Music frequency cybersecurity remote control
TCFM signal-based authorization enhances smart grid cybersecurity by ensuring only authorized signals are processed, addressing the challenge of maintaining security across heterogeneous devices with limited computing power.
Patent Information
- Application Number
- FR2022013118
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2022-12-09
- Publication Date
- 2026-02-06
- Estimated Expiration
- 2042-12-09
AI Technical Summary
Existing cybersecurity mechanisms for smart grid devices are challenged by the continuous increase in computing power and the advent of quantum computers, necessitating continuous updates across millions of heterogeneous devices with limited computing power, making it difficult to maintain security over extended periods.
Implementing a method using TCFM signals, decoded by receivers, to verify authorization through a recognition strategy, ensuring only authorized signals are processed, enhancing security without requiring complex modifications.
Provides enhanced security and reliable operation of smart grid devices by allowing only authorized signals to be processed, adaptable to different environments, and easy to implement without costly updates.
Smart Images

Figure 00000011_0000 
Figure 00000012_0000 
Figure 00000012_0001
Abstract
Description
Title of the invention: Music frequency cybersecurity remote control technical field
[0001] This disclosure falls within the domain of information systems security.
[0002] More specifically, this disclosure relates to a method for securing an information system and to a corresponding computer program, communication system, and information system. Previous technique
[0003] According to the definition of ANSSI (National Agency for Information Systems Security), "cybersecurity is a desired state for an information system enabling it to withstand events originating in cyberspace that could compromise the availability, integrity or confidentiality of the data stored, processed or transmitted and the related services that these systems offer or make accessible. Cybersecurity uses information systems security techniques and relies on the fight against cybercrime and the implementation of cyber defense."
[0004] One of the many aspects of cybersecurity relies on securing communications through authentication and encryption mechanisms built on different types of cryptographic algorithms. The nature of the algorithms used, as well as the length of the secrets shared or not (encryption keys), are all parameters that influence the effectiveness of existing mechanisms.
[0005] However, despite the implementation of additional measures and best practices (password complexity, cryptographic key length, regular changes to shared secrets and / or periodic certificate renewal, etc.), the validity of the mechanisms in place is not perpetual, given the continuous increase in computing power and the coming revolution of quantum computers. Therefore, any organization seeking to ensure the cybersecurity of its systems must always stay one step ahead of cybercriminal threats. This results in a perpetual race against time and a need for continuous updating of security functions.
[0006] There is therefore a permanent need for enhanced security of communications.
[0007] In the specific context of the smart grid, we are faced with the proliferation of communicating objects and systems which, given the amounts invested, have a lifespan exceeding a few tens of years. These devices have been around for years and are sometimes deployed over time according to different technological stages. Furthermore, connected objects are characterized by lower computing power compared to, for example, a typical office IT infrastructure. Therefore, ensuring the cybersecurity of these connected objects represents a real challenge: deploying security updates across a fleet of millions of heterogeneous devices that must be maintained for 20 years or more is no easy task. Summary
[0008] This disclosure improves the situation.
[0009] A method is proposed for securing an information system comprising a plurality of communicating systems distributed in the same territory and connected to the same electrical network, the communicating systems each comprising a first receiver capable of receiving coded signals of frequency less than or equal to 3000 Hz carried by the electrical network, a second receiver capable of receiving signals through a communication channel, and a device connected to the first and second receivers, the process being implemented by communicating systems after the first receivers receive the same coded signal, the process comprising, for each communicating system: - obtain a code resulting from the decoding of the coded signal received by the first receiver, - verify the obtained code using a recognition strategy, thus obtaining a verification result, and - when the verification result is indicative of success, allow the device to process a signal from the second receiver, otherwise, do not allow said processing.
[0010] The term "territory" refers to an area of national or regional scale, as opposed to an area of local scale such as a dwelling. A large site, for example an industrial site, can by extension be considered a "territory." Similarly, the electrical grid is a network of regional or national scale and not a domestic network.
[0011] The proposed method ensures that only authorized signals can be processed. Thus, the method offers increased security and ensures that communicating systems will operate reliably. The method is quick and easy to implement and does not require costly or complex modifications to the communicating systems. Finally, the method is highly flexible and can be easily adapted to different needs and environments.
[0012] A communication system is also proposed comprising a first receiver capable of receiving coded signals of a frequency less than or equal to 3000 Hz carried by an electrical network, a second receiver capable of receiving signals through a communication channel, and a device connected to the first and second receivers, the communicating system being configured to, after receiving a coded signal from the first receiver: - obtain a code resulting from the decoding of a coded signal received by the first receiver, - verify the obtained code using a recognition strategy, thus obtaining a verification result, and - when the verification result is indicative of success, allow the device to process a signal from the second receiver, otherwise, do not allow said processing.
[0013] An information system comprising a plurality of communicating systems as defined above is also proposed, the communicating systems being distributed in the same territory and connected to the same electrical network.
[0014] A computer program is also proposed comprising instructions for implementing the above process when this program is executed by a processor.
[0015] A non-transient recording medium readable by a computer is also proposed on which a program is recorded for the implementation of the above process when this program is executed by a processor.
[0016] In an example of an embodiment applicable to the above process and / or system, using the recognition strategy corresponds to comparing the code obtained with a pre-calculated code according to the principle of a rolling code.
[0017] In an example of an embodiment applicable to the above process and / or system, the processing includes obtaining by the device the signal from the second receiver, and / or extracting by the device at least one instruction contained in the signal from the second receiver and / or generating by the device at least one command based on at least one instruction contained in the signal from the second receiver.
[0018] In general, various control mechanisms make it possible to prevent unauthorized signals from being obtained, to prevent unauthorized instructions from being extracted and unauthorized commands from being generated.
[0019] In an example of an embodiment applicable to the above process and / or system, the coded signal received by the first receiver comprises a signal of a given frequency modulated in on / off fashion.
[0020] The frequency range used allows fast and efficient communication between devices over a long distance with a low probability of conflict or noise.
[0021] In an example of an embodiment applicable to the above process and / or system, the coded signal received by the first receiver comprises a plurality of signals of different frequencies modulated in on / off fashion.
[0022] Using multiple signals allows for the transmission of more complex and complete information, or offers more efficient and faster transmission of the same amount of data sent simultaneously and processed in parallel. Brief description of the drawings
[0023] Other features, details and advantages will become apparent from reading the detailed description below and from analyzing the accompanying drawings, in which: Fig. 1
[0024] [Fig.1] represents a TCFM communication system involving a transmitting station and a receiver. Fig. 2
[0025] [Fig.2] represents an information system according to a particular embodiment example. Fig. 3
[0026] [Fig.3] represents a communicating system according to a particular embodiment. Fig. 4
[0027] [Fig.4] illustrates by means of a flowchart a method of securing the communicating system of [Fig.3], according to a particular embodiment example. Description of the implementation methods
[0028] The invention proposed herein aims to use the TCFM signal to enhance the cybersecurity of communicating devices on the smart grid. The principle is simple: the TCFM signal is injected into the network and captured by the communicating devices. Once captured, the signal is processed by an embedded security device. This device can be a combination of security technologies, such as cryptography, authentication, intrusion protection, etc. The TCFM signal is then used to activate the embedded security device, thereby protecting the network and the communicating devices against external attacks.
[0029] The invention proposed here therefore offers an additional means of securing the network and communicating devices of the smart grid. Indeed, the TCFM signal is very difficult to hack, which ensures optimal security. Furthermore, the TCFM signal is capable of covering a large area, thus improving network coverage and the security of communicating devices.
[0030] Since its implementation in 1958, the TCFM system, or "Centralized Musical Frequency Remote Control," has been operated in France. This signal helps to better manage the load curve by controlling domestic hot water or collective uses such as street lighting and the implementation of historical tariff options. With the advent of modern smart meters, TCFM is becoming obsolete for the aforementioned uses.
[0031] Figure 1 illustrates the known general operating principle of a TCFM system. Consider a substation (110) connecting an upstream high-voltage electrical network (100) to a downstream high- or medium-voltage electrical network (130). The substation includes a TCFM transmission station (120). The TCFM transmitting station includes a signal generator (122) operating at 175 Hz, the frequency intended and used in France, or more generally according to the EMC reference standard IEC 61000-2-2, and one or more signals in a frequency range from 110 Hz to 3000 Hz. Typically, a signal generator (122) is combined with a shunt circuit (124), a TCFM controller (128), and an injection circuit (126) connected to an injection transformer, enabling the injection of at least one signal at the intended frequency, modulated in a binary fashion. In typical use of the 175 Hz signal, the associated data rate is approximately 0.1 bits per second.This signal then allows unidirectional communication over long distances, on the order of a hundred kilometers, between the source station (120) and numerous receivers (150) in low-voltage electrical networks (140) downstream. The receivers (150) are likely to include electromechanical meters, electronic meters, hot water tank relays, etc.
[0032] TCFM is certainly an aging technology which offers very low throughput and strictly unidirectional communication, but one of its advantages is that it is extremely complicated to inject a signal with a frequency between 110 and 3000 Hz into an electrical network over a significant range.
[0033] Indeed, while it is not difficult to generate a signal at this frequency (a simple commercially available "function generator" can do this), it is much more difficult to have sufficient injection power for the signal to propagate over several tens of kilometers in the low and medium voltage distribution network: the power of TCFM transmitters typically varies between 63 kVA and 250 kVA.
[0034] The TCFM can therefore be considered inviolable on a large scale.
[0035] Figure 2 illustrates an information system comprising a control system (200) and a plurality of communicating systems (222, 232, 242) connected to a communication device (226, 236, 246).
[0036] Each communication device (226, 236, 246) can be based on either a wired technology, for example ADSL, PLC or fiber optics, or on a wireless technology, for example sub-GHz radio, WiFi, 4G or 5G. The communication device is at least capable of and configured to receive signals transmitted by a communication system (210) and can optionally be capable of and configured to transmit signals via the communication system (210).
[0037] It is proposed to couple each communicating system (222, 232, 242) to be secured with a TCFM receiver (224, 234, 244) and to use a TCFM transmission from a TCFM transmitting station (120) controlled by a control system (200) to enhance the security of communications involving the communicating system (222, 232, 242) and the communication system (210). Numerous TCFM receiver models are commercially available.
[0038] Figure 3 provides, in a particular example, a suitable internal representation of a communicating system (222). This includes, at least, a microcontroller (300), a data storage memory (302) and a local communication interface (304) with the TCFM receiver (224) and with the communication device (226).
[0039] Similar to existing authentication systems that allow a human user to validate a banking transaction with their mobile phone, a device consisting of a TCFM signal receiver, a microcontroller capable of decoding specific commands and a local communication interface with the communicating system, can, in a similar way, replace the manual action of validating a transaction by the human user in the example mentioned above.
[0040] According to one example, the control system (200) can be informed of an intention to transmit one or more signals via the communication system (210) and can, on this basis, trigger the transmission of one or more TCFM signals by the TCFM transmitting station (120).
[0041] According to another example, the control system (200) can control, directly or indirectly, both the TCFM transmitting station (120) and the communication system (210) and can thus trigger in close proximity in time both the transmission of one or more TCFM signals by the TCFM transmitting station and the broadcasting of one or more signals through the communication system (210).
[0042] The emitted TCFM signals may correspond to a TCFM sequence that can be recognized by a protected communicating system or by a group of protected communicating systems. For example, it may be a security code that can be reconstructed, at the level of each targeted communicating system, by pulses at one or more given frequencies (for example, 175 Hz and / or 188 Hz) before each communication previously classified as critical by the network administrator, such as a firmware update or a load shedding operation.
[0043] Strategies for defining a security code, also commonly called a "PIN code," and for its recognition by microcontrollers embedded in the targeted communication systems must be the subject of dedicated studies before an optimal technical solution can be determined. Existing mechanisms can be used among the possible technical solutions.
[0044] Current PIN definition strategies generally involve using a cryptographic algorithm to generate a unique PIN for each protected communicating system. The most commonly used algorithms are block ciphers, asymmetric ciphers, and stream ciphers. In block ciphers, the PIN is generated from a block of encrypted data. In asymmetric ciphers, the PIN is generated from two public and private keys, which are used for communication between the server and the embedded microcontroller. In stream ciphers, the PIN is generated from a stream of encrypted data. PIN recognition by an embedded microcontroller is generally performed by comparing the received PIN to a predefined PIN stored in the microcontroller's memory.If the codes match, the microcontroller grants access to an application or system. Most embedded microcontrollers use encryption algorithms to secure the PIN code and protect it against brute-force attacks.
[0045] A rolling code algorithm, widely used today for remotely unlocking a vehicle using its key, is a security mechanism that operates using a PIN code that changes with each successive transmission. This code is generated from cryptographic data stored at the receiver and from information contained in the received signal. The main advantages of this technology are security and efficiency. The security code ensures that only authorized transmitters can interact with the protected communication system. Furthermore, the code changes with each use, which reduces the risk of hacking. In addition, the code is generated very quickly, which allows, for example, for the rapid deployment of updates across a fleet of protected communication systems.
[0046] An example of an algorithm that can be used to implement the proposed technique locally at the level of protected communicating systems is presented in [Fig. 4] in the form of a flowchart. A TCFM signal is obtained (400) at the TCFM receiver connected to the protected communicating system, then decoded (402) locally to obtain a security code (404) which is made accessible to the microcontroller (300) of the protected communicating system. The code is then verified (406). Based on the result of the verification, authorization may be granted (410) or not (408) for processing a signal received at the level of the communicating device connected to the protected communicating system. The concept of "processing" to which the authorization relates is to be understood in a broad sense.Depending on the implementation chosen, this could involve, for example, reading a received signal, storing it in memory, and performing computer processing by the microcontroller, such as extracting at least one instruction contained in the received and / or stored signal, or generating at least one command based on at least one instruction thus extracted.
[0047] The proposed technique is not intended to replace existing encryption and authentication mechanisms, but it strengthens the overall cybersecurity of the smart grid and can be offered as a cybersecurity service to a user of equipment connected to the electrical grid.
Claims
Demands
1. A method for securing an information system comprising a plurality of communicating systems distributed within the same territory and connected to the same electrical network, the communicating systems each comprising a first receiver capable of receiving coded signals of a frequency less than or equal to 3000 Hz carried by the electrical network, a second receiver capable of receiving signals through a communication channel, and a device connected to the first and second receivers, the method being implemented by the communicating systems after the first receivers receive the same coded signal, the method comprising, for each communicating system: - obtaining a code resulting from the decoding of the coded signal received by the first receiver, - verifying the code obtained using a recognition strategy, thus obtaining a verification result, and - when the verification result is indicative of success,Allow the device to process a signal from the second receiver; otherwise, do not allow said processing.
2. A method according to claim 1, wherein using the recognition strategy corresponds to comparing the obtained code with a pre-calculated code according to the principle of a rolling code.
3. A method according to claim 1 or 2, wherein the processing comprises obtaining by the device the signal from the second receiver, and / or extracting by the device at least one instruction contained in the signal from the second receiver and / or generating by the device at least one command based on at least one instruction contained in the signal from the second receiver.
4. A method according to any one of claims 1 to 3, wherein the coded signal received by the first receiver comprises a signal of a given frequency modulated in an on / off manner.
5. A method according to any one of claims 1 to 4, wherein the coded signal received by the first receiver comprises a plurality of signals of different frequencies modulated in on / off fashion.
6. A computer program comprising instructions for carrying out the method according to any one of claims 1 to 5 when this program is executed by a processor.
7. A communicating system comprising a first receiver capable of receiving coded signals of frequency less than or equal to 3000 Hz carried by an electrical network, a second receiver capable of receiving signals through a communication channel, and a device connected to the first and second receivers, the communicating system being configured to, after receiving a coded signal by the first receiver: - obtain a code resulting from a decoding of a coded signal received by the first receiver, - verify the code obtained using a recognition strategy, thus obtaining a verification result, and - when the verification result is indicative of success, allow the device to process a signal from the second receiver, otherwise, not allow said processing.
8. Information system comprising a plurality of communicating systems according to claim 7, the communicating systems being distributed in the same territory and connected to the same electrical network.