Method for dynamically assigning identifiers to an embedded universal integrated circuit card (EUICC) of a user device and corresponding system

DE602022019208T2Active Publication Date: 2025-08-13THALES SA +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE602022019208
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2021-01-25
Filing Date
2022-01-25
Publication Date
2025-08-13
Estimated Expiration
2042-01-25

AI Technical Summary

Technical Problem

Existing communication systems lack the ability to securely and dynamically assign identifiers to user equipment, making communications traceable and vulnerable to interception, which is addressed by the method of dynamically assigning ephemeral identifiers to user equipment using an embedded universal integrated circuit card (eUICC) to enhance security and anonymity.

Method used

A method for dynamically assigning identifiers, such as IMSI, to an eUICC in user equipment through an identifier management equipment connected to a mobile telephone network, creating a specific subscriber profile and implementing a strong authentication procedure to ensure secure and ephemeral communication.

Benefits of technology

The method ensures untraceable and secure communication by assigning ephemeral identifiers, making it difficult for malicious actors to intercept communications and allowing for robust authentication and key exchange, thereby enhancing network security.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to a method for dynamically assigning at least one identifier to user equipment comprising an embedded universal integrated circuit card, hereinafter referred to as eUICC (for "Embedded Universal Integrated Circuit Card" in English), and which is also sometimes referred to as an embedded subscriber identification module or eSIM ("Embedded Subscriber Identification Module") in the literature.

[0002] When communicating via a mobile telephone network, user equipment uses different identifiers, some of which are specific to it (and therefore identical from one communication to another) and others assigned to it by the network (and even if they change from one communication to another are known to the network).

[0003] These identifiers therefore make it possible to trace the communications of this user equipment on the network. Communications can be listened to and the user of the equipment and the recipient of the communications (whether a service or another user) can be identified.

[0004] There is therefore a need to make communications between user equipment and a recipient untraceable in order to secure exchanges.

[0005] According to the GSMA standard, a terminal that has only one radio interface must first obtain a temporary profile (e.g. provided by the operator and entered by the terminal user) to establish an initial connection to a mobile telephone network. This initial connection then allows the terminal to access an SM-DP+ to download a definitive profile using an activation code, which the terminal must also obtain. US 2020 / 169868 A1 discloses the possibility for the terminal to simultaneously obtain MNO-specific information and an activation code, the MNO information enabling the initial connection and the activation code enabling access to an SM-DP+. The manner of obtaining this information remains in accordance with section 3.1 of SGP 22 of the GSMA standard.

[0006] The purpose of the present invention is to meet this need.

[0007] For this purpose, the subject of the invention is a method for dynamically assigning identifiers, the method consisting in assigning at least one subscription identifier, for example an IMSI, to an embedded universal integrated circuit card - eUICC residing in a user equipment - UE, the method consisting in transmitting by an identifier management equipment, through a first mobile telephone network whose radio interface is used by the UE to connect, a subscription identifier in a field of a message exchanged in accordance with a standard protocol for attaching a roaming terminal on the first mobile telephone network, the identifier management equipment being connected to an external roaming interface of the first mobile telephone network, the transmitted subscription identifier having been selected by the identifier management equipment from a previously defined pool of subscription identifiers,the method further comprising creating, by means of the identifier management equipment, a specific subscriber profile for the eUICC and updating a subscriber service with said subscriber profile, said subscriber profile incorporating the subscription identifier assigned to the eUICC.,

[0008] According to particular embodiments, the method comprises one or more of the following characteristics, taken in isolation or in all technically possible combinations: the method consists in transmitting to the eUICC a temporary subscription identifier and creating a temporary subscriber profile, allowing the UE to attach to the first mobile telephone network, the method furthermore consisting in implementing a strong authentication procedure between the eUICC and the identifier management equipment. the method consists, once the eUICC has been authenticated, in establishing a secure link allowing an exchange of diversified keys from the eUICC to the identifier management equipment, then in transmitting to the eUICC a definitive subscription identifier and in creating a definitive subscriber profile, these transmission and / or creation steps using the exchanged diversified keys. the eUICC and the identifier management equipment exchange encryption parameters making it possible to calculate, on both sides, credentials, said subscriber profile integrating said credentials.the identifier management equipment (recognizes an eUICC to which to provide an identifier from an eUICC identifier received from the eUICC and present in a list of eUICC identifiers stored by the identifier management equipment. the method further comprises a step of dynamically assigning an equipment identifier (IMEI) to a radio module of the UE. the method further comprises a step of dynamically assigning a virtual IP address for the UE as the source of a communication. the method further comprises a step of dynamically assigning a virtual IP address for each recipient with which the UE has the right to communicate.

[0009] The invention also relates to a system comprising user equipment and an identifier server for implementing the preceding method of dynamic allocation of identifiers, comprising: a user equipment - UE, the UE using a radio interface of a first mobile telephone network to connect; an "Embedded Universal Integrated Circuit Card" - eUICC residing in the UE; and an identifier management equipment connected to an external roaming interface of the first mobile telephone network, the identifier management equipment being capable of: allocating to the eUICC a subscription identifier selected from a pool of subscription identifiers stored by the identifier management equipment; transmitting to the eUICC the subscription identifier allocated in a field of a message exchanged in accordance with a standard protocol for attaching a roaming terminal to the first mobile telephone network;to create a specific eUICC subscriber profile; and to update a subscriber service with said subscriber profile, said subscriber profile incorporating the subscription identifier assigned to the eUICC.;

[0010] Preferably, the identifier management equipment is associated with a subscriber server, or “Home Subscriber Server”, providing said subscriber service.

[0011] The invention and its advantages will be better understood upon reading the following detailed description of a particular embodiment, given solely as a non-limiting example, this description being made with reference to the appended drawings in which: There figure 1 is a schematic representation of an installation integrating a radiocommunication infrastructure and a system allowing the implementation of the method according to the invention; The figure 2 is a schematic representation in block form of the method according to the invention; and, The figure 3 is a timeline of the messages exchanged in the installation of the figure 1 for carrying out the main step of the process of the figure 2 . GENERAL INFORMATION

[0012] The method according to the invention makes it possible to assign ephemeral identifiers to a source and, advantageously, to the recipient of communications from this source, while the source is connected to an intermediate mobile telephone network.

[0013] Ephemeral identifiers include a source hardware identifier (e.g., IMEI), a source subscription identifier (e.g., IMSI), a source IP address, and a recipient IP address.

[0014] The method according to the invention allows the anonymization of exchanges between the source and the recipient and therefore makes any communication on the intermediate network untraceable, in particular from a communication from the source to another. It also makes any usurpation by a malicious actor of the ephemeral identity attributed to a source detectable.

[0015] The implementation of the method according to the invention provides, on the network side, an identifier management device offering in particular an identifier allocation service. This device is in particular connected to an external interface of the intermediate mobile telephone network in order to detect sources seeking to register with the intermediate network and which are subscribed to the identifier allocation service. This device is capable of dynamically allocating and delivering a set of ephemeral identifiers to the source and, advantageously, to the recipient that the source is seeking to reach. This device advantageously makes it possible to control different nodes of the network to manage the communication between the source and the destination.

[0016] The implementation of the method according to the invention is provided on the source side, a terminal, or user equipment UE (“User Equipment”) of the type comprising an on-board universal integrated circuit card, or eUICC card in the following.

[0017] Generally speaking, an eUICC card ("Embedded Universal Integrated Circuit Card") is a SIM card (Subscriber Identity Module) which has the capacity to be reprogrammed remotely via the radio interface ("Over The Air" programming - OAT) by a machine, such as an SMDP server ("Subscription Manager - Data Preparation"), of the network to which the UE is connected.

[0018] In this way, a user can store several subscription profiles on the UE he uses, each profile corresponding to subscriptions with different operators and / or, for the same operator, for different services (such as data exchange, long distance calls, etc.)

[0019] The use of an eUICC card is necessary because the most fundamental identifier to be modified is the IMSI (International Mobile Subscriber Identity). This identifier is normally stored by a SIM (subscriber identity / identification module) card, which cannot be modified.

[0020] Specifically to the invention, the UE is programmed to implement certain steps of the method. Accordingly, the UE will sometimes be referred to as the TIC / TAC client. The eUICC card is also programmed to implement some of the steps of the method according to the invention. The eUICC card will sometimes be referred to as the TIC / TAC card. SYSTEM

[0021] Referring to the figure 1 , a first embodiment of the system according to the invention will be presented in detail.

[0022] The system according to the invention comprises a UE 1, or TIC / TAC client 1, a radiocommunication infrastructure, and identifier management equipment 64.

[0023] The present invention is based on a radiocommunication infrastructure of the 3G, 4G or 5G type, as defined by the 3GPP ("3rd Generation Partnership Project"). In the following, the case of a 4G type infrastructure will be taken more particularly as an example, but the person skilled in the art knows how to apply the teaching of the present description to the case of other types of infrastructure, in particular a 5G type infrastructure.

[0024] The radiocommunication infrastructure comprises a first network 10, which is a mobile telephone network used by the UE 1 for its air interface.

[0025] The radiocommunication infrastructure comprises a second network 20, for example a secure private network (such as a data center), grouping together various sensitive applications 21, 22, 23 on machines placed behind a “firewall”.

[0026] In the present embodiment, these sensitive applications are the recipients of communications from the source that constitutes the UE 1. First Network

[0027] The 10 mobile telephone network is a network that uses 4G technology, for example.

[0028] For example, a PLMN (“Public Land Mobile Network”), which offers a radiocommunication service in a geographical region (for example a specific country) and which is managed by a primary operator.

[0029] The first network 10 comprises a radio access subnetwork 11, or RAN (“Radio Access Network”), integrating a plurality of access points 12, or eNB (“e-Node B” in 4G). An eNB allows a UE to connect by means of a wireless radio link to the first network 10. For example, the UE1 is connected (or seeks to establish a connection) through the link 81 with an eNB 12 of the RAN 11.

[0030] Advantageously, the EDGE (“Enhanced Data Rates for GSM Evolution”) protocol is implemented by machines 13 adapted from RAN 11.

[0031] The first network 10 includes a core subnetwork 15, or ePC (“evolved Packet Core” in 4G).

[0032] This core subnetwork 15 includes in particular: A service gateway 14, or SGW (“Serving Gateway”), which handles, at the “usage plane” level, the routing of “useful” flows (voice communications, data traffic, etc.) between the RAN 11 and the ePC 15. An MME (“Mobile Management Entity”) server 16, which manages, at the “control plane” level, the sessions (authentication, authorizations, voice and data session, etc.) and the mobility (location, paging, handover, etc.) of a UE connected to the RAN 11. A PCRF (“Policy and Charging Rules Function”) server 17, which gathers, in real time, the information coming from and going to the first network 10, by establishing rules and making decisions as to the policy to be applied to each active subscriber on the first network. A gateway 19, or PGW (“Packet Data Network Gateway”) responsible for the exchange of “useful” flows with other networks (public or private), in particular with the Internet. The PGW 19 is notably connected to the second network 20.

[0033] Associated with the first network 10, a subscriber server or HSS server (“Home Subscriber Server”) 18, capable of offering a subscriber service. The HSS 18 includes a database of the profiles of the subscribers of the first operator, with their rights and their characteristics.

[0034] On the figure 1 , different connections have been represented: Link 82 is a data flow link between the eNB 12 and the SGW 14. Link 83 is a data flow link between the SGW 14 and the PGW 19. Link 84 is a control data link between the SGW 14 and the MME 16. Link 85 is a control data link between the eNB 12 and the MME 16. Link 89 is a control data link between the PGW 19 and the PCRF 17.

[0035] The ePC 15 core subnetwork has external interfaces, for example an external interface known as “roaming” (called “S6a” in 4G) between the MME 16 and HSS 18. It is represented by link 70. EU - TIC / TAC client

[0036] EU 1 includes a computing means, such as a processor 2, a storage means, such as a memory 3, an eUICC 4 and a radio module 5. These components are connected by a suitable data bus 6.

[0037] The memory 3 comprises the instructions of computer programs which, when executed by the processor 2, allow the implementation of certain functionalities. In particular, the memory 3 comprises the instructions of a program 31 allowing the implementation by the UE 1 of certain of the steps of the method according to the invention.

[0038] Radio module 2 is known as such. It stores two identifiers: The IMEI (“International Mobile Equipment Identity”), which is assigned to the UE 1 following the implementation of the method according to the invention; and, the IPvo: the virtual IP (“Internet Protocol”) address assigned to the UE 1 originating the communication following the implementation of the method according to the invention.

[0039] The eUICC 4 comprises a calculation means, such as a processor 42, and a storage means, such as a memory 43.

[0040] The memory 43 comprises the instructions of computer programs which, when executed by the processor 42, allow the implementation of certain functionalities. In particular, the memory 43 comprises the instructions of a program 41 allowing the implementation by eUICC 4 of certain of the steps of the method according to the invention.

[0041] Furthermore, memory 43 stores various information.

[0042] At a time t1, before the implementation of the method according to the invention, the memory 43 comprises: The EID (“eUICC ID”) is an identifier of the eUICC 4; The master key MK (“Master Key”) is a key shared with the dynamic identifier allocation service; The keys MK1, MK2 are diversified keys characteristic of the eUICC 4; and, Cer certificates constituting a signature of the eUICC 4.

[0043] At a time t2, after the implementation of the method according to the invention, the memory 43 further comprises: The IMSI (international mobile subscriber identity) is an identifier normally assigned by an operator to UE SIM cards whose users are registered / subscribed with that operator; ICCID (integrated circuit card identifier), which is an identifier of the hardware part of the eUICC 4; and, Ki (Subscriber Authentication Key) and OPc (derived operator code), which are an example of a set of keys allowing mutual authentication between a subscriber and an operator. Such a set of keys is sometimes referred to as credentials. Second Network

[0044] The second network 20 is for example a secure private network.

[0045] The second network 20 comprises security network equipment, for example of the “firewall” type, called FW / NAT equipment 29. On command from the identifier management equipment 64, it performs a mating of the virtual IP address assigned to the UE 1 and the virtual IP address assigned to the recipient (application 21, 22 or 23) on the data packets circulating through the FW / NAT equipment 29.

[0046] The second network 20 comprises one or more routers 28.

[0047] The second network 20 comprises several machines offering different services as recipients of the communication from the UE 1. These services are, for example, applications 21, 22, 23. These applications are sensitive and must be protected in particular against intruders usurping the address of user equipment having access rights.

[0048] The communication of data flows between the first and second networks 10 and 20 is carried out according to a link 86 between the PGW 19 of the first network 100 and the FW / NAT 29 of the second network. This is for example a communication according to the TCP-IP protocol, possibly passing through one or more intermediate networks, such as in particular the Internet.

[0049] On the figure 1 , the data flow communication between the FW / NAT 29 and the router 28 is carried out according to a link 87 and the data flow communication between the router 28 and the machines 21, 22 and 23 is carried out according to a link 88. ID management equipment

[0050] The identifier management equipment 64 consists of one or more computers programmed to carry out certain of the steps of the method according to the invention so as to provide a service for dynamically allocating identifiers and, once these identifiers have been allocated to a source and a recipient, a service for managing communications between the source and the recipient.

[0051] The identifier management equipment 64 is for example based on an architecture of the SDN (“Software Defined Network”) type. It then comprises a network control component 50 and a service orchestration application component, or orchestrator, 60. Network control component

[0052] The network control component 50 includes: a DNS (“Domain Name System”) module 55 and a “DNS proxy” module 54. These modules, associated with a NMCD (“Network Management Cyber Defense”) cyber defense functionality of the orchestrator 60, participate in the allocation and use of a virtual IP address of a recipient. These modules are connected to the orchestrator 60 by a REST API (“Application Programming Interface Representational State Transfer”) 72 type link. The DNS module 55 could be positioned in the second network 20 itself. an IPAM (“IP address management”) module 56, participating in the allocation and use of a virtual IP address of a source. This module is connected to the orchestrator 60 by a REST API 72 type link. The IPAM module 56 could be positioned in the second network 20 itself.an authorization and authentication module, called AAA module ("Authentication, Authorization, Accounting / Auditing") 57, for implementing authentication mechanisms based on certificates, such as for example the EAP-TLS mechanism ("Extensible Authentication Protocol - Transport Layer Security"). This module is connected to the orchestrator 60 by a REST API type link 72. The AAA module 57 could be positioned in the second network 20 itself. a dynamic identifier allocation server module, or TIC / TAC server 51, participating in the allocation and use of an ephemeral IMSI to a source. The TIC / TAC server 51 is connected to the orchestrator 60 by a connection of the REST API type 72. The TIC / TAC server 51 is connected to the external roaming interface 70 of the first network 10. The TIC / TAC server 51 can be identified as an AuC (“Authentication Center”), but does not have any of the other functionalities of an HSS.The TIC / TAC server 51 comprises, for example, a sub-module SP 52 whose function is to identify UEs subscribed to the dynamic identifier allocation service and to implement the transfer protocol of an ephemeral ISMI, as well as advantageously a sub-module SG 53 whose function is to simplify the management of the keys and rights of the UEs subscribed to the service. Orchestrator

[0053] The service orchestration component 60 has the function of synchronizing the different services, in particular the allocation and management of ephemeral identifiers, mobility management, and control of the uniqueness of communications.

[0054] The orchestrator 60 manages the different modules of the network control component 50.

[0055] In addition, the orchestrator 60 is connected to the HSS 18 by a link 71 of the REST API type.

[0056] The orchestrator 60 is connected to the PCRF 17 by a link 77 of the Rx interface type.

[0057] The orchestrator 60 is connected to the PGW 19 by a link 73 of the SGi Radius interface type.

[0058] The orchestrator 60 is connected to the FW / NAT 29 and to the router 28 by links 74 of the Yang REST interface type.

[0059] The orchestrator 60 is connected to the machines associated with the applications 21, 22, 23 by a link 76 of the REST API type.

[0060] The service orchestration component 60 maintains a database 65.

[0061] Database 65 contains the data necessary for assigning ephemeral identifiers to a subscriber to the service and, once an ephemeral identity has been assigned, controlling the network nodes to enable communication between the source and the recipient.

[0062] In particular, database 65 includes: A pool of IMSIs; A list of EIDs of UEs subscribed to the service and the Cer certificates of each of these UEs; The master key MK of the dynamic identifier assignment service; A list of real IP addresses of recipients, such as applications 21, 22, 23 on the second network 20; A pool of virtual IP addresses for sources, IPvo; and, A pool of virtual IP addresses for recipients, IPvd.

[0063] And, for each UE actually using the service at a given time, the database 65 also includes: The current IMEI of this UE; The current IMSI of this UE; The EID of this UE; The diversified keys MK1, MK2 of this UE; The credentials Ki and OPc of this UE; The virtual IP address IPvo assigned to this UE; and, A list of virtual IP addresses L_IPvd, assigned to the recipients that this UE has the right to reach. PROCESS

[0064] As shown in the figure 2 , according to a preferred embodiment, the method 80 comprises the dynamic allocation of an IMEI (part 82 of the method), an IMSI (part 84), an origin virtual IP address (part 86) and a destination virtual IP address (part 88). IMEI Assignment

[0065] IMEI is an identifier of the UE 1 radio module 5.

[0066] For example, when UE 1 is powered on, the TIC / TAC application 31 is executed and starts by calculating an ephemeral IMEI for radio module 2. For example, the IMEI is randomly drawn. The result of this calculation is passed to radio module 5, which will label the data packets it will transmit during communication with this ephemeral IMEI.

[0067] The next time you use UE 1, another IMEI value will be calculated.

[0068] Thus, the identifier of the hardware part of the user equipment is changed and is no longer characteristic of the radio module 5 or the eUICC card 4. IMSI Assignment

[0069] The subscription identifier is the identifier that the present invention mainly helps to dynamically modify.

[0070] This second part 84 of the method 80 comprises a first phase 100 of enrolling a UE 1 with the dynamic identifier allocation service. This enrollment consists of providing the UE 1 with a temporary profile, which is not traceable. The provision of this temporary profile is however carried out on the basis of weak authentication of the UE 1 with the dynamic identifier allocation service. By weak authentication is meant the implementation of an authentication procedure based for example on the transmission by the UE 1 to the service of a particular identifier, and / or unilateral authentication, and / or authentication with a generic encryption key.

[0071] The first phase 100 then advantageously continues with strong authentication of the UE 1 with the service. Strong authentication means the implementation of a mutual and robust authentication procedure of the UE 1 and the service, based for example on the exchange of signatures. Successful authentication then allows the UE 1 to fully access the dynamic identifier allocation service and the associated resources.

[0072] This makes it possible in particular to then provide the UE 1 with a definitive profile. For example, a secure tunnel is established to transmit diversified keys MK1 and MK2 from the UE 1 to the service and, in a second phase 200 of the method, a definitive profile is associated with the UE 1. This definitive profile is also not traceable.

[0073] This part of the method is based on a mechanism for exchanging hidden data in the fields of messages conventionally exchanged when registering user equipment with a radiotelephone network, such as the first network 10. This mechanism is for example described in patent application EP 3 506 668.

[0074] An embodiment of this second part 84 is illustrated in the figure 3 .

[0075] In an initial step 90, an IMSI reserve is provided to the equipment 64. This IMSI reserve comprises a plurality of IMSIs reserved for the dynamic identifier allocation service. This list comes for example from an operator.

[0076] Advantageously, other secondary identifiers, such as the MSISDN (Mobile Station ISDN) and the ICCID (integrated circuit card identifier), may be provided to the UE 1 at the same time and in the same way as the IMSI. To simplify the description, only the IMSI is considered in the following.

[0077] At this stage, nothing is provisioned on the associated HSS 18. First phase

[0078] In this first phase, the UE 1 will first use a first IMSI, e-IMSI1, generated randomly to register with the first network. This IMSI will be identified by the first network 10 as belonging to another network. The first network will therefore seek to know the roaming rights of this UE 1. The TIC / TAC server 51 will take advantage of this to retrieve the EID of the UE 1, and send it a temporary IMSI, t-IMSI. The t-IMSI will make it possible to implement a strong authentication procedure and, if this identification is successful, to establish a tunnel link for the secure exchange of diversified keys from the UE 1 to the equipment 64.

[0079] More specifically, on the network 10 side: Step 101: the user turns on the UE 1. Step 102: the TIC / TAC card 4 does not detect any definitive IMSI in its memory 43 and then calculates, randomly, a first IMSI, e-IMSI1. Alternatively, an origin IMSI allowing a public signature or a reference IMSI associated with a third-party PLMN is pre-recorded on the TIC / TAC card 4, such as to force the MME 16 to use its roaming interface. Step 103: To enroll in the network 10, the UE 1 requests an IMSI from the TIC / TAC card 4. Step 104: the TIC / TAC card 4 returns the value of the e-IMSI1, calculated in step 102. Step 105: the UE 1 seeking to connect to the first network 10, sends an attachment request to the MME 16. This attachment request includes the e-IMSI1. Step 106: Following receipt of the attachment request, the MME 16, noting that the e-IMSI1 does not correspond to an IMSI associated with the first network 10, sends an authentication request on its external interface 70 to the HSS 18.Step 107: the TIC / TAC server 51, connected to the external interface 70, intercepts the authentication request. The TIC / TAC server 51 requests in response from the TIC / TAC card 4 its EID in order to be able to identify it as one of the subscribers to the dynamic identifier allocation service. This request is masked in a conventional authentication request. Step 108: an authentication request is transmitted from the TIC / TAC server 51 to the MME 16. Step 109: an authentication request is transmitted from the MME 16 to the UE 1. Step 110: an authentication request is transmitted from the UE 1 to the TIC / TAC card 4. Step 111: following receipt of the authentication request, the TIC / TAC card 4 reads the EID present in its memory 43 and encrypts it with the master key MK associated with the service. Step 112: The TIC / TAC card 4 responds to the authentication request from the UE 1 by passing it the encrypted EID, MK(EID).Step 113: UE 1 responds to the authentication request from MME 16 with a standard authentication failure message. This message includes the encrypted EID. Step 114: MME 16 transmits an authentication failure message on its external interface 70. This message is intercepted by the TIC / TAC server 51. Step 115: Equipment 64, which has the master key MK, decrypts the EID. It checks that the EID is present in the list of EIDs of the subscribers to the service. If the received EID is not in the list of EIDs (or corresponds to a stolen EID), a command is sent to the TIC / TAC card 4 of UE 1 to block its PIN and only the use of a PUK code for this EID will allow UE 1 to be unblocked.

[0080] If the received EID is listed in the EID list as subscribed to the service, the equipment 14 selects a temporary IMSI, t-MSI, from the IMSI pool.

[0081] The TIC / TAC server 51 of the equipment 64 encrypts the t-IMSI using the master key MK and transmits to the TIC / TAC card 4 the encrypted t-IMSI, MK(t-IMSI), as well as a random number RAND, and an encryption result XRES. This transmission is carried out by masking this information in a new authentication request from the TIC / TAC card 4.

[0082] Step 116: an authentication request is thus transmitted from the TIC / TAC server 51 to the MME 16.

[0083] Step 117: MME 16 retains the XRES and retransmits the authentication request to UE 1.

[0084] Step 118: The authentication request is retransmitted from UE 1 to TIC / TAC card 4.

[0085] Step 119: TIC / TAC 4 card calculates a RES result from RAND and t-IMSI.

[0086] Step 120: the TIC / TAC 4 card responds to the authentication request from the UE 1 with a message including the RES result.

[0087] Step 121: UE 1 responds to the authentication request from MME 16 with a message including the RES result.

[0088] Step 122: The MME compares the RES and the XRES.

[0089] Step 123: these quantities being identical, the MME 16 retransmits the authentication response on the external interface 70. The authentication response is intercepted by the TIC / TAC server 51.

[0090] Step 124: The TIC / TAC server 51 returns an authentication error message to the MME 16.

[0091] Step 125: MME 16 rejects UE 1's attachment request.

[0092] From the point of view of the MME 16, that is to say of the first network 10, there was therefore only an exchange of authentication messages which led to an authentication failure, whereas the equipment 64 was able to recover the IMEI and the EID of the TIC / TAC card 4 and the latter a temporary IMSI.

[0093] Step 126: the TIC / TAC 51 server (SG 53 sub-module) calculates, from the t-IMSI assigned to the TIC / TAC 4 card, the master key MK, and the random number RAND sent to the TIC / TAC 4 card, a Ki1 and an OPc1.

[0094] The TIC / TAC server 51 transmits these credentials to the orchestrator 60 so that it can provision, via the link 71, the HSS 18 with the information of this new user, which is the TIC / TAC card 4 of the UE 1. The equipment 64 provides the t-IMSI (possibly t-ICCID), the IMEI, the Ki and the OPc. It also and preferably indicates the IT or telecommunications resources in order to meet the user's needs.

[0095] Step 127: The TIC / TAC 4 card stores the t-IMSI in place of e-IMSI1 and calculates the Ki1 and OPc1, with its master key MK and the random number RAND received from the TIC / TAC 51 server.

[0096] Finally, the TIC / TAC 4 card commands a restart of the radio module 5 which will allow an attachment to the HSS 18 with the t-IMSI. Advantageously, the TIC / TAC 4 card checks that this connection remains temporary and does not extend beyond, for example, two minutes.

[0097] Step 128: The TIC / TAC 4 card refreshes the information from the radio module 5 of the UE 1 by indicating the t-IMSI.

[0098] Step 129: UE 1 seeking to connect to the first network 10, sends an attachment request to the MME 16. This attachment request includes the t-IMSI.

[0099] Step 130: Following receipt of the attachment request, the MME 16 sends an authentication request on its external “roaming” interface 70. This attachment request includes the t-IMSI.

[0100] Step 131: HSS server 18, now properly provisioned with the temporary profile of UE 1, responds with an authentication request message with the RAND, XRES, AUTN parameters necessary for mutual authentication to be performed at MME 16.

[0101] Step 132: Some of these parameters are stored by the MME 16 while it retransmits the others in the authentication message to the UE 1.

[0102] Step 133: The authentication message is retransmitted from UE 1 to TIC / TAC card 4.

[0103] Step 134: the TIC / TAC 4 card, after positive verification of the XAUTN, calculates a RES.

[0104] Step 135: TIC / TAC card 4 transmits the RES to UE 1.

[0105] Step 136: UE 1 transmits the RES to MME 16.

[0106] Step 137: the MME compares the RES and the XRES, and, these two quantities being effectively identical, the MME 16 accepts the attachment of UE 1.

[0107] Step 138: Conventionally, once the attachment is accepted, the MME 16 transmits to the HSS 18 location information for the UE 1.

[0108] Steps 139-140: once the UE 1 is attached to the first network with its temporary profile (t-IMSI), a strong authentication procedure is preferably implemented. For example, the UE 1 authenticates itself with the orchestrator 60 and the AAA service 57 (exchange of Cer certificates in accordance with the EAP-TLS protocol), via the link 73. In the event of positive authentication, the UE 1 can benefit from the services managed by the equipment 64, in particular access to the resources of the second network 20.

[0109] In particular, the method continues by establishing a secure tunnel through the first network 10, between the UE 1 and the PGW 19 (suitably controlled by the orchestrator 60).

[0110] Step 141: the TIC / TAC 4 card then transmits its diversified keys MK1 and MK2 to the orchestrator 60 (via the PGW 19 and the link 73). At this moment, the orchestrator 60 therefore knows the EID and the keys MK1 and MK2 of the TIC / TAC 4 card.

[0111] Step 142: The TIC / TAC 4 card automatically detaches from the network 10 in order to close the secure tunnel. Second phase

[0112] Step 201: EU 1 restarts.

[0113] Step 202: The TIC / TAC 4 card then randomly calculates a second IMSI, e-IMSI2.

[0114] Step 203: UE 1 requests an IMSI from TIC / TAC card 4.

[0115] Step 204: The TIC / TAC 4 card sends the e-IMSI2 value.

[0116] Step 205: UE 1 seeking to connect to the network, sends an attachment request to the MME 16 of the first network 10. This attachment request includes the e-IMSI2.

[0117] Step 206: Following receipt of the attachment request, the MME 16 issues an authentication request to the HSS 18.

[0118] Step 207: The TIC / TAC server 51, which listens on the external interface 70, intercepts the authentication request.

[0119] Step 208: TIC / TAC server 51 then requests the UE 1 for the ElD of the TIC / TAC card 4. This request is hidden in an authentication request.

[0120] Step 208: An authentication request is transmitted from the TIC / TAC server 51 to the MME 16.

[0121] Step 209: An authentication request is transmitted from MME 16 to UE 1.

[0122] Step 210: An authentication request is transmitted from UE 1 to TIC / TAC card 4.

[0123] Step 211: The TIC / TAC 4 card reads its EID and encrypts it with its master key MK.

[0124] Step 212: The TIC / TAC card 4 responds to the authentication request from the UE 1 by passing it the encrypted EID, MK(EID).

[0125] Step 213: UE 1 responds to the MME 16 authentication request with a standard authentication failure message. This message masks the encrypted EID as an attribute: MK(EID).

[0126] Step 214: MME 16 transmits an authentication failure message to HSS 18. This message is intercepted by the TIC / TAC server 51.

[0127] Step 215: The TIC / TAC server 51 decrypts the EID. The TIC / TAC server 51 queries the orchestrator 60 to find out if it has the diversified keys for this EID and, if so, receives the corresponding information as well as a definitive IMSI, d-IMSI, chosen from the IMSI pool. The TIC / TAC server 51 encrypts the d-IMSI using the key MK1 in order to transmit it to the TIC / TAC card 4, as well as a random number RAND and an encryption result XRES.

[0128] This transmission is carried out by means of a new request for authentication of the TIC / TAC 4 card.

[0129] Step 216: An authentication request is then transmitted from the TIC / TAC server 51 to the MME 16.

[0130] Step 217: MME 16 retains the XRES and retransmits an authentication request to UE 1.

[0131] Step 218: An authentication request is transmitted from UE 1 to TIC / TAC card 4.

[0132] Step 250: in parallel, the TIC / TAC 51 server calculates, with the MK2 key of the TIC / TAC 4 card and the transmitted random number RAND, a second set of credentials, Ki2 and an OPc2.

[0133] Step 251: the equipment 14, via the link 71, deprovisions the t-IMSI from the HSS server 18 and provisions, via the link 71, the HSS server 18. The equipment 14 indicates the identifiers of the new user: d-IMSI, IMEI, Ki2 and the OPc2. Other information of the user profile can advantageously be recorded in the HSS 18, such as the services or resources associated with this new user.

[0134] Step 219: The TIC / TAC 4 card calculates a RES result from the RAND and the d-IMSI.

[0135] Step 220: the TIC / TAC 4 card responds to the authentication request from the UE 1 with a message including the RES result.

[0136] Step 221: UE 1 responds to the authentication request from MME 16 with a message including the RES result.

[0137] Step 222: MME 16 compares the RES and the XRES.

[0138] Step 223: these quantities being identical, the MME 16 retransmits the authentication response to the HSS 18. The authentication response is intercepted by the TIC / TAC server 51.

[0139] Step 224: The TIC / TAC 51 server responds with an error message to MME 16.

[0140] Step 225: MME rejects UE 1's attachment request.

[0141] Step 227: the TIC / TAC 4 card, having retrieved the d-IMSI, stores it in place of the e-IMSI2. Then the TIC / TAC 4 card calculates Ki and OPc credentials with its MK2 key and the random number RAND received from the equipment 14. Finally, the TIC / TAC 4 card orders a restart of the radio module 5 which will allow an attachment to the HSS 18 with the d-IMSI received.

[0142] Step 228: the TIC / TAC 4 card orders a refresh of the profile information used by the radio module 5 of the UE 1 by indicating the value of the d-IMSI.

[0143] Step 229: The UE 1 connects to the first network 10 by sending an attachment request to the MME 16. This attachment request includes the d-IMSI.

[0144] Step 230: Following receipt of the attachment request, the MME 16 sends an authentication request to the HSS 18. This attachment request includes the d-IMSI.

[0145] Step 231: the HSS server 18, which has been provisioned with the final profile of this user, responds with a confirmation message with the RAND, XRES, AUTN parameters necessary for mutual authentication carried out at the MME 16 level.

[0146] Step 232: Some of these parameters are stored by the MME 16 while the MME 16 retransmits the others in the authentication message to the UE 1.

[0147] Step 233: The authentication message is retransmitted from UE 1 to TIC / TAC card 4.

[0148] Step 234: the TIC / TAC 4 card, after calculating the XAUTN and verifying that it corresponds to the AUTN, calculates the RES.

[0149] Step 235: TIC / TAC card 4 transmits the RES to UE 1.

[0150] Step 236: UE 1 transmits the RES to MME 16.

[0151] Step 237: the MME compares the RES and the XRES and, these two quantities being effectively identical, the MME 16 accepts the attachment of UE 1.

[0152] Step 238: conventionally, once the attachment is accepted, the MME 16 transmits to the HSS 18 location information for the UE 1.

[0153] Thus, following the detection by the service equipment 64 of a request to enroll a new terminal with the first mobile telephone network, a profile (including an ephemeral IMSI and associated credentials) was generated by the identifier management equipment 64. In parallel with the transmission to the terminal of this profile, an HSS server associated with the first network was provisioned with this profile. This allows enrollment of the mobile terminal on the first network with an ephemeral profile.

[0154] Many variations of this part of the process are possible. In particular, one could implement only the first part, if it is considered that the transmission of an ephemeral IMSI (t-IMSI) by encryption with a shared key (master key MK) offers a sufficient level of security.

[0155] Furthermore, when a new terminal seeks to register by indicating an EID (or a certificate) to the equipment 64, the verification that this EID (this certificate) is that of a subscriber who can benefit from the service may include a control step carried out manually by an operator, via a human-machine interface connected to the equipment 64. Origin virtual IP assignment

[0156] In step 86, for the dynamic allocation of an IP address to the UE 1, or virtual IP origin IPvo, the equipment 64 implements the IPAM module 56. The mechanism implemented is known per se. It makes it possible to allocate an IP address to the UE1 from the reserve of IP addresses, Pool_IPvo, of the database 65. The equipment 64 transmits the chosen IPvo to the ePC 15, which in turn transmits it to the UE 1. Destination virtual IP assignment

[0157] In step 88, for the dynamic allocation of an IP address to the recipient, or virtual IP recipient IPvd, the equipment 64 implements for example the mechanism presented in patent application FR n° 20 09408, filed on September 17, 2020. The DNS 55 and Proxy DNS 54 modules are used in particular.

[0158] Associated with the IP address of UE 1 (IPvo) is a list of virtual IP addresses (L_IPvd) of possible recipients of UE 1. These virtual addresses for the recipients are chosen from the pool of IP addresses, Pool_IPvd.

[0159] The actual IP address of the recipient IPrd, i.e. of the machine running applications 21, 22 or 23, is never communicated to a UE, but is replaced by a virtual IP address, which is temporary and unique per UE registered with the service, and which, preferably, is only valid for the duration of the session between this UE and the recipient.

[0160] Advantageously, the equipment 64 determines virtual addresses to be associated with the UE 1 only when the UE 1 sends a domain name resolution request to the DNS 55. The response to such a request is the virtual IP address of the desired recipient.

[0161] Preferably, the equipment 64 only determines virtual addresses for the applications that the user of the UE 1 has the right to consult.

[0162] The equipment 64 is capable of configuring the FW / NAT firewall 29 to substitute, in a packet entering the second network 20, the virtual address of an application with its real address and conversely in a packet leaving the second network 20, the real address of an application with its virtual address.

[0163] The equipment 64 is capable of configuring the router(s) 28 of the second network 20 to direct the data flows. For example, if the equipment 64 detects suspicious data flows usurping the identities of certain UEs subscribed to the service, it can configure the routers 28 to send these flows to decoy applications.

[0164] It is the orchestrator 60 which maintains a correspondence table between the real and virtual identity of a source, and, for this source, a corresponding table between the real and virtual identity of a destination.

[0165] Finally, after these steps, UE 1 can establish communication with the desired application. VARIANTS

[0166] The embodiment described above is that of an identifier management device 64 cooperating with a second network 20 of the private network type and an HSS 18. However, numerous alternative implementations are possible.

[0167] Alternatively, the device 64 cooperates with a BSS / OSS (“Business Support System / Operations Support System”) in addition to or instead of an HSS. This can, for example, calculate the credentials of the new user instead of the SG sub-module 53, which is then no longer necessary.

[0168] Alternatively, the TIC / TAC server 51 is on the first network 10 or on the second network 20.

[0169] The second network can be a mobile phone network (or at least the core of such a network).

[0170] Alternatively, the recipient is another UE on the first network or another mobile network. BENEFITS

[0171] The present invention makes it possible to locally and dynamically manage the subscription of a mobile terminal to a mobile telephone network and to allocate to this terminal (as well as to the recipient of its communications) an ephemeral identity (IMSI, IMEI, IP, Ki, OPc, etc.)

[0172] By ephemeral we mean information with a limited validity over time (i.e. short lifespan).

[0173] Allocating a new identity or updating an identity can be done at any time.

[0174] The allocation of an ephemeral, untraceable identity then allows strong authentication to be carried out, giving the authorized mobile terminal the ability to access critical resources, for example hosted on a private network.

[0175] The implementation of the invention therefore allows for real discretion in exchanges.

[0176] The prior art requires the implementation of provisioning servers, for example SMDP, which are generally centralized and do not allow the dynamic creation of subscriber profiles and more generally theater provisioning.

[0177] The invention therefore makes it possible to simplify the management of the provisioning of profiles in the eUICC of the terminals, as well as the configuration of the network cores with these profiles.

[0178] The invention makes it possible to synchronize enrollment with access to critical services and to dynamically manage the ephemeral nature of communications.

[0179] The invention makes it possible to control the uniqueness of each ephemeral communication. No duplication of a communication in whole or in part is possible.

[0180] No pre-registration is required at the mobile terminal level, nor at the TIC / TAC server level (apart from an IMSI reserve). HSS provisioning is dynamic via the credential management equipment. This allows for high resilience to terminal theft (i.e. EID and MK).

Claims

1. A method for dynamic allocation of identifiers (80), the method consisting in allocating at least one subscription identifier (IMSI) to an embedded universal integrated circuit card - eUICC (4) residing in an item of user equipment - UE (1), the method consisting in transmitting, by an item of identifier management equipment (64), through a first mobile telephone network (10) of which a radio interface (11) is used by the UE (1) to make an authentication request which will not lead to an attachment to the network, a subscription identifier (IMSI) in a field of a message exchanged in accordance with a standard attachment protocol of a roaming terminal on the first mobile telephone network (10), the identifier management equipment (64) being connected to an external roaming interface (70) of the first mobile telephone network (10), the transmitted subscription identifier (IMSI) having been selected by the identifier management equipment (64) from a pool of previously defined subscription identifiers, the method further consisting in creating, by means of the identifier management equipment (64), a specific subscriber profile for the eUICC (4) and updating a subscriber service with said subscriber profile, said subscriber profile incorporating the subscription identifier allocated to the eUICC.

2. The method according to claim 1, consisting in transmitting to the eUICC (4) a temporary subscription identifier and creating a temporary subscriber profile, allowing the UE (1) to attach itself to the first mobile telephone network (10), the method further consisting in implementing a strong authentication procedure between the eUICC (4) and the identifier management equipment (64).

3. The method according to claim 2, consisting, once the eUICC (4) has been authenticated, in establishing a secure link allowing an exchange of diversified keys from the eUICC to the identifier management equipment (64), then in transmitting to the eUICC a definitive subscription identifier and creating a definitive subscriber profile, these transmission and / or creation steps using the diversified keys exchanged.

4. The method according to any one of claims 1 to 3, wherein the eUICC (4) and the identifier management equipment (64) exchange encryption parameters making it possible to calculate credentials on both sides, said subscriber profile incorporating said credentials.

5. The method according to any one of claims 1 to 4, wherein the identifier management equipment (64) recognizes an eUICC (4) to which to provide an identifier from an identifier of the eUICC received from the eUICC and present in a list of eUICC identifiers stored by the identifier management equipment (64).

6. The method according to any one of claims 1 to 5, further comprising a step (82) for dynamic allocation of an equipment identifier (IMEI) to a radio module (5) of the UE (1).

7. The method according to any one of claims 1 to 6, further comprising a step (86) for dynamic allocation of a virtual IP address for the UE (1) as the source of a communication.

8. The method according to any one of claims 1 to 7, further comprising a step (88) for dynamic allocation of a virtual IP address for each recipient with which the UE (1) has the right to communicate.

9. A system for implementing the method for dynamic allocation of identifiers (80) according to any one of the preceding claims, comprising: - an item of user equipment - UE (1), the UE (1) using a radio interface (11) of a first mobile telephone network (10) to connect; - an embedded universal integrated circuit card or card - eUICC (4) residing in the UE (1); and - an item of identifier management equipment (64) connected to an external roaming interface (70) of the first mobile telephone network (10), the identifier management equipment (64) being able to: allocate to the eUICC (4) a subscription identifier selected from a pool of subscription identifiers stored by the identifier management equipment (64); transmit the allocated subscription identifier to the eUICC (4) in a field of a message exchanged in accordance with a standard attachment protocol of a roaming terminal on the first mobile telephone network (10); create subscriber profile (1) specific to the eUICC (1); and update a subscriber service with said subscriber profile, said subscriber profile incorporating the subscription identifier allocated to the eUICC.

10. The system according to claim 9, wherein the identifier management equipment (64) is associated with a subscriber server - HSS (18) providing said subscriber service.