Secure gateway for local management of a heterogeneous set of connected objects

By implementing a local gateway system that secures personal information with symmetric key encryption, the challenges of managing a heterogeneous set of connected objects are addressed, improving user ergonomics and security while reducing reliance on public networks.

FR3157048A1Pending Publication Date: 2025-06-20ELECTRICITE DE FRANCE
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
FR2023014213
Authority / Receiving Office
FR · FR
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-12-14
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

Current solutions for managing a heterogeneous set of connected objects are cumbersome and insecure, requiring users to register with multiple service platforms, manage personal data across different platforms, and face security risks due to data transmission over public networks.

Method used

A method and system that move certain functionalities from service platforms to a local gateway, allowing users to manage connected objects locally. The system uses a symmetric key generated from private/public key pairs associated with the gateway and the user's device to secure personal information stored within the gateway.

Benefits of technology

This approach enhances user ergonomics and security by reducing the need for multiple platform registrations, minimizing data transmission over public networks, and ensuring secure storage and access to personal information within the local gateway.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Method for managing a set of connected objects (E1, E2, E3, …, En) located in a given location (L), from a device (C) associated with at least one user associated with said given location, this method comprising: - operations for managing the connected objects from a gateway (GTW) located within said given location (L), at least some of these management operations involving personal information of the at least one user, - and in which said personal information is stored in a digital structure within the gateway (GTW), secured by a symmetric key generated from a first pair (KGTW) of private / public keys associated with the gateway (GTW) and a second pair (KC) of private / public keys associated with the device (C). Figure for the abstract: Fig. 1
Need to check novelty before this filing date? Find Prior Art

Description

Title of the invention: Secure gateway for local management of a heterogeneous set of connected objects FIELD OF THE INVENTION

[0001] The present invention relates to the management of connected objects located in a given location. It relates more particularly to the management of sensitive data, such as personal data, in the context of such management of a fleet of connected objects, in particular in the case where these objects may come from different suppliers.

[0002] The project that gave rise to this invention received funding from the European Union's Horizon 2020 research and innovation programme under grant agreement No. 894240.

[0003] Domestic or business premises contain a growing number of connected objects (or loT for "Internet of Things" in English) whose nature is extremely diverse and which, in general, are supplied by different manufacturers. In a residential premises, one can typically find, as connected objects, electronic equipment such as a connected television, lighting systems, household appliances, connected sockets, water heaters, charging stations, electrical panels, inverters, etc.

[0004] In order to be able to manage each of these connected objects, the user must generally register on a platform of the supplier or manufacturer of the connected object, which provides this connectivity service. This platform is generally a cloud computing platform (or "cloud" according to the usual terminology in English).

[0005] Very generally, a fleet of connected objects is made up of objects having various manufacturers and therefore managed by different service platforms. In other words, the user must register and register his connected objects with all the service platforms concerned. In addition, he must also interact with each of these platforms in order to be able to manage his different connected objects.

[0006] Orchestration solutions have been proposed. Examples include Apple's Homekit™, Google Assistant™, and Amazon's Alexa™. The user can create scenarios that combine objects from different brands. To do this, however, they will need to create accounts in each manufacturer's service platform (or "cloud") and then configure usage scenarios for their connected objects in the orchestrators, which can then interact with the manufacturers' different service platforms.

[0007]

[0008]

[0009]

[0010]

[0011]

[0012]

[0013]

[0014] However, such proposals are hardly satisfactory. Indeed, the proper functioning of the overall system depends on respecting interfaces that allow the orchestrator to implement the planned scenarios in collaboration with a multitude of proprietary service platforms. Furthermore, in addition to the technical aspects, contractual and pricing issues may arise for the implementation of these collaborations between platforms. The management, by the user, of a set of service platforms makes the solution not very ergonomic and difficult to maintain over time for the user, particularly in the event of changes to certain platforms which could lead to reconfigurations of the orchestrator. Furthermore, users must provide personal information to a multitude of service platforms, which can be both a barrier to the deployment of such a solution and an increase in security risks. There is therefore a need to improve current state-of-the-art proposals. Summary of the invention The invention aims to move certain functionalities assigned to service platforms to local equipment. For these purposes, according to a first aspect, the present invention can be implemented by a method for managing a set of connected objects located in a given location, from a device associated with at least one user associated with said given location, said method comprising: - operations for managing said connected objects from a gateway located within said specific premises, at least some of said management operations involving personal information of said at least one user, - and wherein said personal information is stored in a digital structure within said gateway, secured by a symmetric key generated from a first private / public key pair associated with said gateway and a second private / public key pair associated with said device. According to preferred embodiments, the invention comprises one or more of the following features which may be used separately or in partial combination with each other or in total combination with each other: - said management operations include the recovery of data from said connected objects, and the storage of said data within said gateway, - said management operations include the control of at least some of said connected objects according to commands transmitted by said device; - said gateway exchanges data with a remote processing platform, through a telecommunications network, using a lightweight messaging protocol; - to access said personal information, said device retrieves said second key pair, receives from said gateway a token and the public key of said first key pair, generates a first symmetric key from said public key of said first key pair and the private key of said second key pair, transmits to said gateway said token encrypted using said first symmetric key as well as said public key of said second key pair; and said gateway determines a second symmetric key from said public portion of said second key pair, and the private key of said first key pair, and grants or denies access to said personal information by decrypting said token from said second symmetric key. - said second pair of keys is previously provided in the form of a coding physically associated with said platform, and said device is adapted to determine said second pair of keys from said coding. - access to said personal information is granted if said second symmetric key makes it possible to find the value of said token and then, if necessary, by opening said digital structure using said second symmetric key.

[0015] According to another aspect, there is provided a computer program comprising instructions for implementing a method as previously described, when the method is implemented on an information processing platform.

[0016] According to another aspect, there is provided a gateway comprising a processor adapted to implement a method as previously described.

[0017] According to another aspect, there is provided a system comprising a gateway as previously described, and a device associated with at least one user.

[0018] Other characteristics and advantages of the invention will appear on reading the following description of a preferred embodiment of the invention, given by way of example and with reference to the appended drawings. BRIEF DESCRIPTION OF THE FIGURES

[0019] The attached drawings illustrate the invention: [Fig.l] schematically illustrates a context of use of a proposed method.

[0020] [Fig.2] schematically represents an organizational chart according to a mode of realization lization of the invention.

[0021] DETAILED DESCRIPTION OF EMBODIMENTS OF THE INVENTION

[0022] In [Fig. 1] are represented a set of connected objects, E,, E2, E3, ..., En, located in a given room L.

[0023] The determined premises L may correspond to a geographically limited space within the perimeter of which a given user can have the connected objects and control them. This space may correspond to a personal home (apartment, house, etc.), or to the premises of a company, a store, etc.

[0024] The determined premises may possibly have extensions outside of a limited space, when for example certain connected objects are remote: a charging station for an electric car may be located in a garage, a garden, or even overlook the roadway, and be outside the main space corresponding to the accommodation, while being within the user's control perimeter.

[0025] Connected objects can be of different natures. Generally speaking, it is any equipment adapted to communicate with third-party devices through a telecommunications network.

[0026] For example, we can cite: - household appliances (ovens, refrigerators, hotplates, etc.), - lighting systems - heating and thermal regulation systems, - security systems (motion detectors, surveillance cameras, etc.) - smart electricity meters (such as Linky™ in France, for example), - connected electrical outlets etc.

[0027] The user may wish to control these different objects, program operating schedules, retrieve data, establish interaction scenarios between certain objects, etc.

[0028] In the general case, the fleet of connected objects forms a heterogeneous set, that is to say in which each connected object can be supplied by a different manufacturer or distributor, so that they can be natively provided to be managed by distinct service platforms. The proposed method makes it possible, among other advantages, to avoid separate management for each connected object or to call upon an orchestrator which would also require individual registration of the orchestrator with each service platform.

[0029] In particular, an important issue is the management of thermal regulation. (temperature management, humidity level, etc.) of room L, based on energy and environmental constraints. Standards are currently being developed or refined for the establishment of a home energy management system (HEMS).

[0030] In the following, the case of a user is considered, but it must be understood that several users can be considered. In the case of domestic use, several members of the family can be users of the connected objects and can manage them. In the case of industrial or corporate use, similarly, several users with administrator status may have to manage the fleet of connected objects. Alternatively, an administrator profile can be defined, this single functional user profile can then be used by several physical users.

[0031] A device C is associated with the user (or users) to enable them to manage the set of connected objects.

[0032] This device is typically a mobile telecommunications device, such as a smartphone or a digital tablet. It can also be a laptop or desktop computer, a connected television, etc. This device can be equipped with a specific software application for managing the various connected objects available in the specific location L.

[0033] A GTW gateway is also provided, suitable for communicating with the various connected objects.

[0034] A pairing phase can be provided to allow each connected object to communicate with the GTW gateway.

[0035] The GTW gateway is also suitable for, once this initialization has been carried out, carrying out operations for managing connected objects.

[0036] These management operations may include some of the management operations performed by service platforms in the state of the art. In particular, this may include: - the recovery of data from connected objects Eb E2, E3, ..., En, and the storage of this data within said GTW gateway; - the control of at least some of these connected objects EH E2, E3, ..., En according to commands transmitted by the device C.

[0037] Thus, the gateway can centralize the various data produced by the equipment. These data can be of different natures: they can be measurements carried out by sensors, for example, in particular measurements of electrical consumption, etc.

[0038] It can also allow the control of objects, either by directly relaying commands transmitted by the device C, or, indirectly, by following a program, or scenario, previously established using device C.

[0039] Furthermore, the GTW gateway can perform processing, in particular on data retrieved from connected objects. Thus, all or part of the tasks usually performed by service platforms can be moved to the GTW gateway.

[0040] This makes it possible in particular to limit the data flows transmitted to a service platform. This makes it possible to limit the traffic on the telecommunications network and the load on the service platforms, but also to reduce the dependence of users on the use of public networks such as the Internet. The proposed system can thus operate without an Internet connection, for example in the event of a temporary interruption of the Internet access service.

[0041] Furthermore, users may not want data from their connected objects to be transmitted to a service platform, even if it is secure and its owner agrees to the use of this data. Relocating the processing of data to a gateway located within the specific premises L ensures greater confidence in the mechanism and its adoption by users.

[0042] The GTW gateway can however communicate with a service platform S, through the telecommunications network N, typically composed of an access network and a public Internet network.

[0043] Different role sharing between the GTW gateway and the S service platform can be envisaged.

[0044] The service platform S may be in charge of managing the GTW gateway, including software updates, fault management, etc.

[0045] Data from connected objects may also be transmitted to the service platform S for processing that cannot be performed locally, for example in order to aggregate data from several gateways. In such a case, it may be provided that these data are anonymized.

[0046] At least some of the management operations performed by the GTW gateway require or involve personal information of the user.

[0047] Generally speaking, it may be necessary for the user to identify himself in order to be able to carry out certain operations. It is indeed important that a third party cannot access the management functions of the various connected objects without being authorized to do so.

[0048] This is obviously the case for reasons of privacy and good management of personal data, but also for security reasons: it could thus be possible for a burglar to know the rhythm of life within a home, to have information on the presence or absence of family members, to remotely deactivate security systems (surveillance camera, for example, etc.

[0049] In other words, data from connected objects may involve or constitute personal information, since it describes individual user behavior.

[0050] The personal information may also include the identifiers of the connection between the GTW gateway and the various devices, in particular with the device(s) C associated with the user. This connection may for example be provided by a wireless local area network, for example meeting the Wi-Fi standard. Since such a wireless local area network is open to vulnerabilities, it must be secured, at least by connection parameters, of the identifier / passphrase type.

[0051] Personal information may also include information intended for the processing of data from connected objects.

[0052] This information may in particular be a computer code (object) allowing the processing of this data. It may also be a predictive model, of the neural network type. This model may be initially implemented or downloaded into the gateway and includes meta-parameters and synaptic weights which have been trained. It may be desirable to protect this information.

[0053] Personal information (which may include connection parameters, data from connected objects, etc.) may be stored in a digital structure within the GTW gateway.

[0054] Securing the digital structure makes it possible to prevent a third party from having access to it. They cannot therefore access personal data or connection parameters. They cannot therefore connect to the GTW gateway to retrieve data and / or send commands to control the connected objects. For example, without this personal data, a burglar cannot control the security systems of the specific premises L in order to deactivate them.

[0055] Furthermore, securing the digital structure in which personal data is stored meets the societal requirements imposed in different jurisdictions. In Europe, it helps meet the requirements of the General Data Protection Regulation, GDPR (European regulation 2016 / 679).

[0056] This secure digital structure can be called a “digital safe”. Only the owner of the data has the possibility of opening this safe using a device C with which it is associated.

[0057] The security is carried out by a symmetric key generated from a first pair, KGtw, of private / public keys associated with the GTW gateway and a second pair, Kc, of private / public keys associated with the device C.

[0058] Key pairs enable asymmetric encryption: data can be encrypted by a sender using the public key of a recipient (who therefore initially distributed this public key). Only the recipient can then decrypt the given using his private key. The private and public keys are mathematically designed to enable this asymmetric mechanism.

[0059] Asymmetric cryptography, or public key cryptography, is a relatively recent field of cryptography. It makes it possible to ensure the confidentiality of a communication, or to authenticate the participants, without relying on secret data shared between them, unlike symmetric cryptography which requires this prior shared secret.

[0060] [Fig.2] illustrates an embodiment making it possible to secure access to the digital space using this double pair of keys.

[0061] According to one implementation, in a step, the second pair of keys, Kc is provided in the form of a coding physically associated with the GTW platform. This coding may be a graphic coding of the barcode or matrix code type. It may for example be a graphic coding of the QR code family, but there are other matrix code formats with similar operation, such as Flashcode or 2D-Doc.

[0062] This coding may be physically affixed to the gateway packaging when it is purchased. It may also appear in a notice associated with the gateway.

[0063] Preferably, although possible, it is not affixed to the gateway itself, in order to avoid a theft of the gateway causing a risky situation. If the coding is not on the gateway, then a thief must seize both it and device C (assuming that the coding is either destroyed or stored in a safe place).

[0064] Although its coding is physically associated with the GTW platform, the second pair of keys, Kc, is initially unknown to the platform (i.e. not stored in its memory). During the process, it will only learn the public key Kcpub of this second pair of keys Kc.

[0065] This second pair of keys, Kc, is logically associated with the device C which will learn it in a step S3, during a pairing phase between the GTW gateway and the latter.

[0066] It should be noted here that if several devices C are used, they will retrieve the same pair of keys Kc. In this way, as will be seen, the devices will be paired with the GTW gateway so that each will be able to access the content of the secure digital structure indifferently. This mechanism of physically associating the coding of the pair of keys Kc with the GTW gateway thus makes it easy to share this same pair among a set of devices.

[0067] In a step S2, the digital space can be secured within the GTW gateway. This digital space is a memory area suitable for storing personal information and possibly other sensitive information.

[0068] This digital space is secured by a symmetric key generated from the two key pairs. In particular, these two key pairs are mathematically designed so that the same symmetric key is generated using a private key from the first or second key pair, and the public key from the other key pair.

[0069] In this step S2, the installation of the digital space is carried out in the premises of the gateway manufacturer, so that the security conditions are high and the use of the private key Kcpriv of the second pair of keys Kcne does not pose a security problem since it cannot be learned by accident or maliciously by a third party. It should be noted that at this stage, the end user is not a priori known, so that in addition no vulnerability linked to the vicinity of the latter is identifiable.

[0070] Preferably, a pre-encrypted file can be provided to the manufacturer of the GTW gateway, who then installs it on it. Thus, even the manufacturer of the gateway cannot be considered a point of vulnerability in the process: from an industrial point of view, this makes it possible to avoid the implementation of a manufacturing security strategy (authentication of authorized personnel, implementation of secure private networks, VPN, etc.)

[0071] This private key Kcprivest is used for generating the symmetric key, but is not stored, so that a malicious reading of the gateway's memory will not allow a third party to know it. In addition, the generation of the symmetric key can be performed on a third-party computer, used for configuring the gateway, but not necessarily on it.

[0072] The symmetric key can therefore be generated from this private key Kcpriv of the second key pair and the public key KGTWpub of the first key pair.

[0073] From these two keys, a secret can be determined using, for example, a Diffie-Hellman key exchange algorithm. This method allows the same secret to be determined by two parties, using their respective asymmetric key pair. This well-known method was initially described in the article by W. Diffie and M. Hellman, "New directions in cryptography", IEEE Transactions on Information Theory, vol. 22, no. 6,^ 1976, pp. 644-654.

[0074] The symmetric key can be derived from this secret shared by both keys.

[0075] This symmetric key can be a 256-bit AES (for “Advanced Encryption Standard”) type key. This AES-256 key can be generated from a PBKDF2 function.

[0076] In particular the AES algorithm can be used with a GCM (Galois / Counter Mode) construction mode.

[0077] AES (literally "advanced encryption standard") is a widely used and extensively documented symmetric encryption algorithm. The Wikipedia page gives its algorithm in high-level pseudo-language and provides pointers to scientific articles describing it more fully:

[0078] https: / / fr.wikipedia.org / wiki / Advanced_Encryption_Standard

[0079] These standards AES-256, PBKDF2... correspond to the current cryptography mechanisms and are accessible to those skilled in the art. There are also numerous tools or examples of computer codes (in JavaScript, for example) allowing the generation of the symmetric key to be implemented easily.

[0080] Using GCM mode helps protect against content injection attacks. The integrity provided to the data by this encryption does not allow a cyber-attacker to inject content into the transmitted data.

[0081] However, it is clear that other cryptographic algorithms can also be used, in particular depending on the appearance of new standards and new algorithms that are more efficient, more appropriate or more widespread.

[0082] In addition, the first KGTWest key pair is also installed in the gateway, for example in a configuration file.

[0083] Once the gateway is installed in the determined room L, the following steps (S3-S7) can be implemented in order to enable collaboration between the gateway and the device C.

[0084] In a step S3, therefore, the device(s) C recovers the second pair of keys Kc.

[0085] This recovery can be carried out by means of the camera of the device C in the case where this key pair is encoded in the form of a matrix code type encoding (QR code, etc.). But other implementations are also possible to allow device C to acquire this key pair.

[0086] This step can be implemented during the installation of the system at the user's premises. It may be necessary to first install a specific application on the device C, this application being adapted to implement the steps of the method allowing the pairing of the device C with the GTW gateway.

[0087] In a step S4, the device C receives from the gateway a token and the public key K GTWPub of the first pair of keys KGTW.

[0088] This transmission can be done by a wireless communication protocol, for example a short-distance communication protocol such as the Bluetooth™ protocol.

[0089] The token can be any character string, determined, for example randomly, by the GTW gateway.

[0090] Using a token helps protect against replay attacks. In this type of cyberattack, a malicious third party listens to the communication in order to replay it later as is. Generating a dynamic token no longer allows this type of replay.

[0091] Upon receipt of this information, in a step S5, the device C can generate a first symmetric key K1, in the same way as described previously, but based on the public key KGTWPub of the first key pair, transmitted in step S4, and the private key Kcpriv of the second key pair, retrieved in step S3.

[0092] Device C can then encrypt the token using this symmetric key K.

[0093] In step S6, the device C transmits to the gateway GTW the token encrypted using the symmetric key Kl, as well as the public key Kcpub of the second pair of keys Kc.

[0094] Upon receipt of this data, in a step S7, the GTW gateway can determine a second symmetric key K2. This symmetric key K2 is derived using the same mechanism as previously described, but from the public key Kcpub of the second key pair Kc, received in step S6, and the private key KGTWpriv of the first key pair KGTW stored locally.

[0095] In a step S8, the GTW gateway may or may not grant access to the personal information stored in the secure space by decrypting the token from this second symmetric key K2.

[0096] More precisely, according to one embodiment, this step can be broken down into two sub-steps: In a step S81, the gateway verifies that the second symmetric key K2 actually makes it possible to find the value of the token previously transmitted to the device C, Then, if this is the case, in a step S82, access to the digital structure can be granted using this second symmetric key K2.

[0097] Granting access actually involves decrypting the digital space using the second symmetric key.

[0098] In other words, this step aims to determine that the two symmetric keys K1 and K2 are identical. If this is not the case, access is not authorized and, in any case, the use of the second symmetric key K2 would not allow the digital space to be decrypted.

[0099] This process therefore guarantees the security of the information stored in the digital space: only a device associated with a user who has previously been able to pair with the gateway can open the secure digital space.

[0100] Of course, the present invention is not limited to the examples and the embodiment described and shown, but is defined by the claims. It is in particular susceptible of numerous variants accessible to those skilled in the art.

Claims

Claims

1. Method for managing a set of connected objects (Eb E2, E3, En) located in a given location (L), from a device (C) associated with at least one user associated with said given location, said method comprising: - operations for managing said connected objects from a gateway (GTW) located within said given location (L), at least some of said management operations involving personal information of said at least one user, - and in which said personal information is stored in a digital structure within said gateway (GTW), secured by a symmetric key generated from a first pair (KGTW) of private / public keys associated with said gateway (GTW) and a second pair (Kc) of private / public keys associated with said device (C).

2. Method according to the preceding claim in which said management operations comprise the recovery of data from said connected objects (Eb E2, E3, ..., En), and the storage of said data within said gateway (GTW).

3. Method according to one of the preceding claims, in which said management operations comprise the control of at least some of said connected objects (Eb E2, E3, ..., En) according to commands transmitted by said device (C).

4. Method according to one of the preceding claims, in which said gateway exchanges data with a remote processing platform (S), through a telecommunications network (N), using a lightweight messaging protocol.

5. Method according to one of the preceding claims, in which to access said personal information, said device (C): - (S3) retrieves said second pair of keys (Kc), - (S4) receives from said gateway a token and the public key of said first pair of keys (KGTW), - (S5) generates a first symmetric key (Kl) from said public key of said first pair of keys and the private key of said second key pair; - (S6) transmits to said gateway (GTW) said token encrypted using said first symmetric key (Kl) as well as said public key of said second key pair (Kc); and said gateway, - (S7) determines a second symmetric key (K2) from said public part of said second key pair (Kc), and the private key of said first key pair (KGTW), and, - (S8) grants or not access to said personal information by decrypting said token from said second symmetric key (K2).

6. Method according to the preceding claim in which said second pair of keys (Kc) is previously provided (SI) in the form of a coding physically associated with said platform (GTW), and said device (C) is adapted to determine (S3) said second pair of keys (Kc) from said coding.

7. Method according to one of claims 5 or 6, in which access (S8) to said personal information is granted if said second symmetric key (K2) makes it possible to find the value of said token (S81) then, if necessary, by opening (S82) said digital structure by means of said second symmetric key (K2).

8. Computer program comprising instructions for implementing a method according to one of the preceding claims, when said method is implemented on an information processing platform.

9. Gateway (GTW) comprising a processor adapted to implement a method according to one of claims 1 to 7.

10. System comprising a gateway (GTW) according to the preceding claim, and a device (C) associated with at least one user.

Citation Information

Patent Citations

  • System for transmitting two-way radio communications via computer networks

    EP2016679A2

  • Method of sharing key between devices using physical access restriction

    US20160330182A1

  • System and method for virtual internet of things (IOT) devices and hubs

    US20170005820A1

  • Efficient Internet-Of-Things (IoT) Data Encryption / Decryption

    US20220141004A1

  • Control Method, Apparatus, and System

    US20220272077A1