Method for secure configuration and use of a system for monitoring and/or controlling modules

US10270783B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-10270783-B2
Application numberUS-201615220640-A
CountryUS
Kind codeB2
Filing dateJul 27, 2016
Priority dateSep 30, 2015
Publication dateApr 23, 2019
Grant dateApr 23, 2019

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Monitoring and controlling modules of a system includes obtaining, with a portable piece of equipment associated with an installation operator, an identifier that encodes a physical network address of a communicating module, and obtaining, with the portable piece of equipment, an installation geolocation information item. The physical network address and the installation geolocation are transmitted to a central server by the portable piece of equipment, and the central server verifies prior storage of said physical network address. If the physical network address cannot be verified, the server stores the physical network address in association with the identifier.

First claim

Opening claim text (preview).

The invention claimed is: 1. A method for secure configuration of a system of modules for monitoring and controlling pieces of domestic, industrial or office equipment, the system comprising a communicating module to receive items of monitoring and control information from other modules of the system and to communicate the items of monitoring and control information received to a central server via a first communication mode, the method comprising: obtaining, with a portable piece of equipment associated with an installation operator, an identifier that encodes at least a physical network address of the communicating module, obtaining, with the portable piece of equipment, an installation geolocation information item, transmitting, by the portable piece of equipment, an information item containing said physical network address to said central server via a second communication mode; transmitting, with said portable piece of equipment, to the central server, via the second communication mode, the installation geolocation information item, verifying, with the central server, prior storage of said physical network address, and in the event of negative verification, authorizing configuration of said system of modules and recording, in a memory of the central server, said physical network address in association with an identification information item for the installation operator and with said received installation geolocation information item; and in the event of a positive verification: blocking configuration of the system of modules to deny the system of modules access to the central server, and sending a notification containing said received installation geolocation information item to an initial installation operator identified by an installation operator identification information item stored in association with said physical network address in the central server. 2. The method according to claim 1 , wherein, prior to the step of obtaining an identifier, a step of obtaining an identification information item for the installation operator, comprising at least one e-mail address of the installation operator. 3. The method according to claim 1 , further comprising extracting an initial geolocation information item recorded in said memory of the central server in association with said physical network address and sending the initial geolocation information item to an initial installation operator. 4. The method according to claim 3 , wherein a step of receiving an unblocking authorization or denial sent by said initial installation operator. 5. The method according to claim 1 , wherein, in the event of the positive verification, the method includes extracting an initial geolocation information item recorded in said memory of the central server in association with said physical network address, and rendering the system of modules unusable from a remote location by blocking the configuration of the system of modules when said initial geolocation information item differs substantially from the received installation geolocation information item, to within a predetermined tolerance level. 6. The method according to claim 1 , wherein said identifier encodes binary information items, and in that the method has a step of reading the identifier and extracting a physical network address from the encoded binary information items. 7. The method according to claim 6 , wherein the identifier moreover has information items relating to the modules of the system of modules. 8. A non-transitory computer-readable medium encoded with computer-readable instructions that, when executed by a computer, cause the computer to perform the method according to claim 1 . 9. A method for secure use of a system of modules for monitoring and controlling pieces of domestic, industrial or office equipment, the system of modules comprising a communicating module to receive items of monitoring and control information from other modules of the system and to communicate the information items received to a central server via a first communication mode, for putting the system of modules to use, the method comprising: obtaining, with a portable piece of equipment associated with a final user, a physical network address of the communicating module and transmitting said physical network address to said central server; verifying, with the central server, prior storage of said physical network address; and in the event of the physical network address being present: blocking configuration of the system of modules to deny the system of modules access to the central server, and sending a notification containing an installation geolocation information item to an initial installation operator identified by an installation operator identification information item stored in association with said physical network address in the central server. 10. The method for secure use of a system according to claim 9 , comprising: obtaining a use geolocation information item for the communicating module and transmitting to the central server, with said portable piece of equipment associated with the final user, the use geolocation information item, following verification of a presence of the physical network address in a memory of the server, extracting an initial geolocation information item recorded in said memory of the central server in association with said physical network address and verifying agreement between the recorded initial geolocation information item and the received use geolocation information item. 11. The method for secure use of a system according to claim 10 , wherein in the absence of agreement, the method further comprises: receiving an authorization or a prohibition for unblocking of the use of the system of modules, sent by said installation operator. 12. A non-transitory computer-readable medium encoded with computer-readable instructions that, when executed by a computer, cause the computer to perform the method according to claim 9 . 13. A system for secure configuration of a system of modules for monitoring and controlling pieces of domestic, industrial or office equipment, comprising said system of modules and a central server, said system of modules comprising a communicating module to receive monitoring and control information items from other modules of the system of modules and to communicate the information items received to the central server via a first communication mode, the system comprising: a portable piece of equipment associated with an installation operator, configured to: obtain an identifier encoded with a physical network address of the communicating module, obtain an installation geolocation information item, transmit, via a second communication mode, an information item including said physical network address to said central server; transmit, via the second communication mode and to the central server, the installation geolocation information item, the central server being configured to: verify prior storage of said physical network address, in the event of negative verification, to authorize the configuration of said system of modules and to recording, in a memory of the central server, said physical network address in association with an identification information item for the installation operator and with said installation geolocation information item, and in the event of a positive verification, block configuration of the system of modules to deny the system of modules access to the central server, and sending a notification containing said received installation geolocation information item to an initial installation operator identified by a

Assignees

Inventors

Classifications

  • H04L63/107Primary

    wherein the security policies are location-dependent, e.g. entities privileges depend on current location or allowing specific operations only from locally connected terminals · CPC title

  • received data contents, e.g. message integrity · CPC title

  • Remote metering · CPC title

  • H04W12/04Primary

    Key management, e.g. using generic bootstrapping architecture [GBA] · CPC title

  • Graphical identity · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US10270783B2 cover?
Monitoring and controlling modules of a system includes obtaining, with a portable piece of equipment associated with an installation operator, an identifier that encodes a physical network address of a communicating module, and obtaining, with the portable piece of equipment, an installation geolocation information item. The physical network address and the installation geolocation are transmi…
Who is the assignee on this patent?
Schneider Electric Ind Sas
What technology area does this patent fall under?
Primary CPC classification H04L63/107. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Apr 23 2019 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 12 related publications on this page (citations in our corpus or others sharing the same primary CPC).