025162892A1 (fr) | Procédé de gestion de l'appel par un client d'une interface de programmation applicative | |
| FR3093882A1 (fr) | Procédé de configuration d’un objet communicant dans un réseau de communication, terminal utilisateur, procédé de connexion d’un objet communicant au réseau, équipement d’accès et programmes d’ordinateur correspondants. | |
| FR3112053A1 (fr) | Procédé de gestion d’une phase d’appairage entre dispositifs de traitement de données. | |
| EP3360293A1 (fr) | Moyens de gestion d'accès à des données | |
| FR3091120A1 (fr) | Procédé d’optimisation de l’utilisation de passerelles en fonction des messages à transmettre | |
| WO2018234662A1 (fr) | Procédé de contrôle de l'obtention par un terminal d'un fichier de configuration |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24735643 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024735643 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2024735643 Country of ref document: EP Effective date: 20260128 |
|
| ENP | Entry into the national phase |
Ref document number: 2024735643 Country of ref document: EP Effective date: 20260128 |