Method, device and system for checking the validity of a message
Patent Information
- Application Number
- EP2023758692
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-09-01
- Filing Date
- 2023-08-30
- Publication Date
- 2025-07-09
AI Technical Summary
Existing data infrastructures in communication networks face challenges in ensuring that messages exchanged between functions comply with specific requirements and security standards, particularly when managed by distinct actors, leading to potential non-conformity and security issues.
A method and system for validating messages by using signed digital proofs that include an identifier of a certification register, an entity certification identifier, and a validity parameter, allowing the receiving function to verify the signature, integrity, and compliance with required characteristics, ensuring that the message meets communication network and service requirements.
This approach ensures that functions in a communication network validate messages step-by-step, guaranteeing compliance with security, quality of service, and location requirements, thereby validating the chain of functions and the implemented service, even when managed by separate entities.
Smart Images

Figure 1.1
Abstract
Description
[0001] DESCRIPTION
[0002] Title of the invention: Method, device and system for checking the validity of a message
[0003] 1. Technical field
[0004] The invention is implemented in a data infrastructure, this infrastructure possibly being instantiated by a plurality of actors involved in the provision of a communication service. The invention aims more specifically to ensure that a function (or module or device) of the infrastructure receiving a message from another function can ensure the conformity of the message, and consequently of the transmitting function, to a set of requirements specific to the infrastructure and to the communication service.
[0005] 2. State of the art
[0006] According to known techniques, data infrastructures are known and make it possible in particular to provide a service to a customer by relying on the contribution of one or more actors pooling resources such as functions (equipment, modules). The provision of the service requires the provision by the actors of data useful for the provision of services. Furthermore, communication networks increasingly rely on functions, including virtualized functions, possibly administered by separate actors. Thus, for example, in fifth-generation communication networks, network or value-added functions initially defined as unitary functions, for example implemented in specific equipment, are increasingly implemented by interconnecting elementary functions composing a unitary function.A network function is therefore increasingly in the form of a set of interconnected elementary functions communicating with each other. These elementary functions are also possibly managed by separate entities. Thus, the network data analysis function, NWDAF (Network Data Analytics Function), which allows in particular the collection of data relating to a user, a network function, or a maintenance and management function, can be implemented from distributed software functions. The NWDAF function interacts with different entities of a communication network such as the AMF (Access and Mobility Function), SMF (Session Management Function), PCF (Policy Control Function), UDM (Unified Data Management) and AF (Application Function) entities.This NWDAF entity, when structured into several elementary functions, also requires message exchanges between these elementary functions. Thus, as described in 3GPP TS 29.520 release 17 of September 2020 and 3GPP TS 23.288 release 17 of March 2021, the NWDAF function can be decomposed into an AnLF (Analytics Logical Function) in charge of data analysis and inference and the provision of statistics and an MTLF (Model Training Logical Function) in charge of instantiating and training new training models for data analysis. In addition, particularly when the data source and the entity in charge of exploiting an analysis result are not managed by the same actor, then the analysis data are transmitted between the functions via a NEF (Network Exposition Function).The elementary functions of an NWDAF can also interact with a DCCF (Data Collection and Coordination Function) in charge of data collection and coordination of data recipients, for example when several functions require the same data or when several NWDAF entities, possibly composed of distributed elementary functions, are deployed in a communication network.
[0007] In addition to the example of an NWDAF function requiring an exchange of messages between several functions of a communication network, it should be noted that mobile network access analysis functions of the SON (Self Organizing Network) type, mobile network data analysis management functions MD AF (Management Data Analytic Function), services for analyzing information collected on mobile network terminals by DCAF (Data Collection AF) functions can be implemented from elementary functions or modules requiring exchanges of messages between the modules and with other entities of a communication network such as the function or functions constituting an NWDAF function. Services based on storage and processing of data on access (Edge Computing) represent another environment requiring exchanges between possible entities managed by separate actors.Thus, an Edge Computing environment includes Cloud functions EAS (Edge application Server), EES (Edge enabler Server), ECS (Edge configuration Server) and Cloud clients in the terminal EEC (Edge Enabler Client) and AC (Application Client).
[0008] However, these message exchanges generated in particular by the distribution of elementary functions possibly managed by different actors, depending on the state of the art, are likely not to comply with specifications common to a data space and / or a communication network, or even not to comply with security requirements issued by a regulator and / or a manager of the communication network. It is not possible, according to the techniques currently used, for a function receiving a message from another function to ensure that the message received complies with one or more requirements of the communication network and / or of a service whose data is routed or processed by the functions.
[0009] The present invention aims to provide improvements over the state of the art.
[0010] 3. Statement of the invention
[0011] The invention improves the situation using a method for checking the validity of a message sent by a first function to a second function, the two functions contributing to the instantiation of a service in a communication network, the method being implemented in the second function, capable of analyzing a message comprising a signed digital credential, the signed credential comprising an identifier of a certification register of the communication network, an identifier of a certification entity and a validity parameter of a characteristic relating to the service of the first function, and comprising:
[0012] - receipt of the message including the signed digital proof associated with the characteristic of the first function relating to the service,
[0013] - obtaining from the certification registry determined from the identifier received from decryption data associated with the identifier of the certification entity,
[0014] - a determination of the validity of the message received including:
[0015] - verification of the signature and integrity of the digital proof signed by the certification entity using the decryption data obtained,
[0016] - a comparison of the validity parameter of the signed digital credential with a required value associated with at least one characteristic.
[0017] A function of a communication network, which can also be called a module, equipment or virtualized instance, can contribute to the provision of a service in a communication network, such as an application service intended for a user or a network service, if it meets one or more requirements specific to the service in general, therefore also to the communication network, or even to the user. Thus, the function must obtain from a certification entity a signed digital credential, which can also be called a certificate, or proof or token, associated with a characteristic of the function, guaranteeing that the characteristic is indeed approved by a certification entity and that the function can effectively contribute to the service. A function may require the approval of several characteristics from one or more certification entities.Knowing that the other functions, with which the function exchanges messages for the implementation of the service, have no information on the approval received or not, the method makes it possible to inform them and allows them to effectively verify that the function having transmitted to them a data message relating to the service, has indeed obtained one or more certifications or approvals for all the characteristics requiring such certification. The method is particularly useful when the functions are managed by separate actors and the functions have no other means a priori of informing each other of their respective certifications.Thus, the two functions can exchange signed digital credentials via a file attached to a service-related data message, and the receiving function can verify this agreement by comparing the data present in the file with reference values and by verifying the signature of the credential by means of decryption data obtained from a registry managing the characteristic decryption data. This data makes it possible to verify the signature, the fact that the credential has not been modified and that values, for example binary elements or a sequence of numbers, concerning the characteristic conform to values required for the message received from the first function, and subsequently the function, to be validated.The receiving function, identified as the second function, must be able to unambiguously determine that a signed digital credential associated with a characteristic received from another function, the sending function or the first function, is intrinsically linked to a certification of the characteristic by a certification entity of the communication network. The validity of the signature and the values of the signed digital credential implies the validity of the message comprising the signed digital credential since the signed digital credential informs the receiving function about the certification of characteristics of the sending function. The validity of the message sent by the first function also allows the first function to be validated by the second function.For a service developed by a chain of functions, the validation of messages step by step by the functions makes it possible to validate the chain, the functions involved, and therefore consequently the service implemented.
[0018] According to one aspect of the invention, in the control method, the two functions are elementary modules of a device of the communication network. The method is particularly advantageous in a context where the two functions constitute two elements of a device or equipment. In particular, if the two modules are virtualized functions and they are possibly administered by separate managers, the method makes it possible to guarantee that each module complies with a set of security, quality of service, location, etc. requirements and that the service implemented by the different modules corresponds to a service implemented by a corresponding physical device or equipment, comprising the different modules within the same physical entity.
[0019] According to another aspect of the invention, in the control method, the validity parameter of a characteristic is one or more parameters among the following parameters:
[0020] - a maximum validity date for the signed supporting document,
[0021] - a non-revocation parameter for the signed digital proof,
[0022] - an identifier of the characteristic.
[0023] Advantageously, the validity parameter of the signed digital credential may include a maximum validity date of the signed digital credential and the first function by comparing the maximum date and the date of receipt may consider whether the received message is valid or not. The parameter may also be non-revocation information represented by a binary element. By comparing this binary element with a reference value, the second function may determine whether the credential is valid or not. The identifier of the characteristic, compared for example with an identifier obtained from a management entity, makes it possible to detect for example identity theft and not to validate the message if these identifiers do not correspond for example.
[0024] According to another aspect of the invention, in the control method, the decryption data is a public decryption key associated with a private encryption key relating to the certification entity.
[0025] The digital credential may be signed with an encryption key associated with the certification entity that certified the characteristic corresponding to the signed digital credential. Thus, according to one example, the signed digital credential may be a hash encrypted with a private encryption key. The second function, using for example a public key associated with the private encryption key, may decrypt the hash and then determine whether the decrypted hash has the same value as the hash calculated by the second function and thus verify the signature and integrity of the credential. According to another aspect of the invention, in the control method, determining the validity of the data further comprises revoking the first function in the case where the signature and integrity of the signed digital credential are not verified and / or the validity parameter of the signed digital credential is not equivalent to the required value.
[0026] In the case where the signature of the signed digital credential cannot be verified, because the value of the decrypted hash does not correspond to a value calculated by the second function, and / or if the integrity of the received message is not respected and / or one of the values of the credential does not correspond to an expected value, the message is not validated. This may be due to a revoked certificate or because the first function sending the message is not what it claims to be, and for example, a function has usurped the identity of another function. If one or more characteristics of the first function cannot be certified, then it is revoked and message exchanges with this function are interrupted.
[0027] According to another aspect of the invention, in the control method, said signed digital proof comprises information on the location of a revocation register, said revocation register being capable of recording validity information relating to a characteristic of the first function.
[0028] The signed digital credential may advantageously include location information, such as an IP address or a DNS name, from a revocation registry, thus enabling the second function to inquire from this registry whether data is still valid or whether a certificate obtained by the first function from the certification entity is still valid and thus have up-to-date information on the ability of the first function to continue sending and receiving messages associated with the service. The second function may also use this information to inform the revocation registry about an invalid signed digital credential and subsequently about a certification of a characteristic to be renewed.
[0029] According to another aspect of the invention, in the control method, the characteristic relating to the service of the first function is one or more of the following characteristics:
[0030] - a safety feature of the first function,
[0031] - a characteristic of conformity of the message with a data format of a specific function of the communication network,
[0032] - a location characteristic of the first function, - a consent characteristic of a user of the service for the use of data relating to a user of the service, included in the message,
[0033] - a characteristic of conformity of the first function with a rule determined by a regulatory entity of the communication network,
[0034] - an identifying characteristic of a legal entity in charge of the first function.
[0035] For a function to be compliant with a service, a communication network, a user or a data space comprising a plurality of functions, it may have to comply with a set of characteristics. The certification entity responsible for assigning a certificate for a characteristic may be specific or responsible for certifying a plurality of characteristics. In the latter case, the certification entity assigns respective certificates for a set of distinct characteristics. The characteristics may be imposed by a requirement of a user of the service, an external entity responsible for verifying, for example, the security of the implementation of the service, a message format verification body, an actor or operator responsible for managing the communication network and / or providing the service.
[0036] According to another aspect of the invention, in the control method, said determination of validity comprises the transmission to the certification register of the signed digital proof and an identifier of the first function, and the reception, following this transmission, of the decryption data associated with the certification entity.
[0037] The determination may advantageously comprise an exchange of messages between the second function and the certification registry, allowing the second function to receive, upon explicit request, decryption data associated with the certification entity having certified the characteristic and possibly specific to the characteristic.
[0038] The various aspects of the control method that have just been described can be implemented independently of one another or in combination with one another. The invention also relates to a method for transmitting a message by a first function to a second function, the two functions contributing to the instantiation of a service in a communication network, the method being implemented in the first function, capable of attaching a signed digital credential to the message to be transmitted to the second function, the signed credential comprising an identifier of a certification register of the communication network, an identifier of a certification entity and a validity parameter of a characteristic relating to the service of the first function, and comprising:
[0039] - obtaining the signed digital proof from the certification entity,
[0040] - an addition of the signed digital proof obtained to the message relating to the service to be transmitted to a second function,
[0041] - a transmission to the second function of the message including the added signed digital proof.
[0042] According to one aspect of the invention, the transmission method further comprises a transmission to the certification entity of a request for certification of the characteristic and in that the signed digital proof obtained comprises certification information generated from encryption data associated with the certification entity.
[0043] The invention also relates to a device for checking the validity of a message sent by a first function to a second function, the two functions contributing to the instantiation of a service in a communication network, the device instantiated in the second function being capable of analyzing a message comprising a signed digital credential, the signed credential comprising an identifier of a certification register of the communication network, an identifier of a certification entity and a validity parameter of a characteristic relating to the service of the first function and comprising:
[0044] - a receiver, capable of receiving the message comprising the signed digital proof associated with the characteristic of the first function relating to the service,
[0045] - an obtaining module, capable of obtaining from the certification register determined from the identifier received a decryption data associated with the identifier of the certification entity,
[0046] - a determination module capable of determining the validity of the message (Mes) received comprising:
[0047] - a verification module, capable of verifying the signature and the integrity of the digital proof signed by the certification entity by means of the decryption data obtained and the identifier of the certification entity received,
[0048] - a comparator, capable of comparing the validity parameter of the signed digital proof with a required value associated with at least one characteristic.
[0049] This device is capable of implementing in all its embodiments the control method previously described. The invention also relates to a device for transmitting a message by a first function to a second function, the two functions contributing to the instantiation of a service in a communication network, the device implemented in the first function being capable of attaching to the message to be transmitted to the second function a signed digital credential, the signed credential comprising an identifier of a certification register of the communication network, an identifier of a certification entity and a validity parameter of a characteristic relating to the service of the first function, and comprising:
[0050] - an obtaining module, capable of obtaining signed digital proof from the certification entity,
[0051] - an addition module, capable of adding the signed digital proof obtained to the message relating to the service to be transmitted to a second function,
[0052] - a transmitter, capable of transmitting to the second function the message including the added signed digital proof.
[0053] This transmission device is capable of implementing in all its embodiments the transmission method which has been described above.
[0054] The invention also relates to a system for controlling the validity of a message sent by a first function to a second function, the two functions contributing to the instantiation of a service in a communication network, comprising
[0055] - a control device,
[0056] - a transmission device.
[0057] The invention also relates to computer programs comprising instructions for implementing the steps of the respective control and transmission methods which have just been described, when these programs are both executed by a processor and a recording medium readable respectively by a control device and a transmission device on which the computer programs are recorded.
[0058] The above-mentioned programs may use any programming language, and may be in the form of source code, object code, or intermediate code between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0059] The above-mentioned information carriers may be any entity or device capable of storing the program. For example, a carrier may include a storage medium, such as a ROM, for example a CD ROM or a microelectronic circuit ROM, or a magnetic recording medium.
[0060] Such a storage medium may, for example, be a hard disk, a flash memory, etc. On the other hand, an information carrier may be a transmissible medium such as an electrical or optical signal, which may be conveyed via an electrical or optical cable, by radio or by other means. A program according to the invention may in particular be downloaded from a network such as the Internet.
[0061] Alternatively, an information carrier may be an integrated circuit in which a program is incorporated, the circuit being adapted to perform or to be used in performing the methods in question.
[0062] 4. Brief description of the drawings
[0063] Other characteristics and advantages of the invention will appear more clearly on reading the following description of particular embodiments, given as simple illustrative and non-limiting examples, and the appended drawings, among which: [Fig 1] according to one aspect of the invention, describes a communication network in which the control method and the transmission method are instantiated.
[0064] [Fig 2] describes the implementation of the transmission method in a communication network according to one embodiment of the invention.
[0065] [Fig 3] describes the implementation of the control method according to one embodiment of the invention.
[0066] [Fig 4] describes a control device according to one embodiment of the invention.
[0067] [Fig 5] describes a transmission device according to one embodiment of the invention.
[0068] 5. Description of embodiments
[0069] In the remainder of the description, embodiments of the invention are presented in a communication network. This network can be implemented to route communication data to fixed or mobile terminals and the network can be implemented from physical equipment and / or virtualized functions. This network can be used for routing and / or processing residential or business customer data.
[0070] We first refer to [Fig 1] which presents a communication network in which the control method and the transmission method are instantiated. The functions implemented by a mobile communications network operator (MNO) are as follows: - A NF (Network Function) which can be any function of the mobile communications network ensuring the routing, processing or management of data from the mobile network, for example from or to a user of the mobile network. The NF function is for example a virtual function ensuring a routing, security, filtering or even an application function in the mobile network. These functions can for example transmit data specific to a communication service to analysis functions such as the DCCF and NWDAF functions described below. Only one NF function is represented but the MNO network can comprise several NF functions.
[0071] The Data Collection Coordination Function (DCCF) subscribes to the UDM / NRF / BSF (described below) to be notified of context information associated with a data flow to authorize analysis and / or collection of data associated with a user (such as GDPR consent). This DCCF collects and distributes data required by a NF "consumer". This function avoids multiple function subscriptions for identical data and sending notifications containing the same information.
[0072] - The UDM (Unified Data Management), NRF (Network Repository Function) and BSF (Binding Support Function) functions are respective functions for user management, NFs management and session management in a mobile communications network.
[0073] - The Messaging Framework Adaptor Function (MFAF) enforces the transfer policy defined by the DCCF. For example, data consumers and data sources exchange data through the MFAF function.
[0074] The communications network also includes the following functions:
[0075] - A NWDAF (Network Data Analytics Function) collects data from various functions, performs analyses of the collected data in order to propose adaptations of the functions for the services implemented on a communications network.
[0076] - An ADRF (Analytics Data Repository Function) is responsible for storing the collected data. It should be noted that the function can be broken down into two functions, namely the MTLF function described below and the AnLF (Analytical Logical Function) function not shown in [Fig 1]. This AnLF function is responsible for inferring a model, deriving data analyses from it and exposing these analyses to those requesting these analyses.
[0077] - An MTLF function (Model Training Logical Function) responsible for training a model and providing new training methods.
[0078] - The communications network further comprises certification entities CAF1, CAF2, CAF3, CAFn responsible for certifying characteristics of the various functions mentioned above. Several certification entities are possibly deployed to certify a plurality of characteristics of the functions. According to the example of [Fig 1], each certification entity certifies a characteristic and the entities CAF1, CAF2, CAF3, CAFn certify the respective characteristics Caractl, Caract2, Caract3, Caract4 associated with a communications service, the service possibly being an application service or a network service.The characteristics may correspond to security characteristics, location characteristics, compliance with a rule determined by a regulatory entity, consent of a user to the use of data from messages sent or received by this user, compliance with GDPR (General Data Protection Regulation) conditions, data storage conditions, etc. The CAF1, CAF2, CAF3, CAFn entities may be managed by various entities and an entity may certify a plurality of characteristics. Thus, each network function, as mentioned above, is certified by one or more CAF1, CAF2, CAF3 and CAFn certification entities when the function includes one or more of the Caractl, Caract2, Caract3, Caract4 characteristics.This certification is particularly important when the functions are managed by different actors and when these contribute to the routing of data in a data space, in which a plurality of actors possibly contribute by making functions available. Thus, each actor, which can be an operator or a service provider or a regulatory entity, has the guarantee that the functions involved in the routing of data associated with a service comply with a certain number of constraints and obligations.When a CAF1, CAF2, CAF3 and CAFn certification entity certifies a characteristic Caractl, Caract2, Caract3, Caract4 for a function among the functions NF, DCCF, MF AF, NRF, UDM, BSF, ADRF, NWDAF, MTLF, AnLF for a given service, following a request for said function, the certification entity issues to the function a signed digital credential associated with the characteristic for the service in question. Certain characteristics, in particular security or user consent characteristics, may be specific to a service while some are more generic and may be common to a plurality of services.The sending function, once it has obtained the various signed digital credentials, for example using a private encryption key, associated with the service, may attach them to the messages exchanged with the other functions so that the functions receiving the messages can check the validity of the message received. The message received by a receiving function may be a control message and may correspond to a message exchanged between functions of a “disaggregated” device, said functions preferably being virtualized.
[0079] The communications network also includes a Certif register of certificates, such as decryption data, associated with the characteristics. The register is updated by the various certification entities CAF1, CAF2, CAF3 and CAFn, making it possible to certify a characteristic for a function or to update its certification. The Certif register includes the up-to-date certificates and ensures the availability of up-to-date certificates, making it possible to determine the effective certifications of the various characteristics of functions contributing to a service in the communications network. A Certif certification register and a CAFn certification entity are separate entities. The Certif register includes the decryption data used to verify a signature of a signed digital credential assigned by the CAFn certification entity to a function of a communications network.
[0080] The signed digital credential transmitted by one function to another function may correspond to a certificate as held by the Certif registry or the signed digital credential may be relative to a certificate, i.e. the certificate may be used to contribute to the verification of the received message, by verifying the signature of the digital credential and the integrity of the signed digital credential.
[0081] Reference is then made to [Fig 2] which describes the implementation of the transmission method in a communication network according to one embodiment of the invention. In this embodiment, the NF entity, which can be any type of function of a communication network, interacts and sends / receives messages from other functions of the communication network. According to another example, the NF function can be replaced by a function of a disaggregated NWDAF, such as an AnLF function or an MTLF function, or it can be replaced by any function described in [Fig 1].
[0082] The NF function, in order to be integrated into the communication network and interact with the other functions of this network, must be certified, that is to say that different characteristics of the function must be verified according to a service to be implemented in the communication network. Some characteristics of the function are independent of this service while some of them are relative to the service to be instantiated. Thus, for example, the location of the function is most often independent of the service while a data format is linked to the service to be instantiated. A characteristic is considered to be relative to a service even if the same characteristic can be common to several services. The service can be a communication network control service or a value-added service (voice, text, video).
[0083] In order to be certified for a service, the NF function requests, prior to implementing the service, a certification entity responsible for certifying that a characteristic of the NF function is compatible with the service and the communication network. Knowing that a plurality of characteristics are possibly to be certified, the NF function requests one or more certification entities associated respectively with distinct characteristics. Thus, the NF function requests the entities CAF1, CAF2, CAF3 and CAFn to certify four characteristics required for the implementation of a service. The certification entities CAF1, CAF2, CAF3 and CAFn can be managed by a single or several actors. For example, one certification entity can be managed by a regulatory entity and another can be managed by a security auditor.This certification is particularly useful when the functions likely to exchange messages are themselves managed by separate actors and each actor must ensure the conformity of the functions of the other actors.
[0084] During a step E1, the NF function, which according to this example is a disaggregated function of an NWDAF function, transmits a certification request message for a location characteristic to the CAF1 entity. The certification request message includes information relating to the location of the NF function, and possibly a service identifier, and in response to this request, the CAF1 entity performs an audit during a step E2 to ensure that the location indicated by the NF function is indeed that indicated in the certification request.This audit may include the sending and receiving of several messages between the NF function and the CAFE entity. When the audit determines that the location of the NF function is validated and corresponds to a parameter of the service to be instantiated, then the CAF1 entity certifies the characteristic and transmits a certificate, necessary to attest to the conformity of this location characteristic, to a Certif certification registry during a step E3. The certificate transmitted to the Certif registry may correspond to a token and / or a public decryption key corresponding to a private key associated with the CAF1 entity and possibly to the characteristic.This certificate then makes it possible to attest a signed digital credential, including one or more parameters relating to a characteristic, transmitted by a function to another function during message exchanges relating to a communication service for which one or more characteristics are certified. According to another example, the certificate registered in the Certif registry corresponds to a public certificate containing a public security key. According to an example, the certificate is as indicated below: Token: { " @ context" : [.
[0085] "https: / / w.w3.org / 2018 / credent i al s / vl",
[0086] "https: / / www.w3.org / 2018 / credenti ls / examples / vl"
[0087] ] ,
[0088] "id": "http: / / example.edu / credentials / 3732",
[0089] "type": ["Ver if iableCredential", "UniversityDegreeCredential"], "issuer": "https: / / example.edu / issuers / 14", "issuanceDate": "2010-01-01T19:23:24Z", "credentialsubject": {
[0090] "id": "did: example: ebfeblf 712ebc6f lc276el2ec21", "degree": {
[0091] "type" : "BachelorDegree" , "name" : "Bachelor of Science and Arts"}} ,
[0092] The token contains
[0093] The address or certificate is registered "id": "http: / / example.edu / credentials / 3732",
[0094] - The certificate type: [ "VerifiableCredential" ,
[0095] - The address of the certifier's identity: "issuer": "https: / / example. edu / issuers / 14",
[0096] When it was issued: "issuanceDate": "2010-01-01T19:23:24Z",
[0097] - The address or certificate is registered to prove the subject of the certificate here bachelor degree "type": "BachelorDegree", "name": "Bachelor of Science and Arts" In [Fig 2], only one Certif register is described but it is possible to have several certification registers, for example associated with separate certification entities.
[0098] During step E4, the Certif certification register attests to the CAF1 entity the correct receipt and registration of the certificate received from said CAF1 entity by sending it an acknowledgment message.
[0099] During a step E5, the CAF1 entity transmits to the NF function the signed digital proof of the certified characteristic. This signed digital proof includes an identifier of the Certif certification register, an identifier of the CAF1 certification entity and one or more validity parameters of the location characteristic, the signed digital proof being signed with encryption data specific to the CAF1 certification entity and possibly to the location characteristic.
[0100] Correspondingly, the NF function certifies a security-related characteristic for the service to be instantiated with the certification entity CAF2 during steps E' 1 to E' 5 corresponding to steps E1 to E5 cited previously. According to an alternative, the entity CAF2 and the entity CAF1 are a single entity. The entity CAF2 is managed by an actor other than the one managing the entity CAF1 and aims to ensure that the NF function complies with security constraints, for example in terms of supported security protocols and / or compliance with confidentiality constraints. If the NF function complies with the security conditions as prescribed by the entity CAF2, in accordance with the requirements of the communication network in which the NF function is deployed and / or a contract signed with other actors for the instantiation of the service, it obtains signed digital proof relating to the security characteristic.
[0101] Correspondingly, the NF function requests certification during steps E” 1 to E” 5, corresponding to steps E1 to E5, a characteristic relating to compatibility with a specification of the communication network in which the service is to be instantiated. According to one example, the NF function obtains certification from the CAFn entity attesting to the compatibility of the NF function with a 3GPP Release 17 specification. The CAFn entity is, according to this example, an entity managed by a body different from the entity administering the NF function. The NF function thus obtains, during step E” 5, a signed digital credential associated with the 3GPP Release 17 specification from the CAFn certification entity.
[0102] Once the NF function has received all the signed digital credentials associated with a service to be instantiated in the communication network, it adds, during a step E6, these different signed digital credentials in a conformity document grouping together all the signed digital credentials received. If only one signed digital credential is obtained, the conformity document corresponds to the signed digital credential received.
[0103] Example of a compliance document
[0104] {
[0105] "@context": [
[0106] "https: / / www.w3.org / 2018 / credentials / vl",
[0107] "https: / / www.w3.org / 2018 / credentials / examples / vl"
[0108] ],
[0109] "type": "VerifiablePresentation",
[0110] "verifiableCredential": [{
[0111] "@context": [
[0112] "https: / / www.w3.org / 2018 / credentials / vl",
[0113] "https: / / www.w3.org / 2018 / credentials / examples / vl"
[0114] ],
[0115] "id": "http: / / example.edu / credentials / 1872",: address of registration of the signed digital credential
[0116] "type": ["VerifiableCredential", "AlumniCredential"],
[0117] "issuer": "https: / / example.edu / issuers / 565049",
[0118] "issuanceDate": "2010-01-01T19:23:24Z",
[0119] "credential Subject": {
[0120] "id": "did:example:ebfeblf712ebc6flc276el2ec21",: address to check if the characteristic is compliant
[0121] "alumni OP: {
[0122] "id": "did:example:c276el2ec21ebfeblf712ebc6fl",
[0123] "name": [{
[0124] "value": "Example University",
[0125] "lang": "en"
[0126] }, {
[0127] "value": "University Example",
[0128] "lang": "fr"
[0129] }]
[0130] }
[0131] },
[0132] "proof 1 : {: proof of validity of the signed digital credential obtained by the function "type": "RsaSignature2018", : Type of encryption used for the digital credential
[0133] "created": "2017-06-18T21:19:1OZ",
[0134] "proofPurpose" : "assertionMethod",
[0135] "verificationMethod": "https: / / example.edU / issuers / 565049#key-l ",: Address to retrieve the decryption data from 56049 (university) to verify the signature
[0136] "jws":HeyJhbGciOiJSUzIlNiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0I119..T CYt5X sITJXlCxPCT8yAV-TVkffiq_PbChOMqsLfRoPsnsgw5WEuts01mq- pQy7UJiN5mgRxD-WUcX16dUEMGlv50aqzpqh4Qktb3rk- BuQy72IFLOqVOG_zS245- kronKb78cPN25DGlcTwLtjPAYuNzVB Ah4vGHSrQyHUdBBPM": signature of the digital receipt
[0137] }
[0138] }],
[0139] "proof': {
[0140] "type": "RsaSignature2018",
[0141] "created": "2018-09-14T21:19:10Z",
[0142] "proofPurpose" : "authentication",
[0143] "verificationMethod": "did:example:ebfeblf712ebc6flc276el2ec21#keys-l",
[0144] "challenge": n lf44d55f-fl61-4938-a659-f8026467fl26",
[0145] "domain": "4jt78h47fh47",
[0146] "jws":
[0147] "eyJhbGciOiJSUzIlNiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0I119..kTCYt5
[0148] Xs ITJ kronKb78cPktb3rkBuQy72IFLN25DYuNzVBAh4vGHSrQyHUGlcTwLtjPAnK b78"
[0149] }: proof signed by the function issuing the signed digital proof}
[0150] In a step E7, the NF function transmits a message relating to the communication service to a DCCF type function. The message corresponds, for example, to a request message with a view to obtaining a plurality of information that the DCCF will have previously collected from other functions of the communication network. The NF function adds to the request message the conformity document that it will have constituted during step E6. Thus, thanks to this conformity document, the DCCF entity can verify the conformity of the characteristics of the NF function for all the characteristics evaluated, present in the conformity document, and determine whether the signed digital credentials are valid, whether the NF function has indeed had its characteristics certified, whether a signature of a signed digital credential can be verified using a certificate held by the certification register Certif.The embodiment describes a message exchange between any NF function and a DCCF function but this mode is also valid for one or more message exchanges between functions of a data space, as described in [Fig 1],.
[0151] We then refer to [Fig 3] which describes the implementation of the control method according to one embodiment of the invention.
[0152] In a step E7, corresponding to step E7 of [Fig 2], the NF function transmits a request message, the request message corresponding to the instantiation of a communication service to the DCCF function in order to obtain user data as well as data session information of the service. The request message includes the signed digital credentials as obtained in accordance with the description of [Fig 2] above.
[0153] During a step E8, the DCCF function obtains from the certification registry Certif, an identifier of which is possibly present in a received signed digital credential, one or more decryption data, associated with the certification entities having certified the characteristics, therefore associated with the characteristics of the NF function for which it has just received the request message. In order to carry out the validity check of the message received during step E7, the DCCF function can obtain all the decryption data associated with the NF function by providing the Certif registry with an identifier of the NF function (DNS name, URI address (Uniform Resource Identifier), IP address, decentralized identity (did)...), as well as an identifier of the certification entity having certified a characteristic, this identifier being present in the received signed credentials.In the case where the decryption data is specific to the NF function, in addition to the identifier of the entity having certified a characteristic, an identifier of the function may also be transmitted and if a decryption data is associated with a service, an identifier of the service associated with the NF function may be transmitted in addition to the NF function identifier and the identifier of the certification entity.Obtaining can be carried out via an exchange of messages between the DCCF function and the certification register Certif, the message transmitted to the certification register comprising an identifier of the certification entity having attested to the validity of a characteristic, an identifier of the NF function and possibly an identifier of the service, and the receipt in return of decryption data specific to the certification entity having certified the characteristic of the service corresponding to the signed digital credential and associated with the NF function, thus allowing the DCCF function to validate the message received during step E7. According to an example, the DCCF function transmits to the certification register Certif the signed digital credential received from the NF function.
[0154] During a step E9, the DCCF function having obtained one (or more) decryption data associated with the certification entity and corresponding to the characteristic(s) is able to determine whether the received message is valid by validating or not the signed digital credentials received from the NF function during step E7. To carry out this validation, the DCCF function verifies the signature and the integrity of the signed digital credential using the decryption data, such as a public key.According to one example, the signed digital credential comprises a proof signed using encryption data, such as a private key, specific to the certification entity having previously certified the characteristic in accordance with the exchanges of [fig 2]. Using the decryption data corresponding to the encryption key used for signing the signed digital credential and encrypting the proof, the DCCF function determines that the signature is valid if the information obtained using the decryption data is identical to the proof received in the signed digital credential. This operation also makes it possible to verify that the signed digital credential has not been modified and therefore that its integrity is valid.The DCCF function also compares parameters, such as parameters relating to the maximum validity date of the credential, a non-revocation parameter of the signed credential, or even a characteristic identifier, to validate the message. These parameters are not necessarily encrypted and can be verified by comparing them to reference values.
[0155] In a step E10, the DCCF function transmits to an NWDAF function a message in order to obtain statistical data relating to a communication service, the service possibly being identical to the service at the initiative of the request message transmitted by the NF function in step E7. The service may independently be a network service, for example to implement or modify a connectivity service and / or an application service (video, message, voice). The message transmitted in step E10 comprises a conformity document, comprising one or more signed digital credentials, which the DCCF function has previously obtained from one or more certification entities.
[0156] In a step E11, the NWDAF function obtains from the certification registry Certif a public key relating to a certification entity having certified a security feature, to the service and to a security feature of the DCCF function. According to an example, the NWDAF function transmits an identifier of the DCCF function and possibly of the security service, an identifier of the certification entity having certified the feature. In step E12, according to one of the methods indicated in step E9, the NWDAF function determines that the digital credential relating to the security feature for the service, signed by the certification entity is valid and consequently that the message received in step E10 is valid and therefore that the DCCF function is certified. This verification was possible using the public key obtained in step E11.
[0157] In step E13, following the message transmitted to the NWDAF entity in step E10, the DCCF entity receives a response message from the NWDAF entity. This message relating to the same service, includes signed digital credentials relating to characteristics of conformity of the NWDAF function with a 5G network and consent of a user for the exploitation of the data of the service concerning him, in a conformity document therefore comprising two signed digital credentials associated with the two characteristics. The signed digital credentials further comprise an address of a revocation register Revoc, capable of recording validity information relating to the two characteristics of the NWDAF function cited above.
[0158] In a step E14, the DCCF function obtains from the certification register Certif a set of decryption data allowing verification of the signed digital credentials relating to the NWDAF function, these data relating to certification entities for compliance with a 5G network and the consent of the user whose identifiers were present in the signed digital credentials, and to characteristics / claims of compliance of the NWDAF function with a 5G network and consent of a user. It should be noted that the characteristics linked to the service may also relate to a location of the NWDAF function, compliance of the NWDAF function with a rule determined by a regulatory entity, for example in connection with obligations to backup data or use user data, or to an identification characteristic of a legal entity in charge of the NWDAF function.
[0159] In step E15, the DCCF function determines that at least one received signed digital credential does not correspond to a certificate presented by the NWDAF. This may be explained by the fact that the signed digital credential is no longer valid, the validity limit date of the validity parameter being prior to the reception of the message of step E13, and / or that the NWDAF function is not the function that it claims to be and / or that at least one signed digital credential has been modified during the sending or processing thereof, this verification being carried out using decryption data relating to the certification entity having certified one or both of the characteristics cited above, this data being obtained in step E14.When several characteristics have given rise to several signed digital credentials, it is possible for the DCCF function to evaluate the impact of the revocation of a certificate or a signed digital credential to decide whether or not to validate the message received and subsequently whether or not to revoke the NWDAF function having issued several signed digital credentials.
[0160] The DCCF function decides that the NWDAF function is not compliant because one or more signed digital credentials are not valid and therefore not to validate the received message, which could compromise the service and possibly the communications network.
[0161] In the case where a revocation registry address is present in the signed digital credential, the DCCF function can furthermore transmit during an optional step E1 6 a revocation subscription from the NWDAF function to the revocation registry Revoc which allows the DCCF function to be notified in the event of revocation of a certificate associated with the NWDAF function and thus to decide to cut off the service by blocking the exchange of messages between a function and the NWDAF function.
[0162] Optionally, in an exchange not shown in [Fig 3], a CAF function that periodically analyzes the conformity certificates of the NF functions can inform the revocation registry Revoc of the revocation of the NWDAF function so that, for example, the certification registry Certif updates the management information of the signed digital credentials, for example by deleting the decryption data associated with these certificates. The registry Certif can also request the certification entity associated with the signed credential to update the certification and consequently the signed digital credential that it holds. The revocation of the NWDAF function also induces a breakdown in communication relating to the service, knowing that the non-certification of a function in a multi-actor data space can lead to security problems.
[0163] In a step E1 7, the DCCF function managed by a telecommunications operator transmits a message relating to a data storage service of a service to an ADRF (Analytics Data Repository Function) function managed by a service provider. The message transmitted by the DCCF function may include an identifier of the entity managing the DCCF function, for example the operator of the communications network in which the DCCF function is deployed. The identifier may be deduced from the address of the DCCF function used to communicate with the ADRF function or it may be an identifier specific to the entity. Each function, managed by an entity distinct from the other function, must ensure the compliance of the other function with regard to security, location and GDPR compliance characteristics.The DCCF function adds to the message relating to the service the signed digital credentials associated with the characteristics cited above previously obtained from certification entities, the signed digital credentials integrating hashes (in order to verify the non-repudiable nature of the message). During a step E1 8, the ADRF function obtains from the certification registry Certifs the decryption data associated with these characteristics and with the signed digital credentials of the DCCF function, this decryption data being in the form of public encryption keys or any other decryption parameter associated with the entities in charge of the respective certifications.The ADRF function includes the identifier of the certification entities from which it has received identifiers in the signed digital credentials and it may include the identifier of the entity managing the DCCF function if it has received it as well as an identifier of the DCCF function, which the function will have transmitted to it in the message transmitted during step E17, as well as possibly an identifier of the service (for example data storage) so that the Certif registry transmits to it only the decryption data required for the DCCF function and possibly the service.During a step E19, the ADRF function determines whether the DCCF function that sent it a message for data storage is indeed certified, i.e. that all the characteristics required for communication between the two functions and possibly specific to a data space and / or a regulator such as a public management office, have been indeed certified and that the signed digital credentials are still valid. If the ADRF function is capable of decrypting the hashes received using the public keys obtained from the Certif registry, that it has a guarantee that the message received has not been modified by recalculating the hash from the public key, and that the validity parameters correspond to reference values, then the signed digital credentials are considered valid and the DCCF function is considered certified.In the case where the communication between the DCCF function and the ADRF function is bidirectional, the DCCF function can also ensure the certification of the ADRF function by implementing steps identical to steps E17 to E19. According to this example, the ADRF function can also add an identifier of the entity managing the ADRF function, for example of the service provider.
[0164] In the various exchanges indicated above between functions but also between a function and the different registers, it is possible to add an identifier in a message sent to another entity (function or register). This identifier can be one or more identifiers including:
[0165] An identifier of the owner of the data and the results of analyses possibly carried out by an entity other than the owner,
[0166] An identifier of the data storage provider that offers a service to orchestrate storage or analytics functions or virtual instances of these functions, an identifier of the software providers that develop the analytical models and services, involving an NWDAF function or a plurality of functions of an NWDAF function if it is decomposed.
[0167] A customer identifier, for example, who gives consent for the processing and analysis of data from a service concerning them.
[0168] During a step E20, and according to one example, the NF and DCCF functions, involved in the routing or processing of data of a service, transmit backup data (in English log) to a recording register LOG. This backup data can be time-stamped, according to one example. According to one example, the messages transmitted during step E20 are alternately sent to the LOG register during each exchange of messages, once the functions have been certified, therefore following steps E9, E12. The recording register LOG can thus be used for an audit, particularly useful when the functions such as the NF and DCCF functions are managed by separate entities, the data recorded in the LOG register then being able to serve as legal evidence. The message transmitted during step E20 includes one or more of the following information:
[0169] - The signed digital proof relating to a certification associated with a characteristic relating to the service,
[0170] - Proof of the determination of the validity of the conformity obtained by a function,
[0171] - An identifier of the function receiving the message including the added signed digital proof,
[0172] - An identifier of the function sending the message including the signed digital proof,
[0173] - A timestamp of the transaction corresponding to the transmitted message, the message including the signed digital proof.
[0174] According to another embodiment, the conformity document comprising the set of signed digital credentials is not systematically transmitted between the different functions of the communication network but it is possible for a function to transmit it to a single function, for example the DCCF, which ensures the validity control of a message for a set of functions. Thus, functions can delegate the validity control to a third function to limit the signaling overhead generated by the addition of the conformity document to the messages between the different functions. In this embodiment, it is necessary for the function to which the validity control is delegated to be trustworthy and for prior exchanges to be secure between the delegating functions and the proxy function, such as the DCCF, which ensures the control.The third-party function will then receive the signed digital credentials from the other functions and validate them or not using the decryption data received from the Certif registry. The third-party function will inform the other functions of the validity of the signed digital credentials relating to a given function.
[0175] The control method and the transmission method are particularly relevant in a communication network where communication devices (NWDAF, NEF (Network Exposure Function), ADRF, etc.) are managed by different entities and where these functions interact with functions external to the mobile network such as user terminals and / or application servers. The methods thus make it possible to certify that the exchanges comply with a contract signed between the entities, with a regulation or a specification or even with a user's wishes. Some of these functions transmit data (or information) relating to one or more communication services (audio, video, text, etc.) in messages to other functions responsible for processing, storing or aggregating them, for example.Knowing that services may have specific constraints, signed digital credentials are advantageously related to a particular communication service or to a set of services having the same constraints. Thus, each function involved in the routing of this data (or information) relating to a service has the capacity to validate or not the signed digital credentials transmitted by another function of the communication network. In the particular case where the signed digital credential concerns a user's consent, and this consent is revoked leading to a revocation of the function transmitting the signed digital credential, then the data relating to the user are possibly deleted and the exchange of messages between functions is interrupted following the revocation.
[0176] An example of implementation in a communication network where an NWDAF device is disaggregated is shown below:
[0177] In each request made by the following interfaces / services Nddcf, Nadrf, Nnwdaf, Nmfaf, Ndrf, Nnf, linking disaggregated NWDAF functions managed by different actors, the conformity presentation document "conformitydoc" must be added to the parameters of the existing interfaces / services. The services described below must add the conformity doc in their parameter.
[0178] To minimize communication network overload and signaling delays:
[0179] Nmfaf services should not contain the compliance document,
[0180] Only the exchanges in the control plane (via the DCCF) must present it and at least the following services and their responses so that each actor can present their documents via the Nardf interfaces / services and the Nnwdaf, Nmtlf, Ndccf, Nmtlf o The subscription services: StorageRequest, StorageSubscriptionRequest, Subscribe / Notify, RetrievalSubscribe) o The context exchange services Nddcf_ContextManagement (Register / Update (request / response)
[0181] Each function receiving a conformity document "conformitydoc" must verify the validity of the "token" certificates (or signed digital credentials) present in this conformity document. The validity of the messages issued by a function and subsequently of the function is verified with the information recorded in the certification registers and more specifically by evaluating whether the proofs of the tokens of the conformity document and those calculated with the help of the public keys of the CERTIF register coincide, that is to say that there is a relationship between the proof of conformity and the certificate.
[0182] Proof of compliance may relate to the certificate obtained from a CAF registered in a certification register in accordance with the following options:
[0183] - A first function inserts a token which corresponds to a string of characters associated with claims in which several pieces of information can be concatenated (example of such data: a certificate (which can itself be a certificate address allowing a public key to be retrieved from a registry, an expiration date, a CAF address (a certification entity), a signature (hash information). The proof of conformity is for example the hash information or the token.
[0184] The first function performs an operation calculating a checksum on a message to be sent, then encrypts this checksum with a private key of A (which gives an encrypted hash-A inserted into the token)
[0185] The second function, receiving the token and seeking to ensure the validity of a message sent by the first function, performs the following operations: o The second function also calculates the hash information of the received message, which gives a hash-B o The second function decrypts the encrypted hash-A received using the public key of A corresponding to or included in the certificate received from the certification registry and compares this decrypted hash-A to the hash-B value that it has just calculated
[0186] In this case, the certificate obtained from the registry is relative to the token received since the public address makes it possible to ensure the equality of the decrypted hash-A and hash-B, and therefore the validity of the message received with regard to the signature and integrity of the token.
[0187] If the verification of a certificate fails then the "conformity doc" is rejected and the message exchange service between the functions cannot be carried out.
[0188] According to another embodiment, the control and transmission methods can be implemented in a mobile access communication network SON (Self Organizing Network) or the functions exchange messages relating to a self-configuration and self-operation service of the access network.
[0189] According to yet another embodiment, the control and transmission methods can be implemented between terminals and an information collection function on these terminals.
[0190] According to yet another embodiment, the control and transmission methods can be implemented in an Edge Computing type communication network, for example, by adding the compliance document to the APIs transporting the profiles of the EAS (Edge Application Server) EES (Edge Enabler Server) Clouds, ECS (Edge Configuration Server) and Cloud clients in the EEC (Edge Enabler Client) terminal and ACs (Application Client). The compliance document can also be added to the context descriptions associated with storage space providers (clouds) which are used by a mobile network, for example, to apply local policies and regulations to the storage spaces.The control and transmission methods can be implemented in a communication architecture comprising several chained functions where each function of the chain can control the validity of a message sent by one of the nodes of the chain and received by the node verifying the validity using the signed digital credentials present in the conformity document accompanying the message.
[0191] We then refer to [Fig 4] which presents a device 300 for checking the validity of a message according to an embodiment of the invention.
[0192] Such a control device may be implemented in a network or application function or in an elementary module of a device of a communication network, such as a 5G network. Alternatively, the control device may be instantiated in a communication terminal such as a mobile terminal or access equipment of a fixed network.
[0193] For example, the control device 300 comprises a processing unit 330, equipped for example with a microprocessor pP, and controlled by a computer program 310, stored in a memory 320 and implementing the control method according to the invention. At initialization, the code instructions of the computer program 310 are for example loaded into a RAM memory, before being executed by the processor of the processing unit 330. Such a control device 300 comprises:
[0194] - a receiver (301), capable of receiving the message (Mes) comprising the signed digital proof associated with the characteristic of the first function relating to the service,
[0195] - an obtaining module (302), capable of obtaining from the certification register (Certif) determined from the identifier received a decryption data item associated with the identifier of the certification entity,
[0196] - a determination module (303) capable of determining the validity of the message (Mes) received comprising:
[0197] - a verification module, capable of verifying the signature and the integrity of the digital proof signed by the certification entity using the decryption data obtained,
[0198] - a comparator, capable of comparing the validity parameter of the signed digital proof with a required value associated with at least one characteristic.
[0199] According to this example, the determination module 303 is represented by a single module but according to another example, the verification module and the comparator are two separate modules. We then refer to [Fig 5] which presents a transmission device 400 according to an embodiment of the invention.
[0200] Such a transmission device 400 may be implemented in a network or application function or in an elementary module of a device of a communication network, such as a 5G network. According to an alternative, the control device may be instantiated in a communication terminal such as a mobile terminal or access equipment of a fixed network.
[0201] For example, the transmission device 400 comprises a processing unit 430, equipped for example with a microprocessor pP, and controlled by a computer program 410, stored in a memory 420 and implementing the transmission method according to the invention. At initialization, the code instructions of the computer program 410 are for example loaded into a RAM memory, before being executed by the processor of the processing unit 430.
[0202] Such a transmission device 400 comprises:
[0203] - an obtaining module (401), capable of obtaining signed digital proof from the certification entity,
[0204] - an addition module (402), capable of adding the signed digital proof obtained to the message relating to the service to be transmitted to a second function,
[0205] - a transmitter (403), capable of transmitting to the second function of the message (Mes) including the added signed digital proof.
Claims
CLAIMS 1. Method for checking the validity of a message sent by a first function to a second function, the two functions contributing to the instantiation of a service in a communication network, the method being implemented in the second function, capable of analyzing a message comprising a signed digital credential, the signed credential comprising an identifier of a certification register of the communication network, an identifier of a certification entity and a validity parameter of a characteristic relating to the service of the first function, and comprising: - a reception (E7, E10) of the message (Mes) including the signed digital proof associated with the characteristic of the first function relating to the service, - an acquisition (E8, El 1) from the certification register (Certif) determined from the identifier of the certification register received from decryption data associated with the identifier of the certification entity, - a determination (E9, E12) of the validity of the message (Mes) received comprising: - verification of the signature and integrity of the digital proof signed by the certification entity using the decryption data obtained, - a comparison of the validity parameter of the signed digital credential with a required value associated with at least one characteristic.
2. Control method, according to claim 1, in which the two functions are elementary modules of a device of the communication network.
3. Control method, according to claim 1 or claim 2, in which the validity parameter of a characteristic is one or more parameters among the following parameters: - a maximum validity date for the signed supporting document, - a non-revocation parameter for the signed digital proof, - an identifier of the characteristic, 4. Control method, according to one of claims 1 to 3, in which the decryption data is a public decryption key associated with a private encryption key relating to the certification entity.
5. Control method, according to one of claims 1 to 4, in which the determination of the validity of the data further comprises a revocation of the first function in the case where the signature and the integrity of the signed digital credential are not verified and / or the validity parameter of the signed digital credential is not equivalent to the required value.
6. Control method, according to one of claims 1 to 5, in which the signed digital proof further comprises information on the location of a revocation register, said revocation register being capable of recording validity information relating to a characteristic of the first function.
7. Control method according to one of claims 1 to 6, in which the characteristic relating to the service of the first function is one or more of the following characteristics: - a safety feature of the first function, - a characteristic of conformity of the message with a data format of a specific function of the communication network, - a localization characteristic of the first function, - a characteristic of consent of a user of the service for the exploitation of data relating to the user included in the message, - a characteristic of conformity of the first function with a rule determined by a regulatory entity of the communication network, - an identifying characteristic of a legal entity in charge of the first function.
8. Control method, according to one of claims 1 to 7, further comprising the transmission to the certification register of the signed digital proof and an identifier of the first function, and the reception, following this transmission, of the decryption data associated with the certification entity.
9. Method for transmitting a message by a first function to a second function, the two functions contributing to the instantiation of a service in a communication network, the method being implemented in the first function, capable of attaching a signed digital credential to the message to be transmitted to the second function, the signed credential comprising an identifier of a certification register of the communication network, an identifier of a certification entity and a validity parameter of a characteristic relating to the service of the first function, and comprising: - obtaining (E5, E'5, E”5) from the certification entity of the signed digital proof, - an addition (E6) of the signed digital proof obtained to the message relating to the service to be transmitted to a second function, - a transmission (E7) to the second function of the message including the added signed digital proof.
10. Transmission method further comprising a transmission to the certification entity of a request for certification of the characteristic and in that the signed digital proof obtained comprises certification information generated from encryption data associated with the certification entity.
11. Device (300) for checking the validity of a message sent by a first function to a second function, the two functions contributing to the instantiation of a service in a communication network, the device instantiated in the second function being capable of analyzing a message (Mes) comprising a signed digital credential, the signed credential comprising an identifier of a certification register of the communication network, an identifier of a certification entity and a validity parameter of a characteristic relating to the service of the first function and comprising: - a receiver (301), capable of receiving the message (Mes) comprising the signed digital proof associated with the characteristic of the first function relating to the service, - an obtaining module (302), capable of obtaining from the certification register (Certif) determined from the identifier of the certification register received from decryption data associated with the identifier of the certification entity, - a determination module (303) capable of determining the validity of the message (Mes) received comprising: - a verification module, capable of verifying the signature and the integrity of the digital proof signed by the certification entity using the decryption data obtained, - a comparator, capable of comparing the validity parameter of the signed digital proof with a required value associated with at least one characteristic.
12. Device (400) for transmitting a message (Mes) by a first function to a second function, the two functions contributing to the instantiation of a service in a communication network, the device implemented in the first function being capable of attaching to the message to be transmitted to the second function a signed digital proof, the signed proof comprising an identifier of a certification register of the communication network, an identifier of a certification entity and a validity parameter of a characteristic relating to the service of the first function, and comprising: - an obtaining module (401), capable of obtaining signed digital proof from the certification entity, - an addition module (402), capable of adding the signed digital proof obtained to the message relating to the service to be transferred to a second function, - a transmitter (403), capable of transmitting to the second function the message comprising the added signed digital proof. System for controlling the validity of a message transmitted by a first function to a second function, the two functions contributing to the instantiation of a service in a communication network, comprising - a control device according to claim 11, - a transmission device according to claim 12. Computer program, characterized in that it comprises the instructions for implementing the steps of the control method according to one of claims 1 to 8, when said program is executed by a processor Computer program, characterized in that it comprises the instructions for implementing the steps of the transmission method according to one of claims 9 or 10, when said program is executed by a processor.