PASSWORD MANAGEMENT METHOD FOR A CONNECTED OBJECT AND DEVICE EXECUTING THE METHOD.
The method addresses security and interoperability challenges in connecting IoT devices by using a password management system with temporary MAC address substitution, enabling easy and secure network access for devices with basic interfaces.
Patent Information
- Application Number
- FR2024006692
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-21
- Publication Date
- 2025-12-26
AI Technical Summary
Existing methods for connecting IoT devices to communication networks face security challenges due to lower security levels and complex interoperability issues, especially when users are unable to identify or obtain the device's MAC address, which complicates the connection process.
A method that temporarily substitutes a generic MAC address for the device's actual MAC address during the connection process, using a password management system that manages a list of password and MAC address combinations, allowing for easy and secure network access without requiring users to know or input the actual MAC address.
Facilitates secure and efficient connection of IoT devices to networks by simplifying the authentication process, ensuring compatibility, and enhancing network security without complex user interactions.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: METHOD FOR MANAGING PASSWORDS FOR A CONNECTED OBJECT AND DEVICE EXECUTING THE METHOD. technical field
[0001] The present invention relates to a secure connection of a station to a communication network, via an access point of that network. More particularly, the invention relates to an improved method for assigning a password to a device, for the purpose of an authenticated connection of that device to a communication network. PRIOR TECHNOLOGY
[0002] An increasing number and variety of devices are capable of being connected to communication networks as part of their use, including, in particular, so-called "IoT" (Internet of Things) connected objects. These connected objects may potentially have lower security levels than other devices such as computers or smartphones, for example, and this could then reduce the overall security level of a communication network to which such an object is connected. Some security methods rely on a centralized authentication server, but this type of infrastructure is not well suited to home use.Security standards, such as WP A3, rely on the use of TLS certificates (Transport Layer Security), which allows for the use of unique connection information for each station that might connect to a communication network. However, such a solution presents significant interoperability constraints between connected objects and access point devices, requiring complex manipulations that are undesirable in the consumer product sector. Therefore, it can be practical to use connection methods that combine a unique identifier for a station, such as a MAC address, with a password. Unfortunately, the MAC address of a station, especially when it is a connected object, is sometimes inaccessible to a novice user or at least difficult to identify or obtain.
[0003] The situation can be improved. Description of the invention
[0004] An object of the present invention is to provide an easy and fast method for securely connecting a station to a communication network, whereby each station has a password associated with its MAC address, including when a A user wishing to establish such a connection either does not know the MAC address of the station or does not wish to search for it. This is the case, for example, with so-called "connected" devices that offer only a basic user interface.
[0005] To this end, a method is proposed for connecting a station to a communication network via an access point device, the method comprising:
[0006] - a definition of a password, with reference to a station identifier, the identifier being a MAC address of the station, and,
[0007] - a connection to the network, subsequent to the step of defining a password, the connection using a combination of the station's MAC address and the defined password, for the purpose of authenticating the station within the network.
[0008] the method being cleverly such that a generic MAC address is temporarily substituted for the station's MAC address in a list of passwords each associated with a station identifier in the form of a MAC address, during a substitution step, and until the station's MAC address can be obtained by the access point device during the connection phase.
[0009] According to one embodiment, the process is further such that: - A password management module manages a list of connection information sets, each set comprising at least one password and a station identifier in the form of a MAC address. - an authentication module performs a validity check of connection requests to said access point, each of said connection requests being issued by a station, - a connection management module configured to store representative connection and disconnection information and transmit this information to one or more third-party devices,
[0010] and according to which the substitution step is carried out by the password management module.
[0011] According to one embodiment, the process is carried out in the access point device of the communication network.
[0012] According to one embodiment, the generic MAC address is 00:00:00:00:00:00, known as "wildcard".
[0013] Another object of the invention is a connection management module for a station to a communication network via an access point device, the module comprising electronic circuitry configured to operate:
[0014] - a definition of a password, with reference to an identifier of said station, said the identifier being a MAC address of the station, and,
[0015] - a connection to the network, subsequent to said password definition step, said connection using in combination said MAC address of the station and said defined password, for the purpose of authenticating said station in said network,
[0016] said connection management module being characterized in that it further comprises electronic circuitry configured to temporarily substitute a generic MAC address for said MAC address of the station in a list of passwords each associated with a station identifier in the form of a MAC address, during a substitution step, and until said MAC address of the station can be obtained (for example read) by said access point device during said connection phase.
[0017] According to one embodiment, the connection management module for a station to a communication network comprises electronic circuitry including: - a password management module configured to manage a list of connection information sets, each set comprising at least one password and a station identifier in the form of a MAC address, - an authentication module configured to perform a validity check of connection requests to said access point, each of said connection requests being issued by a station, - a connection management module configured to store representative connection and disconnection information and transmit this information to one or more third-party devices,
[0018] and the password management module further comprising circuitry for operating said substitution step.
[0019] The invention also relates to a communication network access point device, comprising a connection management module as previously described.
[0020] Another object of the invention is a communication network comprising at least one access point device as mentioned above.
[0021] The invention also relates to a computer program product comprising program code instructions for executing the steps of a process as previously described when this program is executed by a processor of a connection management module of a communication network, as well as an information storage medium comprising such a computer program product. Brief description of the drawings
[0022] The features of the invention mentioned above, as well as others, will become clearer upon reading the following description of at least one example of implementation, the said description being made in relation to the attached drawings, among which:
[0023] [Fig.1] illustrates a LAN-type communication network comprising wireless access point devices, to which stations can be connected, according to one embodiment;
[0024] [Fig.2]; illustrates details of an access point device as used in the network communication already represented on the [Fig.l];
[0025] [Fig.3] is a flowchart illustrating steps in a connection process of a station to a wireless access point of the communication network already shown in [Fig.1], according to one embodiment;
[0026] [Fig.4] is a flowchart illustrating the creation of a password in association with a MAC address of a station to be connected to the communication network already shown in [Fig.1], according to one embodiment;
[0027] [Fig.5] is a flowchart illustrating a connection of a station to the network of communication already represented in [Fig. 1], using in combination a MAC address of the station and a created password, according to one embodiment; and,
[0028] [Fig.6] is a diagram illustrating an example of the internal architecture of a module connection management configured to execute the process illustrated in relation to [Fig.3], according to one embodiment.
[0029] DETAILED DESCRIPTION OF IMPROVEMENTS
[0030] Figure 1 illustrates a LAN (Local Area Network) communication network 1. The communication network 1 is connected to a WAN (Wide Area Network) via a home gateway GW 10 and a communication link 10a that connects the gateway GW 10 to the WAN 1000. According to the described embodiment, the communication network 1 comprises three wireless access point devices 11, 12, and 13, each configured to operate wireless connections (not shown in Figure 1) between one or more stations 01, 02, 03 and the communication network 1. According to the described embodiment in Figure 1, the communication network 1 comprises three wireless access point devices 11, 12, and 13, each configured to operate wireless connections (not shown in Figure 1) between one or more stations 01, 02, 03 and the communication network 1.[l] The wireless access point device 11 is connected to the communication network 1 via the wireless access point device 12, through a communication link 11' established between the wireless access point device 11 and the wireless access point device 12. Also according to the described embodiment, the wireless access point device 12 is connected to the communication network 1 via the home gateway GW 10, through a communication link 12'. Finally, and still according to the described embodiment, the wireless access point device 13 is also connected to the communication network 1 via the home gateway GW 10, through a communication link 13'. The term "station". Herein, "Wireless Access Point" refers to any electronic and / or computer device configured to be connected to at least one LAN (Local Area Network), such as, for example, a desktop computer, a laptop computer, a connected tablet, a connected smart TV, a smartphone, a smartwatch, a connected household appliance, an alarm or personal assistance device, a radio receiver, a connected speaker, a data storage device, etc. These examples are obviously not exhaustive. Of course, other various electronic and / or computer devices can be connected to the communication network 1, but for the sake of simplicity, these are not shown in [Fig. 1]. The wireless access point device 11 includes one radio resource RI; the wireless access point device 12 includes one radio resource R2; and the wireless access point device 13 includes two radio resources R3 and R4.The terms "radio resource" or "radio" here refer to an electronic interface configured to operate bidirectional wireless communications between a compatible remote device and the communication network 1, for example, according to a protocol from the 802.11 family of standards of the Institute of Electrical and Electronics Engineers (IEEE), or so-called 'Wi-Fi' type networks. Examples of implementations can be found, for example, in the context of the IEEE 802.11-2020 standard or the IEEE 802.11be amendment, in its D4.0 or D5.0 version, or in its later or final versions. Other implementation examples can also be found, for example, in the context of a version of the IEEE 802.11 standard or an amendment to this 802.11 standard incorporating the IEEE 802.11be amendment, such as the IEEE 802.11bf D3.0 amendment or the IEEE 802.11bn amendment. These apply to both home wireless networks and enterprise networks.It should be noted that the Wireless Access Point 13 device also includes a W3 wired connection interface.
[0031] The wireless access point 13 further includes a connection management module 100, configured to manage the connection and disconnection of one or more stations to the communication network 1, via the wireless access point 13 through its radio resource R3 or via its wired interface W3. Similarly, the wireless access points 11 and 12 each include a connection management module configured to manage the connection and disconnection of stations to the communication network 1 through them. For the sake of simplicity, details relating to the implementation of one or more embodiments in relation to an access point of the communication network 1 will be described below only with reference to the wireless access point 13. The principles described are applicable to the other wireless access points of the communication network 1.
[0032] According to one or more embodiments, the wireless access point device 13 comprises electronic circuitry configured to implement:
[0033] - a password management module configured to operate a password management a list of connection information sets, each of which includes at least one password and a station identifier in the form of a MAC address, stored together in a password list (and therefore in a MAC address list),
[0034] - an authentication module configured to perform a validity check of connection requests to the access point device 13, each connection request being issued by a station, and,
[0035] - a connection management module configured to store information representative of connections and disconnections and transmit this information to one or more third-party devices.
[0036] According to one embodiment, the connection management module includes the aforementioned password management module and authentication module.
[0037] The authentication module operates using a combination of a password and a MAC address, which combination is obtained from the password management module. Furthermore, the connection management module initiates connections by requesting the authentication module to verify the identity and access rights of a station identified for the purpose of establishing a connection.
[0038] Cleverly and according to one embodiment, the password management module of the connection management module 100 further includes circuitry configured to perform a step of substituting a MAC address of a station with a generic MAC address, when the MAC address of a station to be connected to the communication network 1 cannot be provided by a user of the station wishing to connect the latter to the communication network 1.
[0039] According to the example shown in [Fig.1], the stations within range of the access point devices of the communication network 1 are stations 01, 02 and 03 which are respectively a laptop 01, a connected camera 02, and a smartphone 03.
[0040] Figure 2 illustrates architectural details of the wireless access point device 13, which includes, in addition to a radio resource R3, a wired connection interface W3. The wireless access point device 13 also includes a digital core 13c and an internal connection management module 100. An internal communication bus 130 connects the digital core 13c, the connection management module 100, the radio resource R3, and the wired connection interface W3. The digital core 13c is connected to the rest of the communication network (via the gateway GW 10) by means of the connection link 13'.
[0041] Figure 3 is a flowchart illustrating steps in a method for connecting station 02, one of stations 01, 02, and 03, to the wireless access point device 13 of the communication network 1, executed by the connection management module 100, according to one embodiment. A first step, S30, is an initialization step at the end of which all devices of the communication network 1 are normally powered and initialized to operate nominally, including, in particular, the access point device 13 and station 02, except that station 02 is not yet connected to the communication network at this stage. A step S31 aims to define a password for station 02, in relation to its MAC address, which station 02 is not yet connected to communication network 1. Details of this step (or phase) of creating a password for station 02 are described later in relation to [Fig.4].Once a password has been defined in step S31, step S32 aims to connect station 02, a connected object camera, to communication network 1. This involves first authenticating station 02 within communication network 1 using the previously defined password and the station's MAC address, and then establishing a connection, which is authorized once the authentication step has been successfully completed. In other words, the final connection can only be established if the station (here, station 02) is authorized to join communication network 1 as a connected station. In one embodiment, the authentication step includes implementing data encryption between station 02 and the wireless access point device 13.The details of the data encryption are not elaborated upon here as they are not relevant to understanding the invention.
[0042] Advantageously and cleverly, the step of creating a password for station 02, which is not yet connected to the communication network, includes associating an automatically generated (randomly) password with a temporary wildcard MAC address. This is used when the station user is unable to enter the MAC address of station 02, either because they do not know it or because they do not wish to enter it, considering such an operation complex, too slow, and / or too slow. In one embodiment, the temporarily used wildcard address is named "wildcard" and has the value 00:00:00:00:00:00.
[0043] Fig. 4 details operations carried out during step S31 of the process of connecting a station to the communication network 1 described previously in relation to Fig. 3, executed by the connection management module 100 of the wireless access point device 13 of the communication network 1.
[0044] An S40 step is a connection request step at the end of which a user of the station concerned (02, according to the example described) is about to define a password for this station not yet connected to the communication network 1, before or after having requested a connection of the station to the communication network 1. Depending on the security mode implemented, the password must be stored in combination with the MAC address of the station concerned, for the purpose of subsequent authentication during a connection step, and possibly for the implementation of encryption between the station concerned and the access point device to which it must be connected in order to integrate the communication network 1.In one embodiment, the wireless access point device includes a user interface, also commonly called a human-machine interface, allowing the user to enter information necessary for creating (or defining) the password directly, either via the wireless access point device itself or via a console connected to it. During step S41, the user, through the available user interface, selects whether or not to request automatic password generation. This involves automatically determining a string of characters that defines a login password for the station in question, for the purpose of connecting to the communication network 1. If the user opts for automatic password generation (step S41, "yes"), the password management module of the connection management module 100 randomly determines a string (or sequence) of characters during step S42b.Conversely, if the user chooses to define their own connection password string (step S41, "no"), they enter a string that is then stored by the password management module of the connection management module 100 during step S42a. Step S43 aims to distinguish between two scenarios depending on whether the user, using the connection method of station 02 to the communication network 1 via the wireless access point device 13, knows or does not know the MAC address of the station 02 to be connected, or whether they behave as if they do not know it.If the user has successfully identified the MAC address of the station to be connected, for which they have just set a password (step S43, "yes"), the user enters this MAC address during step S44a. The MAC address is then recorded during step S45, with reference to the previously set password, in a table (list) of MAC address and password combinations, respectively associated in pairs. Cleverly, if the user is unaware of, or behaves as if unaware of, the MAC address of station 02, they inform the connection management module 100 via the user interface, and the MAC address of the station associated with the previously set password is determined to be the generic MAC address, for example, the wildcard MAC address (00:00:00:00:00:00), during a [process / operation]. step S44b then stored in a table (list) of combinations of MAC addresses and passwords, respectively associated in pairs during a step S45. The notion of list here includes the case for which only one entry (combination of a password and a MAC address) is present in the list, in addition to the cases where the list includes a plurality of entries.
[0045] Figure 5 details operations performed during step S32 of the process for connecting a station to the communication network 1 described previously in relation to Figure 3, executed by the connection management module 100 of the wireless access point device 13 of the communication network 1. Step S50 is an initial step during which a station (here 02, according to the example described) requests a connection via a radio or wired interface of an access point device (the access point device 13, according to the example described). If necessary, the user first enters the SSID (Service Set Identifier) and the required password in the internal system of the station concerned, the object of the upcoming connection. The station is then identified, and more specifically authenticated by the communication network 1.During the connection phase, the authentication module of the connection management module 100 queries the password management module. This password management module then scans the list of access rights information sets, namely the combinations (or pairs) of passwords and MAC addresses. The connection management module, in turn, queries the authentication module before ultimately authorizing a connection from the station, if the station is authenticated, or rejecting the connection request. During an S51 step, the password management module checks, while scanning the list of password and MAC address combinations, whether the MAC address of the station wishing to connect is present in the password management module's list.If this is the case (step 51, "yes"), then step S52 verifies whether the password stored in combination with the MAC address in the list is correct. If the password stored in combination with the MAC address in the list is correct (step S52, "yes"), then the connection is validated in step S55. Conversely, if the password is not correct (step S52, "no"), the connection request is rejected in step S54 by the connection management module 100. If, on the other hand, the identified MAC address of the station wishing to connect is not present in the password management module's list, then step S43 verifies whether the list contains a generic MAC address, such as, for example, the MAC address 00:00:00:00:00:00. If no generic MAC address is listed in the password management module. (step S43, "no"), the connection request is rejected, during step S54, by the connection management module (100).Conversely, if in the case where a generic MAC address has been identified in the password list (step S43, "yes"), and the password recorded in combination in the list satisfies the authentication check(s), which is verified during a step S56 (step S56, "yes"), then an update of the password list is performed by the password management module, under the control of the connection management module 100, during a step S57, and the real MAC address of the station, visible or obtained by the connection management module 100 during the connection step S32, replaces the generic MAC address temporarily and cleverly used as a substitute MAC address, with the real MAC address of the station concerned, in the password list, and the connection of the station is confirmed in step S55.
[0046] Figure 6 schematically illustrates an example of the internal architecture of a connection management module 100 of the wireless access point 13. It should be noted that Figure 6 could also represent the internal architecture of a wireless access point such as the wireless access point device 13 or the wireless access point device 11 or 12, or even the internal architecture of a connection gateway device such as the home gateway GW 10, and even the architecture of a station such as stations 01, 02 and 03. According to the hardware architecture example shown in Figure 6,6], the connection management module 100 of the wireless access point device 13 then comprises, connected by a communication bus 120: a processor or CPU (Central Processing Unit) 101; a RAM (Random Access Memory) 102; a ROM (Read Only Memory) 103; a storage unit such as a hard disk drive (or a storage media reader, such as an SD card reader (Secure Digital) 104); at least one communication interface 105 enabling the connection management module 100 of the wireless access point 13 to communicate with other devices to which it is connected, such as the stations whose connection it manages, for example.
[0047] The processor 101 is capable of executing instructions loaded into RAM 102 from ROM 103, external memory (not shown), storage media (such as an SD card), or a communication network. When the connection management module 100 of the wireless access point device 13 is powered on, the processor 101 is capable of reading instructions from RAM 102 and executing them. These instructions form a computer program causing the processor 101 to implement all or part of a process described in relation to [Fig. 3] (and therefore [Fig. 4] and [Fig. 5]) or described variants of this process.
[0048] All or part of the process described in relation to [Fig.3] or its described variants can be implemented in software form by executing a set of instructions by a programmable machine, for example a DSP (Digital Signal Processor) or a microcontroller, or be implemented in hardware form by a dedicated machine or component, for example an FPGA (Field-Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit). In general, the connection management module 100 of the wireless access point device 13 includes electronic circuitry configured to implement the processes described in relation to itself.Obviously, the 100 connection management module of the 13 wireless access point device also includes all the elements usually present in a system comprising a control unit and its peripherals, such as a power supply circuit, a power monitoring circuit, one or more clock circuits, a reset circuit, input / output ports, interrupt inputs, bus drivers, this list being non-exhaustive.
Claims
Demands
1. A method for connecting a station (02) to a communication network (1) via an access point device (13), the method comprising: - a definition of a password (S31), with reference to an identifier of said station, said identifier being a MAC address of the station, and, - a connection to the network (S32), subsequent to the aforementioned password definition step (S31), said connection step using in combination the station's MAC address and the defined password, for the purpose of authenticating the station within the network, said method being characterized in that a generic MAC address is temporarily substituted for said MAC address of station (02) in a list of passwords each associated with a station identifier in the form of a MAC address, during a substitution step, and until said MAC address of station (02) can be obtained by said access point device (13) during said connection phase (S32).
2. The method according to claim 1, wherein: - A password management module manages a list of connection information sets, each set comprising at least one password and a station identifier in the form of a MAC address. - an authentication module performs a validity check of connection requests to said access point, each of said connection requests being issued by a station, - a connection management module configured to store representative connection and disconnection information and transmit this information to one or more third-party devices, and according to which said substitution step is carried out by said password management module.
3. A method according to any one of claims 1 and 2, the method being carried out in said access point device (13) of the communication network (1).
4. A method according to any one of claims 1 to 3, wherein said wildcard MAC address is 00:00:00:00:00:00, referred to as "wildcard".
5. Connection management module (100) of a station (02) to a communication network (1) via an access point device (13), the connection management module (100) comprising electronic circuitry configured to operate: - a password definition (S31), with reference to an identifier of said station, said identifier being a MAC address of the station, and, - a connection to the network (S32), subsequent to said password definition step, said connection step using in combination said MAC address of the station and said defined password, for the purpose of authenticating said station in said network,said connection management module being characterized in that it further comprises electronic circuitry configured to temporarily substitute a generic MAC address for said station MAC address (02) in a list of passwords each associated with a station identifier in the form of a MAC address, during a substitution step, and until said station MAC address can be obtained by said access point device during said connection phase.
6. Connection management module (100) of a station (02) to a communication network (1) according to claim 5, the connection management module (100) comprising electronic circuitry including: - a password management module configured to manage a list of connection information sets, each set comprising at least one password and a station identifier in the form of a MAC address, - an authentication module configured to perform a validity check of connection requests
7.
8.
9.
10. access point, each of these connection requests being issued by a station, - a connection management module configured to store representative connection and disconnection information and transmit this information to one or more third-party devices, and the password management module further including circuitry to perform said substitution step. Access point device (13) to a communication network (1), comprising a connection management module (100) according to one of claims 5 and 6. Communication network (1) comprising at least one access point device (13) according to claim 7. A computer program product characterized in that it comprises program code instructions for executing the steps of the process (S31, S32) according to any one of claims 1 to 3, when said program is executed by a processor of a connection management module (100) of a communication network (1). Information storage medium comprising a computer program product according to the preceding claim.
Citation Information
Patent Citations
Methods, devices and systems for dynamic network access administration
WO2015116593A1
Mac address-bound WLAN password
WO2017165043A1