GATEWAY FOR COMMUNICATION VIA A RADIO NETWORK WITH AT LEAST ONE NODE AND VIA A WIRED NETWORK USING A BLOCKCHAIN
Patent Information
- Application Number
- DE602019081287
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2018-12-06
- Filing Date
- 2019-12-02
- Publication Date
- 2026-02-11
- Estimated Expiration
- 2039-12-02
AI Technical Summary
Existing LoRaWAN networks require significant resources for deployment, including gateways and application servers, and lack flexibility in ownership and security, especially when covering large areas.
A gateway system using blockchain technology to facilitate secure data transfer between nodes and recipients without shared ownership, employing ephemeral keys and smart contracts to ensure confidentiality and payment, allowing decentralized network deployment.
Enables secure, decentralized data transfer with confidentiality and fair payment, reducing the need for extensive infrastructure and enabling multiple actors to deploy and use the network independently.
Description
TECHNICAL FIELD OF THE INVENTION
[0001] The present invention relates generally to the field of telecommunications in a network with IoT connected objects, in particular the field of network communication systems using a gateway, connected to an object or a node and an application receiving data from the object or node.
[0002] The invention also relates to a gateway for communicating by radio network with at least one node or object and by wired network with at least one application or at least one application server of a recipient and a data storage device constituting at least one database storing blockchain transactions, and the use of one or more gateways in a system for connected objects and user applications.
[0003] It also relates to a communication method enabling communication via radio network with at least one node or object and via a wired network with at least one application or at least one application server of a recipient through at least one gateway and a data storage device constituting at least one database storing blockchain transactions. STATE OF THE PRIOR TECHNIQUE
[0004] Low-Power Wide Area Networking (LPWAN) technology, or wide area network, is a computer network covering a large geographical area and enabling a wide variety of services and applications. In particular, it meets the data communication needs of the Internet of Things (IoT). An IoT device is often characterized by small electronic equipment that consumes little power to transmit a limited amount of data at a time via radio link, allowing it to operate for several years on a single battery.
[0005] However, LPWAN technology offers a limited transmission rate but robust modulation that enables communications over several kilometers. This range reduces the need for equipment deployment, thus decreasing the number of antennas and / or gateways required.
[0006] Today there are different implementations of LPWAN technology (Sigfox, NB-loT...).
[0007] LoRaWAN is one of the most satisfactory implementations of LPWAN technology, thanks to its "open source" system support and the possibility for anyone to create their own network.
[0008] LoRaWAN uses unlicensed radio spectrum waves, much like Wi-Fi, meaning anyone can use these radio frequencies without paying transmission rights fees. This flexible deployment strategy has driven industries and businesses to invest in the technology. It allows them to either use an existing public network or install their own private network if they are concerned about network ownership.
[0009] LoRaWAN comes with ease of installation, is completely free of industrial property rights and royalties (which is not the case for Sigfox) and offers the most robust level of security and confidentiality.
[0010] Thanks to its low power consumption (lifespan of several years, button cell battery) and long range, LoRaWAN has attracted the attention of industrial players to meet various needs in diverse fields. This includes management advantages for monitoring and surveillance (in airports, parking lots, construction sites, warehouses, retail outlets, energy management optimization, land-use planning, pallet and container tracking; "smart" cities with smart meters, parking lot detectors, urban lighting control, waste management; or "smart" buildings and homes that can detect water leaks, control rodent or termite traps, and all kinds of smart home sensors).
[0011] The LoRaWAN architecture consists of at least one device or sensor that detects and collects data to transmit to a radio-range gateway, at least one gateway that acts as an access point and sends packets to a network server through a backhaul network; a central network, the network server that receives all packets received from the gateways and directs them to an application server, and finally, at least one application server that manages the client application and processes the data.
[0012] This type of system is suitable and convenient from a privacy and security standpoint, but has the drawback that, even though a LoRa gateway can cover a large area of several kilometers, it requires considerable resources to independently cover the entire area of use of the devices (e.g., entire countries). A company wishing to deploy its own private network will need to install gateways, application servers, and, most importantly, a core network.
[0013] In this context, it is interesting to propose a solution for a wide communication network that requires fewer resources from the user for its deployment, while maintaining a high level of confidentiality and security.
[0014] It may also be interesting to propose a solution in which the communication network could be deployed by several interesting actors, rather than dependent on a single actor.
[0015] Several initiatives for creating a network are known in the past. For example, the PicoWAN network allows for easy and less expensive deployment than traditional methods, but offers a limited coverage area and requires the installation of gateways to provide the network.
[0016] The prior art document "Using blockchain technology to build trust in sharing LoRaWAN loT" describes a gateway enabling an IoT device to communicate encrypted data to a recipient application. This document considers the use of a blockchain.
[0017] The prior art document CHA SHI-CHO et al, « a blockchain connected gateway for BLE-Based Devices in the Internet of Things »This document describes a gateway connected to a blockchain database for Bluetooth Low Energy (BLE) IoT devices. It proposes creating and using smart contracts to manage IoT device information and privacy policies. The gateway itself also has a smart contract. However, this is done solely to record and store user preferences on the blockchain database, where they are tracked and cannot be modified without being detected. This document does not, however, improve network security or availability. EXPOSITION OF THE INVENTION
[0018] The present invention aims to overcome certain drawbacks of the prior art by proposing a communication network for Internet of Things data, which is similar to an operator network such as a 2G / 3G / 4G cellular network, the SIGFOX network or a LoRaWAN network, but without the said network requiring an operator to function or an entity specifically deploying relay antennas in an area where it does not have any.
[0019] The invention is defined by the attached claims.
[0020] The invention thus relates to a gateway for communicating via a radio network with at least one node or object and via a wired network with at least one application or at least one application server of a recipient, and a data storage device constituting at least one database storing blockchain transactions. The gateway comprises several code modules executable on one or more hardware processing components such as a microprocessor to constitute a machine. The modules are stored in at least one machine-readable medium, of which at least: A second transmitter module, which, by executing at least one code on a hardware component, sends data over the radio network to a node communicating with at least one connected object (D). This data is stored in at least one machine-readable medium on the gateway. The data includes at least one ephemeral public key (ePk) complementary to one ephemeral private key (eSk). A third receiver module, which includes multiple codes executed on a hardware component to receive data from a node or object on the radio network, includes: a signature, an encrypted message, and a blockchain address of the recipient's application or application server (@R) linked to a blockchain transaction created by the recipient's application or application server (@R), which includes an IP address of the recipient's application or application server. The third module includes a search submodel which,by executing code on a hardware component, searches for a transaction at the blockchain address of the recipient's application or application server and retrieves said IP address of the recipient's application or application server contained in the transaction, and a sender submodule (6) which, by executing code on a hardware component, triggers the sending via IP protocol to the IP address of the recipient's application or application server of at least: the encrypted message, the signature, the ephemeral public key, and the gateway's blockchain address, A fourth blockchain management module comprising: at least one search submodule which, by executing code on a hardware component, searches for a transaction or blockchain transaction data created by the recipient in the database storing blockchain transactions and which includes or results from a specific ephemeral public key (ePk) script,said search beginning when the encrypted message, the ephemeral public key, and the signature are sent to the recipient; and a transaction creation sub-module which, by executing code on a hardware component, creates a new blockchain transaction destined for the gateway itself using a script incorporating the ephemeral private key (eSk) to validate the script of the blockchain transaction (8) created by the recipient; said new transaction, once validated, includes the eSk key to allow decryption of the encrypted message; said creation beginning when said blockchain transaction created by the recipient has been found.
[0021] Thus the invention has the advantage of allowing at least one transfer of a message from a node to a recipient, via a gateway which does not necessarily share the same owner with the recipient and / or the node, while guaranteeing the security and confidentiality of the message, the ephemeral private key being known only to the gateway and the node, both actors in the communication.
[0022] According to other advantageous aspects of the invention, the gateway according to the invention incorporates one or more of the following features, taken individually or in all technically possible combinations: According to one particular feature, the event triggering the generation and / or sending of the ephemeral private and public keys by a first gateway generator module and / or the second gateway sender module can be at least one event chosen from the following list: the reception by radio link (2) of a request for the ephemeral public key from at least one node communicating with at least one connected object, the periodic transmission, by a transmission module of the gateway, optionally the second module of the gateway, of a signaling message containing the ephemeral public key, or one of their combinations.
[0023] Thus, the generation of private and / or public ephemeral keys is more flexible and can be triggered by several phenomena which will be chosen according to the situation and its constraints.
[0024] According to another peculiarity, the gateway's fourth blockchain management module also includes a verification sub-module which, by executing codes associated with a hardware component, verifies by means of the ephemeral private key (eSk) that said transaction contains a financial value, and optionally measures said financial value, the verification sub-module being further configured to stop the transaction if the verification fails or if the financial value contained in the transaction is less than a value previously negotiated between the gateway and the node and stored in a medium readable by the gateway.
[0025] Using cryptocurrency in a data transfer transaction incentivizes gateways to join the system thanks to the potential reward offered for each data transfer. This verification, performed by the verification sub-module, allows the gateway to validate the transaction only if the payment is present and sufficient, for example, equal to a previously negotiated value. This prevents the recipient from failing to pay or underpaying the gateway for the data transfer.
[0026] According to another characteristic, the gateway is used with a node communicating with at least one connected object, or directly an object (1), the node or object comprising at least one or more executable code modules on one or more processing hardware components such as a microprocessor to constitute a machine, the modules being stored in at least one machine-readable medium, and at least: A machine-readable medium constituting a memory space containing a private key (Sk) and a blockchain address of the recipient transmitted by an application of the recipient or the recipient's application server to the node; A receiver module which, by executing code on a hardware component, receives the ephemeral public key (ePk) sent by the gateway; A generator module which, by executing code on a hardware component, generates a message (m) in response to data from a connected object. said module comprising an encryption sub-module which, by means of the ephemeral public key (ePk) sent by the gateway, encrypts this message to obtain the ciphertext message (Em), the encryption sub-module further performing a signature, the signature (Sig) being the encryption, of a hash of the ciphertext message and of the ephemeral public key received from the gateway, by means of the private key (Sk) contained in the memory space of the node, the generator module (N5) also comprising a transmitter sub-module which sends the signature, the ciphertext message and the blockchain address of the recipient to the gateway via the radio network.
[0027] This allows the node to communicate data to the gateway and to offer a telecommunications network according to the invention which is distributed and reliable.
[0028] According to another peculiarity, the encryption submodule of the node or object first encrypts the message (m) generated by the generator module (N5) using a symmetric key (K) shared with an application or application server of the recipient to obtain the encrypted message Ek(m) before the encryption submodule encrypts the message using the ephemeral public key (ePk) sent by the gateway, to obtain the double encrypted message (Em).
[0029] Thus, the message can only be decrypted using a key (K) known only to the node or object and the recipient. The message can be encrypted with this key on the node and decrypted on the recipient's side. This encryption is necessary if data confidentiality is required. A gateway without the key will not be able to decrypt the message, thus preserving confidentiality during exchanges with a third-party entity, such as a gateway that does not share the same owner as the node and the recipient.
[0030] According to one particular feature, a gateway according to the invention can be used with: A node or object according to the invention; an application or application server of the recipient, the application or server comprising at least one or more code modules executable on one or more hardware processing components such as a microprocessor to constitute a machine, the modules being stored in at least one machine-readable medium, including at least: a generation module which, by executing code on a hardware component, generates and sends the private key (Sk) and optionally the symmetric key (K) to the node communicating with at least one connected object; a machine-readable medium constituting a memory space comprising a public key (Pk) complementary to the private key (Sk) transmitted to the node; a first transaction module which, by executing code on a hardware component, creates a blockchain transaction at the blockchain address of the recipient's application or application server.said blockchain transaction including the IP address of the recipient's application or application server; A receiving module which, by executing code on a hardware component, receives from the gateway, via a long-distance network, for example the Internet, the data including the encrypted message, the signature, and the ephemeral public key sent by the gateway, and upon receiving said data, launches a signature verification sub-module which verifies, by means of a signature calculation using the private key (Sk) stored in memory space, by comparing the result of the calculation with the received signature, that the received signature was indeed generated by the node communicating with at least the connected object, the module stopping the transaction if this verification fails; A transaction module, optionally the first transaction module, which, by executing code on a hardware component,creates a blockchain transaction at the recipient's blockchain address once the verification submodule has performed message verification; the transaction includes at least one specific script, using the ephemeral public key sent by the gateway; The transaction module includes a search submodule which, once the encrypted message (Em), the ephemeral public key (ePk), and the signature (Sig) are received, or the transaction created by the recipient, searches for a blockchain transaction incorporating the gateway's blockchain address and a signing script using the ephemeral private key (eSk); The transaction module includes a decryption submodule which, once the blockchain transaction is found, uses the ephemeral private key (eSk) of said transaction to decrypt the encrypted message from the node received from the gateway by the receiving module, and preferably also using the symmetric key (K) shared with the node.The transaction module optionally includes a read / write sub-module and a memory space in which the read / write sub-module stores data and which, once the blockchain transaction is found, stores the ephemeral private key (eSk) of said transaction in the machine-readable medium of the recipient's application or application server. Advantageously, the use of a gateway, a node, and a recipient according to the invention allows the implementation of a system for a distributed network whose various actors may belong to different and unrelated owners, while guaranteeing non-abusive use of the network through the use of blockchain characteristics.
[0031] According to a particular feature, the gateway's transaction module unlocks the transaction created by said module after a certain period, if the gateway has not unlocked the transaction during that period.
[0032] Advantageously, the recipient can retrieve the transaction details if the ephemeral private key (eSK) is not provided in time, for example, if the gateway malfunctions. This incentivizes the various parties involved in the communication to transmit data quickly.
[0033] According to one particular feature, the communication system node can use RSA-512 encryption to perform its data signing.
[0034] Advantageously, RSA-512 encryption allows for limiting the size of the payload sent over the limited LoRaWAN network. Payload refers to the volume of data exchanged between the different parties.
[0035] According to one particularity, the gateway's fourth blockchain management module includes a time measurement sub-module associated with an instruction to wait for a confirmation time after receiving a blockchain transaction from the recipient, preferably at least before receiving the transaction requiring the provision of the ephemeral secret key.
[0036] This will help protect against the recipient's "double spending," a phenomenon whereby the recipient can successively create a transaction and spend it, allowing them to recover the ephemeral private key without rewarding the gateway for the data transfer.
[0037] According to one particular feature, the gateway's fourth blockchain management module awaits confirmation of the blockchain block mining by other blockchain participants.
[0038] Advantageously, mining provides cryptographic proof that does not rely on trust between the participants who provided the information.
[0039] According to one particular feature, the gateway also includes a first generator module which includes at least one code executed on a hardware component, to generate the ephemeral private key (eSk) and the ephemeral public key (ePk) complementary to said ephemeral private key (eSk), preferably in response to a triggering event, and stores these keys (ePk, eSk) in a machine-readable medium.
[0040] The invention also relates to a method of communication between at least one connected object linked by radio either directly to a node or to at least one gateway communicating via a wired network with at least one application or at least one application server of at least one recipient, characterized in that it comprises: a gateway comprising several code modules executable on one or more hardware processing components such as a microprocessor to constitute a machine, the modules being stored in at least one machine-readable medium including at least: A first generator module A second transmitter module A third receiver module which includes a transmitter sub-module,A fourth blockchain management module that includes at least one search sub-module and one transaction creation sub-module; a node of a connected object comprising at least one or more code modules executable on one or more processing hardware components such as a microprocessor to constitute a machine, the modules being stored in at least one machine-readable medium and at least: One machine-readable medium, One receiver module (N2), One generator module (N5) comprising an encryption sub-module and a transmitter sub-module; an application or application server of the recipient comprising at least one or more code modules executable on one or more processing hardware components such as a microprocessor to constitute a machine, the modules being stored in at least one machine-readable medium.including at least: A generation module, a machine-readable medium, a first transaction module, a receiver module including a verification sub-module, a transaction module, optionally the first transaction module including a search sub-module, a read / write sub-module and a decryption sub-module. The modules perform their actions by executing code on at least one hardware component; and that it includes at least the following steps: I- Generation by the generation module of the application or the recipient's application server of a public key (Pk) and recording on a machine-readable medium constituting a memory space, then generation and sending of the private key (Sk) complementary to the public key (Pk) to the node communicating with at least one connected object,and recording in the readable medium of the node constituting a memory space the transmitted private key (Sk); II- Creation of a blockchain transaction by the transaction module of the recipient's application or application server at the blockchain address of the recipient's application or application server, said blockchain transaction including the IP address of the recipient's application or application server; III- Sending by the second transmitting module of the gateway over the radio network to a node communicating with at least one connected object (D), of the ephemeral public key (ePk) stored in at least one machine-readable medium of the gateway; IV- Reception by the receiving module of the node of the ephemeral public key (ePk) sent by the second transmitting module of the gateway; V- Generation by the generator module of the node, of a message (m) in response to data from a connected object (D),Encryption of the message (m) by the encryption sub-module of the generator module (N5), using the ephemeral public key (ePk), to obtain the encrypted message (Em). Creation of a signature by the encryption sub-module, the signature (Sig) being the encryption of a hash of the encrypted message and the ephemeral public key received from the gateway, using the private key (Sk) contained in the node's memory space. VI- Sending the signature.of the encrypted message from the recipient's blockchain address by the sender sub-module of the generator module (N5) of the node to the gateway via the radio network; VII- Reception of the data by the third receiver module of the gateway and search by the search sub-model of the third receiver module of the gateway for a blockchain address of the recipient's application or application server (@R) linked to a blockchain transaction created by the recipient's application or application server (@R) including an IP address of the recipient's application or application server and retrieves said IP address, VIII- Sending by the sender sub-module of the third module of the gateway via IP protocol to the IP address of the recipient's application or application server of at least: the encrypted message, the signature,the ephemeral public key and the blockchain address of the gateway; IX- Reception by the receiving module of the application or an application server of the recipient, via IP protocol, of the gateway data including the encrypted message, the signature and the ephemeral public key, and upon receipt of said data, launch of a signature verification sub-module, and verification by means of a signature calculation using the private key (Sk) stored in memory space by comparing the result of the calculation with the received signature that the received signature was indeed generated by the node communicating with at least the connected object, the transaction being stopped by the module if the verification fails; X- Creation of a blockchain transaction at the recipient's blockchain address by the transaction module of the application or an application server of the recipient, optionally the first transaction module,Once the verification sub-module has verified the message, the transaction includes at least one specific script, using the ephemeral public key (ePk); XI- Search for a transaction of the blockchain transaction (8) created by the recipient in the database storing blockchain transactions and which contains or results from a specific script with an ephemeral public key (ePk) by the search sub-module of the fourth blockchain management module of the gateway, once the data sending during step VIII has been carried out, then, once said blockchain transaction created by the recipient is found, creation of a new blockchain transaction by the transaction creation sub-module of the fourth blockchain management module of the gateway using as inputs the outputs of the previous transaction,and using a script incorporating the ephemeral private key (eSk). XII- Search in the blockchain by the search submodule of the recipient's application or application server for the transaction created by the gateway, retrieval of the ephemeral private key (eSk) and, optionally, recording of said ephemeral private key (eSk) by the read / write submodule in the machine-readable media of the recipient's application or application server. XIII- The decryption submodule of the recipient's application or application server decrypts the message (Em) using the ephemeral private key (eSk) retrieved by the search submodule.
[0041] The communication method according to the invention has the advantage of allowing the transfer of a message from a node to a recipient, in a distributed network, via a gateway which does not share the same owner with the recipient and / or the node, while guaranteeing the security and confidentiality of the message, the ephemeral private key being known only to the gateway and the node involved in the communication, the use of blockchain characteristics increasing the security of the communication.
[0042] According to a particular embodiment of the invention, step XI of the method further includes a verification by the search sub-module of the fourth blockchain management module of the gateway that said transaction contains a financial value, and optionally a measurement of said financial value, the transaction being stopped by the sub-module if the verification fails or if the financial value contained in the transaction is less than a value previously negotiated between the gateway and the node.
[0043] This encourages recipients to offer financial value, which must also be sufficient, and encourages gateways to offer their services for data transfer in exchange for a reward.
[0044] According to a particular embodiment of the invention, step V further comprises a first encryption of the message (m) is carried out by the encryption sub-module of the generator module (N5) of the node using a symmetric key (K) shared with an application or application server of the recipient to obtain the encrypted message Ek(m), before the encryption using the ephemeral public key (ePk) is carried out, to obtain the double encrypted message (Em). The decryption of the double encrypted message (Em) by the decryption sub-module of the application or application server of the recipient in step XIII is then carried out using the ephemeral private key (eSk) and then the symmetric key (K).
[0045] Thus, the message can only be fully decrypted using a key (K) known only to the node and the recipient. The message is then encrypted with this key on the node and decrypted on the recipient's side. This step is necessary if data confidentiality is required. Since the gateway does not possess the key, it will be unable to decrypt the message, and confidentiality is maintained during the exchange with a foreign entity, such as a gateway that does not share the same owner as the node and the recipient.
[0046] In a particular non-limiting embodiment, the verification script used in step X includes a verification that the ephemeral private key (eSk) given by the gateway is the one that corresponds to the ephemeral public key (ePk) of the transaction and an unlocking of the transaction after a certain time.
[0047] This communication method guarantees the following properties: Data integrity, data authenticity, correct payment to the gateway if the recipient receives the data, and receipt of the data by the recipient in case of payment.
[0048] Furthermore, if the message (m) is double encrypted, using the symmetric key (K) data confidentiality is ensured.
[0049] This exchange protocol requires a specific transaction type to resist attacks. Since the funds in step X are locked until the correct private key is provided, it may be necessary for the transaction to also be time-locked. This allows the funds in a transaction to be locked for a specified number of blocks. The recipient can then specify that the funds remain locked until either 1) the associated private key is revealed or 2) a specified period of time has elapsed.
[0050] The blockchain validation system can be proof of work, proof of stake, or any other system for validating a blockchain database. BRIEF DESCRIPTION OF THE FIGURES
[0051] Other features and advantages of the present invention will become clearer upon reading the following description, made with reference to the accompanying drawings, in which: [ Figure 1 ] there figure 1 represents a simplified schematic view of the communication system, between a gateway, a recipient and a node of a connected object, via the radio network, symbolized by arrows, and the terrestrial network (Internet), symbolized by the symbol 5. Figure 2 ] there figure 2 is a simplified schematic view representing the different stages of the communication method (sequence of different exchanges)
[0052] The systems shown in some of the figures can be provided in various configurations. In some embodiments, the systems can be configured as a distributed system in which one or more system components are distributed across one or more networks in a cloud computing system. DETAILED DESCRIPTION OF THE DIFFERENT MODES OF IMPLEMENTATION OF THE INVENTION
[0053] In the following description, specific details are presented for explanatory purposes to allow for a thorough understanding of the embodiments of the invention. However, it will be evident that various embodiments can be implemented without these specific details. The figures and description are not intended to be restrictive.
[0054] Specific details are given in the following description to enable a thorough understanding of the embodiments. However, those skilled in the art will understand that the embodiments can be implemented without these specific details. For example, circuits, systems, networks, processes, and other components can be represented as components in a diagram so as not to unnecessarily obscure the embodiments. In other cases, well-known circuits, processes, algorithms, structures, and techniques can be represented without unnecessary detail to avoid obscuring the embodiments.
[0055] In a particular embodiment of the invention, a simplified example of which is illustrated in the figure 1, a connected object (D) can communicate with a recipient (7) via a foreign gateway (3). Thus, the gateway (3) allows a message (m) to pass from a node (1) to an application or application server of a recipient (7), the gateway 3 acting as a relay between the node (1) and the recipient (7), communicating with them respectively by radio network, by wireless link (2), preferably by the LoRaWAN network, and by Internet network with an IP link (6).
[0056] In other words, the sensor of a connected object (D) directly linked to a node (1) generates data that it must send to a recipient (7). The node (1) is not within radio range of the recipient (7). To send its data, it will use an intermediary, a gateway (3) via a wireless or radio link (2). The gateway (3) is connected via an IP link (4) to the Internet (5), as is the recipient (7), which is also connected via an IP link (6) to the Internet (5). The blockchain database is not shown here and is accessible by the gateway (3) and the recipient (7) via an IP link.
[0057] We understand that the connected object is associated with a sensor, a probe or any other technical means configured to generate data to be transmitted to a recipient.
[0058] The telecommunications network according to the invention is distributed and reliable, while ensuring non-abusive use of the network, through the use of blockchain characteristics.
[0059] This goal is achieved through a specific architecture based on the LoRaWAN network. This network is characterized by the fact that it relies on the users themselves to function, and trust and proper use of the network are ensured through a blockchain.
[0060] In the network according to the invention, which could be called BcWAN (Blockchain Wide Area Network), each user can decide to deploy one or more gateway(s) which allow objects of that user or other users to transmit data over the Internet.
[0061] For example, a person has deployed a gateway in their home connected to their internet router. They have also fitted their dog with a GPS collar and a BcWAN connection. When the dog is near its owner's house, its location is sent directly to the BcWAN gateway via radio. If the dog escapes and goes out of range of its owner's gateway, its location can be relayed through another user's gateway. For example, when the other user's gateway detects the collar's node, it will generate a unique private and public ephemeral key pair and send the public ephemeral key to the collar's node, allowing it to begin data transfer over the BcWAN network whenever it wants.
[0062] Just like the LoRaWan network, the network according to the invention can be used in the management of tools for tracking and monitoring (airports, parking lots, construction sites, warehouses, retail outlets), optimization of energy management, land planning, tracking of pallets, transport containers; "smart" cities with smart meters, detectors for parking lots, control of street lighting, waste management; or "smart" buildings and houses that can detect water leaks, control rodent or termite traps, and all smart home sensors.
[0063] The network according to the invention is a decentralized platform that allows different parties to access their nodes and collect data through external gateways (which the parties do not own), while maintaining confidentiality and security standards.
[0064] Instead of a single actor deploying the network, a blockchain-based architecture manages access to network control and allows gateways to communicate directly across a peer-to-peer network. A node belonging to a recipient can send data to the recipient via a foreign gateway, whereas: The gateway and the recipient may not trust each other, data confidentiality must be ensured, gateways should not be able to receive more data than is necessary for participation in the network, and the gateway may be rewarded for the data transfer carried out.
[0065] Memory refers to all types of machine-readable storage media. Machine-readable storage media, also known as computer-readable storage media, includes but is not limited to portable and non-portable storage devices, optical storage devices, and various other media capable of storing, containing, or supporting instructions and / or data, as well as any medium that participates in providing instructions to a processor for execution. Machine-readable media may include non-transient media on which data can be stored, but does not include carrier waves and / or transient electronic signals propagating wirelessly or through wired connections. Non-volatile media include, for example, optical and magnetic disks, or read-only memories. Volatile media include dynamic memory, including cache memory.Transmission media include coaxial cables, copper wires, and optical fibers. Common forms of computer-readable media include, but are not limited to, floppy disks, flex disks, hard drives, magnetic tape, other magnetic media, CD-ROMs, DVDs, other optical media, punched cards, other physical media with hole patterns, RAM, PROM and EPROM, FLASH-EPROM, other memory chips or cartridges, carrier waves, or any other medium from which a computer can read. Various forms of computer-readable media can be involved in carrying one or more sequences of one or more instructions to a processor for execution.
[0066] A computer program product can include code and / or instructions executable by a machine that may represent a procedure, function, subroutine, program, routine, module, software, class, or any combination of instructions, data structures, or program statements. A segment of code can be coupled to another segment of code or to a hardware circuit by transmitting and / or receiving information, data, arguments, parameters, or memory contents. Information, arguments, parameters, data, etc., can be transmitted, forwarded, or sent by any appropriate means, including memory sharing, message passing, token passing, network passing, etc.
[0067] Several functional units described herein have been named modules to emphasize their independent execution. For example, a module can be implemented by an electronic circuit, such as an integrated circuit, or by other types of component arrangements, such as semiconductors, logic gates, transistors, or other discrete components. Such modules can also be implemented by one or more software applications or portions of executable code within at least one software environment, for execution by various types of processors, regardless of the programming language used. An identified module of executable code can, for example, comprise one or more physical or logical blocks of machine instructions, which can be organized into objects, processes, or functions.Furthermore, the routines and instructions of an identified module need not be physically located together, but may include disparate instructions stored in different locations which, when functionally and logically brought together, form the module and achieve the stated purpose of the module.
[0068] Indeed, a module can be a single instruction of executable code, or a plurality of instructions, and can even be distributed across several different code segments or programs and stored in multiple memory blocks. Similarly, operational data can be identified and represented in modules, and can be incorporated in any suitable form and organized into any suitable type of data structure. Operational data can be collected or distributed across different locations, including various finite storage devices, and can exist, at least partially, simply as electronic signals on a system or network. Different modules can thus compose grouped modules, or even a single module.
[0069] Furthermore, embodiments can be implemented through hardware, software, firmware, middleware, microcode, hardware description languages, or any combination thereof. When implemented in software, firmware, middleware, or microcode, the program code or code segments required to perform the necessary tasks (e.g., a computer program product) can be stored on machine-readable media. A processor can then perform the necessary tasks.
[0070] The term "hardware component" means any hardware component and any combination of electronic components that enables the performance of a task, such as one or more devices, processors, or processing devices that can be configured to execute the function(s) of each of the elements and modules of the structural arrangement described herein. For example, the device(s), processor(s), or processing device(s) can be configured to execute one or more sequences of one or more machine-executable instructions contained in main memory in order to implement the process(es) or function(s) described in this application. Execution of the instruction sequences contained in main memory causes the processors to execute at least some of the steps of the process or functions of the elements described herein.One or more processors in a multiprocessor arrangement can also be used to execute instruction sequences contained in main memory or a memory-readable computer. In variant embodiments, hardwired circuits can be used instead of, or in combination with, software instructions. Thus, the embodiments are not limited to any specific combination of hardware and software circuits.
[0071] The term "blockchain" refers to a technology for storing and transmitting information that is transparent, secure, and operates without a central controlling authority. By extension, a blockchain constitutes a database containing the history of all transactions made between its users since its creation. This database is secure and distributed: it is shared by its various users without intermediaries, allowing each user to verify the validity of the chain.
[0072] Each blockchain transaction has inputs and outputs; this is the medium of exchange for the cryptocurrency. For a transaction's output to be "spent," it is added to the input of a new transaction. The new transaction must validate the script linked to the previous transaction. The script is a series of instructions that allows control over the use of the transaction's outputs. The basic script of the Bitcoin blockchain is called pay-to-public hashing. It controls who will receive the outputs.
[0073] A "blockchain address" is a unique identifier that designates the destination of a transaction. The entity to which the blockchain address belongs will create a blockchain transaction for this destination. This transaction will then be retrieved from the blockchain database using this identifier.
[0074] The goal of BcWAN is to create a shared LoRaWAN infrastructure that allows different parties to deploy and use the network without relying on a single network operator or having to deploy the entire network themselves. The key idea behind BcWAN is that it doesn't depend on a trusted third party, which can be difficult to define in such a situation. In fact, BcWAN requires no centralized server or trusted third party, unless one considers a blockchain as such. To prevent abuse on the network, BcWAN relies on cryptocurrencies and microtransactions.
[0075] The term "WAN" refers to a wide area network, which includes at least a wired transmission / link component, but may also include a wireless transmission / link component.
[0076] The radio network (wireless link) through which the node or object and the gateway communicate is a medium-distance network, whose data flow is generally more limited than a long-distance network like the Internet.
[0077] A long-distance network is defined as a wired and / or wireless network that allows data to be transferred over a long distance, such as the Internet. It is understood that data transmitted over the Internet can use protocols such as TCP / IP or UDP / IP.
[0078] The term "node or object" refers to a communication device that can be the node of a smart object, or the object itself capable of communication. Therefore, unless explicitly stated otherwise, when referring to a node, we mean either a node or an object.
[0079] This architecture can include a financial reward in exchange for message delivery. Thus, each time a network participant sends a message through one of its nodes, they must pay for the message delivery. When a participant forwards a message through one of its gateways, they receive some cryptocurrency as a reward for processing the message.
[0080] The invention proposes a LoRa-based network architecture that enables data transmission through third parties without requiring a trusted intermediary. This is particularly advantageous because it allows parties with a shared objective to deploy a common network securely and fairly while adhering to security standards. Rules are enforced via a blockchain to ensure fair exchanges within the federated network. Parties not participating in the network cannot benefit from the goods exchanged within it.
[0081] The invention also offers a new way for parties to exchange data securely in a potentially malicious environment without needing a trusted third party.
[0082] Such an exchange is based on the principle of "fair exchange" between the party sending the data to be paid to the transmitter, usually a gateway, and the transmitter who wishes to receive the cryptocurrency in exchange for sending the data. This principle must be respected for the exchange to function.
[0083] The invention addresses this problem by ensuring that payment is made if and only if the data is sent to the recipient via the gateway, using the functionalities provided by Blockchain scripts, also known as smart contracts.
[0084] A first aspect of the invention thus relates to a gateway (3) for communicating via a radio network (2) with at least one node or object (1) and via a wired network (4, 6) with at least one application or at least one application server of a recipient (7) and a data storage device constituting at least one blockchain database (8) storing blockchain transactions, the gateway (3) being characterized in that it comprises several code modules executable on one or more hardware processing components such as a microprocessor to constitute a machine, the modules being stored in at least one machine-readable medium, of which at least: A second transmitter module (P2) which, by executing at least one code on a hardware component, sends data over the radio network to a node (1) communicating with at least one connected object (D), data stored in at least one medium readable by the gateway machine, the data including at least one ephemeral public key (ePk) complementary to an ephemeral private key (eSk), A third receiver module (P3) which includes a plurality of codes executed on a hardware component, to receive data from a node or object (1) of the radio network (2), the data including: a signature (Sig), an encrypted message (Em), and a blockchain address of the application or application server of a recipient (@R) linked to a blockchain transaction created by the application or application server of the recipient (7) including an IP address of the application or application server of the recipient (7), The third module (P3) includes a search sub-model which, by executing code on a hardware component, searches for a transaction at the blockchain address of the recipient's application or application server (@R) and retrieves said IP address of the recipient's application or application server (7) contained in the transaction, and a sender sub-module (6) which, by executing code on a hardware component, triggers the transmission via IP protocol (4) to the IP address of the recipient's application or application server (7) of at least: the encrypted message (Em), the signature (Sig), the ephemeral public key (ePk), and the blockchain address of the gateway (3). A fourth blockchain management module (P4) includes: at least one search sub-module which, by executing code on a hardware component,searches for a transaction or blockchain transaction data (8) created by the recipient (7) in the database (8) storing blockchain transactions and which includes or results from a specific ephemeral public key (ePk) script, said search beginning when the encrypted message, the ephemeral public key, and the signature are sent to the recipient (7), and; a transaction creation sub-module which, by executing code on a hardware component, creates a new blockchain transaction destined for the gateway (3) itself using a script incorporating the ephemeral private key (eSk) to validate the script of the blockchain transaction (8) created by the recipient (7), said new transaction, once validated, includes the key (eSk) to allow decryption of the encrypted message (Em), said creation beginning when said blockchain transaction created by the recipient has been found.
[0085] According to a non-limiting embodiment that can be combined with other embodiments, the event triggering the generation and / or sending of the ephemeral private and public keys (eSk, ePk) by a first generator module (P1) of the gateway and / or the second sender module (P2) of the gateway (3) can be at least one event chosen from the following list: the reception by wireless technology (2) of a request for the ephemeral public key (ePk) from at least one node (1) communicating with at least one connected object (D), the periodic transmission, by a transmission module of the gateway, optionally the second module of the gateway (3), of a signaling message containing the ephemeral public key (ePk), or one of their combinations.
[0086] According to a non-limiting embodiment and combinable with other embodiments, the node includes a transmitter module (N1) which, by executing code on a hardware component, sends an information request including at least the ephemeral public key (ePk), to the gateway (3).
[0087] According to another non-limiting embodiment which can be combined with other embodiments, the private and public keys are already generated and stored in one or more media readable respectively by the gateway and the node, the generation of said keys by the gateway is then not necessary, and the gateway does not then include a first generator module to generate said keys.
[0088] According to another non-limiting embodiment and combinable with other embodiments, the fourth blockchain management module (P4) further includes a verification sub-module which, by executing codes associated with a hardware component, verifies by means of the ephemeral private key (eSk) that said transaction contains a financial value, and optionally measures said financial value, the verification sub-module being further configured to stop the transaction if the verification fails or if the financial value contained in the transaction is less than a value previously negotiated between the gateway (3) and the node (1) and stored in a medium readable by the gateway (3).
[0089] According to another aspect of the invention, the gateway can be used with a node (1) communicating with at least one connected object (D), or directly with an object (1), the node or object (1) comprising at least one or more code modules executable on one or more hardware processing components such as a microprocessor to constitute a machine, the modules being stored in at least one machine-readable medium, and at least: A machine-readable medium constituting a memory space including a private key (Sk) and a blockchain address of the recipient (@R) transmitted by an application or application server of the recipient (7) to the node (1); A receiver module (N2) which, by executing code on a hardware component, receives the ephemeral public key (ePk) sent by the gateway (3) and forwarded; A generator module (N5) which, by executing code on a hardware component, generates a message (m) in response to data from a connected object (D), said module comprising an encryption sub-module which, by means of the ephemeral public key (ePk) sent by the gateway (3), encrypts this message to obtain the ciphertext (Em), the encryption sub-module also performing a signature, the signature (Sig) being the encryption, of a hash of the ciphertext message and of the ephemeral public key (ePk) received from the gateway, by means of the private key (Sk) contained in the memory space of the node (1), the generator module (N5) also comprising a transmitter sub-module which sends the signature (Sig), the ciphertext (Em) and the blockchain address (@R) of the recipient to the gateway (3) via the radio network (2).
[0090] In one embodiment, certain modules used by the node and / or gateway can be distributed across the network, such as the readable media.
[0091] According to one embodiment, the encryption submodule first encrypts the message (m) generated by the generator module (N5) using a symmetric key (K) shared with an application or application server of the recipient (7) to obtain the encrypted message Ek(m) before the encryption submodule encrypts the message using the ephemeral public key (ePk) sent by the gateway (3), to obtain the double-encrypted message (Em).
[0092] According to one embodiment, the gateway (3) is used, with the node (1) of a connected object, and an application or application server of the recipient (7), the application or server comprising at least one or more code modules executable on one or more processing hardware components such as a microprocessor to constitute a machine, the modules being stored in at least one machine-readable medium, of which at least: A generation module (D1) which, by executing code on a hardware component, (13) generates and sends the private key (Sk) and optionally the symmetric key (K) to the node (1) communicating with at least one connected object; A machine-readable medium constituting a memory space comprising a public key (Pk) complementary to the private key (Sk) transmitted to the node (1);A first transaction module (D2) which, by executing code on a hardware component, creates a blockchain transaction at the blockchain address of the recipient's application or application server (@R) (7), said blockchain transaction including the IP address of the recipient's application or application server;A receiver module (D3) which, by executing code on a hardware component, receives from the gateway (3), via a long-distance network, for example the Internet (4,6), the data including the encrypted message (Em), the signature (Sig) and the ephemeral public key (ePk) sent by the gateway, and upon receiving said data, launches a signature verification sub-module (Sig) which verifies by means of a signature calculation using the private key (Sk) stored in memory space by comparing the result of the calculation with the received signature (Sig) that the received signature (Sig) was indeed generated by the node (1) communicating with at least the connected object (D), the module (D3) stopping the transaction if this verification fails;A transaction module (D4), optionally the first transaction module (D2), which, by executing code on a hardware component, creates a blockchain transaction at the recipient's blockchain address (@R) once the verification sub-module has performed message verification, the transaction including at least one specific script, using the ephemeral public key (ePk) sent by the gateway; The transaction module (D4) including a search sub-module (11) which, once the encrypted message (Em), the ephemeral public key (ePk), and the signature (Sig) are received, or the transaction created by the recipient, searches for a blockchain transaction incorporating the gateway's blockchain address and a signing script using the ephemeral private key (eSk);The transaction module (D4) comprising a decryption sub-module which, once the blockchain transaction is found, uses the ephemeral private key (eSk) of said transaction to decrypt the encrypted message from the node received from the gateway by the receiving module, and preferably also by means of the symmetric key (K) shared with the node. The transaction module (D4) optionally also comprising a read / write sub-module and a memory space in which the read / write sub-module stores data and which, once the blockchain transaction is found, stores the ephemeral private key (eSk) of said transaction.
[0093] The node (1), the recipient's application or application server (7), and at least one gateway, form a communication system (10) allowing at least one transfer of a message from a node to a recipient, via a gateway which does not necessarily share the same owner with the recipient and / or the node, while guaranteeing the security and confidentiality of the message, the ephemeral private key being known only to the gateway and the node, both actors in the communication.
[0094] It is understood that when sending data, such as an encryption key, the node and / or gateway may send other data in addition to the data explicitly described. Thus, in a non-exhaustive example, the node and / or gateway send additional data concerning the transaction, its cost, and its reputation.
[0095] According to a combinable embodiment, in addition to the gateway sending the data necessary for communication, said gateway can send other data concerning itself or concerning the data transfer.
[0096] According to one embodiment, in the communication system (10), the transaction module (D4, D2) of the recipient (7) unlocks the transaction created by said module (D4, D2) after a certain period, if the gateway (3) has not unlocked the transaction during this period.
[0097] According to one embodiment, in the communication system (10), the node (1) uses RSA-512 encryption to perform its data signature.
[0098] According to one embodiment, in the communication system (10), the fourth blockchain management module (P4) of the gateway (3) includes a time measurement sub-module associated with an instruction to wait for a confirmation time after receiving a blockchain transaction from the recipient, preferably at least before receiving the transaction requiring the provision of the ephemeral secret key (eSk).
[0099] According to one embodiment, the gateway (3) further includes a first generator module (P1) which includes at least one code executed on a hardware component, to generate the ephemeral private key (eSk) and the ephemeral public key (ePk) complementary to said ephemeral private key (eSk), preferably in response to a triggering event, and stores these keys (ePk, eSk) in a machine-readable medium.
[0100] According to another non-limiting embodiment, which can be combined with other embodiments, the invention also relates to a communication method as illustrated by way of example in the figure 2 to implement the following steps: I. The recipient (7) generates a public key (Pk) and a private key (Sk) complementary to the public key (Pk), and optionally a symmetric key (K). The recipient (7) shares the private key (Sk) and optionally the symmetric key (K) with the node. The public (Pk) and private (Sk) keys are for single use only. II. The recipient (7) creates a blockchain transaction at the blockchain address (@R) of the recipient's (7) application or application server, containing the IP address of the recipient's (7) application or application server. III. The gateway (3) generates an ephemeral public key (ePk) and an ephemeral private key (eSk) complementary to the ephemeral public key (ePk). This pair will be used only for this message. The gateway (3) sends the ephemeral public key (ePk) to the node (1) using the radio network to the receiver module (N2) of node (1).The transmission occurs either because node (1) requests it, or in advance when gateway (3) discovers node (1)'s neighborhood, or because gateway (3) regularly broadcasts this key to its surroundings in a signaling message. IV. The node's generator module (N5) generates a message (m) in response to data from a connected object (D). The node encrypts the message (Em) using the ephemeral public key (ePk). The encryption can be simple (encrypted only by ePk) or double (encrypted by K then ePk). The node signs the encryption result (Em) and the ephemeral public key (ePk) using its own private key (Sk). The signature is called the Sig. V. Node (1) sends the encrypted message (Em), the signature (Sig), and the recipient's address (@R) to the gateway using the radio network. VI.The gateway (3) finds the recipient's IP address in the blockchain at the recipient's address (@R) and records it. VII. The gateway (3) sends the encrypted message (Em), the ephemeral public key (ePk), and the signature (Sig) to the recipient (7) via their IP address using the Internet (IP). VIII. The recipient (7) verifies the message's authenticity using the signature (Sig) and their public key (Pk), which is complementary to the private key (Sk) used by the node for the signature. IX. The recipient (7) creates a transaction in the blockchain with a given output (fixed or negotiated with the gateway) and a specific script. The script requires the ephemeral private key (eSk) associated with the ephemeral public key (ePk) to unlock the amount provided in the transaction. X. The gateway (3) searches for this transaction in the blockchain at the recipient's blockchain address (@R). XI.Once the recipient's transaction (7) is found, the gateway (3) creates a new transaction using the outputs of the previous transaction as input. In this transaction, it provides the ephemeral private key (eSk) to validate the script of the previous transaction. The transaction is destined for the gateway itself. XII. The recipient (7) can consult the transaction list to find the gateway's (3) transaction and retrieve the ephemeral private key (eSk) in order to decrypt the message (Em) using the ephemeral private key (eSk) and optionally the symmetric key (K). XIII. The recipient (7) decrypts said message (Em).
[0101] In a non-limiting embodiment of the invention, a communication system (10) is composed of at least one node or object (1), a gateway (3) and a receiver (7), exchanging information with each other and via a blockchain (8) as illustrated by way of example in the figure 2 . This communication system (10) thus includes the node (1), the gateway (3) and the recipient (7), having their own characteristics, the list of which is described above, the characteristics of each embodiment being combinable with each other.
[0102] In one embodiment that guarantees data confidentiality, the node (1) and the recipient (7) share a symmetric key (K). The message (m) can be encrypted with this symmetric key (K) on the node (1) and decrypted on the recipient's side (7). This step is necessary if data confidentiality is required.
[0103] In another embodiment, guaranteeing the integrity and primarily the authenticity of the data, node (1) also signs the message (possibly encrypted) (Em) and the ephemeral public key (ePk) with a secret key (Ska). Node (1) and the recipient (7) must also share a secret key (Sk) on node (1) and a public key (Pk) on the recipient. A phase where the recipient (7) and node (1) can communicate directly with each other is therefore necessary to load the required keys onto node (1). Once node (1) is out of range of the recipient (7), it will use a foreign gateway (3) as a relay and will use the secret key (Sk) and symmetric key (K) to communicate securely and confidentially with the recipient (7).
[0104] In a non-limiting embodiment, the recipient's (7) transaction module (D4, D2) unlocks the transaction created by said module (D4, D2) after a certain time if the gateway (3) has not unlocked the transaction within that time. For Bitcoin, the OP_CHECKLOCKTIMEVERIFY script operator was introduced to handle time-locked issues. This operator allows the transaction to be locked until the correct ephemeral private key (eSk) is provided or until a certain time has elapsed, after which the transaction creator, here the recipient (7), can retrieve the transaction contents, in the event that the ephemeral private key (eSk) is not provided in time. The OP_CHECKRSA512PAIR script operator was also introduced to verify that the ephemeral private key (eSk) provided by the gateway corresponds to the ephemeral public key (ePk) of the transaction.Other script operators having the same function may substitute the above operators indifferently in the embodiments set forth in this application.
[0105] In a non-limiting embodiment, the verification script used in step X includes a check of the ephemeral private key (eSk) provided by the gateway to ensure it corresponds to the ephemeral public key (ePk) of the transaction, and an unlocking of the transaction after a certain time. This allows the holder of the ephemeral private key (eSk) associated with the ephemeral public key (ePk) specified in the transaction to use the transaction's outputs. The script also allows the transaction's creator to retrieve the outputs after a defined time. Indeed, if the gateway fails, the outputs are not discarded but are retrieved by the transaction's creator. This also incentivizes the gateway to reveal the eSk quickly to ensure it does not lose its gains.
[0106] The verification script is as follows: 1 <rsapubkey>< / rsapubkey> 2 < <rsaprivkey> >< / rsaprivkey> 3 OP_CHECKRSA512PAIR 4 OP_IF 5 < <sig> > < <pubkey> >< / pubkey> < / sig> 6 OP_DUP 7 OP_HASH160 8 <pubkeyhash>< / pubkeyhash> 9 OP_EQUALVERIFY 10 OP_ELSE 11 <block_height+100> 12 OP_CHECKLOCKTIMEVERIFY 13 OP_DROP 14 < <sig> > < <buyerpubkey>< / buyerpubkey> < / sig> 15 OP_DUP 16 OP_HASH160 17 <buyerpubkeyhash>< / buyerpubkeyhash> 18 OP_EQUALVERIFY 19 OP_ENDIF 20 OP_CHECKSIG
[0107] The script execution is detailed in Tables 1 and 2 under two different scenarios. The case where the provided ephemeral secret (eSk) matches the ephemeral public key (ePk) is described in an example illustrated by Table 1, while the case where the ephemeral secret (eSk) does not match but the time allotted to claim the transaction has expired is described in an example illustrated by Table 2.
[0108] The Stack column shows the stack status as the script executes. The Script column shows the remaining portion of the script to be executed. Finally, the Description column provides a description of the current step.
[0109] The data between angle brackets: <exemple>are provided without the transaction whose output is used. Data between double angle brackets: < <exemple>> are provided in the transaction that spends an output from the first transaction. [Table 1] Pile Script Description Empty <rsapubkey> < <rsaprivkey> > OP_CHECKRSA512PAIR OP_IF< / rsaprivkey> < / rsapubkey> The data provided is combined with the script. < <sig> > < <pubkey>> OP_DUP OP_HASH160 <pubkeyhash>< / pubkeyhash> < / pubkey> < / sig> OP_EQUALVERIFY OP_ELSE<block_height+100> OP_CHECKLOCKTIMEVERIFY OP_DROP < <sig> >< / sig> < <buyerpubkey>> OP_DUP OP_HASH160 <buyerpubkeyhash>< / buyerpubkeyhash> < / buyerpubkey> OP_EQUALVERIFY OP_ENDIF OP_CHECKSIG <rsapubkey>< / rsapubkey> OP_CHECKRSA512PAIR OP_IF <sig> <pubkey> OP_DUP< / pubkey> < / sig> The constants are added on the stack. < <rsaprivkey> >< / rsaprivkey> OP_HASH160 <pubkeyhash> OP_EQUALVERIFY OP_ELSE< / pubkeyhash> <block_height+100> OP_CHECKLOCKTIMEVERIFY OP_DROP <sig> <buyerpubkey> OP_DUP OP_HASH160< / buyerpubkey> < / sig> <buyerpubkeyhash> OP_EQUALVERIFY OP_ENDIF< / buyerpubkeyhash> OP_CHECKSIG True OP_IF <sig> <pubkey>OP_DUP OP_HASH160 <pubkeyhash>< / pubkeyhash> < / pubkey> < / sig> OP_CHECKRSA512PAIR verifies that the private key at the top of the stack is the one that corresponds to the public key in 2 e< element on the stack. OP_EQUALVERIFY OP_ELSE<block_height+100> OP_CHECKLOCKTIMEVERIFY OP_DROP <sig> <buyerpubkey>< / buyerpubkey> < / sig> OP_DUP OP_HASH160 <buyerpubkeyhash>< / buyerpubkeyhash> OP_EQUALVERIFY OP_ENDIF OP_CHECKSIG Empty <sig> <pubkey>OP_DUP OP_HASH160 <pubkeyhash>< / pubkeyhash> < / pubkey> < / sig> OP_IF checks if the element at the top of the stack is not false If applicable, the next OP_ELSE instruction and all subsequent instructions up to and including OP_ENDIF are ignored. OP_EQUALVERIFY OP_CHECKSIG <sig> <pubkey>< / pubkey> < / sig> OP_DUP OP_HASH160 <pubkeyhash> OP_EQUALVERIFY< / pubkeyhash> The remaining set of instructions is similar to the pay-to-pubkey-hash classic. OP_CHECKSIG [Table 2] Pile Script Description Empty <rsapubkey> <rsaprivkey> OP_CHECKRSA512PAIR OP_IF< / rsaprivkey> < / rsapubkey> The data provided is combined with the script. <sig> <pubkey>OP_DUP OP_HASH160 <pubkeyhash>< / pubkeyhash> < / pubkey> < / sig> OP_EQUALVERIFY OP_ELSE<block_height+100> OP_CHECKLOCKTIMEVERIFY OP_DROP <sig>< / sig> <buyerpubkey>OP_DUP OP_HASH160 <buyerpubkeyhash>< / buyerpubkeyhash> < / buyerpubkey> OP_EQUALVERIFY OP_ENDIF OP_CHECKSIG <rsapubkey> <rsaprivkey>< / rsaprivkey> < / rsapubkey> OP_CHECKRSA512PAIR OP_IF <sig> <pubkey> OP_DUP< / pubkey> < / sig> The constants are added on the stack. OP_HASH160 <pubkeyhash> OP_EQUALVERIFY OP_ELSE< / pubkeyhash> <block_height+100> OP_CHECKLOCKTIMEVERIFY OP_DROP <sig> <buyerpubkey> OP_DUP OP_HASH160< / buyerpubkey> < / sig> <buyerpubkeyhash> OP_EQUALVERIFY OP_ENDIF< / buyerpubkeyhash> OP_CHECKSIG False OP_IF <sig> <pubkey>OP_DUP OP_HASH160 <pubkeyhash>< / pubkeyhash> < / pubkey> < / sig> OP_CHECKRSA512PAIR verifies that the private key at the top of the stack is the one that corresponds to the public key in 2 e< element on the stack. OP_EQUALVERIFY OP_ELSE<block_height+100> OP_CHECKLOCKTIMEVERIFY OP_DROP <sig>< / sig> <buyerpubkey>OP_DUP OP_HASH160 <buyerpubkeyhash>< / buyerpubkeyhash> < / buyerpubkey> OP_EQUALVERIFY OP_ENDIF OP_CHECKSIG Empty <block_height+100> OP_CHECKLOCKTIMEVERIFY OP_DROP OP_IF checks if the element at the top of the stack is false If necessary, subsequent instructions up to and including OP_ELSE are ignored. The next OP_ENDIF instruction will also be ignored. <sig> <buyerpubkey> OP_DUP OP_HASH160< / buyerpubkey> < / sig> <buyerpubkeyhash> OP_EQUALVERIFY OP_CHECKSIG< / buyerpubkeyhash> <block_height+100> OP_CHECKLOCKTIMEVERIFY OP_DROP <sig>< / sig> The constant is added to the stack. <buyerpubkey>OP_DUP <sig> <buyerpubkey> OP_HASH160< / buyerpubkey> < / sig> < / buyerpubkey> <buyerpubkeyhash> OP_EQUALVERIFY OP_CHECKSIG< / buyerpubkeyhash> <block _height+100> ON_DROP <sig> <buyerpubkey> OP_DUP OP_HASH160< / buyerpubkey> < / sig> OP_CHECKLOCKTIMEVERIFY invalidates the transaction if the current block is less than the value on the stack. <buyerpubkeyhash> OP_EQUALVERIFY OP_CHECKSIG< / buyerpubkeyhash> <block _height+100> say> <buyerpubkey> OP_DUP OP_HASH160< / buyerpubkey> OP_DROP removes the first element from the stack. <buyerpubkeyhash> OP_EQUALVERIFY OP_CHECKSIG< / buyerpubkeyhash> <sig> <buyerpubkey>< / buyerpubkey> < / sig> OP_DUP OP_HASH160 <buyerpubkeyhash>< / buyerpubkeyhash> The remaining set of instructions is similar to the pay-to-pubkey-hash classic but intended for the creator of the initial transaction. OP_EQUALVERIFY OP_CHECKSIG
[0110] Furthermore, it is noted that individual implementations can be described as a process, which is represented by a flowchart, data flowchart, structure diagram, or block diagram. While a flowchart can depict operations as a sequential process, many operations can be performed in parallel or simultaneously. Moreover, the order of operations can be rearranged. A process is considered complete when its operations are finished, but additional steps may not be included in the diagram. A process can be represented by a method, function, procedure, subchain, subroutine, and so on. When a process is represented by a function, its termination can be defined as a return of the function to the calling function or the main function. This is particularly relevant for transaction lookup phases in the blockchain database.
[0111] This application describes various technical features and advantages with reference to the figures and / or various embodiments. Those skilled in the art will understand that the technical features of a given embodiment can in fact be combined with features of another embodiment unless the contrary is explicitly stated, or it is obvious that such features are incompatible, or that the combination does not provide a solution to at least one of the technical problems mentioned in this application. Furthermore, the technical features described in a given embodiment can be isolated from the other features of that embodiment unless the contrary is explicitly stated.Also, certain aspects are not detailed in order to avoid obscuring and complicating the present description, and the person skilled in the art will understand that various and varied means may be used and that the invention is not limited to the examples described.
[0112] It should be obvious to those skilled in the art that the present invention allows for embodiments in many other specific forms without departing from the scope of the invention as claimed. Therefore, the present embodiments should be considered illustrative, but may be modified within the scope defined by the attached claims, and the invention should not be limited to the details given above.
[0113] It will be readily understood from reading this application that the components of the present invention, as generally described and illustrated in the figures, can be arranged and designed in a wide variety of different configurations. Thus, the description of the present invention and the accompanying figures are not intended to limit the scope of the invention but merely represent selected embodiments. LIST OF REFERENCE SIGNS
[0114] (1) Node (2) Wireless, radio link (3) Gateway (4) Wired (IP) link (5) Internet (6) Link (IP) (7) Recipient (8) Blockchain database (10) Communication system (P1) First generator module (Gateway) (P2) Second transmitter module (Gateway) (P3) Third receiver module (Gateway) (P4) Fourth blockchain management module (Gateway) (N2) Receiver module (Node) (N5) Generator module (Node) (D1) Generation module (Recipient) (D2) First transaction module (Recipient) (D3) Receiver module (Recipient) (D4) Second transaction module< / exemple> < / exemple>
Claims
1. Device for communication between at least one connected object (D) linked via radio (2) either directly to a node (1) or to at least one gateway (3) communicating via a wired network (4, 6) and at least one application or at least one application server of at least one recipient (7), the device comprising: a gateway (3) comprising a plurality of modules of codes that are executable on one or more processing hardware components such as a microprocessor to form a machine, the modules being stored in at least one machine-readable medium and including at least: a second transmitter module; a third receiver module comprising a transmitter sub-module; a fourth blockchain management module comprising at least a search sub-module and a transaction creation sub-module; a node (1) comprising at least one or more modules of codes that are executable on one or more processing hardware components such as a microprocessor to form a machine, the modules being stored in at least one machine-readable medium and at least: a machine-readable medium; a receiver module; a generator module comprising an encryption sub-module and a transmitter sub-module; an application or application server of the recipient (7) comprising at least one or more modules of codes that are executable on one or more processing hardware components such as a microprocessor to form a machine, the modules being stored in at least one machine-readable medium and including at least: a generation module; a machine-readable medium; a first transaction module; a receiver module comprising a verification sub-module; a transaction module, optionally the first transaction module comprising a search sub-module, a read / write sub-module and a decryption sub-module; the modules perform their actions by executing codes on at least one hardware component; wherein: I- the generation module of the application or application server of the recipient (7), by executing codes on a hardware component, generates a public key, Pk, and saves in a machine-readable medium constituting a memory space, then generates and sends the private key, Sk, which is complementary to the public key, Pk, to the node (1) communicating with the at least one connected object (D), and saves the transmitted private key, Sk, in the readable medium of the node (1) constituting a memory space; II- the transaction module of the application or application server of the recipient (7) creates, by executing codes on a hardware component, at the blockchain address of the application or application server of the recipient, said blockchain transaction comprising the IP address of the application or application server of the recipient (7); III- the second transmitter module of the gateway (3), by executing codes on a hardware component, sends an ephemeral public key, ePk, stored in at least one medium that is readable by the machine of the gateway, over the radio network (2) to the node (1) communicating with the at least one connected object; IV- the receiver module of the node (1), by executing codes on a hardware component, receives the ephemeral public key, ePk, sent by the second transmitter module of the gateway (3); V- the generator module of the node (1), by executing codes on a hardware component, generates a message, m, in response to data from the at least one connected object, and the encryption sub-module of the generator module encrypts the message, m, by means of the ephemeral public key, ePk, by executing codes on a hardware component, in order to obtain the encrypted message, Em, and the encryption sub-module, by executing codes on a hardware component, creates a signature, Sig, which is the encryption, from a hash coding of the encrypted message and the ephemeral public key, ePk, received from the gateway, by means of the private key, Sk, contained on the memory space of the node (1), VI- the transmitter sub-module of the generator module of the node (1), by executing codes on a hardware component, sends the signature, Sig, of the encrypted message, Em, and the blockchain address of the recipient to the gateway (3) via the radio network (2); VII- the third receiver module of the gateway (3), by executing codes on a hardware component, receives the data and the search sub-model of the third receiver module of the gateway searches for a blockchain address of an application or application server of a recipient linked to a blockchain transaction created by the application or application server of the recipient comprising an IP address of the application or application server of the recipient and retrieves said IP address; VIII- the transmitter sub-module of the third gateway module, by executing codes on a hardware component, sends via IP protocol, to the IP address of the application or application server of the recipient (7) at least: the encrypted message, Em, the signature, Sig, the ephemeral public key, ePk, and the blockchain address of the gateway (3); IX- the receiver module of the application or application server of the recipient, by executing codes on a hardware component, receives, via IP protocol, data from the gateway (3) comprising the encrypted message, Em, the signature, Sig, and the ephemeral public key, ePk, and upon receipt of said data a sub-module for verifying the signature, Sig, of the application or application server of the recipient is launched which verifies, by means of a signature calculation using the private key, Sk, saved on the memory space by comparing the result of the calculation with the received signature, Sig, that the received signature, Sig, has indeed been generated by the node (1) communicating with at least the at least one connected object, the transaction being stopped by the module if the verification fails; X- the transaction module of the application or application server of the recipient, optionally the first transaction module, by executing codes on a hardware component, creates a blockchain transaction at the blockchain address of the recipient once the verification sub-module has verified the message, the transaction comprising at least one specific script, using the ephemeral public key, ePk; XI- by executing codes on a hardware component, the search sub-module of the fourth blockchain management module of the gateway searches for a transaction of the blockchain transaction (8) created by the recipient (7) in the database storing blockchain transactions and which comprises or results from a specific script with the ephemeral public key, ePk, once the data has been sent in step VIII, then, once said blockchain transaction created by the recipient (7) has been found, the transaction creation sub-module of the fourth blockchain management module of the gateway creates a new blockchain transaction, using as inputs the outputs of the previous transaction, and using a script incorporating the ephemeral private key, eSk; XII- the search sub-module of the application or application server of the recipient, by executing codes on a hardware component, searches the blockchain for the transaction created by the gateway (3), retrieving the ephemeral private key, eSk, and, optionally, the read / write sub-module saves said ephemeral private key, eSk, in the medium that is readable by the machine of the application or application server of the recipient (7); XIII- the decryption sub-module of the application or application server of the recipient (7), by executing codes on a hardware component, decrypts the message, Em, using the ephemeral private key, eSk, retrieved by the search sub-module.
2. Device according to claim 1, wherein the event triggering the generation and / or sending of ephemeral private and public keys, eSk, ePk, by a first generator module of the gateway and / or the second transmitter module of the gateway (3) can be at least one event selected from the following list: the wireless technology (2) receiving a request for the ephemeral public key, ePk, from the at least one node (1) communicating with the at least one connected object (D), periodic transmission, by a transmission module of the gateway, optionally the second module of the gateway (3), of a signaling message containing the ephemeral public key, ePk, or one of the combinations thereof.
3. Device according to claim 1 or 2, wherein the fourth blockchain management module further comprises a verification sub-module which, by executing codes associated with a hardware component, verifies by means of the ephemeral private key, eSk, that said transaction contains a financial value, and optionally measures said financial value, the verification sub-module being further configured to stop the transaction if the verification fails or if the financial value contained in the transaction is less than a value that is previously negotiated between the gateway (3) and the node (1) and is stored in a medium that is readable by the gateway (3).
4. Communication system (10) comprising a device according to one of claims 1 to 3, and further the node (1) communicating with the at least one connected object (D), the node (1) comprising at least one or more modules of codes that are executable on one or more processing hardware components such as a microprocessor to form a machine, the modules being stored in at least one machine-readable medium, and at least: a machine-readable medium constituting a memory space comprising a private key, Sk, and a blockchain address of the recipient transmitted by an application or application server of the recipient (7) to the node (1); a receiver module which, by executing codes on a hardware component, receives the ephemeral public key, ePk, sent by the gateway (3); a generator module which, by executing codes on a hardware component, generates a message (m) in response to data from the connected object, said module comprising an encryption sub-module which, by means of the ephemeral public key, ePk, sent by the gateway (3), encrypts this message in order to obtain the encrypted message, Em, the encryption sub-module also creates a signature, the signature, Sig, being the encryption, from a hash coding of the encrypted message and the ephemeral public key, ePk, received from the gateway, by means of the private key, Sk, contained on the memory space of the node (1), the generator module also comprises a transmitter sub-module that sends the signature, Sig, the encrypted message, Em, and the blockchain address of the recipient to the gateway (3) via the radio network (2).
5. Communication system (10) according to the preceding claim, wherein the encryption sub-module encrypts the message, m, generated by the generator module a first time by means of a symmetric key, K, shared with the application or application server of the recipient (7) in order to obtain the encrypted message, Ek(m), before the encryption sub-module encrypts the message by means of the ephemeral public key, ePk, sent by the gateway (3), in order to obtain the twice-encrypted message, Em.
6. Communication system (10) according to claim 4 or 5, comprising: the application or application server of the recipient (7), the application or server comprising at least one or more modules of codes that are executable on one or more processing hardware components such as a microprocessor to form a machine, the modules being stored in at least one machine-readable medium and including at least: a generation module which, by executing codes on a hardware component, (13) generates and sends the private key, Sk, and optionally the symmetric key, K, to the node (1) communicating with the at least one connected object; a machine-readable medium constituting a memory space comprising a public key, Pk, which is complementary to the private key, Sk, transmitted to the node (1); a first transaction module which, by executing codes on a hardware component, creates a blockchain transaction at the blockchain address of the application or application server of the recipient (7), said blockchain transaction comprising the IP address of the application or application server of the recipient; a receiver module which, by executing codes on a hardware component, receives from the gateway (3), via a long-distance network, e.g. the Internet (4, 6), the data comprising the encrypted message, Em, the signature, Sig, and the ephemeral public key, ePk, sent by the gateway, and upon receipt of said data, launches a signature verification sub-module, Sig, which verifies by means of a signature calculation using the private key, Sk, saved on the memory space by comparing the result of the calculation with the received signature, Sig, that the received signature, Sig, has indeed been generated by the node (1) communicating with the at least one connected object, the module stopping the transaction if this verification fails; a transaction module, optionally the first transaction module, which, by executing codes on a hardware component, creates a blockchain transaction at the blockchain address of the recipient once the verification sub-module has verified the message, the transaction comprising at least one specific script, using the ephemeral public key, ePk sent by the gateway; the transaction module comprising a search sub-module (11) which, once the encrypted message, Em, the ephemeral public key, ePk, and the signature, Sig, have been received, or the transaction has been created by the recipient, searches for a blockchain transaction incorporating the blockchain address of the gateway and a signature script using the ephemeral private key, eSk; the transaction module comprising a decryption sub-module which, once the blockchain transaction has been found, uses the ephemeral private key, eSk, of said transaction to decrypt the encrypted message of the node received from the gateway by the receiver module, and preferably additionally by means of the symmetric key, K, shared with the node, the transaction module optionally further comprising a read / write sub-module and a memory space in which the read / write sub-module saves data and which, once the blockchain transaction has been found, saves the ephemeral private key, eSk, of said transaction.
7. Communication system (10) according to claim 5 or 6, wherein the transaction module of the recipient (7) unlocks the transaction created by said module after a certain period of time, if the gateway (3) has not unblocked the transaction within this period of time.
8. Communication system (10) according to any one of the preceding claims, wherein the node (1) uses RSA-512 encryption to perform its data signature.
9. Communication system (10) according to any one of the preceding claims, wherein the fourth blockchain management module of the gateway (3) comprises a time measurement sub-module associated with an instruction to wait for a confirmation time after receipt of a blockchain transaction from the recipient (7), preferably at least before receipt of the transaction requiring the ephemeral secret key, eSk to be provided.
10. System (1) according to any one of the preceding claims, wherein the gateway (3) further comprises a first generator module which comprises at least one code executed on a hardware component, for generating the ephemeral private key, eSk, and the ephemeral public key, ePk, which is complementary to said ephemeral private key, eSk, preferably in response to a triggering event, and stores these keys, ePk, eSk, in a machine-readable medium.
11. Method for communication between at least one connected object (D) linked via radio (2) either directly to a node (1) or to at least one gateway (3) communicating via a wired network (4,6) with at least one application or at least one application server of at least one recipient (7), the method comprising: a gateway (3) comprising a plurality of modules of codes that are executable on one or more processing hardware components such as a microprocessor to form a machine, the modules being stored in at least one machine-readable medium and including at least: a second transmitter module; a third receiver module comprising a transmitter sub-module; a fourth blockchain management module comprising at least a search sub-module and a transaction creation sub-module; a node (1) comprising at least one or more modules of codes that are executable on one or more processing hardware components such as a microprocessor to form a machine, the modules being stored in at least one machine-readable medium and at least: a machine-readable medium; a receiver module; a generator module comprising an encryption sub-module and a transmitter sub-module; an application or application server of the recipient (7) comprising at least one or more modules of codes that are executable on one or more processing hardware components such as a microprocessor to form a machine, the modules being stored in at least one machine-readable medium and including at least: a generation module; a machine-readable medium a first transaction module; a receiver module comprising a verification sub-module a transaction module, optionally the first transaction module comprising a search sub-module, a read / write sub-module and a decryption sub-module; the modules perform their actions by executing codes on at least one hardware component; and that the method comprises at least the following steps: I- the generation module of the application or application server of the recipient (7) generating a public key, Pk, and saving in a machine-readable medium constituting a memory space, then generating and sending the private key, Sk, which is complementary to the public key, Pk, to the node (1) communicating with the at least one connected object (D), and saving the transmitted private key, Sk, in readable medium of the node (1) constituting a memory space II- the transaction module of the application or application server of the recipient (7) creating a blockchain transaction at the blockchain address of the application or application server of the recipient, said blockchain transaction comprising the IP address of the application or application server of the recipient (7); III- the second transmitter module of the gateway (3) sending an ephemeral public key, ePk, stored in at least one medium that is readable by the machine of the gateway, over the radio network (2) to the node (1) communicating with the at least one connected object; IV- the receiver module of the node (1) receiving the ephemeral public key, ePk, sent by the second transmitter module of the gateway (3); V- the generator module of the node (1) generating a message, m, in response to data from the at least one connected object, the encryption sub-module of the generator module encrypting the message, m, using the ephemeral public key, ePk, in order to obtain the encrypted message, Em, the encryption sub-module creating a signature, Sig, the signature, Sig, being the encryption, from a hash coding of the encrypted message and the ephemeral public key, ePk, received from the gateway, by means of the private key, Sk, contained on the memory space of the node (1), VI- the transmitter sub-module of the generator module of the node (1) sending the signature, Sig, the encrypted message, Em, and the blockchain address of the recipient to the gateway (3) via the radio network (2); VII- the third receiver module of the gateway (3) receiving data and the search sub-model of the third receiver module of the gateway searching for a blockchain address of an application or application server of the recipient linked to a blockchain transaction created by the application or application server of the recipient comprising an IP address of the application or application server of the recipient and retrieving said IP address, VIII- the transmitter sub-module of the third module of the gateway sending, via IP protocol, to the IP address of the application or application server of the recipient (7) at least: the encrypted message, Em, the signature, Sig, the ephemeral public key, ePk, and the blockchain address of the gateway (3); IX- the receiver module of the application or an application server of the recipient receiving, via IP protocol, data from the gateway (3) comprising the encrypted message, Em, the signature, Sig, and the ephemeral public key, ePk, and upon receipt of said data, launching a sub-module for verifying the signature, Sig, and verifying by means of a signature calculation using the private key, Sk, saved on the memory space by comparing the result of the calculation with the received signature, Sig, that the received signature, Sig, has indeed been generated by the node (1) communicating with the at least one connected object, the transaction being stopped by the module if the verification fails; X- the transaction module of the application or an application server of the recipient, optionally the first transaction module, creating a blockchain transaction at the blockchain address of the recipient, once the verification sub-module has verified the message, the transaction comprising at least one specific script, using the ephemeral public key, ePk; XI- the search sub-module of the fourth blockchain management module of the gateway searching for a transaction of the blockchain transaction (8) created by the recipient (7) in the database storing blockchain transactions and which comprises or results from a specific script with an ephemeral public key, ePk, once the data has been sent in step VIII, then, once said blockchain transaction created by the recipient (7) has been found, the transaction creation sub-module of the fourth blockchain management module of the gateway creating a new blockchain transaction, using as inputs the outputs of the previous transaction, and using a script incorporating the ephemeral private key, eSk; XII- the search sub-module of the application or application server of the recipient searching the blockchain for the transaction created by the gateway (3), retrieving the ephemeral private key, eSk, and, optionally, the read / write sub-module saving said ephemeral private key, eSk, in the medium that is readable by the machine of the application or application server of the recipient (7). XIII- the decryption sub-module of the application or an application server of the recipient (7) decrypting the message, Em, using the ephemeral private key, eSk, retrieved by the search sub-module.
12. Communication method according to claim 11 which further comprises in step XI a verification by the search sub-module of the fourth blockchain management module of the gateway (3) that said transaction contains a financial value, and preferably a measurement of said financial value, the transaction being stopped by the sub-module if the verification fails or if the financial value contained in the transaction is less than a value previously negotiated between the gateway (3) and the node (1).
13. Communication method according to claim 11 or 12, which further comprises, in step V, a first encryption of the message (m) is performed by the encryption sub-module of the generator module of the node (1) by means of a symmetric key, K, shared with an application or application server of the recipient (7) in order to obtain the encrypted message, Ek(m), before encrypting by means of the ephemeral public key, ePk, is performed, in order to obtain the twice-encrypted message, Em, wherein the decryption of the twice-encrypted message, Em, by the decryption sub-module of the application or an application server of the recipient (7) in step XIII is then performed by means of the ephemeral private key, eSk, followed by the symmetric key (K).
14. Communication method according to one of claims 11 to 13, wherein the gateway (3) comprises a first generator module, the method further comprising, prior to step III, a first step of each of the first generator modules of the gateway generating an ephemeral private key, eSk1, eSk2, and an ephemeral public key, ePk1, ePk2, which is complementary to said ephemeral private key, eSk11, eSk2, preferably in response to a triggering event, and storing these keys, ePk1, eSk1, ePk2, eSk2, in the medium that is readable by the machine of the gateway.