Methods for the protection of a piece of equipment and for the provision of data, and corresponding electronic devices and electronic assembly, computer program products and information storage media

EP4736370A1Pending Publication Date: 2026-05-06ORANGE SA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
EP · EP
Patent Type
Applications
Current Assignee / Owner
ORANGE SA
Filing Date
2024-06-26
Publication Date
2026-05-06

AI Technical Summary

Technical Problem

Current network security solutions, such as firewalls and intrusion detection systems, are inadequate for protecting industrial equipment as they restrict communication protocols like OPC-UA and ModBus, preventing external devices from querying protected equipment for data, thus limiting their applicability in industrial settings.

Method used

Implementing a method that partitions a communications network into two portions, allowing unidirectional communication from a first device within the protected portion to a second device in an exposed portion, enabling the transmission of addressing identifiers and current data values while restricting access to prevent malicious attacks.

Benefits of technology

This approach effectively secures industrial equipment by allowing secure data access from outside the network while preventing unauthorized access and maintaining communication protocol functionality, thus enhancing network security without requiring equipment modification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024067919_02012025_PF_FP_ABST
    Figure EP2024067919_02012025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method that is implemented in a first device in a communication network having a first portion comprising a piece of equipment as well as a second portion, the two portions being interconnected via the first device and a second device using unidirectional communication, the method comprising: • transmitting, to the second device, an address of the piece of equipment in the first portion; • during a communication between the piece of equipment and the first device, obtaining a value of a piece of data about the piece of equipment; • transmitting said value to the second device. The invention also relates in particular to a corresponding method for providing data as well as to corresponding electronic devices, a corresponding electronic assembly, and corresponding computer program products and information storage media.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DESCRIPTION

[0002] Title of the invention: Methods for protecting equipment and providing data, electronic devices and assemblies, computer program products and corresponding information media

[0003] Technical field

[0004] This application relates to the field of securing at least a portion of a communications network.

[0005] It relates in particular to a method for protecting at least one item of equipment, implemented by a first electronic device of a first portion of a communication network, and a method for providing data(s), implemented by a second electronic device of a second portion of a communication network, as well as the corresponding electronic devices and assemblies, computer program products and information media.

[0006] 1. State of the art

[0007] The present invention relates to the protection of at least one piece of equipment accessible via a communications network. This may, for example, be equipment handling sensitive data, or carrying out sensitive processing, and may therefore be the target of attack by malicious third parties, either to unduly access sensitive data, or to disrupt, or even prevent, certain processing via the propagation of a computer virus to the equipment.

[0008] This equipment is, for example, part of a private company network or a home network, interconnected to a public network such as the Internet.

[0009] Examples of sensitive data include personal data (medical data, banking data, etc.), industrial data (such as plans of manufactured objects, data relating to the production of certain industrial machines such as measurement results, number of parts produced, etc.), history of orders received by industrial equipment, alerts, etc.

[0010] Malicious third parties may, for example, be tempted to disable equipment to harm a company or obtain a ransom. Private network security solutions have been developed to protect a device or a set of devices belonging to the same private network from such attacks. Examples include solutions based on firewalls and / or intrusion detection systems.We can also cite the use of virtual private networks (VPN) (or VPN for Virtual Private Network according to the English terminology) isolating by encryption, within a wide area network, the exchanges between the equipment of the wide area network belonging to the virtual private network. Such solutions make it possible to limit communications with equipment outside the private network to communications sent from the private network to these "external" equipment, and thus prevent access from outside the network to equipment to be protected. However, these solutions, sometimes called "network diodes", are sometimes inappropriate and very restrictive for protecting certain electronic equipment such as industrial machines. Indeed, such solutions only allow information to be sent back at the initiative of the protected equipment.Software running on an electronic device outside the private network cannot therefore query protected equipment to obtain data in return. Such solutions severely limit, or even prevent, the use of certain communication protocols based on such requests, particularly certain protocols that are very widespread in the industrial sector (such as, in the industrial sector, the OPC-UA or ModBus protocols used by many machine tools on the market). They are therefore not suitable for protecting certain equipment on the market.

[0011] The present application aims to propose improvements to at least some of the disadvantages of the state of the art.

[0012] 2. Statement of the invention

[0013] The present application aims to improve the situation using a method for protecting equipment, called equipment to be protected, of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via a first electronic device and a second electronic device in unidirectional communication, so as to only allow communications from the first device to the second device, said method comprising:

[0014] • a transmission to said second device of an addressing identifier of said equipment on said first portion of said communication network;

[0015] • during a connection (or communication) between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment;

[0016] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0017] The present application relates in particular to a method for protecting equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via a first electronic device and a second electronic device in unidirectional communication, so as to only allow communications from the first device to the second device, said method comprising:

[0018] • obtaining an addressing identifier for said equipment to be protected on said first portion of said communication network, said addressing identifier being obtained dynamically by scanning said first portion;

[0019] • a transmission to said second device of said addressing identifier; • during a communication between said equipment to be protected and said first device, obtaining the current value of at least one data item of said equipment;

[0020] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0021] According to at least one embodiment, the protection method comprises obtaining a description relating to said equipment to be protected and comprising at least:

[0022] • said addressing identifier of said equipment to be protected on said first portion of said communications network;

[0023] • a designation of at least one communication protocol with said equipment;

[0024] • said addressing information of at least one piece of data from said equipment accessible for reading via said equipment.

[0025] According to at least one embodiment, the protection method comprises transmitting to said second device information identifying said protocol.

[0026] According to at least one embodiment, the protection method comprises, upon updating at least one first of said at least one accessible data item, a transmission to said second device, via said unidirectional communication, of said updated value.

[0027] According to at least one embodiment, said description is obtained when launching said protection method.

[0028] According to at least one embodiment, said description is obtained dynamically by said first device by scanning said first portion.

[0029] According to at least one embodiment, said current value and / or update of said first data is obtained by interrogating said equipment.

[0030] According to at least one embodiment, said interrogation of said equipment is carried out several times and a time interval between two successive interrogations of said equipment takes into account temporal information included in said description.

[0031] According to at least one embodiment, said first electronic device is in a fixed connection (direct for example) with said equipment to be protected.

[0032] The present application also relates to a method for providing data from at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, and at least a second portion interconnected with said first portion via a first electronic device and a second electronic device in unidirectional communication, so as to only allow communications from the first device to the second device, said method comprising:

[0033] • obtaining a description relating to at least one piece of equipment of said first portion of said communication network comprising at least one addressing identifier of said at least one piece of equipment on said first portion of said communication network; • assigning to said second device said at least one addressing identifier obtained, as addressing identifier of said second device on said second portion of said network, upon receipt of a request having as destination address said addressing identifier and relating to at least one first piece of data of said equipment, transmitting a value of said at least one first piece of data, previously obtained via said unidirectional communication, to a sender of said request.

[0034] According to at least one embodiment, said description is obtained via said unidirectional communication.

[0035] According to at least one embodiment, said description obtained via said supply method comprises:

[0036] • a designation of at least one communication protocol with said equipment;

[0037] • addressing information for at least one item of data from said equipment accessible for reading via said equipment of said first portion of said network; and said request is received according to said protocol and relates to said addressing information. The characteristics, presented in isolation in the present application in connection with certain embodiments of one of the methods of the present application, may be combined with each other according to other embodiments of this method.

[0038] According to another aspect, the present application also relates to an electronic device adapted to implement at least one of the methods of the present application in any of its embodiments.

[0039] The present application thus relates to a first electronic device of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising equipment to be protected, and at least a second portion interconnected with said first portion via the first device and a second device in unidirectional communication with the first device, so as to allow only communications from the first device to the second device, said first device comprising at least one processor configured to:

[0040] • a transmission to said second device of an addressing identifier of said equipment on said first portion of said communication network;

[0041] • during a connection (or communication) between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment;

[0042] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0043] The present application relates in particular to a first electronic device of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising equipment to be protected, and at least a second portion interconnected with said first portion via the first device and a second device in unidirectional communication with the first device, so as to allow only communications from the first device to the second device, said first device comprising at least one processor configured to:

[0044] • obtaining an addressing identifier for said equipment to be protected on said first portion of said communication network, said addressing identifier being obtained dynamically by scanning said first portion;

[0045] • a transmission to said second device of said addressing identifier;

[0046] • during communication between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment;

[0047] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0048] The present application also relates to a second electronic device of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising equipment to be protected, and at least a second portion interconnected with said first portion via a first electronic device and said second electronic device in unidirectional communication, so as to allow only communications from the first device to the second device, said second device comprising at least one processor configured to:

[0049] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network; of at least one piece of equipment on said first portion;

[0050] • upon receipt of a request having as destination address said addressing identifier and relating to at least one first data item of said equipment, transmission of a value of said at least one first data item, previously obtained via said unidirectional communication, to a sender of said request.

[0051] According to another aspect, the present application also relates to an electronic assembly of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising equipment to be protected, and at least a second portion interconnected with said first portion via a first device of said electronic assembly and a second device of said electronic assembly in unidirectional communication, via unidirectional communication means of said electronic assembly, so as to allow only communications from the first device of said electronic assembly to the second device of said electronic assembly, said at least one first device of said electronic assembly comprising at least one first processor configured to:

[0052] • a transmission to said second device of an addressing identifier of said equipment on said first portion of said communication network;

[0053] • during a connection (or communication) between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment;

[0054] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0055] And said at least one second electronic device comprising at least one second processor configured to:

[0056] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network, of at least one piece of equipment on said first portion;

[0057] • upon receipt of a request having as destination address said addressing identifier and relating to at least one first data item of said equipment, a transmission of a value of said at least one first data item, previously obtained via said unidirectional communication, to a sender of said request.

[0058] The present application relates in particular to an electronic assembly of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising equipment to be protected, and at least a second portion interconnected with said first portion via a first device of said electronic assembly and a second device of said electronic assembly in unidirectional communication with the first device of said electronic assembly, via unidirectional communication means of said electronic assembly so as to allow only communications from the first device of said electronic assembly to the second device of said electronic assembly, said at least one first device of said electronic assembly comprising at least one first processor configured to:

[0059] • obtaining an addressing identifier for said at least one piece of equipment to be protected on said first portion of said communication network, said addressing identifier being obtained dynamically by scanning said first portion;

[0060] • a transmission to said second device of said addressing identifier of said at least one piece of equipment to be protected;

[0061] • during a connection (or communication) between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment; • transmitting to said second device, via said unidirectional communication, the current value obtained.

[0062] And said at least one second electronic device comprising at least one second processor configured to:

[0063] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network, of at least one piece of equipment of said first portion;

[0064] • upon receipt of a request having as destination address said addressing identifier and relating to at least one first data item of said equipment, a transmission of a value of said at least one first data item, previously obtained via said unidirectional communication, to a sender of said request.

[0065] According to another aspect, the present application also relates to a system comprising at least one equipment to be protected and at least one electronic protection assembly, in a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment to be protected, and at least a second portion interconnected with said first portion via a first device of said electronic protection assembly and a second device of said electronic protection assembly in unidirectional communication with the first device of said electronic protection assembly, via unidirectional communication means of said electronic protection assembly so as to only allow communications from the first device of said electronic protection assembly to the second device of said electronic protection assembly,said at least one first device of said electronic protection assembly comprising at least one first processor configured to:,

[0066] • a transmission to said second device of an addressing identifier of said equipment on said first portion of said communication network;

[0067] • during a connection (or communication) between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment;

[0068] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0069] And said at least one second electronic device comprising at least one second processor configured to:

[0070] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network; of at least one piece of equipment on said first portion; • upon receipt of a request having as destination address said addressing identifier and relating to at least one first piece of data of said equipment, a transmission of a value of said at least one first piece of data, previously obtained via said unidirectional communication, to a sender of said request.

[0071] The present application relates in particular to a system comprising at least one piece of equipment to be protected and at least one electronic protection assembly, in a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said piece of equipment to be protected, and at least a second portion interconnected with said first portion via a first device of said electronic protection assembly and a second device of said electronic protection assembly in unidirectional communication with the first device of said electronic protection assembly, via unidirectional communication means of said electronic protection assembly so as to only allow communications from the first device of said electronic protection assembly to the second device of said electronic protection assembly,said at least one first device of said electronic protection assembly comprising at least one first processor configured to:,

[0072] • obtaining an addressing identifier for said at least one piece of equipment to be protected on said first portion of said communication network, said addressing identifier being obtained dynamically by scanning said first portion;

[0073] • a transmission to said second device of said addressing identifier of said at least one piece of equipment to be protected;

[0074] • during a connection (or communication) between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment;

[0075] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0076] And said at least one second electronic device comprising at least one second processor configured to:

[0077] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network, of at least one piece of equipment of said first portion;

[0078] • upon receipt of a request having as destination address said addressing identifier and relating to at least one first data item of said equipment, a transmission of a value of said at least one first data item, previously obtained via said unidirectional communication, to a sender of said request. The present application also relates to a computer program comprising instructions for implementing the various embodiments of at least one of the above methods, when said program is executed by a processor, and an information medium readable by an electronic device and on which the computer program is recorded.

[0079] The present application thus relates to a computer program comprising instructions for implementing, when the program is executed by a processor of a first electronic device, a method for protecting equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via the first device and a second device in unidirectional communication with the first device, so as to only allow communications from the first device to the second device, said method comprising:

[0080] • a transmission to said second device of an addressing identifier of said equipment on said first portion of said communication network;

[0081] • during a connection (or communication) between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment;

[0082] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0083] The present application relates in particular to a computer program comprising instructions for implementing the various embodiments of at least one of the above methods, when said program is executed by a processor, and an information medium readable by an electronic device and on which the computer program is recorded.

[0084] The present application relates in particular to a computer program comprising instructions for implementing, when the program is executed by a processor of a first electronic device, a method for protecting equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via the first device and a second device in unidirectional communication with the first device, so as to only allow communications from the first device to the second device, said method comprising:

[0085] • obtaining an addressing identifier for said equipment to be protected on said first portion of said communication network, said addressing identifier being obtained dynamically by scanning said first portion;

[0086] • a transmission to said second device of said addressing identifier; • during a communication between said equipment to be protected and said first device, obtaining the current value of at least one data item of said equipment;

[0087] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0088] Furthermore, the present application relates to a computer program comprising instructions for implementing, when the program is executed by a processor of a second electronic device, a method for providing data from at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, and at least a second portion interconnected with said first portion via a first electronic device and the second electronic device in unidirectional communication, so as to allow only communications from the first device to the second device, said method comprising:

[0089] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network; of at least one piece of equipment on said first portion;

[0090] • upon receipt of a request having as destination address said addressing identifier and relating to at least one first data item of said equipment, a transmission of a value of said at least one first data item, previously obtained via said unidirectional communication, to a sender of said request.

[0091] The present application also relates to an information medium readable by a processor of a first electronic device and on which is recorded a computer program comprising instructions for implementing, when the program is executed by the processor, a method for protecting equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via the first device and a second device in unidirectional communication with the first device, so as to allow only communications from the first device to the second device, said method comprising:

[0092] • a transmission to said second device of an addressing identifier of said equipment on said first portion of said communication network;

[0093] • during a connection (or communication) between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment;

[0094] • a transmission to said second device, via said unidirectional communication, of the current value obtained. The present application relates in particular to an information medium readable by a processor of a first electronic device and on which is recorded a computer program comprising instructions for implementing, when the program is executed by the processor, a method for protecting equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via the first device and a second device in unidirectional communication with the first device, so as to allow only communications from the first device to the second device, said method comprising:

[0095] • obtaining an addressing identifier for said equipment to be protected on said first portion of said communication network, said addressing identifier being obtained dynamically by scanning said first portion;

[0096] • a transmission to said second device of said addressing identifier;

[0097] • during communication between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment;

[0098] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0099] The present application further relates to an information medium readable by a processor of a second electronic device and on which is recorded a computer program comprising instructions for implementing, when the program is executed by the processor, a method of a method for providing data from at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, and at least a second portion interconnected with said first portion via a first electronic device and the second electronic device in unidirectional communication, so as to allow only communications from the first device to the second device, said method comprising:

[0100] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network; of at least one piece of equipment on said first portion;

[0101] • upon receipt of a request having as destination address said addressing identifier and relating to at least one first data item of said equipment, a transmission of a value of said at least one first data item, previously obtained via said unidirectional communication, to a sender of said request.

[0102] The above-mentioned programs may use any programming language, and may be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable form.

[0103] The information (or recording) media referred to in this application may be any entity or device capable of storing the program. For example, an information medium may comprise a storage medium, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording medium.

[0104] Such storage means can be, for example, a hard disk, flash memory, etc.

[0105] On the other hand, an information carrier may be a transmissible information carrier such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means. A program according to the invention may in particular be downloaded from a network such as the Internet.

[0106] Alternatively, an information carrier may be an integrated circuit in which a program is incorporated, the circuit being adapted to execute or to be used in the execution of any of the embodiments of at least one of the methods which are the subject of the present patent application.

[0107] Generally speaking, by obtaining an element, we mean in the present application for example a reception of this element from a communication network, an acquisition of this element (via for example user interface elements, sensors, etc.), a creation of this element by various processing means such as by copying, encoding, decoding, transformation etc and / or an access of this element from a local or remote storage medium accessible to at least one device (such as the first and / or the second device) implementing, at least partially, this obtaining.

[0108] 3. Brief description of the drawings

[0109] Other characteristics and advantages of the invention will appear more clearly on reading the following description of particular embodiments, given as simple illustrative and non-limiting examples, and the appended drawings, among which:

[0110] [Fig 1] shows a simplified view of an exemplary system in which at least some embodiments of the methods of the present application may be implemented,

[0111] [Fig 2] shows a simplified view of a device suitable for implementing at least certain embodiments of at least one of the methods of the present application,

[0112] [Fig 3] presents an overview of the method of protecting the present application, in certain of its embodiments.

[0113] [Fig 4] presents an overview of the data provisioning method of the present application, in some of its embodiments. [Fig 5] presents a simplified view of an exemplary system 500 in which at least some embodiments of the method of the present application may be implemented.

[0114] 4. Description of the embodiments

[0115] This application aims to provide a simple and effective solution for both protecting one or more devices in a communications network against computer attacks, in particular external to this communications network, while making it possible to obtain (for example on request), in particular from outside the communications network, and in a secure manner, data from these devices to be protected. To this end, the application proposes to equip the communications network with at least two devices, creating a partition of the communications network into at least two portions.

[0116] By partition, we mean here a division of the communication network into a plurality of portions each comprising at least one electronic device, separated two by two (except for certain interconnection elements between the at least two devices as specified below) and the union of which reconstitutes the communication network.

[0117] At least a first of these portions is a portion (called "protected") inaccessible from an electronic device located outside this first portion, this first portion comprising at least one piece of equipment to be protected. At least a second portion called "exposed" is accessible, directly or via interconnection equipment, to devices outside the first portion (such as devices located in a "first" protected portion other than the first "protected" portion where the equipment is located, and / or devices of the second portion, and / or devices outside the communication network).

[0118] The communication network may in particular be a private or local network. The equipment(s) to be protected may for example be industrial machines. According to the present application, a first device belonging to a protected portion accesses, in read mode, data from equipment to be protected located in this protected portion, and transmits them to a second device, located in an exposed portion (i.e. external to this protected portion), where these data are accessible to a third-party device (such as a device not belonging to the communication network, or belonging to the exposed portion of the communication network) and / or likely to be provided (systematically, by subscription and / or on request) to a third-party device. An at least partial duplication of the data accessible in read mode from the equipment to be protected is thus implemented on the second device.The first device and the second device communicate only via one-way communication means, so as to make possible only communications emitted from the first device (from the protected portion) to the second device (in the exposed portion).

[0119] Thus, according to the present application, it is possible to receive (at the second device) requests from a third-party device wishing to obtain data from the equipment to be protected, and to provide it in return with this data (previously obtained via the first device), in complete security for the equipment to be protected.

[0120] The logical assembly comprising the at least one first and second devices and the unidirectional communication means is also referred to in the present application as an “electronic assembly”, or “electronic protection assembly”, or even “Smart Diode” (or Smart Diode according to the English terminology). Depending on the embodiments, it may be a virtual assembly, virtually encapsulating the first and second devices and their unidirectional communication means or a physical assembly (such as a hardware element), having for example a housing in which the at least one first and second devices and their unidirectional communication means are installed. This assembly may comprise, depending on the embodiments, and the topology of the network (for example the number of devices to be protected), a variable number of “first” devices and “second” devices.

[0121] Such an electronic assembly offers the advantage of being easy to install in a communication network, for example as an "intermediary" between a (particular) piece of equipment to be protected and the rest of the communication network, or in such a way as to limit access to this equipment to be protected to only accesses made by the first device or simply to limit access to the equipment to be protected to devices located in a (protected) portion of the communication network, to which this equipment belongs. Such an assembly can also help to offer a "turnkey" product to a communication network administrator.

[0122] Such an electronic assembly can thus help, at least in certain embodiments, to secure equipment to be protected, without requiring modification and / or replacement of this equipment.

[0123] For the sake of clarity, the term “electronic equipment” or “equipment” is used in this application to refer to equipment that may be protected by the electronic assembly. The term “electronic device” or “device” will be used to refer to the first or second electronic device of the electronic assembly 160 introduced above. The term “electronic device” or “device” relates to any electronic device (it may sometimes be equipment to be protected or a device of the electronic assembly).

[0124] The present application is now described in more detail in connection with Figure 1.

[0125] Figure 1 shows a system 100 in which certain embodiments of the invention can be implemented. The system 100 comprises one or more electronic devices, at least some of which can communicate with each other via one or more communication networks 110, 120, 130 which may be partitioned and / or interconnected. In the example illustrated, the system thus comprises a private network partitioned into two portions 110, 120. One of the portions 120 is further interconnected with another network 130 (such as a wide area and / or public network), thus allowing communications between electronic devices 150, 164, 170 of this portion 120 and electronic devices 180 not belonging to the private network.

[0126] The private network may for example be a private business or home network, for example a local private network (or LAN for Local Area Network, according to English terminology). The other network 130 may for example be another local network, or a “wide” network with significant geographical coverage, such as a metropolitan area network (or MAN, for Metropolitan Area Network, according to English terminology) or a network whose geographical area covers at least one region of a country, or a country (or WAN, for Wide Area Network, according to English terminology). It may for example be a WAN network of the internet type, or cellular, GSM - Global System for Mobile Communications, UMTS - Universal Mobile Telecommunications System, Wifi - Wireless, etc.).

[0127] As illustrated in FIG. 1, the system 100 may also comprise several electronic devices 140 in a non-interconnected portion 110 of the private network, such as a terminal (such as a laptop, a smartphone, a tablet or a connected object), a connected object (such as a robot, an automatically and / or remotely guided mobile device, an energy meter, a machine tool in the case of an industrial private network, and / or household appliance in the case of a home network), a server, for example an application server, and / or a storage device.

[0128] The system comprises at least one electronic assembly 160 as introduced above aimed at protecting at least certain electronic equipment 140 of the private network 110. The first device 162 of the electronic assembly 160 is located in a portion 110 called "to be protected" of the private network comprising the equipment 140 to be protected. The first device 162 communicates with the second device 164 (located in the interconnected portion 120) via unidirectional communication means 168, not allowing communication in the opposite direction. Such unidirectional communication means may vary according to the embodiments (and in particular according to the hardware capabilities of the first and / or second device).In certain embodiments, the unidirectional communication means may comprise at least one optocoupler, and / or bidirectional communication means having been limited to a single direction of transmission, such as an Ethernet cable, a serial link and / or an optical fiber and / or at least one digital isolator with galvanic, capacitive, inductive and / or optical isolation.

[0129] The presence of optocoupler(s) allows the two devices to be physically separated (no electrical flow is exchanged, just light), and therefore to reinforce the security of the exchanges. The electrical isolation of the devices from each other can help, for example, to prevent attacks by injection of current or electrical signal on the second portion of the said network.

[0130] The system may also include network management and / or interconnection elements 164, 170. In particular (and even if not illustrated in FIG. 1), in certain embodiments, the electronic assembly 160 may include an interconnection gateway with another network. In certain embodiments, this gateway may for example be connected to the second device of the electronic assembly (and therefore allow an interconnection between the “exposed” portion of the private network and the other network). In other embodiments, the second device may itself play the role of an interconnection gateway between the “exposed” portion of the private network and the other network.

[0131] The private network can for example use fixed links such as at least one serial link and / or one Ethernet link, or wireless means of communication. The network can implement a communication protocol such as ModBus Serial, or CAN (acronym for "Controller Area Network") in the case of a serial link, or such as (ModBus TCP, OPC-UA, MQTT (for Message Queuing Telemetry in English), Siemens S7) in the case of an Ethernet link.

[0132] Figure 2 illustrates a simplified structure of an electronic device 200 of the system 100, for example the first device 162, the first device 162, and / or the equipment to be protected 140 of Figure 1. Depending on the embodiments, it may be a server, and / or a terminal, or even a microcomputer with a simple human-machine interface such as a Raspberry Pi ©, an OrangePi © or even a NanoPl NEO.

[0133] The device 200 comprises in particular at least one memory M 210. The device 200 may in particular comprise a buffer memory, a volatile memory, for example of the RAM type (for “Random Access Memory” according to English terminology), and / or a non-volatile memory (for example of the ROM type (for “Read Only Memory” according to English terminology). The device 200 may also comprise a processing unit UT 220, equipped for example with at least one processor P 222, and controlled by a computer program PG 212 stored in memory M 210. At initialization, the code instructions of the computer program PG are for example loaded into a RAM memory before being executed by the processor P.In the case where the apparatus is the first device 162 and / or the second device 164 of the electronic assembly, said at least one processor P 222 of the processing unit UT 220 can in particular implement, individually or collectively, any one of the embodiments of at least one of the methods of the present application (described in particular in relation to figures 3 and 4), according to the instructions of the computer program PG.

[0134] The device may also comprise, or be coupled to, at least one I / O input / output module 230. The at least one I / O input / output module 230 of the device may comprise, in certain embodiments, at least one module for interfacing with a user of the device (also referred to more simply in this application as a “user interface”). By user interface of the device, we mean for example an interface integrated into the device 200, or a part of a third-party device with which it is coupled by wired or wireless communication means.For example, it may be a secondary screen of the device. A user interface may in particular be a user interface, called an "output" user interface, adapted to a rendering (or to the control of a rendering) of an output element of a computer application used by the device 200, for example an application running at least partially on the device 200 or an "online" application running at least partially remotely, for example on a server. Examples of output user interfaces of the device include one or more screens, in particular at least one graphical screen (touch screen for example), one or more speakers, a connected object.

[0135] By rendering, we mean here a restitution (or “output” according to English terminology) on at least one user interface, in any form, for example including textual, audio and / or video components, or a combination of such components.

[0136] Furthermore, a user interface may be a so-called "input" user interface, adapted to acquire a command from a user of the device 200. This may in particular be an action to be performed in connection with a returned item, and / or a command to be transmitted to a computer application used by the device 200, for example an application running at least partially on the device 200 or an "online" application running at least partially remotely, for example on a server. Examples of an input user interface of the device include a sensor, an audio and / or video acquisition means (microphone, camera (webcam) for example), a keyboard, a mouse.

[0137] The device may also comprise, or be coupled to, at least one I / O input / output module 230, such as a communication module, allowing the device 200 to communicate with at least one other device of the system 100, via wired or wireless communication interfaces. For example, it may be at least one Ethernet type interface, and / or Wifi, Bluetooth type.

[0138] In the case where the apparatus is the first device 162 or the second device 164 of the electronic assembly, the communication means comprise an interface 1622, 1642 for unidirectional communication between the two devices, such as an Ethernet type interface, or a serial interface with an optocoupler 166 of the electronic assembly 160. In the example of FIG. 1, the optocoupler can be connected directly to the serial interface. For example, the transmission port of the first device (protected portion) can be connected to one pin of the optocoupler and the reception port of the second device (exposed portion) can be connected to another pin of the optocoupler. Each side of the optocoupler can be supplied with voltage by the first and second devices respectively (for example with a voltage of 3.3V).

[0139] In certain embodiments, when the device 200 belongs to a first portion to be protected, the communication means of the device (except possibly the unidirectional communication means above when the device is one of the first and second devices) may be solely wired communication means, so as to physically limit the possibilities of access (directly or via this device) to equipment to be protected located in the same portion to be protected of the network (and therefore the possibilities of attacks by third parties). Thus, at least one of the first and second devices 162, 164 may be a microcomputer of the “NanoPi NEO” © type, equipped only with an Ethernet port (and no WiFi). Said at least one microprocessor of the first device 162 may in particular be adapted to:

[0140] • a transmission to the second device of an addressing identifier of the equipment on the first portion of the communication network;

[0141] • during a connection (or communication) between said equipment to be protected and the first device, obtaining the current value of at least one piece of data from said equipment;

[0142] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0143] For example, said at least one microprocessor of the first device 162 may in particular be adapted to:

[0144] • obtaining an addressing identifier for said equipment to be protected on said first portion of said communication network, said addressing identifier being obtained dynamically by scanning said first portion;

[0145] • a transmission to said second device of said addressing identifier;

[0146] • during communication between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment;

[0147] • a transmission to said second device, via said unidirectional communication, of the current value obtained.

[0148] Said at least one microprocessor of the second device 164 can in particular be adapted for:

[0149] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network; of at least one piece of equipment on said first portion;

[0150] • upon receipt of a request having as destination address said addressing identifier and relating to at least one first data item of said equipment, a transmission of a value of said at least one first data item, previously obtained via said unidirectional communication, to a sender of said request.

[0151] Some of the above input-output modules are optional and may therefore be absent from the equipment to be protected, the first device and / or the second device in certain embodiments.

[0152] The electronic assembly introduced above may comprise, in certain embodiments, a physical housing in which the first and second devices and the one-way communication means from the first device to the second device are housed. The housing may, for example, limit or prevent physical access to the first and second devices and their one-way communication means. It may in particular be a housing closed by a non-repositionable guarantee strip, or a sealed housing, so as to make any opening of the housing visible, due to deterioration of a seal or the guarantee strip, or to make it difficult to open.The housing may, for example, provide physical access to at least certain communication interfaces of the first and / or second device (other than the unidirectional means of communication between these two devices, for example) and / or include communication interfaces connected to at least certain of the communication interface(s) of the first and second device.

[0153] In some embodiments, the housing may only provide access to certain wired communication interface(s) of the first device. For example, this may involve "forcing" the use of certain communication interfaces between the equipment and the first device, offering, for example, advantages in terms of security (for example, due to the protocol involved in such interfaces) or favoring the use of "wired" interfaces. In some embodiments, the housing may allow access to several communication interfaces of the first and second devices, so as to provide a set adapted to different network environments.

[0154] In certain embodiments, for example when the electronic assembly introduced above does not prevent access to certain interfaces of the first device, some of these interfaces can be deactivated in software (for example not providing any service), so that third-party equipment cannot access in reading and / or writing (via an SHH connection in the case of an Ethernet link for example) the description of the first device and data of the equipment stored by the first device.

[0155] The term "module" or the term "component" or "element" of the device is understood here to mean a hardware element, in particular wired, or a software element, or a combination of at least one hardware element and at least one software element. The method according to the invention can therefore be implemented in various ways, in particular in wired form and / or in software form.

[0156] Figure 3 illustrates certain embodiments of the protection method 300 of the present application. The method 300 can for example be implemented by a first device located in a protected portion of a communication network such as the first device 162 of the electronic assembly 160 of the system 100.

[0157] According to the embodiments, the method can be implemented automatically at startup of the first device (via a script executed at startup (“boot”) of the device) or later, for example following the launch, manual or automatic (via a background task for example) of an executable implementing at least one embodiment of the method. The method can notably comprise, as illustrated in FIG. 3, a so-called initialization phase 310 (during startup of the device for example or later, upon receipt of a user command for example). This initialization phase 310 comprises obtaining 312 a description relating to at least one piece of equipment (to be protected) located in the same “first” portion as the first device. The description can take the form of one or more files for example, in YAML, XML or JSON format for example.The description may in particular include information necessary for identifying the equipment, and / or information necessary for establishing communication between the first device and the equipment and / or information describing the data (location, size, type, structure, etc.) which the first device must access on the equipment or which the latter is likely to provide to the first device. Depending on the embodiments, and depending on the unidirectional communication means implemented between the first and second devices, the description may further include information necessary for establishing unidirectional communication between the first device and the second device (such as an address of the second device on the communication network, a protocol to be used, etc.).

[0158] The information necessary to identify equipment to be protected may include at least one of the following identification information: a textual label; an address (or addressing identifier) ​​of the equipment on the first portion (for example, according to the protocols, an IP address, a MAC address of at least one access point of the equipment, a URL (for Uniform Resource Allocator according to English terminology), etc.); a manufacturer reference of the equipment; a serial number of the equipment; a combination of at least two of the above identification information.

[0159] The information necessary for establishing communication between the first device and the equipment (in addition to the identification information) includes in particular at least one of the following so-called communication information: information designating a protocol that can be used to communicate with the equipment; a port of the equipment that can be used to communicate with the equipment according to said protocol; at least one connection security element (such as an access identifier, a password, a public or private key, etc.); additional parameters specific to certain protocol(s) (such as a “topic” in the case of the MQTT protocol or a URL in the case of the OPC-UA protocol); a combination of at least two of the above communication information.

[0160] Examples of protocols include hierarchical protocols, using standardized data structures, such as Open Platform Communications Unified Architecture (OPC UA) ModBus protocols, or non-hierarchical protocols such as MQTT or Direct UDP.

[0161] The information describing the data (location, size, type, structure, etc.) which the first device must access on the equipment and / or which the latter is likely to provide to the first device includes in particular, for at least one protocol used, at least one of the following data descriptive information: a textual label; so-called addressing information relating to a location at least one of these data (such as one or more addresses, a range of addresses, a designation of one or more registers, etc.); an indication of a type of at least one of these data (boolean, integer, etc.); information relating to a memory size of at least one of these data; information relating to a structure of at least one of these data; a decryption key for at least one of these data; a time interval between two accesses to at least one of these data (for example a minimum, maximum, or nominal duration between two accesses) (for example of the order of a few milliseconds or a few seconds such as 100 ms, 1 s, 2s, or 5s); temporal information (time, time range, etc.) limiting access to at least one of these data; a combination of at least two of the above data descriptive information.

[0162] Note that the information describing data may vary depending on the protocol(s) used.

[0163] In some embodiments, the time interval between two accesses may vary depending on the data concerned, for example depending on the expected frequency of variation of this data (so as to access more frequently the data likely to vary most frequently than other data varying less frequently), or depending on the criticality of the data (so as to access more frequently the most critical data, the variation of which may reflect an alarming situation).

[0164] A time limitation on access to equipment data may, for example, make it possible to avoid access to equipment data at times when such access would be likely to impair the proper development of the equipment (for example, by adding a processing load to the equipment during periods of high equipment usage). A time limitation on access to equipment data may also, in certain embodiments, make it possible to exclude access during periods (such as nights or weekends) when the equipment is not in use and therefore when data relating to its operation would be insignificant and / or not likely to vary. Such an embodiment may help to save CPU resources of the equipment and / or the first device and therefore limit their energy consumption.A time limitation on access to equipment data can also, for example, prevent access to equipment data at times when the data would be inaccessible or inconsistent (during scheduled equipment updates, for example).

[0165] It should be noted that the information describing data included in the description may only concern some of the data accessible for reading by said equipment.

[0166] Such an embodiment may make it possible to filter the data of equipment accessible to said first device. Thus, in certain embodiments, it may be possible to choose (or filter) the data that can be obtained from a portion other than the protected portion, so as, for example, not to provide data of a confidential nature.

[0167] Some of this identifying, communication, and / or data-describing information may be optional in some embodiments. For example, communication information such as connection security features may be absent when access to the equipment is not restricted within the first portion. In addition, some of the data-describing information may depend on the protocol(s) designated in the communication information.

[0168] An example of a description is shown below. In this example, the description, for simplicity, concerns only a single device to be protected and describes several protocols. config ve sion: 1.0 config date: 2023-05-04 modules:

[0169] "Modbus 1 type: modbus ip: 192.168.0.5 port: 9400 interval: 1 registers:

[0170] - 0-105 coils:

[0171] - 0-1

[0172] "SiemensTest": type: opcua ip: 192.168.0.5 endpoint: 'ope. tcp: / / l 92.168.0.5:4840 / endpoint' interval: 1 nodes:

[0173] - 'ns=l;s= UI-A@supervision \ exports-4-0-4statistics-l :sigma2 '

[0174] - 'ns=2;i=1234'

[0175] "Opc-UA server test": type: opcua ip: 192.168.0.20 endpoint: 'opc. tcp: / / l 92.168.0.20: 4840 / endpoint' auth: username: 'admin' password: 'admin' nodes:

[0176] - 'ns=l;s= UI-A@supervision \ exports-4-0-4statistics-l :sigma2 '

[0177] - 'ns=2;i=1234'

[0178] "Siemens S7": type: opcua ip: 192.168.0.10 endpoint: 'opc. tcp: / / l 92.168.0.10: 4840 / endpoint' auth: caCert: ' / certs / truc.pem ' privateKey: ' / certs / private.key ' interval: 1 nodes:

[0179] - 'ns=l;s= UI-A@supervision \ exports-4-0-4statistics-l :sigma2 '

[0180] - 'ns=2;i=1234'

[0181] "MqttBroker": type: mqtt ip: 192.168.0.50 port: 1883 auth: username: 'admin' password: 'admin' topics:

[0182] - '#' In certain embodiments, the description may for example be obtained by accessing a storage area accessible to the first device (such as a storage area local to the first device or located in the first portion of the network or a removable storage area (such as a USB key) coupled to the first device or accessible via a serial connection on a micro-USB port of the first device. This may in particular be a micro-USB port inaccessible to a third party when the housing of the electronic assembly comprising the first device is closed.

[0183] In some embodiments, the description may be created, or completed, dynamically (and at least partially automatically) by the device itself.

[0184] In such an embodiment, the method may comprise a scanning of the first portion to discover the devices present in the first portion, then at least one attempt to connect to these devices using one or more candidate protocols (depending on the embodiments), making it possible, when a connection attempt is successful, to detect at least one protocol used by the equipment. The scanning may use, in certain embodiments, a protocol making it possible to associate the network layer protocol address (typically an IPv4 address) of a remote host with its link layer protocol address (typically a MAC address), such as the ARP protocol (for Address Resolution Protocol). The scanning may, for example, test all IP addresses (from 0.0.0.0 to 255.255.255.255) to discover the machines present, including those located in a subnet of the first portion.

[0185] Once the machines are identified, the process may include scanning open ports and testing the connection with supported protocols.

[0186] The connection attempts may optionally use additional elements (such as at least one port value (to discover at least one open port on the device concerned) and / or additional parameters consistent with this (or these) candidate protocol(s)). Examples of candidate protocols include MQTT, UPC-UA, ModBus, UDP, etc. For example, the method may comprise, for each discovered device of the first portion, a connection attempt with a set of candidate protocols defined by configuration (manual or automatic) of the device.

[0187] When at least one connection attempt has been successfully made for at least one discovered device, the method may include a recording of the address of the discovered device in association with the protocols that enabled the connection, and any additional elements in said description.

[0188] Such an embodiment can make it possible not only to create a description, but also to automatically update an existing description, by adding information relating to a newly discovered piece of equipment or by modifying information in the description relating to a piece of equipment, for example to add information relating to a new protocol accepted by this piece of equipment (following a software update of the equipment for example), or to delete the designation of a port that has become inaccessible (defective for example).

[0189] In certain embodiments, the method may further comprise an (optional) update of the description obtained, either automatically by the first device (by applying parameterization rules for example) or by an operator, via a user interface of the first device. This may involve, for example, the deletion, in a description created automatically by the first device, of information describing certain protocols (deemed to be insecure for example), or of certain data (deemed too critical to allow their access in certain implementations), it may also involve manually completing a descriptive file created automatically by the first device.

[0190] As illustrated in Figure 3, the method may include transmitting 316 at least a portion of the obtained description 312 to the second device.

[0191] In such embodiments, the method may comprise an initialization of this unidirectional communication, prior to this transmission, possibly taking into account configuration data, local or remote, accessible to the first device. The transmission 316 may in particular comprise the transmission of at least one item of identification information of the equipment such as an address of the equipment on the first portion (for example according to the protocols an IP address, a MAC address, etc.), (also called addressing identifier on the first portion in the present application).

[0192] It may also include at least some communication information (e.g., information relating to a protocol and / or a communication port) and / or some data descriptive information.

[0193] In particular in certain embodiments, the transmitted descriptive portion may include descriptive information likely to help the second device "impersonate" the equipment, with respect to devices of the second portion or external to the communication network.

[0194] In certain embodiments, for example when the unidirectional communication between the first and the second device is implemented via at least one optocoupler, the method may comprise a serialization 314 of the information to be transmitted from the description before their transmission via the optocoupler.

[0195] The transmission format may differ depending on the implementation. For example, it may be an XML or JSON format. The pseudo-code below illustrates as an example the transmission of the description in a serialized form in the case of the JSON protocol: {'m ' : 'description {JSON description}} where in this example

[0196] • m announces the type of data transmitted (here announcement of data corresponding to a description) • description is a textual label announcing the transmission of a description {JSON description} in JSON format.

[0197] As illustrated in Figure 3, the method may comprise obtaining 320 at least one of the data from said equipment, designated by the data descriptive information of said equipment, and transmitting 340 at least one of the data obtained to the second device (via the unidirectional means).

[0198] The way in which the equipment data is obtained may vary depending on the embodiments and in particular depending on the description obtained 312.

[0199] For example, the first device can connect to the equipment to be protected via at least one protocol described in the description (OPC-UA, ModBus, MQTT, Ethernet, etc.) and read access to at least one of the data (such as a node (for OPC-UA), a “coil” or a “register” (for ModBus)) described in the description. For example, during initialization of the device, all the data of the equipment described in the description can be obtained 320 and transmitted 350 to the second device.

[0200] Obtaining 320 and transmitting 350 at least one piece of data can be performed several times.

[0201] This transmission 350 of at least one piece of data may be optional in certain embodiments. In such embodiments, the method may comprise a storage 360 ​​of the data obtained (at least during the first obtaining of the data) and, after another obtaining of data following this first obtaining, a comparison 330 of the “new” value of at least one piece of data obtained with the currently stored value (therefore with the last value previously obtained for this data). The transmission 350 and / or the storage 360 ​​of the “new” value may then be carried out conditionally, for example only when the new value is different from the previous value.

[0202] Transmission 350 and / or storage 360 ​​may be performed in any order.

[0203] The transmission 350, and possibly the storage 360, can be carried out according to the embodiments either at the end of the water or after obtaining all the data.

[0204] According to the embodiments, obtaining the value of a data item can be done via a query of the equipment (for example a request to read the content of at least one register or a storage area of ​​such data on the equipment), and / or by receiving the value on a communication interface of the first device, at the initiative of the equipment itself (for example via a registration (or subscription) mechanism of the first device with the equipment to receive the value of the data).

[0205] For example, in certain embodiments, the interrogation of the equipment, to obtain at least one data item, can be carried out taking into account information from the description, such as a time interval required between two accesses to the at least one data item and / or possible temporal information limiting access to the at least one of these data items.

[0206] It is noted that the method may comprise in certain embodiments (for example when the unidirectional communication between the first and the second device is implemented via at least one optocoupler) a serialization 340 of the data to be transmitted before their transmission via the optocoupler. Such serialization may help to improve the security of the method, since the data once serialized no longer reveals its structure and may therefore be more difficult to interpret by a malicious third party who intercepts it and does not have knowledge of the protocol (proprietary for example, or standard) to be used to interpret it.

[0207] The transmission format may differ depending on the implementation. For example, it may be XML or JSON format.

[0208] For example, the following serialized data may be transmitted by the first device in a format including in particular in the header an announcement of the type of data transmitted (protocol used or announcement of data corresponding to a description, etc.), a label identifying this type of data, as well as possible text labels or digital code announcing the meaning of the elements which follow them.

[0209] By way of non-limiting example, the following serialized data may be transmitted by the first device in the case of the OPC-UA protocol when a connection between the first device and the equipment has been established for the first time (during or after initialization for example):

[0210] { 'm 'opcua 'ns ' : [ListNamespaces] where

[0211] • m announces the type of data transmitted (the protocol used here)

[0212] • opcua is a text label designating the use of the OPC-UA protocol

[0213] • ns announces the transmission of the “namespaces” to be created by the second device

[0214] • [ListNamespaces] designates the list of equipment namespaces in JSON format

[0215] {'m': 'opcua 'x': [ListNodes]} where

[0216] • x announces the transmission of nodes to be created by the second device

[0217] • [ListNodes] means the list of OPC-UA nodes, their attributes and their value in JSON format

[0218] As another example, the following serialized data may be transmitted by the first device in the case of the OPC-UA protocol following a description update: {“m ' : 'opcua 'n ' : [ListNodes], 'del ' : [true / false]} where:

[0219] • n announces a designation of added or deleted nodes • 'del': announces a boolean [true / false] specifying whether it is an added or deleted node

[0220] According to another example, the following serialized data may be transmitted by the first device in the case of the OPC-UA protocol following an update of at least one node: {'m' : 'opcua', 'u' : {'node' : [Id-Node], 'value' : [NewValue]}}

[0221] • u announces an update of at least one node

[0222] • node announces a node identifier ( / Node-Id]) and value announces the value [NewValue] of this node

[0223] As another example, the following serialized data may be transmitted by the first device after a poll of the equipment in the case of the modBus protocol:

[0224] { ' 'm ' : 'modbus ', 'r ' : [RegisterKey], 'c ' : [CoilKey]}where:

[0225] • modbus is a text label designating the use of the ModBus protocol

[0226] • r announces the transmission of “register” values

[0227] • [RegisterKey], designates the list of equipment registers and their values ​​in JS ON format

[0228] • r announces the transmission of “coils” values

[0229] • [CoilKey] denotes the list of equipment coils and their values ​​in JS ON format

[0230] According to another example, the following serialized data may be transmitted by the first device after receiving an event from the equipment in the case of the MQTT protocol relating to a topic to which the first device has subscribed:

[0231] {'m' : 'mqtt', 't' : [Topic], 'pT : [payload]} where:

[0232] • mqtt is a text label designating the use of the MQTT protocol

[0233] • t announces a transmission relating to the topic [Topic] and

[0234] • pl announces a transmission of the content I pay load / AM message received

[0235] In another example, the following serialized data may be transmitted by the first device after receiving a UDP packet from the equipment: {'m': 'direct', 'p': [packet]}

[0236] • direct is a text label designating the use of the UDP protocol

[0237] • p announces the transmission of a network packet [packet] in Base64 format.

[0238] The serialization 340 of the data before their transmission may be optional in certain embodiments. For example, when the communication between the equipment and the first device, such as unidirectional communication, uses an Ethernet link (without selecting a particular protocol), the data from the equipment may simply be obtained and transmitted in the form of network packets. In other words, it may be a simple transfer of data from the protected equipment to the second device. FIG. 4 illustrates certain embodiments of the method 400 for providing data of the present application. The method 400 may, for example, be implemented by a second device located in a portion of a communication network that is completely separate from a protected portion of this network, such as the second device 164 of the electronic assembly 160 of the system 100.

[0239] Similar to what was described above for the method 300 implemented by the first device, the method 400 can be implemented, depending on the embodiments, when starting the second device, or later, and can comprise, as illustrated in FIG. 4, a so-called initialization phase 410 (when starting the device for example or later, upon receipt of a user command for example).

[0240] This initialization phase 410 includes obtaining 416 a description relating to data that the second device will receive. This data will come from equipment located in a “first” protected portion of the network, inaccessible to the second device. They will be received via a one-way communication established with a first device, and via this first device

[0241] In certain embodiments, the description may be obtained 416 by reception, via a one-way communication between the first and second devices. In such embodiments, the method may comprise an initialization 412 (and / or an establishment) of this one-way communication, prior to this reception, possibly taking into account configuration data, local or remote, accessible to the second device. The method may also comprise a deserialization 414 of the received data (if these have been serialized before their transmission to the second device).

[0242] In some embodiments, the description obtained 416 may be identical to the description described in connection with the method 300 implemented in the first device. For example, the two descriptions may be obtained 312, 416 by copying the same removable storage medium, or the second device may receive from the first device the entire description that the first device itself previously obtained 312. In such embodiments, the description of the second device may then contain certain information not useful to the second device (such as a password, or a public or private key necessary for a connection to the equipment from which the data originates).Such an embodiment can offer advantages in terms of simplicity of processing (first device side) and / or simplicity of configuration, therefore time saving, second device side, since it is not necessary to provide a “description” specific to the second device.

[0243] In other embodiments, the description of the second device may be different from that previously obtained by the first device. In particular, certain information contained in the description previously obtained by the first device may be omitted from the description of the second device. The description obtained 416 by the second device may in particular include identification information of the equipment from which the data originates, and in particular the address of the equipment on the first portion of the network.

[0244] The description obtained 416 may in particular comprise information describing the data (location, size, type, structure, etc.) that the second device is likely to receive from the first device, similar for example to those described in connection with the method implemented by the first device, certain information (such as a time interval between two accesses or temporal information limiting access to at least one piece of data) may be omitted. In certain embodiments, for example depending on the unidirectional communication means implemented between the first and second devices, the description obtained 416 may further comprise information necessary for establishing unidirectional communication from the first device to the second device.This information may be optional, in particular when it is otherwise accessible to the second device, for example via device configuration data (and has for example been previously used to initiate one-way communication between the two devices as mentioned above).

[0245] Optionally, the description may also include information relating to the output format of at least some data before its provision to a third-party device.

[0246] In some embodiments, as explained above, the description may be received from the first device. In other embodiments, the description may be obtained by accessing a storage area accessible to the second device (such as a storage area local to the second device or accessible from the second portion of the network or a removable storage area (such as a USB key) coupled to the second device).

[0247] Similar to what has been described in connection with the protection method 300, in certain embodiments, the provision method 400 may comprise an (optional) update of the obtained description 416, either automatically by the second device, or via a user interface of the second device, to delete certain information from the description or to add new information.

[0248] As illustrated in Figure 4, the method may comprise obtaining 420 the value of at least one data item from the protected equipment. This obtaining may comprise receiving 422 the at least one data item via the unidirectional communication between the first device and the second device. Furthermore, when the data received 422 by the second device is serialized, the method may comprise deserialization 424 of the data. This deserialization may for example use the information of the description obtained 416 (in particular descriptive data information), in order to find the structure of the data before their transmission by the first device. The method may comprise storing the data obtained in a manner consistent with the descriptive data information obtained. For example, in certain embodiments, this may involve storing the data in a manner identical to their storage on the equipment (same address(es), same size, etc.).In other embodiments, it may be stored in a different form (e.g., compressed, so as to save memory space).

[0249] The method may further comprise a transmission 430 of at least some of the data obtained to a third-party device (at the request of this equipment and / or upon subscription of the device to updates of this data for example). This transmission may be preceded by a transcoding (for example a decompression), when the data to be transmitted are stored in a form (format, structure, etc.) different from that in which they are stored on the protected equipment.

[0250] In certain embodiments, the description obtained 416 by the second device may comprise, in addition to the information necessary for obtaining and processing by the second device the data from the equipment, other information. For example, the description obtained may comprise, in addition for example to the address of the equipment on the first portion of the network, certain other information necessary for establishing communication with the equipment such as information designating a protocol that can be used to communicate with the equipment, a port of the equipment that can be used to communicate with the equipment according to this protocol, additional parameters specific to certain protocol(s).Depending on the embodiments, this may be information identical to that contained in the description described in connection with the method 300 of FIG. 3, or information deduced from at least some of the information contained in the description obtained 312 by the first device.

[0251] For example, the description may include information necessary for the second device to receive third-party device requests intended for the equipment, and to respond to them as if those responses came from the equipment.

[0252] In particular, the description may include the address of the equipment on the first portion and the method may include assigning to the second device an address, on the second portion, identical to that of the equipment on the first portion. Such embodiments may thus help an administrator of the communication network to have a “plug and play” solution. Thus, the insertion of the electronic assembly into the network, for the protection of a piece of equipment, may be transparent to other devices already present in the network and may not require modifying a routing (or addressing) plan of the entire network or modifying the software of one of the third-party devices wishing to obtain data from the equipment.

[0253] For example, in some embodiments, the electronic assembly may be installed in an existing network comprising equipment that is (newly) to be protected. When the electronic assembly is installed so as to be able to communicate (for example via a wired link) with the equipment to be protected, thus constituting a first portion of the network (comprising at least the equipment and the first device), a network operator may not have to perform any action (apart from this installation). The data of the equipment described in the description may be automatically duplicated on the second device, and thus made accessible outside the first, protected portion of the network via an address of the second device identical to that of the equipment.As a result, devices and software outside the protected portion of the network can continue to access the equipment's data, without changing the access routine they used before the electronic assembly was installed to protect the equipment. In fact, the connection, from the perspective of these devices and software, can be identical to a direct connection to the equipment.

[0254] The present application proposes an electronic assembly constituting, at least in some of its embodiments, a simple and effective solution for securely uploading data from an industrial machine connected to a public network such as the Internet. In particular, in at least some embodiments, the configuration of at least one of the first and second devices of the electronic assembly can be easy (in particular when it is automatic) and one or other of the devices of the electronic assembly can be usable with several different protocols, which can therefore make it possible to offer a solution adaptable to different industrial environments.

[0255] In certain detailed embodiments in connection with figures 3 and 4, the first device and a second device can be adapted to communicate according to several protocols with, respectively, at least one equipment to be protected and at least one third-party device.

[0256] In one variant (illustrated in Figure 5), the first device and the second device can communicate respectively with an equipment to be protected and a third-party device with a single protocol.

[0257] In a variant, the first device can select the second device with which to communicate according to the unidirectional communication depending on the protocol used to communicate with equipment to be protected (the system 100 comprising for example several “second devices” respectively using different protocols to communicate with third-party devices.

[0258] In another variant, several “first devices” can communicate with the same second device, the latter being able, for example, to have several different addresses, each chosen to correspond to that of a piece of equipment to be protected received from one of the first devices.

[0259] Figure 5 shows an example of implementation of the solution that is the subject of this application to protect three devices. In the example illustrated, each device uses a different communication protocol and is protected by an electronic assembly (smart diode) according to the invention specific to this protocol. The data made available by a smart diode on an exposed portion of the network (and interconnected with the internet) can be used (query, subscription, etc.) by network monitoring devices.

[0260] The solution presented in this application can find applications in many fields, and in particular in areas that are prime targets for computer attacks. Thus, in the manufacturing industry, the solution that is the subject of this application can help protect industrial machines (to prevent their corruption, for example), by preventing access to certain sensitive data from these machines, such as data relating to the industrial processes implemented, while making other data (such as production data) available to monitoring and control applications.

[0261] Another example of implementation concerns the field of distribution. The solution that is the subject of this application can in fact be used to help protect electronic point-of-sale equipment, by limiting the possibilities of access to data stored on this equipment, such as sales data and / or sensitive customer information.

[0262] Yet another example of implementation concerns the field of finance (banking, financial services) and in particular the sensitive financial and personal information handled, which the solution which is the subject of this application can help to protect from attacks (while offering possibilities of access to other data, less sensitive for example).

[0263] The solution that is the subject of this application may also find applications in the health field, to protect patients' sensitive medical data while allowing health professionals to access at least some of this data.

Claims

CLAIMS 1. Method for protecting equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via a first electronic device and a second electronic device in unidirectional communication, so as to only allow communications from the first device to the second device, said method comprising: • obtaining an addressing identifier for said equipment to be protected on said first portion of said communication network, said addressing identifier being obtained dynamically by scanning said first portion; • a transmission to said second device of said addressing identifier; • during communication between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment; • a transmission to said second device, via said unidirectional communication, of the current value obtained.

2. Protection method according to claim 1 comprising obtaining a description relating to said equipment to be protected and comprising at least: • said addressing identifier of said equipment to be protected on said first portion of said communications network; • a designation of at least one communication protocol with said equipment; • said addressing information of at least one piece of data from said equipment accessible for reading via said equipment.

3. Protection method according to claim 2 comprising a transmission to said second device of information identifying said protocol.

4. Protection method according to claim 2 or 3 where said description is obtained dynamically by said first device by scanning said first portion.

5. Protection method according to any one of claims 1 to 4 comprising, upon updating at least one of said at least one accessible data item, a transmission to said second device, via said unidirectional communication, of said updated value.

6. Protection method according to any one of claims 1 to 5 where said current value and / or update of said first data is obtained by interrogating said equipment.

7. Protection method according to claims 2 and 6 where said interrogation of said equipment is carried out several times and where a time interval between two successive interrogations of said equipment takes into account time information included in said description.

8. Method for providing data from at least one device of a communication network partitioned into a plurality of portions comprising at least a first portion, and at least a second portion interconnected with said first portion via a first electronic device and a second electronic device in unidirectional communication, so as to allow only communications from the first device to the second device, said method comprising: • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network; of at least one piece of equipment on said first portion; • upon receipt of a request having as destination address said addressing identifier and relating to at least one first data item of said equipment, a transmission of a value of said at least one first data item, previously obtained via said unidirectional communication, to a sender of said request.

9. Method for providing data according to claim 8, said method comprising: obtaining a description relating to said at least one piece of equipment of said first portion of said communication network comprising said at least one addressing identifier of said at least one piece of equipment on said first portion of said communication network.

10. A method of providing according to claim 9 wherein said description is obtained via said one-way communication.

11. A method of providing according to claim 9 or 10 wherein said description comprises: • a designation of at least one communication protocol with said equipment; • a designation of at least one item of addressing information for at least one item of data of said equipment accessible in reading mode via said equipment of said first portion of said network; and where said request is received according to said protocol and relates to said addressing information.

12. First electronic device of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising equipment to be protected, and at least a second portion interconnected with said first portion via the first device and a second device in unidirectional communication with the first device, so as to allow only communications from the first device to the second device, said first device comprising at least one processor configured to: • obtaining an addressing identifier for said equipment to be protected on said first portion of said communication network, said addressing identifier being obtained dynamically by scanning said first portion; • a transmission to said second device of said addressing identifier; • during communication between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment; • a transmission to said second device, via said unidirectional communication, of the current value obtained.

13. Second electronic device of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising equipment to be protected, and at least a second portion interconnected with said first portion via a first electronic device and said second electronic device in unidirectional communication, so as to allow only communications from the first device to the second device, said second device comprising at least one processor configured to: • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network; of at least one piece of equipment on said first portion; • upon receipt of a request having as destination address said addressing identifier and relating to at least one first data item of said equipment, transmission of a value of said at least one first data item, previously obtained via said unidirectional communication, to a sender of said request.

14. Electronic assembly of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising equipment to be protected, and at least a second portion interconnected with said first portion via a first device of said electronic assembly and a second device of said electronic assembly in unidirectional communication with the first device of said electronic assembly, via unidirectional communication means of said electronic assembly so as to allow only communications from the first device of said electronic assembly to the second device of said electronic assembly, said at least one first device of said electronic assembly comprising at least one first processor configured to: • obtaining an addressing identifier for said at least one piece of equipment to be protected on said first portion of said communication network, said addressing identifier being obtained dynamically by scanning said first portion; • a transmission to said second device of said addressing identifier of said at least one piece of equipment to be protected; • during a connection (or communication) between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment; • a transmission to said second device, via said unidirectional communication, of the current value obtained. And said at least one second electronic device comprising at least one second processor configured to: • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network, of at least one piece of equipment of said first portion; • upon receipt of a request having as destination address said addressing identifier and relating to at least one first data item of said equipment, a transmission of a value of said at least one first data item, previously obtained via said unidirectional communication, to a sender of said request.

15. System comprising at least one piece of equipment to be protected and at least one electronic protection assembly, in a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment to be protected, and at least a second portion interconnected with said first portion via a first device of said electronic protection assembly and a second device of said electronic protection assembly in unidirectional communication with the first device of said electronic protection assembly, via unidirectional communication means of said electronic protection assembly so as to allow only communications from the first device of said electronic protection assembly to the second device of said electronic protection assembly, said at least one first device of said electronic protection assembly comprising at least one first processor configured to: • obtaining an addressing identifier for said at least one piece of equipment to be protected on said first portion of said communication network, said addressing identifier being obtained dynamically by scanning said first portion; • a transmission to said second device of said addressing identifier of said at least one piece of equipment to be protected; • during a connection (or communication) between said equipment to be protected and said first device, obtaining the current value of at least one piece of data from said equipment; • a transmission to said second device, via said unidirectional communication, of the current value obtained. And said at least one second electronic device comprising at least one second processor configured to: • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier, on said first portion of said communication network, of at least one piece of equipment of said first portion; • upon receipt of a request having as destination address said addressing identifier and relating to at least one first data item of said equipment, a transmission of a value of said at least one first data item, previously obtained via said unidirectional communication, to a sender of said request.

16. Computer program comprising instructions for implementing, when said program is executed by a processor, a protection method according to any one of claims 1 to 7 and / or a provision method according to any one of claims 8 to 11.

17. Information medium readable by an electronic device and on which is recorded a computer program comprising instructions for the implementation, when said program is executed by a processor, of a protection method according to any one of claims 1 to 7 and / or of a supply method according to any one of claims 8 to 11.