Method and system for controlling the delivery of goods
Patent Information
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- KATALX
- Filing Date
- 2024-07-23
- Publication Date
- 2026-06-03
Smart Images

Figure EP2024070919_30012025_PF_FP_ABST
Abstract
Description
DescriptionTitle of the invention: Method and system for controlling the delivery of goodsField of the invention
[0001] This invention pertains to the field of logistics flow control, and particularly the delivery of goods.
[0002] It applies in particular but without limitation to the control or to the monitoring of a medication delivery process.Prior art
[0003] Logistics flows and in particular the delivery of medications are complex processes. They generally involve several entities, typically at least one shipper of the goods, at least one logistics service provider, for example a carrier, and a customer receiving the goods.
[0004] The logistics flow can logically be broken down into a certain number of operations, for example operations of packing of the goods, operations of carrying of the goods, administrative operations, for example customs operations, for example supplying certificates of conformity.
[0005] The logistics flow must also sometimes be carried out in a way that complies with delivery conditions, for example location of the goods, temperature or humidity conditions for the proper conservation of the goods, ...
[0006] As the delivery progresses, or after the delivery, there is a general need to allow authorized persons to have good visibility of the different operations, conditions and events which have occurred during the delivery, but in a confidential way.
[0007] No satisfactory system exists to date.Subject and summary of the invention
[0008] Thus, the invention makes provision for a method for controlling the delivery of a goods, said method being implemented by a controlling system and including:- a step of registering at least one user with an access management module of said controlling system and of supplying authenticating means to a workstation of said at least one user;- a step of obtaining a configuration file of the delivery, this file including items of information about at least one future operation that must take place during said delivery, said obtaining step being determined by an authentication of said user based on said authenticating means supplied to this user and by the checking of a right of this user to carry out said obtaining step given arole of the user and his rights in accordance with a security policy, which contains written logical rules on access right to view and update information based on user's role and attributes associate with that role;- a step of recording a result of at least one said operation in a visibility database of the delivery at the request of a user, said recording being determined by an authentication of said user and by the checking of a right of this user to formulate said request given a role of the user and his rights in accordance with said security policy which contains rules specifying roles and actions can be carry by the role ; and- a step of recording at least one transaction representative of said at least one operation and a signature of said transaction in an immutable and verifiable audit database, said signature being made using a private key of said system.
[0009] . Example of attributes but are user's geographical location, user's organization, user's time and day of access.
[0010] The step of obtaining the configuration file may consist in downloading the configuration file from the workstation of a said user, this downloading is determined by said authentication of said user and by the checking of said user's right.
[0011] Alternatively, the step of obtaining the configuration file comprises a step of creating the configuration file of delivery, said creating step being determined by said authentication of said user and by the checking of said user's right.
[0012] Correspondingly, the invention relates to a system for controlling the delivery of goods, this system including:- an access management module configured to register at least one user and to supply authenticating means to a workstation of said at least one user;- a module for obtaining a configuration file of the delivery, this file including items of information about at least one operation that must take place during said delivery, said obtaining being determined by:(i) an authentication of said user by said access management module based on said authenticating means supplied to this user and by(ii) the checking, by a module for applying security policy rules associated with roles and actions carried by a role, of a right of this user to carry out said obtaining given a role of the user and his rights in accordance with said security policy;- a module for managing the visibility of the delivery configured to record a result of at least one operation in a visibility database of the delivery at the request of a user, said recording being determined by:(i) the authentication of said user by said access management module and by(ii) the checking, by a module for applying a security policy rules of a right of this user to formulate said request given a role of the user and his rights in accordance with said securitypolicy rules;- said visibility management module being configured to record at least one transaction representative of said at least one operation and a signature of said transaction in an immutable and verifiable audit database, said signature being made using a private key of said system.
[0013] The module for obtaining the configuration file may be configured to download or to create the configuration file.
[0014] Thus, and in general, the invention makes provision for a method and a system for controlling a delivery of goods, this method and this system offering the possibility, to authorized persons, of accessing and monitoring data and states relating to critical operations of the delivery process.
[0015] Indeed, in an embodiment, the method according to the invention includes, at the request of a user, a step of querying the visibility database, this query being determined by an authentication of this user and by the checking of a right of this user to formulate this request given a role of the user and his rights in accordance with said security policy.
[0016] The invention makes provision for defining the future operations and conditions of the delivery in a configuration file and for checking that this configuration file is actually downloaded or created by an authenticated and authorized person.
[0017] Thus, the downloading and any subsequent access to the system according to the invention by a user, in read mode and in write mode, can only be carried out by authenticated users and in accordance with a security policy.
[0018] In an embodiment of the invention, the security policy is in accordance with the ABAC model.
[0019] It is recalled that an ABAC (Attribute-Based Access Control) policy is an access control model which uses the attributes of the users, resources and conditions to determine whether or not a user is authorized to access a given resource.
[0020] Moreover, and very advantageously, the invention makes provision, for each operation recorded in the visibility database, to record a corresponding transaction and the signature of this transaction in another database, the latter being immutable and unfalsifiable.
[0021] Very advantageously, the signatures are all generated using a private and secret key of the delivery controlling system. This key is not attributed to a user of the system but a key of the system itself.
[0022] - said visibility management module being configured to record at least one transaction representative of said at least one operation and a signature of this transaction in an immutable and verifiable audit database, said signature being carried out using a private key of said system.
[0023] This immutable and verifiable database can be a blockchain.
[0024] This database can be categorized as an audit database since it subsequently makes it possible to gain knowledge of all the relevant operations and events that have occurred during the delivery.
[0025] In an embodiment of the controlling method, the configuration file includes at least certain items of information from among:- items of information about data to be entered and about the persons authorized to make such an entry;- items of information about at least one step of carrying of the goods;- items of information about at least one document to be downloaded and about the persons authorized to carry out this downloading;- predefined conditions of said future delivery.
[0026] In accordance with a particular embodiment of the invention, in addition to the authorized users, connected objects can access the delivery controlling system in write mode and / or in read mode, as long as these objects have been specifically referenced in the system by a user who is authenticated and has the rights to do so.
[0027] Thus, in an embodiment, data entered by an authorized person include an identifier of a connected object configured to measure condition data of said goods item, the method including:- a step of obtaining measurements of condition data by the connected object and of recording these measurements in a database of delivery conditions;- a step of recording at least one transaction representative of said measurements and a signature of said transaction in the immutable and verifiable audit database, said signature being made using the private key of said system; and- if these measurements do not conform to the conditions of said delivery, a step of recording these measurements in an exception database.
[0028] This feature advantageously makes it possible to measure in real time the conditions of the delivery (location, temperature, humidity, shock, light or other conditions), for example by attaching a connected object declared in the system to the goods. Each measurement is the subject of a transaction, recorded with its signature, in the audit database.
[0029] In an embodiment, the invention makes provision for putting in place an automatic anomaly detection mechanism, an anomaly being detected if the operations planned in future in the configuration file are not recorded as they are in the visibility database. Any detected anomaly is the subject of a transaction recorded with its signature in the audit database.
[0030] Thus, in an embodiment, the method includes:- a step of checking the conformity of the items of information recorded in the visibility database with respect to the expected information of the configuration file and if this is not the case a step of recording an anomaly in an exception database; and- a step of recording at least one transaction representative of said anomaly and a signature of said transaction in the immutable and verifiable audit database, said signature being made using the private key of said system.
[0031] As stated above, when a measurement does not conform to the planned delivery conditions, it is the subject, in addition to the recording of the corresponding transaction in the audit database, of a recording in an exception database.
[0032] In a particular embodiment, the invention makes provision for an automatic mechanism for processing these exceptions.
[0033] Thus, in an embodiment, the method includes:- a step of querying the exception database to identify measurements that do not conform to the conditions of the delivery; and, where applicable:- a step of deciding on the processing to be given to this said measurement.
[0034] A type of processing can for example consist in alerting a user.
[0035] In an embodiment, the steps of checking conformity and processing non-conforming measurements are carried out by an anomaly processing module trained to detect anomalies and to decide on their processing based on a set of rules and historical data.
[0036] In summary, the invention offers authorized users visibility, optionally in real time, of relevant items of information of the delivery. This can in particular include items of information about the progress of the operations, sensor values, state information, and documents.
[0037] All these items of information are the subject of a signed transaction recorded in the audit database.List of figures
[0038] Figure 1 illustrates the main steps of a delivery controlling method in accordance with a particular embodiment of the invention;
[0039] Figure 2 schematically represents a delivery controlling system in accordance with a particular embodiment of the invention;
[0040] Figure 3 is an example of a configuration file.Detailed description
[0041] Figure 1 shows in the form of a flowchart the main steps of a delivery controlling method PCL in accordance with a particular embodiment of the invention.
[0042] In the embodiment, this method is implemented by a delivery controlling system KX which will be described with reference to figures 2 and 3 in an example of a scenario implementing the invention.
[0043] In the embodiment described here, the controlling method KX includes a step E10 of recording the users authorized to interact with the system KX. This recording step for example includes a phase of setting up a password and supplying authenticating means specific to the users (tokens, certificates etc.).
[0044] Such recording means are known to those skilled in the art. They allow the system KX to check, for each access of a user to the system, whether or not this user is an authorized user.
[0045] Next, as soon as a user wishes to access the system KX to carry out an operation, the method checks during a step E20, firstly that the user is authenticated but also that the user holds rights to carry out this operation.
[0046] This is for example the case if a user asks to download a configuration file FCONF of a future delivery: the downloading of this file by a user (step E30) can only be carried out after authenticating the user and checking a right of the user to carry out this download.
[0047] In a preferred embodiment, the rights of a user to carry out an operation are defined as a function of the role or roles of the user and of a security policy of ABAC type.
[0048] In the same way, if a user wishes to record (step E40) the result of an operation or any other item of information in the system KX, this recording is determined by the step E20 of authenticating the user and checking the right of this user to formulate such a recording request, given his user role and his rights defined by the security policy. Ditto, the downloading of a document in the system KX by a user is subject to the same requirements.
[0049] In the embodiment described here, the system KX includes a visibility database in which are recorded all the relevant events of the delivery, particularly those recorded by the authorized users. These can for example be events relating to the carrying of the goods or the carrying out of formalities. Any item of information entered by an authorized user (relating for example to the lot number or to the serial number of the goods) is also recorded in this visibility database.
[0050] In the same way, if a user wishes to query this visibility database to obtain information about the delivery, the supplying of such an item of information is determined by the step E20 of authenticating the user and checking the right of this user to request this information given his role and his rights defined by the security policy.
[0051] In an embodiment of the invention, the configuration file can include at least certain items of information from among:- items of information about data to be entered and about the persons authorized to carry out this entry;- items of information about at least one step of carrying of the goods;- items of information about at least one document to be downloaded and about the persons authorized to carry out this downloading;- conditions of said future delivery.
[0052] In an embodiment of the invention, a user can also ask for one or several connected object to take measurements of conditions data of the goods. For example, the user can input the serial number of such a connected object, this entry only being authorized after authenticating the user and checking his rights given the security policy.
[0053] This connected objects may for example be a temperature sensor, a GPS module, humidity sensor, a shock detector (such as an accelerometer), a light detector attached to the goods to respectively detect the temperature or humidity on the goods, whether the box was opened or a possible impact.
[0054] In one embodiment, any future shipment is identified by a shipment ID recorded in the configuration file and the configuration file may comprise one or a plurality of connected objects recorded with this shipment ID in the configuration file.
[0055] When such a connected object has been validly declared and configured to take the desired measurements, these measurements are taken, for example regularly or at times defined in the configuration file, during a step referenced E60. These measurements are for example recorded in a database of delivery conditions.
[0056] In the embodiment described here, if the system KX detects (step E70) that the measured data do not conform to those defined in the configuration file, they are recorded in an exception database (step E80).
[0057] In the embodiment described here, the controlling method PCL implements an anomaly detection mechanism and for some of these anomalies, an anomaly processing mechanism.
[0058] In the embodiment described here, the anomalies are handled by an expert system or by a module trained for this purpose which relies on a set of rules and on historical data.
[0059] Thus, during a step E100, the anomaly management module checks the conformity of the information recorded in the visibility database with respect to the items of information of the configuration file and in the event of any non-conformity records an anomaly in an exception database.
[0060] In the embodiment described here, the anomaly management module is further configured to handle the case of condition measurements which do not conform to the configuration file.
[0061] Thus, during a step El 10, the anomaly management module queries the exception database to identify measurements that do not conform to the delivery conditions; and where applicable decides on the processing to be given to this measurement.
[0062] In the embodiment described here, the delivery controlling method includes a step E90, implemented, each time that:- an item of information is recorded in the visibility database (step E40);- a condition measurement is taken (step E60);- each time an anomaly is detected (step E100), this step consisting in recording, in an immutable and verifiable audit database, a transaction representative of this event and a signature of this transaction made using the private key of the system.
[0063] This audit database offers complete traceability of the delivery by aggregating items of information of the visibility database BDV]s and of the measurement database BDIoT.
[0064] Figure 2 shows a system and a method for controlling the carrying of goods in accordance with an embodiment of the invention.
[0065] In the example of figure 2, three entities are considered, namely a shipper EXP, a logistics service provider LOG, and a customer CLT. For each of the three entities EXP, LOG, CLT three users are represented, namely:- a user having a role ADM of administrator EXP-ADM, LOG-ADM, CLT-ADM;- a user having a role MNG of manager EXP-MNG, LOG-MNG, CLT-MNG; and- a user having a role OP of operator EXP-OP, LOG-OP, CLT-OP.
[0066] Figure 2 also shows the workstation, for example a personal computer, a server, a tablet or a smartphone of each of these users. The workstation of the administrator (or manager or operator respectively) of the entity ENT (where ENT represents the shipper EXP, the logistics service provider LOG or the customer CLT) is denoted PCENTA (or PCENTM, PCENTOrespectively).
[0067] The circled figures show steps which can be implemented in at least one particular mode of a method for controlling the carrying of goods in accordance with a particular embodiment of the invention.Registration of the manager EXP- MGR of the shipper MXP with the server KX
[0068] During a step 1, the manager EXP-MGR of the shipper EXP uses his workstation PCEXPM to register with the server KX. This registration can for example be done by means of a page WEB.
[0069] In the embodiment described here, during a step 2, the manager EXP-MGR inputs his first name, his surname, his e-mail address, his username EXP-MGR and the name of his entity EXP into an administration module MODAdmser so that these items of information (or attributes) are stored (step 3) in a permissions database BDPERM.
[0070] During a general step 4, a module MODABAC for applying an ABAC security policy periodically checks the new permissions recorded in the permissions database BDPERM.
[0071] During a step 5, the administration module MODAdmregisters the manager EXP-MNG of the shipper EXP with an access management module MODSGA (Identity Access Management System). This access management module MODSGAis for example a platform of a cloud computing network administered by a service provider, for example the platform AWS (trademark, Amazon Web Services) of the company Amazon (trademark).
[0072] During a step 6, the access management module MODSGAsends a request (for example an e- mail) to the workstation PCEXPM of the manager EXP-MNG of the shipper EXP to ask him to reset his password.
[0073] During a step 7, the manager EXP-MNG of the shipper EXP uses his workstation PCEXPM to change his password. In the embodiment described here, this step known to those skilled in the art is carried out under the control of the access management module MODSG.
[0074] During a step 8a, the access management module MODSGAverifies the new user attributes. If the verification is successful, the access management module MODSGAstores the password of the manager EXP-MNG of the shipper EXP and generates an authentication token TOKEMwhich is stored in the browser of this user, in his workstation PCEXPM at step 8. In the embodiment described here, this token is valid as long as the manager EXP-MNG communicates with the server KX. It is for example invalidated by the server KX in the event of inactivity of the manager EXP-MNG for a given period, for example 30 minutes. This token TOKEM makes it possible to guarantee the validity and authenticity of the exchanges between the browser of the user EXP- MNG and the server KX.Configuration of a delivery flow
[0075] During a step 9, the administrator EXP-ADM of the shipper EXP uses his workstation PCEXPA to register with the server KX. This step is similar to the step 1 of registration of the manager EXP- MNG.
[0076] During a step 10, the administrator EXP-ADM of the shipper EXP changes his password at the request of the access management module MODSGA. This step is similar to steps 6 and 7 of changing the password of the manager EXP-MNG.
[0077] During a step 11, the access management module MODSGAstores the password of the administrator EXP-ADM and generates an authentication token TOKEA which is stored in the browser of this administrator, in his workstation PCEXPA- This step is similar to step 8, the token TOKEA making it possible to guarantee the validity and the authenticity of the exchanges between the browser and the administrator EXP-ADM and the server KX.
[0078] During a step 12, the administrator EXP-ADM downloads a configuration file FCONF of the delivery, this file including items of information about operations that must take place during said delivery. Alternatively, the administrator may use a set of UI screens that creates such configuration files for the user.
[0079] The configuration file FCONF can also comprise items of information about data to be entered, for example lot numbers and / or serial numbers of the goods, and the persons authorized to carry out this entry.
[0080] The configuration file FCONF may comprise items of information about one or more future steps of carrying the goods, for example a future departure location and future arrival location along with the estimated date of this carrying step.
[0081] The configuration file may comprise information about documents to be downloaded (certificate of conformity, customs documents, delivery notes etc.) for example the type of this document, the estimated download date, and the persons authorized to carry out these downloads.
[0082] An example of a configuration file FCONF is shown in figure 3. This file describes the steps of a delivery. In this example, the configuration file FCONF includes a line for each step, this line including:- a column ET# including a number of this step;- a column ETN which includes a name of this step;- a column VO which includes a start town of this step;- a column PO which includes a start country this step;- a column LgO which includes the longitude of the start location of this step;- a column LtO which includes the latitude of the start location of this step;- a column EDO which includes an estimated start date for the beginning of this step;- a column VD which includes an end town of this step;- a column PD which includes an end country of this step;- a column LgD which includes the longitude of the end location of this step;- a column LtD which includes the latitude of the end location of this step;- a column EDD which includes an estimation date of the end of this step;- at least one action RA to be carried out;- a number RA# of this action RA;- a type TA of this action;- an identifier RESP of the person responsible for this action;- where applicable, a type of document TD to be recorded during said action;- a list SW of identifiers of persons who can access the result of this action.
[0083] For certain steps, the start and end location of a step can be identical.
[0084] In the embodiment described here, the types of action TA include:- the type UPL: for a step of downloading a document;- the type DATA: for a data entry step;- the type ACK for a checking step.
[0085] In the embodiment described here, the types of document TD include:- the type COO: for certificates of origin;- the type COC: for certificates of conformity;- the type EPOD for electronic proofs of delivery.
[0086] In the embodiment described here, the configuration file FCONF also includes a table for recording identifiers of connected objects to be used to track conditions of the delivery.
[0087] In the example described here, this table includes:- a column loT# including a connected object number;- a column MN including a brand or a type of connected object to be used;- a column "Serial#" intended to receive a serial number of a connected object of the brand or of the type of the column MN;- a condition to be measured, for example a temperature, a degree of humidity, a brightness etc.;- a lower limit BB and an upper limit BH.
[0088] In the example of figure 2, the configuration file FCONF describes a flow in four steps.First step.- Number of the step (ET#): 1- Name of the step (ETN): "Preparation of delivery";- Town and country of origin of the start location of the step (VO, PO): "Pune, India";- Town and country of the end location of the step (VD, PD): "Pune, India";- Longitude and latitude of the start location of the step (LgO, LtO): "73.94; 25.26"- Longitude and latitude of the end location of the step (LgD, LtD): "73.94; 25.26"- Start date of the step (EDO): "22 / 11 / 11"- End date of the step (EDD): "22 / 11 / 11".Actions to be carried out:- Action 1 :Action to be carried out RA: Download the certificate of origin.Type of action TA: UPL, downloading action;Manager of the action RESP: the operator EXP-OP of the shipper EXP;Type of document to be downloaded TD: COO: certificate of origin.Persons who can gain knowledge of the result of this action: LOG-OP (operator LOG-MNG of the logistics service provider), LOG-MNG (manager of the logistics service provider) and CLT-OP (operator of the customer).- Action 2:Action to be carried out RA: Download the certificate of conformity.Type of action TA: UPL, downloading action;Manager of the action RESP: the operator EXP-OP of the shipper EXP;Type of document to be downloaded TD: COC: certificate of conformity.Persons who can gain knowledge of the result of this action: LOG-OP (operator LOG-MNG of the logistics service provider), LOG-MNG (manager of the logistics service provider) and CLT-OP (operator of the customer).- Action 3:Action to be carried out RA: Enter the lot numbers Lot# of the goods, the serial numbers Serial # of the goods, and the numbers loT# of connected objects authorized to take measurements of the temperature of the goods during the delivery;Type of action TA: DATA, data entry;Manager of the action RESP: the operator EXP-OP of the shipper EXP;Persons who can gain knowledge of the result of this action: LOG-OP (operator LOG-MNG of the logistics service provider), LOG-MNG (manager of the logistics service provider) and CLT-OP (operator of the customer).Second step.- Name of the step (ESN): "Carrying to Mumbai".- Town and country of origin of the start location of the step (VO, PO): "Pune, India";- Longitude and latitude of this location (LgO, LtO): "73.94 ; 25.26"- Town and country of the end location of the step (VD, PD): "Mumbai, India";- Longitude and latitude of this location (LgD, LtD): '72.87; 19.07"- Start date of the step (EDO): "22 / 11 / 11"- End date of the step (EDD): "22 / 11 / 11"Actions to be carried out:- Action 1 :Action to be carried out RA: Enter the Mumbai to Doha flight number.Type of action TA: DATA, data entry;Manager of the action RESP: LOG-OP of the logistics service provider LOG.Persons who can gain knowledge of the result of this action: EXP-OP (operator of the shipper), EXP-MNG (manager of the shipper) and CLT-OP (operator of the customer).- Action 2:Action to be carried out: Confirm that the customs export formalities at Mumbai have been carried out.Type of action TA: ACK, checking;Manager of the action RESP: LOG-OP of the logistics service provider LOG.Persons who can gain knowledge of the result of this action: EXP-OP (operator of the shipper), EXP-MNG (manager of the shipper) and CLT-OP (operator of the customer).Third step.- Name of the step (ESN): "Carrying to Doha";- Town and country of the start location of the step (VO, PO): "Mumbai, India";- Longitude and latitude of this location (LgO, LtO) : "72.87 ; 19.07"- Town and country of the end location of the step (VD, PD): "Doha, Qatar";- Longitude and latitude of this location (LgD, LtD): "51.43 ; 25.28"- Start date of the step (EDO): "22 / 11 / 11"- End date of the step (EDD): "22 / 11 / 12".Actions to be carried out:- Action 1 :Action to be carried out RA: Confirm that the customs export formalities at Doha have been carried out.Type of action TA: ACK, checking;Manager of the action RESP: LOG-OP of the logistics service provider LOG.Persons who can gain knowledge of the result of this action: EXP-OP (operator of the shipper), EXP-MNG (manager of the shipper) and CLT-OP (operator of the customer).Fourth step.- Name of the step (ESN): "Carrying to the customer";- Town and country of the start location of the step (VO, PO): "Doha, Qatar";- Longitude and latitude of this location (LgO, LtO): "51.43 ; 25.28"- Town and country of the end location of the step (VD, PD):"Rumaylah, Qatar";- Longitude and latitude of this location (LgD, LtD): "72.87 ; 19.07"- Start date of the step (EDO) : "22 / 11 / 12"- End date of the step (EDD) : "22 / 11 / 12"Actions to be carried out:- Action 1 :Action to be carried out RA: Download the proof of delivery note.Type of action TA: UPL, downloading action;Manager of the action RESP: the operator CLT-OP of the customer CLT;Type of document to be downloaded EPOD: COO: electronic proof of deliveryPersons who can gain knowledge of the result of this action: EXP-OP (operator of the shipper), EXP-MNG (manager of the shipper) and LOG-OP (operator of the logistics service provider).
[0089] In the example described here, this table includes:- a column Nb including a connected object number;- a column MN including a brand or a type of connected object to be used;- a column "Serial#" intended to receive a serial number of a connected object of the brand or of the type of the column MN;- a condition to be measured, for example a temperature, a degree of humidity, a brightness etc.;- a lower limit BB and an upper limit BH.
[0090] In the example of figure 2, the table of connected objects of the configuration file FCONF includes- a single connected object (Nb= 1);- of the brand XYZ (column MN);- to measure a temperature condition (column COND):- the temperature must be understood as being between 24° (lower limit BB) and 26° (upper limit BH).
[0091] During a step 13, the module MODABAC for applying the ABAC security policy checks whether or not the administrator EXP-ADM of the shipper EXP was authorized (step 12) to download the configuration file FCONF of the delivery flow.
[0092] It uses lines 1 to 7 of the policy presented in Appendix 1.
[0093] If the module MODABAC checks, given the ABAC security policy, that the administrator EXP- ADM of the shipper EXP was authorized to download the configuration file FCONF, the module MODABACapplies the ABAC security policy and transfers a request about managing the visibility of the delivery to module MODVis for managing the visibility of the delivery.
[0094] During a step 14, the visibility management module MODV]s records the information of the configuration file FCONF in a visibility database BDViSof the delivery.Execution of the steps of the flow of the delivery
[0095] We will now describe the execution of the steps of the flow of the delivery.
[0096] During a step 15, the operator EXP-OP of the shipper EXP uses his workstation PCEXPO to register with the server KX. This step is similar to the step 1 of registering the manager EXP- MNG.
[0097] During a step 16, the operator EXP-OP of the shipper EXP changes his password at the request of the access management module MODSGA. This step is similar to steps 6 and 7 of changing the password of the manager EXP-MNG.
[0098] During a step 17, the access management module MODSGAstores the password of the operator EXP-OP and generates an authentication token TOKEo which is stored in the browser of this operator, in his workstation PCEXP0- This step is similar to the step 8, the token TOKEOmaking it possible to guarantee the validity and the authenticity of the exchanges between the browser of the operator EXP-OP and the server KX.
[0099] During a step 18, the operator EXP-OP downloads the certificate of origin COO (as required by the configuration file FCONF- of the delivery flow (step 1 "Delivery service", action RAI "Download certificate of origin"). The module MODABAC for applying the ABAC security policy checks whether or not the operator EXP-OP of the shipper EXP is authorized to download documents of the type TD certificate of origin COO.
[0100] It uses lines 17 to 24 of the policy presented in Appendix 1.
[0101] Only if it is determined that the operator is authorized to download this certificate, during a step 19, the visibility management module MODVis records in the visibility database BDVis an item of information according to which the certificate of origin COO has been downloaded and the visibility management module MODVis records the certificate of origin COO in the document database BDDOCduring a step 20.
[0102] During a step 21, the operator EXP-OP downloads the certificate of conformity COC (as required by the configuration file FCONF- of the delivery flow (step 1 "Delivery service", action RA2 "Download certificate of conformity"). The module MODABAC for applying the ABAC security policy checks whether or not the operator EXP-OP of the shipper EXP is authorized to exchange documents of the type TD certificate of conformity COC.
[0103] It uses lines 25 to 33 of the policy presented in Appendix 1.
[0104] During a step 22 the visibility management module MODVE updates the visibility database BDVE to indicate that the downloading of the certificate of conformity COO was carried out on 22 / 11 / 11 at Pune by the operator EXP-OP.
[0105] During a step 23, the visibility management module MODVis records the certificate of conformity COC in the document database BDDOC.
[0106] During a step 24, the operator EXP-OP enters the lot numbers Lot# of the goods, the serial numbers Serial # of the goods. In the example described here:Lot# =ABCXR123Serial# =123456789
[0107] He also enters the serial number "Serial #" of a connected object of the brand MN to track the temperature of the goods. In the example described here: IoT#=K12345.
[0108] During a step 25, the module MODABAC for applying the ABAC security policy checks whether or not the operator EXP-OP of the shipper EXP is authorized to enter this information.
[0109] It uses lines 35 to 42 of the policy presented in Appendix 1.
[0110] Only if this is the case, during a step 26 the visibility management module MODViSupdates the visibility database BDVis by recording the following items of information:"Delivery of the Lot# =ABCXR123, Serial# =123456789, Temperature to be monitored between 24°C and 26°C by IoT#=K12345."
[0111] During this same step, the operator EXP-OP defines the temperature to be monitored by the connected object loT of serial number IoT#=K12345, namely the authorized range [24°C, 26°C].
[0112] During a step 27 , the visibility management module MODVE records in an immutable and verifiable audit database BDAUDIT transactions representative of the operations and the server KX signs these transactions with its private key. The items of information recorded in this database are tamper-proof and unfalsifiable. New transactions can be recorded but the recorded transactions can be neither destroyed nor modified.Recording of the conditions by the loT
[0113] In the embodiment described here, when a connected objected has been declared and configured to monitor the conditions of a delivery (step 26), during a step 28 a module MODIoTfor managing connected objects obtains, for example regularly, measurements taken by these connected objects and records this measurements in a database of delivery conditions BDIOT(step 29).
[0114] For example, while temperature sensor data, GPS location data, and shock detector data are recorded (step 30a) by the MODIoTmodule, the MODABAC module validate if data from connected object can be associated with shipment specified in a configuration file.
[0115] If the measurements are not in the range defined in the configuration file FCONF, the corresponding transactions are recorded in an exception database BDEXO For example the following transaction is recorded "detected temperature of 28°C on 22 / 11 / 11 by the connected object loT# = K12345.
[0116] During a step 30, the module MODfoT for managing connected objects of the flow records all the transactions in the audit database BDAUDIT and the server KX signs these transactions with its private key.Interactions with the operator of the logistics service provider
[0117] During a step 31, the operator LOG-OP of the logistics service provider LOG uses his workstation PCLOGO to register with the server KX.
[0118] During a step 32, the operator LOG-OP changes his password at the request of the access management module MODSGA.
[0119] During a step 33, the access management module MODSGAstores the password of the operator LOG-OP and generates an authentication token TOKLOwhich is stored in the browser of this operator, in its workstation PCLOGO-
[0120] During a step 34, the operator LOG-OP checks whether or not the custom formalities have been carried out at Mumbai by querying the visibility database BDvis.
[0121] During a step 35, the module MODABAC for applying the ABAC security policy checks whether or not the operator LOG-OP of the logistics service provider LOG is authorized to carry out this check as a function of the security policy.
[0122] It uses lines 43 to 52 of the policy presented in Appendix 1.
[0123] Only if this is the case, during a step 36 the visibility management module MODViSupdates the visibility database with items of delivery flow management information to indicate that the customs formalities were carried out at Mumbai on 22 / 11 / 11 by the operator LOG-OP.Detection of anomalies
[0124] The server KX includes an anomaly detection module MODAito detect events that do not conform to the procedure defined in the configuration file FCONF-
[0125] For this purpose, the anomaly detection module MODAI accesses, for example regularly:- the visibility database BDViSto identify the events planned by the configuration file FCONF- ; and- the exception database BDEXCto check whether or not temperature measurements not conforming to the requirements of the configuration file FCONF have been recorded in it.
[0126] In the example described here, the action 1 of the third step "Carriage to Doha" makes provision for the confirmation of the execution of the export customs formalities at Doha to be carried out on 22 / 11 / 12.
[0127] If the anomaly detection module MODAI detects (during a step 37) that these formalities have not been carried out, it records an exception in the exception database BDEXC.
[0128] During a step 38, the anomaly detection module MODAI records a transaction representative of said exception in the database BDAUDIT and the server KX signs these transactions with its private key.
[0129] In the same way, the configuration file FCONF includes an indication according to which the temperature of the goods must be between 24° (lower limit BB) and 26° (upper limit BH).
[0130] If the anomaly detection module MODAI detects (step 39) by querying the exception database BDEXC a temperature measurement outside this range, it decides how to handle this exception during a step 40. To do this it uses, for example, a set of decision rules and a historical data of temperature measurements.
[0131] For example, an action can consist in alerting users having access to the workflow.
[0132] If the anomaly detection module MODAI detects (during a step 42) that goods are not located in an expected location at a given time, for example in this example in Mumbai on the morning of 22-11-12, it decides, based on a set of rules, whether or not an exception must be recorded in the exception database BDEXc-
[0133] During a step 44, the anomaly detection module MODAIrecords the exception in the audit database BDAUDrr and the server KX signs these transactions with its private key.Interactions with the operator of the customer
[0134] During a step 45, the operator CLT-OP of the customer uses his workstation PCCTO to register with the server KX.
[0135] During a step 46, the operator CLT-OP changes his password at the request of the access management module MODSGA-
[0136] During a step 47, the access management module MODSGAstores the password of the operator CLT-OP and generates an authentication token TOKCo which is stored in the browser of the workstation PCCTO of this operator.
[0137] During a step 48, the operator CLT-OP queries the server KX to know the location where the goods are located.
[0138] During a step 49, the module MODABACfor applying the ABAC security policy checks whether or not the operator CLT-OP of the logistics service provider LOG is authorized to obtain this item of information and, only if this is the case, supplies to the operator the item of location information recorded in the visibility database BDVis.APPENDIX 11: {2: "application": "KATALX_APP", 3: "comment":4: "version": "20220831",5: "policy": {6: "rules": [7: {8: "resource": "F-config",9: "action": "DOWNLOAD",10: "conditions": [11: "principakrole = 'ADM'",12: "8iprincipal:organization = 'EXP'"13: "8iprincipal:status = 'active'"14: ]15: },16: {17: "resource": "COO-doc",18: "action": "DOWNLOAD",19: "conditions": [20: "principakrole = 'OP'",21: "8iprincipal:organization = 'EXP'"22: "8iprincipal:status = 'active'"23: ]24: },25: {26: "resource": "COC-doc",27: "action": "DOWNLOAD",28: "conditions": [29: "principakrole = 'OP'",30: "8iprincipal:organization = 'EXP'"31: "8iprincipal:status = 'active'"32: ]33: },34: {35: "resource": "SHIPMENT-details",36: "action": "EDIT",37: "conditions": [38: "principakrole = 'OP'",39: "8iprincipal:organization = 'EXP'"40: "8iprincipal:status = 'active'"41: ]42: },43: {44: "resource": "CUSTOMS",45: "action": "EDIT",46: "conditions": [47: "principakrole = 'OP'",48: "&principal organization = 'LOG'",49: "8iprincipal:region = 'IN'",50: "8iprincipal:status = 'active'"51 : ]52 : },53 :54 : « ressource » : « cle»55 : « action » : « partager »56 : « conditions » : (28)57 : « principal : statut = 'actif' »58 :59 : « ressource » : « cle»60 : « action » : « obtenir»61 : « conditions » : (32)62 : « principal : location ct ['na'] »,63 : « & principal : departement ct contexte : masterKeylnfo :cryptage :departement »,64 : « & contexte: masterKeylnfo :cryptage :expiration>MAINTENANT() »65 :66 : « ressource » : « enregistrementDescription »67 : « action » : « decrypter »68: « conditions » :69: « principal : decryptionKeys ct contexte DecryptionKeys »,70: « & contexte decryption Key :expiration>MAINTENANT() »
Claims
Claims[Revendication 1] A method for controlling the delivery of goods, said method being implemented by a controlling system (KX) and including:- a step (E10, 1, 5) of registering at least one user (EXP-MGR) with an access management module (MODSGA) of said controlling system (KX) and of supplying (8) authenticating means (TOKEM) to a workstation (PCEXPM) of said at least one user (EXP-MGR);- a step (E30, 12) of obtaining a configuration file (FCONF) of the delivery, this file (FCONF) including items of information about at least one future operation that must take place during said delivery, said obtaining step being determined by (E20) an authentication (11) of said user based on said authenticating means (TOKEM) supplied to this user and by the checking (13) of a right of this user to carry out said obtaining step given a role (OP) of the user and his rights in accordance with a security policy, which contains written logical rules on access right to view and update information based on user's role and attributes associate with that role;- a step (E40, 19, 22, 26, 36) of recording a result of at least one said operation in a visibility database of the delivery (BDVis) at the request (18, 21) of a user, said recording being determined (E20) by an authentication of said user and by the checking (4) of a right of this user to formulate said request given a role (OP) of the user and his rights in accordance with said security policy which contains rules specifying roles and actions can be carry by the role; and- a step (E90, 27) of recording at least one transaction representative of said at least one operation and a signature of said transaction in an immutable and verifiable audit database (BDAUD), said signature being made using a private key of said system (KX).[Revendication 2] The controlling method as claimed in claim 1 wherein said configuration file (FCONF) includes at least certain items of information from among:- items of information about data to be entered and about the persons authorized to carry out this entry;- items of information about at least one step of carrying of the goods;- items of information about at least one document to be downloaded and about the persons authorized to carry out this downloading;- predefined delivery conditions of said future delivery.[Revendication 3] The controlling method as claimed in claim 2, wherein said data entered (24) by an authorized person (EXP-OP) include an identifier of a connectedobject configured to measure delivery conditions of said goods, the method including:- a step (E60, 28) of obtaining by the connected object, measurements of data representative of conditions of the delivery t and (29) of recording these measurements in a database of delivery conditions (BDIOT);- a step (E90, 30) of recording at least one transaction representative of said measurements and a signature of said transaction in said immutable and verifiable audit database (BDAUD), said signature being made using the private key of said system (KX); and- if said measurements do not conform to the delivery conditions of said delivery (E70), a step (E80) of recording said measurements in an exception database (BDEXC).[Revendication 4] The controlling method as claimed in one of claims 1 to 3, including, at the request (31, 48) of a user, a step (E50, 49) of querying the visibility database (BDVJS), said query being determined (E20) by an authentication of said user and by the checking (33, 47) of a right of this user to formulate this request given a role (OP) of the user and his rights in accordance with said security policy.[Revendication 5] The controlling method as claimed in one of claims 1 to 4, including:- a step (E100, 37) of checking the conformity of the items of information recorded (19, 22, 26, 36, 42) in the visibility database (BDV]s) with respect to the information of the configuration file (FCONF) and in the event of any non-conformity a step of recording an anomaly in an exception database (BDEXC); and- a step (E90, 38) of recording at least one transaction representative of said anomaly and a signature of said transaction in the immutable and verifiable audit database (BDAUD), said signature being made using the private key of said system (KX).[Revendication 6] The controlling method as claimed in claim 3, including:- a step (E110, 39) of querying the exception database (BDEXc) to identify measurements that do not conform to the delivery conditions; and, where applicable:- a step (E120, 40) of deciding on the processing to be given to this said measurement.[Revendication 7] The controlling method as claimed in claim 5 or 6 characterized in that said steps (El 10, 37) of checking conformity (E120, 40) and processing nonconforming measurements are implemented by an anomaly processing module(MODAI) trained to detect anomalies and to decide on their processing based on a set of rules and historical data.[Revendication 8] The controlling method as claimed in any of claims 1 to 7 wherein the security policy is in accordance with the ABAC model.[Revendication 9] A system (KX) for controlling the delivery of goods, said system (KX) including:- an access management module (MODSGA) configured to register at least one user (EXP-MGR) and to supply authenticating means (TOKEM) to a workstation (PCEXPM) of said at least one user (EXP-MGR);- a module for obtaininga configuration file (FCONF) of the delivery, this file (FCONF) including items of information about at least one operation that must take place during said delivery, said obtaining being determined by:(i) an authentication of said user by said access management module (MODSGA) based on said authenticating means (TOKEM) supplied to this user and by(ii) the checking (4), by a module (MODABAC) for applying security policy rules associated with roles and actions carried by a role, of a right of this user to carry out said obtaining given a role (OP) of the user and his rights in accordance with said security policy;- a module (MODVis) for managing the visibility of the delivery configured to record a result of at least one operation in a visibility database (BDViS) of the delivery at the request (18, 21) of a user, said recording being determined by:- a module for managing the visibility of the delivery configured to record a result of at least one operation in a visibility database of the delivery at the request of a user, said recording being determined by:(i) the authentication of said user by said access management module (MODSGA) and by(ii) the checking (4), by a module (MODABAc) for applying a security policy, of a right of this user to formulate said request given a role (OP) of the user and his rights in accordance with said security policy;- said visibility management module (MODVIS) being configured to record at least one transaction representative of said at least one operation and a signature of said transaction in an immutable and verifiable audit database (BDAUD), said signature being made using a private key of said system (KX).