Protected Reset of Internet of Things Devices

By storing access code between IoT devices and cloud backends and comparing them with local configuration interfaces, the problem of IoT devices being unable to be reconfigured when they cannot communicate with cloud backends is solved, and the protected reconfiguration of devices is realized, avoiding the risk of devices being delivered.

CN114902218BActive Publication Date: 2025-06-20SIEMENS ENERGY GLOBAL GMBH & CO KG
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080090265.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-11-20
Filing Date
2020-10-26
Publication Date
2025-06-20
Estimated Expiration
2040-10-26

AI Technical Summary

Technical Problem

Existing IoT devices cannot perform protected reconfiguration without communicating with the cloud backend when device configuration and access code are lost or incorrectly configured, resulting in the device being unable to use properly.

Method used

By storing the access code on the cloud backend and IoT devices and when the device cannot communicate with the cloud backend, use the local configuration interface to enter the access code queryed from the cloud backend to compare, and allow the device to reconfigure if it matches.

Benefits of technology

It enables protected reconfiguration when the IoT devices cannot communicate with the cloud backend without destroying the security of the device, avoiding the risk of the device being delivered.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114902218B_ABST
    Figure CN114902218B_ABST
Patent Text Reader

Abstract

The present invention relates to a method for reconfiguring an Internet of Things device (10), wherein the Internet of Things device (10) can be connected to a cloud backend (20) via a network. The method includes the following preparatory steps: storing an access code to be locally input in the cloud backend (20); and storing the access code or verification information formed therefrom on the Internet of Things device (10). The method further includes the following steps for reconfiguring the Internet of Things device (10): querying the access code from the cloud backend (20); inputting the queried access code into the local configuration interface (13) of the Internet of Things device (10) or an input device (31) connected to the local configuration interface (13) of the Internet of Things device (10); comparing the input access code with the access code stored on the Internet of Things device (10) or the verification information formed therefrom; and releasing the Internet of Things device (10) for reconfiguration in the case where the comparison of the input access code with the access code stored on the Internet of Things device (10) or the verification information formed therefrom results in an affirmative outcome.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a method for reconfiguring Internet of Things (IoT) devices. In particular, the present invention relates to the problem of how the reset (in other words: reconfiguration) of IoT devices can be carried out in a protected manner without the device itself having to communicate with a cloud backend via a network for this purpose. Background Art

[0002] IoT devices collect data and send the data to a cloud backend in a protected manner. An example of such an IoT device is a product of Siemens AG This product collects monitoring data from a transformer and sends the monitoring data to a cloud backend via an encrypted communication connection (usually the TLS (Transport Layer Security) protocol) for evaluation.

[0003] IoT devices must be configured. The configuration can be carried out remotely via a cloud interface or via a local management interface (Command Line Interface or Web Server). To prevent unauthorized configuration changes, authentication of service access is required. For this purpose, a password or a similar access code is usually entered at the local management interface.

[0004] If the access code is no longer known, the associated device can no longer be configured and used. If the communication with the cloud backend is interrupted, for example due to a previous misconfiguration, the device cannot be used and must be sent in for repair.

[0005] Therefore, there is a need to be able to reset the device access code or the entire device configuration (Password Reset / Factory Reset) in order to regain access to the local management. This must be carried out in a protected manner to prevent unauthorized resets. Summary of the Invention

[0006] The method according to claim 1 of the present invention provides such a method. Advantageous variants and refinements are disclosed in the dependent claims, the description and the drawings.

[0007] A method for reconfiguring an IoT device that can be connected to a cloud backend via a network according to the present invention comprises the following steps:

[0008] - Storing an access code to be entered locally in the cloud backend,

[0009] - Store the access code or the authentication information formed based on the access code on the Internet of Things device.

[0010] - Query the access code from the cloud backend.

[0011] - Input the queried access code into the local configuration interface of the Internet of Things device or an input device connected to the local configuration interface of the Internet of Things device.

[0012] - Compare the input access code with the access code stored on the Internet of Things device or the authentication information formed based on the access code, and

[0013] - When the comparison between the input access code and the access code stored on the Internet of Things device or the authentication information formed based on the access code is a positive result, release the Internet of Things device for reconfiguration.

[0014] Here, the first two steps must be executed before the remaining steps. The first two steps can also be called preparation steps. The access code or the authentication information formed based on the access code can be stored on the Internet of Things device during the production of the Internet of Things device in the factory. Alternatively, the access code or the authentication information can also be implemented by the customer during onboarding, i.e., when the Internet of Things device is put into operation. This can also be repeated automatically, for example, daily, weekly, or monthly. This has the advantage that new access codes and associated authentication information are set up automatically. Thus, the access codes set up in the past can no longer be misused, even if they may have been known to attackers.

[0015] Advantageously, when the Internet of Things device is put into operation, a connection between the Internet of Things device and the cloud backend is established.

[0016] The subsequent steps, namely the query, input, and comparison of the access code, occur when the Internet of Things device should be specifically reconfigured, for example, because the communication connection between the Internet of Things device and the cloud backend is no longer working properly.

[0017] Generally, the access code can be, for example, a random value that has letters, numbers, and / or special characters. The access code can generally also be a bit sequence or an XML data structure or a JSON data structure.

[0018] In the first variant, the access code can be formed (in other words: generated) by the Internet of Things device itself.

[0019] Alternatively, the access code can also be formed by the cloud backend.

[0020] In another variant, a first random value is formed by the Internet of Things device, and a second random value is formed by the cloud backend. Subsequently, a common access code is generated based on the first random value and the second random value.

[0021] In the context of this patent application, the terms "access code" and "device access code" are used synonymously. Additionally, in the context of this patent application, for better readability, "Internet of Things device" is abbreviated as "device" in some places.

[0022] In the context of this patent application, an Internet of Things device is generally understood to be a device that can be connected either wired or wirelessly and that generates data and / or executes control commands. An Internet of Things device is sometimes also referred to in technical terms as an "Edge Device" or a "Smart Edge Device".

[0023] In a specific embodiment, the Internet of Things device monitors a transformer. For example, the Internet of Things device transmits the oil level, temperature, under-voltage winding current, and / or GPS location of the transformer to the cloud.

[0024] The cloud backend is understood to be an IT service that can be accessed via a public or private network. The cloud backend can generally be accessed via the Internet or a public mobile radio network, such as 3G, LTE, 5G, LoRa, NB-IoT, or SigFox. Examples of cloud backends include Siemens MindSphere, Microsoft Azure, Amazon AWS. Data transmission can be protected by encryption, for example, via the TLS protocol (TLS: Transport Layer Security; Secure Transport Layer).

[0025] The cloud backend stores the access code to be entered locally so that the access code can be provided to authorized users when needed. The Internet of Things device can either directly store the access code or store the verification information formed based on the access code. The verification information enables the Internet of Things device to verify the validity of the access code entered locally (as is known to those skilled in the field of password verification).

[0026] At a later point in time, the access code to be entered locally on the Internet of Things device can thus be queried from the cloud backend by an authorized user. The access code can be displayed, for example, or provided as a text file. The access code can be displayed as a graphical element to prevent easy copying of the access code by means of Copy&Paste.

[0027] Advantageously, the access code queried from the cloud backend is input at the local configuration interface of the Internet of Things device. Here, for example, it may involve an RS232 interface, a USB interface, an SPI interface or an I2C interface. Advantageously, the input is performed by means of an input device connected to the local configuration interface via a LAN cable. It is also possible that the Internet of Things device has a user interface, such as a keyboard or a touch-sensitive screen (Touch Screen), which can input the access code.

[0028] In addition, the cloud service can authenticate the accessing user and record which user has obtained the device access code. This enables the identification of the user accessing the device locally, even if the device itself technically only supports a simple device access code. This supports the implementation of the requirement of IEC62443-4.2 for "unique user identification" (requirement CR1.1(1)).

[0029] The access code to be input locally can enable different types of access to the Internet of Things device: First, it is conceivable to directly access the configuration menu of the Internet of Things device by means of the access code. Second, the access code enables the resetting of the local access password. In this case, the user must reset the access password to obtain access to the configuration menu. Third, it is conceivable to directly perform a "Factory Reset" by means of the access code, that is, to reset the entire device settings to the factory settings.

[0030] One of the mentioned access types can be fixedly predefined in the Internet of Things device. However, in a variant, multiple access codes with different associated actions can be prepared, which can be provided to authorized users by the cloud backend as needed. Then, the device performs the corresponding action according to which access code is input.

[0031] In addition, multiple or several access codes to be input locally can be prepared.

[0032] Preferably, the access code can only be used restrictedly (especially only once). After re-establishing cloud connectivity, a new set of local device access codes is preferably established.

[0033] In a variant, the cloud backend provides an access code for reconfiguration only if the device in question has not logged in and / or updated its status data in the cloud backend via the network within a certain time period (e.g., 1 hour, 1 day, 1 week). This has the advantage that, regardless of user authorization, the access code for local management access to the device is provided only if the device in question has been unable to connect to the cloud backend for a long time. Conversely, in normal operation, if cloud access works as set up, the reset code, i.e., the access code, cannot be queried. Here, the device configuration must then be carried out via the cloud backend.

[0034] It is also possible that after local access, normal cloud communication must be re-established within a time window (e.g., 10 minutes, 1 hour, 24 hours). If this is not successful, the device automatically reactivates the secure previous configuration.

[0035] The present invention enables Internet of Things devices whose configuration for cloud access no longer works properly (specifically, for example, Internet of Things devices of Siemens AG) to be put back into operation in a protected manner. This also works properly especially when the Internet of Things device is no longer able to communicate with the cloud backend (e.g., because the network configuration for cloud access has been misconfigured).

[0036] Furthermore, it is not necessarily required to manually configure a local service access password on the Internet of Things device. As long as the Internet of Things device works as set up, the Internet of Things device can be managed (in other words: configured) via the cloud interface. The prepared access code is provided only when access to the cloud no longer works properly. This has the advantage that the local configuration interface of the Internet of Things device cannot be accessed during normal operation. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] The present invention will be described below by way of example and schematically with reference to two drawings. In the drawings:

[0038] Figure 1 The arrangement of an Internet of Things device, a cloud backend, and a user according to the prior art is shown, and

[0039] Figure 2 A flowchart of a method for reconfiguring an Internet of Things device according to an embodiment of the present invention is shown. DETAILED DESCRIPTION

[0040] Figure 1 An application scenario is shown of how an Internet of Things device 10 can conventionally be reconfigured in a protected manner. For example, an " Internet of Things device" of Siemens AG (abbreviation: ) is used as the Internet of Things device 10. The task of 10 is to monitor the transformer 11 connected to it. 10 collects the monitoring data / operating data of the transformer 11 (such as the temperature and filling level of the coolant) and the ambient temperature through its own sensors 121 and through the sensors 122, 123 of the transformer 11. This information is transmitted to the cloud backend 20 via a mobile radio interface 41 (such as UMTS, LTE, 5G, LoRa, NB-IoT or SigFox) and the Internet 43. Thereby, for example, it can be identified when the transformer 11 needs maintenance (predictive maintenance). Firmware is installed on 10 to collect sensor data, preprocess the sensor data if necessary, and to establish a data transmission connection to the cloud backend 20. Establishing a data transmission connection to the cloud backend 20 can be achieved, for example, via TCP / IP, TLS and HTTP, MQTT, OPC UA or CoAP.

[0041] In addition, in order to manage the Sensformer Internet of Things device 10, that is, to remotely change configuration settings or import firmware updates, a second connection is established. For this purpose, the service technician 30 connects to the configuration interface of the cloud service via the input device 31 and a web browser and enters configuration changes, which are then transmitted to the Internet of Things device 10. The connection between the input device 31 (such as a laptop) and the Internet 43 is Figure 1 identified by the reference numeral 42 in the figure.

[0042] However, in very rare cases, such as in the case of technical failures or incorrect operations, it may occur that the imported configuration does not work properly. Therefore, for example, an incorrect URL of the cloud service, an incorrect certificate of the cloud service, an incorrect device certificate, an incorrect APN name (Access Point Name, the network name for mobile radio access) of the mobile radio configuration or a similar error may cause the Internet of Things device 10 to no longer be able to connect to the cloud backend 20. Then it is also no longer possible to correct the configuration via the cloud backend 20.

[0043] Therefore, a local configuration interface (LCI) 13 is also provided for this case, which can be implemented, for example, as an RS232 interface, a USB interface, an SPI interface or an I2C interface. The service technician 31 can connect via a local cable connection to The local configuration interface 13 of the IoT device 10 is connected. This connection is usually protected by a password or access code known only to the service technician 30. If the service technician forgets the password or access code, it is no longer possible to access the IoT device 10 and the IoT device 10 must be delivered, for example, for reconfiguration.

[0044] The present invention proposes that, in this case, an access code pre-generated by the cloud backend and stored on the IoT device must be entered in order to regain access to the configuration settings. Here, the current configuration settings can be automatically reset in whole or in part to default values ​​(e.g., password reset, factory reset).

[0045] Figure 2 A flow chart of a method for reconfiguring an IoT device 10 according to an embodiment of the present invention is shown. This is only an exemplary process, for which there are a series of alternatives and variants, which are obviously disclosed to a person skilled in the art in the general description of the present invention or are obvious to him based on his professional knowledge.

[0046] The method for reconfiguration is divided into two phases: first, a phase of generating and storing an access code (phase 100); and then a phase of actually reconfiguring the IoT device 10 by means of the local configuration interface 13 (phase 200). If the IoT device 10 has been successfully reconfigured, the IoT device can communicate with the cloud backend 20 normally again (phase 300) and, for example, send sensor data of the IoT device to the cloud backend 20.

[0047] exist Figure 2 In the example of , the first stage 100 includes the following steps: a connection signal is sent from the IoT device 10 to the cloud backend 20 (step 101); a confirmation of the receipt of the connection signal is sent from the cloud backend 20 back to the IoT device 10 (step 102). Then, the cloud backend 20 generates an access code to be entered locally and stores it in the cloud backend 20 (step 103). Subsequently, the generated access code or the verification information formed based on the access code is transmitted from the cloud backend 20 to the IoT device 10 (step 104). In the next step 105, the access code or the verification information formed based on the access code is stored on the IoT device 10 (step 105). Then it is confirmed that "the access code or verification information has been stored on the IoT device 10 (step 106)", and a signal is sent that "the connection between the IoT device 10 and the cloud backend 20 is interrupted (step 107)". Finally, the cloud backend 20 confirms this to the IoT device 10 (step 108).

[0048] If an unplanned and unwanted interruption occurs in the connection between the Internet of Things device 10 and the cloud backend 20 and the Internet of Things device 10 needs to be reconfigured, then phase 200 becomes effective, and the steps are as follows: Send a query regarding the access code from the user 30 to the cloud backend 20 (step 201); Reply to the user 30 from the cloud backend 20 by sending the stored access code (step 202); Enter the obtained access code at the Internet of Things device 10, for example, by means of a laptop, which is connected to the local configuration interface of the Internet of Things device 10 using a LAN connection. Subsequently, compare the entered access code with the previously stored access code or associated verification information at the Internet of Things device 10 (step 204). If the two access codes are identical or if the verification information matches the entered access code, then a factory reset is performed in the Figure 2 illustrated example (step 205). This enables, among other things, the configuration settings to be changed by the user 30 (step 206). This is notified to the user 30 (step 207). In the next step, the user 30 reconfigures the Internet of Things device according to their ideas and wishes (step 208). Store the new configuration settings on the Internet of Things device 10 (step 209), and finally send a confirmation to the user 30 (step 210).

[0049] Thereupon, the Internet of Things device 10 can be reused to access the cloud backend 20, so that the third phase 300 becomes effective, that is, the normal access of the Internet of Things device 10 to the cloud backend 20 becomes effective. This is represented in Figure 2 by sending a connection signal from the Internet of Things device 10 to the cloud backend 20 (step 301) and sending a received confirmation from the cloud backend 20 to the Internet of Things device 10 (step 302).

[0050] Therefore, the method illustrated in Figure 2 exemplarily shows how to reconfigure the Internet of Things device in a protected manner, while the Internet of Things device 10 itself does not have to communicate with the cloud backend for this purpose (during reconfiguration).

[0051] List of reference numerals

[0052] 10 Internet of Things device, for example

[0053] 11 Transformer

[0054] 121 Sensor

[0055] 122 Sensor

[0056] 123 Sensor

[0057] 13 Local configuration interface

[0058] 20 Cloud backend

[0059] 30 Users, service technicians

[0060] 31 Input device

[0061] 41 Connection between the Internet of Things device and the Internet

[0062] 42 Connection between the input device and the Internet

[0063] 43 Internet connection

[0064] 100 Generate and store access codes

[0065] 101…108 Steps

[0066] 200 Reconfigure the Internet of Things device through the local configuration interface of the Internet of Things device

[0067] 201…210 Steps

[0068] 300 The Internet of Things device routinely accesses the cloud backend

[0069] 301, 302 Steps

Claims

1. A method for reconfiguring an Internet of Things device (10), wherein, The Internet of Things device (10) can be connected to a cloud backend (20) via a network, including the following steps: - Form a first random value by the Internet of Things device (10), - Form a second random value by the cloud backend (20), - Form an access code based on the first random value and the second random value, - Store the access code to be locally input in the cloud backend (20), - Store the access code or verification information formed based on the access code on the Internet of Things device (10), where the access code is provided only under the following condition: the Internet of Things device (10) has not logged in to the cloud backend (20) via the network within a predetermined time period, - Query the access code from the cloud backend (20), - Input the queried access code into the local configuration interface (13) of the Internet of Things device (10) or an input device (31) connected to the local configuration interface (13) of the Internet of Things device (10), - Compare the input access code with the access code stored on the Internet of Things device (10) or the verification information formed based on the access code, and - Release the Internet of Things device (10) for reconfiguration in the case where the comparison between the input access code and the access code stored on the Internet of Things device (10) or the verification information formed based on the access code is a positive result.

2. The method according to claim 1, wherein, The access code is generated by the Internet of Things device (10) or by the cloud backend (20).

3. The method according to claim 1 or 2, wherein, Querying the access code from the cloud backend (20) includes the following sub-steps: - Send a query to the cloud backend (20), and - Provide the access code.

4. The method according to claim 3, wherein, The provision of the access code is carried out by displaying the access code, a text file containing the access code, or a graphical element mapping the access code.

5. The method according to claim 1 or 2, wherein, Querying the access code from the cloud backend (20) includes: - Authenticating the user (30) making the query, and / or - Collecting and storing the user (30) making the query.

6. The method according to claim 1 or 2, wherein, Input the access code queried from the cloud backend (20) into an input device (31), and the input device is connected to the local configuration interface (13) of the Internet of Things device (10) via a LAN cable.

7. The method according to claim 1 or 2, wherein, In the case where the comparison between the input access code and the access code stored on the Internet of Things device (10) or the verification information formed based on the access code is a positive result, - Provide a local access password for local reconfiguration of the Internet of Things device (10), or - Reset the entire device settings of the Internet of Things device (10) to the factory settings.

8. The method according to claim 1 or 2, wherein, The access code can be used only a limited number of times.

9. The method according to claim 1 or 2, wherein, The access code can be used only once.

10. The method according to claim 1 or 2, wherein, If the Internet of Things device (10) does not reconnect to the cloud backend (20) within a predetermined time period after the reconfiguration, the reconfiguration is revoked.

11. The method according to claim 1 or 2, Among them, The Internet of Things device (10) monitors the transformer.

Citation Information

Patent Citations

  • Account access recovery system, method and apparatus

    CN107710715A

  • Method and system for resetting secure passwords

    US20070250914A1

  • System and Method for Resetting Passwords on Electronic Devices

    US20160352702A1