IP Library › Granted Patent US 12,563,021
Granted Patent B2
US 12,563,021 · App. 18/134,108 · Granted Feb 24, 2026

Secure communication protocol for communication devices

Inventors: William Afshari (Saint-Paul de Vence, FR); Zakarya Drias (Boston, MA)
Assignee: Schneider Electric Industries SAS
H04L63/0435H04L9/085H04L9/321H04L63/162H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,563,021
App. No.
18/134,108
Granted
Feb 24, 2026
Kind
B2
Abstract

A method for transmitting secured Ethernet frames on a communication line, the method including the following in a transmitter module: receiving an Ethernet frame comprising payload data from a network layer; retrieving a secure policy, defining the type of security to be applied to the Ethernet frame; producing an initialization vector based on an encryption counter and a physical address of the transmitter module; creating an authentication tag by applying an authentication algorithm on the secure policy, the initialization vector and the payload data using a shared key and the initialization vector; adding the secure policy, the initialization vector and the authentication tag to the payload data to create a secured Ethernet frame; and sending the secured Ethernet frame to a data link layer for transmission on the communication line.

Claims (58)

1 . A method for transmitting secured Ethernet frames on at least one communication line, said method comprising performing in a transmitter module:

receiving an Ethernet frame comprising payload data from a network layer,

retrieving a secure policy, the secure policy defining a type of security to be applied to the Ethernet frame, wherein the secure policy specifies whether encryption and authentication, authentication only, or neither encryption nor authentication is to be applied,

determining, from the secure policy, the type of security to be applied to the Ethernet frame,

contingent upon a determination that the type of security to be applied is authentication or encryption, producing an initialization vector based on both an encryption counter and a physical address of the transmitter module,

contingent upon a determination that the type of security to be applied is authentication, creating an authentication tag by applying an authentication algorithm on the secure policy, the initialization vector and the payload data using a shared key and the initialization vector,

adding the secure policy, the initialization vector, if any, and the authentication tag, if any, to the payload data to create a secured Ethernet frame, and

sending the secured Ethernet frame to a data link layer for transmission on the at least one communication line.

2 . The method according to claim 1 , wherein the Ethernet frame was provided using an industrial Ethernet protocol, and further comprising:

encrypting the payload data by applying an encrypting algorithm on the payload data using the shared key and the initialization vector.

3 . The method according to claim 1 , wherein a size of the authentication tag is at least 8 bytes and the authentication tag is added into a first field following a second field containing the payload data.

4 . The method according to claim 1 , wherein the shared key is a symmetric cryptographic key.

5 . The method according to claim 1 , wherein the shared key is known from a receiver module to which the secured Ethernet frame is transmitted on the at least one communication line.

6 . A method for receiving secured Ethernet frames on at least one communication line, said method comprising performing in a receiver module:

receiving a secured Ethernet frame comprising payload data from a data link layer on the at least one communication line,

retrieving a secure policy included in the secured Ethernet frame, the secure policy specifying a type of security to be applied to the secured Ethernet frame, wherein the secure policy specifies whether encryption and authentication, authentication only, or neither encryption nor authentication are applied,

determining, from the secure policy, the type of security to be applied to the secured Ethernet frame,

contingent upon a determination that the type of security to be applied is authentication or encryption, retrieving an initialization vector included in the secured Ethernet frame,

contingent upon a determination that the type of security to be applied is authentication:

creating a verification authentication tag by applying an authentication algorithm on the secure policy, the initialization vector and the payload data using a shared key and the initialization vector, and

authenticating the secured Ethernet frame if the verification authentication tag matches an authentication tag included in the secured Ethernet frame, and

sending the secured Ethernet frame to a network layer for analysis of content of the payload data of the secured Ethernet frame.

7 . The method according to claim 6 , wherein the secured Ethernet frame is based on an Ethernet frame transmitted using an industrial Ethernet protocol and the payload data are encrypted and further comprising:

decrypting the payload data by applying a decrypting algorithm on the payload data using the shared key and the initialization vector.

8 . The method according to claim 6 , wherein the shared key is known from a transmitter module from which the secured Ethernet frame is received on the at least one communication line.

9 . A transmitter module for transmitting secured Ethernet frames on at least one communication line, said transmitter module comprising:

one or more network interfaces to communicate with receiver modules;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the process when executed operable to:

receive an Ethernet frame comprising payload data from a network layer,

retrieve a secure policy, the secure policy defining a type of security to be applied to the Ethernet frame, wherein the secure policy specifies whether encryption and authentication, authentication only, or neither encryption nor authentication is to be applied,

determine, from the secure policy, the type of security to be applied to the Ethernet frame,

contingent upon a determination that the type of security to be applied is authentication or encryption, produce an initialization vector based on both an encryption counter and a physical address of the transmitter module,

contingent upon a determination that the type of security to be applied is authentication, create an authentication tag by applying an authentication algorithm on the secure policy, the initialization vector and the payload data using a shared key and the initialization vector,

add the secure policy, the initialization vector, if any, and the authentication tag, if any, to the payload data to create a secured Ethernet frame, and

send the secured Ethernet frame to a data link layer for transmission on the at least one communication line.

10 . A receiver module for receiving secured Ethernet frames on at least one communication line, said receiver module comprising:

one or more network interfaces to communicate with transmitter modules;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process executable by the processor, the process when executed operable to:

receive a secured Ethernet frame comprising payload data from a data link layer on the at least one communication line,

retrieve a secure policy included in the secured Ethernet frame, the secure policy specifying a type of security to be applied to the secured Ethernet frame, wherein the secure policy specifies whether encryption and authentication, authentication only, or neither encryption nor authentication are applied,

determine, from the secure policy, the type of security to be applied to the secured Ethernet frame,

contingent upon a determination that the type of security to be applied is authentication or encryption, retrieve an initialization vector included in the secured Ethernet frame,

contingent upon a determination that the type of security to be applied is authentication:

create a verification authentication tag by applying an authentication algorithm on the secure policy, the initialization vector and the payload data using a shared key and the initialization vector, and

authenticate the secured Ethernet frame if the verification authentication tag matches an authentication tag included in the secured Ethernet frame, and

send the secured Ethernet frame to a network layer for analysis of content of the payload data of the secured Ethernet frame.

11 . A non-transitory computer readable storage medium, with a computer program stored thereon, said computer program comprising instructions for, when executed by a processor, carrying out the method according to claim 1 .

12 . A non-transitory computer readable storage medium, with a computer program stored thereon, said computer program comprising instructions for, when executed by a processor, carrying out the method according to claim 6 .

13 . The method according to claim 1 , wherein the initialization vector contains 8 bytes, wherein 1 or 2 bytes of the 8 bytes are used for the physical address of the transmitter module and 6 or 7 bytes of the 8 bytes are used for the encryption counter.

14 . The method according to claim 1 , wherein the Ethernet frame is received via the at least one communication line.

15 . The method according to claim 6 , wherein the secured Ethernet frame was transmitted via the at least one communication line.

16 . The transmitter module according to claim 9 , wherein at least one module of a group of modules comprising the transmitter module and the receiver modules is an input/output (I/O) module or is a cluster manager that is configured to manage communication with a set of input/output (I/O) modules.

17 . The receiver module according to claim 10 , wherein at least one module of a group of modules comprising the receiver module and the transmitter modules is an input/output (I/O) module or is a cluster manager that is configured to manage communication with a set of input/output (I/O) modules.

18 . The transmitter module according to claim 16 , wherein the set of I/O modules is configured for connecting to at least one of the group comprising a sensor, a communications module, actuator, and a relay.

19 . The receiver module according to claim 17 , wherein the set of input output (I/O) modules is configured for connecting to at least one of the group comprising a sensor, a communications module, actuator, and a relay.

20 . The transmitter module according to claim 9 , wherein the transmitter module is included in a communication device that further includes a receiver module of the receiver modules, and the communication device is configured to transmit the secured Ethernet frame to another communication device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 13, 2023
From: AFSHARI, WILLIAM; DRIAS, ZAKARYA
To: SCHNEIDER ELECTRIC INDUSTRIES SAS
Reel/Frame 063313/0788 →
Priority Claims (1)
EP 22305626 · Apr 27, 2022 · regional
Continuity (1)
Related Publication 20230353545A1 · Nov 2, 2023
References Cited (17)
US 5802178A · Holden · 1998 [cited by examiner]
US 6253321B1 · Nikander · 2001 [cited by examiner]
US 11748492B1 · Campagna · 2023 [cited by examiner]
US 20020035635A1 · Holden · 2002 [cited by examiner]
US 20020154779A1 · Asano · 2002 [cited by examiner]
US 20020184487A1 · Badamo · 2002 [cited by examiner]
US 20020188839A1 · Noehring · 2002 [cited by examiner]
US 20050198531A1 · Kaniz · 2005 [cited by examiner]
US 20080075073A1 · Swartz · 2008 [cited by applicant]
US 20150010012A1 · Koponen · 2015 [cited by examiner]
US 20190268145A1 · Barth · 2019 [cited by examiner]
US 20200366715A1 · Chopra et al. · 2020 [cited by applicant]
US 20210294889A1 · Zeh et al. · 2021 [cited by applicant]
US 20220393856A1 · Goel · 2022 [cited by examiner]
EP 4020942A1 · 2022 [cited by examiner]
WO WO2020084151A1 · 2020 [cited by examiner]
European Search Report and Search Opinion dated Oct. 7, 2022 for corresponding European Patent Application No. EP22305626.8, 8 pages. [cited by applicant]