Method for generating a digital fingerprint of a connected object and associated device

The method generates a digital fingerprint of connected objects by modeling their environment, addressing security challenges in IoT by enhancing object identification and authentication, thus improving IT security.

WO2025125558A1PCT designated stage expired Publication Date: 2025-06-19ORANGE SA
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/086195
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-15
Filing Date
2024-12-13
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

The rapid deployment of connected objects in the Internet of Things (IoT) introduces challenges in IT security, particularly in detecting 'phantom' connected objects that pose as authentic objects or are replicas, using spoofed identifiers, thereby compromising existing security solutions.

Method used

A method for generating a digital fingerprint of a connected object by obtaining a data model of its physical and/or IT environment, including spatial and functional resources, and using this data model to generate a digital fingerprint that allows identification of the connected object within a telecommunications network.

Benefits of technology

The method enhances security by providing a robust means of identifying and authenticating connected objects, thereby mitigating the risk of phantom objects and improving overall IT security in IoT environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024086195_19062025_PF_FP_ABST
    Figure EP2024086195_19062025_PF_FP_ABST
Patent Text Reader

Abstract

The invention relates to a method for generating a digital fingerprint of a connected object of a telecommunications network, the method comprising: obtaining a data model of a physical and / or computing environment of the connected object; and using the data model to generate a digital fingerprint.
Need to check novelty before this filing date? Find Prior Art

Description

Method for generating a digital fingerprint of a connected object and associated device

[0001] The present invention belongs to the general field of telecommunications. It relates more particularly to a method for generating a digital fingerprint of a connected object, and an electronic device (called a digital fingerprint generation device) configured to implement said method for generating a digital fingerprint.

[0002] It also relates to a method for authenticating a connected object or for verifying the validity of a digital fingerprint of a connected object. It further relates to an electronic device (called an electronic authentication device or a device for verifying the validity of a digital fingerprint) configured to implement said authentication method.

[0003] The present invention also relates to a general method for authenticating a connected object comprising the steps of the method for generating a digital fingerprint of a connected object and the method for verifying the validity of a digital fingerprint, as well as a communication system comprising said electronic device for generating a digital fingerprint, said electronic device for verifying the validity of a digital fingerprint and said connected object.

[0004] The invention finds a particularly advantageous application for applications of the “Internet of Things” type (IoT), in particular in the context of so-called “device-to-device communications” or “D2D communications” or communications between a connected object and its digital twin.

[0005] As is well known, connected objects (sometimes also called "smart objects") are hardware and / or software devices, and are characterized by their ability to interact with their immediate physical environment, generally through a microcontroller to control a sensor and / or an actuator, as well as by their connectivity. These objects are connected to a communication network, such as for example the public Internet network within the framework of the Internet of Things (IoT) and can therefore communicate with other systems to obtain and / or provide information.

[0006] Thus, connected objects can capture and send back to the network the current value of information specific to their environment and / or receive from the network a command whose execution can have an effect on this environment.

[0007] The fields in which these connected objects are used are very varied, and include in particular industry – sometimes called "Industry 4.0" –, for example with the use of connected robots to enable more detailed monitoring of the different stages of production or with the use of predictive maintenance systems; the smart city, for example to monitor and manage a traffic and transport system; security, for example with the use of connected cameras and presence sensors; health, for example with the use of connected medical devices or fall detection devices to combat loss of autonomy; energy, for example with the use of electricity meters communicating with an electricity network manager; or household appliances, for example with the use of connected kitchen robots or dishwashers.

[0008] Connected objects are experiencing rapid growth, with their number worldwide reaching 8.6 billion in 2019, 15.1 billion in 2023, and expected to exceed 29 billion by 2030.

[0009] The rapid and massive deployment of these new technologies in the context of the Internet of Things, however, introduces new challenges in terms of IT security, linked to the heterogeneity of the functionalities offered by these connected objects, the heterogeneity of the protocols they use, the dynamic and decentralized nature of the environments in which they are deployed as well as their coexistence in the same environment.

[0010] In the IoT field, one of the challenges in terms of IT security concerns the detection of so-called "phantom" connected objects, which pretend to be authentic connected objects or are the result of a replication of an authentic object, and which therefore use a usurped identifier. The security of existing solutions would benefit from being improved.

[0011] The present invention aims to remedy all or part of the drawbacks of the prior art, in particular those set out above, by proposing a solution which helps to strengthen the security linked to the identification or authentication of a connected object.

[0012] To this end, and according to a first aspect, the invention relates to a method for generating a digital fingerprint of a connected object of a telecommunications network according to claim 1. Claims 2 to 9 describe preferred embodiments of the generation method according to the invention.

[0013] The method for generating a digital fingerprint of a connected object of a telecommunications network may comprise: obtaining at least one data model of a physical and / or IT environment of the connected object, the data model including spatial resources representative of portions or objects of the physical environment, and / or IT resources of the IT environment accessible by the connected object, spatial relationships and / or functional relationships linking said resources, said connected object itself being represented as an IT resource; and, generating a digital fingerprint from the data model, said digital fingerprint allowing identification of said connected object with an electronic device of said telecommunications network.

[0014] The method for generating a digital fingerprint of a connected object of a telecommunications network can be implemented by an electronic digital fingerprint generation device.

[0015] As discussed in more detail below, the electronic device for generating a digital fingerprint corresponds, for example, to a relay device, such as a home gateway, connected to the connected object for which a fingerprint is generated. This electronic device for generating a digital fingerprint may also correspond to the connected object itself, to another connected object, or to a remote server whose services are, for example, accessible through cloud computing.

[0016] By "spatial resource" we mean a representation of a physical object (eg, "door", "window") of the physical environment of the connected object, or of an identifiable spatial portion of this physical environment, such as a room of a building (eg, "gym", "living room", "pergola").

[0017] For the purposes of the invention, a "spatial relationship" corresponds to a topological relationship between two resources of the data model. "Is part of", "is equal to", "is in", "does not overlap", "partially overlaps", "touches" or "is adjacent to" are examples of spatial relationships.

[0018] "IT resource" means a representation of any electronic device, service or function that can be accessed by the connected object for which a fingerprint is generated. This includes, for example, other connected objects also located in the physical environment of the connected object, or storage or computing resources located on remote servers and therefore not necessarily in the immediate vicinity of the connected object.

[0019] These computing resources are connected to each other through "functional relationships" which correspond to semantic relationships characterizing the network links between these computing resources.

[0020] As discussed in more detail below, at least one property can be associated with at least one resource and / or relationship in this data model.

[0021] Generally speaking, it is considered that the steps of a process should not be interpreted as being linked to a notion of temporal succession.

[0022] In certain embodiments, the generation method may further comprise one or more of the following features, taken individually or in any technically possible combination.

[0023] In certain embodiments, the generation method further comprises transmitting the generated digital fingerprint to an electronic device of said telecommunications network with which the connected object is likely to communicate. This digital fingerprint is, for example, transmitted so as to enable the identification of said connected object with said electronic device.

[0024] In certain implementation modes, the data model corresponds to a graph, called a "context graph", including nodes representing the resources of the data model, and arcs linking said nodes and representing the relationships of said data model.

[0025] In some implementations, the obtain step includes a conversion of the data model into a knowledge representation language.

[0026] This step is sometimes referred to as "serialization" in this application. In some implementations, the resulting data model can be converted to RDF / XML (an acronym for Resource Description Framework / Extensible Markup Language).

[0027] In some implementations, the method comprises obtaining an initial data model and the at least one data model is obtained by filtering data from the initial data model.

[0028] Filtering may differ depending on the implementation methods.

[0029] Thus, when the initial data model corresponds to a graph, the filtering corresponds for example to a selection of a sub-graph of said graph including nodes at a first distance of a node representative of said connected object. In one example, d=1, and only the nodes adjacent to the node representative of said connected object are selected. The first distance may be in certain implementation modes a constant distance, obtained for example by accessing a configuration file.

[0030] Alternatively, filtering is the removal of a value from at least one property associated with a resource and / or relationship from the data model.

[0031] In some implementations, the method may further comprise canonicalizing the data model. This step is sometimes referred to as "canonicalization." Thus, a data model that potentially has multiple possible representations or formalizations is converted into a single format (e.g., a proprietary format or a "standard" format of the technology domain).

[0032] In some implementations, at least one of the computing resources is associated with at least one property including at least one of the following: metadata relating to an identification, a location, a manufacturer, and / or a usable network protocol; data representative of a method of accessing the at least one computing resource; data representative of input data and / or data generated by the at least one computing resource; data representative of computing functions offered by the at least one computing resource; data resulting from a capture of media data by the at least one computing resource and / or the connected object; a combination of at least two of the above elements.

[0033] In some implementations, obtaining at least one data model and / or generating a digital fingerprint is repeated, so as to obtain a dynamic digital fingerprint over time.

[0034] These steps are, for example, repeated at a first frequency, constant for example, or in response to the detection of a specific event, for example in response to the detection of an event likely to affect the security of the data stored and / or exchanged by this connected object.

[0035] In some implementations, obtaining at least one data model is repeated T times, an obtained data model being generated at a time t=1..T, and the generation of a digital fingerprint is a generation of a digital fingerprint associated with the time t=T and depending on a combination of the T obtained data models.

[0036] In some implementations, the combination corresponds to a concatenation of the T data models.

[0037] According to a second aspect, the invention relates to a method for authenticating a connected object according to claim 10. Claims 11 to 13 describe preferred embodiments of the authentication method according to the invention.

[0038] According to an unclaimed aspect, the present disclosure relates to a method for verifying the validity of a digital fingerprint of a connected object in the context of an authentication of said connected object, the method being implemented by an electronic device for verifying the validity of a digital fingerprint and comprising: obtaining a first digital fingerprint of said connected object generated from a data model of a physical and / or IT environment of the connected object, the data model including spatial resources representative of portions or objects of the physical environment, and / or IT resources of the IT environment accessible by the connected object, spatial relationships and / or functional relationships linking said resources, said connected object itself being represented as an IT resource;a validation of the identification of said connected object based on a similarity between the first digital fingerprint and a second digital fingerprint of the connected object obtained by said electronic device. As discussed in more detail below, the electronic device for verifying the validity of a digital fingerprint corresponds, for example, to a remote server on which services are deployed which the connected object wishes to access, to a relay device, or to another connected object.;

[0039] In some implementations, obtaining a first digital fingerprint includes receiving, from the connected object or a relay device connected to the connected object, the first digital fingerprint.

[0040] In certain embodiments, the verification method further comprises a comparison between the first digital fingerprint and the second digital fingerprint of the connected object, implemented by the electronic device for verifying the validity of a digital fingerprint.

[0041] As discussed in more detail below, the electronic device for verifying the validity of a digital fingerprint corresponds, for example, to a relay device connected to the connected object whose digital fingerprint is being verified, to a remote server, to a connected object separate from the connected object whose digital fingerprint is being verified, or to the connected object whose digital fingerprint is being verified itself.

[0042] In certain implementation modes, a digital twin of said connected object is deployed on a remote server, and at each synchronization of data between the digital twin and the connected object, the exchanges are authenticated on the basis of the previously generated fingerprint.

[0043] In certain implementation modes, a digital twin of said connected object is deployed on said electronic device for verifying the validity of a digital fingerprint, and obtaining a second digital fingerprint of the connected object comprises generating said second digital fingerprint from data of said digital twin representative of a current operating state of said connected object.

[0044] According to a third aspect, the invention relates to a general method for authenticating a connected object comprising the steps of the method for generating a digital fingerprint of a connected object and of the method for verifying the validity of a digital fingerprint previously mentioned.

[0045] According to a fourth aspect, the invention relates to an electronic device, called a digital fingerprint generation device, configured to implement the method for generating a digital fingerprint of a connected object previously mentioned in any of its embodiments.

[0046] According to a fifth aspect, the invention relates to an electronic device, called a device for verifying the validity of a digital fingerprint or an electronic authentication device. Said electronic device is configured to implement the method for authenticating a connected object or the method for verifying the validity of a digital fingerprint of a connected object previously mentioned in any of its embodiments.

[0047] According to a sixth aspect, the invention relates to a communication system comprising the connected object, the electronic device for generating a digital fingerprint, and the electronic device for authenticating or verifying the validity of a digital fingerprint previously mentioned.

[0048] As discussed in more detail below, the electronic device for generating a digital fingerprint takes, for example, the form of a relay device, such as a home gateway, to which said connected object is connected, and the electronic device for verifying the validity of a digital fingerprint takes, for example, the form of a remote server to which said gateway is connected.

[0049] According to a seventh aspect, the invention relates to a computer program comprising instructions for implementing the method for generating a digital fingerprint of a connected object of the present application, in any of its embodiments, when said program is executed by a computer.

[0050] According to an eighth aspect, the invention relates to a computer-readable recording medium on which the computer program according to the seventh aspect is recorded.

[0051] According to a ninth aspect, the invention relates to a computer program comprising instructions for implementing the method for authenticating a connected object or the method for verifying the validity of a digital fingerprint of a connected object of the present application, in any one of its embodiments, when said program is executed by a computer.

[0052] According to a tenth aspect, the invention relates to a computer-readable recording medium on which the computer program according to the ninth aspect is recorded.

[0053] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended drawings which illustrate an exemplary embodiment thereof without any limiting character. In the figures: la is an example of a communication system in which a general method of authenticating a connected object can be implemented; la represents modules embedded in an electronic device for generating a digital fingerprint, according to an exemplary implementation of the invention; la represents modules embedded in an electronic device for verifying the validity of a digital fingerprint, according to an exemplary implementation of the invention; la represents an example of hardware architecture of an electronic device for generating a digital fingerprint; la represents an example of hardware architecture of an electronic device for verifying the validity of a digital fingerprint;lais an example of an environmental data model in the form of a conceptual graph;illustrates, in the form of a flowchart, the main steps of a method for generating a digital fingerprint of a connected object of the present application, according to an example of implementation;illustrates, in the form of a flowchart, the main steps of a method for verifying the validity of a digital fingerprint of a connected object of the present application, according to an example of implementation.;

[0054] This is an example of a communication system in which a general method of authenticating a connected object can be implemented.

[0055] As illustrated by the, the communication system comprises a relay device in the form of a home gateway 20. A home gateway is a network termination device and is often called a "box", CPE (initials of "Customer Premises Equipment" meaning "equipment in a customer's residence"), or HG (initials of "Home Gateway" meaning "home gateway"). Its role is notably to establish and manage a connection between a local area network (Local Area Network) and a telecommunications network (also commonly called an "access network", "extended network" or "Wide Area Network" according to Anglo-Saxon terminology), such as the Internet. Typically, a home gateway integrates a router, a wireless network access point, a switch and a modem.

[0056] The home gateway 20 is configured to administer a local network, for example within a home 50, which comprises a set of objects 10-1, 10-2, 10-3 connected to this home gateway 20 via a wired or wireless connection.

[0057] It is recalled here that in the present application, the term "connected object" means an electronic device configured to capture, store, process and / or transmit data and / or to receive and transmit instructions, and which has the capacity to connect to a telecommunications network for this purpose.

[0058] A connected object may include or be coupled, for example, to at least some of the following elements: sensors configured to transpose a physical measurement, such as temperature or movement, into digital data; actuators configured to generate an action and transmit, in response to the generated action, information characterizing this action. Triggering an alarm, activating / deactivating a motor, using switches or light dimmers are examples of actions that can be generated by an actuator; an entity with data processing and analysis capabilities, or even dialogue with another electronic device or with a dedicated infrastructure, such as a data collection and processing platform.

[0059] The local network comprises, in the example illustrated, several connected objects 10-1, 10-2 and 10-3 which take, for example, the form of a connected speaker equipped with a voice assistant 10-1, a presence sensor 10-2 or a door opening and closing actuator 10-3.

[0060] In this example, the home gateway 20 is configured in hardware and software to implement a method for generating a digital fingerprint of a connected object, such as the object 10-1 previously mentioned, for example in order to allow identification of said connected object in the network (for example with another device or object of the network and / or with its digital twin 300-1.

[0061] For this, the home gateway 20 is connected to a remote server 30 via a telecommunications network 40 such as the Internet, and this remote server 30 comprises the digital twin 300-1 of the object 10-1 previously mentioned. This remote server further comprises the digital twin 300-2 of the object 10-2 and the digital twin 300-3 of the object 10-3.

[0062] In this application, a digital twin is a digital replication of a real object or process, which has the particularity of evolving according to the transformations of the object or process to which it is attached. A digital twin is based on a physical model which is continuously fed by data collected via sensors placed on or near the real object, or resulting from an inspection, at a certain time, of this object. Thus, unlike a classic digital model, a digital twin is configured to provide, at each moment, information on the current operating state of the object to which it is connected.

[0063] The detailed embodiments are described, by way of example, considering the presence of three connected objects. It should be noted, however, that the number of connected objects does not constitute a limitation of the invention, and nothing precludes considering a number of connected objects less than or greater than three. Furthermore, no limitation is attached to the nature of the connected objects.

[0064] Furthermore, the detailed embodiments are described, by way of example, considering the presence of three digital twins. It should however be noted that the number of digital twins does not constitute a limitation of the invention, and nothing excludes considering a number of digital twins less than or greater than three (some of the connected objects may for example not be associated with any digital twin or the same digital twin may correspond to a logical grouping of several connected objects).

[0065] Finally, as illustrated by the, the domestic gateway 20 is located within a physical environment corresponding to a dwelling 50. However, the invention is in no way limited by the fact of considering a dwelling as a geographical area for installing the connected objects, any other area being able to be envisaged (factory, agricultural exploitation, city, building, etc.).

[0066] The represents modules embedded in an electronic device for generating digital fingerprints. This electronic device for generating digital fingerprints corresponds for example to the relay device 20 or to the remote server 30 and notably comprises a MOD_OBT module and a MOD_GEN module whose functions are described below with reference to the.

[0067] The represents modules embedded in an electronic device, called an authentication device or a device for verifying the validity of a digital fingerprint. This electronic device for verifying the validity of a digital fingerprint corresponds, for example, to the relay device 20, to the remote server 30, or to a connected object, for example a connected object distinct from the connected object whose digital fingerprint is verified or the connected object whose digital fingerprint is verified itself, and comprises in particular a MOD_OBT module and a MOD_VAL module whose functions are described below with reference to the.

[0068] It represents an example of hardware architecture of an electronic device for generating digital fingerprints.

[0069] As illustrated by the, the electronic device for generating digital fingerprints has the hardware architecture of a computer. Thus, the electronic device for generating digital fingerprints comprises in particular a processor 1, a random access memory 2, a read-only memory 3 and a non-volatile memory 4. It also comprises a communication module 5.

[0070] The read-only memory 3 of the electronic device for generating a digital fingerprint constitutes a recording medium as proposed, readable by the processor 1 and on which is recorded a computer program PROG_GEN in accordance with the invention, comprising instructions for executing steps of the method for generating a digital fingerprint of a connected object as proposed below. The program PROG_GEN defines one or more functional modules of the electronic device for generating a digital fingerprint, which rely on or control the hardware elements 1 to 5 cited above, and which comprise in particular: a module MOD_OBT for obtaining at least one data model of a physical and / or computer environment of a connected object, the data model including spatial resources representative of portions or objects of the physical environment, and / or computer resources of the computer environment accessible by the connected object,spatial relationships and / or functional relationships linking said resources, said connected object itself being represented as a computer resource; and, a MOD_GEN module for generating a digital fingerprint from the data model, said digital fingerprint allowing identification of said connected object with an electronic device of said telecommunications network.,

[0071] Furthermore, the electronic device for generating a digital fingerprint may also comprise other modules, in particular for implementing certain modes of the method for generating a digital fingerprint of a connected object, as described in more detail later.

[0072] It represents an example of hardware architecture of an electronic device for verifying the validity of a digital fingerprint.

[0073] As illustrated by the, the electronic device for verifying the validity of a digital fingerprint has the hardware architecture of a computer. Thus, the electronic device for verifying the validity of a digital fingerprint comprises in particular a processor 1, a random access memory 2, a read-only memory 3 and a non-volatile memory 4. It also comprises a communication module 5.

[0074] The read-only memory 3 of the electronic device for verifying the validity of a digital fingerprint constitutes a recording medium as proposed, readable by the processor 1 and on which is recorded a computer program PROG_VER in accordance with the invention, comprising instructions for executing steps of the method for authenticating a connected object or for verifying the validity of a digital fingerprint as proposed below. The program PROG_VER defines one or more functional modules of the electronic device for verifying the validity of a digital fingerprint, which rely on or control the hardware elements 1 to 5 cited above, and which include in particular: a module MOD_OBT for obtaining a first digital fingerprint of said connected object generated from a data model of a physical and / or computer environment of the connected object,the data model including spatial resources representative of portions or objects of the physical environment, and / or IT resources of the IT environment accessible by the connected object, spatial relationships and / or functional relationships linking said resources, said connected object itself being represented as an IT resource; a module MOD_VAL for validating the identification of said connected object based on a similarity between the first digital fingerprint and a second digital fingerprint of the connected object obtained by said electronic device.,

[0075] Furthermore, the electronic device for verifying the validity of a digital fingerprint may also comprise other modules, in particular for implementing certain embodiments of the method for verifying the validity of a digital fingerprint of a connected object, as described in more detail later.

[0076] This is an example of a data model of an environment in the form of a conceptual graph.

[0077] In the present application, a conceptual graph corresponds to a computer representation of a physical and / or computer environment of a connected object in the form of a graph (which may or may not be oriented depending on the embodiments). The conceptual graph comprises: nodes representative of spatial resources and corresponding to portions of objects or objects of the physical environment; nodes representative of computer resources; arcs representative of the spatial relationships and functional relationships connecting said resources.

[0078] Generally, a spatial relationship can link two spatial resources together, e.g., to characterize the topology between two portions of a physical environment (e.g., "the entrance is adjacent to the living room"). A spatial relationship can also link a spatial resource and a computing resource (e.g., "the home gateway is located in the entrance").

[0079] As illustrated by the, the conceptual graph aims to represent the environment of a connected object and includes (in the illustrated example) the following nodes, representative of computing resources:

[0080] – a node 410 representative of the door opening and closing actuator, such as the actuator 10-3 illustrated in. This node 410 is associated with several properties specific to the door opening and closing actuator including its identifier (“IoT-A”), its type (“DoorLock” for “door opening and closing actuator”), its status (“locked” for “locked”), and the creation date of this resource (“October 19, 2021 at 12:55:42”);

[0081] – a node 420 representative of a relay device, such as the home gateway 20 of the. This node 420 is associated with several properties including its identifier (“IoT-B”) and its type (“Router” for “router”);

[0082] – a node 430 representative of a video surveillance camera. This node 430 is associated with several properties including its identifier (“IoT-C”) and its type (“camera”);

[0083] – a node 440 representative of a temperature sensor. This node 430 is associated with several properties including its identifier (“IoT-D”) and its type (“TemperatureSensor” for “temperature sensor”).

[0084] Generally, a computing resource can be associated with at least one property including at least one of the following:

[0085] – metadata relating to an identification, location, manufacturer, and / or usable network protocol;

[0086] – data representing a method of accessing at least one IT resource;

[0087] – data representative of input data and / or data generated by at least one computer resource;

[0088] – data representative of IT functions offered by at least one IT resource;

[0089] – data resulting from a capture of media data by at least one IT resource and / or the connected object;

[0090] – a combination of at least two of the above.

[0091] The computing resources represented by nodes 410, 430 and 440 are connected to node 420 through "functional relationships" represented by directed arcs going from said nodes 410, 430 and 440 to said node 420. In this example, a single "hasGateway" functional relationship is considered. The "hasGateway" functional relationship linking nodes 410 and 420 is associated with several properties such as the creation date of the functional relationship ("October 19, 2023 at 12:55:42"), the port ("8502") and the protocol ("TCP", acronym for "Transmission Control Protocol") to be used.

[0092] The conceptual graph may further comprise one or more nodes representing spatial resources. Thus, in the example of the, the conceptual graph may comprise:

[0093] – a 450 node representing the living room of a home. This 450 node is associated with several properties including its identifier (“livingRoom” for “living room”) and its type (“room” for “room”);

[0094] – a 460 node representing the entrance to a dwelling. This 460 node is associated with several properties including its identifier (“entrance” for “entrance”) and its type (“room” for “room”).

[0095] Node 450 is connected to node 440 representing a temperature sensor through a spatial relationship "isIn" (for "is located in") represented by an oriented arc going from node 440 to node 450. Thus, this data model in the form of a graph thus makes it possible to represent in a simple and easily interpretable manner that the temperature sensor is located in the living room of the home.

[0096] Nodes 410, 420 and 430 are connected to node 460 representing the entrance to a dwelling through the spatial relationship "isIn" represented by directed arcs going from nodes 410, 420 and 430 to node 460. In this example, the spatial relationship "isIn" linking nodes 410 and 460 is associated with a property relating to the creation date of the functional relationship (here "October 19, 2022 at 12:55:42").

[0097] Illustrates, in the form of a flowchart, the main steps of a method for generating a digital fingerprint of a connected object, such as the connected object 10-1 of the, according to an example of implementation.

[0098] The method for generating a digital fingerprint of a connected object comprises a first step S2000 implemented by the electronic device for generating a digital fingerprint of a connected object – here the relay device 20 – and during which a data model of a physical and IT environment of a connected object is obtained. This model includes spatial resources representative of portions or objects of the physical environment of this connected object, IT resources of the IT environment accessible by the connected object, spatial relationships, as well as functional relationships linking said resources. The connected object considered is itself represented as an IT resource.

[0099] In certain implementation modes, this data model corresponds to a graph, called a "context graph", including nodes representing the resources of the data model, and arcs linking said nodes and representing the relationships of said data model.

[0100] For the remainder of the description, we consider the particular case where this data model corresponds to a "conceptual graph". It should be noted, however, that the use of a conceptual graph is only one example of a data model that can be considered, and does not constitute a limitation of the invention.

[0101] This first step S2000 comprises the sub-steps S200, S210, S220 and S230. During the sub-step S200, an initial context graph is obtained by the electronic device for generating a digital fingerprint of a connected object.

[0102] In certain implementation modes, this initial context graph can be generated by the electronic device for generating a digital fingerprint, and this from an exploration ("scan" according to the English terminology) of the network in order to determine the computing resources of a given environment as well as the functional relationships between these computing resources. The data concerning the spatial resources and / or the spatial relationships are for their part obtained for example by analyzing metadata associated with at least one computing resource (for example with each computing resource), before being aggregated within a conceptual graph. Alternatively, these spatial data can be determined for example by analyzing the headers of the packets transmitted by the computing resources.

[0103] The method for generating a digital fingerprint may further comprise a sub-step S210 during which the context graph obtained in step S200 is serialized. In other words, the context graph obtained in step S200 is converted into a knowledge representation language.

[0104] In some implementations, the resulting conceptual graph can be converted to RDF / XML (an acronym for Resource Description Framework / Extensible Markup Language). Alternatively, the resulting conceptual graph is converted to a format that conforms to the NGSI-LD model.

[0105] In some implementations, the conceptual graph converted to RDF / XML conforms to the JSON-LD syntax (acronym for "JavaScript Object Notation for Linked Data").

[0106] The method for generating a digital fingerprint may further comprise a sub-step S220 during which the data resulting from the serialization S210 are filtered.

[0107] In some implementations, the filtering step comprises selecting a subgraph of said conceptual graph that includes nodes at a first distanced from a node representative of the connected object for which a fingerprint is generated. Thus, sid=1, only the nodes adjacent to the node representative of the connected object are selected. Alternatively, a different first and second distanced may be considered for the computing resources and for the spatial resources.

[0108] In some implementations, the filtering step may include removing data such as resources, relationships and / or properties (or property values) associated with the resources and / or relationships.

[0109] Then, during a step S230, the serialized data or, where appropriate, the data resulting from the filtering step can be put into canonical form. This step is sometimes called "canonicalization" ("canonicalization" or "normalization" according to English terminology), and aims to convert the serialized data or, where appropriate, the data resulting from the filtering step and which may have several different formalizations or representations, into a "standardized" or "normal" form.

[0110] In some implementations, "canonicalization" may include generating a canonical XML document, for example, in accordance with a W3C (acronym for "World Wide Web Consortium") "Canonical XML Version" specification. For example, "canonicalization" may remove white space from tags, and / or use particular character encodings, and / or sort namespace references, and / or eliminate redundant references, and / or remove XML and DOCTYPE declarations, and / or transform relative URIs (acronym for "Uniform Resource Identifier") into absolute URIs.

[0111] The method for generating a digital fingerprint further comprises a step S240 during which a digital fingerprint allowing identification of said connected object with an electronic device of said telecommunications network is generated. To do this, an algorithm for generating a digital fingerprint based on the application of a cryptographic hash function, such as SHA-1, SHA-2 or MD5, to a file / document is implemented.

[0112] In some implementations, the file / document to which a hash function is applied may include data identifying the electronic fingerprint generation device.

[0113] During a step S250, the relay device 20 transmits the digital fingerprint H generated during the step S240 to the connected object 10. This digital fingerprint H is received by the connected object 10-1 during a step S100 and stored in the memory of said connected object, for example so that it can be reused in the context of an identification of said connected object 10-1 with another electronic device, such as the remote server 300.

[0114] During a step S260, the relay device 20 can transmit the digital fingerprint H generated during step S240 to a remote server 300 with which the connected object might wish to identify itself.

[0115] In some implementations (represented by a dotted arrow), the steps of obtaining S2000 at least one data model and / or generating S240 a digital fingerprint may be repeated, so as to obtain a dynamic digital fingerprint over time. This feature may help to improve the relevance and reliability of the digital fingerprint considered over time.

[0116] In some implementations, the dynamic digital fingerprint may be generated at a first frequency (e.g., constant), i.e., regularly after a first duration has elapsed. Alternatively or in combination, the dynamic digital fingerprint is generated in response to a determination of an event likely to affect the data captured and / or exchanged by the connected device 10.

[0117] In certain embodiments, the obtaining step S2000 is repeated T times, the conceptual graph obtained being generated at a time t=1..T, and the method further comprises a concatenation of the T conceptual graphs obtained; and the generation S240 of a digital fingerprint S240 is a generation of a digital fingerprint associated with the current time t=T as a function of said concatenation.

[0118] Alternatively, not all T conceptual graphs are considered, but only the last T* conceptual graphs are considered to generate the dynamic digital fingerprint associated with the current time t=T. This value T* is defined autonomously by the digital fingerprint generation device, or explicitly by a user. If defined autonomously, the value T* can take an arbitrary default value considered "reasonable" given the storage capacities of the device, for example the last ten graphs, or according to a time limit, for example the graphs of the last ten days. Alternatively, sampling of all stored graphs is possible, for example the last ten graphs at a rate of one graph per 24-hour period.

[0119] Illustrates, in the form of a flowchart, the main steps of a method for verifying the validity of a digital fingerprint of a connected object, according to an example of implementation. This method is implemented by a device for verifying the validity of a digital fingerprint.

[0120] As illustrated by the, the method for verifying the validity of a digital fingerprint comprises a first step S600 during which a digital fingerprint H, called the first fingerprint, emitted by a connected object 10, is obtained (for example received by the remote server 30).

[0121] This first fingerprint H is generated in accordance with the method for generating a digital fingerprint illustrated in, and corresponds to the fingerprint H received by the connected object 10-1 during step S100 previously described with reference to.

[0122] The method for verifying the validity of a digital fingerprint of a connected object further comprises a step S610 during which a digital fingerprint, called a second digital fingerprint, associated with the connected object is obtained.

[0123] In certain embodiments, this second digital fingerprint was stored in memory of said remote server 30, after having been received during step S300 previously described with reference to the.

[0124] Alternatively, a digital twin of the connected object for which the fingerprint is verified is deployed on the remote server 30, and this second digital fingerprint is generated on the fly by this remote server 30, from the data of said digital twin representative of a current operating state of this connected object.

[0125] The method further comprises a step S620 during which the first and second digital fingerprints are compared. If the fingerprints are similar (for example identical), an acknowledgment message ACK is transmitted to the connected object during a step S630. Otherwise, a negative acknowledgment message NACK is transmitted to the connected object during this step S630.

Claims

Method for generating a digital fingerprint of a connected object (10-1) of a telecommunications network, the method being implemented by an electronic device (20, 30) and comprising:obtaining (S2000) at least one data model of a physical and / or computer environment of the connected object (10-1); andgenerating (S240) a digital fingerprint (H) from the data model. Generation method according to claim 1, wherein said data model includes spatial resources representative of portions or objects of the physical environment, and / or computing resources of the computing environment accessible by the connected object, spatial relationships and / or functional relationships linking said resources, said connected object is itself represented as a computing resource. Generation method according to claim 1 or claim 2, further comprising a transmission of the generated digital fingerprint to an electronic device of said telecommunications network with which the connected object is likely to communicate. Generation method according to one of claims 1 to 3, where the data model corresponds to a graph, called a "context graph", including nodes representative of the resources of the data model, and arcs linking said nodes and representative of the relationships of said data model. Generation method according to one of claims 1 to 4, wherein the step of obtaining (S2000) at least one data model comprises a conversion (S210) of the data model into a knowledge representation language. A generation method according to one of claims 1 to 5, wherein the method comprises obtaining (S200) an initial data model and wherein said at least one data model is obtained by filtering (S220) the data of the initial data model. Generation method according to one of claims 1 to 6 taken in combination with claim 2, where at least one of the computing resources of the data model is associated with at least one property including at least one of the following elements: metadata relating to an identification, a location, a manufacturer, and / or a usable network protocol; data representative of a method of access to the at least one computing resource; data representative of input data and / or data generated by the at least one computing resource; data representative of computing functions offered by the at least one computing resource; data resulting from a capture of media data by the at least one computing resource and / or the connected object; a combination of at least two of the above elements. Generation method according to one of claims 1 to 7, in which the obtaining (S2000) of at least one data model and / or the generation (S240) of a digital fingerprint are repeated, so as to obtain a dynamic digital fingerprint over time. Generation method according to one of claims 1 to 7, where the obtaining (S2000) of at least one data model is repeated T times, an obtained data model being generated at a time t=1..T, and where the generation of a digital fingerprint (S240) is a generation of a digital fingerprint (H(t=T)) associated with the time t=T and a function of a combination of the T data models obtained. Method for authenticating a connected object (10-1), the method being implemented by an electronic device (20, 30, 10-1, 10-2, 10-3) and comprising an authentication of said connected object as a function of a similarity between a first digital fingerprint (H) received for said connected object and a second digital fingerprint (H*) of the connected object obtained by said electronic device, said second digital fingerprint (H*) of said connected object being generated from a data model of a physical and / or computer environment of the connected object (10-1). Authentication method according to claim 10, wherein the data model includes spatial resources representative of portions or objects of the physical environment, and / or computing resources of the computing environment accessible by the connected object, spatial relationships and / or functional relationships linking said resources, said connected object itself being represented as a computing resource. Authentication method according to claim 10 or claim 11, comprising a validation (S630) of the identification of said connected object (10-1) as a function of a similarity between the first digital fingerprint (H) and the second digital fingerprint (H*) of the connected object (10-1) obtained by said electronic device (20, 30, 10-1, 10-2, 10-3). Authentication method according to one of claims 10 to 12, wherein a digital twin (300-1) of said connected object (10-1) is deployed on said electronic device (30), and wherein obtaining a second digital fingerprint of the connected object (10-1) comprises generating said second digital fingerprint from data of said digital twin (300-1) representative of a current operating state of said connected object (10-1). Electronic device configured to implement the method according to one of claims 1 to 13. Computer program comprising instructions for implementing the method according to one of claims 1 to 13, when said program is executed by a computer.

Citation Information

Patent Citations

  • System and method for configuring IoT devices depending on network type

    EP4057569A1

  • Device fingerprinting, tracking, and management

    US20190384956A1

  • Fast Internetwork Reconnaissance Engine

    US20210067547A1

  • System and method for fingerprint-based network mapping of cyber-physical assets

    US20210226927A1