Methods for the protection of a piece of equipment and for the transmission of data, and corresponding electronic devices and electronic assembly, computer program products and information storage media
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- ORANGE SA
- Filing Date
- 2024-06-26
- Publication Date
- 2026-05-06
AI Technical Summary
Existing network security solutions, such as firewalls and intrusion detection systems, are inadequate for protecting industrial equipment as they restrict communication protocols like OPC-UA and ModBus, preventing external devices from accessing protected equipment while maintaining network security.
A method involving a communication network partitioned into two portions, with a first device in the protected portion and a second device in the exposed portion, using addressing identifiers and filtering rules to conditionally transcode and transmit data packets, allowing secure access while preventing unauthorized access.
Enables secure access to protected equipment while maintaining network security by filtering and transcoding data packets based on specific rules, allowing only authorized access requests to proceed, thus protecting sensitive data and preventing malicious attacks.
Smart Images

Figure EP2024067921_02012025_PF_FP_ABST
Abstract
Description
[0001] DESCRIPTION
[0002] Title of the invention: Methods for protecting equipment and transmitting data, electronic devices and assemblies, computer program products and corresponding information media
[0003] Technical field
[0004] This application relates to the field of securing at least a portion of a communications network.
[0005] It relates in particular to a method for protecting at least one item of equipment, implemented by a first electronic device of a first portion of a communication network, and a method for transmitting data(s), implemented by a second electronic device of a second portion of a communication network, as well as the corresponding electronic devices and assemblies, computer program products and information media.
[0006] 1. State of the art
[0007] The present invention relates to the protection of at least one piece of equipment accessible via a communications network. This may, for example, be equipment handling sensitive data, or carrying out sensitive processing, and may therefore be the target of attack by malicious third parties, either to unduly access sensitive data, or to disrupt, or even prevent, certain processing via the propagation of a computer virus to the equipment.
[0008] This equipment is, for example, part of a private company network or a home network, interconnected to a public network such as the Internet.
[0009] Examples of sensitive data include personal data (medical data, banking data, etc.), industrial data (such as plans of manufactured objects, data relating to the production of certain industrial machines such as measurement results, number of parts produced, etc.), history of orders received by industrial equipment, alerts, etc.
[0010] Malicious third parties may, for example, be tempted to disable equipment to harm a company or obtain a ransom. Private network security solutions have been developed to protect one or more devices belonging to the same private network from such attacks. Examples include solutions based on firewalls and / or intrusion detection systems.We can also cite the use of virtual private networks (VPN) (or VPN for Virtual Private Network according to the English terminology) isolating by encryption, within a wide area network, the exchanges between the equipment of the wide area network belonging to the virtual private network. Such solutions make it possible to limit communications with equipment outside the private network to communications sent from the private network to this "external" equipment, and thus prevent access from outside the network to equipment to be protected.
[0011] However, these solutions, sometimes called "network diodes", are sometimes inappropriate and very restrictive for protecting certain electronic equipment such as industrial machines. Indeed, such solutions only allow information to be sent back at the initiative of the protected equipment. Software running on an electronic device outside the private network cannot therefore query a protected equipment to obtain data in return. Such solutions severely limit, or even prevent, the use of certain communication protocols based on such requests, particularly certain protocols that are very widespread in the industrial sector (such as, in the industrial sector, the OPC-UA or ModBus protocols used by many machine tools on the market). They are therefore not suitable for protecting certain equipment on the market.
[0012] The present application aims to propose improvements to at least some of the disadvantages of the state of the art.
[0013] 2. Statement of the invention
[0014] The present application aims to improve the situation using a method for protecting at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via a first device of said first portion and a second device of said second portion, said method comprising:
[0015] • a transmission to said second device of at least one addressing identifier of said equipment of said first portion of said communication network;
[0016] • a transcoding of data received from said second device into at least one structured data packet comprising at least one addressing identifier of a device receiving said packet on said first portion;
[0017] • a transmission of said packet to said recipient equipment; at least one of said transcoding and / or transmission being carried out conditionally, taking into account at least one filtering rule relating to the content of said packet.
[0018] In some embodiments, said filtering rule takes into account at least one element contained in said packet among the following elements:
[0019] • a designation of a device transmitting said packet;
[0020] • addressing information relating to at least one piece of data from said equipment;
[0021] • a type of access to be carried out on said data;
[0022] • a designation of a communication protocol used by said package;
[0023] • a combination of at least two of the above elements.
[0024] In some embodiments, said filtering is performed before said transcoding. In some embodiments, said filtering is performed after said transcoding.
[0025] In some embodiments, said first and second devices communicate with each other via at least two communication paths, a first unidirectional communication path allowing the first device to receive data from said second device, and a second unidirectional communication path allowing the first device to send to said second device a response to said packet transmitted to said recipient equipment.
[0026] In some embodiments, said transcoding comprises deserialization of said data.
[0027] The present application also relates to a method for transmitting at least one piece of data intended for at least one piece of equipment in a communication network partitioned into a plurality of portions comprising at least a first portion, and at least a second portion interconnected with said first portion via a first device of said first portion and a second device of said second portion; said method comprising:
[0028] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier of a piece of equipment in said first portion
[0029] • upon receipt of a structured data packet having as destination address said addressing identifier, a serialization of the data of said packet; and
[0030] • a transmission of said serialized data to said first device. at least one of said serialization and / or said transmission being carried out conditionally taking into account at least one filtering rule relating to the content of said packet.
[0031] In some embodiments, said filtering rule takes into account at least one element contained in said packet among the following elements:
[0032] • a designation of a device transmitting said packet;
[0033] • addressing information relating to at least one piece of data from said equipment;
[0034] • a type of access to be carried out on said data;
[0035] • a designation of a communication protocol used by said packet;
[0036] • a combination of at least two of the above elements.
[0037] In certain embodiments, the transmission method comprises obtaining a description relating to said equipment of said first portion of said communication network comprising said at least one addressing identifier of said at least one equipment on said first portion of said communication network.
[0038] In some embodiments, said filtering is performed on the serialized data. In some embodiments, said filtering is performed before said serialization. In some embodiments, said first and second devices communicate with each other via at least two unidirectional communication paths, a first unidirectional communication path allowing the second device to transmit data to said first device, and a second, unidirectional communication path allowing the second device to receive from the first device a response to said data transmitted to said first device.
[0039] The features presented in isolation in the present application in connection with certain embodiments of one of the methods of the present application can be combined with each other according to other embodiments of this method.
[0040] According to another aspect, the present application also relates to an electronic device adapted to implement at least one of the methods of the present application in any of its embodiments.
[0041] The present application thus relates to a first electronic device of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising at least one piece of equipment to be protected and said first device, and at least a second portion interconnected with said first portion via the first device and a second device of said second portion, said first device comprising at least one processor configured to:
[0042] • a transmission to said second device of at least one addressing identifier of said equipment of said first portion of said communication network;
[0043] • a transcoding of data received from said second device into at least one structured data packet comprising at least one addressing identifier of a device receiving said packet on said first portion;
[0044] • a transmission of said packet to said recipient equipment; at least one of said transcoding and / or transmission being carried out conditionally taking into account at least one filtering rule.
[0045] The present application also relates to a second electronic device of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising at least one piece of equipment, and at least a second portion comprising said second device, and interconnected with said first portion via a first device of said first portion and the second device; said second device comprising at least one processor configured to:
[0046] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier of a piece of equipment in said first portion
[0047] • upon receipt of a structured data packet having as destination address said addressing identifier, a serialization of the data of said packet and; • a transmission of said serialized data to said first device. at least one of said serialization and / or said transmission being carried out conditionally taking into account at least one filtering rule relating to the content of said packet.
[0048] According to another aspect, the present application also relates to an electronic assembly for protecting at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via at least a first device of said electronic assembly, said first device belonging to said first portion, and at least a second device of said electronic assembly, said second device belonging to said second portion, said at least one first electronic device comprising at least one processor configured to:
[0049] • a transmission to said second device of at least one addressing identifier of said equipment of said first portion of said communication network;
[0050] • a transcoding of data received from said second device into at least one first structured data packet comprising at least one addressing identifier of a recipient device of said first packet on said first portion;
[0051] • a transmission of said first packet to said recipient equipment; at least one of said transcoding and / or transmission being carried out conditionally taking into account at least one first filtering rule relating to the content of said first packet. said at least one second electronic device comprising at least one processor configured to:
[0052] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier of a piece of equipment in said first portion
[0053] • upon receipt of a second structured data packet having as destination address said addressing identifier, a serialization of the data of said second packet and;
[0054] • a transmission of said serialized data to said first device. at least one of said serialization and / or said transmission being carried out conditionally taking into account at least one second filtering rule relating to the content of said second packet.
[0055] According to another aspect, the present application also relates to a system comprising at least one piece of equipment to be protected and at least one electronic assembly for protecting said at least one piece of equipment, in a communication network partitioned into a plurality of portions comprising at least a first portion comprising said equipment, and at least a second portion interconnected with said first portion via at least a first device of said electronic assembly, said first device belonging to said first portion and at least a second device of said electronic assembly, said second device belonging to said second portion,: said at least one first electronic device comprising at least one processor configured to:
[0056] • a transmission to said second device of at least one addressing identifier of said equipment of said first portion of said communication network;
[0057] • a transcoding of data received from said second device into at least one first structured data packet comprising at least one addressing identifier of a recipient device of said first packet on said first portion;
[0058] • a transmission of said first packet to said recipient equipment; at least one of said transcoding and / or transmission being carried out conditionally taking into account at least one first filtering rule relating to the content of said first packet; said at least one second electronic device comprising at least one processor configured to:
[0059] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier of a piece of equipment in said first portion
[0060] • upon receipt of a structured data packet having as destination address said addressing identifier, a serialization of the data of said second packet and;
[0061] • a transmission of said serialized data to said first device. at least one of said serialization and / or said transmission being carried out conditionally taking into account at least one second filtering rule relating to the content of said second packet.
[0062] The present application also relates to a computer program comprising instructions for implementing the various embodiments of at least one of the above methods, when said program is executed by a processor, and an information medium readable by an electronic device and on which the computer program is recorded.
[0063] The present application thus relates to a computer program comprising instructions for implementing, when the program is executed by a processor of a first electronic device, a method for protecting at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment and said first device, and at least a second portion interconnected with said first portion via the first device and a second device of said second portion, said method comprising:
[0064] • a transmission to said second device of at least one addressing identifier of said equipment of said first portion of said communication network;
[0065] • a transcoding of data received from said second device into at least one structured data packet comprising at least one addressing identifier of a device receiving said packet on said first portion;
[0066] • a transmission of said packet to said recipient equipment; at least one of said transcoding and / or transmission being carried out conditionally taking into account at least one filtering rule relating to the content of said packet.
[0067] Furthermore, the present application relates to a computer program comprising instructions for implementing, when the program is executed by a processor of a second electronic device, a method for transmitting at least one piece of data from at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, and at least a second portion, comprising said second device and interconnected with said first portion via a first device of said first portion and the second device; said method comprising:
[0068] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier of a piece of equipment in said first portion
[0069] • upon receipt of a structured data packet having as destination address said addressing identifier, a serialization of the data of said packet and;
[0070] • a transmission of said serialized data to said first device. at least one of said serialization and / or said transmission being carried out conditionally taking into account at least one filtering rule relating to the content of said packet.
[0071] The present application also relates to an information medium readable by a processor of a first electronic device and on which is recorded a computer program comprising instructions for implementing, when the program is executed by the processor, a method for protecting at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment and said first device, and at least a second portion interconnected with said first portion via the first device of said first portion and a second device of said second portion, said method comprising:
[0072] • a transmission to said second device of at least one addressing identifier of said equipment of said first portion of said communication network; • a transcoding of data received from said second device into at least one structured data packet comprising at least one addressing identifier of a recipient equipment of said packet on said first portion;
[0073] • a transmission of said packet to said recipient equipment; at least one of said transcoding and / or transmission being carried out conditionally taking into account at least one filtering rule relating to the content of said packet.
[0074] The present application further relates to an information medium readable by a processor of a second electronic device and on which is recorded a computer program comprising instructions for implementing, when the program is executed by the processor, a method for transmitting at least one piece of data from at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, and at least a second portion comprising said second device and interconnected with said first portion via a first device of said first portion and the second device of said second portion, said method comprising:
[0075] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier of a piece of equipment in said first portion;
[0076] • Upon receipt of a structured data packet having as destination address said addressing identifier, a serialization of the data of said packet and;
[0077] • A transmission of said serialized data to said first device. at least one of said serialization and / or said transmission being carried out conditionally taking into account at least one filtering rule relating to the content of said packet.
[0078] The above-mentioned programs may use any programming language, and may be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0079] The information (or recording) media referred to in this application may be any entity or device capable of storing the program. For example, an information medium may comprise a storage medium, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording medium.
[0080] Such storage means can be, for example, a hard disk, flash memory, etc.
[0081] On the other hand, an information carrier may be a transmissible information carrier such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means. A program according to the invention may in particular be downloaded from a network such as the Internet.
[0082] Alternatively, an information carrier may be an integrated circuit in which a program is incorporated, the circuit being adapted to execute or to be used in the execution of any of the embodiments of at least one of the methods which are the subject of the present patent application.
[0083] Generally speaking, by obtaining an element, we mean in the present application for example a reception of this element from a communication network, an acquisition of this element (via for example user interface elements, sensors, etc.), a creation of this element by various processing means such as by copying, encoding, decoding, transformation etc. and / or an access of this element from a local or remote storage medium accessible to at least one device (such as the first and / or the second device of the set) implementing, at least partially, this obtaining.
[0084] 3. Brief description of the drawings
[0085] Other characteristics and advantages of the invention will appear more clearly on reading the following description of particular embodiments, given as simple illustrative and non-limiting examples, and the appended drawings, among which:
[0086] [Fig 1] shows a simplified view of an exemplary system in which at least some embodiments of the methods of the present application may be implemented,
[0087] [Fig 2] shows a simplified view of a device suitable for implementing at least certain embodiments of at least one of the methods of the present application,
[0088] [Fig 3] presents an overview of the method of protecting the present application, in certain of its embodiments.
[0089] [Fig 4] shows an overview of the data transmission method of the present application, in some of its embodiments.
[0090] [Fig 5] a simplified view of an exemplary system 500 in which at least some embodiments of the method of the present application may be implemented.
[0091] 4. Description of the embodiments
[0092] The present application aims to provide a simple and effective solution allowing both to protect one or more devices of a communication network against computer attacks, in particular external to this communication network, while allowing electronic devices, located for example in an unprotected portion of the communication network or outside the communication network, to access (in reading and writing) and in a secure manner, at least certain data of these devices to be protected. To this end, the application proposes to equip the communication network with at least two devices, these devices realizing a partition of the communication network into at least two portions.
[0093] By partition, we mean here a division of the communication network into a plurality of portions each comprising at least one electronic device, separated two by two (except for certain interconnection elements between the at least two devices as specified below) and the union of which reconstitutes the communication network.
[0094] At least a first of these portions is a portion (called "protected") inaccessible directly from an electronic device located outside this first portion, this first portion comprising at least one piece of equipment to be protected. At least a second portion called "exposed" (i.e. external to this first protected portion) is accessible, directly and / or via interconnection equipment, to devices outside the first portion (such as devices located in a "first" protected portion other than the first "protected" portion where the equipment is located, and / or devices of the second portion, and / or devices outside the communication network).
[0095] The equipment(s) to be protected may, for example, be industrial machines.
[0096] According to the present application, requests for access to equipment from a device external to the first portion are filtered by the first and / or the second device, in application of filtering rules, so as to retain only access requests deemed safe. For example, only requests concerning non-critical equipment of the first portion may be retained. According to another example, only requests to read memory zone(s) of equipment of the first portion may be retained. According to yet another example, only write requests relating to "non-critical" memory zones of equipment of the first portion issued by certain devices (such as a device of a network administrator) may be retained.
[0097] Different federation rules may be applied by the first and / or second devices. For example, in network topologies where the first device may receive requests from multiple second devices each interconnecting the first (protected) portion with different exposed second portions, the federation rule(s) applied by the first device may take into account the second device from which the requests were received. In particular, in some embodiments, the first device may receive requests from a "second device" implementing no federation.
[0098] These may also be identical or similar rules. Applying the same rule to the second device and then to the first device may allow, at the second device, to delete certain packets earlier in the processing chain (in accordance with the federation rules), thus avoiding unnecessary processing. At the first device, it may protect against possible corruption of the second device (located in an "exposed" portion of the network) and in particular of its federation rules.
[0099] In some embodiments, the first device and the second device communicate only via one-way communication means. Thus, third-party device requests received by the second device may be transmitted by the second device (from the exposed portion) to the first device via a first one-way communication path. Allowing only one-way communications may help to better control exchanges between a third-party device and equipment (via the electronic assembly) and therefore to better prevent attacks from third-party devices.
[0100] It is noted that messages, corresponding for example to “UDP” messages from the equipment or to possible responses to requests, can be transmitted via a second unidirectional communication path from the protected portion to the exposed portion. Examples of responses include, when it is a read request, data values from the equipment receiving the request and / or in the case of a write request, a confirmation of receipt of the request or a confirmation of writing. In certain embodiments, as illustrated 1, the messages (such as “UDP” messages or responses) are transmitted from the first device to the second device (via the second communication path). Alternatively, they can be transmitted transparently to the first and second devices (via a second communication path not passing through the first and second devices).In certain embodiments, where the messages pass through the first and second devices, message filtering may optionally be implemented by the first device and / or the second device (so as to ensure, for example, that no sensitive data can be communicated to a device external to the first portion). This filtering may be based on rules that are identical or similar to those used during the first communication path (for example, they may relate to the same registers) or on different rules.
[0101] Thus, according to the present application, it is possible to receive requests from a third-party device wishing to obtain data from the equipment to be protected, and to provide it with this data in return, in complete security for the equipment to be protected.
[0102] This application may in particular help both to protect a portion of the network, while allowing the control of at least certain equipment in this first portion from outside the network.
[0103] The logical assembly comprising the at least one first and second devices and the means of communication (unidirectional for example) between these at least two devices is also called in the present patent application "electronic assembly", "electronic protection assembly" or "Smart Diode" (or Smart Diode according to the English terminology). Depending on the embodiments, it may be a virtual assembly, virtually encapsulating the first and second devices and first unidirectional communication means in a first direction of communication (from the second device to the first device), and optionally second unidirectional communication means in a second direction of communication, opposite to the first direction) or a physical assembly (such as a hardware element), having for example a housing in which the at least one first and second devices and their means of mutual communication are installed.This assembly may include, depending on the embodiments and the topology of the network (for example the number of portions to be protected), a variable number of “first” devices and “second” devices.
[0104] Such an electronic assembly offers the advantage of being easy to install in a communication network, for example as an "intermediary" between a (particular) piece of equipment to be protected and the rest of the communication network, or in such a way as to limit access to this equipment to be protected to only accesses made by the first device or simply to limit access to the equipment to be protected to devices located in a (protected) portion of the communication network, to which this equipment belongs. Such an assembly can also help to offer a "turnkey" product to a communication network administrator.
[0105] Such an electronic assembly can thus help, at least in certain embodiments, to secure equipment to be protected, without requiring modification and / or replacement of this equipment.
[0106] For the sake of clarity, the term "electronic equipment" or "equipment" is used in this application to refer to equipment that may be protected by the electronic assembly. The term "electronic device" or "device" will be used to refer to the first or second electronic device of the electronic assembly 160 introduced above. The term "electronic device" or "device" relates to any electronic device (it may sometimes be equipment to be protected or a device of the electronic assembly).
[0107] The present application is now described in more detail in connection with Figure 1.
[0108] Figure 1 shows a system 100 in which certain embodiments of the invention can be implemented. A system 100 comprises one or more electronic devices, at least some of which can communicate with each other via one or more communication networks 110, 120, 130 which may be partitioned and / or interconnected. In the example illustrated, the system thus comprises a private network partitioned into two portions 110, 120. One of the portions 120 is further interconnected with another network 130 (such as a wide area and / or public network), thus allowing communications between electronic devices 150, 164, 170 of this portion 120 and electronic devices 180 not belonging to the private network.
[0109] A private network may for example be a private business or home network, for example a local private network (or UAN for Local Area Network, according to English terminology). The other network 130 may for example be another local network, or a “wide” network with significant geographical coverage, such as a metropolitan area network (or MAN, for Metropolitan Area Network, according to English terminology) or a network whose geographical area covers at least one region of a country, or a country (or WAN, for Wide Area Network, according to English terminology). It may for example be a WAN network of the internet type, or cellular, GSM - Global System for Mobile Communications, UMTS - Universal Mobile Telecommunications System, Wifi - Wireless, etc.). As illustrated in FIG. 1, the system 100 may also comprise a non-interconnected portion 110 of the private network, called protected, comprising one or more electronic devices 140.This may include equipment such as a terminal (such as a laptop, smartphone, tablet or connected object), a connected object (such as a robot, an automatically and / or remotely guided mobile device, an energy meter, a machine tool in the case of a private industrial network, and / or household appliances in the case of a home network), a server, for example an application server, and / or a storage device.
[0110] The equipment of the non-interconnected portion 100 may use different communication protocols depending on the embodiments, such as OPCUA (for OPen Connectivity - Unified Architecture), MQTT (for Message Queuing Telemetry Transport in English), ModBus TCP, Siemens S7, MTConnect, LabView. These protocols may differ depending on the equipment of the non-interconnected portion.
[0111] According to the present application, a device not belonging to a first protected portion (such as a device not belonging to the communication network, or belonging to the second “exposed” portion of the communication network) transmits a data packet (a request to read or write from / in a memory area for example) intended for equipment in the first portion.The second device intercepts this data packet, optionally decides whether or not to keep this data packet based on a filtering rule (hereinafter called the “second” filtering rule with reference to the “second” device) and, if applicable (if the packet complies with this second filtering rule), transcodes this packet into serialized data and transmits it to the first device, located in the protected portion, where this data is again filtered by the first device before being transcoded in the form of at least one new data packet (having, depending on the embodiments, a structure identical to or different from that of the packet sent by the third-party device). This or these new packets is / are then transmitted to a device receiving the first portion.The response from the third-party equipment may then be transmitted via the first and second devices to the third-party device that sent the data packet (e.g., using a data serialization / deserialization mechanism with and / or without filtering).
[0112] Thus, according to the present application, it is possible to receive requests from a third-party device wishing, for example, to access, in reading and / or writing, data from the equipment to be protected, and to provide it with this data in return, in complete security for the equipment to be protected. The system comprises at least one electronic assembly 160 as introduced above aimed at protecting at least certain electronic equipment 140 of the private network 110. The first device 162 of the electronic assembly 160 is located in a portion 110 called "to be protected" of the private network comprising the equipment 140 to be protected.The first device 162 communicates with the second device 164 (located in the interconnected portion 120) via unidirectional communication means 1622, 1624, 1642, 1644, comprising for example first unidirectional communication means 1622, 1642 in a first direction of communication, and second unidirectional communication means 1624, 1644 in a second direction of communication, opposite to the first direction. Such unidirectional communication means may vary according to the embodiments (and in particular according to the hardware capabilities of the first and / or the second device).In certain embodiments, the unidirectional communication means may comprise at least one optocoupler, and / or bidirectional communication means having been limited to a single direction of transmission, such as an Ethernet cable, a serial link and / or an optical fiber and / or at least one digital isolator with galvanic, capacitive, inductive and / or optical isolation.
[0113] In some embodiments, the first and second communication means may be different. For example, the second device may transmit data to the first device via an Ethernet link limited to one direction of communication and the first device may transmit data to the second device via an optocoupler. In other embodiments, the first and second communication means may be similar. For example, each of the first and second unidirectional communication means may include an optocoupler 166.
[0114] The presence of optocoupler(s) allows the two devices to be physically separated (no electrical flow is exchanged, just light), and therefore to reinforce the security of the exchanges. Electrically isolating the devices from each other can help, for example, to prevent attacks by injecting current or electrical signals into the second portion of the said network.
[0115] The system may also include network management and / or interconnection elements 164, 170. In particular (and even if not illustrated in FIG. 1), in certain embodiments, the electronic assembly 160 may include at least one interconnection gateway with another network. In certain embodiments, this gateway may for example be connected to the second device of the electronic assembly (and therefore allow an interconnection between the “exposed” portion of the private network and the other network). In other embodiments, the second device may itself play the role of an interconnection gateway between the “exposed” portion of the private network and the other network.
[0116] The private network can, for example, use wired connections such as at least one serial connection and / or one Ethernet connection, or wireless communication means. The network can implement a communication protocol such as ModBus Serial, or CAN (an acronym for "Controller Area Network") in the case of a serial connection, or such as ModBus TCP, OPC-UA, MQTT in the case of an Ethernet connection.
[0117] Figure 2 illustrates a simplified structure of an electronic device 200 of the system 100, for example the first device 162, the first device 162, and / or the equipment to be protected 140 of Figure 1. Depending on the embodiments, it may be a server, and / or a terminal, or even a microcomputer with a simple human-machine interface such as a RaspberryPi ©, an OrangePi © or even a NanoPl NEO.
[0118] The device 200 comprises in particular at least one memory M 210. The device 200 may in particular comprise a buffer memory, a volatile memory, for example of the RAM type (for “Random Access Memory” according to English terminology), and / or a non-volatile memory (for example of the ROM type (for “Read Only Memory” according to English terminology). The device 200 may also comprise a processing unit UT 220, equipped for example with at least one processor P 222, and controlled by a computer program PG 212 stored in memory M 210. At initialization, the code instructions of the computer program PG are for example loaded into a RAM memory before being executed by the processor P.In the case where the apparatus is the first device 162 and / or the second device 164 of the electronic assembly, said at least one processor P 222 of the processing unit UT 220 can in particular implement, individually or collectively, any one of the embodiments of at least one of the methods of the present application (described in particular in relation to figures 3 and 4), according to the instructions of the computer program PG.
[0119] The device may also comprise, or be coupled to, at least one I / O input / output module 230. The at least one I / O input / output module 230 of the device may comprise, in certain embodiments, at least one module for interfacing with a user of the device (also referred to more simply in this application as a “user interface”). By user interface of the device, we mean for example an interface integrated into the device 200, or a part of a third-party device with which it is coupled by wired or wireless communication means. For example, it may be a secondary screen of the device.
[0120] A user interface may in particular be a user interface, called an “output” user interface, adapted to rendering (or controlling a rendering) of an output element of a computer application used by the device 200, for example an application running at least partially on the device 200 or an “online” application running at least partially remotely, for example on a server. Examples of output user interfaces of the device include one or more screens, in particular at least one graphical screen (touch screen for example), one or more speakers, a connected object.
[0121] By rendering, we mean here a restitution (or “output” according to English terminology) on at least one user interface, in any form, for example including textual, audio and / or video components, or a combination of such components.
[0122] Furthermore, a user interface may be a so-called "input" user interface, adapted to acquire a command from a user of the device 200. This may in particular be an action to be performed in connection with a returned item, and / or a command to be transmitted to a computer application used by the device 200, for example an application running at least partially on the device 200 or an "online" application running at least partially remotely, for example on a server. Examples of input user interfaces include a sensor, an audio and / or video acquisition means (microphone, camera (webcam) for example), a keyboard, a mouse.
[0123] The device may also comprise, or be coupled to, at least one I / O input / output module 230, such as a communication module, allowing the device 200 to communicate with at least one other device of the system 100, via wired or wireless communication interfaces. For example, it may be at least one Ethernet type interface, and / or Wifi, Bluetooth type.
[0124] In the case where the apparatus is the first device 162 or the second device 164 of the electronic assembly, the communication means 1622, 1622, 1642, 1644 comprise for example first unidirectional communication means 1622, 1642 in a first direction of communication, and second unidirectional communication means 1624, 1644 in a second direction of communication, opposite to the first direction, such as at least one Ethernet type interface, or at least one serial interface with an optocoupler of the electronic assembly 160. In the example of FIG. 1, the optocoupler can be connected directly to the serial interface. For example, the transmission port of the first device (protected portion) can be connected to one pin of the optocoupler and the reception port of the second device (exposed portion) can be connected to another pin of the optocoupler.Each side of the optocoupler can be supplied with voltage from the first and second device respectively (e.g. with a voltage of 3.3V).
[0125] In certain embodiments, when the device 200 belongs to a first portion to be protected, the communication means of the device (except possibly the unidirectional communication means above when the device is the first device) may be only family communication means, so as to physically limit the possibilities of access (directly or via this device) to equipment to be protected located in the same portion to be protected of the network (and therefore the possibilities of attacks by third parties). Thus, at least one of the first and second devices 162, 164 may be a microcomputer of the “NanoPi NEO” © type, equipped only with an Ethernet port (and no Wifi).
[0126] Said at least one microprocessor of the first device 162 can in particular be adapted for:
[0127] • a transmission to said second device of at least one addressing identifier of said equipment of said first portion of said communication network;
[0128] • a transcoding of data received from said second device into at least one structured data packet comprising at least one addressing identifier of a device receiving said packet on said first portion;
[0129] • a transmission of said packet to said recipient equipment; at least one of said transcoding and / or transmission being carried out conditionally taking into account at least one filtering rule relating to the content of said packet.
[0130] Said at least one microprocessor of the second device 164 can in particular be adapted for:
[0131] • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier of a piece of equipment in said first portion
[0132] • upon receipt of a structured data packet having as destination address said addressing identifier, a serialization of the data of said packet and;
[0133] • a transmission of said serialized data to said first device. at least one of said serialization and / or said transmission being carried out conditionally taking into account at least one filtering rule relating to the content of said packet.
[0134] Some of the above input-output modules are optional and may therefore be absent from the equipment to be protected, the first device and / or the second device in certain embodiments.
[0135] The electronic assembly introduced above may comprise, in certain embodiments, a physical housing in which the first and second devices and the means of bidirectional communication between the first device and the second device are housed. The housing may, for example, limit or prevent physical access to the first and second devices and their means of mutual communication. It may in particular be a housing closed by a non-repositionable guarantee strip, or a sealed housing, so as to make any opening of the housing visible, due to deterioration of a seal or the guarantee strip, or to make it difficult to open.The housing may, for example, provide physical access to at least certain communication interfaces of the first and / or second device (other than the means of mutual communication between these two devices, for example) and / or include communication interfaces connected to at least certain of the communication interface(s) of the first and second device.
[0136] In some embodiments, the housing may only provide access to certain wired communication interfaces of the first device. For example, this may involve "forcing" the use of certain communication interfaces between the equipment and the first device, offering, for example, advantages in terms of security (for example, due to the protocol involved in such interfaces) or favoring the use of "wired" interfaces. In some embodiments, the housing may allow free access to several communication interfaces of the first and second devices, so as to provide a set adapted to different network environments.
[0137] In certain embodiments, for example when the electronic assembly introduced above does not prevent access to certain interfaces of the first device, some of these interfaces can be deactivated in software (for example not providing any service), so that third-party equipment cannot access in reading and / or writing (via an SHH connection in the case of an Ethernet link for example) the description of the first device and data of the equipment stored by the first device.
[0138] The term "module" or the term "component" or "element" of the device is understood here to mean a hardware element, in particular wired, or a software element, or a combination of at least one hardware element and at least one software element. The method according to the invention can therefore be implemented in various ways, in particular in wired form and / or in software form.
[0139] Figure 3 illustrates certain embodiments of the method 300 for protecting the present application (implemented for example by a first device of an electronic assembly according to the invention) and Figure 4 illustrates certain embodiments of the method 400 for providing data of the present application (implemented for example by a second device of an electronic assembly according to the invention). The method 400 (before the method 300) is now described to respect a chronological order of processing of a request (such as read / write access to equipment) received from a third-party device, and thus facilitate the reading of the present patent application.
[0140] The method 400 can for example be implemented by a second device located in a portion of a communication network completely distinct from a protected portion of this network, such as the second device 164 of the electronic assembly 160 of the system 100.
[0141] According to the embodiments, the method can be implemented automatically at startup of the second device (via a script executed at startup ("boot") of the device) or later, for example following the launch, manually or automatically (via a background task for example) of an executable implementing at least one embodiment of the method 400. The method can notably comprise, as illustrated in FIG. 4, a so-called initialization phase 410 (during startup of the second device for example or subsequently, upon receipt of a user command for example). This initialization phase 410 comprises an establishment 412 (initialization and / or establishment) of communications (for example unidirectional) from the second device to the first device, and optionally unidirectional communications from the first device to the second device.
[0142] This initialization phase 410 also includes obtaining 414 a description, which may take the form of one or more files in YAML, XML or JSON format for example. This description may in particular include information relating to the requests that the second device will receive (format of the packets to be received for example), and / or information relating to filtering rules that the second device must apply, and / or information relating to equipment for which a packet that will be received by the second device may be intended (such as an identifier of this equipment, a designation of at least one protocol that it can use, etc.), information relating to the data to be transmitted to the first device (protocol to be used, format, etc.).In some embodiments, the description may also include information necessary for establishing one-way communication between the second device and the first device and vice versa (such as an address of the first device on the communication network, a data format and / or a protocol to be used to communicate with the first device, etc.).
[0143] In other embodiments, where the description is for example at least partially received from the first device via the mutual communication means, the information necessary for establishing a one-way communication between the second device and the first device can be obtained by the second device (via configuration data locally accessible to the second device or remotely for example) prior to setting up 412 the two-way communication means and obtaining 414 the description. When the description is received by the second device, obtaining the description can comprise a deserialization of the data (corresponding to the description) received (if the content of the description has been serialized before its transmission to the second device).
[0144] The format for receiving the description may differ depending on the implementation. For example, it may be an XML or JSON format. The pseudo-code below illustrates, as an example, the transmission of the description in a serialized manner in the case of the JSON protocol: {'m ' : 'description {JSON description}} where in this example
[0145] • m announces the type of data transmitted (here announcement of data corresponding to a description)
[0146] • description is a text label announcing the transmission of a description {JSON description} in JSON format.
[0147] As explained above, in some embodiments, the description may be received from the first device. In other embodiments, the description may be obtained by accessing a storage area accessible to the second device, such as a storage area local to the second device or accessible from the second portion of the network or a removable storage area (such as a USB key) coupled to the second device.
[0148] Concerning more specifically the information relating to the packets to be received, the description obtained 414 may in particular include information describing at least one protocol (such as Ethernet) to be used to receive these packets, a size of the packets, a format (or structure) of the packets, a reception rate, etc.
[0149] Examples of protocols include hierarchical protocols, using standardized data structures, such as Open Platform Communications Unified Architecture (OPC-UA) and ModBus, or non-hierarchical protocols such as MQTT and Direct Datagram Protocol (UDP).
[0150] Concerning the information relating to at least one filtering rule that the second device must apply, they may include for example: a designation of at least one accepted or prohibited protocol; a designation of at least one network domain whose requests, when issued from this domain, will be accepted or prohibited; an identifier of at least one device, issuer of a request, accepted or prohibited; a designation of at least one portion of the network accepted or prohibited as a portion to which a recipient of a request belongs; an identifier of at least one device accepted or prohibited as a recipient of a request; a type of access request (read, write, etc.) accepted or prohibited; a range of addresses accepted or prohibited as parameters of a request; a parameter accepted or prohibited in connection with a particular protocol (such as a “topic” for MQTT for example) a combination of at least two of said information.
[0151] Some of this information may be optional in certain embodiments. Concerning the information relating to a device for which a packet may be intended, it may notably include an addressing identifier of this device (for example, according to the protocols, an IP address, a MAC address of at least one access point, etc.), a designation of at least one protocol that it accepts, a communication port open on this device.
[0152] In embodiments where the electronic assembly comprises means for unidirectional communication from the first device to the second device, the description may also comprise information relating to data to be received from the first device in response to the second device sending a request from a third-party device. This may for example be a protocol to be used to receive this data, and / or a size, type and / or format of this data, or a protocol to be used to transmit this data, and / or an output format of this data to be used for its transmission to a third-party device.
[0153] Some of the above information may be optional in the description in certain embodiments.
[0154] An example of a description is presented below.
[0155] In this example, the description concerns several devices. The term "devices" announces a list of devices to be protected (designated by their respective IP addresses), each accessible by a different protocol in this example. For each, we find the authorized ports, the authorized transmitters (sources) (designated by their respective IP addresses), the type of possible access and the registers, the "namespaces" (for OPC-UA), topic (for MQTT), http requests (for MTConnect) authorized by type of access. config ve sion : 1.0 config date: 2023-05-15 diode: hostname: SmartDiode devices:
[0156] "192.168.0.5": type: modbus ports:
[0157] - 9400
[0158] - 502 sources:
[0159] - '192.168.0.1 ' read:
[0160] - 0-105
[0161] - 200-420 write:
[0162] - 1-12
[0163] - 200-202
[0164] - 400
[0165] "192.168.0.11": type: opcua ports:
[0166] - 48040
[0167] - 4840 read:
[0168] - 'ns =l;s= UI-A@supervision\exports-4-0-4statistics-l :sigma2 '
[0169] - 'ns=2;i=1234' write:
[0170] - 'ns=3;i=568'
[0171] - 'ns=2;i=1234'
[0172] "192.168.0.12": type: s7 read:
[0173] - '1:10-20' # DB=1, range 10 to 20 write:
[0174] - '10:50'
[0175] - '10:60-70'
[0176] "192.168.0.100": type: mqtt ports:
[0177] - 1883 read:
[0178] - '#' write:
[0179] - ' / topic / whatever'
[0180] "192.168.0.13": type: mtconnect read:
[0181] - / probe # All devices
[0182] - / M12345 / probe # Specific device
[0183] - / (M12345\M45678) / probe # Specific devices
[0184] - / ([a-zA-zO-9-]+) / probe # Any device
[0185] - / current? path= / / Ax s (?: ' / ['?.]+) *&at=(\d+) # / / Axes and all its children
[0186] - / current? path= / / Rotary / / Data!tem [type = "LOAD"](?: [ A \.] +)*&at=(\d+)
[0187] - / sample?path= / / Axes(? : V A \.J +)*&from=(\d+)&count=(\d+)
[0188] - / asset / ([a-zA-zO-9;-]+)?type=(''w>+)&count=(d+)&device=([a-zA-zO-9- ]+)&removed=(truefialse)
[0189] In certain embodiments, the transmission method 400 may comprise an (optional) update of the obtained description 414, either automatically by the second device, or via a user interface of the second device, to delete certain information from the description or add new information (for example to create, delete and / or modify at least one filtering rule).
[0190] As illustrated in Figure 4, the method may comprise a processing 420 of a data packet originating from a third-party device located outside the protected portion. This may for example be a request for read or write access to a memory area of a device in the first portion. The packet may for example be obtained 422 (i.e. received here) by the second device via the second portion of the communication network. For example, when the second device is connected to the second portion via an Ethernet link, the second device may intercept the data packets circulating on the second portion of the network and having a destination address corresponding to an addressing identifier contained in the description. As illustrated in Figure 4, the method may comprise an examination 430 of the received packets, taking into account at least one filtering rule (called a “second” filtering rule with reference to the “second” device).The at least one second filtering rule can for example be obtained 432 from the information present in the description (and detailed above). The method can thus comprise a filtering 434 of the packets received to retain only those consistent with the at least one “second” filtering rule obtained.
[0191] Thus, according to a first example, packets having the MQTT protocol can be kept or deleted according to their "topic". According to a second example, packets having the OPC-UA protocol can be kept or deleted according to the designated nodes and a type of request (read or write access) to which the packet corresponds. According to a third example, packets having the ModBus protocol can be kept or deleted according to the designated registers and a type of request (read or write access) to which the packet corresponds. The destination equipment can also be taken into account when keeping or deleting packets.
[0192] For example, in connection with the example description above, a packet intended for the "ModBus" machine will be kept only if its destination port is 9400 and concerns "registers" 0 to 105 of "coils" 0 to 1 in the case of a read access request. On the other hand, only write access requests to registers 0-12 will be kept. Thus, a write request to register 13, for example, will be eliminated.
[0193] As illustrated, the method may comprise a transcoding 440 of the stored packets. Thus, the method may comprise an extraction 442 of the data contained in the obtained packet 422 taking into account the structure of the packet and in particular the protocol used in the encoding of the packet. The extracted data may for example comprise, in addition to the address of the recipient of the packet, at least one destination port on the destination equipment, a type of request to be addressed to the equipment, data related to the command (address range, data values, etc.).
[0194] For example, in the case of an MQTT protocol, the following pseudo code can be implemented during extraction:
[0195] #Extract destination IP destination ip = packet[16:20]
[0196] #Extract destination port destination _port = packet[20:22]
[0197] # Extract MQTT topic topic length = packet
[0030] topic = packet [31: 31+ topic length ] # Extract MQTT payload payload length = packet [31+ topic _length+ 1 ] payload = packet[31+topic_length+2:31+topic_length+2+payload_length]
[0198] In the example of Figure 4, the method may include serialization of the extracted data. This serialization may, for example, take into account the description obtained 414 (in particular a designation, in the description; of a protocol to be used for serialization, such as XML or JSON).
[0199] For example, the serialized data may include in the header an announcement of a type of data (protocol used or announcement of data corresponding to a description, etc.), a label identifying this type of data, as well as possible text labels or digital code announcing the meaning of the elements which follow them. These announcements may be optionally included in certain embodiments, in particular when the description of the second device (and that of the first device) only provides a single protocol. As illustrated in FIG. 4, the method may include a transmission 450 to the first device of the transcoded data (via one of the unidirectional communication paths set up for example).
[0200] Alternatively, filtering can be performed on the extracted / serialized data (not the received packets).
[0201] Filtering on packets (rather than serialized data) allows filtering to be based on the structure of the packets (and therefore the semantics of the fields in those packets). It also avoids unnecessary serialization processing of data that will not be retained.
[0202] Optionally, the method may comprise processing 460 of a message from the equipment (such as a UDP message or a response to the request sent to the first device (and transmitted by the latter to the equipment)). Upon receipt 462 of a message, the method may comprise transmission 464 of the response to the third-party device for which it is intended. In certain embodiments, this may in particular involve a simple retransmission of a received packet. The processing may possibly comprise filtering of the received packets (similarly to what has already been described above, but possibly with different filtering rules (for example to prohibit the communication of the content of certain registers), or to filter the recipients of the messages).
[0203] Depending on the embodiments, the manner in which the second device obtains a packet intended for a device in the first portion may vary. For example, in some embodiments where the second device is connected to the second portion of the communications network via an Ethernet link, the second device may intercept data packets traveling on the second portion of the network when their destination address matches that of the device. In other embodiments, the second device may use, as its own addressing identifier on the second portion, an addressing identifier of at least one device on the first portion.The addressing identifier of the equipment on the first portion may for example be obtained by reading the description or received from the first device and the method may comprise a definition or modification of its own addressing identifier to be equal to the addressing identifier of the equipment on the first portion. It may also involve an addition of the addressing identifier of the equipment on the first portion to its addressing identifier(s) on the second portion.
[0204] Such embodiments may allow the second device to "impersonate" the equipment, vis-à-vis devices of the second portion or external to the communication network. Such embodiments may thus help an administrator of the communication network to have a "plug and play" solution. Thus, the insertion of the electronic assembly into the network, for the protection of a piece of equipment, may be transparent to other devices already present in the network and may not require modifying a routing (or addressing) plan of the entire network or modifying the software of one of the third-party devices wishing to obtain data from the equipment.
[0205] In particular, when the second device is part of an electronic assembly protecting several pieces of equipment, the second device can be assigned several addresses (IP for example) on the second portion (via “subnets” for example) each identical to one of the addressing identifiers of a piece of equipment to be protected on the first portion.
[0206] For example, in some embodiments, the electronic assembly may be installed in an existing network comprising equipment that is (newly) to be protected. When the electronic assembly is installed so as to be able to communicate (for example via a wired link) with the equipment to be protected, thus constituting a first portion of the network (comprising at least the equipment and the first device), a network operator may not have to perform any action (other than this installation). Since requests intended for the equipment are received by the second device and any responses from the equipment are transmitted by the second device, devices and software external to the protected portion of the network may continue to make requests to the equipment, without modifying the access routine that they used before the installation of the electronic assembly to protect the equipment.The insertion of the electronic assembly into the network can therefore be transparent to these devices and software.
[0207] We now describe the method 300 illustrated in FIG. 3, and implemented for example by a first device located in a protected portion of a communication network such as the first device 162 of the electronic assembly 160 of the system 100.
[0208] Similar to what has been described above for the method 400 implemented by the second device, the method 300 can be implemented, depending on the embodiments, when the first device is started, or later, and can comprise, as illustrated in FIG. 3, a so-called initialization phase 310 (when the first device is started for example or later, upon receipt of a user command for example). This initialization phase can comprise obtaining 312 a description which can take the form of one or more files for example and which can in particular comprise information relating to the establishment of a bidirectional communication between the first device and the second device (such as an address of the second device on the communication network, a protocol to be used, etc.).) and / or information relating to the data that the first device will receive from the second device (protocol to be used, format, etc.), and / or information relating to rules for filtering this data that the first device must apply, and / or information relating to at least one piece of equipment for which this data may be intended (such as an identifier of this equipment, a designation of at least one protocol that it may use, etc.), and / or information relating to the structuring of this data into data packet(s) before their transmission to a piece of equipment, and information relating to communication to be established with a piece of equipment for the transmission of at least one such packet (such as a password, or a public or private key necessary for a connection to the equipment).
[0209] The information relating to the establishment of a two-way communication between the first device and the second device, the information relating to the data that the first device will receive from the second device (protocol to be used, format, etc.), and / or the information relating to the structuring of this data into packet(s) may be similar to that described in connection with the transmission method 400 (the format of the packets received by the second device may be different from the format of the packets transmitted by the first device).
[0210] The information relating to filtering rules may be similar to those described in connection with the transmission method 400. In certain embodiments, the filtering rules may differ from the filtering rules applied by the second device. For example, the filtering rules to be applied by the first device may take into account the second device from which the data is received (when the first device can receive data from several "second" devices) so as, for example, to eliminate certain data corresponding to write requests originating from a second portion interconnected with a public network such as the Internet.
[0211] The information necessary for the identification of equipment to be protected may include at least one of the following identification information: a textual label; an address (or addressing identifier) of the equipment on the first portion (for example, depending on the protocols, an IP address, a MAC address of at least one access point of the equipment, etc.); a manufacturer's reference of the equipment; a serial number of the equipment; a combination of at least two of the above identification information.
[0212] The information necessary for establishing communication between the first device and the equipment (in addition to the identification information) may include in particular at least one of the following so-called communication information: information designating a protocol that can be used to communicate with the equipment; a port of the equipment that can be used to communicate with the equipment according to said protocol; at least one connection security element (such as an access identifier, a password, a public or private key, etc.); additional parameters specific to certain protocol(s) (such as a “topic” in the case of the MQTT protocol). a combination of at least two of the above communication information.
[0213] Examples of protocols for communicating with equipment include hierarchical protocols, using standardized data structures, such as Open Platform Communications Unified Architecture (OPC-UA) ModBus protocols, or non-hierarchical protocols such as MQTT or Direct UDP.
[0214] Some of the information in the description may be optional in some embodiments. For example, communication information such as connection security features may be absent when access to the equipment is not restricted within the first portion. In addition, some of the data descriptive information may depend on the protocol(s) designated in the communication information. In some embodiments, the description may, for example, be obtained by accessing a storage area accessible to the first device (such as a storage area local to the first device or located in the first portion of the network or a removable storage area (such as a USB key) coupled to the first device or accessible via a serial connection on a micro-USB port of the first device).This may include a micro-USB port inaccessible to a third party when the casing of the electronic assembly containing the first device is closed.
[0215] In some embodiments (e.g., some embodiments where the description is obtained by reading a storage area accessible to the first device), the method 300 may include transmitting 316 at least a portion of the obtained description 312 to the second device.
[0216] In some embodiments, the description may be created, or completed, dynamically (and at least partially automatically) by the first device itself. In such an embodiment, the method may comprise a polling (or exploration) (or ARP (for Address Resolution Protocol) scan according to the English terminology) of the first portion, to discover the devices present in the first portion, then at least one attempt to connect to these devices using one or more candidate protocol(s) (depending on the embodiments), making it possible, when a connection attempt succeeds, to detect at least one protocol used by the equipment. The connection attempts may possibly use additional elements (such as at least one port value (to discover at least one open port on the device concerned) and / or additional parameters consistent with this (or these) candidate protocol(s).For example, the method may include, for each discovered device of the first portion, attempting to connect with a set of candidate protocols defined by configuration (manual or automatic) of the device.
[0217] When at least one connection attempt has been successfully made for at least one discovered device, the method may include a recording of the address of the discovered device in association with the protocols that enabled the connection, and any additional elements in said description.
[0218] Such an embodiment may allow not only the creation of a description, but also the automatic updating of an existing description. This may involve adding information relating to a newly discovered device or modifying information in the description relating to a device, for example to add information relating to a new protocol accepted by this device (following a software update of the device for example), or to delete the designation of a port that has become inaccessible (defective for example).
[0219] In some embodiments, the method may further comprise an (optional) update of the description obtained by the first device. Thus, an automatic update may comprise, for example, an addition of default filtering information, applicable for access requests to a newly discovered device (and recorded in the description), such as retaining only read access requests, or an addition of filtering information prohibiting the use, regardless of the device concerned, of a low-security protocol for example) or prohibiting the use of a defective port.
[0220] An update may also be performed manually by an operator, via a user interface of the first device, in particular to create and / or delete and / or modify filtering information. This may involve, for example, manually completing a descriptive file automatically created by the first device.
[0221] In some embodiments, the description obtained 312 may be identical to the description described in connection with the method 400 implemented in the first device. For example, the two descriptions may be obtained by copying the same removable storage medium, or the second device may receive from the first device the entire description that the first device itself previously obtained 312 (or vice versa). In such embodiments, the description of the second device may then contain certain information not useful to the second device (such as a password, or a public or private key necessary for a connection to the equipment from which the data originates).Such an embodiment may offer advantages in terms of simplicity of processing (for one of the first and second devices) and / or simplicity of configuration, and therefore time saving, on the second device side, since it is not necessary to provide a “description” specific to the second device. In other embodiments, the descriptions may be different. In particular, certain information contained in the description obtained by the first device and relating to the equipment to be protected and / or to communications with this equipment (such as a password for example) may be omitted from the description obtained by the second device. In addition, in certain embodiments where the format of the packets to be created by the first device and the format of the packets received by the second device are different, information contained in the descriptions and relating to the formats of the packets to be received or created will be different.
[0222] The initialization phase 310 may comprise an establishment 314 of the bidirectional communication means with the second device and, optionally, a transmission 316 of at least a portion of the description obtained 310 to the second device. The transmission 316 may in particular comprise the transmission of at least one item of identification information of the equipment such as an address of the equipment on the first portion (for example according to the protocols an IP address, a MAC address, etc.), (also called an addressing identifier on the first portion in the present application).
[0223] It may also include at least some information for communication with the equipment (e.g., information relating to a protocol and / or a communication port).
[0224] In particular in certain embodiments, the transmitted descriptive portion may include descriptive information likely to help the second device "impersonate" the equipment, with respect to devices of the second portion or external to the communication network.
[0225] The method may comprise obtaining 320 data, corresponding to a request from a third-party device, received (obtained) from the second device, via the bidirectional communication means. The method may further comprise transcoding, for example deserialization (or structuring) 330 of this data to obtain a structured data packet. The structuring of the data may take into account information present in the description designating a protocol used by the equipment.For example, taking the example of the data extraction pseudo-code cited previously in connection with the transmission method 400, the pseudo-code allowing the deserialization of this data into a structured packet, according to the MQTT protocol could be the following: mqtt jjcicket = bytearrciy() mqtt jjcicket += bytes(packet['destination_ip]' ) mqtt _packet += bytes(packet ['destination _port]) mqtt _packet += b'\x00\x00' mqtt _packet += bytes( [len(packet ['topic]' )]) mqtt _packet + = packet ['topic]' mqtt _packet + = packet [p' ayload'].
[0226] The method may comprise an examination 340 of the extracted data taking into account at least one filtering rule (called “first” filtering rule with reference to the “first” device). The at least one “first” filtering rule may for example be obtained 342 from the information present in the description of the first device (and detailed above). The method may thus comprise a filtering 344 of the received data, or alternatively a filtering of the packets formed from the received data, to retain only those (or those) consistent with the at least one “first” filtering rule obtained.
[0227] Alternatively, filtering can be performed on the extracted data, so that only the data to be retained is structured into packets. As explained above, filtering on packet-structured data allows you to rely on the packet structure for applying filtering rules.
[0228] As illustrated in Figure 3, the method comprises a transmission 350 of the packet obtained on the first portion of the network, to a device receiving this packet.
[0229] Following the transmission of at least one packet which corresponds to a request from a third-party device (intended for the equipment), the first device can optionally process a response from the equipment, more precisely the first device can receive a message 362 from the equipment and transmit 364 this message (after serialization and / or filtering before or after this possible serialization) to the second device.
[0230] In certain detailed embodiments in connection with figures 3 and 4, the first device and the second device can be adapted to communicate according to several protocols with, respectively, at least one equipment to be protected and at least one third-party device.
[0231] In one embodiment, the first device and the second device may communicate with a device to be protected and a third-party device with a single protocol. For example, the network may comprise several electronic protection assemblies, each protecting one or more devices having the same protocol. Such embodiments may allow for simpler descriptions. In particular, in some embodiments the electronic assembly may be dedicated to a particular protocol and programmed for this single protocol. In one embodiment, upon initialization, several second devices may communicate with the first device to respectively transmit requests from third-party devices using different protocols.
[0232] In another variant, the same second device can communicate with several “first devices”, this second device being able, for example, to have several different addresses, each chosen to correspond to that of equipment protected by one of the first devices and directing the requests received to the appropriate “first” device.
[0233] The present application proposes an electronic assembly constituting, at least in some of its embodiments, a simple and effective solution for requesting data securely from an industrial machine connected to a public network such as the Internet. In particular, in at least some embodiments, the configuration of at least one of the first and second devices of the electronic assembly can be easy (in particular when it is automatic) and one or other of the devices of the electronic assembly can be usable with several different protocols, which can therefore make it possible to offer a solution adaptable to different industrial environments.
[0234] The solution presented in the present application can find applications in many fields, and in particular in areas that are prime targets for computer attacks. Thus, in the manufacturing industry, the solution that is the subject of the present application can help protect industrial machines (to prevent their corruption, for example), by preventing access to certain sensitive data from these machines, such as data relating to the industrial processes implemented, while making other data (such as production data) available to monitoring and control applications. In the example of Figure 5, the electronic protection assembly 160 is implemented to allow secure remote interrogation of an industrial machine (the equipment 140) by a third-party SCADA (Supervisory Control and Data Acquisition) type remote management device from an unsecured portion of the communication network.
[0235] Another example of implementation concerns the field of distribution. The solution that is the subject of this application can in fact be used to help protect electronic point-of-sale equipment, by limiting the possibilities of access to data stored on this equipment, such as sales data and / or sensitive customer information.
[0236] Yet another example of implementation concerns the field of finance (banking, financial services) and in particular the sensitive financial and personal information handled, which the solution that is the subject of this application can help to protect from attacks (while providing access possibilities to other, less sensitive, data for example). The solution that is the subject of this application can also find applications in the field of health, to protect sensitive medical data of patients while leaving access possibilities to at least some of this data to health professionals.
Claims
CLAIMS 1. Method for protecting at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via a first device of said first portion and a second device of said second portion, said method comprising: • a transmission to said second device of at least one addressing identifier of said equipment of said first portion of said communication network; • a transcoding of data received from said second device into at least one structured data packet comprising at least one addressing identifier of a device receiving said packet on said first portion; • a transmission of said packet to said recipient equipment; at least one of said transcoding and / or transmission being carried out conditionally taking into account at least one filtering rule relating to the content of said packet.
2. Protection method according to claim 1 where said filtering rule takes into account at least one element contained in said packet among the following elements: - a designation of a device transmitting said packet; - addressing information relating to at least one piece of data from said equipment; - a type of access to be carried out on said data; - a designation of a communication protocol used by said packet; - a combination of at least two of the above elements; 3. Protection method according to claim 1 or 2 wherein said filtering is carried out before said transcoding.
4. Protection method according to claim 1 or 2 wherein said filtering is carried out after said transcoding.
5. Protection method according to one of claims 1 to 4 where said first and second devices communicate with each other via at least two communication paths, a first unidirectional communication path allowing the first device to receive data from said second device, and a second unidirectional communication path allowing the first device to send to said second device a response to said packet transmitted to said recipient equipment.
6. Protection method according to any one of claims 1 to 5 where the method said transcoding comprises a deserialization of said data.
7. Method for transmitting data intended for at least one device of a communication network partitioned into a plurality of portions comprising at least a first portion, and at least a second portion interconnected with said first portion via a first device of said first portion and a second device of said second portion, said method comprising: • An assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier of a piece of equipment in said first portion; • Upon receipt of a structured data packet having as destination address said addressing identifier, a serialization of the data of said packet; and • a transmission of said serialized data to said first device. at least one of said serialization and / or said transmission being carried out conditionally taking into account at least one filtering rule relating to the content of said packet.
8. Transmission method according to claim 7 where said filtering rule takes into account at least one element contained in said packet among the following elements: - a designation of a device transmitting said packet; - addressing information relating to at least one piece of data from said equipment; - a type of access to be carried out on said data; - a designation of a communication protocol used by said packet; - a combination of at least two of the above elements; 9. Transmission method according to claim 7 or 8 comprising obtaining a description relating to said equipment of said first portion of said communication network comprising said at least one addressing identifier of said at least one equipment on said first portion of said communication network.
10. Transmission method according to one of claims 7 to 9 where said filtering is carried out on the serialized data 11. Transmission method according to one of claims 7 to 10 where said filtering is carried out before said serialization.
12. Transmission method according to one of claims 7 to 11 where said first second devices communicate with each other via at least two unidirectional communication paths, a first unidirectional communication path allowing the second device to transmit data to said first device, and a second unidirectional communication path allowing the second device to receive from the first device a response to said data transmitted to said first device.
13. First electronic device of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising at least one piece of equipment to be protected and said first device, and at least a second portion interconnected with said first portion via the first device and a second device of said second portion, said first device comprising at least one processor configured to: • a transmission to said second device of at least one addressing identifier of said equipment of said first portion of said communication network; • a transcoding of data received from said second device into at least one structured data packet comprising at least one addressing identifier of a device receiving said packet on said first portion; • a transmission of said packet to said recipient equipment; at least one of said transcoding and / or transmission being carried out conditionally taking into account at least one filtering rule.
14. Second electronic device of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising at least one piece of equipment, and at least a second portion comprising said second device, and interconnected with said first portion via a first device of said first portion and the second device; said second device comprising at least one processor configured to: • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier of a piece of equipment in said first portion • upon receipt of a structured data packet having as destination address said addressing identifier, a serialization of the data of said packet and; • a transmission of said serialized data to said first device; at least one of said serialization and / or said transmission being carried out conditionally taking into account at least one filtering rule relating to the content of said packet.
15. Electronic assembly for protecting at least one piece of equipment of a communication network partitioned into a plurality of portions comprising at least a first portion, comprising said equipment, and at least a second portion interconnected with said first portion via at least a first device of said electronic assembly, said first device belonging to said first portion, and at least a second device of said electronic assembly, said second device belonging to said second portion, said at least one first electronic device comprising at least one processor configured to: • a transmission to said second device of at least one addressing identifier of said equipment of said first portion of said communication network; • a transcoding of data received from said second device into at least one first structured data packet comprising at least one addressing identifier of a recipient device of said first packet on said first portion; • a transmission of said first packet to said recipient equipment; at least one of said transcoding and / or transmission being carried out conditionally taking into account at least one first filtering rule relating to the content of said first packet. said at least one second electronic device comprising at least one processor configured to: • an assignment to said second device, as an addressing identifier on said second portion of said network, of at least one addressing identifier of a piece of equipment in said first portion • upon receipt of a second structured data packet having as destination address said addressing identifier, a serialization of the data of said second packet and; • a transmission of said serialized data to said first device. at least one of said serialization and / or said transmission being carried out conditionally taking into account at least one second filtering rule relating to the content of said second packet.
16. Computer program comprising instructions for implementing a protection method according to one of claims 1 to 6, and / or a transmission method according to one of claims 7 to 12, when said program is executed by a processor.
17. Information medium readable by an electronic device and on which is recorded a computer program comprising instructions for implementing a protection method according to at least one of claims 1 to 6, and / or a transmission method according to at least one of claims 7 to 12.