Method and device for controlling the execution of at least one action by a connected object in a communication network

The method and device use security certificates to securely manage access and execute commands for connected devices in home automation systems, addressing the challenge of managing multiple device passwords and enhancing security during installation.

FR3153956B1Active Publication Date: 2026-03-13SOMFY ACTIVITES SA
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
FR · FR
Patent Type
Patents
Current Assignee / Owner
Filing Date
2023-10-10
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

Existing home automation systems face challenges in securely managing access to multiple connected devices during installation and configuration, as setting up unique passwords for each device is impractical and insecure.

Method used

A method and device for controlling actions by connected objects in a communication network using security certificates to establish secure connections, verify authorization, and execute commands based on predefined access rights, ensuring encrypted communication and secure execution of actions.

Benefits of technology

Facilitates secure access for multiple connected devices by using security certificates to authenticate and authorize remote controllers, enhancing security and simplifying the installation and configuration process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000026_0000
    Figure 00000026_0000
  • Figure 00000027_0000
    Figure 00000027_0000
  • Figure 00000028_0000
    Figure 00000028_0000
Patent Text Reader

Abstract

Method and device for controlling the execution of at least one action by a connected object in a communication network. This method includes opening (82) a secure connection between a building connected object and a remote controller, implementing a first security certificate of the connected object and a second security certificate of the remote controller, and receiving via said secure connection (42) a command to execute at least one action issued by the remote controller, then the steps of: extracting (86) a value from a predetermined field of the second security certificate, called the access authorization value of the remote controller; verifying (90), in a structure for storing associations between access authorization values ​​and sets of authorized commands, that said received command belongs to a set of at least one authorized command associated with said access value;and in case of a positive check, execution (92) of at least one action associated with the received command. Figure for the abbreviation: Figure 3;
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Method and device for controlling the execution of at least one action by an object connected in a communication network

[0001] The present invention relates to a method for controlling the execution of at least one action by a connected building object in a communication network, as well as an associated execution control device.

[0002] The invention applies in particular to home automation systems for buildings comprising at least one connected object, and for the control, configuration and / or maintenance of a home automation system for buildings.

[0003] More generally, the invention relates to the field of the Internet of Things (IoT) for buildings, both for commercial buildings and residential buildings, whether individual or collective.

[0004] By connected object, we mean an electronic object connected by wire or wirelessly to a communication network, and configured to transmit or receive data via the communication network.

[0005] By connected building object, we mean a connected object adapted to be placed in a building, and configured to provide comfort and energy management functions, such as heating, ventilation and air conditioning, but also functions for managing lighting and controlling openings, such as blinds or roller shutters placed in front of windows of the building or even remote security by controlling closing systems (doors, locks).

[0006] Typically, the equipment in the same building is connected to a control unit, which has the function of supervising this equipment and controlling its operation.

[0007] When a communication network is implemented in a home automation system comprising at least one connected object, the connected object can be controlled remotely by a remote controller via the communication network, for example, using one or more gateway network devices. It is then preferable to add a layer of security to ensure that control of the connected object is indeed carried out by a third party authorized by the appropriate access rights.

[0008] To ensure security, it is known to secure access to the connected object by password by individually assigning a unique password to each connected object, the unique password being, for example, indicated on the label of the connected object in plain text or encoded in a QR code datagram. Thus, a user Having this unique password, a user can connect individually to the connected device to send it a command associated with an action. However, setting up a secure connection with a unique password for each connected device is not feasible in certain specific use cases, for example, during the installation and configuration phase of a home automation system with a large number of connected devices, as the installer would then be forced to manage as many unique passwords as there are connected devices.

[0009] There is therefore a need to secure access to control the execution of actions by connected objects for buildings connected to a communication network, while facilitating secure access for a large number of connected objects.

[0010] To this end, the invention relates to a method for controlling the execution of at least one action by a connected building device in a communication network, said connected building device comprising a network interface enabling a connection to said communication network, said execution being controlled by a remote controller adapted to connect to said communication network, the method being implemented by a processing unit of said connected building device adapted to execute at least one action of the connected building device, and comprising at least the following steps: - opening a secure connection between said connected building device and the remote controller, implementing a first security certificate of the connected device and a second security certificate of the remote controller, the step of opening a secure connection enabling encrypted communication between said connected building device and the remote controller, and including the receipt of the second security certificate of the remote controller; and - reception, via said secure connection, of a command to execute at least one action issued by said remote controller, according to a communication protocol.

[0011] This process further comprises the steps of: - extraction of a value from a predetermined field of the second security certificate of the remote controller, called the remote controller access authorization value; - verification, within a memory structure for associations between access authorization values ​​and sets of authorized commands, that said received command belongs to a set of at least one authorized command associated with said access value, the memory structure being stored in an electronic memory of said connected building object, and - in case of positive verification, execution of at least one action associated with the received order.

[0012] Advantageously, the proposed method makes it possible to use the same security certificate to establish a secure connection and to verify, in a memory structure recorded in a memory of the connected object, by means of the authorization value extracted from the predetermined field of the security certificate of the remote controller, whether the remote controller is actually authorized to command the execution of one or more actions.

[0013] The method of controlling the execution of at least one action by a connected building object in a communication network according to the invention may also have one or more of the characteristics below, taken independently or according to all technically conceivable combinations.

[0014] The method further includes a step in which, in the event of a negative check, said at least one action associated with the received command is not executed, and a warning is sent via said secure connection.

[0015] The extraction step further includes an extraction of a second value from a predetermined field of the second security certificate of the remote controller to obtain an identifier of a third party operating said remote controller.

[0016] The method further includes a step of storing, in an execution report, said received command in association with the identifier of the third party operating said remote controller.

[0017] When the building connected object processing unit is configured to open a plurality of secure connections in parallel, the opening of a secure connection with a given remote controller depends on the access authorization value extracted from the second security certificate of said remote controller.

[0018] The verification step implements a memory structure in the form of a table associating, with each remote controller access authorization value, a list of at least one command to execute at least one action by the connected building object.

[0019] When the connected building object stores the first security certificate of the connected building object, during the step of opening a secure connection, the processing unit of the connected building object determines whether the second security certificate of the remote controller received and the first security certificate of the connected building object are signed by the same trusted third party, in order to register, if so, the second security certificate of the remote controller as a trusted security certificate in a public key infrastructure contained in its electronic memory.

[0020] The method further comprises a downloading step into an electronic memory connected building object electronics of an update file of at least one executable program implemented by the connected building object processing unit, the received command being included in a set of connected building object setting commands, the action associated with the received command being an implementation of said file.

[0021] The connected object is a home automation device of a home automation system for a building.

[0022] According to another aspect, the invention relates to a device for controlling the execution of at least one action by a connected object in a building communication network, implemented in said connected building object, the connected building object comprising a network interface enabling a connection to said communication network, said execution being controlled by a remote controller adapted to connect to said communication network, said connected object comprising a processing unit of said connected building object adapted to execute at least one action of the connected building object, and comprising at least: - a module for opening a secure connection between said connected building device and the remote controller, implementing a first security certificate of the connected device and a second security certificate of the remote controller, opening a secure connection allowing encrypted communication between said connected building device and the remote controller, and including the reception of the second security certificate of the remote controller; and - a receiving module, via said secure connection, for an execution command of at least one action issued by said remote controller, according to a communication protocol.

[0023] The processing unit further comprises: - a module for extracting a value from a predetermined field of the second security certificate of the remote controller, called the remote controller access authorization value; - a verification module, within a structure for storing associations between access authorization values ​​and sets of authorized commands, to ensure that the received command belongs to a set of at least one authorized command associated with the access value, the storage structure being stored in an electronic memory of the connected building object, and

[0024] - an execution module, in case of a positive check, of at least one action associated with the order received.

[0025] According to another aspect, the invention relates to a system for controlling the execution of at least one action by a connected building object in a communication network, the system comprising said connected object and a remote controller, said connected object comprising a device for controlling the execution of at least one action as briefly described above.

[0026] According to another aspect, the invention relates to an information storage medium, on which are stored software instructions for the execution of a method of controlling the execution of at least one action by an object connected in a communication network as briefly described above, when these instructions are executed by a programmable electronic device.

[0027] The invention also relates to a computer program comprising software instructions which, when executed by a computer, implement a method for controlling the execution of at least one action by an object connected in a communication network as defined above.

[0028] The invention will become clearer upon reading the following description, given solely by way of non-limiting example, and made with reference to the drawings in which:

[0029] [Fig-1] [Fig.1] is a schematic representation of a home automation system for connecting connected objects for buildings;

[0030] [Fig.2] [Fig.2] is a schematic representation of a communication system implementing execution control of at least one action per connected object of a home automation system;

[0031] [Fig.3] [Fig.3] is a flowchart of the main steps of a control process execution of at least one action by a connected object in a first embodiment mode;

[0032] [Fig.4] [Fig.4] is a schematic representation of a variant of the system of communication of the [Fig.2];

[0033] [Fig. 5] [Fig. 5] is a flowchart of the main steps of an example application of the method of controlling the execution of at least one action by a connected object in the context of updating at least one connected object for a building from a remote controller.

[0034] Figure 1 schematically represents a building 2 comprising, for example, four rooms or zones Z1, Z2, Z3, Z4. Building 2 is, for example, an office complex, a residential building, a commercial or industrial building, or any combination of these uses. It may, in particular, be an apartment building or a detached house.

[0035] Building 2 is equipped with a home automation system 4 conforming to a first embodiment of the invention. The home automation system 4 comprises a set of objects connected devices for buildings distributed across zones Z1, Z2, Z3, and Z4 of building 2. The set of connected devices for buildings includes at least one connected device 6 for buildings. Each connected device 6 for buildings in the set of connected devices for buildings is connected to a communication network 14.

[0036] By object connected to a communication network, we mean an electronic object connected by wire or wirelessly to a communication network, here to the communication network 14, and configured to transmit and / or receive data via the communication network 14 according to a wired communication protocol (e.g. Ethernet, Power-over-Ethernet, USB, FireWire, RS-485, Arcnet, FDDI, Token Ring, etc.) or wireless (e.g. Wi-Fi, Thread, ZigBee, Z-Wave, Bluetooth, BLE, IrDA, etc.).

[0037] By connected building object, we mean a connected object adapted to be placed in a building, here in building 2, and configured to provide comfort and energy management functions, such as heating, ventilation and air conditioning, but also functions for managing lighting and controlling openings, such as blinds or roller shutters placed in front of windows of the building or even remote security by controlling closing systems (doors, locks).

[0038] A connected object 6 for building is for example a controllable home automation device 6a, a control unit 6b, or a sensor 6c.

[0039] A controllable home automation device 6a is at least configured to receive data via the communication network 14 according to a wired or wireless communication protocol, the data including at least one command associated with at least one action of the controllable home automation device 6a.

[0040] A controllable home automation device 6a is, for example, an actuator arranged to move or adjust an element of the building 2, for example, an electromechanical actuator to move a roller shutter or a patio awning, or a control system for a heating or ventilation system. A controllable home automation device 6a can also be a lighting device, for example, outdoor patio lighting or a lighting control system, or even an alarm siren of an alarm system.

[0041] A control unit 6b is at least configured to transmit data via the communication network 14 according to a wired or wireless communication protocol, the data including at least one command associated with at least one action of a controllable home automation device 6.

[0042] A control unit 6b is intended to receive control instructions from a user of building 2, in order to control directly or indirectly, one or more of the controllable home automation devices 6a of the home automation system 4.

[0043] A control unit 6b is, for example, a central control unit, called commonly referred to as a "home automation box", or a fixed or mobile control point.

[0044] A sensor 6c is intended to convert at least one physical quantity relating to the state of the building 2, or to the environment of the building 2, or to at least one connected object 6 for the building of the home automation system 4, into at least one signal proportional to this at least one physical quantity.

[0045] This signal is, for example, an electrical signal, a light signal, or a radio frequency signal. This signal is then transmitted by the sensor 6c to at least one connected object 6 for the building of the home automation system 4. A sensor 6c is, for example, an alarm system, or a video camera, in particular a video surveillance camera.

[0046] One or more sensors 6c can be integrated into a controllable home automation device 6a, or into a control point 6b. The home automation system 4 can also include one or more independent sensors.

[0047] The home automation system 4 further includes at least one remote controller 8 connected to the communication network 14. The remote controller 8 is configured to control and / or configure at least one connected building object 6 from the set of connected building objects of the home automation system 4.

[0048] The remote controller 8 is operated by at least one third party, for example an installer, a user or a maintenance agent of the home automation system 4.

[0049] For the purposes of the invention, the term "remote" of the remote controller 8 indicates that the remote controller 8 is physically distant from the connected object 6 for building which it is configured to control and / or configure, and is in no way limiting to the location of the remote controller 8 in relation to building 2, the remote controller 8 being able to be located inside or outside building 2.

[0050] Advantageously, the remote controller 8 is a control and / or configuration tool for at least one connected object 6 for the building that it is intended to control and / or configure.

[0051] The remote controller 8 can be any one of the connected objects 6 for building from the set of connected objects for building of the home automation system 4, such as a controllable home automation device 6a, a control unit 6b, or a sensor 6c.

[0052] The communication network 14 can be of any kind, for example a wired PAN or wireless WP AN personal network, a wired LAN or wireless WLAN local area network, or any combination of at least two networks including in this case at least one network equipment 10 implementing a gateway role enabling communication from one network to another.

[0053] Advantageously, the communication network 14 is connected to a wide area or external communication network 16, such as the Internet, via a network equipment 10 implementing an access point role to the extended or external network 16. In this way, each connected object 6 for building of the home automation system 4 can communicate with at least one remote equipment 12 connected to the extended or external communication network 16, to send reports on the operating status of the home automation system 4 for diagnostic purposes, or to receive control and / or configuration instructions.

[0054] A remote device 12 is for example a fixed remote device 12a connected to the extended or external network 16, such as a computer server and / or a building management system (BMS), or a mobile remote device 12b connected to the extended or external network 16, such as a smart mobile phone device or "smartphone", a tablet or any other equivalent device.

[0055] The communication network 14 can be of the multipoint type and / or of the point-to-point type and can consist of one or more network equipment 10 not shown, such as routers and / or gateways, allowing the connected objects for building of the home automation system 4 to communicate with each other and / or with at least one remote controller 8.

[0056] The remote controller 8 can be any of the remote equipment 12 connected to the communication network 14 via the extended or external communication network 16. In this way, the remote controller 8 can communicate from the extended or external communication network 16 with at least one connected object 6 for building that it is configured to control and / or configure.

[0057] Fig. 2 schematically illustrates a system for controlling the execution of actions by a connected object 6 for building in a communication network 14, the connected object 6 for building being any one of the set of connected objects 6 for building of the home automation system 4 installed in building 2.

[0058] Generally, each connected building object 6 has a low-level communication interface 20, commonly called a network interface, operating at the physical layer of the communication network 14, and allowing the connected building object 6 to connect to the communication network 14. In this way, each connected building object 6 can communicate with at least one other device connected to the communication network 14, such as another connected building object 6 of the home automation system 4, a remote controller 8, and / or a remote device 12a, 12b via the extended or external communication network 16.

[0059] Advantageously, the network interface 20 is a wired network interface conforming to a wired communication protocol, such as the IEEE 802.3 standard communication protocol, commonly known as Ethernet.

[0060] Optionally, the network interface 20 can also be compliant with a PoE (Power-over-Ethernet) Ethernet cable power supply protocol, allowing the connected building device 6 to be powered electrically from a PoE power supply device, the PoE power supply device advantageously being a network device 10 of the communication network 14 to which the connected building device 6 is connected.

[0061] Alternatively, the network interface 20 is a wireless network interface conforming to a wireless communication protocol, such as the IEEE 802.11 standard communication protocol, or the IEEE 802.15.1 standard communication protocol, or the IEEE 802.15.4 standard communication protocol.

[0062] The connected building object 6 further comprises at least one processing unit 22 connected to the network interface 20, and at least one electronic memory 24 connected to the processing unit 22.

[0063] The network interface 20 of the connected building device 6 is adapted to communicate, via an internal data link, with the processing unit 22, for example a microcontroller or a plurality of logic units, the processing unit 22 being configured to control actions related to the functionality of the corresponding connected building device 6. For example, the actions are accessible by means of an application programming interface (API) implemented by the processing unit 22.

[0064] The electronic memory 24 of the connected object 6 for building contains a public key infrastructure 30, also called PKI (acronym for the Anglo-Saxon term "Public Key Infrastructure").

[0065] The electronic memory 24 of the connected building object 6 stores in its public key infrastructure 30 a first pair of keys 32, 34 consisting of a first private key 32 and a first public key 34, the first private key 32 being associated with the first public key 34, the first private key 32 being configured to decrypt a message which has been encrypted with the corresponding first public key 34.

[0066] The electronic memory 24 of the connected building object 6 also stores, in its public key infrastructure 30, a first security certificate 36. The first security certificate 36 is unique to the connected building object 6.

[0067] For the purposes of the invention and in a manner known to those skilled in the art, a security certificate, also called a public key certificate or electronic certificate, is a named digital document representing a user, computer, service, or device. A security certificate contains the public key of the object of the security certificate, and does not contain the private key of the subject of the security certificate, which must It must be stored securely. A security certificate is digitally signed by a trusted third party and, for this purpose, contains at least one signature constructed from the trusted third party's private key. Once issued, a security certificate is tamper-proof, personalized, and certified by the trusted third party.

[0068] In one embodiment, the first security certificate 36 of the connected building object 6 is a TLS / SSL type public key certificate conforming to the X.509 standard, the format of which is more particularly described in the IETF RFC 5280 document "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile".

[0069] Alternatively, the first security certificate 36 of the connected object 6 for building is a TLS / SSL type public key certificate conforming to the OpenPGP standard, the format of which is more particularly described in the IETF RFC 4880 “OpenPGP Message Format”, and the use of which during communications secured by TLS / SSL is described in the IETF RFC 6091 “Using OpenPGP Keys for Transport Loyer Security (TLS) Authentication”.

[0070] Here, the first security certificate 36 of the connected object 6 for building represents the connected object 6 for building, and contains at least the first public key 34 of the connected object 6 for building, and a first digital signature 38 of a trusted third party 50. The first digital signature 38 of the trusted third party 50 is constructed from the private key of the trusted third party 50, and attests to the identity of the connected object 6 for building.

[0071] Preferably, the first security certificate 36 of the connected building device 6 is issued by the trusted third party 50 and recorded in production in the first public key infrastructure 30 of the connected building device 6. Once issued by the trusted third party 50, the security certificate 36 of the connected building device 6 is tamper-proof, in other words, unmodifiable.

[0072] Advantageously, the trusted third party 50 is constituted by a Certification Authority CA, the Certification Authority having a known role of issuing security certificates describing digital identities and of making available means of verifying the validity of the security certificates it has provided.

[0073] Advantageously, in one embodiment, the first safety certificate 36 of the connected building object 6 is self-signed, for example and advantageously, by the manufacturer of the connected building object 6, the manufacturer acting here as Certification Authority.

[0074] The electronic memory 24 of the connected building device 6 also stores a memory structure 26, for example in the form of a table, as schematically illustrated in [Fig. 2], the memory structure 26 associating VAL_q values, called access authorization values, with command sets E_q of associated actions.

[0075] The access authorization values ​​VAL_q are predetermined, for example integer values ​​coded on a predetermined number of bits.

[0076] In one embodiment, each access authorization value VAL_q is associated with a list of commands E_q={Ciq,...CPq}. The number of commands in a set (e.g., a list) E_q is greater than or equal to 1. The number of commands per set E_q varies from one set of commands to another.

[0077] The number N of access authorization values ​​is any chosen integer.

[0078] For example, the number N is equal to 3, corresponding respectively to three categories of control sets:

[0079] - a first access authorization value VAL_1 is associated with commands basic E_l,

[0080] - a second access authorization value VAL_2 is associated with commands E_2 adjustment, and

[0081] - a third access authorization value VAL_3 is associated with commands security E_3.

[0082] In some embodiments, the same command is part of several sets of commands.

[0083] The commands are accessible by means of the application programming software interface, known as API, implemented by the processing unit 22 of the connected object 6 for building which is associated with it.

[0084] The home automation system 4 further comprises at least one remote controller 8 connected to the communication network 14, the remote controller 8 being configured to control and / or configure at least one connected object 6 for building.

[0085] In a manner analogous to the connected object 6 for building, the remote controller 8 includes a network interface 20' adapted to connect the remote controller 8 to the communication network 14, at least one processing unit 22' connected to the network interface 20', and at least one electronic memory 24' connected to the processing unit 22'.

[0086] In one embodiment, the network interface 20' of the remote controller 8 is connected to a human-machine interface 28', allowing interaction with a user: receiving commands, displaying data or information received from the connected object 6 for building.

[0087] The electronic memory 24' of the remote controller 8 contains a public key infrastructure 30'.

[0088] The electronic memory 24' of the remote controller 8 stores in the public key infrastructure 30' of the remote controller 8 a second key pair 32', 34' of the remote controller 8 consisting of a second private key 32' of remote controller 8 and a second public key 34' of remote controller 8, the second private key 32' of remote controller 8 being associated with the second public key 34' of remote controller 8, the second private key 32' of remote controller 8 being configured to decrypt a message that has been encrypted with the corresponding second public key 34' of remote controller 8.

[0089] The electronic memory 24' of the remote controller 8 further stores, in the public key infrastructure 30' of the remote controller 8, a second security certificate 36' of the remote controller 8. According to embodiments, the second security certificate 36' represents the remote controller 8 and is unique to the remote controller 8, or represents a user of the remote controller 8 and in this case is unique to the user of the remote controller 8.

[0090] Advantageously, the second security certificate 36' of the remote controller 8 is issued by the same trusted third party 50 as the first security certificate 36 of the connected object 6 for building which the remote controller 8 is intended to control, in other words, the first security certificate 36 and second security certificate 36' are signed by the same trusted third party 50, and each contain for this purpose a signature constructed from the private key of said trusted third party 50.

[0091] In this way, the processing unit 22 of the connected building object 6 can trust a remote controller 8 whose security certificate contains a signature built from the same private key that was used to build the signature contained in its own security certificate.

[0092] As is known, the second security certificate 36' of the remote controller 8 has a plurality of fields, the size and purpose of which are standardized. For example, in the case of a TLS / SSL public key certificate conforming to the X.509 standard, these fields and their functionalities are described in the IETF RFC 5280 "Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile".

[0093] The second security certificate 36' of the remote controller 8, issued by the trusted third party 50, has a predetermined field whose value is set to one of the access authorization values ​​VAL_q, depending on the third party operating the remote controller 8.

[0094] For example, in the case of a TLS / SSL type public key certificate conforming to the X.509 standard, the predetermined field is the "Subject" field, the "Subject" field being made up of a non-zero set of ATTR_q attributes whose known primary function is to identify the entity associated with the public key contained in the security certificate.

[0095] Here, the non-zero set of ATTR_q attributes of the "Subject" field of the second The primary known function of the security certificate 36' of remote controller 8 is therefore to identify the entity associated with the second public key 34' contained in the second security certificate 36' of remote controller 8.

[0096] Alternatively, other fields besides the "Subject" field can be used for this purpose, such as the extension field conforming to the third version of the X.509 standard.

[0097] For example, in the case of an application where the access authorization value corresponds to one of the three categories of command sets detailed above, namely VAL_1 for basic commands, VAL_2 for setting commands and VAL_3 for security commands, the value of the ATTR_1 attribute "commonName" (or CN) of the "Subject" field is set to VAL_1 when the third party operating the remote controller 8 is a standard user, to VAL_2 when the third party operating the remote controller 8 is a maintenance agent and to VAL_3 when the third party operating the remote controller 8 is a home automation network installer.

[0098] Thus, the predetermined field, for example the "Subject" field of the second security certificate 36' of the remote controller 8, is used in a manner diverted from its known primary function, to indicate the authorization of access to the control of certain actions of the connected building object 6 by the third party operating the remote controller 8. Advantageously, this makes it possible to ensure security in the remote control of the corresponding connected building objects 6.

[0099] According to one variant, in addition to the Attr_q attribute of the predetermined field "Subject" whose value is modified to indicate the access authorization value of the remote controller 8, called in this case the first attribute Attr_l of the predetermined field, a second attribute Attr_2 of the predetermined field is used to identify the third party receiving the second security certificate 36' of the remote controller 8, in other words the third party operating the remote controller 8. The third party receiving the second security certificate 36' of the remote controller 8 is for example, as indicated above, a user, a maintenance agent or an installer.

[0100] For example, the value of the second attribute Attr_2 "organizationName" (or O) is set to a value identifying the third-party recipient, for example the name of the organization receiving the second security certificate 36' of remote controller 8, the recipient organization operating remote controller 8.

[0101] The processing unit 22 of the connected object 6 for building is configured to implement a module 40 for opening a secure connection with the remote controller 8, the processing unit 22' of the remote controller 8 being configured to implement a module 41 for requesting a secure connection.

[0102] Thus, modules 40 and 41 cooperate to implement a secure connection 42, using the first security certificate 36 of the connected object 6 for building and the second security certificate 36' of the remote controller 8.

[0103] For example, and in a known manner, the establishment of a secure connection 42 implements the TCP / TLS (Transmission Control Protocol / Transport Layer Security) communication network security protocol, during which an exchange of security certificates is implemented between the processing unit 22 of the connected object 6 for building and the processing unit 22' of the remote controller 8.

[0104] In particular, the module 40 for opening a secure connection 42 with the remote controller 8 receives the second security certificate 36' from the remote controller 8, and compares the second digital signature 38' of the second security certificate 36' from the remote controller 8 with the first digital signature 38 of its own security certificate 36, here the first security certificate 36 of the connected object 6 for building.The processing unit 22 of the connected building object 6 then determines whether the two digital signatures 38, 38' are constructed from the same private key associated with the trusted third party 50, and if so, registers in its public key infrastructure 30, the second security certificate 36' of the remote controller 8 as a trusted certificate in order to establish a master secret (translated from the Anglo-Saxon term "master secret") shared with the connected building object 6 and the remote controller 8, this shared master secret allowing to authenticate and encrypt, in other words to encrypt / decrypt, each message exchanged between the connected building object 6 and the remote controller 8.

[0105] In this way, a secure connection 42 can be implemented between the connected object 6 for building and the remote controller 8.

[0106] The processing unit 22' of the remote controller 8 is further configured to implement a command module 43 for executing at least one action by the connected building object 6, the command being sent by the remote controller 8, via the secure connection 42, and according to a high-level communication protocol operating at the application layer level of the connected building object 6 (e.g. io-homecontrol, SDN (Somfy Digital Network), Synergy, Matter, etc.) and understandable by the processing unit 22 of the connected building object 6.

[0107] Optionally, the processing unit 22' of the remote controller 8 also implements a module 44 for receiving data or information from the connected building device 6. For example, when the connected building device 6 is associated with a sensor, data provided by the sensor is received from the connected building device 6.

[0108] The processing unit 22 of the connected object 6 for building is further configured to implement a module 45 for receiving, via the secure connection 42, a command Cq to execute at least one action issued by the remote controller 8.

[0109] In addition, the processing unit 22 of the connected object 6 for building is further configured to implement a module 46 for extracting the access authorization value VAL_q from the predetermined field of the second security certificate 36' of the remote controller 8, previously received during the opening of the secure connection 42.

[0110] The processing unit 22 also implements a verification module 47, which checks whether the received command Cq belongs to the set of stored commands E_q={Ciq,.. .C Pq] associated with the extracted access authorization value VAL_q.

[0111] In case of positive verification, the processing unit 22 of the connected object 6 for building executes at least one action associated with the received Cq command.

[0112] Optionally, in the event of a positive verification, the processing unit 22 of the connected building object 6 records at least one piece of information relating to this positive verification in the electronic memory 24 of the connected building object 6, thus allowing traceability of attempts to execute received commands that produced a positive verification.

[0113] In case of negative check, it is considered that the remote controller 8 is not authorized for the received Cq command, at least one action associated with this command is then not executed by the processing unit 22 of the connected object 6 for building.

[0114] Optionally, a warning module 48 is implemented to execute at least one predetermined action in the event of a negative check of whether the command Cq belongs to the set of stored commands E_q={Ciq,...CPq] associated with the extracted access authorization value VAL_q. For example, the predetermined action in the event of a negative check is a notification to the remote controller 8, which can, for example, be displayed on the user interface of the remote controller 8, and / or an action to secure the connected building device 6, and / or an action to record information relating to this negative check in the electronic memory 24 of the connected building device 6, thus enabling traceability of attempts to execute received commands that resulted in a negative check.

[0115] A programmable electronic device comprising modules 40, 45, 46, 47, and 48, and storing a memory structure 26 forms a control device for the execution of at least one action by a connected object 6 for building.

[0116] In the example of [Fig. 2], modules 40, 45, 46, 47, and 48 are each implemented as software, or a software component, executable by the processing unit 22 of the connected building device 6. These modules form a computer program, also called a computer program product, which, when executed by the processing unit 22, implements the execution control method. at least one action by the connected object 6 for building.

[0117] This computer program is further capable of being stored on a computer-readable medium, not shown. A computer-readable medium is, for example, a medium capable of storing electronic instructions and being connected to a bus of a computer system. For example, a readable medium is an optical disc, a magneto-optical disc, a ROM, a RAM, any type of non-volatile memory (e.g., FLASH or NVRAM), or a magnetic card. A computer program comprising software instructions is then stored on the readable medium.

[0118] In an alternative not shown, modules 41, 45, 46, 47, and 48 are each implemented as a programmable logic component, such as an FPGA (Field Programmable Gate Array) or an integrated circuit, such as an ASIC (Application Specified Integrated Circuit).

[0119] Fig. 3 is a flowchart of the main steps of a process for controlling the execution of at least one action by a connected building object 6, the control process being implemented by a processing unit 22 of the connected building object 6.

[0120] The method includes a step 80 of receiving a secure connection request from a remote controller 8, and a step 82 of opening a secure connection using respectively the first security certificate 36 of the connected object 6 for building and the second security certificate 36' of the remote controller 8.

[0121] Step 82 implements substeps corresponding to a TCP / TLS negotiation known from the TCP / TLS communication network security protocol.

[0122] During the implementation of step 82 of opening a secure connection 42 with the remote controller 8, the processing unit 22 of the connected object 6 for building receives the second security certificate 36' from the remote controller 8, then determines whether the second security certificate 36' from the remote controller 8 received and the first security certificate 36 of the connected object 6 for building are signed by the same trusted third party 50, in order to register, if so, the second security certificate 36' from the remote controller 8 as a trusted security certificate in the public key infrastructure 30 contained in its electronic memory 24.

[0123] To determine whether the second security certificate 36' of the remote controller 8 received and the first security certificate 36 of the connected building object 6 are signed by the same trusted third party 50, the processing unit 22 of the connected building object 6 compares the digital signature 38' of the second security certificate 36' of the remote controller 8 received with the digital signature 38 of its own certificate of security 36, here the first security certificate 36 of the connected object 6 for building, and verifies that the digital signature 38' of the security certificate 36' of the remote controller 8 and the digital signature 38 of the connected object 6 for building are built from the same private key associated with the same trusted third party 50.

[0124] Advantageously, the registration of the second security certificate 36' of the remote controller 8 as a trusted security certificate is carried out automatically by the processing unit 22 of the connected object 6 for building.

[0125] Similarly, during the implementation of step 82 of opening a secure connection 42 with the connected object 6 for building, the processing unit 22' of the remote controller 8 receives the first security certificate 36 of the connected object 6 for building, then determines whether the first security certificate 36 of the connected object 6 for building received and its own security certificate 36', here the second security certificate 36' of the remote controller 8, are signed by the same trusted third party 50, in order to register, if necessary, the first security certificate 36 of the connected object 6 for building received as a trusted security certificate in the public key infrastructure 30' contained in its electronic memory 24'.

[0126] Advantageously, the registration of the first security certificate 36 of the connected object 6 for building received as a trusted security certificate is executed automatically by the processing unit 22' of the remote controller 8.

[0127] Alternatively, the registration of the first security certificate 36 of the connected object 6 for building received as a trusted security certificate of the remote controller 8, may require prior validation by the third party operating the remote controller 8, for example by submitting to the third party operating the remote controller 8, via the human-machine interface 28, an acceptance / refusal interface to register the security certificate 36 of the connected object 6 for building received as a trusted security certificate of the remote controller 8.

[0128] In this way, when each security certificate 36, 36' is registered respectively by the remote controller 8 and the connected building object 6 as a trusted certificate, the step 82 of opening a secure connection establishes, in a known manner, a master secret key shared with the connected building object 6 and the remote controller 8, this shared master secret key making it possible to authenticate and encrypt, in other words to encrypt / decrypt, each message exchanged between the connected building object 6 and the remote controller 8 via the secure connection 42.

[0129] Thus, an execution command can be sent in encrypted form via the secure connection to the connected object 6 for building from the remote controller 8.

[0130] Advantageously, if during the opening step 82 of a secure connection, at least one of the processing unit 22 of the connected object 6 for building and the unit processing unit 22' of the remote controller 8, determines that the first security certificate 36 of the connected object 6 for building and the second security certificate 36' of the remote controller 8 are signed by different third parties, at least one of the processing unit 22 of the connected object 6 for building and the processing unit 22' of the remote controller 8 can reject and / or block the opening of a secure connection between the connected object 6 for building and the remote controller 8.

[0131] The method then includes receiving 84, via the secure connection 42, a command to execute at least one action by the connected object 6 for building.

[0132] During step 86, the value of a predetermined attribute ATTR_q of a predetermined field of the second security certificate 36' of the remote controller 8 is extracted, this value corresponding to the access authorization value VAL_q of the remote controller 8. The predetermined attribute ATTR_q is, for example, the attribute "commonName" (or CN) of the "Subject" field of a TLS / SSL public key security certificate conforming to the X.509 standard.

[0133] According to one variant, the access authorization value VAL_q of the remote controller 8 is extracted from a first predetermined attribute ATTR_1 of a predetermined field of the second security certificate 36', and an ID identifier of the third party operating the remote controller 8 is extracted from a second attribute ATTR_2 of the predetermined field of the second security certificate 36'.

[0134] In general, the access authorization value VAL_q of the remote controller 8 is extracted from any attribute of any field of the second security certificate 36' of the remote controller 8, provided that the value of this attribute can be set to one of the access authorization values ​​VAL_q of the remote controller 8 while preserving the basic operation of the second security certificate 36' of the remote controller 8 for the implementation of opening a secure connection 42 between the remote controller 8 and the connected building object 6.

[0135] In one embodiment, the access authorization value VAL_q of the remote controller 8, and optionally the ID identifier of the third party operating the remote controller 8, are stored (step 88) in the electronic memory 24 of the connected building object 6.

[0136] Furthermore, when the ID of the third party operating the remote controller 8 is obtained, the method includes storing in an execution report file (or log) at least one piece of information indicating the command and the ID of the third party operating the remote controller 8. This allows a report of the requested executions to be stored, with additional information where appropriate, for example the date and time of receipt of the commands.

[0137] The method then includes a verification step 90, in the storage structure of access authorization value associations and sets of commands, of the membership of the command received in step 84 in the set of commands associated with the access authorization value VAL_q of the remote controller 8.

[0138] If the check is successful, the command is executed (step 92).

[0139] In case of a negative check, the command is not executed.

[0140] Optionally, in the event of a negative check, a warning step 94 is implemented.

[0141] In one embodiment, described with reference to [Fig.4], the connected building object 6 is adapted to establish a number P of secure connections 42 in parallel, P being an integer strictly greater than 1, for example P=5.

[0142] In [Fig.4], three secure connection channels 42A, 42B, 42C are illustrated by way of example, the connected building object 6 having established in parallel a first secure connection 42A with a controllable device 6a, a second secure connection 42B with a control unit 6b, and a third secure connection 42C with a sensor 6c.

[0143] Advantageously, the processing unit 22 of the connected building object 6, having received a secure connection request from a remote controller 8, can be configured to reject the opening of a secure connection with this remote controller 8, if the number P of secure connections 42 in parallel already established by the connected building object 6 is greater than or equal to a predetermined number P_max, P_max being an integer strictly less than P, and if none of the values ​​of the predetermined attributes ATTR_q extracted from each security certificate which enabled the establishment of the number P_max of secure connections with the connected building object 6, is equal to a predetermined access authorization value VAL_q of the remote controller 8.

[0144] In this way, the connected building device 6 can reserve at least one secure connection with a remote controller 8 where the value of a predetermined ATTR_q attribute of a predetermined field of the second security certificate 36' of the remote controller 8 is equal to a predetermined access authorization value VAL_q of the remote controller 8. This ensures the possibility of intervention by an authorized remote controller 8 for updating, configuring the operating parameters, or modifying the program code implemented by the connected building device 6.

[0145] More generally, in other variants can be envisaged, a secure connection being for example reserved for each type of third party operating a remote controller 8 (e.g. user, installer, maintenance).

[0146] Figure 5 illustrates an example of the application of the method of controlling the execution of at least one action by a connected object 6 for building execution, the action cor responding in this example to a secure update of at least one program executable by the processing unit 22 of the connected object 6 for building.

[0147] For this example, the second security certificate 36' of the remote controller 8 includes a predetermined field whose value of a predetermined attribute ATTR_q of this predetermined field is set to an access authorization value VAL_2 of the remote controller 8, the access authorization value VAL_2 being associated with a set of E_2 setting commands of the connected object 6 for building.

[0148] In this embodiment, the method includes a step 96 of downloading and storing in an electronic memory of the connected building object 6, an update file of one or more functionalities and / or one or more parameters of at least one executable program implemented by the processing unit 22 of the connected building object 6.

[0149] For example, the download is carried out via an FTP (for "File Transfer Protocol") connection, between the communication interface 20 of the connected object 6 for building and a remote FTP client (e.g. FileZilla) of the connected object 6 for building.

[0150] Advantageously, the electronic memory can be a FLASH type memory connected to the processing unit 22 of the connected object, thus allowing the downloaded update file to be automatically cleared from memory in the event that the opening of a secure connection subsequently fails.

[0151] The method then includes a secure connection opening step 98, the secure connection opening step 98 being implemented following a secure connection request step received from the remote controller 8 by the connected building object 6. The secure connection opening step 98 uses respectively the first security certificate 36 of the connected building object 6 and the second security certificate 36' of the remote controller 8, in a manner analogous to that described for the secure connection opening step 82 with reference to [Fig. 3].

[0152] Step 96 of downloading can be implemented either before or after step 98 of opening a secure connection.

[0153] The process then includes a step of receiving 100 an execution command Ci of the previously downloaded update file, the execution command Ci being sent by the remote controller 8, via the secure connection opened during step 98, according to a high-level communication protocol operating at the application layer level of the connected building object 6 (e.g. io-homecontrol, SDN, Synergy, Matter, etc.) and understandable by the processing unit 22 of the connected building object 6.

[0154] The process then includes a step 102 of extracting the access authorization value VAL_2 from the second security certificate 36' of the remote controller 8, and a Step 104 verifies that the Cireçue command is indeed contained within the E_2 command set associated with the VAL_2 access authorization value of the extracted remote controller 8. This association is stored in the memory structure 26 stored in the electronic memory 24 of the connected building device 6. Extraction steps 102 and verification steps 104 correspond respectively to extraction step 86 and verification step 90 described with reference to [Fig. 3].

[0155] Since the Cireçue command is indeed contained within the E_2 command set associated with the VAL_2 access authorization value of the extracted remote controller 8, the process then includes an execution step 106 of the update file.

[0156] Other embodiments can obviously be deduced by a person skilled in the art from the embodiments described above.

Claims

Demands

1. A method for controlling the execution of at least one action by a connected building device (6) in a communication network (14), said connected building device (6) having a network interface (20) enabling a connection to said communication network (14), said execution being controlled by a remote controller (8) adapted to connect to said communication network (14), the method being implemented by a processing unit (22) of said connected building device (6) adapted to execute at least one action of the connected building device (6), and comprising at least the steps of: - opening (82) a secure connection (42) between said connected object (6) for building and the remote controller (8), implementing a first security certificate (36) of the connected object (6) and a second security certificate (36') of the remote controller (8), the step of opening (82) a secure connection (42) allowing encrypted communication between said connected object (6) for building and the remote controller (8), and comprising a reception of the second security certificate (36') of the remote controller (8); and - reception (84), via said secure connection (42), of a command to execute at least one action issued by said remote controller (8), according to a communication protocol; characterized in that the process further comprises the steps of: - extraction (86) of a value from a predetermined field of the second security certificate (36') of the remote controller (8), called the access authorization value of the remote controller (8); - verification (90), in a memory structure (26) of associations between access authorization values ​​(VAL_q) and sets (E_q) of authorized commands, that said received command belongs to a set of at least one authorized command associated with said access value, the memory structure (26) being stored in an electronic memory (24) of said connected object (6) for building; and - in case of positive verification, execution (92) of at least one action associated with the received command.

2. A method according to claim 1, further comprising a step in which, in the event of a negative check, said at least one action associated with the received command is not executed, and a warning is sent (94) via said secure connection (42).

3. A method according to any one of claims 1 or 2, wherein the extraction step (86) further comprises an extraction of a second value from a predetermined field of the second security certificate of the remote controller (8) to obtain an identifier of a third party operating said remote controller (8).

4. Method according to claim 3, further comprising a step (88) of storing, in an execution report, said command received in association with the identifier of the third party operating said remote controller (8).

5. A method according to any one of claims 1 to 4, the processing unit (22) of the connected building object (6) being configured to open a plurality of secure connections in parallel, wherein the opening of a secure connection with a given remote controller (8) depends on the access authorization value extracted from the second security certificate of said remote controller (8).

6. A method according to any one of claims 1 to 5, wherein the verification step (90) implements a memory structure (26) in the form of a table associating, with each access authorization value (VAL_q) of the remote controller (8), a list of at least one command to execute at least one action by the connected object (6) for building.

7. A method according to any one of claims 1 to 6, wherein the connected building device (6) stores the first security certificate (36) of the connected building device (6), wherein, during the opening step (82) of a secure connection, the processing unit (22) of the connected building device (6) determines whether the second security certificate (36') of the remote controller (8) received and the first security certificate (36) of the connected building device (6) are signed by the same trusted third party (50), in order to register, if so, the second security certificate (36') of the remote controller (8) as trusted security certificate in a public key infrastructure (30) contained in its electronic memory (24).

8. A method according to any one of claims 1 to 7, further comprising a step (96) of downloading into an electronic memory of the connected building device (6) an update file of at least one executable program implemented by the processing unit (22) of the connected building device (6), the command received being included in a set of setting commands for the connected building device (6), the action associated with the command received being an implementation of said file.

9. A method according to any one of claims 1 to 8, wherein said connected object is a home automation device of a home automation system (4) for building.

10. Computer program comprising software instructions which, when executed by a programmable electronic device, implement a method for controlling the execution of at least one action by a connected object (6) in accordance with claims 1 to 9.

11. A device for controlling the execution of at least one action by a connected building object (6) in a communication network (14), implemented in said connected building object (6), the connected building object (6) having a network interface (20) allowing a connection to said communication network (14), said execution being controlled by a remote controller (8) adapted to connect to said communication network (14), said connected building having a processing unit (22) of said connected building object (6) adapted to execute at least one action of the connected building object (6), and comprising at least: - a module for opening a secure connection (42) between said connected building object (6) and the remote controller (8), implementing a first security certificate (36) of the connected building object (6) and a second security certificate (36') of the remote controller (8),the opening (82) of a secure connection (42) enabling encrypted communication between said connected object (6) for building and the remote controller (8), and including the reception of the second security certificate (36') of the remote controller (8); and, - a receiving module (50), via said secure connection (42), of a command to execute at least one action issued by said remote controller (8), according to a communication protocol; characterized in that the processing unit (22) further comprises: - an extraction module (46) of a value from a predetermined field of the second security certificate (36') of the remote controller (8), called the access authorization value of the remote controller (8); - a verification module (47), in a memory structure (26) of associations between access authorization values ​​(VAL_q) and sets (E_q) of authorized commands, that said received command belongs to a set of at least one authorized command associated with said access value, the memory structure (26) being stored in an electronic memory (24) of said connected building object (6); and - an execution module, in case of positive verification, of at least one action associated with the received command.

12. Control system for the execution of at least one action by a connected object (6) for building in a communication network (14), the system comprising said connected object (6) and a remote controller (8), said connected object (6) comprising a control device for the execution of at least one action according to claim 11.