NON-POE DEVICE AUTHENTICATION DEVICE
By employing an analog trace generation device to simulate a unique startup trace for non-POE devices connected to a POE injector or switch, the authentication of these devices is simplified and secured, addressing the inadequacies of existing methods and reducing hacking risks.
Patent Information
- Application Number
- FR2022010863
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-10-20
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-10-20
AI Technical Summary
Existing authentication methods for non-POE peripherals connected to a POE injector or switch are inadequate, as they can be easily bypassed and require complex implementations, posing risks of hacking and destabilization of computer systems.
An analog trace generation device is used between the non-POE device and the POE injector or switch, simulating a unique startup analog trace to authenticate the non-POE device using a similar technique to that used for POE devices, thereby simplifying the authentication process and reducing hacking risks.
This solution allows for the secure and simple authentication of non-POE devices, reducing the risk of hacking and system destabilization, while being easier to implement than complex authentication systems.
Smart Images

Figure 00000018_0000 
Figure 00000018_0001 
Figure 00000019_0000
Abstract
Description
Title of the invention: DEVICE FOR AUTHENTICATING A NON-POE PERIPHERAL Technical field
[0001] The present invention relates to the field of authentication of peripherals connected to a computer network.
[0002] The invention relates more particularly to the authentication of peripherals connected to an injector or a switch, i.e. a device capable of injecting an electrical voltage into a network cable. This power supply technology is called "POE" (according to the English expression "Power Over Ethernet") in the literature.
[0003] More specifically, the invention aims at the authentication of a non-POE device connected to a POE injector or switch.
[0004] For the purposes of the invention, a “peripheral” may correspond to a computer, an embedded system, an electromechanical device such as a camera, a door switch, a connected air conditioner or any other system that can be connected by a network cable. A “non-POE peripheral” corresponds to a peripheral that is not powered by POE technology.
[0005] Thus, the invention can be used in a large number of sectors of activity to manage various equipment. Prior art
[0006] To authenticate a device on a network, it is known to request the physical address of the device and to check if this physical address is registered in a list of predefined addresses. The physical address is better known by the acronym MAC address for "Media Access Control" in the literature. This MAC address is supposed to be unique for each device.
[0007] However, it is possible to change this MAC address and thus bypass the authentication performed by the MAC address. Furthermore, it may be cumbersome to look up the MAC address of a device and register it on the authentication device when installing a new device.
[0008] There are many other more secure authentication systems. However, these authentication systems are often more complex to implement than MAC address authentication.
[0009] The invention particularly aims to authenticate devices ensuring the structural operation of a building or an agglomeration. The devices concerned may be a controlled power supply, a camera, a control device access control of a door, an alarm system, air conditioning, etc. It is not uncommon to use more than a thousand devices to ensure the structural operation of a tower, including the access control devices associated with each door, the surveillance devices, the air conditioning devices, and all the controlled power supplies.
[0010] All these devices are conventionally connected to one or more networks in order to ensure global or semi-global maintenance of all the devices. However, these devices present a great heterogeneity and conventionally carry very little computing power so that it is not possible to use complex authentication methods with a program executed on the devices.
[0011] Furthermore, when deploying or replacing these devices, it can be tedious to search for the MAC address of each device to enter it into an authentication center.
[0012] The authentication center is also a sensitive point in an authentication architecture because it typically contains strategic information on the devices authorized to connect to a network.
[0013] Thus, if a hacker manages to enter this authentication center, he can modify a large number of rights and destabilize an entire computer system. The invention also aims to limit the impact of hacking on the entire computer system.
[0014] To remedy this problem, patent EP 3 550 461 of the present applicant proposes to carry out authentication of a peripheral at the level of a device which provides an electrical power supply to the peripheral via a network cable, according to POE technology.
[0015] To do this, [Fig.l] of patent EP 3 550 461 illustrates an electrical energy injector 10, the main function of which is to inject an electrical voltage onto a wire of a network cable 13a, not used to transmit data. An injector 10 conventionally comprises a network input 20, so as to receive a network cable without electrical power supply, and a network output 23 configured to connect a peripheral 12a according to POE technology, i.e. using the network cable 13a to electrically power the peripheral 12a.
[0016] To inject this electrical power supply, the injector 10 comprises an AC voltage input 21, intended to be connected to a mains socket, and an AC-DC converter 14.
[0017] The DC voltage, coming from the converter, is injected onto a wire of the network cable 13a by an assembler 22. Alternatively, the assembly of the wires carrying the data with the wire carrying the electrical energy can be carried out directly at the pins of the connector of the network output 23.
[0018] In addition to these known elements, the injector 10 comprises means for monitoring the current consumed by the peripheral 12a, for example an ammeter or any other device making it possible to acquire the current over time.
[0019] This current measurement Ic is transmitted to means for detecting an initialization phase P3 in the evolution of the current Ic. As illustrated in [Fig.5] of patent EP 3 550 461, there are several phases P1-P4 in the POE power supply.
[0020] The first phase PI consists of detecting a device 12a supporting POE technology. To do this, the injector 10 and the device 12a modulate their impedances and the injector 10 changes the supply voltage between -9 volts and -18 volts. After this first phase PI, the injector 10 knows whether or not it can supply power to a device 12a that supports POE technology.
[0021] If the injector 10 knows that it can power a peripheral 12a which supports POE technology, a second communication phase P2 will be carried out so as to detect the type of POE which is used by the peripheral 12a and to increase the power supply level up to the typical level of the POE power supply, i.e. -55 volts.
[0022] Until this increase in the supply voltage, the current Ie is substantially zero because the peripheral 12a does not yet accept receiving the supply voltage and it does not consume any current Ie.
[0023] When the voltage is increased to reach the typical supply level, i.e. between 400 and 410 ms in the example of [Fig.5] of patent EP 3 550 461, the evolution of the current presents a current peak. Following these negotiation phases P1-P2 between the injector 10 and the peripheral 12a, the voltage is constant at a value of -55 volts.
[0024] Unlike the voltage, the current Ie varies greatly following the end of these negotiation phases P1-P2 during an initialization phase P3 until reaching a stabilization phase P4 for which the peripheral 12a is in a stabilized operating regime with a constant current Ie.
[0025] This initialization phase P3 is different between two distinct peripherals 12a, for example between a camera and a telephone, thus forming a physical signature of the peripheral 12a.
[0026] This physical signature is linked to the electronic architecture of the device, i.e. the structure and tolerance of its converter, the nature of the electronic components, the topology of the components and the electromagnetic disturbances which result from it...
[0027] The electronic circuits of these peripherals 12a have internal capacitors, which can vary the residual energy inside the electronic circuits following a power cut. The current profile 1e in this initialization phase P3 does not vary as a function of the inactivity time of the electronic circuit. electronics, that is, the time during which the internal capacitors have been discharged. In addition, variations in the supply voltage between -48 volts and -55 volts do not impact the current profile le in this initialization phase P3. In the case of a camera, the mode of use of the camera does not modify the current profile le in this initialization phase P3.
[0028] Thus, the injector 10 comprises means for detecting the start of this initialization phase P3 by taking into consideration the shape of the current profile Ic and / or the shape of the supply voltage profile. For example, the detection means may correspond to a logic circuit 24 capable of detecting the crossing of a threshold SI so as to detect the formation of the current peak. As a variant, the injector 10 may detect the increase in voltage before acquiring the initialization phase P3. The end of this initialization phase P3 may be programmed after a predetermined duration, for example 400 ms.
[0029] When the initialization phase P3 is acquired, it is transmitted to means for identifying this initialization phase P3 with respect to known initialization phases. For example, the known initialization phases can be stored in a database 26 integrated into the injector 10.
[0030] The comparison between the initialization phase P3 and the known initialization phases can be carried out for all known means, for example a least squares method or a neural network.
[0031] As illustrated in [Fig.l] of patent EP 3 550 461, this comparison is carried out by an electronic circuit 25 receiving the initialization phase P3 and the known initialization phases.
[0032] Authentication of the peripheral 12a is performed when the difference between the initialization phase P3 and one of the known initialization phases is less than a threshold value, for example 5%. Filtering can be performed on the initialization phase P3 prior to comparison with the known initialization phases.
[0033] These known initialization phases may be pre-programmed in the database 26 and / or means may enable the injector 10 to record an initialization phase P3 when installing a new peripheral 12a.
[0034] If the device 12a is authenticated, an indicator 27 may light up briefly. Otherwise, if the device 12a is not authenticated, an alarm 28 may be triggered.
[0035] [Fig. 2] of patent EP 3 550 461 illustrates a second embodiment in which the device corresponds to a network switch 11 comprising a POE power supply. Conventionally, a network switch 11 comprises a routing member 29 configured to connect several devices 12b-12c with a network routed from a network input 20.
[0036] The network switch also integrates an AC voltage input 21, intended to be connected to a mains socket, and an AC-DC converter 14. The DC voltage, coming from the converter 14, is injected onto a wire of several network cables 13b-13c by several assemblers 22. The switch 11 can connect peripherals which do not use POE technology and peripherals which use POE technology.
[0037] The switch 11 also comprises means 16b-16c for supervising the currents consumed by each peripheral 12b-12c connected in POE. In the switch 11, all of the processing of these currents, necessary for the authentication of the peripherals 12b-12c, is carried out in a supervision unit 18, for example a microprocessor or a microcontroller.
[0038] Unlike [Fig.l] of patent EP 3 550 461, the switch 11 does not integrate a database 26 to store the known initialization phases, but it is connected to the routing device 29 so that it can communicate via the network with an external secure server to obtain these known initialization phases.
[0039] With the injector 10 of [Fig.l] or the switch 11 of [Fig.2] of patent EP 3 550 461, it is therefore possible to authenticate a peripheral 12a-12c by following the steps of the flowchart of [Fig.3] of patent EP 3 550 461. A first step 50 consists of monitoring the current Ic consumed by the peripheral 12a-12c. A second step 51 performs the detection of the initialization phase P3 by using the knowledge of [Fig.5] on the expected evolution of the current and / or the voltage when powering a peripheral 12a-12c. When the initialization phase P3 is detected, the third step 52 aims to compare this initialization phase P3 with known initialization phases.
[0040] If a match exists, the flowchart proceeds to step 53 confirming the authentication of the device 12a-12c. On the other hand, if there is no match, the flowchart proceeds to step 54 indicating an authentication problem.
[0041] A variant of this flowchart is illustrated in [Fig.4] of patent EP 3 550 461 with double authentication by MAC address and by authentication of the initialization phase P3. Following step 51 of detection of the initialization phase P3 or in parallel with this step 51, obtaining the MAC address is carried out in a step 56. This MAC address is used in a step 57 to characterize the device 12a-12c connected in POE.
[0042] Preferably, the device 10-11 integrates a database linking each known MAC address with a description of the device 12a-12c corresponding to the MAC address.
[0043] Unlike the embodiment of [Fig.3] of patent EP 3 550 461, the com- parison 52 of the initialization phase P3 is not carried out on all the known initialization phases, but only on the initialization phase(s) corresponding to the device characterized by the MAC address obtained during step 56.
[0044] Patent EP 3 550 461 of the state of the art thus makes it possible to provide a means of authenticating a POE device powered by a POE injector or switch, which is more difficult to circumvent than filtering by MAC address and simpler to implement.
[0045] However, this solution is not effective for authenticating a non-POE device, even if this device is connected to a POE injector or switch.
[0046] The technical problem of the invention is therefore to provide an authentication device making it possible to simply authenticate a non-POE device connected by a network cable to a POE injector or switch, while limiting the risks and impact of hacking the authentication device. Statement of the invention
[0047] To solve this technical problem, the invention proposes to use an analog trace generation device, arranged between the non-POE device and the POE injector or switch. This analog trace generation device has the function of simulating a startup analog trace unique to the non-POE device, so that it can be authenticated using the same authentication technique as that described for authenticating a POE device in patent EP 3 550 461.
[0048] It is thus possible to authenticate a non-POE device by knowing the electrical behavior of the simulation of the initialization phase of the analog trace generation device.
[0049] For this purpose, the invention relates to a device for authenticating a non-POE device connected by a network cable to a POE injector or switch, the non-POE device not being electrically powered by the POE injector or switch.
[0050] The invention is characterized in that the authentication device comprises a member for generating an analog trace, arranged between the non-POE peripheral and the POE injector or switch, the member for generating an analog trace comprising a data management circuit and a charging circuit associating, with the non-POE peripheral, a specific evolution of the current in an initialization phase.
[0051] To authenticate the non-POE device, the POE injector or switch includes: - means of monitoring the current consumed by the analog trace generation device over time; - means for detecting the initialization phase of the organ for generating an analog trace in the evolution of the current over time; - means of identifying the initialization phase with a known initialization phase associated with the non-POE device; and - means for authenticating the non-POE device if the initialization phase corresponds to the initialization phase known and associated with the non-POE device.
[0052] The invention thus makes it possible to authenticate a non-POE device by means of the physical signature of the device for generating an analog trace, observable during its initialization phase. Thus, this authentication does not require installing a program on the device and can be carried out with very simple processing at the authentication device level.
[0053] The processing operations to be carried out are so simple that they can be implemented on logic circuits or on a low-performance electronic component, such as a microcontroller.
[0054] In doing so, the authentication processes can be implemented as close as possible to the device, i.e. in a POE injector or in a network switch integrating a POE power supply. It follows that if the POE injector or switch were to be hacked, the devices that are not connected to these devices would not be in danger, unlike a centralized authentication system.
[0055] Furthermore, the detection processes being similar to those carried out in patent EP 3 550 461 for detecting POE devices, a POE switch can authenticate the POE devices and the connected non-POE devices, when the non-POE devices are all associated with a specific analog trace generation device.
[0056] Indeed, the analog trace generation device makes it possible to generate an initialization phase specific to each non-POE device. To do this, each analog trace generation device of a network must be different.
[0057] To implement this difference, it is possible to use a charging circuit comprising at least ten electronic components with tolerances greater than 5%, so that the evolution of the current in the initialization phase differs between two distinct analog trace generation devices, at least due to the number and tolerance of the components.
[0058] Furthermore, it is also possible to electronically construct each load circuit with random parameters, for example by using an electronic component placement robot controlled to perform a random component selection sequence. This type of placement robot is called a "pick and place" robot in English literature.
[0059] Preferably, to obtain the randomness of each charging circuit, each charging circuit includes: - at least three sub-circuits which can be activated by means of controlled switches; and - an activation member implementing a specific activation sequence to activate and deactivate the switches in the initialization phase.
[0060] For example, each sub-circuit can integrate a diode, a coil and a capacitor connected in series. The activation of one or more sub-circuits with reduced durations makes it possible to provide reactive energy, via the coil, capacitive energy, via the capacitor, and voltage discontinuities, by the threshold operation of the diode. Thus, by activating the switches controlled specifically for each device for generating an analog trace of a network, it is possible to obtain large differences on the analog traces of the initialization phase.
[0061] Preferably, the specific activation sequence is generated, for each analog trace generation device, by means of at least one random function. Thus, even if the topology of the sub-circuits is identical between two analog trace generation devices, the distinct activation sequence imposes significant variations in the initialization phases, detectable by the injector or the POE switch.
[0062] Furthermore, the analog trace generation device is arranged between the non-POE device and the POE injector or switch. More specifically, this characteristic requires that the analog trace generation device is physically implemented between the electronic functions of the non-POE device and the electronic functions of the POE injector or switch.
[0063] It follows that the analog trace generation device can be implemented directly at a network port of the non-POE device and the POE injector or switch. The analog trace generation device can thus be integrated into the housing of the non-POE device.
[0064] Preferably, the analog trace generation device can be implemented in a standalone box or in a box intended to be fixed on the non-POE device or on the POE injector or switch.
[0065] To do this, said analog trace generation device integrates two network ports: a POE network port to which said charging circuit is connected; and a non-POE network port to which the non-POE device is connected. In this embodiment, the analog trace generation device preferably corresponds to a box integrating an electronic card, preferably a box of small dimensions, typically less than 5 cm in width and length with a height of less than 3 cm.
[0066] When the analog trace generation member is fixed on the non-POE peripheral, said non-POE network port preferably comprises irremovable fixing means between said non-POE network port of the analog trace generation member and a network port of the non-POE peripheral.
[0067] These irremovable fixing means form a physical security device making it possible to ensure that the authenticated non-POE device is actually connected to the device for generating an analog trace.
[0068] An alternative or complementary solution to this physical connection can be achieved by detecting whether the non-POE device is disconnected from the analog trace generation device. In this embodiment, said non-POE network port can comprise means for detecting a break in the physical connection between said non-POE network port of the analog trace generation device and a network port of the non-POE device.
[0069] Furthermore, the data can be simply transferred from the POE network port to the non-POE network port. Alternatively, it is possible to perform processing on this data to verify that the non-POE device is not controlled by a hacker.
[0070] To do this, one solution is to study the behavior of the non-POE device by analyzing the network data transmitted or received by the non-POE device in order to verify that this network data reveals expected behavior of the non-POE device.
[0071] In this embodiment, said data management circuit comprises: - means for analyzing the network data transmitted or received by the non-POE device; the analysis means being configured to detect whether the network frames transmitted or received by the non-POE device correspond to expected network frames or to network frames not expected by the non-POE device; and - means of authenticating an expected use of the non-POE device if the network frames transmitted or received by the non-POE device correspond to expected network frames.
[0072] For example, said analysis means correspond to a neural network trained by a phase of learning the network frames expected and the network frames not expected by the non-POE device.
[0073] Other software means may also be implemented to ensure the presence of an expected user on the non-POE device, for example by searching for an identification code stored on the non-POE device. In this embodiment, the analog trace generation device comprises: - means for searching for a code stored on the non-POE device; and - means for authenticating the presence of the non-POE device if the code stored on the non-POE device corresponds to a verification code stored on said electronic key.
[0074] As a variant or in addition to the other authentication means, the organ for generating an analog trace comprises: - a human-machine interface allowing an authentication element to be obtained; and - means for authenticating a user of the non-POE device if the authentication element obtained by the human-machine interface corresponds to a verification element stored in the analog trace generation device
[0075] The human-machine interface makes it possible to guarantee the presence of an expected user on the non-POE device so as to detect whether a hacker manages to connect physically or remotely to the non-POE device. The human-machine interface can take different forms. For example, said human-machine interface corresponds to a numeric keypad, the analog trace generation device using a code as an authentication element and as a verification element. Alternatively, said human-machine interface corresponds to a fingerprint reader, the analog trace generation device using at least one form of fingerprint as an authentication element and as a verification element. Summary description of the figures
[0076] The manner of carrying out the invention as well as the advantages which result therefrom will emerge clearly from the following embodiment, given for informational purposes but not as a limitation, with the support of the appended figures in which figures 1 to 12 represent:
[0077] [Fig.l]: a schematic representation of an electrical energy injector according to an embodiment of the state of the art;
[0078] [Fig.2]: a schematic representation of a network switch according to an embodiment of the state of the art;
[0079] [Fig.3]: a flowchart of a method for authenticating a device according to a first embodiment of the state of the art;
[0080] [Fig.4]: a flowchart of a method for authenticating a device according to a second mode of the state of the art;
[0081] [Fig.5]: two time representations of the supply voltage and current of a POE device powered by a network cable;
[0082] [Fig.6]: a schematic representation of an electrical energy injector according to an embodiment of the invention;
[0083] [Fig.7]: a schematic representation of a network switch according to an embodiment of the invention;
[0084] [Fig.8]: a schematic representation of a trace generating organ analog according to a first embodiment of the invention;
[0085] [Fig.9]: a schematic representation of an organ for generating an analog trace according to a second embodiment of the invention;
[0086] [Fig. 10]: a schematic representation of an organ for generating an analog trace according to a third embodiment of the invention;
[0087] [Fig. 11]: a schematic representation of an organ for generating an analog trace according to a fourth embodiment of the invention; and
[0088] [Fig. 12]: a schematic representation of an organ for generating an analog trace according to a fifth embodiment of the invention. Detailed description of the invention
[0089] The invention therefore aims to authenticate non-POE devices 12d or 12e. These non-POE devices can be connected to an injector 10 or a switch 11, as illustrated in Figures 6 and 7. It should be noted that the injector 10 of [Fig.6] corresponds to the injector 10 of [Fig.l] of the prior art, and that the switch 11 of [Fig.7] corresponds to the switch 11 of [Fig.2] of the prior art. Thus, these elements are not modified and it is possible to reuse the same authentication steps as those described with reference to Figures 3 and 4.
[0090] Unlike [Fig.l] in which a network cable 13a is connected directly from the injector 10 to a POE device 12a, the embodiment of [Fig.6] proposes to connect the injector 10 to an analog trace generation device 41, itself connected to a non-POE device 12d. To do this, a first network cable 13d is connected from a network port 23 of the injector 10 to a POE port 46 of the analog trace generation device 41. A non-POE network port 47 of the analog trace generation device 41 is also connected to a network port 49 of the non-POE device 12d by means of another network cable 13e.
[0091] In the embodiment of [Fig.7], a POE peripheral 12b is connected to the switch 11 in a manner analogous to the prior art state. Additionally, a non-POE peripheral 12e is also connected to the switch 11 using two network cables 13f and 13g and an analog trace generation device 41 according to the invention.
[0092] In the two embodiments of Figures 6 and 7, the analog trace generation device 41 incorporates two specific circuits: a data management circuit 48 and a charging circuit 42.
[0093] The charging circuit 42 aims to associate a specific current evolution with the non-POE peripheral 12d or 12e during an initialization phase P3. This initialization phase P3 corresponds to that described with reference to Figures 1 to 5 of the prior art. To obtain this specific current evolution, that is, a evolution which differs between two organs of generation of an analog trace 41, it is possible to implement the charging circuit 42 in various ways.
[0094] A first way to implement this charging circuit 42 is to use a large number of electronic components with significant tolerances, such that two distinct realizations of this same electronic circuit exhibit a distinct evolution of the current during the initialization phase P3. In this embodiment illustrated in [Fig.8], the charging circuit 42 includes a transformer 59 connected to the power reception pins on the POE port 46. This transformer is also connected to a POE communication management circuit 50 which is configured to provide the expected voltage variations to implement the POE protocol. This POE communication management circuit 50 is powered by a charge that varies from one analog trace generation device 41 to another, so as to allow the authentication of a single non-POE peripheral 12d or 12e.Alternatively, the load components may be implemented to provide the expected voltage variations to implement the POE protocol, so that the POE communication management circuit 50 is not always necessary.
[0095] In the example of [Fig.8], this variable load is achieved using at least ten electronic components with tolerances greater than 5%. The mounting topology of these components can be designed to maximize the influence of the component tolerance in modifying the initialization phase P3.
[0096] Alternatively, as illustrated in [Fig.9], sub-circuits 43 can be constructed to form this variable load. In the example of [Fig.9], each sub-circuit comprises a diode D, a coil L and a capacitor C connected in series. These elements of each sub-circuit 43 are connected to the POE communication management circuit 50 via a controlled switch 44. All of the controlled switches 44 are activated or deactivated by means of an activation sequence provided by an activation member 45. For example, this activation member 45 can correspond to a microcontroller whose program is defined specifically for the analog trace generation member 41.
[0097] Preferably, this microcontroller program generates a pseudo-random signal using a random generation function. Once this random generation function has been implemented, the microcontroller systematically reproduces the same sequence of control variations of the controlled switches 44, so as to always repeat the same load for the POE communication management circuit 50.
[0098] Furthermore, [Fig.9] also differs from the embodiment of [Fig.8] by the connection of the analog trace generating member 41 with the peripheral non POE 12d. Indeed, in the embodiment of [Fig.9], a network cable 13e is not connected between the two network ports 47 and 49, but irremovable fixing means 57 are placed between these two network ports 47 and 49.
[0099] These immovable fixing means 57 can be glued or welded between the two devices, so that a user cannot replace the non-POE peripheral 12d with another peripheral that would be authenticated by analyzing the current generated by the analog trace generation member 41.
[0100] To prevent replacement of the non-POE peripheral 12d, it is also possible to integrate means for detecting a physical connection break between the non-POE port 47 of the analog trace generation member 41 and the network port 49 of the non-POE peripheral.
[0101] In addition to these elements for protecting against a break in the connection between the logical trace generation member 41 and the non-POE peripheral 12d, it is also possible to add additional protection layers against fraudulent use of the non-POE peripheral 12d.
[0102] In the embodiment of [Fig. 10], the analog trace generation device 41 integrates a specific data management circuit 48, in which analysis means 51 capture, over time, the network frames transmitted or received by the non-POE device 12d, so as to detect potentially fraudulent use of this non-POE device 12d. To do this, the analysis means 51 search for whether the network frames of the non-POE device 12d correspond to expected network frames or to unexpected network frames stored in a database 60. Means for authenticating an expected use 52 make it possible, for example, to raise an alert if the network frames transmitted or received by the non-POE device 12d do not correspond to expected network frames.
[0103] For example, the analysis means 51 may correspond to a neural network or any other known algorithm making it possible to detect the occurrence of undesirable events.
[0104] Another method of authenticating the non-POE device 12d consists of implanting a Cd code in the non-POE device 12d and verifying that this Cd code is present on the device connected to the analog trace generation device 41. To do this, the analog trace generation device 41 can integrate means 53 for searching for the Cd code on the non-POE device 12d, as illustrated in [Fig. 11].
[0105] These search means 53 aim to verify the conformity of the code Cd stored on the non-POE peripheral 12d, with a verification code Cv stored in the analog trace generation device 41. If this is the case, authentication means 54 make it possible to authenticate the presence of the non-POE peripheral 12d. In the case Conversely, an alert can be sent to a system administrator indicating that the identified non-POE 12d device may correspond to a fraudulent or potentially dangerous device.
[0106] Furthermore, other control modes can also be implemented on the analog trace generation device 41, for example devices making it possible to confirm that the user of the non-POE peripheral 12d actually corresponds to a user authorized to use this peripheral. To do this, it is possible to set up a human-machine interface on the analog trace generation device 41. This human-machine interface 55 is illustrated in [Fig. 12] in association with a verification element Ev and means of authenticating a user 56 of the non-POE peripheral 12d.
[0107] For example, the human-machine interface 55 may correspond to a numeric keypad making it possible to compare a code typed by a user with a code integrated as a verification element Ev. Alternatively, the human-machine interface 55 may correspond to a fingerprint reader making it possible to verify that the fingerprint affixed by a user corresponds to a pre-recorded fingerprint defined as a verification element Ev.
[0108] These methods make it possible to ensure efficient IT security in the presence of a non-POE 12d, 12e device authorized to access the network of a company, a building or a community.
[0109] The invention thus makes it possible to provide a means of authentication for a non-POE 12d, 12e device connected via POE, which is more difficult to circumvent than filtering by MAC address and simpler to implement.
Claims
Claims
1. Device for authenticating a non-POE device (12d-12e) connected by a network cable to a POE injector (10) or switch (11), the non-POE device (12d-12e) not being electrically powered by the POE injector (10) or switch (11), characterized in that the authentication device comprises an analog trace generation member (41), arranged between the non-POE device (12d-12e) and the POE injector (10) or switch (11), the analog trace generation member (41) comprising a data management circuit (48) and a charging circuit (42) associating, with the non-POE device (12d-12e), a specific evolution of the current in an initialization phase (P3); the POE injector (10) or switch (11) comprising: - means for supervising (16a-16c) the current consumed by the device for generating an analog trace (41) over time;- means (18, 24) for detecting the initialization phase (P3) of the analog trace generating member (41) in the evolution of the current over time; - means (18, 25) for identifying the initialization phase (P3) with a known initialization phase associated with the non-POE peripheral (12d-12e); and - means (18, 27) for authenticating the non-POE peripheral (12d-12e) if the initialization phase (P3) corresponds to the known initialization phase associated with the non-POE peripheral (12d-12e).;
2. Device for authenticating a non-POE device according to claim 1, wherein said charging circuit (42) comprises at least ten electronic components with tolerances greater than 5%, so that the evolution of the current in the initialization phase (P3) differs between two distinct analog trace generation members (41), at least due to the number and tolerance of the components.
3. A device for authenticating a non-POE device according to claim 1 or 2, wherein said load circuit (42) comprises: - at least three sub-circuits (43) which can be activated via controlled switches (44); and - an activation member (45) implementing a specific activation sequence to activate and deactivate the switches (44) in the initialization phase (P3).
4. A non-POE device authentication device according to claim 3, wherein each sub-circuit integrates a diode (D), a coil (L) and a capacitor (C) connected in series.
5. A device for authenticating a non-POE device according to claim 3 or 4, wherein the specific activation sequence is generated for each analog trace generation member (41) by means of at least one random function.
6. A device for authenticating a non-POE device according to one of claims 1 to 5, wherein said analog trace generating member (41) integrates two network ports: a POE network port (46) to which said charging circuit (42) is connected; and a non-POE network port (47) to which the non-POE device (12d-12e) is connected.
7. A device for authenticating a non-POE device according to claim 6, wherein said non-POE network port (47) comprises irremovable fixing means (57) between said non-POE network port (47) of the analog trace generating member (41) and a network port (49) of the non-POE device (12d-12e).
8. A device for authenticating a non-POE device according to claim 6 or 7, wherein said non-POE network port (47) comprises means for detecting a break in the physical connection between said non-POE network port (47) of the analog trace generating member (41) and a network port (49) of the non-POE device (12d-12e).
9. Device for authenticating a non-POE device according to one of claims 1 to 8, wherein said data management circuit (48) comprises: - means for analyzing (51) the network data transmitted or received by the non-POE device (12d-12e); the analyzing means (51) being configured to detect whether the network frames transmitted or received by the non-POE device (12d-12e) correspond to expected network frames or to network frames not expected by the non-POE device (12d-12e); and - means for authenticating an expected use (52) of the non-POE device (12d-12e) if the network frames transmitted or received by the non-POE device (12d-12e) correspond to expected network frames.
10. A device for authenticating a non-POE device according to claim indication 9, in which said analysis means (51) correspond to a neural network trained by a phase of learning the network frames expected and the network frames not expected by the non-POE device (12d-12e).
11. Device for authenticating a non-POE device according to one of claims 1 to 10, in which the analog trace generation member (41) comprises: - means for searching (53) for a code (Cd) stored on the non-POE device (12d-12e); and - means for authenticating the presence (54) of the non-POE device (12d-12e) if the code (Cd) stored on the non-POE device (12d-12e) corresponds to a verification code (Cv) stored in the analog trace generation member (41).
12. Device for authenticating a non-POE device according to one of claims 1 to 11, in which the analog trace generation member (41) comprises: - a human-machine interface (55) making it possible to obtain an authentication element; and - means for authenticating a user (56) of the non-POE device (12d-12e) if the authentication element obtained by the human-machine interface (55) corresponds to a verification element (Ev) stored in the analog trace generation member (41).
13. Device for authenticating a non-POE device according to claim 12, wherein said human-machine interface (55) corresponds to a digital keyboard, the member for generating an analog trace (41) using a code as an authentication element and as a verification element (Ev).
14. Device for authenticating a non-POE device according to claim 12, in which said human-machine interface (55) corresponds to a fingerprint reader, the member for generating an analog trace (41) using at least one form of fingerprint as an authentication element and as a verification element (Ev).