Device for securing the use of data broadcasting, associated system and method

FR3139257B1Active Publication Date: 2025-09-05ERGYLINK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
FR2022008505
Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-08-24
Publication Date
2025-09-05
Estimated Expiration
2042-08-24

AI Technical Summary

Technical Problem

Existing data broadcasting systems are vulnerable to malicious intrusions and lack robust security measures, particularly against unauthorized transmitters, and existing cryptographic solutions are inefficient and prone to quantum computing attacks, with high implementation costs and resource requirements.

Method used

A device and method that secures data broadcasting using existing radio frequency receiver components to detect unauthorized transmitters by monitoring physical signal characteristics, such as signal strength and noise levels, without additional hardware or bandwidth, and can integrate with existing SoC technology to implement intrusion detection and response.

Benefits of technology

Provides robust, quantum-resistant security against unauthorized transmissions, reducing computing power and bandwidth usage, and enabling efficient implementation in consumer devices with minimal additional costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000028_0000
    Figure 00000028_0000
  • Figure 00000029_0000
    Figure 00000029_0000
  • Figure 00000030_0000
    Figure 00000030_0000
Patent Text Reader

Abstract

According to a first aspect, the invention relates to a device for securing the use of data broadcasting. The device (1) according to the invention comprises at least one digital processing subassembly (3), at least one microprocessor (4), at least one program memory (5), a radiofrequency receiver (6), access (7) to at least one state information (8) of the reception of said radiofrequency receiver (6), at least one program (9) for performing at least one action relating to the security of the broadcast data (2) received or being received or to be received depending on the at least one state information (8) of the reception of said radiofrequency receiver (6). According to a second aspect, the invention relates to a system for securing the use of data broadcasting comprising at least two devices according to the invention and at least one terrestrial or satellite broadcasting infrastructure.According to a third aspect, the invention relates to a method implemented by software in a system according to the invention for securing the use of data broadcasting. Figure for abstract: Fig 1.
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Device for securing the use of data broadcasting, associated system and method Technical field

[0001] The invention lies in the field of broadcasting and telecommunications. Prior art

[0002] The energetic transition towards decarbonized electricity production mainly from intermittent renewable energy sources will require the transition from a quasi-static management of the production-consumption balance by acting solely on the management of production, to a dynamic management of the balance, acting on the management of production when this is still possible but above all by acting on the management of consumption.

[0003] Apart from industrial loads which represent large powers that are easy to control with conventional automation systems communicating via standard solutions in the telecoms sector, the consumer loads in the residential sector, electric mobility and the tertiary sector are mainly diffuse loads of small or medium unit power which are distributed in massive quantities over more or less densely equipped territories.

[0004] Uses such as public and architectural lighting also consume electricity from low-power diffuse loads distributed throughout cities.

[0005] To transmit information or remote controls to large quantities of receivers, most of which are installed inside buildings, often in rooms or technical ducts far from windows, radio broadcasting infrastructures, and to a lesser extent television broadcasting or message broadcasting infrastructures, are more appropriate than telecommunications infrastructures. Infrastructures based on long-range power line transmission techniques such as centralized musical frequency remote controls (TCFM), also known as "ripple control" in English, are also data broadcasting solutions adapted to these uses but they require heavy investments in specific transmitters and require the involvement of electricity network managers.

[0006] Technical solutions designed for the dissemination of information by radio are more robust than radiofrequency solutions in the telecommunications sector. They are emitted by higher power transmitters, have a greater range, are more penetrating inside buildings due to the high transmission powers and relatively low frequencies which are little attenuated by reinforced concrete, are Often implemented redundantly in infrastructures classified as vital for countries, are inexpensive to deploy both on the existing infrastructure side and on the receiver side. Technical solutions from the broadcasting sector are also based on more stable and sustainable technical standards and are generally more energy efficient than solutions from the telecommunications sector in meeting the needs of transmitting the same information to massive quantities of receivers.

[0007] The use of data broadcasting to control diffuse loads in electrical installations offers the additional advantage of not requiring the involvement of electricity network managers.

[0008] The only drawbacks of the solutions designed for data broadcasting are their unidirectional nature descending from the infrastructure to the receivers, a lack of possibility of modulating the range of the broadcasts according to groups of receivers of interest but the technical solutions of the patent published under number FR3053188 remedy this, and a lack of protection against malicious intrusions into the systems. A malicious intrusion being for example based on short-duration emissions made from an unauthorized transmitter installed in a vehicle. It is in fact easy to power an FM transmitter of several thousand watts from a small on-board generator and to deploy a telescopic antenna to obtain from a high point a range capable of covering a relatively large territory.The risk of malicious intrusions into a broadcasting network is a major potential problem when the infrastructure is also used to transmit information used for the management of other infrastructure of systemic importance for countries, such as electricity networks. It is also desirable to protect against malicious intrusions other potential uses of data broadcasting networks such as public lighting, irrigation of food or ornamental crops, alerting populations or sensitive equipment to meteorological or environmental risks related to wind, hail, floods, air or water pollution, ionizing or electromagnetic radiation of human or solar origin.

[0009] Known solutions for enhancing the security of a data transmission channel by broadcasting are mainly based on cryptography, in particular to enable receivers to authenticate the origin of the data and to reject data that comes from unauthenticated transmitters.

[0010] The use of cryptography techniques, however, has many drawbacks. It requires the addition of data for the digital signature of useful data, requires transmission and management of encryption keys and requires significant computing power in the receivers.

[0011] Furthermore, in applications such as the control of power loads in electrical networks, there is a challenge of speed in the execution of transmitted remote controls which goes against the use of cryptography techniques. Indeed, authentication solutions mainly based on cryptography, to be sufficiently secure and robust, require the transmission of a large amount of data for the signature of the content of the messages, require calculation times in the receivers which can be long when they are executed by small common processors, or impose latencies and secure additional means for the management of encryption keys.

[0012] The reduced bandwidth of a digital communication standard based on analogue broadcasting such as RDS is also a limiting factor in the implementation of very robust cryptography solutions.

[0013] Furthermore, the imminent arrival of quantum computing will call into question the robustness of state-of-the-art cryptography solutions currently considered secure, given the ease and speed with which it will be possible to carry out brute force attacks.

[0014] Other theoretically conceivable solutions, since they are known in the field of radio networks for the Internet of Things, such as the recognition of the spectral fingerprint of the radio signal of each legitimate transmitter, would require specific computing resources and processing in a DSP included in each receiver and complex signal processing methods that are difficult and too expensive to implement in devices that must remain competitive on mass markets. The known solutions present problems of insufficient security, in particular with regard to the imminent arrival of quantum computing, of implementation costs that are too high for products manufactured in very large series and of industrialization difficulties. Presentation of the invention

[0015] The aim of the present invention is to at least partially remedy the problems mentioned above by proposing a technical solution which makes it possible to secure the transmission of digital broadcast information.

[0016] A first advantage of the invention is that it is, until proven otherwise, unstoppable in protecting a data broadcasting system against the effects of malicious intrusions aimed at acting on receivers by illegal so-called "pirate" broadcasts. A second advantage of the invention is that it can be implemented without additional hardware cost in the receivers by using existing functionalities of highly integrated reception components of the "system on a chip" type (a category of active semiconductor components better known by the acronym "SoC" in English) standards designed to meet the needs of consumer electronic devices for radio reception. A third advantage of the invention is that it does not consume additional bandwidth in the broadcasting system beyond that necessary for the transmission of useful application data and requires little computing power in the host processor of the device. This is a significant advantage for facilitating the implementation of the invention, particularly in the case of standards with limited data transport capacities such as RDS. A fourth advantage of the invention is that the considerable computing power of quantum computing will have no effect on the effectiveness of the protection provided by the invention, unlike technical solutions based on cryptography.The solutions according to the invention, which are based on physical characteristics of the radio signal and not on the transmitted data, are called "quantum-safe" or "post-quantum" according to the expressions in use in the English language.

[0017] It should be noted that the solution for securing broadcast data transmissions according to the invention is compatible with the implementation of cryptographic solutions, for example to guarantee the congruity of the data transmitted in a given context of use or to prevent the reuse of a command previously received and recorded by simple retransmission. As said cryptographic solutions no longer play a major role in securing the transmission channel against possible malicious intrusions, the quantity of data added for the signature of the useful application data can be significantly reduced without degrading the robustness of the overall security obtained.

[0018] According to a first aspect, the invention relates to a device for securing the use of terrestrial or satellite data broadcasting according to a predetermined technical norm or standard. Said device comprises:

[0019] - at least one digital processing subset comprising at least one microprocessor, at least one program memory;

[0020] - a radio frequency receiver comprising a demodulator and a decoder suitable for receiving terrestrial or satellite broadcast data according to said predetermined standard or technical standard;

[0021] - access to at least one piece of information on the status of the reception of said receiver radio frequency;

[0022] The invention further provides that the at least one program memory comprises at least one program for performing at least one action relating to the security of the broadcast data received or being received or to be received as a function of the at least one item of reception status information from said radiofrequency receiver.

[0023] The at least one digital processing subassembly is for example at least one microcontroller, or at least one system on a chip, or at least one processing unit available in the form of a printed circuit on which components and connectors are mounted to form a digital processing module having standardized technical characteristics, for example an industrial modular computer to the PC104 standard, a low-cost modular computer electronic card such as Raspberry Pi (registered trademark of the Raspberry Pi Foundation) or Arduino (registered trademark of the Arduino team).

[0024] The radio frequency receiver comprising a demodulator and a decoder suitable for receiving data broadcast by terrestrial or satellite means is advantageously based on the use of a standard highly integrated main component of the "system on a chip" type. This type of electronic component is commonly used for the reception of analog or digital radio in sedentary consumer electronic devices such as Hi-Fi system tuners or mobile ones such as stand-alone radio receivers and car radios. They comprise at least one signal processor (a category of processor better known by the acronym "DSP" in English).

[0025] In addition to the reception and restitution of the radiofrequency audio signals broadcast on the selected frequency, and where appropriate the demodulation and decoding of associated digital signals, these standard receiver components continuously calculate, measure or evaluate relevant parameters to enable the receiver to assess the state and quality of the reception. These parameters are made available to the host processor which controls the operation of the receiver circuit within the electronic device concerned. The host processor can thus read all or part of the at least one piece of status information from the receiver according to its application needs and according to the functionalities implemented in the electronic device concerned.For example, status information representative of the strength of the received radio frequency signal at a given frequency is commonly used to display the strength of the received radio frequency signal on an indicator or as part of an automatic station search to determine whether a radio station is listenable with sufficient quality at a given frequency.

[0026] Of course, it does not go beyond the scope of the invention if the at least one digital processing subassembly and the radiofrequency receiver are integrated into a single electronic component or if the functions necessary for implementing the invention are distributed differently in more than two semiconductor electronic components.

[0027] State information representative of the noise level in the signal or the signal-to-noise ratio is commonly used to automatically manage the quality of the audio content reproduced, in particular to best reproduce stereophony depending on the reception conditions. Status information such as the multipath indicator in FM is also commonly used, alone or in combination with other information in car radios to automatically select alternative frequencies broadcasting the same radio program and offering better audio reproduction quality depending on the reception conditions at a given location in a mobile situation. The multipath indicator is also particularly impacted in the event of interference due to the presence of a second transmitter operating at the same frequency as the one to which the receiver is tuned.On the other hand, the impact of the intrusion of a second transmitter on the value of the multipath indicator can be upwards or downwards depending on the wave propagation conditions which pre-existed on the basis of the first transmitter only before the intrusion of the second.

[0028] When the receiver is static and the radiofrequency propagation and reception conditions are stabilized, it is observed that most of said receiver state information varies little over time, both in amplitude and in terms of the speed of variations of said information. The invention is based on the fact that the introduction of a new transmitter into the stabilized environment of a receiver leads to a transient or lasting modification of the value of at least one piece of receiver state information. From then on, it becomes possible to detect the intrusion of a new potentially malicious transmitter and to act appropriately to counter a potential attack by this transmitter.Since this is intrusion detection carried out at the physical reception level with the same hardware means and all or part of the same software means as those used in the receiver to demodulate and decode the broadcast signal, a signal received with sufficient power to constitute a real threat on an operational level necessarily has a detectable impact from at least one standard status information produced by the reception DSP which is made available to the host processor which controls it and which is documented as such in the technical documents of the receiver component.

[0029] The invention provides that the at least one action relating to the security of the broadcast data received or being received or to be received is not to use all or part of said data, or is to use all or part of said data, or to store all or part of said data, or to activate a time delay of a predetermined duration, or to transmit at least one piece of information or at least one remote control to at least one third-party device, or to signal a state or an event to at least one user.

[0030] The invention provides that the at least one action is executed following the crossing of at least one threshold upwards or downwards, by the amplitude or by the variation of the amplitude or by the speed of variation of the amplitude, of the at least one item of reception status information of said radiofrequency receiver or of the difference between the current value of the at least one item of reception status information and a previously determined reference value of the at least one corresponding item of status information.

[0031] Crossing at least one threshold upwards or downwards means verifying the condition of at least one comparison of superiority or inferiority between the current value of the at least one piece of information, or the difference between the current value of the at least one piece of information and a reference value of this at least one piece of information, and at least one predetermined value.

[0032] According to the implementation variants of the invention, the at least one predetermined value is predetermined in the device by construction, or by calculation or by adjustment or by the reception of at least one operating parameter or a remote control. Depending on the status information of the receiver considered, the direction of its variation during the intrusion of a second transmitter is predetermined or unknown. In the latter case, only the variation of the absolute value of the value of the information is taken into account in the digital processing aimed at determining a suspicion of illegal broadcasting according to the invention.

[0033] It is provided that the device according to the invention further comprises hardware and software means capable of transmitting or receiving data within the framework of a local or remote network or direct communication with a third-party device. These means are for example capable of providing the device according to the invention with wireless, wired or optical connectivity to communicate directly or indirectly via equipment acting as a gateway, in a unidirectional or bidirectional manner, with at least one remote server or with a third-party device.

[0034] For example, to transmit at least one piece of information relating to a suspicion of illegitimate transmission to at least one remote server, or to receive at least one piece of information such as an operating parameter, a remote control or software from a remote server. Or to control or configure or update the software embedded in the device, in physical proximity to the latter, by means of a smartphone or a digital tablet running a specific downloadable application or a standard application such as an Internet browser.

[0035] This also involves, for example, establishing a connection to the Internet through hardware and software means implemented in the device. Bluetooth or Wi-Fi connectivity, for example, allows the device to indirectly access the Internet through a device installed nearby acting as a telecom gateway, such as an Internet box. Connectivity based on a standard such as NB-IoT or LTE-M allows the device to be directly connected to the Internet via a cellular telephone infrastructure.

[0036] The invention provides that said device, said standard or said predetermined technical broadcasting standard, the at least one item of reception status information of said radiofrequency receiver, are respectively:

[0037] - an energy manager, or a lighting manager, or a manager irrigation or watering, or a device delivering information, for example information of general interest, municipal information, or a device delivering advertising information, or a device delivering alert information, for example civil security alert information to warn populations in the event of danger, or a communicating electronic meter for electricity, gas, water or heat or cold, or an optional accessory providing reception of broadcast data to another device, or a device acting as a communication gateway, or a supervision system, or a transmitter, or a transmitter used as a transmitter, or a transponder, or an access point to a local network, or an access point to a wide area network;

[0038] - FM-RDS1, or FM-RDS2, or DAB, or DAB+, or HD Radio, or DMB, or DRM, or DVB-S, or DVB-SH, or Sirius XM;

[0039] - the absolute or relative power or level of the received radio signal, or the level absolute or relative noise, or the signal-to-noise ratio, or the multipath indicator, or the offset between the radio frequency of the received transmitter and the nominal frequency of the station to which the receiver is tuned, or the width of the frequency band occupied by the received signal, after frequency change if applicable, or the indicator of the average or maximum modulation percentage, or the decoder error rate, or the content of broadcast information, or the time related to the reception of information normally broadcast recurrently, or the quality indicator of the fast information channel of a digital radio standard, or the FFT offset indicator.

[0040] These last two pieces of information on the status of the reception of said radiofrequency receiver are specific to the reception of digital radio.

[0041] The characteristics of the digital values ​​of the radio reception status information depend in whole or in part on the implementation of the monitoring functions in the electronic receiver components used. In particular their representation in an arbitrary unit or in a standardized unit. Similarly, the resolution and the extent of each reception status information which can be used in the context of the implementation of the invention depends on the internal choices which have been made by the designers of the radio receiver component used. According to the implementation variants of the device according to the invention, it is planned to adapt all or part of the at least one program to perform at least one action related to the security of broadcast data to the technical characteristics of the radio receiver component used.

[0042] The data broadcasting standard known as "FM-RDS1" is the standard based on analog radio broadcasting on the FM band using a 57 KHz subcarrier of the historical RDS standard referenced EN50067. The 57 KHz subcarrier has become the first of the four subcarriers of the so-called "FM-RDS2" revision of the RDS standard which is referenced IEC62106. It is intended to use all or part of the four data streams defined in this standard in the context of the implementation of the invention.

[0043] These broadcasting standards are cited as non-limiting examples, the invention provides for the use of any broadcasting standard for terrestrial or satellite radio or television capable of also broadcasting data.

[0044] According to a second aspect, the invention also relates to a system for securing the use of terrestrial or satellite data broadcasting according to a predetermined technical norm or standard. Said system comprises at least two devices according to the invention and at least one terrestrial or satellite broadcasting infrastructure.

[0045] It is envisaged that the system according to the invention further comprises additional hardware or software means for confirming the detection of illegal broadcasting or for improving the sensitivity or specificity of the detection.

[0046] Additional hardware or software means, for example, at least one server connected to a telecommunications network running at least one software program implementing the method according to the invention, for example to confirm or even to invalidate a suspicion of detection, or to process in a more elaborate manner reception status information transmitted by devices according to the invention. These additional means are also, for example, at least one professional equipment for monitoring all or part of the radiofrequency spectrum, also known as a “radiofrequency probe”, deployed in the coverage area of ​​the broadcasting infrastructure to monitor the quality of reception of legitimate transmitters and detect disturbances, including intrusions by unauthorized transmitters.Professional electronic devices dedicated to monitoring the radio frequency spectrum are in fact capable of detecting intrusive transmitters more sensitively and more precisely thanks to significant signal processing power, the implementation of dedicated algorithms, an antenna and a radio front end, optimized for monitoring the radio frequency spectrum of interest. These professional monitoring devices are capable of implementing technical solutions for detecting intrusive emissions based on the measurement of physical characteristics of the received signal, as in the device and method according to the invention, but in a more . efficient than an implementation of the invention from receiver components designed for the consumer electronics market. These surveillance devices are also capable of implementing techniques for recognizing authorized radio transmitters by their specific radiofrequency spectral fingerprint or by recognizing the presence of at least one predetermined "tattoo" in the radiofrequency signal or in the demodulated audiofrequency signal. Any transmitter not recognized by the at least one surveillance device as an authorized transmitter is deemed to be an intruder transmitter. These radiofrequency spectrum monitoring devices are also capable of implementing techniques for estimating the geolocation of intruder transmitters, in particular by using triangulation techniques.

[0047] According to a third aspect, the invention also relates to a method implemented by software in a system according to the invention for securing the use of terrestrial or satellite data broadcasting according to a predetermined technical norm or standard. Said method comprises a step of monitoring at least one item of reception status information from a radiofrequency receiver and a step of executing at least one processing operation relating to the security of the broadcast data received or being received or to be received as a function of the at least one item of reception status information from said radiofrequency receiver.

[0048] The method according to the invention is implemented by software in a system according to the invention, that is to say in at least one device according to the invention or in at least one piece of equipment included in the associated broadcasting infrastructure.

[0049] According to the implementation variants of the invention, the at least one item of reception status information of said radiofrequency receiver of a device according to the invention is more or less partly processed by the device or by the at least one remote equipment included in the broadcasting infrastructure. Implementation variants are in fact provided where the at least one device according to the invention fully processes the at least one item of reception status information of said radiofrequency receiver to detect a suspicion of intrusion by an unauthorized transmitter and to act appropriately if necessary.Implementation variants are also provided where the at least one device according to the invention transmits the at least one reception status information of said receiver that it comprises, raw or partially processed, to at least one remote equipment included in the associated broadcasting infrastructure which processes the at least one reception status information of said radio frequency receiver received to detect a suspicion of intrusion by an unauthorized transmitter and act appropriately accordingly. The invention further provides refinements such as the provision, by the device or by the equipment of the associated broadcasting infrastructure suspecting an intrusion. of unauthorized transmitter, additional information relating to the trust that can be placed in the intrusion detection information or relating to the geographical location of the detected intruder transmitter.

[0050] It is provided in the method according to the invention that the at least one processing is, the deactivation of the use of all or part of the broadcast data received or in the process of being received or to be received, or the activation of the use of all or part of the broadcast data received or in the process of being received or to be received, or the storage of all or part of the broadcast data received or in the process of being received or to be received, or the activation of a time delay of a predetermined duration during which all or part of the broadcast data received or in the process of being received or to be received are not used, or the transmission to at least one third-party device of at least one piece of information or at least one remote control, or the signaling of a state or an event to at least one user.

[0051] It is provided in the method according to the invention that the at least one processing operation relating to the security of the broadcast data received or being received or to be received is executed following the crossing of at least one threshold, by the amplitude or by the variation of the amplitude or by the speed of variation of the amplitude, of the at least one item of reception status information of said radiofrequency receiver.

[0052] It is provided that the method according to the invention further comprises a step of calculating at least one reference value of the at least one item of state information of the reception of said radiofrequency receiver to which to compare in a recurring manner the current value of the at least one corresponding item of state information.

[0053] It is further provided that said reference value is continuously updated in steady state.

[0054] It is provided that the method according to the invention further comprises a step of automatically adjusting at least one threshold or at least one decision-making criterion from the current value of the at least one piece of state information.

[0055] It is provided that the method according to the invention further comprises a step of determining that an illegal broadcast is detected from information previously received from a predetermined number of devices according to the invention installed in the same geographical area. For example from information previously received substantially at the same time from at least two devices.

[0056] It is provided that the method according to the invention further comprises a step of transmission by said additional hardware or software means of the system, where appropriate, of at least one item of information to at least one device according to the invention or to at least one user, or to at least one authority when illegal broadcasting is detected.

[0057] This refinement of the invention provides for example that a server included in the broadcasting infrastructure having determined that an intrusion has been detected after having received substantially at the same time at least one item of information of suspicion of intrusion from a predetermined number of devices according to the invention located in the same reception zone, transmits to said devices an item of information confirming intrusion detection. The effect of the reception of said confirmation information by said devices being for example to maintain for an indefinite period the inhibition of the exploitation of all or part of the broadcast data received or being received or to be received, and to deactivate the time delay for total or partial automatic reopening of the broadcast data reception channel.The total or partial reopening of the broadcast data reception channel is carried out by reception of an appropriate remote control or by the expiry of a very long time delay advantageously implemented in the devices according to the invention to prevent devices which have not received said appropriate remote control from remaining indefinitely with reception of the broadcast data wholly or partly inhibited.

[0058] This refinement of the invention also provides, for example, that a server included in the broadcasting infrastructure having determined that an intrusion has been detected after listeners have warned the radio station or an authority of the existence of interference hindering reception, by any means such as, for example, the telephone, an Internet website, by e-mail or via a social network.

[0059] This refinement of the invention also provides, for example, that at least one piece of radiofrequency probe type equipment included in the broadcasting infrastructure and capable of detecting intrusions therein more efficiently than by monitoring at least one reception status in at least two devices according to the invention, having determined that an intrusion has been detected, transmits to said devices a first remote control, the reception of which by said devices has the effect, for example, of maintaining or imposing for an indefinite period the inhibition of the use of all or part of the broadcast data received or being received or to be received. The total or partial reopening of the broadcast data reception channel is done, for example, as described in the preceding paragraph.

[0060] The transmission of at least one piece of information to at least one user or at least one authority when an illegal broadcast is detected is a refinement of the invention which aims to alert the appropriate person, for example an operations manager, a person from the radio station concerned or an authority responsible for enforcing the use of frequencies, or the police, to act so that the illegal broadcast which has been detected ceases.

[0061] Advantageously, the at least one piece of information transmitted to at least one authority by a server or by radiofrequency probe type equipment included in the broadcasting infrastructure, comprises at least one piece of information on the time stamp of the detection of the detected intrusion or at least one piece of information on the probable geographical location of the detected illegal transmitter.

[0062] The probable location of the detected intruder transmitter is obtained for example by determining the barycenter of the locations of the devices according to the invention, the individual locations of which are known to the system, having signaled the detection of a suspicion of intruder emission in the same time window.

[0063] The probable location of the detected intruder transmitter is also obtained, for example, by triangulation from intrusion detection information simultaneously obtained by several radiofrequency probe type devices included in the broadcasting infrastructure.

[0064] The location information being for example expressed in the form of a geographic address or in standardized geolocation coordinates of the GPS type.

[0065] The transmission of information or remote control from equipment of the broadcasting infrastructure to at least one device according to the invention is done by broadcasting or by an additional transmission channel where appropriate.

[0066] It is in fact provided that the reception of the broadcast data in the devices according to the invention remains continuously usable for information or remote controls relating to the management of the security of the broadcast data reception channel while being inhibited or blocked for application data relating to the lawful use of the data broadcast that the invention aims to protect against malicious illegal broadcasts.

[0067] The invention provides that artificial intelligence techniques such as, for example, machine learning are used to automatically optimize the operation of the device or system or method according to the invention.

[0068] The invention provides for the use of the device and method according to the invention for the management of electrical networks, in particular for the direct control of the flexibility of consumption of decentralized power loads or by the transmission of information relating to the price of electricity or greenhouse gas emissions.

[0069] The invention provides for the use of the device and method according to the invention for the management of public or architectural lighting.

[0070] The invention provides for the use of the device and the method according to the invention for the management of water distribution networks or for the management of plant irrigation. Brief description of the drawings

[0071] Other advantages and characteristics of the invention will appear on examining the detailed description of non-limiting embodiments, and the appended drawings where:

[0072] [Fig-1] illustrates the internal structure of the device according to the invention.

[0073] [Fig.2] illustrates a first variant of the system according to the invention.

[0074] [Fig.3] illustrates a second variant of the system according to the invention.

[0075] [Fig.4] illustrates the method according to the invention implemented by software in the device according to the invention.

[0076] [Fig.5] illustrates the method according to the invention implemented by software in at least one server included in the system according to the invention. Detailed description

[0077] [Fig.l] illustrates the internal structure of the device according to the invention.

[0078] The device 1 according to the invention for securing the use of radio broadcasting of data 2 by terrestrial or satellite means according to a predetermined technical standard or norm comprises at least one digital processing subassembly 3 comprising at least one microprocessor 4, at least one program memory 5, a radio frequency receiver 6 comprising a demodulator and a decoder suitable for receiving broadcast data 2, an access 7 to at least one status information 8 of the reception of said radio frequency receiver 6. The at least one program memory 5 comprises at least one program 9 for carrying out at least one action relating to the security of the broadcast data received or being received or to be received depending on the at least one status information 8 of the reception of said radio frequency receiver 6.

[0079] In certain variants of implementation of the invention, the device 1 further comprises hardware and software means capable of transmitting or receiving data within the framework of a local or remote network or direct communication with a third-party device. For example, a component or module acting as a Bluetooth or Wi-Fi or NB-IoT or LTE-M or Wi-SUN or LoRaWAN or Sigfox modem or equivalents and successors of these telecommunications standards, and its software stack of protocols.

[0080] In the case of data broadcasting according to the RDS technical standard which is based on analog broadcasting on the FM band, the invention is for example easily and economically implemented from highly integrated components of the common “system on a chip” type which have been designed to be implemented in consumer electronic devices.

[0081] The at least one digital processing subassembly 3 is for example an 8-bit or 16-bit microcontroller from the “AVR” or “PIC” families (registered trademarks of Atmel Corporation and Microchip Technology Inc.). Or one of the numerous microcontrollers or components of the “system on a chip” type comprising at least one 32-bit or 64-bit microprocessor with ARM architecture.

[0082] The radio frequency receiver 6 comprising a demodulator and a decoder suitable for receiving broadcast data 2 and access to at least one state information 8 of the reception of said radio frequency receiver 6 is advantageously based on the use of a highly integrated component of the system-on-a-chip type for the reception of FM radio or digital radio such as for example the TEF668x or the SAF360x from NXP BV, or the Si470x or the Si46xx or the Si46xx from Skyworks Solutions Inc., or the TDA7708 or the TDA7707 from STMicroelectronics NV.

[0083] These components receiving broadcast data are in fact capable of communicating with the microcontroller or the system on a chip which controls them via a control interface based on a two- or three-wire serial bus, for example to the “I2C BUS” standard (registered trademark of NXP BV). The same serial bus is also capable of allowing the microcontroller to receive the broadcast data received by the component and to read at least one of its registers containing at least one reception status information.

[0084] The program memory 5 of the microcontroller 3 further comprises at least one program 9 for performing at least one action relating to the security of the broadcast data received or being received or to be received as a function of the at least one item of reception status information of said radiofrequency receiver 6.

[0085] For example, most radio receiver components based on digital signal processing, in particular those whose references have been cited previously, provide access to numerous registers containing the continuously updated value of reception status information such as the power of the received signal, the noise level, etc.It is provided, for example, that the program of the microcontroller implementing the invention recurrently reads at a relatively rapid rate the value of all or part of the reception status information available in the receiver component implemented, for example over a period of between several tens and several hundreds of milliseconds to allow short reaction times, in particular to deactivate the use of all or part of the broadcast data received or being received or to be received in the event of suspicion of intrusion before any possible broadcasts of malicious data produce undesirable effects.

[0086] It is also provided that the program of the microcontroller implementing the invention dampens the variations of the at least one item of state information 8 of the reception by calculating an average value or by integrating the monitored state information over time.

[0087] It is also provided that the program of the microcontroller implementing the invention calculates a reference value in a normal and stabilized situation of the at least one piece of state information to which to periodically compare the current value of the at least one corresponding piece of state information. This has the advantage of making the method according to the invention self-adaptive according to the particular reception conditions of each receiver and their changes over time.

[0088] The calculation of a reference value to which to compare the current value of the same variable information assumes a significant difference in integration time between the two quantities. Thus, the integration time to obtain a reference value in a normal and stabilized situation of the at least one piece of state information is for example between 1 second and one hour depending on the refresh frequency or the nature of the at least one piece of state information considered. The direction of the comparison is determined according to the quantity observed so that the crossing of a threshold associated with the detection of a suspicion of intrusion by an unauthorized transmitter is consistent with a sudden improvement in all or part of the reception quality indicators or with the appearance of interference.

[0089] For example, a suspicion of intrusion is detected if the current value of the power of the received signal becomes greater than the reference value of the power of the received signal in steady state by a first predetermined number of units or if the current value of the received noise level becomes less than the reference value of the noise level in steady state by a second predetermined number of units. Said first and second numbers of units, the integration time of all or part of the reference values, the periodicity of the comparisons between the reference value and the current value of a reception status information depend on the reception component implemented and the desired sensitivity or specificity.

[0090] It is also provided that the program of the microcontroller implementing the invention processes at least two pieces of reception state information in a dependent manner. This is done for example by means of a calculation formula linking the values ​​of the at least two pieces of reception state information, or by means of at least one conditionality relationship on the value of at least one piece of state information which depends on at least one value of at least one other piece of state information.

[0091] All or part of the operating parameters of the invention can advantageously be modified remotely, or locally by implementing complementary methods based on self-learning to optimize the parameterization in order to obtain satisfactory sensitivity and specificity in the context of use of the invention.

[0092] [Fig.2] illustrates a first variant of the system according to the invention.

[0093] The system 12 for securing the use of data broadcasting by terrestrial or satellite means according to a predetermined technical norm or standard, comprises at least two devices 1a, 1b, 1c according to the invention and at least one terrestrial or satellite broadcasting infrastructure 13. In the illustration of the at least one broadcasting infrastructure 13, [Fig. 2] comprises at least one satellite 14 which, according to the implementation variants of the invention, is capable of carrying out direct broadcasting to the receiving devices 1a, 1b, 1c or indirect broadcasting via at least one terrestrial broadcasting transmitter 15 capable of covering a given territory. Of course, the scope of the invention does not go beyond the most frequent case of an exclusively terrestrial broadcasting infrastructure, or even comprising only a single transmitter, or in the case of an exclusively satellite broadcasting infrastructure.

[0094] An illegal transmitter 16 which in principle does not belong to the system according to the invention 12 but which is an intruder associated with a risk of potential piracy of a service using broadcast data that the implementation of the invention aims to protect.

[0095] When the intruder transmitter 16 begins to transmit at the same frequency as that used to broadcast data legally, a first group 1a of devices according to the invention detects a suspicion of illegal transmission by the effect produced on the value of at least one item of reception status information. The devices having detected the intrusion act in particular by suspending the use of all or part of the broadcast data received or being received or to be received, where appropriate by storing all or part of said data in order to be able to use them later if the intrusion is not confirmed, and advantageously by activating a time delay of a predetermined duration during which the protective action(s) implemented from the start of the detection of a suspicious transmission are maintained, and at the end of which the device resumes its normal operation.

[0096] In certain advantageous variants of implementation of the invention, said time delay sees its duration modified upwards or is forced to expire immediately by the reception of a remote control respectively confirming or denying the intrusion.

[0097] In the implementation variants of the invention in which the at least one device comprises hardware and software means capable of transmitting data within the framework of a local or remote network or direct communication with a third-party device, it is also provided that the at least one device having detected a suspicion of illegal emission further acts by transmitting at least one piece of information to at least one third-party device such as a computer server 11 or by signaling a status or event to at least one user, locally on the device, for example by means of a visual indicator, or remotely by transmitting a notification by any usual means of telecommunication.

[0098] In an advantageous implementation variant of the invention, the system further comprises at least one remote server 11 connected to a telecommunications network 17 enabling it to communicate with devices 1a, 1b, 1c according to the invention which comprise hardware and software means capable at least of transmitting data in the device-to-infrastructure direction. Each device 1a according to the invention which locally detects a suspicion of illegal transmission on the frequency used transmits at least one piece of information relating to this detection to the server 11.

[0099] The server which receives the detection information from all the devices according to the invention having detected a suspicion of illegal transmission can then confirm or not the occurrence of an illegal transmission depending respectively on whether at least a predetermined number of devices according to the invention receiving data broadcast on the same frequency and installed in the same geographical area have detected a suspicious transmission substantially simultaneously, or not.

[0100] If the detection confirmation criteria are satisfied and it was therefore indeed an illegal transmission, then in certain advantageous variants of the invention, the server 11 transmits to the infrastructure a request for broadcasting a confirmation remote control having the effect of suspending for an indefinite period the exploitation of the part of the data which is likely to impact the service provided by the device.

[0101] In certain advantageous implementation variants, it is provided that the reception of the confirmation remote control prolongs the suspension of the exploitation of the data for a second predetermined duration much longer than the initial suspension duration in order to protect the system from the effects of a potential hack, while excluding the possibility of a definitive blocking of the exploitation in devices which would not receive the remote control also transmitted by the server 11 at the end of the processing of the incident to restore the capacity to exploit the data received in the devices concerned.

[0102] If the detection confirmation criteria are not satisfied and it was a false alert, then according to the implementation variants of the invention, the server allows the at least one device having suspected a detection of illegal transmission to reactivate the reception of its application data, and where appropriate to use data which had been stored during the suspension while waiting for the doubt raised by server 11, upon expiry of the timer currently running.

[0103] In certain advantageous variants, the server 11 transmits to the infrastructure a request for broadcasting a remote control for immediate return to normal which is part of the application data that can be received unconditionally by the devices, even if the use of the part of the data that is likely to impact the service provided by the device is suspended due to suspicion of detection of illegal transmission associated with a risk of piracy. The reception of the remote control for return to normal by the at least one device 1a having detected a suspicious transmission has the effect of immediately executing the planned processing operations upon the expiry of the current time delay and thus of restoring as quickly as possible all the functional capacities of the at least one device as well as its capacities to detect new suspicious transmissions.

[0104] Any devices in group 1a that have not received said remote control, for whatever reason, regain all of their capabilities upon expiry of their timeout, which makes this variant implementation of the invention particularly robust because the devices, by design, cannot remain indefinitely with application data reception capabilities suspended. Certain variant implementations of the invention provide that the reception of said remote control by the devices 1b that have not previously detected a suspicious transmission has no effect on them.

[0105] In advantageous implementation variants of the invention, the at least one remote server 11 associates a geographical location with each device of the system according to the invention, for example by querying a database associating at least one unique identification element specific to each of the devices 1a, 1b, 1c with the GPS coordinates or the postal address of the place where it has been installed.

[0106] In advantageous implementation variants of the invention, the detection of a suspicion of intrusion by a plurality of devices according to the invention distributed in the coverage area of ​​an illegal transmitter 16 of which at least one server 11 knows the location of each of the devices 1a allows an estimation of the geolocation of the illegal transmitter 16, for example by triangulation. It is also planned to refine the estimation of the geolocation of the illegal transmitter 16 by exploiting at least one piece of information of the state of the reception transmitted by each device 1a having detected the intrusion, for example the power of the received signal which is linked to the distance which separates the illegal transmitter from the receiver carrying out the measurement.

[0107] It is also provided in certain variants that each device 1a, 1b, calculates and transmits to the at least one server synthetic information representative of the degree of confidence that can be granted to the detection of a suspicion of intrusion.

[0108] Variants of implementation of the invention which are associated with a capacity for geolocation of an intruder transmitter and with control of the broadcasting zone of the remote controls transmitted by the at least one server 11 provide that the reception of a remote control by the devices 11 having not detected a suspicious transmission but nevertheless being included in the estimated coverage zone of the intruder transmitter 16 has the same effect as for devices 11 having detected a suspicion of illegal transmission.

[0109] Refinements of the invention are also provided where the remote controls relating to the confirmation or denial of the detection of an illegal broadcast are transmitted by broadcasting to the infrastructure devices only by the at least one transmitter covering the estimated coverage area of ​​the detected illegal transmitter. Variants are also provided where the remote controls are transmitted by broadcasting by restricting the logical range of the transmitters concerned by additional data to adjust even more precisely the overlap of the coverage areas and thus reduce the operational impact to the strict minimum.

[0110] It is also planned to transmit the remote controls to the devices concerned by a point-to-point link using at least one telecommunications network to reduce as much as possible the operational impact of reception suspensions.

[0111] It is also provided that the at least one server automatically reports the detection of a proven illegal broadcast to the competent authorities in the territory concerned to stop the detected illegal broadcast or to arrest the offenders.

[0112] In certain advantageous variants of the invention, the automatic reporting of the detection of a proven illegal broadcast to the authorities includes the transmission of additional information such as the estimated geolocation of the illegal transmitter, the estimated radiated power, the timestamp of the broadcasts.

[0113] [Fig.3] illustrates a second variant of the system according to the invention.

[0114] The variant of [Fig. 3] differs from that of [Fig. 2] in that the system according to the invention further comprises at least one professional equipment 18 for monitoring all or part of the radio frequency spectrum known as a “radio frequency probe” which is deployed in the coverage area of ​​the broadcasting infrastructure 13. The radio frequency probes 18 are designed primarily to continuously monitor the quality of the signal emitted by one or more radio stations, the continuity of services and interference produced by illegal transmitters 16. Fixed radio frequency probes are commonly used by radio stations, by broadcasters or by the authorities responsible for enforcing the law in force in a given territory regarding the use of the radio frequency spectrum. Mobile versions of this equipment are also used by the competent authorities to locate illegal or pirate transmitters 16.These equipments. Mobile sensors are most often installed in vans comprising a directional antenna, precise geolocation means, calculation means and means of communication to locate the illegal emission point by direction finding and to seize the emission equipment at the scene of the offense or to seal it. It is planned, where appropriate, to optimize the operation of the radiofrequency probes implemented within the framework of the invention to reinforce the security of the use of data broadcasting. This is for example by appropriate updates of their embedded software, by scripts or by specific settings or by specific versions of the equipment.

[0115] It is also planned to carry out additional computer processing in at least one server 11 included in the broadcasting infrastructure 13 of the system 12 according to the invention to supplement processing executed in radiofrequency probes 18. According to the variants of implementation of the invention or according to the choices of the operator, the increased detection capacity of pirate broadcasts that the use of a plurality of radiofrequency probes 18 distributed in the coverage area of ​​the broadcasting infrastructure 13 concerned allows is used in addition to the detection capacities embedded in the devices 1a, 1b according to the invention or as a substitute for the latter.

[0116] [Fig.4] illustrates the method according to the invention implemented by software in the device according to the invention.

[0117] After its initialization step 19, each device according to the invention executes in a loop monitoring processing of at least one piece of information on the state of the reception of the radiofrequency receiver that it includes and carries out a test 20 on the verification of the conditions for detecting suspected intrusion of an illegal transmitter as a function of the at least one piece of information on the state of the reception of the radiofrequency receiver included in the device.

[0118] In the case where a suspicion of intrusion by an illegal transmitter is detected, at least one processing 21 is carried out to suspend the use of all or part of the data received, or being received, or to be received. In advantageous variants of implementation of the invention, at least one additional processing is carried out. For example, the processing 22 of launching a timer whose expiry causes the reactivation of the use of all or part of the data whose use was previously suspended in step 21. Or for example, the processing 23 of storing the data received from the moment of the suspension of their use with a view to their subsequent use if the detection of an illegal transmission is not confirmed, for example in the case of a fortuitous transient disturbance of the reception conditions of the radio which is not associated with a risk of piracy of a service.Or for example the processing 24 of transmission to at least one server. remotely via at least one telecommunications network of at least one piece of information relating to the detection of a suspicion of illegal transmission.

[0119] [Fig.5] illustrates the method according to the invention implemented by software in at least one server included in the system according to the invention.

[0120] After its initialization step 25, the at least one server included in the system according to the invention executes in a loop processing operations for monitoring the reception of at least one piece of information relating to the detection of a suspicion of illegal transmission transmitted by at least one device according to the invention included in the system, and performs a test 26 on the verification of the conditions for a confirmation of the detection of intrusion of an illegal transmitter. The confirmation of the intrusion detection is deemed verified for example if at least a predetermined number of devices according to the invention installed in the same geographical area have detected substantially at the same time a suspicion of illegal transmission by executing the method according to the invention, or if at least one piece of monitoring equipment of the radiofrequency probe type included in the broadcasting infrastructure has detected an illegal transmission.

[0121] In the case where the intrusion of an illegal transmitter is confirmed, at least one processing 27 is carried out to transmit information confirming the detection of an intrusion of an illegal transmitter to all or part of the devices according to the invention included in the system according to the invention. All or part of the devices receiving the confirmation information act at their level accordingly, for example by extending the timeout for suspending the use of the received data beyond the duration which is necessary for the competent authorities to deal with the incident by stopping the illegal transmission and thus eliminating the associated risk of piracy. The duration of the extension of the timeout is predetermined in the software executed by the devices according to the invention or received by the latter as a parameter with the information confirming the detection transmitted by the at least one server.Or, by maintaining the suspension of the use of the received data until the receipt of information on the lifting of the system protection measures. In advantageous variants of implementation of the invention, at least one additional processing 28 is carried out. For example, the transmission to at least one competent authority in the territory where the law has been infringed, of at least one information on the detection of an illegal broadcast via at least one telecommunications network. The information on the detection of an illegal broadcast advantageously includes all the information known to the system according to the invention that may be useful to the authorities for locating the pirate transmitter or for characterizing the offense. The additional information transmitted is by . example the timestamp of the illegal broadcast, an estimate of the geolocation of the pirate transmitter or an estimate of its transmission power.

[0122] In advantageous variants of implementation of the invention, at least one processing 29 is carried out in the case where the conditions for detecting an illegal broadcast are not verified. This processing is for example the transmission to the devices included in the system according to the invention of alert lifting information. The reception of this information by the devices concerned causes an immediate return to their normal operation by reactivating the possibility of using the broadcast data received, and where appropriate, the a posteriori use of the data which were stored during the suspension of their use. The transmissions of the confirmation or alert lifting information are carried out, according to the variants of implementation of the invention, by the broadcasting infrastructure used for the broadcasting of the data within the system according to the invention, or where appropriate, by using at least one telecommunications network.

[0123] Of course, the invention is not limited to the examples which have just been described and numerous adjustments can be made thereto without departing from the scope of the invention, in particular by combining several variants in the same implementation or by combining elements taken from several examples differently or by using other technical standards functionally equivalent to those which are cited as examples, in particular their successors.

Claims

Claims

1. Device (1) for securing the use of data broadcasting (2) by terrestrial or satellite means, comprising: - at least one digital processing subassembly (3) comprising at least one microprocessor (4), at least one program memory (5); - a radiofrequency receiver (6) comprising a demodulator and a decoder suitable for receiving data broadcast (2) by terrestrial or satellite means; - access (7) to at least one state information (8) of the reception of said radiofrequency receiver (6);said device (1) being characterized in that the at least one program memory (5) comprises at least one program (9) for performing at least one action relating to the security of the broadcast data (2) received or being received or to be received as a function of the at least one item of status information (8) of the reception of said radiofrequency receiver (6), the at least one action being to suspend the use by said device of all or part of said broadcast data (2) received, or being received, or to be received.;

2. Device according to claim 1 characterized in that the at least one action related to the security of said broadcast data (2) received or being received or to be received is furthermore not to use all or part of said data, or is to use all or part of said data, or to store all or part of said data, or to activate a time delay of a predetermined duration, or to transmit at least one piece of information or at least one remote control to at least one third-party equipment, or to signal a state or an event to at least one user.

3. Device according to any one of claims 1 or 2 characterized in that the at least one action is executed following the crossing of at least one threshold upwards or downwards, by the amplitude or by the variation of the amplitude or by the speed of variation of the amplitude, of the at least one item of state information of the reception of said radiofrequency receiver or of the difference between the current value of the at least one item of state information (8) of the reception and a reference value previously determined from the at least one corresponding status information (8).

4. Device according to any one of claims 1 to 3, characterized in that it further comprises hardware and software means capable of transmitting or receiving data (10) within the framework of a local or remote network or direct communication with a third-party device.

5. Device according to any one of claims 1 to 4 characterized in that said device (1), the at least one status information (8) of the reception of said radiofrequency receiver (6) are respectively: - an energy manager, or a lighting manager, or an irrigation or watering manager, or a device delivering information, or a device delivering advertising information, or a device delivering alert information, or a communicating electronic meter of electrical energy, gas, water or heat or cold, or an optional accessory providing the reception of broadcast data to another device, or a device acting as a communication gateway, or a supervision system, or a transmitter, or a transmitter used as a transmitter, or a transponder, or an access point to a local network, or an access point to a wide area network;- the absolute or relative power or level of the received radio signal, or the absolute or relative noise level, or the signal-to-noise ratio, or the multipath indicator, or the offset between the radio frequency of the received transmitter and the nominal frequency of the station to which the receiver is tuned, or the width of the frequency band occupied by the received signal, after frequency change where applicable, or the indicator of the average or maximum modulation percentage, or the decoder error rate, or the content of broadcast information, or the time related to the reception of information normally broadcast recurrently, or the quality indicator of the fast information channel of a digital radio standard, or the offset indicator of an FFT;

6. System (12) for securing the use of terrestrial or satellite data broadcasting, characterized in that it comprises at least two devices (la, 1b, 1c) according to any one of claims 1 to 5 and at least one terrestrial or satellite broadcasting infrastructure (13).

7. System (12) according to claim 6 characterized in that it further comprises additional hardware or software means (11, 18) for confirming the detection of an illegal broadcast or for improving the sensitivity or specificity of the detection.

8. Method implemented by software in a system (12) according to claim 6 for securing the use of terrestrial or satellite data broadcasting, said method being characterized in that it comprises a step of monitoring at least one item of reception status information from a radiofrequency receiver and a step of executing at least one processing operation relating to the security of the broadcast data received or being received or to be received as a function of the at least one item of reception status information from said radiofrequency receiver.

9. Method according to claim 8 characterized in that the at least one processing is, the deactivation of the use of all or part of the broadcast data received or in the process of being received or to be received, or the activation of the use of all or part of the broadcast data received or in the process of being received or to be received, or the storage of all or part of the broadcast data received or in the process of being received or to be received, or the activation of a time delay of a predetermined duration during which all or part of the broadcast data received or in the process of being received or to be received are not used, or the transmission to at least one third-party device of at least one piece of information or at least one remote control, or the signaling of a state or an event.

10. Method according to any one of claims 8 or 9, characterized in that it further comprises a step of calculating at least one reference value of the at least one item of state information of the reception of said radiofrequency receiver to which to compare in a recurring manner the current value of the at least one corresponding item of state information.

11. Method according to any one of claims 8 to 10 characterized in that it further comprises a step of determining that an illegal broadcast is detected from information previously received from a predetermined number of devices according to any one of claims 1 to 5 installed in the same geographical area.

12. Method according to any one of claims 8 to 11, characterized in that it further comprises a step of transmitting, by additional hardware or software means of the system, at least one item of information to at least one device according to any one of claims 1 to 5, or to at least one user, or to at least one authority when illegal broadcasting is detected.