Method for enrolling a device with a server
Patent Information
- Application Number
- EP2023762258
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-08-23
- Filing Date
- 2023-08-16
- Publication Date
- 2025-07-02
AI Technical Summary
Smart Grids face increased vulnerability due to the convergence of IT and OT systems, making it challenging to establish secure communications within the network, particularly in ensuring trust and security for devices connected to these systems.
A method for enrolling a device with a server involves establishing communication channels, generating and signing digital certificates using private and public keys to secure communications, with optional encryption and secure tunnel protocols like IPsec, ensuring secure device enrollment and authentication.
This method enhances network security by establishing trusted communications within Smart Grids, protecting against vulnerabilities by authenticating devices and enabling secure interactions within the network.
Smart Images

Figure 1.1
Abstract
Description
[0001] Method of enrolling a device with a server
[0002] DESCRIPTION
[0003] FIELD OF THE INVENTION
[0004] The present invention relates to a method of enrolling a device with a server.
[0005] STATE OF THE ART
[0006] The move towards "smarter" electricity networks, known as "Smart Grids", is a key pivot in the energy transition towards the electricity systems of tomorrow. The implementation of these Smart Grids involves the digitalization of systems and the integration of new communication capabilities and leads to the convergence between information technologies and so-called "operational" technologies (IT: Information Technology / OT: Operational Technology).
[0007] This convergence brings new vulnerabilities to these industrial systems, which now combine cyber and physical dimensions, as is the case for energy networks in particular. The use cases and attack vectors are numerous and diverse. This issue of increasing vulnerability of industrial systems, as the digitalization of equipment progresses, concerns all areas of "use", with different levels of criticality.
[0008] For example, Smart Grids interconnect a growing number of information systems associated with various third-party actors to the network operator's IT system, for which it is not possible to control either the security levels or practices. For example, the system of a wind power producer with that of the distribution network operator. It is therefore becoming increasingly important for network operators to protect their information systems.
[0009] STATEMENT OF THE INVENTION
[0010] A particular problem that arises is how trust can be granted to a device that is part of a network such as a Smart Grid, so that this device can have the right to establish secure communications within such a network.
[0011] One of the aims of the invention is to respond to the problem set out above.
[0012] To this end, according to a first aspect, a method is proposed for enrolling a device intended to communicate in a network with a server, the method comprising the following steps implemented by an administration terminal:
[0013] - establishment of a first communication channel with the device,
[0014] - retrieving via the first communication channel a digital certificate request generated then transmitted by the device, the digital certificate request being associated with a first private key of the device intended to secure communications of the device in the network,
[0015] - establishment of a second communication channel with the server,
[0016] - transmitting the digital certificate request to the server via the second communication channel, the server being configured to sign the digital certification request with a second private key associated with a public key of the server, so as to generate a digital certificate,
[0017] - recovery of the digital certificate via the second communication channel,
[0018] - transmission of the digital certificate to the device via the first communication channel.
[0019] The method according to the first aspect may also comprise the following optional features, taken alone or in combination whenever possible.
[0020] Preferably, the digital certificate request is encrypted by the device with the server's public key, is transmitted to the server in encrypted form, the server being configured to decrypt the digital certificate request in encrypted form with the second private key before signing the decrypted digital certificate request.
[0021] Preferably, the method according to the first aspect further comprises the following steps:
[0022] - generation of a code by the administration terminal, the code being associated with the digital certificate request,
[0023] - transmission of the code to the server via the second communication channel,
[0024] - transmission of the code to a server administrator via a third communication channel different from the second communication channel.
[0025] Preferably, the third communication channel is established between a first device separate from the administration terminal and a second device owned by the administrator, the third communication channel being for example a telephone communication channel.
[0026] Preferably, the method according to the first aspect comprises the following steps:
[0027] - connecting the administration terminal to the device by means of a cable, so that the first communication channel passes through the cable, - disconnecting the cable after transmitting the digital certificate to the device via the first communication channel.
[0028] Preferably, establishing the second communication channel comprises establishing a secure tunnel, preferably with the IPsec protocol.
[0029] Preferably, the second communication channel passes through the device.
[0030] Also provided in a second aspect is a computer-readable memory storing computer-executable instructions for performing the steps of the method in accordance with the first aspect.
[0031] There is also provided, according to a third aspect, an administration terminal comprising:
[0032] - at least one communication interface for establishing a first communication channel with a device, and for establishing a second communication channel with a server,
[0033] - a processing unit, wherein the processing unit is configured to:
[0034] - retrieve via the first communication channel a digital certificate request generated then transmitted by the device, the digital certificate request being associated with a first private key of the device intended to secure communications of the device in the network,
[0035] - transmitting the digital certificate request to the server via the second communication channel, the server being configured to sign the digital certification request with a second private key associated with a public key of the server, so as to generate a digital certificate,
[0036] - retrieve the digital certificate via the second communication channel,
[0037] - transmit the digital certificate to the device via the first communication channel.
[0038] There is also proposed, according to a fourth aspect, a system comprising:
[0039] - an administration terminal according to the third aspect,
[0040] - a server configured to sign the digital certification request with the second private key associated with the server's public key, so as to generate the digital certificate.
[0041] DESCRIPTION OF FIGURES
[0042] Other characteristics, aims and advantages of the invention will emerge from the following description, which is purely illustrative and non-limiting, and which must be read in conjunction with the appended drawings in which: Figure 1 and Figure 2 schematically illustrate a communication gateway, an administration terminal and a server, according to one embodiment.
[0043] Figure 3 is a flowchart of steps of an enrollment method according to one embodiment.
[0044] Throughout the figures, similar elements have identical references.
[0045] DETAILED DESCRIPTION OF THE INVENTION
[0046] With reference to figures 1 and 2, a communication network, for example an electrical network of the “Smart Grid” type as mentioned in the introduction, comprises a device 1 and a server 2.
[0047] The device 1 comprises at least one communication interface for communicating with other equipment in the network (in particular the server) and for communicating with an administration terminal.
[0048] In the embodiment shown in Figure 2, the device 1 comprises a first communication interface 10 for communicating with other equipment in the network (in particular the server), and a second communication interface 11 for communicating with the administration terminal, separate from the first communication interface.
[0049] The first communication interface 10 is arbitrary. It can be wired (Ethernet) or wireless radio (Wi-Fi, cellular, etc.).
[0050] The second communication interface 11 comprises a physical port constituting a physical connection point for a communication cable, so as to enable a wired connection to be established between the communication gateway and an administration terminal.
[0051] The device 1 further comprises a data processing unit 12. The data processing unit 12 comprises at least one processor configured to control the implementation of steps which will be detailed below.
[0052] The device 1 further comprises a memory 14. This memory 1, readable by the data processing unit, stores instructions executable by this unit for the execution of the aforementioned steps. The memory 14 is further adapted to store data which will be discussed below.
[0053] The device 1 is for example a communication gateway 1 . A function performed by the communication gateway 1 is for example to relay data emanating from a first device of the network to a second device of the network. In the following, it will be assumed that the device 1 is such a gateway, it being understood that this is only a non-limiting embodiment.
[0054] The server 2 comprises a communication interface 20 for communicating with other equipment in the network (in particular the communication gateway 1).
[0055] The server 2 further comprises a data processing unit 22. The data processing unit 22 comprises at least one processor configured to control the implementation of steps which will be detailed below.
[0056] The server 2 further comprises a memory 24. This memory 24, readable by the data processing unit, stores instructions executable by this unit for the execution of the aforementioned steps. The memory 24 is further adapted to store data which will be discussed below.
[0057] The server 2 further comprises a human-machine interface 26, allowing an administrator to interact with the server. The human-machine interface 26 typically comprises an output device such as a display screen, making it possible to provide information to the administrator, and an input device, such as a keyboard, allowing this administrator to control the operation of the server and / or to enter data.
[0058] One function of server 2 is to participate in the enrollment of communication gateway 1 within the network, that is to say to declare this gateway as a device authorized to communicate with other devices within the network.
[0059] Figures 1 and 2 also show an administration terminal 3.
[0060] The administration terminal 3 comprises at least one communication interface for communicating with the gateway and with the server.
[0061] In the embodiment shown in Figure 2, the administration terminal comprises a single communication interface 30 allowing communication with the gateway and with the server.
[0062] The communication interface 30 comprises a physical port constituting a physical connection point for a communication cable, so as to enable a wired connection to be established between the physical port (communication interface 11) of the communication gateway and the physical port of the administration terminal (communication interface 30). The administration terminal 3 further comprises a data processing unit 32. The data processing unit 32 comprises at least one processor configured to control the implementation of steps which will be detailed below.
[0063] The administration terminal 3 also comprises a memory 34. This memory 34, readable by the data processing unit, stores instructions executable by this unit for the execution of the aforementioned steps.
[0064] The administration terminal 3 further comprises a human-machine interface 36, allowing a user to interact with the terminal 3. The human-machine interface 36 typically comprises an output device such as a display screen, making it possible to provide information to the user, and an input device, such as a keyboard, allowing this user to control the operation of the server and / or enter data.
[0065] A function performed by the administration terminal 3 is to participate in a process of enrolling the communication gateway 1 with the server 2.
[0066] The administration terminal 3 typically takes the form of portable equipment such as a laptop, a tablet or even a smartphone.
[0067] Referring to Figure 3, a method of enrolling gateway 1 with server 2 comprises the following steps.
[0068] The administration terminal 3 establishes a first communication channel with the communication gateway 1 (step 100).
[0069] In one embodiment, the administration terminal 3 is connected to the communication gateway 1 by means of a communication cable, so as to establish the first communication channel passing through the cable between the administration terminal 3 and the gateway 1. In this embodiment, a first end of the communication cable is connected to the physical port of the gateway (communication interface 11), and a second end of the communication cable, opposite the first end, is connected to the physical port of the administration terminal (communication interface 30). These connections are typically made by a user of the administration terminal 3.
[0070] The first communication channel uses, for example, the SSH protocol over an Ethernet connection (OSI layer 2) and TCP / IP (OSI layer 3). The SSH protocol may require the transmission of connection data (username and / or password) by terminal 3 to gateway 1. This connection data may be stored in advance in terminal 3 or entered into terminal 3 by the user of terminal 3.
[0071] The administration terminal 3 generates an enrollment request R intended for the gateway
[0072] 1 (step 102). The enrollment request includes a public key CÀ of the server 2. Alternatively, the public key CÀ is not transmitted by the administration terminal 3 to the device 1, but is stored in advance in the memory 24 of the gateway 1.
[0073] The enrollment request R is transmitted to the gateway 1 via the first communication channel (step 104). Upon receipt of the enrollment request R (step 106), the gateway 1 generates a private key KPR and a public key KPU associated with the private key KPR.
[0074] Gateway 1 also generates a digital certificate request D associated with the private key KPR (step 108). Request D incorporates the generated public key KPU. Request D may also incorporate a unique identifier for gateway 1, allowing it to be distinguished from other network devices. This unique identifier is, for example, a serial number.
[0075] The private key KPR is stored in the memory of gateway 1, as are the public key CÀ and the public key KPU. The private key KPR is not intended to be communicated to equipment external to gateway 1 (in particular the administration terminal 3).
[0076] The gateway encrypts the request D with the public key CA (step 109).
[0077] Gateway 1 transmits the digital certificate request D in encrypted form to the administration terminal 3 via the first communication channel (step 110).
[0078] The administration terminal 3 retrieves the digital certificate request D in encrypted form via the first communication channel (step 112).
[0079] The administration terminal 3 generates a code C associated with the digital certificate request D (step 114). This code C is, for example, a 4 or 6 digit PIN code.
[0080] The administration terminal 3 establishes a second communication channel with the server
[0081] 2 (step 116). In one embodiment, the second communication channel passes through the communication cable and through the gateway 1. In other words, it is through the gateway 1 that the administration terminal 3 can communicate with the server 2.
[0082] In Figure 1, the first communication channel and the second communication channel are represented by two dotted arrow lines. The second communication channel can be established at any time: before the issuance of the request R, after the retrieval of the electronic signature certification request D, or between these two stages.
[0083] Preferably, the second communication channel comprises a tunnel to allow the administration terminal 3 to communicate securely with the server 2. The tunnel is for example compliant with the IPSec protocol. Preferably, the security of this second communication channel is based on cryptographic elements held by the user of the administration terminal 3. This may for example be a hardware cryptographic token such as a smart card.
[0084] The administration terminal 3 transmits the digital certificate request D in encrypted form to the server 2, via the second communication channel (step 118).
[0085] The administration terminal 3 also transmits the code C to the server 2, via the second communication channel.
[0086] The digital certificate request D in encrypted form and the code C can be transmitted to server 2 in the same message or in separate messages, in any order, but in any case in a way that allows server 2 to understand that these data are associated with each other.
[0087] Once this data has been retrieved by the server 2 (step 120), the server 2 provides the code C to an administrator of this server 2, via its human-machine interface 26 (for example by displaying this code on a display screen).
[0088] The code C is furthermore transmitted to an administrator of the server 2 (step 121) via a third communication channel (not shown) different from the second communication channel. In one embodiment, the third communication channel is established between a first device held by the user (and distinct from the administration terminal 3) and a second device held by the administrator, the third communication channel being for example a telephone communication channel. For example, the administration terminal 3 displays the generated code on a display screen of the administration terminal 3, and the user enters the code displayed in the first device using input means of this device (physical or touch keyboard).
[0089] Ultimately, two code values are provided to the administrator, via two different channels. If these two values match, then the code received by server 2 is considered valid. Otherwise, the code received by server 2 is considered invalid. The administrator triggers the implementation of the following steps by server 2, via the human-machine interface 26, only if the code is valid.
[0090] Server 2 decrypts request D in encrypted form, so as to obtain request D in clear text. Server 2 does this using a private key associated with the public key CÀ, which only server 2 holds.
[0091] Server 2 signs the digital certificate request D with its private key (the one associated with the public key CA) (step 122), and provides as a result of this signing step a certificate S associated with the private key KPR (generated during step 108).
[0092] Server 2 transmits the digital certificate S to the administration terminal 3 via the second communication channel (step 124).
[0093] The administration terminal 3 therefore retrieves the digital certificate S via the second communication channel (step 126). After this transmission, the second communication channel is interrupted.
[0094] The administration terminal 3 transmits the digital certificate S to the communication gateway 1 via the first communication channel (step 128).
[0095] Gateway 1 receives certificate S (step 130).
[0096] After this transmission, the user can disconnect the communication cable from gateway 1; the first communication channel then ceases to exist.
[0097] The possession by gateway 1 of this digital certificate S constitutes proof of enrollment of gateway 1 with server 2.
[0098] The digital certificate S is data associated with the private key KPR initially generated by gateway 1. This private key KPR and the associated certificate S can then be used by gateway 1 to establish secure communications with other network equipment.
[0099] In the above method, the steps performed by the gateway 1 are controlled by the administration terminal 3.
[0100] The process detailed above can be subject to other variations. In particular:
[0101] • The above method, applied to a gateway 1, can be generalized to any other device intended to communicate in the network. • Although advantageous, the use of the code is optional; its verification can be carried out differently than by telephone, in particular automatically, without calling on an administrator;
[0102] • The second communication channel may not pass through gateway 1, but may request an additional communication interface from the administration terminal 3 to enable it to communicate with server 2 without passing through gateway 1.
Claims
CLAIMS 1. Method for enrolling a device intended to communicate in a network with a server, the method comprising the following steps implemented by an administration terminal: - establishment (100) of a first communication channel with the device, - recovery via the first communication channel (112) of a digital certificate request (D) generated then transmitted by the device, the digital certificate request (D) being associated with a first private key (KPR) of the device intended to secure communications of the device in the network, - generation (114) of a code (C) by the administration terminal, the code being associated with the request for a digital signature certificate, - establishment (116) of a second communication channel with the server, - transmission (118) of the digital certificate request (D) and the code to the server via the second communication channel, the server being configured to sign the digital certification request (D) with a second private key associated with a public key (CA) of the server, so as to generate a digital certificate (S), - transmission of the code to a server administrator via a third communication channel different from the second communication channel, - recovery (126) of the digital certificate (S) via the second communication channel, - transmission (128) of the digital certificate (S) to the device via the first communication channel.
2. Method according to the preceding claim, in which the digital certificate request (D) is encrypted by the device with the public key of the server, is transmitted to the server in encrypted form, the server being configured to decrypt the digital certificate request in encrypted form with the second private key before signing the decrypted digital certificate request.
3. Method according to any one of the preceding claims, in which the third communication channel is established between a first piece of equipment separate from the administration terminal and a second piece of equipment held by the administrator.
4. Method according to the preceding claim, the third communication channel being a telephone communication channel.
5. A method according to any preceding claim, further comprising the following steps: - connection of the administration terminal to the device by means of a cable, so that the first communication channel goes through the cable, - disconnection of the cable after transmission of the digital certificate to the device via the first communication channel.
6. Method according to any one of the preceding claims, wherein the establishment of the second communication channel comprises the establishment of a secure tunnel, preferably with the IPsec protocol.
7. Method according to one of the preceding claims, in which the second communication channel passes through the device.
8. Computer-readable memory (34) storing computer-executable instructions for carrying out the steps of the method according to one of the preceding claims.
9. Administration terminal (3) comprising: - at least one communication interface for establishing a first communication channel with a device, and for establishing a second communication channel with a server, - a processing unit, wherein the processing unit is configured to: - retrieve via the first communication channel a digital certificate request (D) generated then transmitted by the device, the digital certificate request (D) being associated with a first private key (KPR) of the device intended to secure communications of the device in the network, - generate a code associated with the digital signature certificate request, - transmitting the digital certificate request (D) and the code to the server via the second communication channel, the server being configured to sign the digital certification request (D) with a second private key associated with a public key (CÀ) of the server, so as to generate a digital certificate (S), - transmit the code to a server administrator via a third communication channel different from the second communication channel, - retrieve the digital certificate (S) via the second communication channel, - transmit the digital certificate (S) to the device via the first communication channel.
10. System comprising: - an administration terminal (3) according to the preceding claim, - a server (2) configured to sign the digital certification request (D) with the second private key associated with the public key (CÀ) of the server, so as to generate the digital certificate (S).