System for protecting a device
By introducing command elements into the controller, the device is allowed to switch between high, low, and reset states, which solves the problems of high cost and vulnerability of existing security systems and achieves flexible and secure security state adjustment.
Patent Information
- Application Number
- CN202010902362.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-09-10
- Filing Date
- 2020-09-01
- Publication Date
- 2025-11-07
- Estimated Expiration
- 2040-09-01
AI Technical Summary
Existing controller security systems suffer from high costs, vulnerability to attacks, and insufficient flexibility, especially in that it is difficult to easily and securely adjust the security status according to needs under different operating conditions.
A safety system is provided, including a command element that switches between high, low, and reset states manually or wirelessly to ensure that the device meets safety requirements in different states and prevents modification of the safety state through remote connection.
It enables simple and secure adjustment of the security state according to operational requirements, reducing the risk of system attacks and improving system flexibility and security.
Smart Images

Figure CN112559986B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present invention relates to a safety system.
[0002] It relates to the field of automation, in particular to industrial process automation, building automation or systems for monitoring and / or controlling power distribution networks. BACKGROUND
[0003] It is known to use programmable logic controllers to manage domestic or industrial processes, for example to manage an electrical grid.
[0004] In order to ensure the safety of these processes, against any risk of data theft or attempted malicious intrusion, the controllers generally comprise one or more safety systems which allow the stored data to be monitored and its integrity to be ensured, and which allow the reliability of the communications of the controller to be guaranteed.
[0005] These safety systems can for example take the form of software (anti-malware tools, firewalls, vulnerability searches, etc.) or physical access restrictions (keys, encryption codes, etc.).
[0006] By way of example, in order to control direct local access to a specific controller module comprising a safety system in the form of a human-machine interface, the safety system requires the operator to enter a password on a keyboard if the operator wishes to access the controller.
[0007] However, such systems are not entirely satisfactory.
[0008] In particular, it is necessary to provide a human-machine interface for each module of the controller. In addition to the fact that the human-machine interface is expensive, time-consuming and power-consuming to implement on each module, said interface can be vulnerable if the password is compromised or stolen.
[0009] Furthermore, while a higher state of security of the controller is required for certain operating conditions, a lower state of security can be sufficient in other operating conditions, and therefore a relatively complex safety system is not required. SUMMARY
[0010] The present invention improves this situation.
[0011] The invention is more particularly aimed at providing an efficient safety system for a device such as a controller, which is particularly simple and flexible to use, and which in particular allows the security state to be changed simply and securely according to the operating requirements.
[0012] A safety system is provided, which is fitted in a device, and which comprises a command element, which can be actuated by an operator at least to:
[0013] - a first position in which the device is configured in a high security state, and
[0014] - a second position in which the device is configured in a low security state.
[0015] By these arrangements, the actuation of the command element of the device allows to set the desired security state. Thus, to ensure the security of the device, while implementing a device allowing to control the physical access and particularly simple and effective software means.
[0016] More particularly, the remote connection to the device does not allow to modify its security state, it is necessary to have direct access and to actuate the security system.
[0017] According to another aspect, there is provided a device comprising such a security system.
[0018] According to another aspect, there is provided a method for operating such a security system, the method comprising the steps of:
[0019] - if the command element is in the first position:
[0020] - verifying whether the security of the device has been configured, and
[0021] - if the security of the device has not been configured, downloading configuration data specific to the device and configuring the security of the device before using the device.
[0022] According to another aspect, there is provided a computer program containing instructions for implementing all or part of a method such as defined in the present document, when this program is executed by a processor.
[0023] According to another aspect, there is provided a computer-readable non-transitory storage medium having such a program stored therein.
[0024] “Computer” means any programmable device processing information, such as a processor included in a desktop computer, a tablet computer, a mobile phone, etc.
[0025] The functions described in the following paragraphs can be implemented selectively. They can be implemented independently of each other or in combination with each other:
[0026] The high security state comprises the configuration of software protection functions.
[0027] The command element is manually actuatable by an operator.
[0028] The command element comprises a slot allowing the pivoting of a selector between at least said first position and said second position.
[0029] The command element can be actuated by an operator by short-range wireless communication with the device.
[0030] The command element can also be actuated to a third position in which the device is in a reset state.
[0031] The device is a programmable logic controller or a programmable logic controller module.
[0032] The device comprises a front face and a back face in which the security system is fitted, the back face being configured to be placed in contact with the holder.
[0033] The method comprises the following steps:
[0034] - if the command element is in the third position:
[0035] - actuating the command element to the first position or to the second position.
[0036] Actuating the command element between the first position and the second position requires an intermediate transition to the third position. BRIEF DESCRIPTION OF DRAWINGS
[0037] Other features, details and advantages will become apparent by reading the following detailed description and analyzing the drawings in which:
[0038] Figure 1 A perspective view of the back face of a device comprising a security system according to one embodiment is shown.
[0039] Figure 2 A perspective view of the front face of the device of Figure 1 fastened to the holder with other devices is shown.
[0040] Figure 3 A schematic view of the device of Figure 1 is shown.
[0041] Figure 4 A partial enlarged view of the back face of the device of Figure 1 is shown.
[0042] Figure 5 A diagram illustrating a method for operating a security system according to one embodiment is shown. DETAILED DESCRIPTION
[0043] The following figures and description contain elements of certain features. Thus, they will likely not only contribute to a better understanding of the present disclosure, but also, where appropriate, to its definition.
[0044] Reference is made to Figure 1 which shows a device 1 comprising a security system according to the present invention. The security system is in particular a computer protection device, also called a network security system.
[0045] According to one embodiment, the device 1 is installed in a programmable logic controller (PLC). Such a controller is configured to control an industrial or domestic process, in particular via sequential information processing. More particularly, the controller allows commands to be sent to one or more other controllers or actuators, the sent commands depending on input data, such as sensor measurements, instruction data, etc.
[0046] By way of example, the controller allows machines and sensors in a factory or building to be controlled, or a power management system to be driven.
[0047] Advantageously, the device 1 according to the application relates to a safety controller.
[0048] According to one embodiment, the device 1 is a module of the controller, such as a communication module. More generally, the device 1 can be any industrial module or piece of equipment allowing safety to be configured remotely.
[0049] As Figure 2 illustrated, the device 1 can be configured to be installed on a holder, such as a rail 2. The holder 2 generally comprises other devices 3, 4, 5 arranged modularly with respect to one another. The device 1 can thus be stored in an electrical enclosure (not shown).
[0050] The device 1 generally has a parallelepiped shape. However, other shapes can also be envisaged.
[0051] The device 1 thus comprises a front face la, visible in Figure 2 , which is accessible to an operator.
[0052] The device 1 also comprises a back face lb, visible in Figure 1 , which can be placed facing the holder 2, in particular in contact with the holder 2. Once the device 1 has been fastened to the holder 2, the back face lb is no longer directly accessible to an operator. In order to be able to access the back face lb, it is necessary to unfasten the device 1 from the holder 2.
[0053] As Figure 2 and Figure 3 illustrated, the device 1 comprises input / output interfaces 10, 11 configured to receive information from or send information to the device 1 in order to manage a process.
[0054] The device 1 also comprises a processor 12 (CPU or central processing unit) configured to process instructions forming an operating computer program of the device 1.
[0055] The device 1 also comprises a memory 13 configured to store instructions forming an operating computer program and various other information.
[0056] Device 1 also includes a wired or wireless communication interface 14, specifically for communicating with a remote server configured to store data of device 1.
[0057] Finally, device 1 may include a power source, such as a battery (not shown), or device 1 may be directly connected to the power grid.
[0058] According to the present invention, the device 1 further includes at least one safety system. The safety system includes a command element 20 assembled in the device 1.
[0059] like Figure 1 As shown, the command element 20 is advantageously mounted in the back side 1b of the device 1.
[0060] Command element 20 can be actuated by the operator.
[0061] According to one embodiment, the command element 20 can be manually actuated by an operator.
[0062] For this purpose, the command element 20 may include a slot that allows a flathead screwdriver-type element to pivot the selector 21. However, other types of manual actuation may also be used, employing a key, crank, or other tools known in themselves (whether dedicated or not). Furthermore, other types of command elements 20 are also possible, such as pivot buttons, etc.
[0063] According to another embodiment, the command element 20 can be actuated without operator contact. Advantageously, actuation is performed over a short distance.
[0064] "Short range" specifically refers to actuation via wireless communication with device 1, such actuation being performed from a distance of less than 1 meter, or even advantageously from a distance of less than 10 centimeters. Such short-range communication can, for example, use Near Field Communication (NFC) technology.
[0065] Such short-range communication is advantageously secure in terms of authentication, integrity, and information confidentiality.
[0066] Therefore, the command element 20 can be actuated between at least a first position and a second position.
[0067] In the first position (in Figure 4 As shown in position A, device 1 is in a high-security state. More specifically, device 1 requires pre-configured security features to be usable. Such configuration allows for the implementation of known protection features, particularly software protection features such as data encryption, firewalls, access control, protection diagnostics, updates, etc.
[0068] By way of example, the device 1 cannot establish any communication until the security state has been configured. Once in the security state, the communication is authenticated and protected.
[0069] In a second position, shown in Figure B, Figure 4 , the device 1 is in a low security state.
[0070] By "low / high security state" is meant to understand the security states in relation to each other. Thus, the low security security state can correspond to a standard state in which the device 1 does not require security configuration or includes less protection functions than the protection functions provided in the high security state.
[0071] According to one embodiment, the command element 20 can also be actuated to one or more other positions corresponding to other security states of the device 1, which are not described below.
[0072] In the embodiment shown in Figure B, Figure 4 , the command element 20 can also be actuated to a third position.
[0073] In the third position, shown in Figure C, Figure 4 , the device 1 is in a reset state. More particularly, the device 1 returns to its initial state, in particular to its state when leaving the factory. The security configuration and some or all protection functions potentially implemented by the device 1 are deleted, in particular erased from the memory 13 of the device 1.
[0074] The device 1 advantageously comprises a dedicated output allowing an operator to learn the security state of the device 1, for example via a signal tower or a stack of lights installed on the electrical enclosure containing the device 1 or via a software intended for the use of the operator.
[0075] The device 1 can also comprise an indicator allowing the operator to know in particular the security state of the device 1. The indicator is placed on the front face la of the device 1, as shown in Figure D. Figure 1
[0076] According to one embodiment, the indicator comprises one or more indicator lights 15 allowing to display the security, diagnostic and / or operating state of the device 1. The operator can in particular compare the display of the light(s) 15 with the position of the security system in order to satisfy himself on the integrity of the device 1.
[0077] A method for operating and more particularly installing the security system of the device 1 is described below with reference to Figures E and F. Figure 5
[0078] Initially, the command element 20 is in one of the first, second or third positions A, B, C, which respectively correspond to the device 1 being in a high security state, a low security state and a reset state.
[0079] If the command element 20 is initially in the first position, the method consists in verifying whether the security of the device 1 has already been configured.
[0080] If the configuration has been performed, the device 1 can be used.
[0081] If the security of the device 1 has not yet been configured, the method comprises one or more additional configuration steps. In these configuration steps, security data CS_conf can be downloaded by the device 1, in particular by means of the communication interface 14. These data are for example downloaded from a specific configuration application stored in a remote server or internal Web server, via Ethernet or USB communication.
[0082] As a variant, the security data CS_conf can already be stored in the memory 13 of the device 1.
[0083] The security is configured by means of a computer program which is advantageously already present in the device 1. Once the configuration has been performed, the security is in place and the device 1 can be used.
[0084] If the command element 20 is initially in the second position, the device 1 can be used without specific configuration of the security of the device 1.
[0085] If the command element 20 is initially in the third position, the command element 20 must be actuated into one of the other positions before any use in order to place the device 1 in a high security state or a low security state. The above-mentioned steps of the method can then be implemented subsequently.
[0086] During use, the device 1 is fastened to the holder 2. The back 1b of the device 1 is then no longer directly accessible to the operator.
[0087] Furthermore, the actuation of the command element 20 is advantageously deactivated when the device 1 is in use, in particular connected to the power supply.
[0088] This makes it possible to prevent the command element 20 from being able to be actuated easily to change the security state of the device 1 after the device 1 has been switched on.
[0089] Thus, if it is desired to pass from a high security state to a low security state, or vice versa, it is necessary to disconnect the device 1 from the power supply and / or to separate the device 1 from the holder 2 in advance in order to make the back 1b of the device 1 accessible again.
[0090] In the event of an unauthorized actuation of the command element 20, the safety system can comprise an alarm (not shown), for example a visual or audio alarm, allowing the operator to be informed.
[0091] According to one embodiment, in order to transition from a high security state to a low security state, or vice versa, it is preferable that the command element 20 must be actuated to a third position.
[0092] Thus, before the device 1 can transition to another security state, the security configuration must be deleted. This makes it possible to ensure that information relating to the configuration of the device 1 cannot be saved in a low security state, which can be more vulnerable to cyber attacks.
[0093] Of course, the application is not limited to the embodiments described above, which are provided by way of example only. It encompasses the various modifications, alternative forms and other variants that can be conceived by a person skilled in the art in the context of the application, and in particular all combinations of the various operating modes described above, whether considered individually or in association.
Claims
1. A safety system fitted in a device (1) forming part of a programmable logic controller and comprising a front face (la) and a back face (lb), the safety system being fitted in the back face (lb) which, when the device is in use, is configured to be placed in contact with a holder (2), the safety system comprising a command element (20) which can be actuated by an operator at least to: - a first position in which the device (1) is configured in a high safety state, and - a second position in which the device (1) is configured in a low safety state, wherein the back face (lb) of the device no longer being directly accessible to the operator when the back face (lb) is in contact with the holder (2).
2. The safety system of claim 1, wherein, the high safety state comprising the configuration of a software protection function of the device (1).
3. The safety system of claim 1 or 2, wherein, the command element (20) being manually actuatable by an operator.
4. The safety system of claim 3, wherein, the command element (20) comprising a slot allowing a selector (21) to pivot between at least the first position and the second position.
5. The safety system of claim 1 or 2, wherein, the command element (20) being actuatable by an operator by short-range wireless communication with the device (1).
6. The safety system of any one of the preceding claims, wherein, the command element (20) also being actuatable to a third position in which the device (1) is in a reset state.
7. A device (1) comprising a safety system according to any one of the preceding claims.
8. A method for operating a safety system according to any one of claims 1 to 6, comprising the steps of: - if the command element (20) is in the first position: - verifying whether the safety of the device (1) has been configured, and - if the safety of the device (1) has not been configured, downloading configuration data specific to the device (1) and configuring the high safety state of the device (1) before using the device (1).
9. A method for operating a safety system according to claim 6 according to claim 8, comprising the steps of: - if the command element (20) is in the third position: - actuating the command element (20) to the first position or to the second position.
10. The method of claim 9, wherein, Actuation of the command element (20) between the first position and the second position requires an intermediate transition to the third position.
11. A computer program product containing instructions for implementing the method according to any one of claims 8 to 10 when the program is executed by a computer.
12. A computer-readable non-transitory storage medium having stored thereon a program for implementing the method according to one of claims 8 to 10 when the program is executed by a computer.
Citation Information
Patent Citations
Secure data storage device
US20120099219A1
Plug-and-play declarative security functionality deployment for an engineering platform
WO2019066883A1