Method and monitoring system for monitoring access to software in a control system
The monitoring method and system with tamper-resistant elements address the challenge of unauthorized access in control systems by ensuring immediate detection and tracking of intrusions, enhancing cybersecurity in industrial facilities.
Patent Information
- Application Number
- JP2025502421
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-07-20
- Publication Date
- 2025-08-05
AI Technical Summary
Existing methods for controlling access to software in control systems of industrial facilities are inadequate, allowing unauthorized physical access and making it difficult to detect and trace intrusions, which can lead to catastrophic outcomes.
A monitoring method and system that utilizes tamper-resistant elements with unique identification codes placed at strategic locations on hardware components and cabinets, ensuring intrusion damages these elements, allowing for real-time detection and tracking of unauthorized access.
Enables immediate detection of unauthorized access attempts, provides a timeline of intrusions, and ensures software integrity throughout the control system's lifecycle, facilitating rapid response to cybersecurity incidents.
Smart Images

Figure 2025525552000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention is a means for preventing undetected physical intrusion into a control system.The present invention relates to a method for monitoring access to software in a control system of an industrial facility. [Background technology]
[0002] In sensitive facilities such as nuclear power plants, access to software elements implemented in control systems must be controlled. Cyber-attacks carried out using malware introduced into software elements can potentially cause catastrophic outages within the facility and must be prevented.
[0003] One possibility for controlling access to software elements is to allow physical access only to duly authorized personnel. However, even with very strict procedures, there always remains the possibility that unauthorized personnel gain physical access to the room housing the hardware components and modify the software elements without being noticed.
[0004] When an intrusion is detected, it can then be very difficult to understand how the software elements were accessed and what was done with them. Summary of the Invention
[0005] The invention therefore proposes a method that allows better monitoring of access to the software of control systems of industrial installations.
[0006] The method also provides information to guide analysis for the purpose of developing a relevant plan of action in the event of an intrusion.
[0007] According to a first aspect, the present invention provides a method for monitoring access to software in a control system of an industrial installation, the control system comprising at least one cabinet storing hardware components containing software components or providing access to software components, the monitoring method comprising: - determining multiple physical intrusion paths for the software components for which monitoring is desired; - providing tamper-resistant elements at respective defined marking locations on the hardware components and / or cabinets, wherein each tamper-resistant element has a unique identification code and the marking locations are selected such that intrusion via one of the physical intrusion paths will damage at least one of the tamper-resistant elements; - storing in a database a reference state comprising a unique identification code of the tamper-resistant element and a corresponding marking location; - during the monitoring phase, checking at least some of the marking locations and comparing them with a reference state; The present invention relates to a monitoring method including:
[0008] The marking locations are appropriately positioned because they are determined based on a thorough analysis of physical intrusion paths into the software component, which are impossible to intrude into without removing or damaging one of the tamper-resistant elements.
[0009] A damaged tamper-resistant element is immediately visible to the operator, for example, by the appearance of a "Framatome Open" message on the tamper-resistant element.
[0010] The absence of a tamper-resistant element is detectable when compared to a reference state. Every tamper-resistant element has a unique identification code, and all identification codes are recorded in a database.
[0011] If an intruder replaces the original tamper-resistant element with another tamper-resistant element carrying a different identification code, this substitution will be easily detected when compared to the reference state.
[0012] The method is applicable throughout the lifecycle of a control system, from the manufacture of the cabinets that house the hardware components to commissioning the control system and thereafter for the operational life of the control system.
[0013] Furthermore, the method allows control system manufacturers to verify the integrity of software components, including during industrial operation when delivering control systems to customers.
[0014] In the event of an intrusion, the method of the present invention helps understand how an intruder penetrated a software component and the timeline of the intrusion.
[0015] The method may have one or more of the following features: - during the monitoring phase, the step of checking at least some of the marking locations comprises: * checking the physical integrity of the tamper-resistant element disposed at said marking location; * checking whether the identification code of the tamper-resistant element arranged at said marking location corresponds to that in a reference state; * Checking whether tamper-resistant elements are missing compared to a reference state; involving one or more of the following actions; - during the monitoring phase, the step of checking at least some of the marking locations comprises: * the act of providing a new tamper-resistant element at a given marking location; * Update the reference state in the database; accompanied by - the or each cabinet comprises an outer body and at least one door assembled to the outer body and allowing access to some of the hardware components, one of the tamper-resistant elements bridging the outer body and the door; - The or each cabinet contains a chassis, the hardware components are removably assembled to the chassis, and the tamper-resistant elements at the marking locations are: * Bridging two hardware components; * Bridging one of the hardware components with the chassis; * Closing at least one port on one of the hardware components; * bridging a hardware component having a port with a connector inserted inside said port; Being arranged; - The electronic reading device: * Reading the identification code of the tamper-resistant element; * providing a marking location associated with an identification code in a reference state; * recording, in a reference state, the identification code of the tamper-resistant element associated with a given marking location; The method is configured to perform at least one of the following operations: - the method comprises the steps of dividing a control system into a plurality of areas and each area into a plurality of sub-areas, each area comprising at least one cabinet, each sub-area comprising a marking location accessible through a given door of a given cabinet, wherein the electronic reader is configured to: * reading the identification codes of all tamper-resistant elements located within the sub-area; * Compare with a reference state and indicate the absence of a tamper-resistant element; be configured to implement; - The monitoring phase * The storage period at the manufacturing site where at least one cabinet was manufactured; * A delivery period during which at least one cabinet is transported from the manufacturing site to the industrial facility; * Duration of storage in the industrial facility before installation in the industrial facility; * Installation period during which at least one cabinet is installed in an industrial facility; * A period of operation during which at least one cabinet is in operation; Covering one or more periods of; - In the reference state, each marking location is recorded as being in use or out of use, and only marking locations recorded as being in use are checked in the monitoring phase.
[0016] According to a second aspect, the present invention provides a monitoring system for monitoring access to software of a control system of an industrial installation, the control system comprising at least one cabinet housing hardware components containing software components or providing access to software components, the monitoring system comprising: - A database for recording the marking locations on hardware components and / or cabinets; - tamper-resistant elements each disposed in one of the marking locations, each tamper-resistant element having a unique identification code; Including, the marking locations are selected such that intrusion into the software component via one of a plurality of physical intrusion paths will damage at least one of the tamper-resistant elements; a database storing a reference state including a unique identification code of the tamper-resistant element and a corresponding marking location; Regarding surveillance systems.
[0017] The monitoring system may have one or more of the following features: - The monitoring system: * Reading the identification code of the tamper-resistant element; * providing a marking location associated with an identification code in a reference state; * recording, in a reference state, the identification code of the tamper-resistant element associated with a given marking location; The electronic reader is configured to perform at least one of the following operations: - the or each cabinet comprises an outer body and at least one door assembled to said outer body allowing access to some of the hardware components, the control system being divided into a plurality of areas and each area into a plurality of sub-areas, each area comprising at least one cabinet, each sub-area comprising a marking location accessible through a given door of a given cabinet, and the electronic reader being configured to: * reading the identification codes of all tamper-resistant elements located within the sub-area; * Compare with the reference state and indicate if any tamper-resistant elements are missing; The method is configured to perform the following steps. - When a check of a given area / sub-area is carried out, the monitoring system: * all operations performed at any given marking location, including the steps of checking said marking location and comparing it with a reference state, removing a tamper-resistant element bound to said marking location and placing a new tamper-resistant element at said marking location; * Areas, sub-areas, cabinets, tamper-resistant elements associated with said given marking locations; * an indication of whether the given marking location is non-compliant, the given marking location being considered non-compliant if the associated tamper-resistant element is missing or damaged or if the identification code of the tamper-resistant element at the marking location does not correspond to the identification code recorded in the reference state; * The date and time when each action is performed; * ID of the operator who performed each action; It is programmed to record this information. - Monitoring system * To extract data from databases; * To extract reference conditions from the database; * To generate a detailed report containing all the information recorded during a given check; * To generate a synthesis of the control system with a detailed report of all the locations of at least one non-conforming marking; is programmed to. - In the reference state, each marking location is recorded as either in use or inactive.
[0018] Other features and advantages of the invention will become apparent from the following detailed description of embodiments thereof, given by way of non-limiting example with reference to the following figures: [Brief explanation of the drawings]
[0019] [Figure 1] 1 is a diagram of a portion of a control system to be monitored; [Figure 2] 1 shows an intact tamper-resistant element. [Figure 3] 1 shows a damaged tamper-resistant element. [Figure 4] 2 illustrates a plurality of tamper-resistant elements disposed at marking locations on one of the cabinets shown in FIG. 1; [Figure 5] 1 is a schematic diagram of a monitoring system of the present invention; DETAILED DESCRIPTION OF THE INVENTION
[0020] The method described below is for monitoring access to software in control systems of industrial facilities.
[0021] The industrial facility may be, for example, a nuclear facility such as a nuclear reactor, a nuclear fuel production plant, or a nuclear fuel reprocessing plant.
[0022] The facility may alternatively be a non-nuclear facility where the infiltration of its control systems could lead to potential danger to humans, the environment, or be detrimental to the economic interests of the facility's owner. The facility may belong to the chemical, agrochemical, pharmaceutical, petrochemical, or other industries.
[0023] A control system is a system in an industrial facility that controls the operation of process equipment or safety equipment or any other equipment that is critical to the safe operation of the industrial facility.
[0024] In a nuclear reactor, the method is particularly adapted for monitoring access to the software of the control system that controls the operation of the reactor core, said control system controlling at least the control rods that are driven into the core to regulate the reactivity of the nuclear fuel and to shut down the reactor in an emergency.
[0025] 1, the control system 1 includes at least one cabinet 3 that stores hardware components 5. The hardware components 5 include or provide access to software components.
[0026] In industries involving critical processes, control systems include multiple control subsystems that are redundant and independent of each other and located in separate electrical rooms.
[0027] Each system 1 or subsystem typically includes multiple cabinets 3 as shown in Figure 1. The cabinets 3 may be located in the same room or housed in different rooms.
[0028] The hardware components 5 are: - a component containing a memory into which the software program is loaded, such as a central unit or an EPROM (erasable programmable read-only memory); - Components containing integrated circuits such as ASICs (Application Specific Integrated Circuits); - a component with a communication port 7 (Fig. 4) or connector that provides access to the software component; - Computer; etc.
[0029] Each cabinet 3 includes an outer body 9 and at least one door 11 assembled to the outer body 9 to allow access to some of the hardware components 5 .
[0030] The outer body 9 and the at least one door 11 completely enclose the hardware component 5. In other words, the hardware component 5 is only accessible when the door 11 is open.
[0031] The door 11 is for example a front door hinged to the outer body 9 .
[0032] The door 11 may alternatively be a side or rear panel that is hinged or removably assembled to the outer body 9 .
[0033] Each cabinet 3 includes a single door 11 or alternatively includes multiple doors 11 each providing access to multiple hardware components 5 .
[0034] 4, the cabinet 3 includes a chassis 12 disposed inside the outer body 9. The hardware components 5 are removably assembled to the chassis 12.
[0035] In the illustrated example, the chassis 12 includes a plurality of racks 13. The hardware components 5 are distributed 7 across the plurality of racks 13.
[0036] Cabinet 3 houses hardware components 5 that contain or provide access to software components, as well as other hardware components 14 that do not contain or provide access to software components.
[0037] The control system 1 further includes a cabinet 3 that houses a test device 15. The cabinet 3 is mobile because the test device 15 is configured to test all the subsystems and must be transported between multiple rooms.
[0038] Test device 15 includes a computer 17. The test device has a front door (not shown) for accessing the screen 19 and keyboard 21 of computer 17, and a rear door (not shown) for accessing the connectors of computer 17.
[0039] The purpose of the monitoring method is to detect physical intrusions into the software components of the control system 1 .
[0040] Physical intrusion can be, for example: - an intruder gains access to the hardware component 5 and modifies or replaces a software component contained within the hardware component 5; - an intruder gains access to the hardware component 5 and replaces the original hardware component 5 with another hardware component that contains a software component with malware; An intruder gains access to a communication port 7 or connector of a piece of hardware 5 and modifies or replaces a software component contained within another piece of hardware 5.
[0041] The monitoring method includes a first step of determining multiple physical access points to a software component for which monitoring is desired.
[0042] This stage is usually referred to as the engineering stage.
[0043] Said steps are typically carried out during the design of the control system 1 before the control system is manufactured.
[0044] A physical entry point is a path by which an intruder can gain physical access to a hardware component that stores a software component or to a communication port or connector that provides access to a software component. A physical entry point includes a list of actions that an intruder must perform, taking into account the physical design of cabinet 3, in order to gain access to a hardware component, communication port or connector.
[0045] The first stage further comprises a step of defining marking locations on the hardware components 5 and / or cabinets 3 where the tamper-resistant elements 23 are to be placed. The marking locations are selected such that an intrusion through one of said physical intrusion paths will result in damage to at least one of the tamper-resistant elements 23.
[0046] The first stage advantageously comprises dividing the control system 1 into areas and each area into sub-areas, each area comprising at least one cabinet 3 .
[0047] Advantageously, each sub-area comprises a marking location accessible through a given door 11 of a given cabinet 3 .
[0048] Thus, each marking location belongs to an identified sub-area, and each sub-area belongs to an identified area.
[0049] The first stage also includes creating a database 35 containing all marking locations together with the corresponding sub-areas to which they belong and the corresponding areas to which the sub-areas belong.
[0050] As shown in FIG. 5, the database 35 is stored in a central server 37 .
[0051] The central server 37 is located, for example, in an engineering center 39 where the first stage takes place. Alternatively, the central server 37 is located in an industrial facility 41.
[0052] The monitoring method further comprises the step of providing tamper-resistant elements 23 at each predetermined defined marking location on the hardware component 5 and / or cabinet 3 .
[0053] Each tamper-resistant element 23 has a unique identification code, which is typically an alphanumeric sequence.
[0054] An example of a tamper-resistant element 23 is shown in FIG.
[0055] The tamper-resistant element is embedded within a label that is printed on paper or plastic.
[0056] The tamper-resistant element carries a unique identification code 25 on its visible surface.
[0057] This tamper-resistant element carries a QR code 27 that encodes a unique identification code.
[0058] This tamper-resistant element carries a hologram 29 that makes the element tamper-resistant. The element cannot be reproduced in a color printer.
[0059] The name of the company that manufactures the control system may also be displayed.
[0060] The tamper-resistant element 23 is affixed onto the hardware component 5 and / or to the cabinet 3. When the tamper-resistant element 23 is removed from the surface to which it is affixed, the bottom layer of the tamper-resistant element 23 degrades and the inscription appears.
[0061] After removal, the tamper-resistant element 23 has the appearance shown in Figure 3. Because the bottom layer is missing, the lettering 31 appears through the visible surface of the tamper-resistant element 23.
[0062] In the example shown, the words "XXXXXXXXXX" appear on the visible surface.
[0063] This makes it possible to detect if the tamper-resistant element has been removed from the marking location where it was originally placed.
[0064] The tamper-resistant element 23 is initially disposed at the marking location after the completion of the manufacture of the corresponding cabinet 3. The corresponding cabinet 3 is the cabinet in which the tamper-resistant element 23 is disposed or the cabinet that houses the hardware component 5 in which the tamper-resistant element 23 is disposed.
[0065] These are preferably installed in the facility where the cabinet 3 is manufactured, prior to shipping the cabinet 3 to the industrial facility.
[0066] Typically, for each cabinet 3, one of the tamper-resistant elements 23 bridges the outer body 9 and the door 11 (as shown diagrammatically in Figure 1), which is called the door tamper-resistant element and the corresponding marking location is called the door marking location.
[0067] More precisely, if the cabinet 3 includes several doors 11 , one tamper-resistant element 23 bridges the outer body 9 with each door 11 .
[0068] By bridge, we mean that one part of the tamper-resistant element 23 is secured to the outer body 9 and another part is secured to the door 11. To open the door 11 and gain access to the hardware components inside the cabinet 3, an intruder must remove the tamper-resistant element from either the door or the outer body 9.
[0069] Inside the cabinet 3, the tamper-resistant element 23 at the marking location is, as shown in FIG. - bridging two hardware components5; - bridging one hardware component 5 with one hardware component 14; - bridging one hardware component 5 with the chassis 12; - closing at least one port 7 of one of the hardware components 5; It is arranged.
[0070] Here, bridge has the same meaning as above.
[0071] If an intruder wishes to remove a hardware component 5 from the chassis 12, he must remove at least one tamper-resistant element 23 from said hardware component 5, or from an adjacent hardware component 5, 14, or from the chassis 12.
[0072] If an intruder wishes to access the communication port 7, he must first at least partially remove the tamper-resistant element 23.
[0073] If the marking location corresponds to a communication port to which the connector is engaged (a case not shown in the figure), the tamper-resistant element 23 is arranged to bridge the connector with the hardware component 5 in which the communication port is arranged.
[0074] If an intruder wishes to remove the connector from the communication port in order to gain access to the communication port or connector, he or she must remove the tamper-resistant element 23 from either the connector or the hardware component 5 .
[0075] The monitoring method further comprises the step of storing in a database the reference state, including the unique identification codes and corresponding marking locations of all tamper-resistant elements 23 placed in the cabinet.
[0076] This action is carried out by the operator when the tamper-resistant element 23 is placed at the corresponding marking location.
[0077] The baseline state is recorded immediately after the tamper-resistant element is first placed in the marking location, and is later updated if the tamper-resistant element is removed or replaced.
[0078] This operation is advantageously carried out using an electronic reading device 33, which will be further explained below.
[0079] The electronic reading device 33 is a mobile electronic device, typically a pad or a mobile phone or a mobile computer or the like.
[0080] The operator will perform at least the following actions: - reading the identification code of the tamper-resistant element 23; - recording the identification code of the tamper-resistant element 23 and the associated marking location in the reference state;
[0081] The above operations are repeated for all tamper-resistant elements 23 .
[0082] Reading is performed by scanning the QR code (registered trademark) with an electronic reader 33, or by recognizing an identification code written on the visible surface of the tamper-resistant element 23, or by manually entering the identification code using a keyboard, or by any other means.
[0083] The recording is done automatically by transferring the data to a central server 37 and implementing routines specially designed for said recording.
[0084] After recording, baseline conditions include: - List of areas of control system 1; - for each area, a list of subareas belonging to that area; - for each subarea, a list of marking locations belonging to that subarea; - for each marking location, the identification code of the corresponding tamper-resistant element 23;
[0085] Furthermore, in the reference state, each marking location is recorded as either in use or out of use. The state of each marking location (in use or out of use) is initially selected by, for example, a database administrator, who is usually in charge of cybersecurity at industrial facilities. This can be updated later by an operator reading the identification code for the reference state. This makes it possible to configure the reference state when gradually operating the control system on site.
[0086] A marking location is recorded as dormant, for example, if it is deployed on a non-existent hardware component 5, or if no software component is loaded on the hardware component.
[0087] Marking locations recorded as resting do not carry a tamper-resistant element 23 and do not belong to the reference state.
[0088] The monitoring method further includes a monitoring step which involves checking and comparing at least some of the marking locations to a reference condition.
[0089] The check is carried out by the operator, advantageously using an electronic reading device 33 .
[0090] The check is repeated periodically.
[0091] The monitoring phase covers one or more of the following periods: - the storage period at the manufacturing site where at least one cabinet 3 was manufactured; - a delivery period during which at least one cabinet 3 is transported from the manufacturing site to the industrial facility; - Storage period in industrial facilities before setup and operation in industrial facilities; - a setup period during which at least one cabinet 3 is set up in the industrial installation; - An operational period during which at least one cabinet 3 is in operation.
[0092] Preferably, the monitoring step covers all of the above-mentioned periods.
[0093] The step of checking at least some of the marking locations involves one or more of the following actions: - checking the physical integrity of the tamper-resistant element 23 arranged at the marking location; - checking whether the identification code of the tamper-resistant element 23 arranged at the marking location corresponds to that of the reference state; - checking whether the tamper-resistant element 23 is missing compared to a reference state.
[0094] Only marking locations that are recorded as in use are checked during the monitoring phase.
[0095] If the tamper-resistant element 23 is damaged or missing, or if the identification code of the tamper-resistant element 23 does not correspond to the identification code recorded in the reference state, the marking location and the corresponding tamper-resistant element are deemed "non-compliant." A cybersecurity event is declared and recorded by the operator. At least the following information is recorded: the marking location of the non-compliant tamper-resistant element 23, the type of non-compliance, and the identification code of the non-compliant tamper-resistant element 23.
[0096] The checks are carried out by an operator with the assistance of a monitoring system. The monitoring system is a traceability tool. The electronic reader 33 is part of the traceability tool. The monitoring system is described below.
[0097] More precisely, during the check operation, the operator first checks the integrity of the door tamper-resistant element 23 of the sub-area or sub-areas.
[0098] If the door tamper-resistant element 23 of a sub-area is "non-compliant", the integrity of all tamper-resistant elements 23 installed in the sub-area accessible through the door must be checked.
[0099] As a reminder, non-compliant tamper-resistant elements 23 are: · Missing; · Damaged; - replaced by another tamper-resistant element 23 (mismatch of the identification code relative to the reference state); There is a possibility.
[0100] The step of checking the integrity of all tamper-resistant elements 23 installed in a sub-area involves the following initial actions: · Using traceability tools to record the marking locations where non-compliant door tamper-resistant elements 23 were detected; scanning and recording the identification code of the non-compliant door tamper-resistant element 23 using an electronic reader 33, if the door tamper-resistant element 23 is still present; · Recording the type of non-conformance using the drop-down menu in the traceability tool; · Declaring and recording cybersecurity incidents with authorities; Providing information on the declared event file number within the traceability tool.
[0101] Next, all tamper-resistant elements 23 present in the sub-area are checked. If the operator forgets to check a marking location, the traceability tool notifies the operator about the oversight. The operator checks the forgotten tamper-resistant elements 23. The information listed above is recorded for all non-compliant marking locations.
[0102] At the end of the check, all marking locations declared non-compliant are secured.
[0103] A new tamper-resistant element 23 is installed in the non-compliant marking location and the database is updated with the identification code of the new tamper-resistant element 23 .
[0104] To do this, the operator: · Specify the marking location on the traceability tool; Place the new tamper-resistant element 23 in the designated marking location; Scan the identification code of the new tamper-resistant element 23 with an electronic reader 33.
[0105] In other words, during the monitoring phase, the step of checking at least some of the marking locations involves the following actions; - the act of removing the tamper-resistant element 23 at a given marking location; - updating the reference state in the database 35;
[0106] The tamper-resistant element 23 is removed because it is damaged or requires physical intervention on the corresponding hardware component 5 .
[0107] During the monitoring phase, the step of checking at least some of the marking locations also involves the following actions: - providing a new tamper-resistant element 23 at a given marking location; - updating the reference state in the database 35;
[0108] For example, a new tamper-resistant element 23 is provided when the marking location is moved from a rest state to a use state, or when replacing a damaged tamper-resistant element 23 .
[0109] After each check, the traceability tool generates a control report, which contains the following elements: - Name of the control system checked during the check operation; - Check summary status: OK or NOK - Check start date and time, check end time - Name of the operator who performed the check - For all marked locations checked: Marking location ID Identification code of the tamper-resistant element present at the marking location - If a non-conformity is detected: Marking locations detected as non-conforming 〇 Reason for nonconformity Identification code of non-compliant tamper-resistant elements o Identification code of new tamper-resistant elements placed to secure the location.
[0110] The management report includes, for each marking location within the sub-area, comments on the status of the marking location and / or the tamper-resistant element 23 arranged at said marking location.
[0111] The check is OK if all marking locations are identical to the situation recorded in the reference state. It is not OK if at least one marking location is not identical to the situation recorded in the reference state.
[0112] The situation at a given marking location will not be the same if the tamper-resistant element is missing, damaged, or has an identification code that differs from the identification code recorded in the reference state.
[0113] The comments for each marking location indicate the condition at the marking location compared to the reference condition.
[0114] The comments can indicate that a new tamper-resistant element has been installed but not mentioned in the reference state, or that an existing tamper-resistant element has been removed.
[0115] The comment indicates whether the marking location is idle.
[0116] A traceability tool allows a history of the control system 1 to be published periodically.
[0117] The history is a chronological list of the following events: - Installation or removal of tamper-resistant elements at the marking locations; - all actions performed by the operator during the check; - Problems detected: missing, damaged or non-compliant tamper-resistant elements; - The status of the marking location shifted between in use and idle.
[0118] The monitoring system 43 will now be described.
[0119] The monitoring system is a traceability tool.
[0120] The monitoring system 43 is for monitoring access to the software of the control system 1 for industrial equipment.
[0121] The control system 1 includes at least one cabinet 3 that stores hardware components 5 that contain and provide access to software components.
[0122] The control system 1 is as described above.
[0123] The monitoring system 43 is specially designed to implement the monitoring methods described above. Conversely, the monitoring methods described above are specially adapted to be performed using the monitoring system 43.
[0124] The monitoring system 43 includes: - a database 35 recording the marking locations of the hardware components 5 and / or cabinets 3; - each tamper-resistant element 23, each disposed in one of the marking locations and each having a unique identification code;
[0125] The marking locations are selected such that intrusion into the software component via multiple physical intrusion paths will result in damage to at least one of the tamper-resistant elements 23 .
[0126] The tamper-resistant element 23 is as described above.
[0127] The marking locations are as described above.
[0128] The database 35 stores the reference conditions including the unique identification codes of the tamper-resistant elements 23 and the corresponding marking locations.
[0129] In the baseline state, each marking location is recorded as either in use or inactive.
[0130] The database 35 is as described above.
[0131] The monitoring system 43: - reading the identification code of the tamper-resistant element 23; - providing a marking location associated with an identification code in a reference state; - recording in a reference form the identification code of the tamper-resistant element 23 associated with a given marking location; The electronic reader 33 is configured to perform at least one of the following operations:
[0132] The electronic reading device 33 is also configured to perform the following operations: - reading the identification code of the tamper-resistant element 23 removed from a given marking location; - updating the reference state in the database 35 with an indication that the tamper-resistant element 23 has been removed and that no tamper-resistant element is disposed within the marking location.
[0133] The electronic reading device 33 is further configured to perform the following operations: - reading the identification code of the new tamper-resistant element 23 provided at a given marking location; - updating the reference state in the database 35 by linking said identification code with the marking location.
[0134] The electronic reading device 33 is further configured to perform the following operations: - reading the identification codes of all tamper-resistant elements 23 located within the sub-area; - comparing with a reference state and indicating whether the tamper-resistant element 23 is missing.
[0135] The monitoring system 43 typically includes multiple electronic readers 33, thus allowing multiple operations to occur simultaneously within the facility.
[0136] As noted above, each electronic reading device 33 is a mobile electronic device, typically a pad, or a mobile phone or a mobile computer or the like.
[0137] The electronic reading device 33 communicates via Wifi or any other suitable means with a server 45 located within the industrial facility 41. The server 45 communicates via Wifi or any other suitable means with a central server 37 hosting the database 35.
[0138] When an operator has to perform an action using the electronic reading device 33, the cybersecurity officer of the industrial facility first authorizes the operator to carry out a check within one or more defined areas / sub-areas.
[0139] Each sub-area has an identification code painted on a label fixed near the sub-area.
[0140] If a sub-area corresponds to a marking location that is accessible through a given door 11 of a given cabinet 3, said identification code is arranged on the door 11.
[0141] The electronic reader 33 provides the operator with several routines: - "Area" routine, - "Deploy tamper-resistant element" routine, - "Removal of tamper-resistant elements" routine, - "Check" routine.
[0142] If the operator selects the "Areas" routine, the electronic reader 33 provides the operator with a tree of areas of the control system 1.
[0143] The operator must first select a given area and check if he is authorized to operate within the selected area.
[0144] To do this, the operator uses the electronic reader 33 to read the identification code of the sub-area, for example on the door 11, which indicates whether the operator is authorized to perform an action in the sub-area.
[0145] The operator can then read on the electronic reading device the tree associated with the sub-areas and the marking locations of each sub-area. For each marking location, the electronic reading device 33 provides the identification code of the tamper-resistant element 23 arranged at said marking location, if any, and the status of the marking location (in use, at rest).
[0146] If the operator selects the "Deploy tamper-resistant element" routine, the electronic reading device 33 provides the operator with a tree of areas of the control system 1.
[0147] The operator selects a given area and checks that he is authorized to operate within the selected area in the same manner as in the "Area" routine.
[0148] The electronic reading device 33 then displays a tree of subareas and a list of marking locations belonging to each subarea.
[0149] For each marking location, the operator can activate a button to read the identification code of the tamper-resistant element 23 disposed at the marking location. The reading can be performed before or after the tamper-resistant element is disposed at the marking location.
[0150] The electronic reader 33 then scans the QR code on the tamper-resistant element 23 and writes the code into a database.
[0151] For each marking location, the operator can also activate a button to change the state of the marking area between in use and inactive.
[0152] The operator may, for example, shift the state to dormant if the marking location is left without a tamper-resistant element.
[0153] If the operator selects the "Remove tamper-resistant element" routine, the electronic reading device 33 provides the operator with a tree of areas of the control system 1.
[0154] The operator selects a given area and checks that he is authorized to operate within the selected area in the same manner as in the "Area" routine.
[0155] The electronic reading device 33 then displays a tree of sub-areas and a list of marking locations belonging to the sub-areas.
[0156] For each marking location, the operator can activate a button to read the identification code of the tamper-resistant element 23 to be removed.
[0157] The electronic reader 33 then scans the QR code on the tamper-resistant element 23 and displays the code for the operator to check.
[0158] If the information regarding the tamper-resistant element is correct, the operator confirms that the tamper-resistant element 23 is to be removed, and the electronic reading device 33 updates the database by writing that the tamper-resistant element 23 has been removed and that the marking location no longer has the tamper-resistant element 23.
[0159] The operator can also activate a button at each marking location to declare a non-conformity. The electronic reader 33 then displays on a new screen a list of anomalies such as missing, damaged or peeled tamper-resistant elements 23, or mismatches between the identification code and the reference condition.
[0160] The operator must then indicate whether the tamper-resistant element is readable. If the tamper-resistant element is readable, the electronic reading device 33 displays a new screen for reading the identification code of the tamper-resistant element. If the tamper-resistant element is not readable, the electronic reading device 33 asks the operator to manually indicate the marking location associated with the tamper-resistant element 23.
[0161] If the operator selects the "Check" routine, the electronic reader 33 provides the operator with a tree of areas of the control system 1.
[0162] The operator selects a given area and checks that he is authorized to work within the selected area in the same manner as in the "Area" routine.
[0163] The electronic reader 33 then displays a screen with two possibilities: sub-area unitary check or sub-area serial check.
[0164] If a unitary check is selected, a list of subareas is displayed. The operator selects a subarea and the electronic reader 33 displays a new screen for reading the identification code of the tamper-resistant element 23 arranged on the door 11 that allows access to said subarea. The electronic reader then displays whether the read identification code corresponds to the identification code recorded in the reference state.
[0165] Before reading the identification code, the operator checks the integrity of the tamper-resistant element 23 and declares it non-compliant if the tamper-resistant element 23 is damaged or missing. The operator therefore proceeds as described above.
[0166] Once one sub-area is finished, the operator selects another sub-area and continues until all sub-areas have been checked.
[0167] If serial check is selected, the electronic reader 33 displays a new screen for reading the identification code. The operator reads the tamper-resistant element 23 located on the door 11 that allows access to all sub-areas in succession. The electronic reader indicates whether the read identification code corresponds to the identification code recorded in the reference state.
[0168] The operator checks the integrity of the tamper-resistant element 23 before the serial check and, if necessary, declares it non-compliant.
[0169] If the tamper-resistant elements 23 arranged on the doors 11 providing access to all sub-areas are OK (no abnormalities, identification codes are the same as in the reference state), all sub-areas are displayed as OK in the database and the operator presses the "check done" button.
[0170] If the tamper-resistant element 23 arranged in one of the doors 11 is not OK (non-compliant, the identification code is not identical to the reference state), it is necessary to check the marking locations in the sub-area accessible through said door 11. This sub-area is marked as not OK in the database.
[0171] The operator then removes the tamper-resistant element 23 arranged on said door and selects the corresponding sub-area on the screen of the electronic reading device 33 .
[0172] The electronic reading device 33 then displays a list of marking locations that belong to the selected sub-area, with a "check" button associated with each marking location.
[0173] The electronic reader 33 also displays a "Serial Check" button.
[0174] The check can be unitary.
[0175] The operator presses the "check" button associated with one of the marking locations and the electronic reader 33 displays a new screen for reading the identification code of the tamper-resistant element 23 located at this marking location. The electronic reader then displays whether the read identification code corresponds to the identification code recorded in the reference state.
[0176] Before reading the identification code, the operator checks the integrity of the tamper-resistant element 23 and declares it non-compliant if the tamper-resistant element 23 is damaged or missing. The operator therefore proceeds as described above.
[0177] When one marking location is finished, the operator presses the "check" button associated with another marking location and continues until all marking locations have been checked.
[0178] If the "Serial Check" button is selected, the electronic reader 33 displays a new screen for reading the identification code. The operator reads the tamper-resistant elements 23 disposed at all marking locations one after the other. The electronic reader displays whether the read identification code corresponds to the identification code recorded in the reference state.
[0179] The electronic reader further indicates whether a check is missing within a sub-area compared to the checks listed in the reference state. The operator examines the missing check and reports a non-conformance if the tamper-resistant element 23 is damaged or missing.
[0180] The operator checks the integrity of the tamper-resistant element 23 before the serial check.
[0181] Once all marking locations in the sub-areas marked "not OK" have been checked, the operator presses the "Done Checking" button.
[0182] The central cybersecurity officer has access to the database of all industrial facilities related to all control systems of each industrial facility. The central cybersecurity officer has access to all management reports and history of all control systems.
[0183] Having access to all this information is crucial when central cybersecurity personnel need to analyze intrusions and decide on post-intrusion actions.
[0184] Local security personnel and operators of a given industrial facility may only have access to information relating to the control systems of said given industrial site.
[0185] Unauthorized duplication of the tamper-resistant elements is made more difficult by the design of the tamper-resistant elements and by Framatome's direct business relationships with tamper-resistant element manufacturers. Only Framatome can order specially designed tamper-resistant elements for use within Framatome's industrial facilities. [Explanation of symbols]
[0186] 1. Control System 3 Cabinet 5. Hardware Components 23 Tamper-resistant elements 35 databases
Claims
1. A method for monitoring access to software in a control system (1) of an industrial facility, the control system (1) including at least one cabinet (3) housing hardware components (5) that contain or provide access to software components, the monitoring method comprising: determining multiple physical access points for software components for which monitoring is desired; - providing tamper-resistant elements (23) at respective defined marking locations on the hardware components (5) and / or on the cabinet (3), the marking locations being selected such that each tamper-resistant element (23) has a unique identification code and that an intrusion via one of said physical intrusion paths will damage at least one of the tamper-resistant elements (23); - storing in a database (35) a reference state comprising the unique identification code of the tamper-resistant element (23) and the corresponding marking location; - during a monitoring phase, checking at least some of the marking locations and comparing them with a reference state; Monitoring methods including:
2. During the monitoring phase, the step of checking at least some of the marking locations comprises: - checking the physical integrity of the tamper-resistant element (23) placed at said marking location; - checking whether the identification code of the tamper-resistant element (23) placed at said marking location corresponds to the identification code of the reference state; - checking whether the tamper-resistant element (23) is missing compared to a reference state; The method of claim 1 , comprising one or more of the following actions:
3. During the monitoring phase, the step of checking at least some of the marking locations comprises: - the act of providing a new tamper-resistant element (23) at a given marking location, - updating the reference state in the database; The method according to claim 1 or 2, wherein
4. 4. The method according to any one of claims 1 to 3, wherein the or each cabinet (3) comprises an outer body (9) and at least one door (11) assembled to the outer body (9) and allowing access to some of the hardware components (5), and one of the tamper-resistant elements (23) bridges the outer body (9) and the door (11).
5. The or each cabinet (3) comprises a chassis (12), the hardware components (5) are removably assembled to the chassis (12), and the tamper-resistant elements (23) at the marking locations are - bridging two hardware components (5, 14) - bridging one of the hardware components (5) with the chassis (12), - closing at least one port (7) of one of the hardware components (5), - bridging a hardware component (5) having a port (7) with a connector inserted inside said port (7), 5. The method according to claim 1, wherein the method is performed in a manner similar to that described above.
6. An electronic reading device (33) - reading the identification code of the tamper-resistant element (23), - providing, in a reference state, a marking location associated with an identification code; - recording, in a reference state, the identification code of the tamper-resistant element (23) associated with a given marking location; The method according to any one of claims 1 to 5, configured to perform at least one of the following actions:
7. The method includes dividing the control system (1) into a plurality of areas and each area into a plurality of sub-areas, each area including at least one cabinet (3), each sub-area including a marking location accessible through a given door (11) of a given cabinet (3), and an electronic reader (33) for: - reading the identification codes of all the tamper-resistant elements (23) located within the sub-area; - comparing with a reference state and indicating the absence of the tamper-resistant element (23); The method according to claim 4 when dependent on claim 6, wherein the method is configured to perform the following:
8. The monitoring stage is - the storage period at the manufacturing site where at least one cabinet (3) was manufactured, a delivery period during which at least one cabinet (3) is transported from the manufacturing site to the industrial facility; - the period of storage at the industrial facility before installation in the industrial facility; - during the installation period, when at least one cabinet (3) is installed in an industrial installation; - an operational period during which at least one cabinet (3) is in operation, 8. The method of claim 1, wherein the method covers one or more of the following periods:
9. 9. A method according to claim 1, wherein in the reference state each marking location is recorded as being in use or out of use, and only marking locations recorded as being in use are checked in the monitoring step.
10. A monitoring system (43) for monitoring access to software of a control system (1) of an industrial facility (41), wherein the control system (1) includes at least one cabinet (3) that stores hardware components (5) that include or provide access to software components, and the monitoring system (43) a database (35) for recording the marking locations on the hardware components (5) and / or cabinets (3); - tamper-resistant elements (23) each disposed in one of the marking locations, each tamper-resistant element (23) having a unique identification code; Including, the marking locations are selected such that intrusion into the software component via one of a plurality of physical intrusion paths will damage at least one of the tamper-resistant elements (23); a database (35) for storing reference states including unique identification codes of the tamper-resistant elements (23) and corresponding marking locations; Monitoring system (43).
11. - reading the identification code of the tamper-resistant element (23), - providing, in a reference state, a marking location associated with an identification code; - recording, in a reference state, the identification code of the tamper-resistant element (23) associated with a given marking location; 11. The monitoring system (43) of claim 10, comprising an electronic reader (33) configured to perform at least one of the following operations:
12. The or each cabinet (3) comprises an outer body (9) and at least one door (11) mounted on said outer body (9) and allowing access to some of the hardware components (5), the control system (1) is divided into a number of areas and each area into a number of sub-areas, each area comprising at least one cabinet (1), each sub-area comprising a marking location accessible through a given door (11) of a given cabinet (3), an electronic reading device (33) - reading the identification codes of all the tamper-resistant elements (23) located within the sub-area; - comparing with a reference state and indicating whether a tamper-resistant element is missing; 12. The monitoring system of claim 11 configured to implement:
13. When a check of a given area / sub-area is performed, the monitoring system: - all operations carried out at any given marking location, including the steps of checking said marking location and comparing it with a reference state, removing the tamper-resistant element (23) bound to said marking location and placing a new tamper-resistant element (23) at said marking location, - the area, sub-area, cabinet (3), tamper-resistant element (23) associated with said given marking location, - an indication of whether said given marking location is non-compliant, said given marking location being considered non-compliant if the associated tamper-resistant element (23) is missing or damaged or if the identification code of the tamper-resistant element (23) at the marking location does not correspond to the identification code recorded in the reference state, - the date and time when each action will be performed; - the ID of the operator who performed each action, 13. The monitoring system of claim 12, programmed to record the following information:
14. - To extract data from the database, - To extract reference conditions from the database, - To generate a detailed report containing all the information recorded during a given check, - to generate a synthesis of the control system with a detailed report of all the locations of at least one non-conforming marking; 14. The monitoring system of claim 13, programmed to:
15. 15. A monitoring system according to any one of claims 10 to 14, wherein in a reference state each marking location is recorded as being in use or inactive.
Citation Information
Patent Citations
Storage cabinet equipped with multiple RFID readers
JP2016507442A
Work support device, work support system, work support method, program, and recording medium
JP2018101306A
Wireless tamper device
JP2019133636A
Direct Data Input for Database for Safety Equipment Items and Method
US20080021905A1
System and method for carrying out an inspection or maintenance operation with compliance tracking using a handheld device
US20100185549A1